Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- GMER 2.1.19357 - http://www.gmer.net
- Rootkit scan 2015-02-03 21:24:18
- Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP3T0L0-3 SAMSUNG_HD321KJ rev.CP100-12 298,09GB
- Running: gmer.exe; Driver: C:\Users\HITOKK~1\AppData\Local\Temp\ufldiuog.sys
- ---- Kernel code sections - GMER 2.1 ----
- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 448 fffff8000efbf000 45 bytes [00, 00, 00, 00, 00, 00, 02, ...]
- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 495 fffff8000efbf02f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...]
- ---- User code sections - GMER 2.1 ----
- .text C:\Windows\system32\taskhost.exe[3900] C:\Windows\system32\kernel32.dll!CreateProcessW 00000000778a0650 6 bytes {JMP QWORD [RIP+0x879f9e0]}
- .text C:\Windows\system32\taskhost.exe[3900] C:\Windows\system32\kernel32.dll!WriteProcessMemory 00000000778cbe80 6 bytes {JMP QWORD [RIP+0x88941b0]}
- .text C:\Windows\system32\taskhost.exe[3900] C:\Windows\system32\kernel32.dll!VirtualProtectEx 00000000778cbf20 6 bytes {JMP QWORD [RIP+0x8874110]}
- .text C:\Windows\system32\taskhost.exe[3900] C:\Windows\system32\kernel32.dll!CreateProcessA 000000007791acf0 6 bytes {JMP QWORD [RIP+0x8705340]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077af15e0 6 bytes {JMP QWORD [RIP+0x86eea50]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077af1620 6 bytes {JMP QWORD [RIP+0x870ea10]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077af1800 6 bytes {JMP QWORD [RIP+0x86ce830]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\kernel32.dll!CreateProcessW 00000000778a0650 6 bytes {JMP QWORD [RIP+0x879f9e0]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\kernel32.dll!WriteProcessMemory 00000000778cbe80 6 bytes {JMP QWORD [RIP+0x88941b0]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\kernel32.dll!VirtualProtectEx 00000000778cbf20 6 bytes {JMP QWORD [RIP+0x8874110]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\kernel32.dll!CreateProcessA 000000007791acf0 6 bytes {JMP QWORD [RIP+0x8705340]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW + 357 000007fefda59055 3 bytes [B5, 6F, 06]
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\ole32.dll!CoCreateInstanceEx 000007fefefade90 6 bytes {JMP QWORD [RIP+0x3221a0]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefefc7490 6 bytes JMP 70005c
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\ole32.dll!CoGetClassObject 000007fefefd2e18 6 bytes JMP 0
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WSOCK32.dll!recv 000007fef73a1744 6 bytes {JMP QWORD [RIP+0x4e8ec]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!WSASend 000007feffd313b0 6 bytes {JMP QWORD [RIP+0x38ec80]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!closesocket + 1 000007feffd318e1 5 bytes {JMP QWORD [RIP+0xce750]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!WSARecv 000007feffd32200 6 bytes JMP 0
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!send 000007feffd38000 6 bytes JMP 0
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!sendto 000007feffd3d7f0 6 bytes JMP 370038
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!socket 000007feffd3de90 6 bytes {JMP QWORD [RIP+0xa21a0]}
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!recv 000007feffd3df40 6 bytes JMP ff961b50
- .text C:\Windows\Explorer.EXE[3192] C:\Windows\system32\WS2_32.dll!WSAAsyncSelect 000007feffd5e5e0 6 bytes JMP 0
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3412] C:\Windows\SYSTEM32\ntdll.dll!NtOpenFile 0000000077af15e0 6 bytes {JMP QWORD [RIP+0x87eea50]}
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3412] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection 0000000077af1620 6 bytes {JMP QWORD [RIP+0x880ea10]}
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3412] C:\Windows\SYSTEM32\ntdll.dll!NtCreateFile 0000000077af1800 6 bytes {JMP QWORD [RIP+0x87ce830]}
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3412] C:\Windows\system32\ole32.dll!CoCreateInstanceEx 000007fefefade90 6 bytes {JMP QWORD [RIP+0x3221a0]}
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3412] C:\Windows\system32\ole32.dll!CoCreateInstance 000007fefefc7490 6 bytes {JMP QWORD [RIP+0x2e8ba0]}
- .text C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe[3412] C:\Windows\system32\ole32.dll!CoGetClassObject 000007fefefd2e18 6 bytes JMP 0
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile 0000000077c9fd64 3 bytes JMP 7130000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4 0000000077c9fd68 2 bytes JMP 7130000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection 0000000077c9ffa4 3 bytes JMP 712d000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4 0000000077c9ffa8 2 bytes JMP 712d000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile 0000000077ca00b4 3 bytes JMP 7133000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4 0000000077ca00b8 2 bytes JMP 7133000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtAcceptConnectPort 0000000077ca0210 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtAcceptConnectPort + 4 0000000077ca0214 2 bytes [23, 71]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077ca088c 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4 0000000077ca0890 2 bytes [29, 71]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtRestoreKey 0000000077ca17e0 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtRestoreKey + 4 0000000077ca17e4 2 bytes [26, 71]
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\kernel32.dll!CreateProcessW 000000007693103d 6 bytes {JMP QWORD [RIP+0x71a4001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000076931072 6 bytes {JMP QWORD [RIP+0x71a7001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\kernel32.dll!LoadLibraryW 00000000769348f3 6 bytes JMP 7136000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\kernel32.dll!LoadLibraryA 000000007693499f 6 bytes JMP 7139000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\KERNELBASE.dll!LoadLibraryExW + 493 00000000765c2c9e 4 bytes CALL 71ac0000
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\ADVAPI32.dll!CreateServiceW 00000000759870c4 6 bytes {JMP QWORD [RIP+0x7189001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\ADVAPI32.dll!CreateServiceA 00000000759a3264 6 bytes {JMP QWORD [RIP+0x718c001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\ADVAPI32.dll!InitiateSystemShutdownW 00000000759bdc55 6 bytes {JMP QWORD [RIP+0x719b001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\ADVAPI32.dll!InitiateSystemShutdownExW 00000000759bdd22 6 bytes {JMP QWORD [RIP+0x7195001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\ADVAPI32.dll!InitiateSystemShutdownA 00000000759bddf7 6 bytes {JMP QWORD [RIP+0x719e001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\ADVAPI32.dll!InitiateSystemShutdownExA 00000000759bde9e 6 bytes {JMP QWORD [RIP+0x7198001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!ioctlsocket 0000000075df3084 6 bytes JMP 70f7000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!sendto 0000000075df34b5 6 bytes JMP 70fd000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075df3918 6 bytes JMP 7109000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!socket 0000000075df3eb8 6 bytes JMP 71af000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075df4406 6 bytes JMP 70e8000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!select 0000000075df6989 6 bytes JMP 70fa000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!recv 0000000075df6b0e 6 bytes JMP 70ef000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!connect 0000000075df6bdd 6 bytes JMP 7106000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!send 0000000075df6f01 6 bytes JMP 7100000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!WSARecv 0000000075df7089 6 bytes JMP 70eb000a
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!WSAGetOverlappedResult 0000000075df7489 6 bytes {JMP QWORD [RIP+0x70e1001e]}
- .text C:\Program Files (x86)\Skype\Phone\Skype.exe[2792] C:\Windows\syswow64\WS2_32.dll!WSAAsyncSelect 0000000075e0b014 6 bytes {JMP QWORD [RIP+0x70f3001e]}
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile 0000000077c9fd64 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtOpenFile + 4 0000000077c9fd68 2 bytes [2F, 71]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection 0000000077c9ffa4 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtCreateSection + 4 0000000077c9ffa8 2 bytes [2C, 71]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile 0000000077ca00b4 3 bytes JMP 7133000a
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtCreateFile + 4 0000000077ca00b8 2 bytes JMP 7133000a
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtAcceptConnectPort 0000000077ca0210 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtAcceptConnectPort + 4 0000000077ca0214 2 bytes [23, 71]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077ca088c 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject + 4 0000000077ca0890 2 bytes [29, 71]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtRestoreKey 0000000077ca17e0 3 bytes [FF, 25, 1E]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\SysWOW64\ntdll.dll!NtRestoreKey + 4 0000000077ca17e4 2 bytes [26, 71]
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\syswow64\kernel32.dll!CreateProcessW 000000007693103d 6 bytes {JMP QWORD [RIP+0x71a4001e]}
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\syswow64\kernel32.dll!CreateProcessA 0000000076931072 6 bytes {JMP QWORD [RIP+0x71a7001e]}
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\syswow64\kernel32.dll!LoadLibraryW 00000000769348f3 6 bytes {JMP QWORD [RIP+0x7135001e]}
- .text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[956] C:\Windows\syswow64\kernel32.dll!LoadLibraryA 000000007693499f 6 bytes {JMP QWORD [RIP+0x7138001e]}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4504] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4504] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4504] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4504] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4504] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4504] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4320] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4320] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4320] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4320] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4320] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4320] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\syswow64\USER32.dll!SetWindowPos 0000000075ee8e4e 5 bytes JMP 00000001100a55a0
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\syswow64\USER32.dll!SetForegroundWindow 0000000075f0f170 1 byte JMP 00000001100a5574
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\syswow64\USER32.dll!SetForegroundWindow + 2 0000000075f0f172 3 bytes {JMP QWORD [RBX+0x19]}
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 0000000075f307d7 5 bytes JMP 00000001100a5624
- .text C:\Program Files (x86)\Steam\Steam.exe[2080] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExA 0000000075f46da0 5 bytes JMP 00000001100a55f8
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[7952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[7952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[7952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[7952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[7952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[7952] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[8104] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[8104] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[8104] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[8104] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[8104] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[8104] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4648] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4648] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4648] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4648] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4648] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[4648] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[1364] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[1364] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[1364] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[1364] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[1364] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[1364] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\syswow64\USER32.dll!SetWindowPos 0000000075ee8e4e 5 bytes JMP 00000001100a55a0
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\syswow64\USER32.dll!SetForegroundWindow 0000000075f0f170 1 byte JMP 00000001100a5574
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\syswow64\USER32.dll!SetForegroundWindow + 2 0000000075f0f172 3 bytes {JMP QWORD [RBX+0x19]}
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 0000000075f307d7 5 bytes JMP 00000001100a5624
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExA 0000000075f46da0 5 bytes JMP 00000001100a55f8
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 69 0000000076061465 2 bytes [06, 76]
- .text C:\Users\Hitokkiri\Downloads\avz4 (1)\avz4\avz.exe[4436] C:\Windows\syswow64\PSAPI.dll!GetModuleInformation + 155 00000000760614bb 2 bytes [06, 76]
- .text ... * 2
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000077aa1398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000077aa143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077aa1594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000077aa191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077aa1bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077aa1d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077aa1edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077aa1fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000077aa27b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077aa27d2 8 bytes {JMP 0x10}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000077aa282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077aa2898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077aa2d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077aa2d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000077aa323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077aa33c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000077aa3a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000077aa3ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077aa3b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077aa4190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077aa4241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077aa42b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 3
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077aa43f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077aa4434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000077aa45d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000077aa46d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000077aa4a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077aa4b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077aa4c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077aa4d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077aa4ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077aa4ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077aa50f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077aa52f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077aa53f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000077aa55e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077aa64d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000077aa668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000077aa687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000077aa68bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077aa68d4 8 bytes [70, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000077aa692c 8 bytes [60, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077aa7166 8 bytes [40, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000077aa7dd1 8 bytes [10, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000077aa7e57 8 bytes [00, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077af1380 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000077af1500 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077af1530 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077af1650 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077af1700 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077af1d30 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077af1f80 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077af27e0 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6840] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000077aa1398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000077aa143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077aa1594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000077aa191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077aa1bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077aa1d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077aa1edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077aa1fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000077aa27b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077aa27d2 8 bytes {JMP 0x10}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000077aa282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077aa2898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077aa2d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077aa2d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000077aa323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077aa33c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000077aa3a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000077aa3ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077aa3b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077aa4190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077aa4241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077aa42b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 3
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077aa43f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077aa4434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000077aa45d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000077aa46d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000077aa4a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077aa4b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077aa4c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077aa4d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077aa4ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077aa4ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077aa50f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077aa52f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077aa53f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000077aa55e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077aa64d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000077aa668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000077aa687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000077aa68bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077aa68d4 8 bytes [70, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000077aa692c 8 bytes [60, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077aa7166 8 bytes [40, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000077aa7dd1 8 bytes [10, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000077aa7e57 8 bytes [00, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077af1380 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000077af1500 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077af1530 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077af1650 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077af1700 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077af1d30 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077af1f80 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077af27e0 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[2640] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000077aa1398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000077aa143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077aa1594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000077aa191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077aa1bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077aa1d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077aa1edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077aa1fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000077aa27b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077aa27d2 8 bytes {JMP 0x10}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000077aa282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077aa2898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077aa2d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077aa2d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000077aa323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077aa33c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000077aa3a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000077aa3ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077aa3b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077aa4190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077aa4241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077aa42b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 3
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077aa43f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077aa4434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000077aa45d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000077aa46d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000077aa4a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077aa4b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077aa4c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077aa4d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077aa4ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077aa4ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077aa50f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077aa52f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077aa53f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000077aa55e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077aa64d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000077aa668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000077aa687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000077aa68bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077aa68d4 8 bytes [70, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000077aa692c 8 bytes [60, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077aa7166 8 bytes [40, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000077aa7dd1 8 bytes [10, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000077aa7e57 8 bytes [00, 6C, F8, FF, 00, 00, 00, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077af1380 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000077af1500 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077af1530 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077af1650 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077af1700 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077af1d30 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077af1f80 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077af27e0 8 bytes JMP 3f3f3f3f
