http://bbs.kafan.cn/viewthread.php?tid=244907&extra=page%3D1
xx.exe
沙盘里跑不起来,只替换了驱动beep.sys恢复SSDT,使kav等主防失效
temp文件夹下释放所需的dll的temp文件
察看得-
- 1000103E PUSH datA.10008020 ASCII "data"
- 10001208 PUSH datA.10008028 ASCII "DLL"
- 1000134E PUSH datA.10008050 ASCII "\system32\drivers\beep.sys"
- 10001384 PUSH datA.10008034 ASCII "\system32\dllcache\beep.sys"
- 100013A9 MOV EDI,datA.1000802C ASCII "beep"
- 1000148C MOV DWORD PTR DS:[ESI],datA.100052A8 ASCII "f7"
- 100014FE PUSH datA.10008080 ASCII "SeDebugPrivilege"
- 1000150B PUSH datA.10008074 ASCII "drvAnti.exe"
- 100015B4 PUSH datA.100080A4 ASCII "winlogon.exe"
- 100015D1 PUSH datA.10008094 ASCII "explorer.exe"
- 10001633 MOV EDI,datA.10008630 ASCII "http://ccc.52gol.com/tk.txt"
- 10001692 MOV ESI,datA.100080C0 ASCII "atapi.sys"
- 10001701 PUSH datA.100080B4 ASCII "\drivers"
- 100017C1 MOV ESI,datA.100080CC ASCII "classpnp.sys"
- 10001831 PUSH datA.100080B4 ASCII "\drivers"
- 10001974 MOV ESI,datA.100080DC ASCII "stpdrive.sys"
- 100019DE PUSH datA.100080B4 ASCII "\drivers"
- 10001A93 MOV ESI,datA.100080EC ASCII "ntfs.sys"
- 10001B02 PUSH datA.100080B4 ASCII "\drivers"
- 10001BC2 MOV ESI,datA.100080F8 ASCII "fastfat.sys"
- 10001C2E PUSH datA.100080B4 ASCII "\drivers"
- 10001D07 MOV EDI,datA.10008138 ASCII "ntoskrnl.exe"
- 10001D1A MOV EDI,datA.10008128 ASCII "NTKRNLPA.exe"
- 10001D2D MOV EDI,datA.10008118 ASCII "ntkrnlmp.exe"
- 10001DC8 MOV EDI,datA.10008104 ASCII "ntkrpamp.exe"
- 10001EF3 PUSH datA.10008148 ASCII "SOFTWARE\Microsoft\IE4"
- 10002001 PUSH datA.10008020 ASCII "data"
- 1000205A PUSH datA.100081B0 ASCII "
复制代码 病毒dll文件调用驱动下载木马
"http://ccc.52gol.com/tk.txt"
列表明文- ver=1
- Url1=http://ccc.52gol.com/xx/soc01.exe
- Url2=http://ccc.52gol.com/xx/soc02.exe
- Url3=http://ccc.52gol.com/xx/soc03.exe
- Url4=http://ccc.52gol.com/xx/soc04.exe
- Url5=http://ccc.52gol.com/xx/soc05.exe
- Url6=http://ccc.52gol.com/xx/soc06.exe
- Url7=http://ccc.52gol.com/xx/soc07.exe
- Url8=http://ccc.52gol.com/xx/soc08.exe
- Url9=http://ccc.52gol.com/xx/soc09.exe
- Url10=http://ccc.52gol.com/xx/soc10.exe
- Url11=http://ccc.52gol.com/xx/soc11.exe
- Url12=http://ccc.52gol.com/xx/soc12.exe
- Url13=http://ccc.52gol.com/xx/soc13.exe
- Url14=http://ccc.52gol.com/xx/soc14.exe
- Url15=http://ccc.52gol.com/xx/soc15.exe
- Url16=http://ccc.52gol.com/xx/soc16.exe
- Url17=http://ccc.52gol.com/xx/soc17.exe
- Url18=http://ccc.52gol.com/xx/soc18.exe
- Url19=http://ccc.52gol.com/xx/soc19.exe
- Url20=http://ccc.52gol.com/xx/soc20.exe
- Url21=http://ccc.52gol.com/xx/soc21.exe
- Url22=http://ccc.52gol.com/xx/soc22.exe
- Url23=http://ccc.52gol.com/xx/soc23.exe
- Url24=http://ccc.52gol.com/xx/soc24.exe
- Url25=http://ccc.52gol.com/xx/soc25.exe
- Url26=http://ccc.52gol.com/xx/soc26.exe
- Url27=http://ccc.52gol.com/xx/soc27.exe
- Url28=http://ccc.52gol.com/xx/soc28.exe
复制代码
[ 本帖最后由 promised 于 2008-5-1 15:02 编辑 ] |