Ultra String Reference
Address Disassembly Text String
00401000 push 0040BB80 local\{48b6dabc-0171-44f2-8093-eb0ca03c772d}
00401013 push 0040BB80 local\{48b6dabc-0171-44f2-8093-eb0ca03c772d}
00401029 push 0040BB30 /autostart
00401223 push 0040BB48 http://
0040124E push 0040BB58 /terms.php
00401270 push 0040BB70 open
004013E1 push 0040BBDC n1\n1.exe
00401456 push 0040BBF0 software\n1\n1\{93963acf-6617-4cae-bc2a-a37c0eac1052}
0040147D push 0040BC5C id
004014D8 mov ecx, 0040BC60 n191_hosts_change
00401513 push 0040BC84 drivers\etc\hosts
0040159D push 0040BCA8 217.20.175.74
004016EA mov ecx, 0040BCB8 n191_install_run_autostart
004016F3 mov ecx, 0040BCF0 n191_install_run
00401708 mov ecx, 0040BD14 n191_getid_failure
00401739 push 0040BD3C anti-virus number-1
004017F4 push 0040BBDC n1\n1.exe
0040181C push 0040BD64 autostart
004018D2 push 0040BD78 n1
00401989 push 0040BD80 collection.php?step=
004019B4 push 0040BDAC &id=
004019DE push 0040BDB8 none
00401BA1 push 0040BD78 n1
00401DCC push 0040BD78 n1
0040207E mov ecx, 0040BDC4 n191_location_incorect
00402224 push 0040BBDC n1\n1.exe
00402275 push 0040BDF4 anti-virus number-1.lnk
004022DA push 0040BD3C anti-virus number-1
00402318 push 0040BDF4 anti-virus number-1.lnk
00402383 push 0040BD3C anti-virus number-1
004023B5 push 0040BE24 uninstall.lnk
00402419 push 0040BDF4 anti-virus number-1.lnk
0040247E push 0040BD3C anti-virus number-1
004024BC push 0040BDF4 anti-virus number-1.lnk
00402523 push 0040BD3C anti-virus number-1
0040254D push 0040BE24 uninstall.lnk
00402591 mov edi, 0040BE40 uninstall
004025E0 push 0040BE54 wscsvc
0040268A mov ecx, 0040BE64 n191_hosts_patch_failure
004026FD mov ecx, 0040BE98 n191_install_exe
00402750 push 0040BD78 n1
0040278C push 0040BEBC n1.cab
004027C8 mov ecx, 0040BECC n191_exe_dl_failure
004027EC push 0040BEF4 cmd.exe
00402816 push 0040BF04 /c expand "
0040286A push 0040BF20 " "
00402884 push 0040BF28 .exe
004028BC push 0040BF34 "
0040292D mov ecx, 0040BF38 n191_expanded
00402941 mov ecx, 0040BF54 n191_disable_sc
0040295D mov ecx, 0040BF74 n191_install_plugin
004029A7 push 0040BF9C n1\qwprotect.dll
004029EB mov ecx, 0040BFC0 n191_ieplugin_dl_failure
00402A1D push 0040BFF4 regsvr32.exe
00402A4E push 0040C010 /s "
00402AAA push 0040BF34 "
00402B12 mov ecx, 0040C01C n191_install_svc
00402B5C push 0040C040 n1\svchost.exe
00402BA0 mov ecx, 0040C060 n191_bsod_dl_failure
00402BAA mov ecx, 0040C08C n191_create_shortcuts
00402BBD mov ecx, 0040C0B8 n191_shortcuts_failure
00402BCC mov ecx, 0040C0E8 n191_install_complete
00402BED push 0040BD78 n1
00402C11 push 0040C114 70.38.11.165
00402C2D push 0040C130 /admin/cgi-bin/get_domain.php?type=download
00402C32 push 0040C188 get
00402CFD push 0040BD78 n1
00402D21 push 0040C114 70.38.11.165
00402D3D push 0040C190 /admin/cgi-bin/get_domain.php?type=site
00402D42 push 0040C188 get
004037FA mov esi, 0040A29C kernel32.dll
00403815 push 0040A28C encodepointer
00403875 mov esi, 0040A29C kernel32.dll
00403890 push 0040A2B8 decodepointer
00403971 mov esi, 0040A29C kernel32.dll
0040399F push 0040A28C encodepointer
004039B3 push 0040A2B8 decodepointer
00403C80 mov esi, 0040A29C kernel32.dll
00403CA7 push 0040A2E8 flsalloc
00403CAF push 0040A2DC flsgetvalueflsalloc
00403CBC push 0040A2D0 flssetvalueflsgetvalueflsalloc
00403CC9 push 0040A2C8 flsfreeflssetvalueflsgetvalueflsalloc
00403FBB push 0040A304 mscoree.dll
00403FCA push 0040A2F4 corexitprocess
00405696 push 0040A940 runtime error!\n\nprogram:
004056DE push 0040A928 <program name unknown>
00405723 push 0040A924 ...<program name unknown>
0040574B push 0040A920 \n\n
00405795 push 0040A8F8 microsoft visual c++ runtime library
004058E3 mov eax, 0040A968 unknown exception
00406135 mov edi, edi (initial cpu selection)
00407808 push 0040AA90 user32.dll
00407823 push 0040AA84 messageboxauser32.dll
00407839 mov dword ptr [esp], 0040AA74 getactivewindowmessageboxauser32.dll
0040784E mov dword ptr [esp], 0040AA60 getlastactivepopup
00407863 mov dword ptr [esp], 0040AA44 getuserobjectinformationa
00407882 push 0040AA2C getprocesswindowstationgetuserobjectinformationa |