Which sequence is responsible for Non - DC?
There are sequences from you file Conquer.exe.
1
004AFC5E |. E8 570B0000 CALL Conquer.004B07BA
---> changed into
004AFC5E |. 90 NOP
004AFC5F |. 90 NOP
004AFC60 |. 90 NOP
004AFC61 |. 90 NOP
004AFC62 |. 90 NOP
2
004B07BA /$ 55 PUSH EBP
---> changed into
004B07BA . C3 RETN
3
005AB8F2 . B8 F4418100 MOV EAX,Conquer.008141F4
---> changed into
005AB8F2 . C2 1800 RETN 18
005AB8F5 90 NOP
005AB8F6 90 NOP
4
005ABD3A . 0F84 DB000000 JE Conquer.005ABE1B
---> changed into
005ABD3A . E9 DC000000 JMP Conquer.005ABE1B
005ABD3F 90 NOP
5
005AC175 . 59 POP ECX
005AC176 . 68 486E9300 PUSH Conquer.00936E48 ; /FileName = "tqwea.dll"
005AC17B . FF15 5C418400 CALL DWORD PTR DS:[<&KERNEL32.LoadLibrar>; \LoadLibraryA
---> changed into
005AC175 . 90 NOP
005AC176 . 90 NOP
005AC177 . 90 NOP
005AC178 . 90 NOP
005AC179 . 90 NOP
005AC17A . 90 NOP
005AC17B . 90 NOP
005AC17C . 90 NOP
005AC17D . 90 NOP
005AC17E . 90 NOP
005AC17F . 90 NOP
005AC180 . 90 NOP
6
005AC246 . 0F84 CC030000 JE Conquer.005AC618
---> changed into
005AC246 . E9 CD030000 JMP Conquer.005AC618
005AC24B 90 NOP
7
005AC716 . 0F8D B4000000 JGE Conquer.005AC7D0
---> changed into
005AC716 . E9 A8010000 JMP Conquer.005AC8C3
005AC71B 90 NOP
8
005B0D65 > FF15 7C418400 CALL DWORD PTR DS:[<&KERNEL32.IsDebugger>; [IsDebuggerPresent
---> changed into
005B0D65 > B8 00000000 MOV EAX,0
005B0D6A . 90 NOP
9
005B0FE8 . E8 53EA0300 CALL Conquer.005EFA40
---> changed into
005B0FE8 . 90 NOP
005B0FE9 . 90 NOP
005B0FEA . 90 NOP
005B0FEB . 90 NOP
005B0FEC . 90 NOP
10
005B101A . 75 29 JNZ SHORT Conquer.005B1045
---> changed into
005B101A . EB 29 JMP SHORT Conquer.005B1045
11
005B12B4 . 0F84 72020000 JE Conquer.005B152C
---> changed into
005B12B4 . E9 73020000 JMP Conquer.005B152C
005B12B9 90 NOP
12
005B1883 . 74 45 JE SHORT Conquer.005B18CA
---> changed into
005B1883 . EB 45 JMP SHORT Conquer.005B18CA
005B18B0 . 75 12 JNZ SHORT Conquer.005B18C4
---> changed into
005B18B0 . EB 12 JMP SHORT Conquer.005B18C4
13
005D630F . 0F8D 4B020000 JGE Conquer.005D6560
---> changed into
005D630F . 90 NOP
005D6310 . 90 NOP
005D6311 . 90 NOP
005D6312 . 90 NOP
005D6313 . 90 NOP
005D6314 . 90 NOP
14
005D6D60 > 68 44849300 PUSH Conquer.00938444 ; ASCII "http://co.91.com/signout/"
005D6D65 > 56 PUSH ESI
---> changed into
005D6D60 > 90 NOP
005D6D61 . 90 NOP
005D6D62 . 90 NOP
005D6D63 . 90 NOP
005D6D64 . 90 NOP
005D6D65 > 90 NOP
15 - remove website pop-up c.d.
