004019C8 Hardware breakpoint 1 at Malware.004019C8
Analysing Malware
3 heuristical procedures
24 calls to known functions
2 loops
004019C2 CALL to memcpy from Malware.0040136C
dest = 10000000
src = Malware.00403044
n = 1120 (4384.)
004019C2 Breakpoint at Malware.004019C2
004019C2 CALL to memcpy from Malware.00401466
dest = 10036000
src = Malware.00403444
n = 14400 (82944.)
004019C2 Breakpoint at Malware.004019C2
004019C2 CALL to memcpy from Malware.00401466
dest = 1004B000
src = Malware.00417844
n = 1000 (4096.)
004019C2 Breakpoint at Malware.004019C2
76B20000 Module C:\WINDOWS\system32\ATL.DLL
76D60000 Module C:\WINDOWS\system32\iphlpapi.dll
71AB0000 Module C:\WINDOWS\system32\WS2_32.dll
71AA0000 Module C:\WINDOWS\system32\WS2HELP.dll
774E0000 Module C:\WINDOWS\system32\ole32.dll
77120000 Module C:\WINDOWS\system32\OLEAUT32.dll
7C9C0000 Module C:\WINDOWS\system32\SHELL32.dll
77F60000 Module C:\WINDOWS\system32\SHLWAPI.dll
773D0000 Module C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
76EB0000 Module C:\WINDOWS\system32\TAPI32.dll
76E80000 Module C:\WINDOWS\system32\rtutils.dll
76B40000 Module C:\WINDOWS\system32\WINMM.dll
7E1E0000 Module C:\WINDOWS\system32\urlmon.dll
77C00000 Module C:\WINDOWS\system32\VERSION.dll
771B0000 Module C:\WINDOWS\system32\WININET.dll
77A80000 Module C:\WINDOWS\system32\CRYPT32.dll
004019A2 Hardware breakpoint 2 at Malware.004019A2
10025D27 Hardware breakpoint 3 at 10025D27
OllyDump -- Start "JMP [Thunk]"(0x25FF) and "CALL [Thunk]"(0x15FF) search
OllyDump -- Import Table
10027000 DLL:ADVAPI32.dll FirstThunkRVA:27000
DLL Name Address Ordinal API Name
10027000 ADVAPI32.dll 77DDECD5 01D4 RegDeleteValueA
10027004 ADVAPI32.dll 77DD6C17 01CB RegCloseKey
10027008 ADVAPI32.dll 77DDE9E4 01CF RegCreateKeyExA
1002700C ADVAPI32.dll 77DD797B 01AB OpenProcessToken
10027010 ADVAPI32.dll 77DD7842 01E5 RegOpenKeyExA
10027014 ADVAPI32.dll 77DD7AAB 01EF RegQueryValueExA
10027018 ADVAPI32.dll 77DDEAD7 01FC RegSetValueExA
1002701C ADVAPI32.dll 77DE4280 01D2 RegDeleteKeyA
10027020 ADVAPI32.dll 77DE5196 01D9 RegEnumKeyExA
10027024 ADVAPI32.dll 77DE4312 01EA RegQueryInfoKeyA
10027028 ADVAPI32.dll 77DDEFFC 001E AdjustTokenPrivileges
1002702C ADVAPI32.dll 77DFC208 014E LookupPrivilegeValueA
10027034 DLL:ATL.DLL FirstThunkRVA:27034
DLL Name Address Ordinal API Name
10027034 ATL.DLL 76B2376F 002F AtlAxGetControl
10027038 ATL.DLL 76B299D0 002A AtlAxWinInit
10027040 DLL:COMCTL32.dll FirstThunkRVA:27040
DLL Name Address Ordinal API Name
10027040 COMCTL32.dll 5D0965CF 0011 InitCommonControls
10027048 DLL:GDI32.dll FirstThunkRVA:27048
DLL Name Address Ordinal API Name
10027048 GDI32.dll 77F3BC60 003A CreateFontA
1002704C GDI32.dll 77F1D3EA 00DE ExtTextOutA
10027050 GDI32.dll 77F15E29 0217 SetBkColor
10027054 GDI32.dll 77F15D77 023E SetTextColor
10027058 GDI32.dll 77F16BFA 0090 DeleteObject
1002705C GDI32.dll 77F161A5 0051 CreateSolidBrush
10027064 DLL:kernel32.dll FirstThunkRVA:27064
DLL Name Address Ordinal API Name
