:kaka2:
rootkit?
0040101D mov edi,c784.0041B110 .770304123.cn
004010C3 mov esi,c784.0041B110 .770304123.cn
004017FD mov edi,c784.0041B120 @jl~f~
004018A3 mov esi,c784.0041B120 @jl~f~
0040194D mov edi,c784.0041B120 @jl~f~
004019F3 mov esi,c784.0041B120 @jl~f~
00401A9D mov edi,c784.0041B128 SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
00401B43 mov esi,c784.0041B128 SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
00401D3C push c784.0041B188 shell32.dll
00401D58 push c784.0041B174 SHGetFolderPathA
00402583 push c784.0041B198 jq
0040258F push c784.0041B194 mr
00402658 push c784.0041B1A0 gq
00402664 push c784.0041B19C ba
0040289A push c784.0041B1BC \regsvr32.exe
00402901 mov edi,c784.0041B1B4 /s "
00402948 mov esi,c784.0041B1B4 /s "
0040294F mov edi,c784.0041B1A8 /u /s "
00402991 mov esi,c784.0041B1A8 /u /s "
004029D2 mov edi,c784.0041B1A4 "
00402A1D mov esi,c784.0041B1A4 "
00402D90 mov edi,c784.0041B1D4 \System32\drivers\etc\hosts
00402DE3 mov esi,c784.0041B1D4 \System32\drivers\etc\hosts
00402E52 mov edi,c784.0041B1CC \hosts
00402E9D mov esi,c784.0041B1CC \hosts
00402FBB push c784.0041B1F4 rt
004030D7 push c784.0041B1F0 w+t
004033FF push c784.0041B20C J3U
0040343F push c784.0041B208 %u
0040345D mov edi,c784.0041B1F8 microsoft_lock
00403575 mov edi,c784.0041B278 \rundll32
0040358C push c784.0041B278 \rundll32
00403615 push c784.0041B274
00403653 mov edi,c784.0041B268 , Always
00403663 push c784.0041B268 , Always
004036C0 mov dword ptr ss:[esp+78],c784.0041B258 WinSta0\Default
004036FF push c784.0041B254 EM
00403704 push c784.0041B24C SYST
00403710 push c784.0041B244 %s%s
004037AF push c784.0041B240 XE
004037B4 push c784.0041B23C .E
004037B9 push c784.0041B238 ER
004037BE push c784.0041B234 R
004037C3 push c784.0041B230 O
004037C8 push c784.0041B22C PL
004037CD push c784.0041B228 X
004037D2 push c784.0041B224 E
004037DE push c784.0041B210 %s%s%s%s%s%s%s%s
00403B8D mov edi,c784.0041B298 {01DE82
00403B9D push c784.0041B298 {01DE82
00403BC8 mov edi,c784.0041B290 F0281
00403BD8 push c784.0041B290 F0281
00403C03 mov edi,c784.0041B284 0BB9D466D}
00403C13 push c784.0041B284 0BB9D466D}
00403F94 push c784.0041B2D4 \
00403FD6 push c784.0041B2D4 \
0040408D push c784.0041B2D0 w
004040BC push c784.0041B2C8 .dll
004041BA push c784.0041B2C4 b
004041E6 push c784.0041B2C8 .dll
004042AD push c784.0041B2C0 c
004042D9 push c784.0041B2B8 .exe
00404386 push c784.0041B2C8 .dll
00404423 push c784.0041B2B0 .bmp
00404529 push c784.0041B2B8 .exe
0040464C push c784.0041B2A8 .flv
00404735 push c784.0041B2A4 cm
00404761 push c784.0041B2A0 .rm
0040620D mov edi,c784.0041B110 .770304123.cn
004062B3 mov esi,c784.0041B110 .770304123.cn
004069ED mov edi,c784.0041B120 @jl~f~
00406A93 mov esi,c784.0041B120 @jl~f~
00406B3D mov edi,c784.0041B120 @jl~f~
00406BE3 mov esi,c784.0041B120 @jl~f~
00406C8C mov dword ptr ds:[esi],c784.00418228 pm@
00406D90 mov dword ptr ds:[ecx],c784.00418228 pm@
00406DCE push c784.0041B40C -v
00406DF5 push c784.0041B3F8 %s Version %d.%d\n
00406E0B mov eax,c784.0041B3EC currently
00406E12 mov eax,c784.0041B3E8 not
00406E18 push c784.0041B3C8 The service is %s installed\n
00406E38 push c784.0041B3C4 -i
00406E5D push c784.0041B3A8 %s is already installed\n
00406E89 push c784.0041B398 %s installed\n
00406EB1 push c784.0041B378 %s failed to install. Error %d\n
00406ED1 push c784.0041B374 -u
00406EF6 push c784.0041B35C %s is not installed\n
