- UID
- 2198
注册时间2005-6-29
阅读权限255
最后登录1970-1-1
副坛主
  
该用户从未签到
|
发表于 2007-10-24 13:09:42
|
显示全部楼层
看来木马客星是完蛋了 得需要重新换壳了 脱壳调试了一下 我这的地址在这:
0062A8AB . 55 PUSH EBP
0062A8AC . 68 C0B36200 PUSH de_Iparm.0062B3C0
0062A8B1 . 64:FF30 PUSH DWORD PTR FS:[EAX]
0062A8B4 . 64:8920 MOV DWORD PTR FS:[EAX],ESP
0062A8B7 . E8 C082DDFF CALL de_Iparm.00402B7C
0062A8BC . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
0062A8BF . C780 0C030000>MOV DWORD PTR DS:[EAX+30C],2
0062A8C9 . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
0062A8CC . C680 09030000>MOV BYTE PTR DS:[EAX+309],0
0062A8D3 . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
0062A8D6 . C680 0A030000>MOV BYTE PTR DS:[EAX+30A],0
0062A8DD . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
0062A8E0 . C780 00030000>MOV DWORD PTR DS:[EAX+300],0FFFA
0062A8EA . 8B45 FC MOV EAX,DWORD PTR SS:[EBP-4]
0062A8ED . C680 08030000>MOV BYTE PTR DS:[EAX+308],1
0062A8F4 . E8 73C9DDFF CALL <JMP.&kernel32.GetSystemDefaultLangID> ; [GetSystemDefaultLangID
0062A8F9 . 8BD8 MOV EBX,EAX
0062A8FB . C605 C5A26400>MOV BYTE PTR DS:[64A2C5],0
0062A902 . C605 C4A26400>MOV BYTE PTR DS:[64A2C4],0
0062A909 . A1 10576300 MOV EAX,DWORD PTR DS:[635710]
0062A90E . 8B00 MOV EAX,DWORD PTR DS:[EAX]
0062A910 . 8B50 78 MOV EDX,DWORD PTR DS:[EAX+78]
0062A913 . A1 C0A26400 MOV EAX,DWORD PTR DS:[64A2C0]
0062A918 . 8B80 F4020000 MOV EAX,DWORD PTR DS:[EAX+2F4]
0062A91E . E8 FDEBE9FF CALL de_Iparm.004C9520
0062A923 . B2 01 MOV DL,1
0062A925 . A1 78654500 MOV EAX,DWORD PTR DS:[456578]
0062A92A . E8 B5BDE2FF CALL de_Iparm.004566E4
0062A92F . 8945 F8 MOV DWORD PTR SS:[EBP-8],EAX
0062A932 . BA 03000080 MOV EDX,80000003
0062A937 . 8B45 F8 MOV EAX,DWORD PTR SS:[EBP-8]
0062A93A . E8 81BEE2FF CALL de_Iparm.004567C0
0062A93F . 33C9 XOR ECX,ECX
0062A941 . BA D8B36200 MOV EDX,de_Iparm.0062B3D8 ; ASCII ".DEFAULT\Software\AngelSoft\iparmor"
0062A946 . 8B45 F8 MOV EAX,DWORD PTR SS:[EBP-8]
0062A949 . E8 B6BFE2FF CALL de_Iparm.00456904
0062A94E . 8D4D F4 LEA ECX,DWORD PTR SS:[EBP-C]
0062A951 . BA 04B46200 MOV EDX,de_Iparm.0062B404 ; ASCII "pass"
兄弟是根据这个函数找到的关键点还是注册表位置 强!
GetSystemDefaultLangID
KEY保存在这里; HKEY_USERS\.DEFAULT\Software\AngelSoft\iparmor |
|