Maze
May 1st, 2009, 11:17
I'm working on some malware that attaches to explorer and other programs via dlls.
I was able to work with them in the past via OllyDbg, but now I can't and I'm
not sure what changed.... has anyone ever run into this ??
YES, the files are there and permissions look good and the malware is running.
Log data
Address Message
OllyDbg v2.00 (intermediate version - under development!)
Attached to 'C:\WINDOWS\system32\notepad.exe'
New process (ID 00000EDC) created
Main thread (ID 00000EE0) created
7C94FFE3 New thread 2. (ID 00000FC8) created
01000000 Module C:\WINDOWS\system32\notepad.exe
3A220000 Module C:\WINDOWS\system32\ntobdis.dll << MALWARE
Unable to open executable file
5AD70000 Module C:\WINDOWS\system32\UxTheme.dll
5CB70000 Module C:\WINDOWS\system32\ShimEng.dll
6F880000 Module C:\WINDOWS\AppPatch\AcGenral.DLL
71AA0000 Module C:\WINDOWS\system32\WS2HELP.dll
....etc
Attached to 'C:\WINDOWS\Explorer.EXE'
New process (ID 00000638) created
Main thread (ID 0000063C) created
7C8106E9 New thread 2. (ID 00000648) created
7C8106E9 New thread 3. (ID 00000650) created
7C8106E9 New thread 4. (ID 00000658) created
7C8106E9 New thread 5. (ID 00000660) created
7C8106E9 New thread 6. (ID 00000730) created
7C8106E9 New thread 7. (ID 000007DC) created
7C8106E9 New thread 8. (ID 000007F8) created
7C8106E9 New thread 9. (ID 000000A8) created
7C8106E9 New thread 10. (ID 000000AC) created
7C8106E9 New thread 11. (ID 000000B0) created
7C8106E9 New thread 12. (ID 000000C4) created
7C8106E9 New thread 13. (ID 000000C8) created
7C8106E9 New thread 14. (ID 000000B8) created
7C8106E9 New thread 15. (ID 000000A4) created
7C8106E9 New thread 16. (ID 000000CC) created
7C8106E9 New thread 17. (ID 000000D0) created
7C8106E9 New thread 18. (ID 000000D8) created
7C8106E9 New thread 19. (ID 000000E0) created
7C8106E9 New thread 20. (ID 000000E4) created
7C8106E9 New thread 21. (ID 000000E8) created
7C8106E9 New thread 22. (ID 00000118) created
7C8106E9 New thread 23. (ID 00000128) created
7C8106E9 New thread 24. (ID 00000078) created
7C8106E9 New thread 25. (ID 00000440) created
7C8106E9 New thread 26. (ID 00000CEC) created
7C8106E9 New thread 27. (ID 00000ACC) created
7C94FFE3 New thread 28. (ID 00000B60) created
01000000 Module C:\WINDOWS\Explorer.EXE
00400000 Module C:\WINDOWS\system32\Normaliz.dll
01480000 Module C:\WINDOWS\system32\xpsp2res.dll
018A0000 Module C:\WINDOWS\system32\vmhgfs1.dll
02C20000 Module C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
10000000 Module C:\WINDOWS\system32\urlamnic\codihcat\rtfagdat.dll << MALWARE
Unable to open executable file
3A220000 Module C:\WINDOWS\system32\ntobdis.dll << MALWARE
Unable to open executable file
3E000000 Module C:\WINDOWS\system32\crtoxnet.dll << MALWARE
Unable to open executable file
42E40000 Module C:\WINDOWS\system32\webcheck.dll
42EF0000 Module C:\WINDOWS\system32\ieframe.dll
478C0000 Module C:\WINDOWS\system32\dot3api.dll
4D4F0000 Module C:\WINDOWS\system32\winhttp.dll
...etc
I was able to work with them in the past via OllyDbg, but now I can't and I'm
not sure what changed.... has anyone ever run into this ??
YES, the files are there and permissions look good and the malware is running.
Log data
Address Message
OllyDbg v2.00 (intermediate version - under development!)
Attached to 'C:\WINDOWS\system32\notepad.exe'
New process (ID 00000EDC) created
Main thread (ID 00000EE0) created
7C94FFE3 New thread 2. (ID 00000FC8) created
01000000 Module C:\WINDOWS\system32\notepad.exe
3A220000 Module C:\WINDOWS\system32\ntobdis.dll << MALWARE
Unable to open executable file
5AD70000 Module C:\WINDOWS\system32\UxTheme.dll
5CB70000 Module C:\WINDOWS\system32\ShimEng.dll
6F880000 Module C:\WINDOWS\AppPatch\AcGenral.DLL
71AA0000 Module C:\WINDOWS\system32\WS2HELP.dll
....etc
Attached to 'C:\WINDOWS\Explorer.EXE'
New process (ID 00000638) created
Main thread (ID 0000063C) created
7C8106E9 New thread 2. (ID 00000648) created
7C8106E9 New thread 3. (ID 00000650) created
7C8106E9 New thread 4. (ID 00000658) created
7C8106E9 New thread 5. (ID 00000660) created
7C8106E9 New thread 6. (ID 00000730) created
7C8106E9 New thread 7. (ID 000007DC) created
7C8106E9 New thread 8. (ID 000007F8) created
7C8106E9 New thread 9. (ID 000000A8) created
7C8106E9 New thread 10. (ID 000000AC) created
7C8106E9 New thread 11. (ID 000000B0) created
7C8106E9 New thread 12. (ID 000000C4) created
7C8106E9 New thread 13. (ID 000000C8) created
7C8106E9 New thread 14. (ID 000000B8) created
7C8106E9 New thread 15. (ID 000000A4) created
7C8106E9 New thread 16. (ID 000000CC) created
7C8106E9 New thread 17. (ID 000000D0) created
7C8106E9 New thread 18. (ID 000000D8) created
7C8106E9 New thread 19. (ID 000000E0) created
7C8106E9 New thread 20. (ID 000000E4) created
7C8106E9 New thread 21. (ID 000000E8) created
7C8106E9 New thread 22. (ID 00000118) created
7C8106E9 New thread 23. (ID 00000128) created
7C8106E9 New thread 24. (ID 00000078) created
7C8106E9 New thread 25. (ID 00000440) created
7C8106E9 New thread 26. (ID 00000CEC) created
7C8106E9 New thread 27. (ID 00000ACC) created
7C94FFE3 New thread 28. (ID 00000B60) created
01000000 Module C:\WINDOWS\Explorer.EXE
00400000 Module C:\WINDOWS\system32\Normaliz.dll
01480000 Module C:\WINDOWS\system32\xpsp2res.dll
018A0000 Module C:\WINDOWS\system32\vmhgfs1.dll
02C20000 Module C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\MSVCR80.dll
10000000 Module C:\WINDOWS\system32\urlamnic\codihcat\rtfagdat.dll << MALWARE
Unable to open executable file
3A220000 Module C:\WINDOWS\system32\ntobdis.dll << MALWARE
Unable to open executable file
3E000000 Module C:\WINDOWS\system32\crtoxnet.dll << MALWARE
Unable to open executable file
42E40000 Module C:\WINDOWS\system32\webcheck.dll
42EF0000 Module C:\WINDOWS\system32\ieframe.dll
478C0000 Module C:\WINDOWS\system32\dot3api.dll
4D4F0000 Module C:\WINDOWS\system32\winhttp.dll
...etc