00406F39 push c784.0041B324 %s removed. (You must delete the file (%s) yourself.)\n
00406F61 push c784.0041B304 Could not remove %s. Error %d\n
00406F81 push c784.0041B300 -s
00406FA2 push c784.0041B35C %s is not installed\n
00406FCB push c784.0041B2FC -e
00406FEC push c784.0041B35C %s is not installed\n
00407018 push c784.0041B2EC %s startup.\n
00407039 push c784.0041B2D8 %s startup failed.\n
0040715A mov edi,c784.0041B434 SYSTEM\CurrentControlSet\Services\EventLog\Application\
00407213 push c784.0041B420 EventMessageFile
0040722A push c784.0041B410 TypesSupported
00407BF9 push c784.0041B578 Software\AD
00407C39 push c784.0041B570 ServTM
00407C86 push c784.0041B578 Software\AD
00407CBE push c784.0041B570 ServTM
00407D06 push c784.0041B578 Software\AD
00407D3E push c784.0041B570 ServTM
00407DC6 push c784.0041B46C kwws9,,;;;-;70`boo-`m,bgsb`h-w{w
00407FD8 mov dword ptr ss:[esp+B8],c784.0041B598 */*
0040805E push c784.0041B58C HTTP/1.1
00408064 push c784.0041B584 POST
004083E8 mov edi,c784.0041B5BC [main]
004083F9 push c784.0041B5BC [main]
00408433 push c784.0041B5B8 u=
00408488 push c784.0041B5AC play.dll
004084C1 mov edi,c784.0041B5A4 p1.dll
00408515 push c784.0041B5A0 bfp
0040853B push c784.0041B59C %s
0040994D push c784.0041B604 %02x
00409B98 push c784.0041B60C \\.\PhysicalDrive%d
00409DA4 mov edi,c784.0041B620 winio.sys
0040A1A2 push c784.0041B638 \\.\Scsi%d:
0040A1ED push c784.0041B62C SCSIDISK
0040A426 push c784.0041B644 WD-W
0040A6D2 mov dword ptr ds:[eax],c784.004182BC 唳@
0040A700 mov dword ptr ds:[ecx],c784.004182BC 唳@
0040B102 mov esi,c784.004182F8 string too long
0040B131 mov [local.15],c784.004182EC 喜@
0040B2F7 mov dword ptr ds:[esi],c784.004182EC 喜@
0040B321 mov esi,c784.00418328 invalid string position
0040B350 mov [local.15],c784.0041831C 烦@
0040B3DF mov dword ptr ds:[esi],c784.0041831C 烦@
0040BF85 mov dword ptr ds:[eax+ecx-8],c784.004183 枋@
0040C1E7 mov dword ptr ds:[esi+4],c784.004183DC 淌@
0040C251 mov dword ptr ds:[esi+4],c784.004183DC 淌@
0040C28B mov dword ptr ds:[ecx],c784.004183DC 淌@
0040C2BB mov dword ptr ds:[esi+8],c784.004183DC 淌@
0040C2DA mov dword ptr ds:[eax+esi],c784.004183CC 枋@
0040C323 mov dword ptr ds:[esi+8],c784.004183DC 淌@
0040C339 mov dword ptr ds:[eax+esi],c784.004183CC 枋@
0040CCD3 mov esi,c784.0041849C ios::badbit set
0040CCDD mov esi,c784.00418488 ios::failbit set
0040CCE4 mov esi,c784.00418478 ios::eofbit set
0040CD21 mov [local.14],c784.0041846C 畚@
0040CF03 mov dword ptr ds:[esi],c784.0041846C 畚@
0040D0A7 mov esi,c784.0041B668 C
0040D196 mov ebx,c784.0041B64C *
0040D1AE mov dword ptr ds:[esi],c784.004184CC 难@
0040D1F2 mov dword ptr ds:[esi],c784.004184CC 难@
0040E751 mov eax,c784.004184F4 Unknown exception
0040E85E push ebp (Initial CPU selection)
00411D88 push c784.004187BC KERNEL32
00411D97 push c784.004187A0 IsProcessorFeaturePresent
00411F42 push c784.004187C8 e+000
00412B26 push c784.00418AA8 <program name unknown>
00412B68 push c784.00418AA4 ...
00412B7C push c784.00418A88 Runtime Error!\n\nProgram:
00412B9A push c784.00418A84 \n\n
00412BC2 push c784.00418A5C Microsoft Visual C++ Runtime Library
00414214 push c784.00418B00 TZ
004156B8 push c784.00418B44 user32.dll
004156CF push c784.00418B38 MessageBoxA
004156E0 push c784.00418B28 GetActiveWindow
004156E8 push c784.00418B14 GetLastActivePopup
004162F1 push c784.00418B68 1#SNAN
0041630B push c784.00418B60 1#IND
0041631C push c784.00418B58 1#INF
00416339 push c784.00418B50 1#QNAN
CA HIPS看不出什么。。