10027064 kernel32.dll 7C810C1E 030A SetFilePointer
10027068 kernel32.dll 7C80A045 024A LoadResource
1002706C kernel32.dll 7C80BCF9 0342 SizeofResource
10027070 kernel32.dll 7C80CD27 0258 LockResource
10027074 kernel32.dll 7C80BF19 00E0 FindResourceA
10027078 kernel32.dll 7C813869 00D1 FindFirstFileA
1002707C kernel32.dll 7C834EC9 00DA FindNextFileA
10027080 kernel32.dll 7C865B1F 0070 CreateToolhelp32Snapshot
10027084 kernel32.dll 7C864DF5 0288 Process32First
10027088 kernel32.dll 7C864F68 028A Process32Next
1002708C kernel32.dll 7C8099B0 013D GetCurrentProcessId
10027090 kernel32.dll 7C8104BC 0068 CreateRemoteThread
10027094 kernel32.dll 7C8021D0 02AA ReadProcessMemory
10027098 kernel32.dll 7C802213 0399 WriteProcessMemory
1002709C kernel32.dll 7C802530 037F WaitForSingleObject
100270A0 kernel32.dll 7C82141D 0154 GetExitCodeThread
100270A4 kernel32.dll 7C809B74 0372 VirtualFree
100270A8 kernel32.dll 7C809AE1 036F VirtualAlloc
100270AC kernel32.dll 7C835EA7 0261 MoveFileA
100270B0 kernel32.dll 7C835DE2 01CC GetTempPathA
100270B4 kernel32.dll 7C861807 01CA GetTempFileNameA
100270B8 kernel32.dll 7C812B6E 01DF GetVersionExA
100270BC kernel32.dll 7C80BB31 03AE lstrcmpi
100270C0 kernel32.dll 7C8309D1 0278 OpenProcess
100270C4 kernel32.dll 7C830BAB 01F0 GlobalDeleteAtom
100270C8 kernel32.dll 7C8360DB 01F1 GlobalFindAtomA
100270CC kernel32.dll 7C8360C1 01EC GlobalAddAtomA
100270D0 kernel32.dll 7C85AC7C 027F OutputDebugStringA
100270D4 kernel32.dll 7C80FDBD 01EE GlobalAlloc
100270D8 kernel32.dll 7C80FCBF 01F5 GlobalFree
100270DC kernel32.dll 7C8325D4 0254 LocalSize
100270E0 kernel32.dll 7C809A1D 024B LocalAlloc
100270E4 kernel32.dll 7C830917 0252 LocalReAlloc
100270E8 kernel32.dll 7C81CAFA 00B7 ExitProcess
100270EC kernel32.dll 7C901000 0097 EnterCriticalSection
100270F0 kernel32.dll 7C9010E0 0244 LeaveCriticalSection
100270F4 kernel32.dll 7C91135A 0080 DeleteCriticalSection
100270F8 kernel32.dll 7C809F81 0219 InitializeCriticalSection
100270FC kernel32.dll 7C8099BF 024F LocalFree
10027100 kernel32.dll 7C80A164 0383 WideCharToMultiByte
10027104 kernel32.dll 7C809E91 0228 IsBadReadPtr
10027108 kernel32.dll 7C8286D6 0040 CopyFileA
1002710C kernel32.dll 7C831EC5 0082 DeleteFileA
10027110 kernel32.dll 7C80E9CF 005D CreateMutexA
10027114 kernel32.dll 7C8024B7 02B4 ReleaseMutex
10027118 kernel32.dll 7C821794 0048 CreateDirectoryA
1002711C kernel32.dll 7C814F7A 01BA GetSystemDirectoryA
10027120 kernel32.dll 7C82134B 01E9 GetWindowsDirectoryA
10027124 kernel32.dll 7C90FE01 0169 GetLastError
10027128 kernel32.dll 7C80B55F 0175 GetModuleFileNameA
1002712C kernel32.dll 7C8106C7 006D CreateThread
10027130 kernel32.dll 7C80236B 0063 CreateProcessA
10027134 kernel32.dll 7C801A28 0050 CreateFileA
10027138 kernel32.dll 7C810B07 015C GetFileSize
1002713C kernel32.dll 7C801812 02A7 ReadFile
10027140 kernel32.dll 7C80BE91 03B1 lstrcpy
10027144 kernel32.dll 7C834D59 03A8 lstrcat
10027148 kernel32.dll 7C8101A1 03B4 lstrcpyn
1002714C kernel32.dll 7C80BE46 03B7 lstrlen
