发布时间:2014-07-15 11:50:28作者:知识屋
Windows XP Service Pack 3Windows XP Professional x64 Edition Service Pack 2Windows Server 2003 Service Pack 2Windows Server 2003 x64 Edition Service Pack 2Windows Server 2003 with SP2 for Itanium-based SystemsWindows Vista Service Pack 2Windows Vista x64 Edition Service Pack 2Windows Server 2008 for 32-bit Systems Service Pack 2Windows Server 2008 for x64-based Systems Service Pack 2Windows Server 2008 for Itanium-based Systems Service Pack 2Windows 7 for 32-bit Systems Service Pack 1Windows 7 for x64-based Systems Service Pack 1Windows Server 2008 R2 for x64-based Systems Service Pack 1Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
00D307E7 6A 27 push 2700D307E9 8D45 AC lea eax, dword ptr [ebp-54]00D307EC 50 push eax 00D307ED 56 push esi ; <clsid:19916E01-B44E-4E31-94A4-4696DF46157B>00D307EE FF15 141CC400 call dword ptr [<&ole32.StringFromGUID2>] ; ole32.StringFromGUID200D307F4 85C0 test eax, eax 00D307F6 7C 1D jl short 00D30815
.text:004F07E9 lea eax, [ebp+sz].text:004F07EC push eax ; lpsz .text:004F07ED push esi ; rguid .text:004F07EE call ds:__imp__StringFromGUID2@12 ; StringFromGUID2(x,x,x)
5DDFF493 6A FF push -15DDFF495 6A 00 push 05DDFF497 FFB5 00F0FFFF push dword ptr [ebp-1000]5DDFF49D 57 push edi 5DDFF49E FF15 BC11CA5D call dword ptr [<&KERNEL32.WaitForMultipleObjects>] ; kernel32.WaitForMultipleObjects5DDFF4A4 85C0 test eax, eax 5DDFF4A6 0F86 28390100 jbe 5DE12DD45DDFF4AC 3BC7 cmp eax, edi 5DDFF4AE 0F83 71390100 jnb 5DE12E25
[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{19916e01-b44e-4e31-94a4-4696df46157b}] "Compatibility Flags"=dword:04000400
0575A004 33 04 C2 77 D5 5E C1 77 FA 40 C2 77 92 9F C3 77 3聎誢羨鶣聎挓脀0575A014 92 9F C3 77 92 9F C3 77 92 9F C3 77 92 9F C3 77 挓脀挓脀挓脀挓脀0575A024 92 9F C3 77 92 9F C3 77 92 9F C3 77 92 9F C3 77 挓脀挓脀挓脀挓脀
056F1A24 /EB 10 jmp short 056F1A36 ; ShellCode开始056F1A26 |5B pop ebx 056F1A27 |4B dec ebx 056F1A28 |33C9 xor ecx, ecx 056F1A2A |66:B9 8C01 mov cx, 18C056F1A2E |80340B 9F xor byte ptr [ebx+ecx], 9F ; 循环解密056F1A32 ^|E2 FA loopd short 056F1A2E056F1A34 |EB 05 jmp short 056F1A3B056F1A36 E8 EBFFFFFF call 056F1A26056F1A3B 56 push esi 056F1A3C 57 push edi 056F1A3D 52 push edx 056F1A3E 33C9 xor ecx, ecx 056F1A40 64:8B71 30 mov esi, dword ptr fs:[ecx+30]056F1A44 8B76 0C mov esi, dword ptr [esi+C]056F1A47 8B76 1C mov esi, dword ptr [esi+1C]056F1A4A 8B5E 08 mov ebx, dword ptr [esi+8]056F1A4D 8B7E 20 mov edi, dword ptr [esi+20]056F1A50 8B36 mov esi, dword ptr [esi]056F1A52 817F 0C 3300320>cmp dword ptr [edi+C], 320033056F1A59 ^ 75 EF jnz short 056F1A4A ; 搜索kernel32.dll
Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{19916e01-b44e-4e31-94a4-4696df46157b}] "Compatibility Flags"=dword:04000400 [HKEY_LOCAL_MACHINESOFTWAREWow6432NodeMicrosoftInternet ExplorerActiveX Compatibility{19916e01-b44e-4e31-94a4-4696df46157b}] "Compatibility Flags"=dword:04000400 [HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{c2c4f00a-720e-4389-aeb9-e9c4b0d93c6f}] "Compatibility Flags"=dword:04000400 [HKEY_LOCAL_MACHINESOFTWAREWow6432NodeMicrosoftInternet ExplorerActiveX Compatibility{c2c4f00a-720e-4389-aeb9-e9c4b0d93c6f}] "Compatibility Flags"=dword:04000400 [HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{53001f3a-f5e1-4b90-9c9f-00e09b53c5f1}] "Compatibility Flags"=dword:04000400 [HKEY_LOCAL_MACHINESOFTWAREWow6432NodeMicrosoftInternet ExplorerActiveX Compatibility{53001f3a-f5e1-4b90-9c9f-00e09b53c5f1}] "Compatibility Flags"=dword:04000400
2011-06-17
电脑开机时出现lass.exe进程是病毒吗?
自拍须谨慎!教你如何通过照片定位查看拍摄地点
电脑病毒最基础知识
黑客学员必须了解的C语言技术
精典详细内网渗透专题文章
教你破解Tp-Link的无线路由密码
解决SecureCRT中文显示乱码
QQ电脑管家和360哪个好?横评实测对比
攻防实战:无线网络路由入侵过程