- UID
- 34504
注册时间2007-8-16
阅读权限8
最后登录1970-1-1
初入江湖

该用户从未签到
|
我手头的病毒脱了外壳后还显示有这个壳:
Morphine 1.2 - 1.3 -> rootkit
我在论坛搜索到一点Morphine的资料,不过和我用OD载和诉结果完全不一样,我这个用OD载入后头如下:
00402715 > E8 F9FBFFFF call 00402313 <-OD载入后停在这
0040271A E8 C6EFFFFF call 004016E5
0040271F E8 4FF5FFFF call 00401C73
00402724 E8 41FCFFFF call 0040236A
00402729 68 04010000 push 104
0040272E 6A 40 push 40
00402730 E8 A1000000 call <jmp.&KERNEL32.GlobalAlloc>
00402735 8BF0 mov esi, eax
00402737 68 04010000 push 104
0040273C 56 push esi
0040273D 6A 00 push 0
0040273F E8 74000000 call <jmp.&KERNEL32.GetModuleFileName>
00402744 56 push esi
00402745 E8 10010000 call <jmp.&KERNEL32.lstrlenA>
0040274A 50 push eax
0040274B 56 push esi
0040274C E8 31F5FFFF call 00401C82
00402751 68 F4010000 push 1F4
00402756 E8 BD000000 call <jmp.&KERNEL32.Sleep>
0040275B 33C0 xor eax, eax
0040275D C3 retn
会的朋友指点下. |
|