10027150 kernel32.dll 7C802446 0343 Sleep
10027154 kernel32.dll 7C809C88 0268 MultiByteToWideChar
10027158 kernel32.dll 7C8097F6 0221 InterlockedIncrement
1002715C kernel32.dll 7C80980A 021D InterlockedDecrement
10027160 kernel32.dll 7C90FE10 02C2 RestoreLastError
10027164 kernel32.dll 7C801AD4 0375 VirtualProtect
10027168 kernel32.dll 7C80DE85 013C GetCurrentProcess
1002716C kernel32.dll 7C80AC6E 00F1 FreeLibrary
10027170 kernel32.dll 7C80AE30 0199 GetProcAddress
10027174 kernel32.dll 7C801D7B 0245 LoadLibraryA
10027178 kernel32.dll 7C80B731 0177 GetModuleHandleA
1002717C kernel32.dll 7C830D64 03AB lstrcmp
10027180 kernel32.dll 7C80932E 01D5 GetTickCount
10027184 kernel32.dll 7C809BD7 0032 CloseHandle
10027188 kernel32.dll 7C81CB23 034C TerminateThread
1002718C kernel32.dll 7C810E17 0390 WriteFile
10027190 kernel32.dll 7C801E1A 034B TerminateProcess
10027198 DLL:MSVCRT.dll FirstThunkRVA:27198
DLL Name Address Ordinal API Name
10027198 MSVCRT.dll 77C623D8 00B7 _adjust_fdiv
1002719C MSVCRT.dll 77C2C407 02D9 malloc
100271A0 MSVCRT.dll 77C39D67 013C _initterm
100271A4 MSVCRT.dll 77C34DF8 01B5 _onexit
100271A8 MSVCRT.dll 77C34E51 006C __dllonexit
100271AC MSVCRT.dll 77C2C0C3 0288 calloc
100271B0 MSVCRT.dll 77C4FA30 0119 _ftol
100271B4 MSVCRT.dll 77C4D1C0 02E5 pow
100271B8 MSVCRT.dll 77C47660 02FF strchr
100271BC MSVCRT.dll 77C47BE0 030B strrchr
100271C0 MSVCRT.dll 77C41B72 02FD sscanf
100271C4 MSVCRT.dll 77C4139C 02AA fseek
100271C8 MSVCRT.dll 77C41574 02AC ftell
100271CC MSVCRT.dll 77C40BB1 029A fgets
100271D0 MSVCRT.dll 77C46320 01FB _strlwr
100271D4 MSVCRT.dll 77C3F010 029F fopen
100271D8 MSVCRT.dll 77C411FB 02A5 fread
100271DC MSVCRT.dll 77C40AB1 0294 fclose
100271E0 MSVCRT.dll 77C4173B 02AE fwrite
100271E4 MSVCRT.dll 77C36D02 02B2 getenv
100271E8 MSVCRT.dll 77C1CF90 0284 atof
100271EC MSVCRT.dll 77C315E8 017D _mbclen
100271F0 MSVCRT.dll 77C31E1D 0193 _mbsnbcmp
100271F4 MSVCRT.dll 77C30C6B 0150 _ismbcdigit
100271F8 MSVCRT.dll 77C3FE49 0324 vsprintf
100271FC MSVCRT.dll 77C32903 01A5 _mbsrchr
10027200 MSVCRT.dll 77C32BB0 01AA _mbsstr
10027204 MSVCRT.dll 77C21868 0010 ??1type_info@@UAE@XZ
10027208 MSVCRT.dll 77C31C3E 018F _mbsinc
1002720C MSVCRT.dll 77C317FF 0186 _mbschr
10027210 MSVCRT.dll 77C472B0 02E0 memmove
10027214 MSVCRT.dll 77C2C21B 02A6 free
10027218 MSVCRT.dll 77C2C437 02EF realloc
1002721C MSVCRT.dll 77C1BE7B 0286 atol
10027220 MSVCRT.dll 77C47A50 0308 strncmp
10027224 MSVCRT.dll 77C31881 0187 _mbscmp
10027228 MSVCRT.dll 77C47A90 0309 strncpy
1002722C MSVCRT.dll 77C4AECF 0318 time
10027230 MSVCRT.dll 77C371BC 02FC srand
10027234 MSVCRT.dll 77C371D3 02EE rand
10027238 MSVCRT.dll 77C3F931 02FA sprintf
1002723C MSVCRT.dll 77C31CBA 0191 _mbslwr
10027240 MSVCRT.dll 77C1BF18 0285 atoi
10027244 MSVCRT.dll 77C36BD0 027D abs
10027248 MSVCRT.dll 77C478A0 0306 strlen
1002724C MSVCRT.dll 77C3FA76 01E3 _snprintf
10027250 MSVCRT.dll 77C35F0D 01C2 _purecall
10027254 MSVCRT.dll 77C46EB0 02DE memcmp
10027258 MSVCRT.dll 77C47730 0300 strcmp
