View Single Post
  #12  
Old May 6th, 2009, 06:53 AM
Bonksie's Avatar
Bonksie Bonksie is offline
Senior Member
 
Join Date: Jun 2004
O/S: Windows XP Home
Location: The Netherlands
Posts: 100
Gmer part 4

.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!GetStartupInfoW 7C7D1E54 5 Bytes JMP 00AC009D
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!GetStartupInfoA 7C7D1EF2 5 Bytes JMP 00AC0F55
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateProcessW 7C7D2336 5 Bytes JMP 100039A0
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateProcessA 7C7D236B 5 Bytes JMP 00AC0F33
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!GetProcAddress 7C7DAE40 5 Bytes JMP 00AC00DD
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!LoadLibraryW 7C7DAEEB 5 Bytes JMP 00AC0FA5
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateFileW 7C7E0800 5 Bytes JMP 00AC001B
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreatePipe 7C7ED83F 5 Bytes JMP 00AC0F72
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateNamedPipeW 7C7FF0DD 5 Bytes JMP 00AC0FDB
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateNamedPipeA 7C830CDC 5 Bytes JMP 00AC002C
.text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!WinExec 7C83250D 5 Bytes JMP 00AC0F44
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExW 77F46AAF 5 Bytes JMP 00860FC3
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExW 77F4776C 5 Bytes JMP 00860062
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyExA 77F47852 5 Bytes JMP 00860FD4
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyW 77F47946 5 Bytes JMP 0086000A
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyExA 77F4E9F4 5 Bytes JMP 00860051
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegOpenKeyA 77F4EFC8 5 Bytes JMP 00860FEF
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyW 77F6BA55 5 Bytes JMP 00860040
.text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!RegCreateKeyA 77F6BCF3 5 Bytes JMP 0086002F
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00850FB7
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00850FC8
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00850FE3
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00850000
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00850038
.text C:\WINDOWS\system32\svchost.exe[1268] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00850011
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!socket 71A34211 5 Bytes JMP 00840000
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!connect 71A34A07 5 Bytes JMP 100038CC
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!send 71A34C27 5 Bytes JMP 10003004
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!WSARecv 71A34CB5 5 Bytes JMP 10002734
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!recv 71A3676F 5 Bytes JMP 100026AC
.text C:\WINDOWS\system32\svchost.exe[1268] ws2_32.dll!WSASend 71A368FA 5 Bytes JMP 10003894
.text C:\WINDOWS\system32\svchost.exe[1268] wininet.dll!InternetOpenA 445EC865 5 Bytes JMP 00830000
.text C:\WINDOWS\system32\svchost.exe[1268] wininet.dll!InternetOpenW 445ECE99 5 Bytes JMP 00830025
.text C:\WINDOWS\system32\svchost.exe[1268] wininet.dll!InternetOpenUrlA 445F0BCA 5 Bytes JMP 00830FEF
.text C:\WINDOWS\system32\svchost.exe[1268] wininet.dll!InternetOpenUrlW 4463AF69 5 Bytes JMP 00830040
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!CreateFileA 7C7D1A28 5 Bytes JMP 00980FEF
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!VirtualProtectEx 7C7D1A61 5 Bytes JMP 00980F57
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!VirtualProtect 7C7D1AD4 5 Bytes JMP 00980F72
