Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » looking at a virus in ollydbg
Search Topic:
Uniqs:
395
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
Security Software Updates - 04 Nov 2008 »
« Dedicated ant-trojan list that is current?  
AuthorAll Replies


jubii

@rogers.com

looking at a virus in ollydbg

I found a .dll that I think is a virus. I loaded it into ollydbg so I could try to look at referenced strings and api calls.

My understanding is that this is probably harmless unless I actually hit F9 to RUN, or step through the code so that something can execute.. That ollydbg simply analyzes the file, displays the disassembled code, then stops at the first instruction before any code has a chance to execute.

Is that correct?

Or have I accidentally gone and made sure the virus was able to execute now? :-(


koma3504
Advocate
Premium
join:2004-06-22
North Richland Hills, TX
upload it the dll to »virusscan.jotti.org/ and »www.virustotal.com/ to see what they see.


jubii

@rogers.com

reply to jubii
Thanks, I did, almost half found something. :/

After more research, apparently when you load a .dll in ollydbg, the .dll start up code executes before the break point.

As I have no idea what exactly the start up code for the .dll does, I'm just going to assume it fully activated the virus, to err on the side of caution, and start looking through removal steps to see if I can find any hint of it.

cdavfrew

join:2008-06-29

reply to jubii
Ollydbg is good for looking at malware, but I prefer sandboxes. CWSandbox is great for determining whether something is malware, because it tells me what files, registry entries, and networking activity the file creates or changes. This way, you can see what the file did to your system.

If you could upload the file to www.uploadmalware.com, this will give it to antivirus labs to study, so that if it is malware, your current antivirus will detect it and remove it.

Best Regards
-
Forums » Up and Running » Security » SecuritySecurity Software Updates - 04 Nov 2008 »
« Dedicated ant-trojan list that is current?  


Tuesday, 24-Nov 20:52:42 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [100] New AT&T Ad Campaign Hits Back At Verizon
· [84] New Bill Takes Aim At Higher Verizon ETFs
· [69] Apple Joins AT&T Verizon Snark Fest
· [39] In-Flight Internet Headed For Bumpy Landing?
· [32] Senators Want ACTA Made Public
· [30] Earthlink Suffers From Major E-mail Outage
· [30] AT&T Offers New Prepaid Wireless plans
· [28] Frontier Increases Modem Rental Fee
· [16] Vivendi In Way Of Comcast's NBC Desires
· [15] Charter Still Fighting With Creditors
Most people now reading
· Mysterious $800 Cash Deposit? [General Questions]
· [Rant] Damn Sermons through my speakers! [Rants, Raves, and Praise]
· Windows 7 boot manager editing questions [Microsoft Help]
· "ISP owners could face jail under child porn bill" - CBC [Canadian Broadband]
· Climate Change Scandal Erupts After Email Hack. [Security]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Several MS Updates today (11/24/2009). [Security]
· What to use while demonoid is down? [Filesharing Software]
· hawaii in thanksgiving [General Questions]