1002725C MSVCRT.dll 77C35C94 00EE _except_handler3
10027260 MSVCRT.dll 77C46030 0189 _mbscpy
10027264 MSVCRT.dll 77C46040 0185 _mbscat
10027268 MSVCRT.dll 77C46F70 02DF memcpy
1002726C MSVCRT.dll 77C47C60 030D strstr
10027270 MSVCRT.dll 77C29CC5 0011 ??2@YAPAXI@Z
10027274 MSVCRT.dll 77C47FCC 032E wcslen
10027278 MSVCRT.dll 77C29CDD 0012 ??3@YAXPAX@Z
1002727C MSVCRT.dll 77C226F6 0049 _CxxThrowException
10027280 MSVCRT.dll 77C3EC4B 0102 _fileno
10027284 MSVCRT.dll 77C2D8E2 0100 _filelength
10027288 MSVCRT.dll 77C1C222 0174 _ltoa
1002728C MSVCRT.dll 77C46665 0205 _strupr
10027290 MSVCRT.dll 77C4624E 01F5 _strcmpi
10027294 MSVCRT.dll 77C1C1F3 0161 _itoa
10027298 MSVCRT.dll 77C475F0 02E1 memset
100272A0 DLL:OLEAUT32.dll FirstThunkRVA:272A0
DLL Name Address Ordinal API Name
100272A0 OLEAUT32.dll 77124880 0006 SysFreeString
100272A4 OLEAUT32.dll 771248F0 0009 VariantClear
100272A8 OLEAUT32.dll 77124BA2 0002 SysAllocString
100272AC OLEAUT32.dll 77124C35 0096 SysAllocStringByteLen
100272B0 OLEAUT32.dll 77124C1B 0007 SysStringLen
100272B4 OLEAUT32.dll 77124950 0008 VariantInit
100272B8 OLEAUT32.dll 77124CFD 000A VariantCopy
100272BC OLEAUT32.dll 77126BBB 000C VariantChangeType
100272C0 OLEAUT32.dll 77124B39 0004 SysAllocStringLen
100272C8 DLL:SHELL32.dll FirstThunkRVA:272C8
DLL Name Address Ordinal API Name
100272C8 SHELL32.dll 7CA24909 0113 SHChangeNotify
100272CC SHELL32.dll 7CA221D6 016D Shell_NotifyIcon
100272D0 SHELL32.dll 7CA41150 0167 ShellExecuteA
100272D8 DLL:SHLWAPI.dll FirstThunkRVA:272D8
DLL Name Address Ordinal API Name
100272D8 SHLWAPI.dll 77FA4980 033B StrTrimA
100272E0 DLL:TAPI32.dll FirstThunkRVA:272E0
DLL Name Address Ordinal API Name
100272E0 TAPI32.dll 76EBFF3D 008C lineInitialize
100272E4 TAPI32.dll 76EBA378 0095 lineNegotiateAPIVersion
100272E8 TAPI32.dll 76EBA600 0098 lineOpenA
100272EC TAPI32.dll 76EB9765 0078 lineGetNewCalls
100272F0 TAPI32.dll 76EB874C 005F lineGetCallInfoA
100272F4 TAPI32.dll 76EC013F 00D1 lineShutdown
100272FC DLL:USER32.dll FirstThunkRVA:272FC
DLL Name Address Ordinal API Name
100272FC USER32.dll 7E4242ED 0258 SetForegroundWindow
10027300 USER32.dll 7E42AF56 0293 ShowWindow
10027304 USER32.dll 7E42D1D2 010F GetDesktopWindow
10027308 USER32.dll 7E42E4A9 0061 CreateWindowExA
1002730C USER32.dll 7E418A80 017C GetWindowThreadProcessId
10027310 USER32.dll 7E42AAFD 0200 PostMessageA
10027314 USER32.dll 7E431211 028B SetWindowsHookExA
10027318 USER32.dll 7E46670B 0276 SetSystemCursor
1002731C USER32.dll 7E42DC14 004A CopyImage
10027320 USER32.dll 7E41DE72 0049 CopyIcon
10027324 USER32.dll 7E42D33E 01B8 LoadCursorA
10027328 USER32.dll 7E42F25B 0164 GetTopWindow
1002732C USER32.dll 7E455F7F 0045 CloseWindow
10027330 USER32.dll 7E419689 01EB MsgWaitForMultipleObjects
10027334 USER32.dll 7E43C972 0254 SetDlgItemTextA
10027338 USER32.dll 7E46B05E 0114 GetDlgItemTextA
1002733C USER32.dll 7E429313 01AC IsWindow
10027340 USER32.dll 7E42C7F9 0267 SetParent
10027344 USER32.dll 7E418F9C 015E GetSystemMetrics
