A forum for reverse engineering, OS internals and malware analysis 

Discussion on reverse-engineering and debugging.
 #7398  by Flamef
 Tue Jul 19, 2011 5:44 am
So,i recently downloaded the "phantOm" plug-in for ollydbg,i extracted the contents(a phantom.dll) in the ollydbg folder,but it doesn't work.Ollydbg is working without this extension,any possible solution? :D

Thanks in advance
 #7399  by EP_X0FF
 Tue Jul 19, 2011 5:50 am
Which OS, type? Put it into plugins directory.
 #7407  by EP_X0FF
 Tue Jul 19, 2011 12:37 pm
Flamef wrote:Win 7 btw
It does not support Win7.
 #7414  by Flamef
 Tue Jul 19, 2011 1:41 pm
Can someone upload his ollydbg(entire) folder at mediafire(or any other site) and give me a download link to test at my virtual(xp)machine?If so i really appreciate it,thanks for the help so far guys.
Also i would like to ask,if i infect the virtual machine with a ransomware,and it locks my screen,after i reboot the computer the "infection" and the lock screen will be away?I am using win 7 virtual machine(Xp mode),i mean it deletes everything on reboot?
 #7416  by EP_X0FF
 Tue Jul 19, 2011 1:48 pm
Flamef wrote:Also i would like to ask,if i infect the virtual machine with a ransomware,and it locks my screen,after i reboot the computer the "infection" and the lock screen will be away?I am using win 7 virtual machine(Xp mode),i mean it deletes everything on reboot?
You need to configure it, to enable Undo disk, IDK how does it looks in XP Mode, but in Virtual PC 2007 this can be done through selecting required VM -> Action->Settings->Undo Disks. VM will create temporary image and if requested VM will rollback / save any changes you do.
 #7425  by Flamef
 Tue Jul 19, 2011 10:10 pm
EP_X0FF wrote:
Flamef wrote:Also i would like to ask,if i infect the virtual machine with a ransomware,and it locks my screen,after i reboot the computer the "infection" and the lock screen will be away?I am using win 7 virtual machine(Xp mode),i mean it deletes everything on reboot?
You need to configure it, to enable Undo disk, IDK how does it looks in XP Mode, but in Virtual PC 2007 this can be done through selecting required VM -> Action->Settings->Undo Disks. VM will create temporary image and if requested VM will rollback / save any changes you do.
Can you upload your Ollydbg folder for me? :mrgreen:
 #7455  by EP_X0FF
 Wed Jul 20, 2011 2:43 pm
Flamef wrote:
EP_X0FF wrote:
Flamef wrote:Also i would like to ask,if i infect the virtual machine with a ransomware,and it locks my screen,after i reboot the computer the "infection" and the lock screen will be away?I am using win 7 virtual machine(Xp mode),i mean it deletes everything on reboot?
You need to configure it, to enable Undo disk, IDK how does it looks in XP Mode, but in Virtual PC 2007 this can be done through selecting required VM -> Action->Settings->Undo Disks. VM will create temporary image and if requested VM will rollback / save any changes you do.
Can you upload your Ollydbg folder for me? :mrgreen:
http://tuts4you.com/download.php?view.2845

This will be enough for you to start, but it's bug fest. However I'm using my own version and can't upload it here.