采用VMProtect加壳
感谢Smallyou93
创建
%Temp%\tcom.dll
%Temp%\tbot.dll
%Temp%\thk.dll
%Temp%\now.tmspage
%Temp%\360Update.dat
%Systemroot%\system32\ws2help.dll
%Systemroot%\system32\sikinstead.dll
%Systemroot%\system32\spacecom.dll%Temp%\nyz.txt
重命名%Systemroot%\system32\ws2help.dll
删除%Systemroot%\System32\dllcache\ws2help.dll
替换了ws2help.dll这个系统文件
查询Cryptographic Services服务是否开启
开启的话停止
一会儿又开启,试图控制Cryptographic Services服务更改以下注册表键值:
HKCU\Softwave\Microsoft\windows\CurrentVersion\Explorer\Shell Folders\\Cache
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\\Directory
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\\Paths
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\path1\\CachePath
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\path2\\CachePath
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\path3\\CachePath
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\\path4\\CachePath
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\path1\\CacheLimit
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\path2\\CacheLimit
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\path3\\CacheLimit
HKLM\Softwave\Microsoft\windows\Internet Settings\Cache\Paths\path4\\CacheLimit
HKCU\Softwave\Microsoft\windows\CurrentVersion\Explorer\Shell Folders\\Cookies
HKCU\Softwave\Microsoft\windows\CurrentVersion\Explorer\Shell Folders\\History
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c241f360-4814-11de-8dc4-806d6172696f}\\BaseClass
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c241f361-4814-11de-8dc4-806d6172696f}\\BaseClass
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c241f362-4814-11de-8dc4-806d6172696f}\\BaseClass
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\\AppData
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c241f363-4814-11de-8dc4-c30afef21e57}\\BaseClass
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable
HKLM\System\CurrentControlSet\Hardware Profiles\0001\Software\Microsoft\windows\CurrentVersion\Internet Settings\\ProxyEnable
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\ProxyBypass
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\IntranetName
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\\UNCAsIntranet
删除注册表值
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\AutoConfigURL