|

http://www.3600gz.cn/thread-13619702-1-1.html 楼主:永不放弃
所有程序在无杀毒情况下打开闪退(任务管理器有,界面一闪就消失了)OD检测
004019B3 push DNF8E0全.0047F413 \
00401A21 push DNF8E0全.0047F415 \Del.exe
00401A7B push DNF8E0全.0047F415 \Del.exe
00401AD5 push DNF8E0全.00480626 \DelFile.sys
00401B2F push DNF8E0全.0048243B "
00401B39 push DNF8E0全.0048243D \Del.exe "
00401B9F push DNF8E0全.00480626 \DelFile.sys
00401BBB mov eax,DNF8E0全.00482448 DelFile.sys
00401BEC push DNF8E0全.00480626 \DelFile.sys
00401C08 mov eax,DNF8E0全.00482448 DelFile.sys
00401CC9 mov ebx,DNF8E0全.00418EF0 j
00401CD6 push DNF8E0全.0048243B "
00401CE0 push DNF8E0全.0048243D \Del.exe "
00401D4B mov ebx,DNF8E0全.00418EF0 j
00401D58 push DNF8E0全.0047F415 \Del.exe
00401DB2 push DNF8E0全.00480626 \DelFile.sys
00401DCE mov eax,DNF8E0全.00482448 DelFile.sys
00401DFF push DNF8E0全.0047F415 \Del.exe
00401E4D push DNF8E0全.00480626 \DelFile.sys
00407633 push DNF8E0全.006610BE D:\Program Files\WINSOD\servicex.exe
0040763F push DNF8E0全.006610E3 software\microsoft\windows\CurrentVersion\Run\servicex
0040768D mov ebx,DNF8E0全.00416BA0 j
004076EE push DNF8E0全.006610E3 software\microsoft\windows\CurrentVersion\Run\servicex
0040772E mov ebx,DNF8E0全.00416BA0 j
0040778F push DNF8E0全.006610E3 software\microsoft\windows\CurrentVersion\Run\servicex
004077C7 mov ebx,DNF8E0全.00416B80 j
004077DC mov ebx,DNF8E0全.00416BA0 j
0040783D push DNF8E0全.006610E3 software\microsoft\windows\CurrentVersion\Run\servicex
0040788A mov ebx,DNF8E0全.00416BA0 j
004078EB push DNF8E0全.006610E3 software\microsoft\windows\CurrentVersion\Run\servicex
00407921 push DNF8E0全.0066111A Software\Microsoft\Windows\CurrentVersion\Run\
0040793B mov ebx,DNF8E0全.00416B80 j
00407950 mov ebx,DNF8E0全.00416BA0 j
004079FF push DNF8E0全.0066111A Software\Microsoft\Windows\CurrentVersion\Run\
00407A21 mov ebx,DNF8E0全.00416BA0 j
00407AD0 push DNF8E0全.0066111A Software\Microsoft\Windows\CurrentVersion\Run\
00407B10 mov ebx,DNF8E0全.00416BA0 j
00407BBF push DNF8E0全.0066111A Software\Microsoft\Windows\CurrentVersion\Run\
运用到DEL.EXE 和servicex ?请管理检测! |
评分
-
查看全部评分
|