004019C8  Hardware breakpoint 1 at Malware.004019C8
          Analysing Malware
            3 heuristical procedures
            24 calls to known functions
            2 loops
004019C2  CALL to memcpy from Malware.0040136C
            dest = 10000000
            src = Malware.00403044
            n = 1120 (4384.)
004019C2  Breakpoint at Malware.004019C2
004019C2  CALL to memcpy from Malware.00401466
            dest = 10036000
            src = Malware.00403444
            n = 14400 (82944.)
004019C2  Breakpoint at Malware.004019C2
004019C2  CALL to memcpy from Malware.00401466
            dest = 1004B000
            src = Malware.00417844
            n = 1000 (4096.)
004019C2  Breakpoint at Malware.004019C2
76B20000  Module C:\WINDOWS\system32\ATL.DLL
76D60000  Module C:\WINDOWS\system32\iphlpapi.dll
71AB0000  Module C:\WINDOWS\system32\WS2_32.dll
71AA0000  Module C:\WINDOWS\system32\WS2HELP.dll
774E0000  Module C:\WINDOWS\system32\ole32.dll
77120000  Module C:\WINDOWS\system32\OLEAUT32.dll
7C9C0000  Module C:\WINDOWS\system32\SHELL32.dll
77F60000  Module C:\WINDOWS\system32\SHLWAPI.dll
773D0000  Module C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll
76EB0000  Module C:\WINDOWS\system32\TAPI32.dll
76E80000  Module C:\WINDOWS\system32\rtutils.dll
76B40000  Module C:\WINDOWS\system32\WINMM.dll
7E1E0000  Module C:\WINDOWS\system32\urlmon.dll
77C00000  Module C:\WINDOWS\system32\VERSION.dll
771B0000  Module C:\WINDOWS\system32\WININET.dll
77A80000  Module C:\WINDOWS\system32\CRYPT32.dll
004019A2  Hardware breakpoint 2 at Malware.004019A2
10025D27  Hardware breakpoint 3 at 10025D27
          OllyDump -- Start "JMP [Thunk]"(0x25FF) and "CALL [Thunk]"(0x15FF) search
          OllyDump -- Import Table
10027000  DLL:ADVAPI32.dll  FirstThunkRVA:27000
            DLL Name      Address   Ordinal   API Name
10027000    ADVAPI32.dll  77DDECD5   01D4     RegDeleteValueA
10027004    ADVAPI32.dll  77DD6C17   01CB     RegCloseKey
10027008    ADVAPI32.dll  77DDE9E4   01CF     RegCreateKeyExA
1002700C    ADVAPI32.dll  77DD797B   01AB     OpenProcessToken
10027010    ADVAPI32.dll  77DD7842   01E5     RegOpenKeyExA
10027014    ADVAPI32.dll  77DD7AAB   01EF     RegQueryValueExA
10027018    ADVAPI32.dll  77DDEAD7   01FC     RegSetValueExA
1002701C    ADVAPI32.dll  77DE4280   01D2     RegDeleteKeyA
10027020    ADVAPI32.dll  77DE5196   01D9     RegEnumKeyExA
10027024    ADVAPI32.dll  77DE4312   01EA     RegQueryInfoKeyA
10027028    ADVAPI32.dll  77DDEFFC   001E     AdjustTokenPrivileges
1002702C    ADVAPI32.dll  77DFC208   014E     LookupPrivilegeValueA
10027034  DLL:ATL.DLL  FirstThunkRVA:27034
            DLL Name      Address   Ordinal   API Name
10027034    ATL.DLL       76B2376F   002F     AtlAxGetControl
10027038    ATL.DLL       76B299D0   002A     AtlAxWinInit
10027040  DLL:COMCTL32.dll  FirstThunkRVA:27040
            DLL Name      Address   Ordinal   API Name
10027040    COMCTL32.dll  5D0965CF   0011     InitCommonControls
10027048  DLL:GDI32.dll  FirstThunkRVA:27048
            DLL Name      Address   Ordinal   API Name