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!LoadLibraryExW 7C7D1AF5 5 Bytes JMP 00980040
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!LoadLibraryExA 7C7D1D53 5 Bytes JMP 00980F83
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!LoadLibraryA 7C7D1D7B 5 Bytes JMP 00980FAF
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!GetStartupInfoW 7C7D1E54 5 Bytes JMP 00980F3A
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!GetStartupInfoA 7C7D1EF2 5 Bytes JMP 00980082
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!CreateProcessW 7C7D2336 5 Bytes JMP 100039A0
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!CreateProcessA 7C7D236B 5 Bytes JMP 00980F29
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!GetProcAddress 7C7DAE40 5 Bytes JMP 00980EF3
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!LoadLibraryW 7C7DAEEB 5 Bytes JMP 00980F94
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!CreateFileW 7C7E0800 5 Bytes JMP 0098000A
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!CreatePipe 7C7ED83F 5 Bytes JMP 00980067
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!CreateNamedPipeW 7C7FF0DD 5 Bytes JMP 00980FCA
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!CreateNamedPipeA 7C830CDC 5 Bytes JMP 0098001B
.text C:\WINDOWS\System32\svchost.exe[1400] kernel32.dll!WinExec 7C83250D 5 Bytes JMP 009800A7
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExW 77F46AAF 5 Bytes JMP 0097002C
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExW 77F4776C 5 Bytes JMP 00970F8A
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyExA 77F47852 5 Bytes JMP 00970FDB
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyW 77F47946 5 Bytes JMP 00970011
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyExA 77F4E9F4 5 Bytes JMP 00970051
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegOpenKeyA 77F4EFC8 5 Bytes JMP 00970000
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW 77F6BA55 2 Bytes JMP 00970FA5
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyW + 3 77F6BA58 2 Bytes [A0, 88]
.text C:\WINDOWS\System32\svchost.exe[1400] ADVAPI32.dll!RegCreateKeyA 77F6BCF3 5 Bytes JMP 00970FB6
.text C:\WINDOWS\System32\svchost.exe[1400] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00960FAD
.text C:\WINDOWS\System32\svchost.exe[1400] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00960042
.text C:\WINDOWS\System32\svchost.exe[1400] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00960FC8
.text C:\WINDOWS\System32\svchost.exe[1400] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00960FEF
.text C:\WINDOWS\System32\svchost.exe[1400] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00960027
.text C:\WINDOWS\System32\svchost.exe[1400] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00960000
.text C:\WINDOWS\System32\svchost.exe[1400] ws2_32.dll!socket 71A34211 5 Bytes JMP 00950FEF
.text C:\WINDOWS\System32\svchost.exe[1400] ws2_32.dll!connect 71A34A07 5 Bytes JMP 100038CC
.text C:\WINDOWS\System32\svchost.exe[1400] ws2_32.dll!send 71A34C27 5 Bytes JMP 10003004
.text C:\WINDOWS\System32\svchost.exe[1400] ws2_32.dll!WSARecv 71A34CB5 5 Bytes JMP 10002734
.text C:\WINDOWS\System32\svchost.exe[1400] ws2_32.dll!recv 71A3676F 5 Bytes JMP 100026AC
.text C:\WINDOWS\System32\svchost.exe[1400] ws2_32.dll!WSASend 71A368FA 5 Bytes JMP 10003894
.text C:\WINDOWS\System32\svchost.exe[1400] wininet.dll!InternetOpenA 445EC865 5 Bytes JMP 00940FEF
.text C:\WINDOWS\System32\svchost.exe[1400] wininet.dll!InternetOpenW 445ECE99 5 Bytes JMP 0094000A
.text C:\WINDOWS\System32\svchost.exe[1400] wininet.dll!InternetOpenUrlA 445F0BCA 5 Bytes JMP 00940FCA
