<span class="pediy"><span class="pediy">
[part 2]
004207D5 8D85 E15C4000 lea eax, dword ptr ss:[ebp+405CE1]
004207EB E8 34120000 call Try.00421A24
00421A68 60 pushad
00421A80 B8 92764000 mov eax, Try.00407692
00421A9C 03C5 add eax, ebp ; buffer
00421AA3 8BF0 mov esi, eax
00421AAA 68 C8000000 push MAX_PATH
00421AAF 50 push eax
00421AB0 FF95 44724000 call dword ptr ss:[ebp+407244] ; kernel32.GetSystemDirectoryA
00421ABB 90 nop
00421AC0 8A06 mov al, byte ptr ds:[esi]
00421AC7 46 inc esi
00421ADF 3C 00 cmp al, 0
00421B0E ^\75 AB jnz short Try.00421ABB
00421B15 C646 FF 5C mov byte ptr ds:[esi-1], 5C ; 目录后边加个"\"
00421B1E C706 63646364 mov dword ptr ds:[esi], 64636463 ; cdcd
00421B29 C746 04 2E73797>mov dword ptr ds:[esi+4], 7379732E ; .sys
00421B5D C746 08 0000000>mov dword ptr ds:[esi+8], 0 ; NULL, 铺张浪费,byte就足够了
; 我这里的文件名
---------------------------------------------------------------------------
00421DB9 ** 3A 5C 57 *:\W
00421DC9 49 4E 44 4F 57 53 5C 53 79 73 74 65 6D 33 32 5C INDOWS\System32\
00421DD9 63 64 63 64 2E 73 79 73 cdcd.sys
---------------------------------------------------------------------------
00421B92 B8 86764000 mov eax, Try.00407686
00421B9C 03C5 add eax, ebp
00421BCB BB 92764000 mov ebx, Try.00407692
00421BFD 03DD add ebx, ebp
00421C2C 6A 00 push 0
00421C2E 6A 20 push 20
00421C30 6A 04 push 4
00421C32 6A 00 push 0
00421C34 6A 02 push 2
00421C36 68 00000040 push 40000000
00421C3B 53 push ebx
00421C3C FF95 48724000 call dword ptr ss:[ebp+407248] ; kernel32.CreateFileA
; 参数,清晰一些
---------------------------------------------------------------
0012FF60 00421C42 /CALL to CreateFileA from Try.00421C3C
0012FF64 00421DC5 |FileName = "E:\WINDOWS\System32\cdcd.sys"
0012FF68 40000000 |Access = GENERIC_WRITE
0012FF6C 00000002 |ShareMode = FILE_SHARE_WRITE
0012FF70 00000000 |pSecurity = NULL
0012FF74 00000004 |Mode = OPEN_ALWAYS
0012FF78 00000020 |Attributes = ARCHIVE
0012FF7C 00000000 \hTemplateFile = NULL
---------------------------------------------------------------
00421C4C 83F8 FF cmp eax, -1
00421C54 /0F84 32010000 je Try.00421D8C ; 坏事了...
00421C76 8985 8A764000 mov dword ptr ss:[ebp+40768A], eax ; 保存句柄
00421CC0 B9 8C310000 mov ecx, 318C ; 驱动文件长度
00421CCA B8 8E764000 mov eax, Try.0040768E
00421CE6 03C5 add eax, ebp ; WriteFile返回结构,名字忘了
00421CED BB 5A774000 mov ebx, Try.0040775A
00421D09 03DD add ebx, ebp ; 可爱的驱动程序
00421D10 6A 00 push 0
00421D12 50 push eax
00421D13 51 push ecx
00421D14 53 push ebx
00421D15 FFB5 8A764000 push dword ptr ss:[ebp+40768A] ; hWnd
00421D1B FF95 4C724000 call dword ptr ss:[ebp+40724C] ; kernel32.WriteFile
; 写出驱动,如果想把这个东西拷贝出来研究要关闭程序,它独占了文件
0012FF68 00421D21 /CALL to WriteFile from Try.00421D1B
0012FF6C 00000024 |hFile = 00000024
0012FF70 00421E8D |Buffer = Try.00421E8D
0012FF74 0000318C |nBytesToWrite = 318C (12684.)