10027048    GDI32.dll     77F3BC60   003A     CreateFontA
1002704C    GDI32.dll     77F1D3EA   00DE     ExtTextOutA
10027050    GDI32.dll     77F15E29   0217     SetBkColor
10027054    GDI32.dll     77F15D77   023E     SetTextColor
10027058    GDI32.dll     77F16BFA   0090     DeleteObject
1002705C    GDI32.dll     77F161A5   0051     CreateSolidBrush
10027064  DLL:kernel32.dll  FirstThunkRVA:27064
            DLL Name      Address   Ordinal   API Name
10027064    kernel32.dll  7C810C1E   030A     SetFilePointer
10027068    kernel32.dll  7C80A045   024A     LoadResource
1002706C    kernel32.dll  7C80BCF9   0342     SizeofResource
10027070    kernel32.dll  7C80CD27   0258     LockResource
10027074    kernel32.dll  7C80BF19   00E0     FindResourceA
10027078    kernel32.dll  7C813869   00D1     FindFirstFileA
1002707C    kernel32.dll  7C834EC9   00DA     FindNextFileA
10027080    kernel32.dll  7C865B1F   0070     CreateToolhelp32Snapshot
10027084    kernel32.dll  7C864DF5   0288     Process32First
10027088    kernel32.dll  7C864F68   028A     Process32Next
1002708C    kernel32.dll  7C8099B0   013D     GetCurrentProcessId
10027090    kernel32.dll  7C8104BC   0068     CreateRemoteThread
10027094    kernel32.dll  7C8021D0   02AA     ReadProcessMemory
10027098    kernel32.dll  7C802213   0399     WriteProcessMemory
1002709C    kernel32.dll  7C802530   037F     WaitForSingleObject
100270A0    kernel32.dll  7C82141D   0154     GetExitCodeThread
100270A4    kernel32.dll  7C809B74   0372     VirtualFree
100270A8    kernel32.dll  7C809AE1   036F     VirtualAlloc
100270AC    kernel32.dll  7C835EA7   0261     MoveFileA
100270B0    kernel32.dll  7C835DE2   01CC     GetTempPathA
100270B4    kernel32.dll  7C861807   01CA     GetTempFileNameA
100270B8    kernel32.dll  7C812B6E   01DF     GetVersionExA
100270BC    kernel32.dll  7C80BB31   03AE     lstrcmpi
100270C0    kernel32.dll  7C8309D1   0278     OpenProcess
100270C4    kernel32.dll  7C830BAB   01F0     GlobalDeleteAtom
100270C8    kernel32.dll  7C8360DB   01F1     GlobalFindAtomA
100270CC    kernel32.dll  7C8360C1   01EC     GlobalAddAtomA
100270D0    kernel32.dll  7C85AC7C   027F     OutputDebugStringA
100270D4    kernel32.dll  7C80FDBD   01EE     GlobalAlloc
100270D8    kernel32.dll  7C80FCBF   01F5     GlobalFree
100270DC    kernel32.dll  7C8325D4   0254     LocalSize
100270E0    kernel32.dll  7C809A1D   024B     LocalAlloc
100270E4    kernel32.dll  7C830917   0252     LocalReAlloc
100270E8    kernel32.dll  7C81CAFA   00B7     ExitProcess
100270EC    kernel32.dll  7C901000   0097     EnterCriticalSection
100270F0    kernel32.dll  7C9010E0   0244     LeaveCriticalSection
100270F4    kernel32.dll  7C91135A   0080     DeleteCriticalSection
100270F8    kernel32.dll  7C809F81   0219     InitializeCriticalSection
100270FC    kernel32.dll  7C8099BF   024F     LocalFree
10027100    kernel32.dll  7C80A164   0383     WideCharToMultiByte
10027104    kernel32.dll  7C809E91   0228     IsBadReadPtr
10027108    kernel32.dll  7C8286D6   0040     CopyFileA
