jdma.exe创建 %System%\jdma.exe 30,472 bytes
MD5: 0xD7886A4D02BC8C5ED636E67168A6AFB6
进程 jdma.exe %System%\jdma.exe 32,768 bytes
服务 jdma jdma "Running" %System%\jdma.exe
新建HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\Set
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_JDMA
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_JDMA\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_JDMA\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\jdma
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\jdma\Security
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\jdma\Enum
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_JDMA
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_JDMA\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_JDMA\0000\Control
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jdma
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jdma\Security
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jdma\Enum
[HKEY_LOCAL_MACHINE\HARDWARE\DESCRIPTION\System\CentralProcessor\Set]
Beizhu = "5.0"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_JDMA\0000\Control]
*NewlyCreated* = 0x00000000
ActiveService = "jdma"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_JDMA\0000]
Service = "jdma"
Legacy = 0x00000001
ConfigFlags = 0x00000000
Class = "LegacyDriver"
ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
DeviceDesc = "jdma"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_JDMA]
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\jdma\Enum]
0 = "Root\LEGACY_JDMA\0000"
Count = 0x00000001
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\jdma\Security]
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\jdma]
Type = 0x00000010
Start = 0x00000002
ErrorControl = 0x00000001
ImagePath = "%System%\jdma.exe"
DisplayName = "jdma"
ObjectName = "LocalSystem"
Description = "jdma"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_JDMA\0000\Control]
*NewlyCreated* = 0x00000000
ActiveService = "jdma"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_JDMA\0000]
Service = "jdma"
Legacy = 0x00000001
ConfigFlags = 0x00000000
Class = "LegacyDriver"
ClassGUID = "{8ECC055D-047F-11D1-A537-0000F8753ED1}"
DeviceDesc = "jdma"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_JDMA]
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jdma\Enum]
0 = "Root\LEGACY_JDMA\0000"
Count = 0x00000001
NextInstance = 0x00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jdma\Security]
Security = 01 00 14 80 90 00 00 00 9C 00 00 00 14 00 00 00 30 00 00 00 02 00 1C 00 01 00 00 00 02 80 14 00 FF 01 0F 00 01 01 00 00 00 00 00 01 00 00 00 00 02 00 60 00 04 00 00 00 00 00 14 00 FD 01 02 00 01 01 00 00 00 00 00 05 12 00 00 00 00 00 18 00 FF 01 0F 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\jdma]
Type = 0x00000010
Start = 0x00000002
ErrorControl = 0x00000001
ImagePath = "%System%\jdma.exe"
DisplayName = "jdma"
ObjectName = "LocalSystem"
Description = "jdma"
修改[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\ServiceCurrent]
(Default) = 0x0000000C
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\ServiceCurrent]
(Default) = 0x0000000C
端口1033 TCP jdma.exe (%System%\jdma.exe)
请求连接jkddd2.3322.org
试图与远程主机建立连接0.0.38.119 --port 1690
255.255.255.255 --port 1690