<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Hunting for Bugs, but Found a Worm</title><link>http://blogs.msdn.com/b/ntdebugging/archive/2011/01/07/hunting-for-bugs-but-found-a-worm.aspx</link><description>Hi All, my name is Ron Riddle and I&amp;rsquo;m an Escalation Engineer on the core Windows team. I worked an issue recently wherein a svchost.exe was crashing due to heap corruption; so, after enabling Page Heap and breaking out the services as needed, I</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Hunting for Bugs, but Found a Worm</title><link>http://blogs.msdn.com/b/ntdebugging/archive/2011/01/07/hunting-for-bugs-but-found-a-worm.aspx#10322710</link><pubDate>Thu, 21 Jun 2012 18:51:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10322710</guid><dc:creator>Dave Black</dc:creator><description>&lt;p&gt;Hi Ron,&lt;/p&gt;
&lt;p&gt;Thanks for the post. Could you please clarify your statement in #3 - &amp;quot;By now, I am suspicious of a rogue module&amp;quot;.&lt;/p&gt;
&lt;p&gt;What did you discover in #1 and #2 that would lead you to have this suspicion?&lt;/p&gt;
&lt;p&gt;Thanks for your time.&lt;/p&gt;
&lt;p&gt;[My suspicion was based on the following facts:&amp;nbsp;&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Malware authors often conceal rogue modules by removing them from the Loaded Modules list.&lt;/li&gt;
&lt;li&gt;The debugger could not map the virtual address to any module within the Loaded&lt;br /&gt;Modules list.&lt;/li&gt;
&lt;li&gt;The page was marked as PAGE_EXECUTE_READWRITE, which means it&amp;rsquo;s a code address.&amp;nbsp;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Of course I realize that virtual machines environments also store executable code on one of the heaps, so the above observations are certainly not a dead giveaway, but they are enough to start formulating theories.]&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10322710" width="1" height="1"&gt;</description></item><item><title>re: Hunting for Bugs, but Found a Worm</title><link>http://blogs.msdn.com/b/ntdebugging/archive/2011/01/07/hunting-for-bugs-but-found-a-worm.aspx#10113426</link><pubDate>Sun, 09 Jan 2011 08:35:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10113426</guid><dc:creator>Miro</dc:creator><description>&lt;p&gt;Nice article Ron, thanks for this! An for the rest of GES guys, please post more frequently! :)&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10113426" width="1" height="1"&gt;</description></item><item><title>re: Hunting for Bugs, but Found a Worm</title><link>http://blogs.msdn.com/b/ntdebugging/archive/2011/01/07/hunting-for-bugs-but-found-a-worm.aspx#10113296</link><pubDate>Sat, 08 Jan 2011 14:18:29 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10113296</guid><dc:creator>Paulo Oliveira</dc:creator><description>&lt;p&gt;Great stuff Ron!! Thanks for sharing!!&lt;/p&gt;
&lt;p&gt;Regards,&lt;/p&gt;
&lt;p&gt;Paulo Oliveira.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10113296" width="1" height="1"&gt;</description></item><item><title>re: Hunting for Bugs, but Found a Worm</title><link>http://blogs.msdn.com/b/ntdebugging/archive/2011/01/07/hunting-for-bugs-but-found-a-worm.aspx#10113249</link><pubDate>Sat, 08 Jan 2011 05:48:59 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10113249</guid><dc:creator>Bob Dobbs</dc:creator><description>&lt;p&gt;That was totally intuitive. I&amp;#39;m so glad Microsoft Windows is easy to use.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10113249" width="1" height="1"&gt;</description></item><item><title>re: Hunting for Bugs, but Found a Worm</title><link>http://blogs.msdn.com/b/ntdebugging/archive/2011/01/07/hunting-for-bugs-but-found-a-worm.aspx#10113230</link><pubDate>Sat, 08 Jan 2011 02:50:28 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:10113230</guid><dc:creator>Felix</dc:creator><description>&lt;p&gt;Thanks for the post! Very interesting stuff.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=10113230" width="1" height="1"&gt;</description></item></channel></rss>