Skip to content

Instantly share code, notes, and snippets.

@blaquee
Created October 16, 2015 21:21
Show Gist options
  • Select an option

  • Save blaquee/60dabfee72ff6677095e to your computer and use it in GitHub Desktop.

Select an option

Save blaquee/60dabfee72ff6677095e to your computer and use it in GitHub Desktop.
00403C1D . E8 42320000 CALL <JMP.&ADVAPI32.LsaLookupNames>
00403C22 . E8 CF2F0000 CALL <JMP.&LZ32.LZStart>
00403C27 . 68 74064300 PUSH 5d8645f7.00430674 ; /Password = "sslrfkjkdfai"
00403C2C . 68 60064300 PUSH 5d8645f7.00430660 ; |ServiceStartName = "z47sHc498Kw8I7Hk9Rk"
00403C31 . 8D55 F0 LEA EDX,DWORD PTR SS:[EBP-10] ; |
00403C34 . 68 84064300 PUSH 5d8645f7.00430684 ; |pDependencies = 5d8645f7.00430684
00403C39 . 52 PUSH EDX ; |pTagId
00403C3A . 68 94064300 PUSH 5d8645f7.00430694 ; |LoadOrderGroup = "kupgnvhjat"
00403C3F . 68 4C064300 PUSH 5d8645f7.0043064C ; |BinaryPathName = "v451917V88JH88126q7"
00403C44 . 6A 2F PUSH 2F ; |ErrorControl = 2F
00403C46 . 6A 33 PUSH 33 ; |StartType = 33
00403C48 . 6A 20 PUSH 20 ; |ServiceType = SERVICE_WIN32_SHARE_PROCESS
00403C4A . 6A 33 PUSH 33 ; |DesiredAccess = SERVICE_QUERY_CONFIG|SERVICE_CHANGE_CONFIG|SERVICE_START|SERVICE_STOP
00403C4C . 68 A0064300 PUSH 5d8645f7.004306A0 ; |DisplayName = "nevbpvllhpyrciy"
00403C51 . 68 B0064300 PUSH 5d8645f7.004306B0 ; |ServiceName = "r6L0QIjh011u6I4720"
00403C56 . 6A 2B PUSH 2B ; |hManager = 0000002B
00403C58 . C745 F0 380000>MOV DWORD PTR SS:[EBP-10],38 ; |
00403C5F . FF15 38704000 CALL DWORD PTR DS:[<&ADVAPI32.CreateServiceA>] ; \CreateServiceA
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment