x-door免杀的问题大家来看看
这是multiccl查出来的
[Temp]
TmpFileName=H_00000000_00029FFF_00029FFF_000016BA.tmp
tmpCodz=C:\Documents and Settings\Administrator\桌面\output\GZUQJVYAz0.Rl
First=0
[CharactorCodz]
newCodz=1
OK=1
CharactorTotal=6
Codz1=~~00002747_00002756_00000010_000016BA
Codz2=H_00001456_00001459_00000004_000016BA
Codz3=H_0000860E_00008611_00000004_000016BA
Codz4=H_00008DBC_00008DBF_00000004_000016BA
Codz5=H_0000F5A0_0000F5A3_00000004_000016BA
Codz6=H_0000FE2A_0000FE2D_00000004_000016BA
第一处
Codz2=H_00001456_00001459_00000004_000016BA
代码如下
0040144B |. FF15 70204000 call dword ptr [<&MSVCRT.fopen>] ; \fopen
00401451 |. 8BF8 mov edi, eax
00401453 |. 83C4 18 add esp, 18
00401456 3BFB cmp edi, ebx
00401458 74 22 je short 0040147C
0040145A 8D85 00FCFFFF lea eax, dword ptr [ebp-400]
00401460 |. 56 push esi
00401461 |. 8B35 6C204000 mov esi, dword ptr [<&MSVCRT.fprintf>; msvcrt.fprintf
00401467 |. 50 push eax ; /<%s>
00401468 |. 68 54324000 push 00403254 ; |format = CR,LF,"%s"
0040146D |. 57 push edi ; |stream
0040146E |. FFD6 call esi ; \fprintf
00401470 |. 68 48324000 push 00403248 ; ASCII CR,LF,"del %%0",CR,LF
00401475 |. 57 push edi
00401476 |. FFD6 call esi
00401478 |. 83C4 14 add esp, 14
0040147B |. 5E pop esi
0040147C |> 57 push edi ; /stream
0040147D |. FF15 68204000 call dword ptr [<&MSVCRT.fclose>] ; \fclose
00401483 |. 59 pop ecx
第二处
Codz3=H_0000860E_00008611_00000004_000016BA
0040860A 59 pop ecx
0040860B BF 143D0910 mov edi, 10093D14
00408610 75 2F jnz short 00408641
00408612 837D 08 04 cmp dword ptr [ebp+8], 4
第四处
Codz5=H_0000F5A0_0000F5A3_00000004_000016BA
0040F59B E8 6CA20000 call 0041980C
0040F5A0 85C0 test eax, eax
0040F5A2 59 pop ecx
0040F5A3 75 07 jnz short 0040F5AC
0040F5A5 68 EC490910 push 100949EC
第三处
Codz4=H_00008DBC_00008DBF_00000004_000016BA
00408DB7 E8 5DFDFFFF call 00408B19
00408DBC 85C0 test eax, eax
00408DBE 0F84 D7000000 je 00408E9B
00408DC4 68 FF0F1F00 push 1F0FFF
00408DC9 8D85 F0FEFFFF lea eax, dword ptr [ebp-110]
第五处
Codz6=H_0000FE2A_0000FE2D_00000004_000016BA
0040FE26 53 push ebx
0040FE27 68 944B0910 push 10094B94
0040FE2C FF75 E0 push dword ptr [ebp-20]
0040FE2F FF15 1C600110 call dword ptr [1001601C]
Codz1=~~00002747_00002756_00000010_000016BA这处在代码中是空的没有代码
那位给看看