|
// 文件名称: I:\新建文件夹\病毒样本\iexplore.exe
// 已创建 : 17.06.2008 23:41
// 类型 : 字符串列表
0040A020: 'http',0000h
0040A030: '&channel=',0
0040A040: '.google.',0
0040A04C: '&tn=',0
0040A054: '.baidu.',0
0040A05C: '.microsoft.',0
0040A068: 'text/html',0
0040A078: 'content-type',0
0040A088: '%smemtk.ini',0
0040A094: 'MAIN',0
0040A09C: '%Y-%m-%d',0
0040A0AC: '%Y,%m,%d,%H,%M,%S',0
0040A0C4: 'iexplore.exe',0
0040A0D4: 'Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_WEBOC_POPUPMANAGEMENT',0
0040A12C: '%s\%s',0
0040A134: '1809',0
0040A13C: 'SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones',0
0040A180: 'http://www.5isoo.com/software/pv/myconfig/default.htm',0
0040A1B8: '%stemp.ini',0
0040A1C4: '%stemp.exe',0
0040A1D0: 'USMSVC_CLICK555',0
0040A1E0: 'http://www.5isoo.com/software/pv/page/cl.asp?id=%s',0
0040A21C: 'http://www.5isoo.com/software/pv/page/ifap.asp?id=%s',0
0040A254: 'http://www.5isoo.com/software/pv/page/ifcl.asp?id=%s',0
0040A298: 'main',0
0040A2A0: 'thread',0
0040A2A8: 'http://www.5isoo.com/software/pv/ver11/adorder.htm',0
0040A2DC: '%sadorder.ini',0
0040A360: 'CWebBrowser2',0
0040A390: 'AD_PG',0
0040A3AC: 'HOME_PG',0
0040A3B4: 'START_PG',0
0040A3C0: 'mode',0
0040A3D4: 'crout',0
0040A3E4: 'subpg',0
0040A3EC: 'homepg',0
0040A3F4: 'http://www.baidu.com/s?lm=0&si=&rn=10&ie=gb2312&ct=0&wd=%s&pn=%ld&ver=0&cl=3',0
0040A444: 'http://www.google.cn/search?complete=1&hl=zh-CN&newwindow=1&q=%s&start=%ld&sa=N',0
0040A494: 'http',0
0040A49C: '<script language="JavaScript" type="text/javascript">var link = document.createElement("A");link.href = ',27h,'%s',27h,';link.innerText = ',27h,'%s',27h,';link.target = ',27h,'_blank',27h,';document.body.appendChild( link );</script>',0
0040A564: 'welcome!',0
附上它自己
[ 本帖最后由 molicn 于 2008-6-17 23:46 编辑 ] |
|