Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Process: iexplore.exe Pid: 580 Address: 0x1e40000
- Vad Tag: VadS Protection: PAGE_EXECUTE_READWRITE
- Flags: CommitCharge: 2, MemCommit: 1, PrivateMemory: 1, Protection: 6
- 0x01e40000 b0 00 eb 70 b0 01 eb 6c b0 02 eb 68 b0 03 eb 64 ...p...l...h...d
- 0x01e40010 b0 04 eb 60 b0 05 eb 5c b0 06 eb 58 b0 07 eb 54 ...`...\...X...T
- 0x01e40020 b0 08 eb 50 b0 09 eb 4c b0 0a eb 48 b0 0b eb 44 ...P...L...H...D
- 0x01e40030 b0 0c eb 40 b0 0d eb 3c b0 0e eb 38 b0 0f eb 34 ...@...<...8...4
- 0x1e40000 b000 MOV AL, 0x0
- 0x1e40002 eb70 JMP 0x1e40074
- 0x1e40004 b001 MOV AL, 0x1
- 0x1e40006 eb6c JMP 0x1e40074
- 0x1e40008 b002 MOV AL, 0x2
- 0x1e4000a eb68 JMP 0x1e40074
- 0x1e4000c b003 MOV AL, 0x3
- 0x1e4000e eb64 JMP 0x1e40074
- 0x1e40010 b004 MOV AL, 0x4
- 0x1e40012 eb60 JMP 0x1e40074
- 0x1e40014 b005 MOV AL, 0x5
- 0x1e40016 eb5c JMP 0x1e40074
- 0x1e40018 b006 MOV AL, 0x6
- 0x1e4001a eb58 JMP 0x1e40074
- 0x1e4001c b007 MOV AL, 0x7
- 0x1e4001e eb54 JMP 0x1e40074
- 0x1e40020 b008 MOV AL, 0x8
- 0x1e40022 eb50 JMP 0x1e40074
- 0x1e40024 b009 MOV AL, 0x9
- 0x1e40026 eb4c JMP 0x1e40074
- 0x1e40028 b00a MOV AL, 0xa
- 0x1e4002a eb48 JMP 0x1e40074
- 0x1e4002c b00b MOV AL, 0xb
- 0x1e4002e eb44 JMP 0x1e40074
- 0x1e40030 b00c MOV AL, 0xc
- 0x1e40032 eb40 JMP 0x1e40074
- 0x1e40034 b00d MOV AL, 0xd
- 0x1e40036 eb3c JMP 0x1e40074
- 0x1e40038 b00e MOV AL, 0xe
- 0x1e4003a eb38 JMP 0x1e40074
- 0x1e4003c b00f MOV AL, 0xf
- 0x1e4003e eb34 JMP 0x1e40074
- Process: iexplore.exe Pid: 580 Address: 0x3970000
- Vad Tag: VadS Protection: PAGE_EXECUTE_READWRITE
- Flags: CommitCharge: 1, MemCommit: 1, PrivateMemory: 1, Protection: 6
- 0x03970000 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
- 0x03970010 00 00 97 03 00 00 00 00 00 00 00 00 00 00 00 00 ................
- 0x03970020 10 00 97 03 00 00 00 00 00 00 00 00 00 00 00 00 ................
- 0x03970030 20 00 97 03 00 00 00 00 00 00 00 00 00 00 00 00 ................
- 0x3970000 0000 ADD [EAX], AL
- 0x3970002 0000 ADD [EAX], AL
- 0x3970004 0000 ADD [EAX], AL
- 0x3970006 0000 ADD [EAX], AL
- 0x3970008 0000 ADD [EAX], AL
- 0x397000a 0000 ADD [EAX], AL
- 0x397000c 0000 ADD [EAX], AL
- 0x397000e 0000 ADD [EAX], AL
- 0x3970010 0000 ADD [EAX], AL
- 0x3970012 97 XCHG EDI, EAX
- 0x3970013 0300 ADD EAX, [EAX]
- 0x3970015 0000 ADD [EAX], AL
- 0x3970017 0000 ADD [EAX], AL
- 0x3970019 0000 ADD [EAX], AL
- 0x397001b 0000 ADD [EAX], AL
- 0x397001d 0000 ADD [EAX], AL
- 0x397001f 0010 ADD [EAX], DL
- 0x3970021 009703000000 ADD [EDI+0x3], DL
- 0x3970027 0000 ADD [EAX], AL
- 0x3970029 0000 ADD [EAX], AL
- 0x397002b 0000 ADD [EAX], AL
- 0x397002d 0000 ADD [EAX], AL
- 0x397002f 0020 ADD [EAX], AH
- 0x3970031 009703000000 ADD [EDI+0x3], DL
- 0x3970037 0000 ADD [EAX], AL
- 0x3970039 0000 ADD [EAX], AL
- 0x397003b 0000 ADD [EAX], AL
- 0x397003d 0000 ADD [EAX], AL
- 0x397003f 00 DB 0x0
- Process: iexplore.exe Pid: 580 Address: 0x5fff0000
- Vad Tag: VadS Protection: PAGE_EXECUTE_READWRITE
- Flags: CommitCharge: 16, MemCommit: 1, PrivateMemory: 1, Protection: 6
- 0x5fff0000 64 74 72 52 00 00 00 00 00 02 ff 5f 00 00 00 00 dtrR......._....
- 0x5fff0010 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
- 0x5fff0020 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
- 0x5fff0030 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
- 0x5fff0000 647472 JZ 0x5fff0075
- 0x5fff0003 52 PUSH EDX
- 0x5fff0004 0000 ADD [EAX], AL
- 0x5fff0006 0000 ADD [EAX], AL
- 0x5fff0008 0002 ADD [EDX], AL
- 0x5fff000a ff5f00 CALL FAR DWORD [EDI+0x0]
- 0x5fff000d 0000 ADD [EAX], AL
- 0x5fff000f 0000 ADD [EAX], AL
- 0x5fff0011 0000 ADD [EAX], AL
- 0x5fff0013 0000 ADD [EAX], AL
- 0x5fff0015 0000 ADD [EAX], AL
- 0x5fff0017 0000 ADD [EAX], AL
- 0x5fff0019 0000 ADD [EAX], AL
- 0x5fff001b 0000 ADD [EAX], AL
- 0x5fff001d 0000 ADD [EAX], AL
- 0x5fff001f 0000 ADD [EAX], AL
- 0x5fff0021 0000 ADD [EAX], AL
- 0x5fff0023 0000 ADD [EAX], AL
- 0x5fff0025 0000 ADD [EAX], AL
- 0x5fff0027 0000 ADD [EAX], AL
- 0x5fff0029 0000 ADD [EAX], AL
- 0x5fff002b 0000 ADD [EAX], AL
- 0x5fff002d 0000 ADD [EAX], AL
- 0x5fff002f 0000 ADD [EAX], AL
- 0x5fff0031 0000 ADD [EAX], AL
- 0x5fff0033 0000 ADD [EAX], AL
- 0x5fff0035 0000 ADD [EAX], AL
- 0x5fff0037 0000 ADD [EAX], AL
- 0x5fff0039 0000 ADD [EAX], AL
- 0x5fff003b 0000 ADD [EAX], AL
- 0x5fff003d 0000 ADD [EAX], AL
- 0x5fff003f 00 DB 0x0
Advertisement
Add Comment
Please, Sign In to add comment