分类: WINDOWS
2010-08-15 11:44:31
C:\Windows\system32\drivers\XSRProto.sys
XSRProto.sys
some.exe
unpacked:004020E0 00000035 C SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SvcHost
unpacked:00402118 0000000C C
unpacked:00402124 0000000B C ServiceDll
unpacked:00402130 00000021 C %SystemRoot%\\system32\\VMUSRV.dll
unpacked:00402154 00000034 C SYSTEM\\CurrentControlSet\\Services\\VMUSRV\\Parameters
unpacked:00402188 0000001D C Virtual Machine User Service
unpacked:004021A8 0000002C C %SystemRoot%\\system32\\svchost.exe -k VMUSRV
unpacked:004021D4 00000007 C VMUSRV
unpacked:004021DC 00000033 C :INS\r\nDEL \"%s\"\r\nif exist \"%s\" goto INS\r\nDEL \"%s\"\r\n
unpacked:00402210 0000000D C %s\\UNINS.bat
unpacked:00402220 00000006 C FILES
unpacked:00402234 0000000B C XSpoof-SR3
unpacked:00402240 0000000C C _
unpacked:0040224C 0000000C C
unpacked:00402258 00000011 C SeDebugPrivilege
unpacked:0040C408 0000005A C insert into T_XSSV (XS_Server,XS_UserName,XS_Password,XS_Type) values('%s','%s','%s',%u)
unpacked:0040C468 0000006C C update T_XSSV set XS_Password='%s',XS_Update=False where XS_Server='%s' AND XS_UserName='%s' AND XS_Type=%d
unpacked:0040C4D8 0000004E C select * from T_XSSV where XS_Type=%d AND XS_Server='%s' AND XS_UserName='%s'
unpacked:0040C528 0000000B C XSpoof-SR3
unpacked:0040C534 00000009 C DATABASE
unpacked:0040C540 00000005 C
unpacked:0040C558 00000007 C VMUSRV
unpacked:0040C664 00000035 C SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\SvcHost
unpacked:0040C69C 0000002B C SYSTEM\\CurrentControlSet\\Services\\XSRProto
unpacked:0040C6C8 00000029 C SYSTEM\\CurrentControlSet\\Services\\VMUSRV
unpacked:0040C6F4 00000009 C XSRProto
unpacked:0040C700 0000002D C update T_XSSV set XS_Update=True where ID=%u
unpacked:0040C730 00000008 C XS_Type
unpacked:0040C738 0000000C C XS_Password
unpacked:0040C744 0000000C C XS_UserName
unpacked:0040C750 0000000A C XS_Server
unpacked:0040C760 0000002B C select * from T_XSSV where XS_Update=false
unpacked:0040C78C 0000001E C system32\\DRIVERS\\XSRProto.sys
unpacked:0040C7AC 00000009 C
unpacked:0040C7B8 00000006 C POST
unpacked:0040C7C0 0000000C C
unpacked:0040C7D0 0000000A C
unpacked:0040C7DC 00000007 C Host:
unpacked:0040C7E4 00000007 C Basic
unpacked:0040C7EC 0000000F C Authorization:
unpacked:0040C7FC 00000005 C GET
unpacked:0040C804 00000006 C %s:%u
unpacked:0040C80C 00000006 C PASS
unpacked:0040C814 00000006 C USER
unpacked:0040C81C 0000001A C Global\\TcpipReconfigEvent
unpacked:0040C838 00000013 C TcpipReconfigEvent
unpacked:0040C84C 00000011 C Global\\XSR3Event
unpacked:0040C860 0000000A C XSR3Event
unpacked:0040C86C 0000000B C
unpacked:0040C878 00000016 C
unpacked:00413F68 00000011 C .?AV_com_error@@
unpacked:00413F88 00000010 C .?AVtype_info@@
unpacked:00424B30 00000012 C 1'?\x1B·&“N‰±Y\\?I=?\a
unpacked:004380D4 0000000D C KERNEL32.DLL
unpacked:004380E1 0000000D C ADVAPI32.dll
unpacked:004380EE 0000000B C MSVCRT.dll
unpacked:004380FA 0000000D C LoadLibraryA
unpacked:00438108 0000000F C GetProcAddress
unpacked:00438118 0000000C C ExitProcess
unpacked:00438126 0000000C C RegCloseKey
unpacked:00438134 00000005 C exit
.snaker:00439050
.snaker:00439060
.snaker:0043906E
.snaker:0043907E
.snaker:00439094
.snaker:004390A4
.snaker:004390B6
.snaker:004390CE
.snaker:004390E6
.snaker:004390FA
.snaker:0043910A
.snaker:0043911A
.snaker:0043912C
.snaker:0043913E
.snaker:0043915A
.snaker:00439178
.snaker:00439188
.snaker:0043919C
.snaker:004391AA
.snaker:004391BA
.snaker:004391CA
.snaker:004391DA
.snaker:004391EA
.snaker:004391FC
.snaker:0043920C
.snaker:0043921C
.snaker:0043922A
.snaker:0043923A
.snaker:00439250
.snaker:00439260
.snaker:0043926C
.snaker:0043927E
.snaker:00439290
.snaker:004392A4
.snaker:004392B2
.snaker:004392C0
.snaker:004392CE
.snaker:004392D8
.snaker:004392EE
.snaker:004392F8
.snaker:00439304
.snaker:00439312
.snaker:00439320
.snaker:00439332
.snaker:00439342
.snaker:00439352
.snaker:00439366
.snaker:00439372
.snaker:00439382
.snaker:0043938C
.snaker:00439394
.snaker:004393A2
.snaker:004393AA
.snaker:004393BE
.snaker:004393C8
HKLM\SYSTEM\CurrentControlSet\Services\VMUSRV
使用的还是“Virtual Machine User Service”,挺有迷惑性的
HKLM\SYSTEM\CurrentControlSet\Services\XSRProto
C:\Windows\system32\drivers\XSRProto.sys
C:\Windows\system32\VMUSRV.dll