10027348 USER32.dll 7E42436E 0112 GetDlgItem
1002734C USER32.dll 7E4290B4 0175 GetWindowRect
10027350 USER32.dll 7E42E8F6 01BC LoadIconA
10027354 USER32.dll 7E42F3C2 023C SendMessageA
10027358 USER32.dll 7E43B144 009F DialogBoxParamA
1002735C USER32.dll 7E424A4E 00C7 EndDialog
10027360 USER32.dll 7E41945D 016F GetWindowLongA
10027364 USER32.dll 7E42C29D 0281 SetWindowLongA
10027368 USER32.dll 7E42B29E 01EA MoveWindow
1002736C USER32.dll 7E42A340 01FE PeekMessageA
10027370 USER32.dll 7E418BF6 02AB TranslateMessage
10027374 USER32.dll 7E429849 00C5 EnableWindow
10027378 USER32.dll 7E42F56B 0287 SetWindowTextA
1002737C USER32.dll 7E43E940 00B6 DrawFrameControl
10027380 USER32.dll 7E43216B 0178 GetWindowTextA
10027384 USER32.dll 7E43C702 00BD DrawTextA
10027388 USER32.dll 7E42908E 0100 GetClientRect
1002738C USER32.dll 7E429C2F 00E3 FillRect
10027390 USER32.dll 7E428717 0027 CharLowerA
10027394 USER32.dll 7E4196B8 00A2 DispatchMessageA
10027398 USER32.dll 7E41AE3F 0036 CharUpperBuffA
1002739C USER32.dll 7E42B222 015D GetSystemMenu
100273A0 USER32.dll 7E42D2C4 00C3 EnableMenuItem
100273A4 USER32.dll 7E44F69C 00B9 DrawMenuBar
100273A8 USER32.dll 7E418C2E 027B SetTimer
100273AC USER32.dll 7E418C42 01B3 KillTimer
100273B0 USER32.dll 7E429823 0118 GetForegroundWindow
100273B4 USER32.dll 7E4507EA 01DD MessageBoxA
100273B8 USER32.dll 7E428845 0028 CharLowerBuffA
100273BC USER32.dll 7E4299F3 0284 SetWindowPos
100273C0 USER32.dll 7E42772B 013B GetMessageA
100273C4 USER32.dll 7E42B3C6 001B CallNextHookEx
100273C8 USER32.dll 7E42F45F 00FD GetClassNameA
100273CC USER32.dll 7E42A5AE 00DF EnumWindows
100273D0 USER32.dll 7E42D5F3 02AF UnhookWindowsHookEx
100273D4 USER32.dll 7E4282E1 00E4 FindWindowA
100273DC DLL:WININET.dll FirstThunkRVA:273DC
DLL Name Address Ordinal API Name
100273DC WININET.dll 771D5C4E 00F6 InternetGetConnectedState
100273E0 WININET.dll 771D1AF9 00B5 GetUrlCacheEntryInfoA
100273E4 WININET.dll 771C33BE 00DA InternetCanonicalizeUrlA
100273EC DLL:iphlpapi.dll FirstThunkRVA:273EC
DLL Name Address Ordinal API Name
100273EC iphlpapi.dll 76D663EF 0029 GetIfEntry
100273F0 iphlpapi.dll 76D66051 001C GetAdaptersInfo
100273F8 DLL

le32.dll FirstThunkRVA:273F8
DLL Name Address Ordinal API Name
100273F8 ole32.dll 77556EC6 0047 CoMarshalInterThreadInterfaceInStream
100273FC ole32.dll 774FEE46 006A CoUninitialize
10027400 ole32.dll 7750057E 0012 CoCreateInstance
10027404 ole32.dll 77517E90 0051 CoRegisterClassObject
10027408 ole32.dll 7752A2F3 005D CoRevokeClassObject
1002740C ole32.dll 77502A53 003C CoInitialize
10027410 ole32.dll 77556DD6 002F CoGetInterfaceAndReleaseStream
10027418 DLL:urlmon.dll FirstThunkRVA:27418
DLL Name Address Ordinal API Name
10027418 urlmon.dll 7E1ED381 0081 CreateURLMoniker
1002741C urlmon.dll 7E23BED5 00B0 URLOpenBlockingStreamA
OllyDump -- Calculating New File Size...
New Import Section Size:1400 New File Size:44E00
OllyDump -- Making New Import Table...
OllyDump -- Dump and Rebuild Finish!!
End of session