005D6EBA > 68 24849300 PUSH Conquer.00938424 ; ASCII "http://conquete.91.com/signout/"
005D6EBF > 56 PUSH ESI ; |Operation
005D6EC0 . FF73 20 PUSH DWORD PTR DS:[EBX+20] ; |hWnd
005D6EC3 . FF15 C8498400 CALL DWORD PTR DS:[<&SHELL32.ShellExecut>; \ShellExecuteA
---> changed into
005D6EBA > 90 NOP
005D6EBB . 90 NOP
005D6EBC . 90 NOP
005D6EBD . 90 NOP
005D6EBE . 90 NOP
005D6EBF > 90 NOP
005D6EC0 . 90 NOP
005D6EC1 . 90 NOP
005D6EC2 . 90 NOP
005D6EC3 . 90 NOP
005D6EC4 . 90 NOP
005D6EC5 . 90 NOP
005D6EC6 . 90 NOP
005D6EC7 . 90 NOP
005D6EC8 . 90 NOP
16 - remove website pop-up c.d.
005D74D3 > 68 A4839300 PUSH Conquer.009383A4 ; ASCII "http://fetih.91.com/signout/"
005D74D8 > 56 PUSH ESI ; |Operation
005D74D9 . FF73 20 PUSH DWORD PTR DS:[EBX+20] ; |hWnd
005D74DC . FF15 C8498400 CALL DWORD PTR DS:[<&SHELL32.ShellExecut>; \ShellExecuteA
---> changed into
005D74D3 > 90 NOP
005D74D4 . 90 NOP
005D74D5 . 90 NOP
005D74D6 . 90 NOP
005D74D7 . 90 NOP
005D74D8 > 90 NOP
005D74D9 . 90 NOP
005D74DA . 90 NOP
005D74DB . 90 NOP
005D74DC . 90 NOP
005D74DD . 90 NOP
005D74DE . 90 NOP
005D74DF . 90 NOP
005D74E0 . 90 NOP
005D74E1 . 90 NOP
17 - remove website pop-up c.d.
005D7E99 > C705 616A056A >MOV DWORD PTR DS:[6A056A61],68006A00
005D7EA3 44849300 DD Conquer.00938444 ; ASCII "http://co.91.com/signout/"
005D7EA7 6A DB 6A ; CHAR 'j'
005D7EA8 00 DB 00
005D7EA9 8B DB 8B
005D7EAA 85 DB 85
005D7EAB 78 DB 78 ; CHAR 'x'
005D7EAC > FB STI
005D7EAD FF DB FF
005D7EAE FF DB FF
005D7EAF . FF70 20 PUSH DWORD PTR DS:[EAX+20] ; |hWnd
005D7EB2 . FF15 C8498400 CALL DWORD PTR DS:[<&SHELL32.ShellExecut>; \ShellExecuteA
---> changed into
005D7EA3 ? 90 NOP
005D7EA4 ? 90 NOP
005D7EA5 ? 90 NOP
005D7EA6 ? 90 NOP
005D7EA7 . 90 NOP
005D7EA8 . 90 NOP
005D7EA9 . 90 NOP
005D7EAA . 90 NOP
005D7EAB . 90 NOP
005D7EAC > 90 NOP
005D7EAD . 90 NOP
005D7EAE . 90 NOP
005D7EAF . 90 NOP
005D7EB0 . 90 NOP
005D7EB1 . 90 NOP
005D7EB2 . 90 NOP
005D7EB3 . 90 NOP
005D7EB4 . 90 NOP
005D7EB5 . 90 NOP
005D7EB6 . 90 NOP
005D7EB7 . 90 NOP
18
005EFB10 . 53 PUSH EBX
---> changed into
005EFB10 . C3 RETN
19
0065E96B . 7E 47 JLE SHORT Conquer.0065E9B4
---> changed into
0065E96B . EB 47 JMP SHORT Conquer.0065E9B4
20
0065F27D |. E8 709F0D00 CALL Conquer.007391F2
---> changed into
0065F27D |. 90 NOP
0065F27E |. 90 NOP
0065F27F |. 90 NOP
0065F280 |. 90 NOP
0065F281 |. 90 NOP
21
00719060 /$ B8 808D8300 MOV EAX,Conquer.00838D80
---> changed into
00719060 $ C3 RETN
00719061 90 NOP
00719062 90 NOP
00719063 90 NOP
00719064 90 NOP
22
00772404 . 53 PUSH EBX
---> changed into
00772404 . C3 RETN
23
007B6C00 . 53 PUSH EBX
---> changed into
007B6C00 . C3 RETN