.text C:\WINDOWS\System32\svchost.exe[1400] wininet.dll!InternetOpenUrlW 4463AF69 5 Bytes JMP 00940025
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreateFileA 7C7D1A28 5 Bytes JMP 010A0FE5
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!VirtualProtectEx 7C7D1A61 5 Bytes JMP 010A0F5F
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!VirtualProtect 7C7D1AD4 5 Bytes JMP 010A0054
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!LoadLibraryExW 7C7D1AF5 5 Bytes JMP 010A0F7C
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!LoadLibraryExA 7C7D1D53 5 Bytes JMP 010A0039
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!LoadLibraryA 7C7D1D7B 5 Bytes JMP 010A0FB2
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!GetStartupInfoW 7C7D1E54 5 Bytes JMP 010A0F3A
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!GetStartupInfoA 7C7D1EF2 5 Bytes JMP 010A008C
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreateProcessW 7C7D2336 5 Bytes JMP 100039A0
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreateProcessA 7C7D236B 5 Bytes JMP 010A0F18
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!GetProcAddress 7C7DAE40 5 Bytes JMP 010A00C2
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!LoadLibraryW 7C7DAEEB 5 Bytes JMP 010A0F97
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreateFileW 7C7E0800 3 Bytes JMP 010A0000
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreateFileW + 4 7C7E0804 1 Byte [84]
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreatePipe 7C7ED83F 3 Bytes JMP 010A006F
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreatePipe + 4 7C7ED843 1 Byte [84]
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreateNamedPipeW 7C7FF0DD 5 Bytes JMP 010A0FC3
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!CreateNamedPipeA 7C830CDC 5 Bytes JMP 010A0FD4
.text C:\WINDOWS\System32\svchost.exe[1424] kernel32.dll!WinExec 7C83250D 5 Bytes JMP 010A0F29
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegOpenKeyExW 77F46AAF 5 Bytes JMP 01090FC3
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegCreateKeyExW 77F4776C 5 Bytes JMP 0109006F
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegOpenKeyExA 77F47852 5 Bytes JMP 01090FD4
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegOpenKeyW 77F47946 5 Bytes JMP 01090FE5
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegCreateKeyExA 77F4E9F4 5 Bytes JMP 01090054
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegOpenKeyA 77F4EFC8 5 Bytes JMP 01090000
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegCreateKeyW 77F6BA55 2 Bytes JMP 01090FB2
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegCreateKeyW + 3 77F6BA58 2 Bytes [12, 89]
.text C:\WINDOWS\System32\svchost.exe[1424] ADVAPI32.dll!RegCreateKeyA 77F6BCF3 5 Bytes JMP 0109002F
.text C:\WINDOWS\System32\svchost.exe[1424] msvcrt.dll!_wsystem 77BF931E 5 Bytes JMP 00FF0036
.text C:\WINDOWS\System32\svchost.exe[1424] msvcrt.dll!system 77BF93C7 5 Bytes JMP 00FF0FAB
.text C:\WINDOWS\System32\svchost.exe[1424] msvcrt.dll!_creat 77BFD40F 5 Bytes JMP 00FF0FC6
.text C:\WINDOWS\System32\svchost.exe[1424] msvcrt.dll!_open 77BFF566 5 Bytes JMP 00FF0000
.text C:\WINDOWS\System32\svchost.exe[1424] msvcrt.dll!_wcreat 77BFFC9B 5 Bytes JMP 00FF001B
.text C:\WINDOWS\System32\svchost.exe[1424] msvcrt.dll!_wopen 77C00055 5 Bytes JMP 00FF0FD7
.text C:\WINDOWS\System32\svchost.exe[1424] ws2_32.dll!socket 71A34211 5 Bytes JMP 00FE0FE5
.text C:\WINDOWS\System32\svchost.exe[1424] ws2_32.dll!connect 71A34A07 5 Bytes JMP 100038CC