1002710C    kernel32.dll  7C831EC5   0082     DeleteFileA
10027110    kernel32.dll  7C80E9CF   005D     CreateMutexA
10027114    kernel32.dll  7C8024B7   02B4     ReleaseMutex
10027118    kernel32.dll  7C821794   0048     CreateDirectoryA
1002711C    kernel32.dll  7C814F7A   01BA     GetSystemDirectoryA
10027120    kernel32.dll  7C82134B   01E9     GetWindowsDirectoryA
10027124    kernel32.dll  7C90FE01   0169     GetLastError
10027128    kernel32.dll  7C80B55F   0175     GetModuleFileNameA
1002712C    kernel32.dll  7C8106C7   006D     CreateThread
10027130    kernel32.dll  7C80236B   0063     CreateProcessA
10027134    kernel32.dll  7C801A28   0050     CreateFileA
10027138    kernel32.dll  7C810B07   015C     GetFileSize
1002713C    kernel32.dll  7C801812   02A7     ReadFile
10027140    kernel32.dll  7C80BE91   03B1     lstrcpy
10027144    kernel32.dll  7C834D59   03A8     lstrcat
10027148    kernel32.dll  7C8101A1   03B4     lstrcpyn
1002714C    kernel32.dll  7C80BE46   03B7     lstrlen
10027150    kernel32.dll  7C802446   0343     Sleep
10027154    kernel32.dll  7C809C88   0268     MultiByteToWideChar
10027158    kernel32.dll  7C8097F6   0221     InterlockedIncrement
1002715C    kernel32.dll  7C80980A   021D     InterlockedDecrement
10027160    kernel32.dll  7C90FE10   02C2     RestoreLastError
10027164    kernel32.dll  7C801AD4   0375     VirtualProtect
10027168    kernel32.dll  7C80DE85   013C     GetCurrentProcess
1002716C    kernel32.dll  7C80AC6E   00F1     FreeLibrary
10027170    kernel32.dll  7C80AE30   0199     GetProcAddress
10027174    kernel32.dll  7C801D7B   0245     LoadLibraryA
10027178    kernel32.dll  7C80B731   0177     GetModuleHandleA
1002717C    kernel32.dll  7C830D64   03AB     lstrcmp
10027180    kernel32.dll  7C80932E   01D5     GetTickCount
10027184    kernel32.dll  7C809BD7   0032     CloseHandle
10027188    kernel32.dll  7C81CB23   034C     TerminateThread
1002718C    kernel32.dll  7C810E17   0390     WriteFile
10027190    kernel32.dll  7C801E1A   034B     TerminateProcess
10027198  DLL:MSVCRT.dll  FirstThunkRVA:27198
            DLL Name      Address   Ordinal   API Name
10027198    MSVCRT.dll    77C623D8   00B7     _adjust_fdiv
1002719C    MSVCRT.dll    77C2C407   02D9     malloc
100271A0    MSVCRT.dll    77C39D67   013C     _initterm
100271A4    MSVCRT.dll    77C34DF8   01B5     _onexit
100271A8    MSVCRT.dll    77C34E51   006C     __dllonexit
100271AC    MSVCRT.dll    77C2C0C3   0288     calloc
100271B0    MSVCRT.dll    77C4FA30   0119     _ftol
100271B4    MSVCRT.dll    77C4D1C0   02E5     pow
100271B8    MSVCRT.dll    77C47660   02FF     strchr
100271BC    MSVCRT.dll    77C47BE0   030B     strrchr
100271C0    MSVCRT.dll    77C41B72   02FD     sscanf
100271C4    MSVCRT.dll    77C4139C   02AA     fseek
100271C8    MSVCRT.dll    77C41574   02AC     ftell
100271CC    MSVCRT.dll    77C40BB1   029A     fgets
100271D0    MSVCRT.dll    77C46320   01FB     _strlwr
100271D4    MSVCRT.dll    77C3F010   029F     fopen
100271D8    MSVCRT.dll    77C411FB   02A5     fread