0012FF78 00421DC1 |pBytesWritten = Try.00421DC1
0012FF7C 00000000 \pOverlapped = NULL
00421D3D FFB5 8A764000 push dword ptr ss:[ebp+40768A]
00421D43 FF95 50724000 call dword ptr ss:[ebp+407250] ; kernel32.CloseHandle
0012FF78 00421D49 /CALL to CloseHandle from Try.00421D43
0012FF7C 00000024 \hObject = 00000024
00421D76 61 popad
00421D7C B8 01000000 mov eax, TRUE ; 收工
00421D86 C3 ret ; 回家
00421D8C 90 nop
00421D91 61 popad
00421D7C B8 01000000 mov eax, FALSE
00421D86 C3 ret
00420807 83F8 00 cmp eax, FALSE ; 失败?
0042080F /0F84 22480000 je Try.00425037
00425037 50 push eax
00425038 FFB5 2A6C4000 push dword ptr ss:[ebp+406C2A]
0042503E FF95 30724000 call dword ptr ss:[ebp+407230] ; kernel32.ReleaseMutex,释放互斥体
00425044 FFB5 2A6C4000 push dword ptr ss:[ebp+406C2A]
0042504A FF95 50724000 call dword ptr ss:[ebp+407250] ; kernel32.CloseHandle,关闭互斥体句柄
00425050 58 pop eax
00425068 83F8 00 cmp eax, 0
0042506B 0F85 4C010000 jnz Try.004251BD
; ..............我没走这条线,不跟了
0042085E 8D85 E25C4000 lea eax, dword ptr ss:[ebp+405CE2]
00420874 E8 7F060000 call Try.00420EF8
-----------------------------
以后不跟那么多线了,受不了
00420F2A 68 3F000F00 push 0F003F
00420F2F 6A 00 push 0
00420F31 6A 00 push 0
00420F33 FF95 CD724000 call dword ptr ss:[ebp+4072CD] ; advapi32.OpenSCManagerA
00420F50 83F8 00 cmp eax, 0
00420F58 /0F84 8F030000 je Try.004212ED
00420F75 8985 3A6C4000 mov dword ptr ss:[ebp+406C3A], eax
00420F85 B8 3E6C4000 mov eax, Try.00406C3E
00420FA1 03C5 add eax, ebp
00420FBA 68 FF010F00 push 0F01FF
00420FBF 50 push eax
00420FC0 FFB5 3A6C4000 push dword ptr ss:[ebp+406C3A]
00420FC6 FF95 D5724000 call dword ptr ss:[ebp+4072D5] ; advapi32.OpenServiceA
00420FD1 83F8 00 cmp eax, 0
00420FD4 0F85 97000000 jnz Try.00421071 ; Jump
0042109E 83F8 00 cmp eax, 0
004210A6 /0F84 41020000 je Try.004212ED
004210B1 8985 586C4000 mov dword ptr ss:[ebp+406C58], eax
004210C1 6A 00 push 0
004210C3 6A 00 push 0
004210C5 FFB5 586C4000 push dword ptr ss:[ebp+406C58]
004210CB FF95 C5724000 call dword ptr ss:[ebp+4072C5] ; advapi32.StartServiceA
; 启动服务,不好玩^^,我这里服务开启,所以产生了ERROR_SERVICE_ALREADY_RUNNING (00000420)
004210E4 FF95 40724000 call dword ptr ss:[ebp+407240] ; ntdll.RtlGetLastWin32Error
00421101 3D E5030000 cmp eax, 3E5
00421106 /0F84 DD000000 je Try.004211E9
00421123 3D 20040000 cmp eax, 420
00421128 /0F84 B6000000 je Try.004211E4 ; GoGoGo,否则Game Over就不好玩了
0042120A B8 446C4000 mov eax, Try.00406C44
00421226 03C5 add eax, ebp
; Oh God save me!!!
---------------------------------------------------------------------------
00421377 5C 5C 2E 5C 44 62 70 65 44 65 76 69 63 65 30 00 \\.\DbpeDevice0.