.text C:\WINDOWS\System32\svchost.exe[1424] ws2_32.dll!send 71A34C27 5 Bytes JMP 10003004
.text C:\WINDOWS\System32\svchost.exe[1424] ws2_32.dll!WSARecv 71A34CB5 5 Bytes JMP 10002734
.text C:\WINDOWS\System32\svchost.exe[1424] ws2_32.dll!recv 71A3676F 5 Bytes JMP 100026AC
.text C:\WINDOWS\System32\svchost.exe[1424] ws2_32.dll!WSASend 71A368FA 5 Bytes JMP 10003894
.text C:\WINDOWS\System32\svchost.exe[1424] wininet.dll!InternetOpenA 445EC865 5 Bytes JMP 00FD0FEF
.text C:\WINDOWS\System32\svchost.exe[1424] wininet.dll!InternetOpenW 445ECE99 5 Bytes JMP 00FD0FDE
.text C:\WINDOWS\System32\svchost.exe[1424] wininet.dll!InternetOpenUrlA 445F0BCA 5 Bytes JMP 00FD000A
.text C:\WINDOWS\System32\svchost.exe[1424] wininet.dll!InternetOpenUrlW 4463AF69 5 Bytes JMP 00FD0025
.text C:\WINDOWS\system32\spoolsv.exe[1620] kernel32.dll!CreateProcessW 7C7D2336 5 Bytes JMP 100039A0
.text C:\WINDOWS\system32\spoolsv.exe[1620] ws2_32.dll!connect 71A34A07 5 Bytes JMP 100038CC
.text C:\WINDOWS\system32\spoolsv.exe[1620] ws2_32.dll!send 71A34C27 5 Bytes JMP 10003004
.text C:\WINDOWS\system32\spoolsv.exe[1620] ws2_32.dll!WSARecv 71A34CB5 5 Bytes JMP 10002734
.text C:\WINDOWS\system32\spoolsv.exe[1620] ws2_32.dll!recv 71A3676F 5 Bytes JMP 100026AC
.text C:\WINDOWS\system32\spoolsv.exe[1620] ws2_32.dll!WSASend 71A368FA 5 Bytes JMP 10003894
.text C:\WINDOWS\system32\ctfmon.exe[1652] kernel32.dll!CreateProcessW 7C7D2336 5 Bytes JMP 100039A0
.text C:\WINDOWS\system32\ctfmon.exe[1652] ws2_32.dll!connect 71A34A07 5 Bytes JMP 100038CC
.text C:\WINDOWS\system32\ctfmon.exe[1652] ws2_32.dll!send 71A34C27 5 Bytes JMP 10003004
.text C:\WINDOWS\system32\ctfmon.exe[1652] ws2_32.dll!WSARecv 71A34CB5 5 Bytes JMP 10002734
.text C:\WINDOWS\system32\ctfmon.exe[1652] ws2_32.dll!recv 71A3676F 5 Bytes JMP 100026AC
.text C:\WINDOWS\system32\ctfmon.exe[1652] ws2_32.dll!WSASend 71A368FA 5 Bytes JMP 10003894
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!CreateFileA 7C7D1A28 5 Bytes JMP 00C50000
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!VirtualProtectEx 7C7D1A61 5 Bytes JMP 00C50081
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!VirtualProtect 7C7D1AD4 5 Bytes JMP 00C50066
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!LoadLibraryExW 7C7D1AF5 5 Bytes JMP 00C50055
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!LoadLibraryExA 7C7D1D53 5 Bytes JMP 00C50FA2
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!LoadLibraryA 7C7D1D7B 5 Bytes JMP 00C50FC7
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!GetStartupInfoW 7C7D1E54 5 Bytes JMP 00C500AF
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!GetStartupInfoA 7C7D1EF2 5 Bytes JMP 00C5009E
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!CreateProcessW 7C7D2336 5 Bytes JMP 100039A0
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!CreateProcessA 7C7D236B 5 Bytes JMP 00C500CA
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!GetProcAddress 7C7DAE40 5 Bytes JMP 00C50100
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!LoadLibraryW 7C7DAEEB 5 Bytes JMP 00C50044
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!CreateFileW 7C7E0800 5 Bytes JMP 00C50011
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!CreatePipe 7C7ED83F 5 Bytes JMP 00C50F67
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!CreateNamedPipeW 7C7FF0DD 5 Bytes JMP 00C50033
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!CreateNamedPipeA 7C830CDC 5 Bytes JMP 00C50022
.text C:\WINDOWS\System32\svchost.exe[1780] kernel32.dll!WinExec 7C83250D 5 Bytes JMP 00C50F4C
.text C:\WINDOWS\System32\svchost.exe[1780] ADVAPI32.dll!RegOpenKeyExW 77F46AAF 5 Bytes JMP 00B40025
Reply With Quote