100271DC    MSVCRT.dll    77C40AB1   0294     fclose
100271E0    MSVCRT.dll    77C4173B   02AE     fwrite
100271E4    MSVCRT.dll    77C36D02   02B2     getenv
100271E8    MSVCRT.dll    77C1CF90   0284     atof
100271EC    MSVCRT.dll    77C315E8   017D     _mbclen
100271F0    MSVCRT.dll    77C31E1D   0193     _mbsnbcmp
100271F4    MSVCRT.dll    77C30C6B   0150     _ismbcdigit
100271F8    MSVCRT.dll    77C3FE49   0324     vsprintf
100271FC    MSVCRT.dll    77C32903   01A5     _mbsrchr
10027200    MSVCRT.dll    77C32BB0   01AA     _mbsstr
10027204    MSVCRT.dll    77C21868   0010     ??1type_info@@UAE@XZ
10027208    MSVCRT.dll    77C31C3E   018F     _mbsinc
1002720C    MSVCRT.dll    77C317FF   0186     _mbschr
10027210    MSVCRT.dll    77C472B0   02E0     memmove
10027214    MSVCRT.dll    77C2C21B   02A6     free
10027218    MSVCRT.dll    77C2C437   02EF     realloc
1002721C    MSVCRT.dll    77C1BE7B   0286     atol
10027220    MSVCRT.dll    77C47A50   0308     strncmp
10027224    MSVCRT.dll    77C31881   0187     _mbscmp
10027228    MSVCRT.dll    77C47A90   0309     strncpy
1002722C    MSVCRT.dll    77C4AECF   0318     time
10027230    MSVCRT.dll    77C371BC   02FC     srand
10027234    MSVCRT.dll    77C371D3   02EE     rand
10027238    MSVCRT.dll    77C3F931   02FA     sprintf
1002723C    MSVCRT.dll    77C31CBA   0191     _mbslwr
10027240    MSVCRT.dll    77C1BF18   0285     atoi
10027244    MSVCRT.dll    77C36BD0   027D     abs
10027248    MSVCRT.dll    77C478A0   0306     strlen
1002724C    MSVCRT.dll    77C3FA76   01E3     _snprintf
10027250    MSVCRT.dll    77C35F0D   01C2     _purecall
10027254    MSVCRT.dll    77C46EB0   02DE     memcmp
10027258    MSVCRT.dll    77C47730   0300     strcmp
1002725C    MSVCRT.dll    77C35C94   00EE     _except_handler3
10027260    MSVCRT.dll    77C46030   0189     _mbscpy
10027264    MSVCRT.dll    77C46040   0185     _mbscat
10027268    MSVCRT.dll    77C46F70   02DF     memcpy
1002726C    MSVCRT.dll    77C47C60   030D     strstr
10027270    MSVCRT.dll    77C29CC5   0011     ??2@YAPAXI@Z
10027274    MSVCRT.dll    77C47FCC   032E     wcslen
10027278    MSVCRT.dll    77C29CDD   0012     ??3@YAXPAX@Z
1002727C    MSVCRT.dll    77C226F6   0049     _CxxThrowException
10027280    MSVCRT.dll    77C3EC4B   0102     _fileno
10027284    MSVCRT.dll    77C2D8E2   0100     _filelength
10027288    MSVCRT.dll    77C1C222   0174     _ltoa
1002728C    MSVCRT.dll    77C46665   0205     _strupr
10027290    MSVCRT.dll    77C4624E   01F5     _strcmpi
10027294    MSVCRT.dll    77C1C1F3   0161     _itoa
10027298    MSVCRT.dll    77C475F0   02E1     memset
100272A0  DLL:OLEAUT32.dll  FirstThunkRVA:272A0
            DLL Name      Address   Ordinal   API Name
100272A0    OLEAUT32.dll  77124880   0006     SysFreeString
100272A4    OLEAUT32.dll  771248F0   0009     VariantClear
100272A8    OLEAUT32.dll  77124BA2   0002     SysAllocString
100272AC    OLEAUT32.dll  77124C35   0096     SysAllocStringByteLen
100272B0    OLEAUT32.dll  77124C1B   0007     SysStringLen
100272B4    OLEAUT32.dll  77124950   0008     VariantInit
100272B8    OLEAUT32.dll  77124CFD   000A     VariantCopy
100272BC    OLEAUT32.dll  77126BBB   000C     VariantChangeType
100272C0    OLEAUT32.dll  77124B39   0004     SysAllocStringLen
100272C8  DLL:SHELL32.dll  FirstThunkRVA:272C8
            DLL Name      Address   Ordinal   API Name
100272C8    SHELL32.dll   7CA24909   0113     SHChangeNotify
100272CC    SHELL32.dll   7CA221D6   016D     Shell_NotifyIcon
100272D0    SHELL32.dll   7CA41150   0167     ShellExecuteA
100272D8  DLL:SHLWAPI.dll  FirstThunkRVA:272D8
            DLL Name      Address   Ordinal   API Name
100272D8    SHLWAPI.dll   77FA4980   033B     StrTrimA
100272E0  DLL:TAPI32.dll  FirstThunkRVA:272E0
            DLL Name      Address   Ordinal   API Name
100272E0    TAPI32.dll    76EBFF3D   008C     lineInitialize
100272E4    TAPI32.dll    76EBA378   0095     lineNegotiateAPIVersion
100272E8    TAPI32.dll    76EBA600   0098     lineOpenA
100272EC    TAPI32.dll    76EB9765   0078     lineGetNewCalls
100272F0    TAPI32.dll    76EB874C   005F     lineGetCallInfoA
100272F4    TAPI32.dll    76EC013F   00D1     lineShutdown
100272FC  DLL:USER32.dll  FirstThunkRVA:272FC
            DLL Name      Address   Ordinal   API Name
100272FC    USER32.dll    7E4242ED   0258     SetForegroundWindow
10027300    USER32.dll    7E42AF56   0293     ShowWindow
10027304    USER32.dll    7E42D1D2   010F     GetDesktopWindow
10027308    USER32.dll    7E42E4A9   0061     CreateWindowExA
1002730C    USER32.dll    7E418A80   017C     GetWindowThreadProcessId
10027310    USER32.dll    7E42AAFD   0200     PostMessageA
10027314    USER32.dll    7E431211   028B     SetWindowsHookExA
10027318    USER32.dll    7E46670B   0276     SetSystemCursor
1002731C    USER32.dll    7E42DC14   004A     CopyImage
10027320    USER32.dll    7E41DE72   0049     CopyIcon
10027324    USER32.dll    7E42D33E   01B8     LoadCursorA
10027328    USER32.dll    7E42F25B   0164     GetTopWindow
1002732C    USER32.dll    7E455F7F   0045     CloseWindow
10027330    USER32.dll    7E419689   01EB     MsgWaitForMultipleObjects
10027334    USER32.dll    7E43C972   0254     SetDlgItemTextA
10027338    USER32.dll    7E46B05E   0114     GetDlgItemTextA
1002733C    USER32.dll    7E429313   01AC     IsWindow
10027340    USER32.dll    7E42C7F9   0267     SetParent
10027344    USER32.dll    7E418F9C   015E     GetSystemMetrics
10027348    USER32.dll    7E42436E   0112     GetDlgItem
1002734C    USER32.dll    7E4290B4   0175     GetWindowRect
10027350    USER32.dll    7E42E8F6   01BC     LoadIconA
10027354    USER32.dll    7E42F3C2   023C     SendMessageA
10027358    USER32.dll    7E43B144   009F     DialogBoxParamA
1002735C    USER32.dll    7E424A4E   00C7     EndDialog
10027360    USER32.dll    7E41945D   016F     GetWindowLongA
10027364    USER32.dll    7E42C29D   0281     SetWindowLongA
10027368    USER32.dll    7E42B29E   01EA     MoveWindow
1002736C    USER32.dll    7E42A340   01FE     PeekMessageA
10027370    USER32.dll    7E418BF6   02AB     TranslateMessage
10027374    USER32.dll    7E429849   00C5     EnableWindow
10027378    USER32.dll    7E42F56B   0287     SetWindowTextA
1002737C    USER32.dll    7E43E940   00B6     DrawFrameControl
10027380    USER32.dll    7E43216B   0178     GetWindowTextA
10027384    USER32.dll    7E43C702   00BD     DrawTextA
10027388    USER32.dll    7E42908E   0100     GetClientRect
1002738C    USER32.dll    7E429C2F   00E3     FillRect
10027390    USER32.dll    7E428717   0027     CharLowerA
10027394    USER32.dll    7E4196B8   00A2     DispatchMessageA
10027398    USER32.dll    7E41AE3F   0036     CharUpperBuffA
1002739C    USER32.dll    7E42B222   015D     GetSystemMenu
100273A0    USER32.dll    7E42D2C4   00C3     EnableMenuItem
100273A4    USER32.dll    7E44F69C   00B9     DrawMenuBar
100273A8    USER32.dll    7E418C2E   027B     SetTimer
100273AC    USER32.dll    7E418C42   01B3     KillTimer
100273B0    USER32.dll    7E429823   0118     GetForegroundWindow
100273B4    USER32.dll    7E4507EA   01DD     MessageBoxA
100273B8    USER32.dll    7E428845   0028     CharLowerBuffA
100273BC    USER32.dll    7E4299F3   0284     SetWindowPos
100273C0    USER32.dll    7E42772B   013B     GetMessageA
100273C4    USER32.dll    7E42B3C6   001B     CallNextHookEx
100273C8    USER32.dll    7E42F45F   00FD     GetClassNameA
100273CC    USER32.dll    7E42A5AE   00DF     EnumWindows
100273D0    USER32.dll    7E42D5F3   02AF     UnhookWindowsHookEx
100273D4    USER32.dll    7E4282E1   00E4     FindWindowA
100273DC  DLL:WININET.dll  FirstThunkRVA:273DC
            DLL Name      Address   Ordinal   API Name
100273DC    WININET.dll   771D5C4E   00F6     InternetGetConnectedState
100273E0    WININET.dll   771D1AF9   00B5     GetUrlCacheEntryInfoA
100273E4    WININET.dll   771C33BE   00DA     InternetCanonicalizeUrlA
100273EC  DLL:iphlpapi.dll  FirstThunkRVA:273EC
            DLL Name      Address   Ordinal   API Name
100273EC    iphlpapi.dll  76D663EF   0029     GetIfEntry
100273F0    iphlpapi.dll  76D66051   001C     GetAdaptersInfo
100273F8  DLL

le32.dll  FirstThunkRVA:273F8
            DLL Name      Address   Ordinal   API Name
100273F8    ole32.dll     77556EC6   0047     CoMarshalInterThreadInterfaceInStream
100273FC    ole32.dll     774FEE46   006A     CoUninitialize
10027400    ole32.dll     7750057E   0012     CoCreateInstance
10027404    ole32.dll     77517E90   0051     CoRegisterClassObject
10027408    ole32.dll     7752A2F3   005D     CoRevokeClassObject
1002740C    ole32.dll     77502A53   003C     CoInitialize
10027410    ole32.dll     77556DD6   002F     CoGetInterfaceAndReleaseStream
10027418  DLL:urlmon.dll  FirstThunkRVA:27418
            DLL Name      Address   Ordinal   API Name
10027418    urlmon.dll    7E1ED381   0081     CreateURLMoniker
1002741C    urlmon.dll    7E23BED5   00B0     URLOpenBlockingStreamA
          OllyDump -- Calculating New File Size...
          New Import Section Size:1400  New File Size:44E00
          OllyDump -- Making New Import Table...
          OllyDump -- Dump and Rebuild Finish!!
End of session