---------------------------------------------------------------------------
0042123F 6A 00 push 0
00421241 6A 00 push 0
00421243 6A 03 push 3
00421245 6A 00 push 0
00421247 6A 01 push 1
00421249 68 000000C0 push C0000000
0042124E 50 push eax
0042124F FF95 48724000 call dword ptr ss:[ebp+407248] ; kernel32.CreateFileA
0012FF7C 0012FFE0
0012FF80 00421255 /CALL to CreateFileA from Try.0042124F
0012FF84 00421377 |FileName = "\\.\DbpeDevice0"
0012FF88 C0000000 |Access = GENERIC_READ|GENERIC_WRITE
0012FF8C 00000001 |ShareMode = FILE_SHARE_READ
0012FF90 00000000 |pSecurity = NULL
0012FF94 00000003 |Mode = OPEN_EXISTING
0012FF98 00000000 |Attributes = 0
0012FF9C 00000000 \hTemplateFile = NULL
; 调查一下服务
0042126C 83F8 FF cmp eax, -1
00421274 /74 77 je short Try.004212ED ; 没启动走人,加载错误
0042127B 8985 546C4000 mov dword ptr ss:[ebp+406C54], eax; save handle
004212AE B8 01000000 mov eax, TRUE
004212B8 8985 706C4000 mov dword ptr ss:[ebp+406C70], eax
004212D5 C3 ret ; 回去了
004208A6 83F8 00 cmp eax, 0 ; over?
004208AE /0F84 83470000 je Try.00425037 ; over
004208C3 C785 5C6C4000 0>mov dword ptr ss:[ebp+406C5C], 3
004208FF B8 5C3A4200 mov eax, Try.00423A5C
00420909 03C5 add eax, ebp
; forgot: 老是这个,我$@%@%@^%@$^
00420922 8985 606C4000 mov dword ptr ss:[ebp+406C60], eax ; Try.0043E18F
00420932 B8 746C4000 mov eax, Try.00406C74
0042093C 03C5 add eax, ebp
0042096B 8985 646C4000 mov dword ptr ss:[ebp+406C64], eax ; Try.004213A7
0042097B B8 5C6C4000 mov eax, Try.00406C5C
00420985 03C5 add eax, ebp
0042098C 6A 00 push 0
0042098E 6A 00 push 0
00420990 6A 00 push 0
00420992 6A 00 push 0
00420994 6A 0C push 0C
00420996 50 push eax
00420997 6A 04 push 4
00420999 FFB5 546C4000 push dword ptr ss:[ebp+406C54]
0042099F FF95 3C724000 call dword ptr ss:[ebp+40723C] ; kernel32.DeviceIoControl
0012FF80 004209A5 /CALL to DeviceIoControl from Try.0042099F
0012FF84 0000004C |hDevice = 0000004C
0012FF88 00000004 |IoControlCode = 4
0012FF8C 0042138F |InBuffer = Try.0042138F
0012FF90 0000000C |InBufferSize = C (12.)
0012FF94 00000000 |OutBuffer = NULL
0012FF98 00000000 |OutBufferSize = 0
0012FF9C 00000000 |pBytesReturned = NULL
0012FFA0 00000000 \pOverlapped = NULL
00420A55 B8 00000000 mov eax, 0
00420A5F 81BD 746C4000 8>cmp dword ptr ss:[ebp+406C74], FFFF8888
00420A6E /0F84 C3450000 je Try.00425037 ; 好像是Over
00420AB8 C785 5C6C4000 0>mov dword ptr ss:[ebp+406C5C], 3
00420AF4 B8 5C3A4200 mov eax, Try.00423A5C
00420AFE 03C5 add eax, ebp
00420B17 8985 606C4000 mov dword ptr ss:[ebp+406C60], eax ; Try.0043E18F
00420B61 B8 746C4000 mov eax, Try.00406C74
00420B6B 03C5 add eax, ebp
00420B9A 8985 646C4000 mov dword ptr ss:[ebp+406C64], eax ; Try.004213A7
00420BBC C785 746C4000 0>mov dword ptr ss:[ebp+406C74], 0
00420BE2 B8 5C6C4000 mov eax, Try.00406C5C
00420BEC 03C5 add eax, ebp
00420BF3 6A 00 push 0
00420BF5 6A 00 push 0
00420BF7 6A 00 push 0
00420BF9 6A 00 push 0
00420BFB 6A 0C push 0C
00420BFD 50 push eax
00420BFE 6A 01 push 1
00420C00 FFB5 546C4000 push dword ptr ss:[ebp+406C54]
00420C06 FF95 3C724000 call dword ptr ss:[ebp+40723C] ; kernel32.DeviceIoControl
0012FF80 00420C0C /CALL to DeviceIoControl from Try.00420C06
0012FF84 0000004C |hDevice = 0000004C
0012FF88 00000001 |IoControlCode = 1
0012FF8C 0042138F |InBuffer = Try.0042138F
0012FF90 0000000C |InBufferSize = C (12.)
0012FF94 00000000 |OutBuffer = NULL
0012FF98 00000000 |OutBufferSize = 0
0012FF9C 00000000 |pBytesReturned = NULL
0012FFA0 00000000 \pOverlapped = NULL
; 中断向量被xxx了,不敢用int3乱动阿!用F4走,或者在Debug里设置用hardware breakpoint进行step,否则****自己想象吧
; ****************************************************************
; 千 万 小 心
; ****************************************************************
00420C0C 90 nop ; F4
00420D07 8B85 746C4000 mov eax, dword ptr ss:[ebp+406C74]
00420D3A 83F8 00 cmp eax, 0
00420D42 /0F84 EF420000 je Try.00425037 ; over
00420D7A 66:8985 5434420>mov word ptr ss:[ebp+423454], ax
00420D86 C1E8 10 shr eax, 10
00420D8E 66:8985 5634420>mov word ptr ss:[ebp+423456], ax
00420DC7 B8 01000000 mov eax, 1
00420DD1 8985 6C6C4000 mov dword ptr ss:[ebp+406C6C], eax
00420E09 50 push eax
00420E0F B8 92764000 mov eax, Try.00407692
00420E2B 03C5 add eax, ebp
; 对驱动进行惨无人道的毁尸灭迹……
00420E5A 50 push eax ; Try.00421DC5
00420E5B FF95 38724000 call dword ptr ss:[ebp+407238] ; kernel32.DeleteFileA
0012FF98 00420E61 /CALL to DeleteFileA from Try.00420E5B
0012FF9C 00421DC5 \FileName = "E:\WINDOWS\System32\cdcd.sys"
00420E66 58 pop eax
00420E6C /E9 C6410000 jmp Try.00425037
00425037 50 push eax
00425038 FFB5 2A6C4000 push dword ptr ss:[ebp+406C2A]
0042503E FF95 30724000 call dword ptr ss:[ebp+407230] ; kernel32.ReleaseMutex
0012FF98 00425044 /CALL to ReleaseMutex from Try.0042503E
0012FF9C 00000020 \hMutex = 00000020
00425044 FFB5 2A6C4000 push dword ptr ss:[ebp+406C2A]
0042504A FF95 50724000 call dword ptr ss:[ebp+407250] ; kernel32.CloseHandle
0012FF98 00425050 /CALL to CloseHandle from Try.0042504A
0012FF9C 00000020 \hObject = 00000020
; 没人性,互斥体也惨遭毒手……
00425050 58 pop eax
00425068 83F8 00 cmp eax, 0
0042506B 0F85 4C010000 jnz Try.004251BD ; Go
004251C2 /E9 39010000 jmp Try.00425300
; 花絮:跳过的这段代码还真惹眼:)
----------------------------------------------------------------
004251CC FA cli
004251D2 BE 4E344200 mov esi, Try.0042344E
004251DC 03F5 add esi, ebp
004251E3 0F010E sidt fword ptr ds:[esi]
004251EB 8B76 02 mov esi, dword ptr ds:[esi+2]
0042520A 66:8B46 18 mov ax, word ptr ds:[esi+18]
00425213 66:8B5E 1E mov bx, word ptr ds:[esi+1E]
00425244 66:8985 5434420>mov word ptr ss:[ebp+423454], ax
00425250 66:899D 5634420>mov word ptr ss:[ebp+423456], bx
00425289 B8 5C3A4200 mov eax, Try.00423A5C
00425293 03C5 add eax, ebp
004252AC 66:8946 18 mov word ptr ds:[esi+18], ax
004252B5 C1E8 10 shr eax, 10
004252E5 66:8946 1E mov word ptr ds:[esi+1E], ax
; 好在我不是9x....哈
----------------------------------------------------------------
