-
-
[原创]一个病毒的分析
-
发表于:
2011-6-9 21:49
13508
-
感染型病毒简单分析
ID:疯狂的小鬼(卡饭)
工具:OD
病毒自身就脱壳
样本地址:968K9s2c8@1M7q4)9K6b7g2)9J5c8W2)9J5c8X3u0T1M7#2)9J5k6h3E0S2k6X3q4F1i4K6u0W2j5$3&6Q4x3V1k6X3L8%4u0#2L8g2)9J5k6i4m8Z5M7q4)9K6c8X3#2G2k6q4)9K6c8s2u0W2k6r3W2J5k6h3y4@1i4K6t1$3k6$3!0@1L8#2)9K6c8r3k6A6L8X3c8H3L8%4y4@1i4K6t1$3M7s2c8A6k6q4)9K6c8o6V1&6y4U0f1I4y4g2)9J5y4Y4m8A6k6q4)9K6c8o6p5&6y4e0t1I4y4e0t1&6i4K6t1$3k6Y4u0G2L8i4g2A6k6q4)9K6c8o6f1#2x3K6t1%4y4#2)9J5y4X3&6T1M7%4m8Q4x3@1u0Q4x3U0k6F1j5Y4y4H3i4K6y4n7i4@1g2r3i4@1u0o6i4K6R3^5y4o6k6Q4c8e0k6Q4b7e0g2Q4b7V1y4Q4c8f1k6Q4b7V1y4Q4z5o6V1`.
00429E5E > 55 push ebp ; 入口
00429EC0 /75 08 jnz short VideoPlu.00429ECA 为了分析。不让他跳
00429EC4 E8 B0000000 call VideoPlu.00429F79 F7 进去看看
00429F79 833D 10234300 0>cmp dword ptr ds:[0x432310],0x1
00429F80 75 05 jnz short VideoPlu.00429F87
00429F82 E8 890B0000 call VideoPlu.0042AB10
00429F87 FF7424 04 push dword ptr ss:[esp+0x4]
00429F8B E8 B90B0000 call VideoPlu.0042AB49
00429F90 59 pop ecx
00429F91 68 FF000000 push 0xFF ; 下面退出进程
00429F96 FF15 34D04200 call dword ptr ds:[<&KERNEL32.ExitProces>; kernel32.ExitProcess
00429F9C C3 retn
[培训]内核驱动高级班,冲击BAT一流互联网大厂工作,每周日13:00-18:00直播授课