返回地址: 00401853 函数名称: lstrcpy(KERNEL32.dll)
lstrcpy: 复制字符串,复制lpString2到lpString1
lpString1=0x0012F64C
lpString2=":try
del ""
lstrcpy返回值: 0x0012F64C (":try
del "")
返回地址: 00401863 函数名称: lstrcat(KERNEL32.dll)
lstrcat: 把string2连接到string1后面
String1=":try
del ""
String2="C:\Documents and Settings\Administrator\桌面\dumped.exe"
lstrcat返回值: 0x0012F64C (":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe")
返回地址: 00401870 函数名称: lstrcat(KERNEL32.dll)
lstrcat: 把string2连接到string1后面
String1=":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
String2=""
if exist ""
lstrcat返回值: 0x0012F64C (":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
if exist "")
返回地址: 00401880 函数名称: lstrcat(KERNEL32.dll)
lstrcat: 把string2连接到string1后面
String1=":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
if exist ""
String2="C:\Documents and Settings\Administrator\桌面\dumped.exe"
lstrcat返回值: 0x0012F64C (":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
if exist "C:\Documents and Set")
返回地址: 0040188D 函数名称: lstrcat(KERNEL32.dll)
lstrcat: 把string2连接到string1后面
String1=":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
if exist "C:\Documents and Set"
String2="" goto try
del %0"
lstrcat返回值: 0x0012F64C (":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
if exist "C:\Documents and Set")
返回地址: 0040189F 函数名称: lstrlen(KERNEL32.dll)
lstrlen: 获取字符串的长度
lpString=":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
if exist "C:\Documents and Set"
lstrlen返回值: 0x00000098(字符串长度)
返回地址: 004018B0 函数名称: WriteFile(KERNEL32.dll)
WriteFile: 将数据写入一个文件
hFile=0x00000064
lpBuffer=0x0012F64C
nNumberOfBytesToWrite=0x00000098
lpNumberOfBytesWritten=0x0012FCF0
lpOverlapped=0x00000000
存入缓冲区中的数据: ":try
del "C:\Documents and Settings\Administrator\桌面\dumped.exe"
if exist "C:\Documents and Set"
异常: 非法访问地址 100B5469h
进程已被SoftSnoop终止
到这里出现了异常,没法调试下去了,打开任务管理器,可以看到进程kandofttk.exe,另外,桌面上有两个文件dumped.exe、dumped.exe.bat,其中dumped.exe.bat的内容为:
:try
del "C:\Documents and Settings\Administrator\桌面\kandofttk.exe"
if exist "C:\Documents and Settings\Administrator\桌面\kandofttk.exe" goto try
del %0
原来创建批处理文件之后还没来得及执行就出现了异常,这个批处理文件显然是用来删除dumped.exe、dumped.exe.bat这两个文件的。