九
28
病毒样本:http://www.52pojie.cn/thread-64398-1-1.html
只分析了exe,感染的dll下次分析
exe
去除启动时候的小漏斗
004017C9 |. 53 push ebx 004017CA |. 55 push ebp 004017CB |. 56 push esi 004017CC |. 57 push edi 004017CD |. FF15 AC104000 call dword ptr [<&USER32.GetInputStat>; [GetInputState 004017D3 |. 33DB xor ebx, ebx 004017D5 |. 53 push ebx ; /lParam => 0 004017D6 |. 53 push ebx ; |wParam => 0 004017D7 |. 53 push ebx ; |Message => WM_NULL 004017D8 |. FF15 64104000 call dword ptr [<&KERNEL32.GetCurrent>; |[GetCurrentThreadId 004017DE |. 50 push eax ; |ThreadId 004017DF |. FF15 B0104000 call dword ptr [<&USER32.PostThreadMe>; \PostThreadMessageA 004017E5 |. 53 push ebx ; /MsgFilterMax => 0 004017E6 |. 53 push ebx ; |MsgFilterMin => 0 004017E7 |. 8D4424 1C lea eax, dword ptr [esp+1C] ; | 004017EB |. 53 push ebx ; |hWnd => NULL 004017EC |. 50 push eax ; |pMsg 004017ED |. FF15 B4104000 call dword ptr [<&USER32.GetMessageA>>; \GetMessageA