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Program Files (x86)\Opera\27.0.1689.54\opera.exe[6308] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 424 0000000077aa1398 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000077aa143f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 500 0000000077aa1594 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000077aa191e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 212 0000000077aa1bf8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077aa1d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077aa1edf 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 89 0000000077aa1fc5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000077aa27b0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077aa27d2 8 bytes {JMP 0x10}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000077aa282f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 184 0000000077aa2898 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077aa2d1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 375 0000000077aa2d67 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000077aa323b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 920 0000000077aa33c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000077aa3a5e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000077aa3ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077aa3b85 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077aa4190 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 161 0000000077aa4241 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetNameFromLangInfoNode + 277 0000000077aa42b5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 3
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 214 0000000077aa43f6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpIsQualifiedLanguage + 276 0000000077aa4434 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 408 0000000077aa45d8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlpNtOpenKey + 657 0000000077aa46d1 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 284 0000000077aa4a9c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberOfSetBitsUlongPtr + 483 0000000077aa4b63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 231 0000000077aa4c57 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!TpWaitForWait + 518 0000000077aa4d76 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text ... * 2
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlDeactivateActivationContext + 256 0000000077aa4ea0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContext + 67 0000000077aa4ef3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlActivateActivationContextEx + 501 0000000077aa50f5 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateUserThread + 256 0000000077aa52f0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringExW + 247 0000000077aa53f7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlIpv6AddressToStringW + 484 0000000077aa55e4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseAlpcCompletion + 438 0000000077aa64d6 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!atol + 194 0000000077aa668e 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!qsort + 76 0000000077aa687c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlLookupElementGenericTableFullAvl + 45 0000000077aa68bd 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 4 0000000077aa68d4 8 bytes [70, 6C, F8, 7E, 00, 00, 00, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlNumberGenericTableElementsAvl + 92 0000000077aa692c 8 bytes [60, 6C, F8, 7E, 00, 00, 00, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!RtlSubtreePredecessor + 790 0000000077aa7166 8 bytes [40, 6C, F8, 7E, 00, 00, 00, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroupMembers + 241 0000000077aa7dd1 8 bytes [10, 6C, F8, 7E, 00, 00, 00, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!TpReleaseCleanupGroup + 119 0000000077aa7e57 8 bytes [00, 6C, F8, 7E, 00, 00, 00, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077af1380 8 bytes {JMP QWORD [RIP-0x4a220]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000077af1500 8 bytes {JMP QWORD [RIP-0x49cef]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077af1530 8 bytes {JMP QWORD [RIP-0x4ac62]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077af1650 8 bytes {JMP QWORD [RIP-0x4a80f]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077af1700 8 bytes {JMP QWORD [RIP-0x4adda]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077af1d30 8 bytes {JMP QWORD [RIP-0x49edf]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077af1f80 8 bytes {JMP QWORD [RIP-0x4a1b5]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077af27e0 8 bytes {JMP QWORD [RIP-0x4ab13]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000755213cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 000000007552146b 8 bytes {JMP 0xffffffffffffffb0}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000755216d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000755219db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000755219fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 0000000075521a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\syswow64\USER32.dll!SetWindowPos 0000000075ee8e4e 5 bytes JMP 00000001100a55a0
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\syswow64\USER32.dll!SetForegroundWindow 0000000075f0f170 1 byte JMP 00000001100a5574
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\syswow64\USER32.dll!SetForegroundWindow + 2 0000000075f0f172 3 bytes {JMP QWORD [RBX+0x19]}
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExW 0000000075f307d7 5 bytes JMP 00000001100a5624
- .text C:\Users\Hitokkiri\Downloads\gmer\gmer.exe[4896] C:\Windows\syswow64\USER32.dll!ChangeDisplaySettingsExA 0000000075f46da0 5 bytes JMP 00000001100a55f8
- ---- Kernel IAT/EAT - GMER 2.1 ----
- IAT C:\Windows\System32\win32k.sys[ntoskrnl.exe!KeUserModeCallback] [fffff880048abec0] \SystemRoot\system32\DRIVERS\klif.sys [unknown section]
- ---- Threads - GMER 2.1 ----
- Thread [3908:3276] 0000000073417a30
- Thread [3908:3280] 0000000077cd2e65
- Thread [3908:3284] 00000000735ac59c
- Thread [3908:3288] 00000000735ac59c
- Thread [3908:3292] 00000000735ac59c
- Thread [3908:3296] 00000000735ac59c
- Thread [3908:164] 00000000735ac59c
- Thread [3908:3532] 00000000735ac59c
- Thread [3908:3544] 00000000735ac59c
- Thread [3908:2360] 000000006defcf5c
- Thread [3908:2364] 000000006df7a8c0
- Thread [3908:5592] 000000006df7a8c0
- Thread [3908:5468] 000000006015aec5
- Thread [3908:5576] 0000000075bcd864
- Thread [3908:5980] 00000000735ac59c
- Thread [3908:5376] 0000000077cd3e85
- Thread [3908:7076] 0000000077cd3e85
- ---- Disk sectors - GMER 2.1 ----
- Disk \Device\Harddisk0\DR0 unknown MBR code
- ---- EOF - GMER 2.1 ----
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement