GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2015-01-15 19:36:59 Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000037 HGST_HTS541010A9E680 rev.JA0OA560 931,51GB Running: rl6jt5r5.exe; Driver: C:\Users\User\AppData\Local\Temp\ufrdapob.sys ---- Kernel code sections - GMER 2.1 ---- .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000182200 15 bytes [00, 28, F6, 01, 80, 1C, 6C, ...] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 16 fffff96000182210 11 bytes [00, 0E, FC, FF, 00, 05, C4, ...] ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffcb84c28c0 7 bytes JMP 00007ffdb65e0260 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ffcb84c43d8 7 bytes JMP 00007ffdb65e0298 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 00007ffcb8571f20 7 bytes JMP 00007ffdb65e0308 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 00007ffcb85740b4 7 bytes JMP 00007ffdb65e0340 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ffcb8574510 7 bytes JMP 00007ffdb65e02d0 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffcb859cea0 7 bytes JMP 00007ffdb65e01f0 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffcb859cf10 7 bytes JMP 00007ffdb65e0228 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ffcb65f299c 7 bytes JMP 00007ffdb65e00d8 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 00007ffcb65f54c8 5 bytes JMP 00007ffdb65e0180 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ffcb65f55b0 5 bytes JMP 00007ffdb65e0148 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffcb65f5e58 5 bytes JMP 00007ffdb65e0110 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 00007ffcb6666200 5 bytes JMP 00007ffdb65e01b8 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ffcb8e77834 10 bytes JMP 00007ffdb65e0420 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 00007ffcb8e7b4d0 5 bytes JMP 00007ffdb65e03b0 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 00007ffcb8e7c6d8 5 bytes JMP 00007ffdb65e03e8 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 00007ffcb8e7c8fc 5 bytes JMP 00007ffdb65e0458 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffcb8e7e39c 9 bytes JMP 00007ffdb65e0378 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffcb8d11500 1 byte JMP 00007ffdb65e0490 .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList + 2 00007ffcb8d11502 6 bytes {JMP 0xfffffffffd8cef90} .text C:\Windows\system32\dwm.exe[988] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffcb8d11750 8 bytes JMP 00007ffdb65e04c8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffcb84c28c0 7 bytes JMP 00007ffdb65e0260 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ffcb84c43d8 7 bytes JMP 00007ffdb65e0298 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 00007ffcb8571f20 7 bytes JMP 00007ffdb65e0308 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 00007ffcb85740b4 7 bytes JMP 00007ffdb65e0340 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ffcb8574510 7 bytes JMP 00007ffdb65e02d0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffcb859cea0 7 bytes JMP 00007ffdb65e01f0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffcb859cf10 7 bytes JMP 00007ffdb65e0228 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ffcb65f299c 7 bytes JMP 00007ffdb65e00d8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 00007ffcb65f54c8 5 bytes JMP 00007ffdb65e0180 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ffcb65f55b0 5 bytes JMP 00007ffdb65e0148 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffcb65f5e58 5 bytes JMP 00007ffdb65e0110 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 00007ffcb6666200 5 bytes JMP 00007ffdb65e01b8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ffcb8629318 7 bytes JMP 00007ffdb65e0538 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 00007ffcb862cbe0 7 bytes JMP 00007ffdb65e0500 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ffcb8e77834 10 bytes JMP 00007ffdb65e0420 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 00007ffcb8e7b4d0 5 bytes JMP 00007ffdb65e03b0 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 00007ffcb8e7c6d8 5 bytes JMP 00007ffdb65e03e8 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 00007ffcb8e7c8fc 5 bytes JMP 00007ffdb65e0458 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffcb8e7e39c 9 bytes JMP 00007ffdb65e0378 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffcb8d11500 1 byte JMP 00007ffdb65e0490 .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList + 2 00007ffcb8d11502 6 bytes {JMP 0xfffffffffd8cef90} .text C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe[1020] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffcb8d11750 8 bytes JMP 00007ffdb65e04c8 .text C:\Windows\system32\nvvsvc.exe[76] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffcb8e6169a 4 bytes [E6, B8, FC, 7F] .text C:\Windows\system32\nvvsvc.exe[76] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffcb8e616a2 4 bytes [E6, B8, FC, 7F] .text C:\Windows\system32\nvvsvc.exe[76] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffcb8e6181a 4 bytes [E6, B8, FC, 7F] .text C:\Windows\system32\nvvsvc.exe[76] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffcb8e61832 4 bytes [E6, B8, FC, 7F] .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffcb84c28c0 7 bytes JMP 00007ffdb65e0260 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ffcb84c43d8 7 bytes JMP 00007ffdb65e0298 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 00007ffcb8571f20 7 bytes JMP 00007ffdb65e0308 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 00007ffcb85740b4 7 bytes JMP 00007ffdb65e0340 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ffcb8574510 7 bytes JMP 00007ffdb65e02d0 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffcb859cea0 7 bytes JMP 00007ffdb65e01f0 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffcb859cf10 7 bytes JMP 00007ffdb65e0228 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ffcb65f299c 7 bytes JMP 00007ffdb65e00d8 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 00007ffcb65f54c8 5 bytes JMP 00007ffdb65e0180 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ffcb65f55b0 5 bytes JMP 00007ffdb65e0148 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffcb65f5e58 5 bytes JMP 00007ffdb65e0110 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 00007ffcb6666200 5 bytes JMP 00007ffdb65e01b8 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\SYSTEM32\user32.dll!CreateWindowExW 00007ffcb8e77834 10 bytes JMP 00007ffdb65e0420 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\SYSTEM32\user32.dll!EnumDisplayDevicesA 00007ffcb8e7b4d0 5 bytes JMP 00007ffdb65e03b0 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\SYSTEM32\user32.dll!EnumDisplayDevicesW 00007ffcb8e7c6d8 5 bytes JMP 00007ffdb65e03e8 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\SYSTEM32\user32.dll!ChangeDisplaySettingsExW 00007ffcb8e7c8fc 5 bytes JMP 00007ffdb65e0458 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\SYSTEM32\user32.dll!DisplayConfigGetDeviceInfo 00007ffcb8e7e39c 9 bytes JMP 00007ffdb65e0378 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffcb8d11500 1 byte JMP 00007ffdb65e0490 .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList + 2 00007ffcb8d11502 6 bytes {JMP 0xfffffffffd8cef90} .text C:\Windows\system32\taskhostex.exe[2740] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffcb8d11750 8 bytes JMP 00007ffdb65e04c8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffcb84c28c0 7 bytes JMP 00007ffdb65e0260 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ffcb84c43d8 7 bytes JMP 00007ffdb65e0298 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 00007ffcb8571f20 7 bytes JMP 00007ffdb65e0308 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 00007ffcb85740b4 7 bytes JMP 00007ffdb65e0340 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ffcb8574510 7 bytes JMP 00007ffdb65e02d0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffcb859cea0 7 bytes JMP 00007ffdb65e01f0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffcb859cf10 7 bytes JMP 00007ffdb65e0228 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ffcb65f299c 7 bytes JMP 00007ffdb65e00d8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 00007ffcb65f54c8 5 bytes JMP 00007ffdb65e0180 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ffcb65f55b0 5 bytes JMP 00007ffdb65e0148 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffcb65f5e58 5 bytes JMP 00007ffdb65e0110 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 00007ffcb6666200 5 bytes JMP 00007ffdb65e01b8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ffcb8e77834 10 bytes JMP 00007ffdb65e0420 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 00007ffcb8e7b4d0 5 bytes JMP 00007ffdb65e03b0 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 00007ffcb8e7c6d8 5 bytes JMP 00007ffdb65e03e8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 00007ffcb8e7c8fc 5 bytes JMP 00007ffdb65e0458 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffcb8e7e39c 9 bytes JMP 00007ffdb65e0378 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffcb8d11500 1 byte JMP 00007ffdb65e0490 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList + 2 00007ffcb8d11502 6 bytes {JMP 0xfffffffffd8cef90} .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffcb8d11750 8 bytes JMP 00007ffdb65e04c8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\SYSTEM32\d3d9.dll!Direct3DCreate9Ex 00007ffcad68a204 4 bytes JMP 00007ffcb65e05a8 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\SYSTEM32\d3d9.dll!Direct3DCreate9 00007ffcad6a22cc 6 bytes JMP 00007ffcb65e0570 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ffcb8629318 7 bytes JMP 00007ffdb65e0538 .text C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe[1108] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 00007ffcb862cbe0 7 bytes JMP 00007ffdb65e0500 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffcb84c28c0 7 bytes JMP 00007ffdb65e0260 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ffcb84c43d8 7 bytes JMP 00007ffdb65e0298 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 00007ffcb8571f20 7 bytes JMP 00007ffdb65e0308 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 00007ffcb85740b4 7 bytes JMP 00007ffdb65e0340 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ffcb8574510 7 bytes JMP 00007ffdb65e02d0 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffcb859cea0 7 bytes JMP 00007ffdb65e01f0 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffcb859cf10 7 bytes JMP 00007ffdb65e0228 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ffcb65f299c 7 bytes JMP 00007ffdb65e00d8 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 00007ffcb65f54c8 5 bytes JMP 00007ffdb65e0180 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ffcb65f55b0 5 bytes JMP 00007ffdb65e0148 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffcb65f5e58 5 bytes JMP 00007ffdb65e0110 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 00007ffcb6666200 5 bytes JMP 00007ffdb65e01b8 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ffcb8e77834 10 bytes JMP 00007ffdb65e0420 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 00007ffcb8e7b4d0 5 bytes JMP 00007ffdb65e03b0 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 00007ffcb8e7c6d8 5 bytes JMP 00007ffdb65e03e8 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 00007ffcb8e7c8fc 5 bytes JMP 00007ffdb65e0458 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffcb8e7e39c 9 bytes JMP 00007ffdb65e0378 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffcb8d11500 1 byte JMP 00007ffdb65e0490 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList + 2 00007ffcb8d11502 6 bytes {JMP 0xfffffffffd8cef90} .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffcb8d11750 8 bytes JMP 00007ffdb65e04c8 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ffcb8629318 7 bytes JMP 00007ffdb65e0538 .text C:\Windows\system32\igfxEM.exe[3660] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 00007ffcb862cbe0 7 bytes JMP 00007ffdb65e0500 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffcb84c28c0 7 bytes JMP 00007ffdb65e0260 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ffcb84c43d8 7 bytes JMP 00007ffdb65e0298 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 00007ffcb8571f20 7 bytes JMP 00007ffdb65e0308 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 00007ffcb85740b4 7 bytes JMP 00007ffdb65e0340 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ffcb8574510 7 bytes JMP 00007ffdb65e02d0 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffcb859cea0 7 bytes JMP 00007ffdb65e01f0 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffcb859cf10 7 bytes JMP 00007ffdb65e0228 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ffcb65f299c 7 bytes JMP 00007ffdb65e00d8 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 00007ffcb65f54c8 5 bytes JMP 00007ffdb65e0180 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ffcb65f55b0 5 bytes JMP 00007ffdb65e0148 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffcb65f5e58 5 bytes JMP 00007ffdb65e0110 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 00007ffcb6666200 5 bytes JMP 00007ffdb65e01b8 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ffcb8e77834 10 bytes JMP 00007ffdb65e0420 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 00007ffcb8e7b4d0 5 bytes JMP 00007ffdb65e03b0 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 00007ffcb8e7c6d8 5 bytes JMP 00007ffdb65e03e8 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\USER32.dll!ChangeDisplaySettingsExW 00007ffcb8e7c8fc 5 bytes JMP 00007ffdb65e0458 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffcb8e7e39c 9 bytes JMP 00007ffdb65e0378 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffcb8d11500 1 byte JMP 00007ffdb65e0490 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList + 2 00007ffcb8d11502 6 bytes {JMP 0xfffffffffd8cef90} .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffcb8d11750 8 bytes JMP 00007ffdb65e04c8 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\SYSTEM32\combase.dll!CoSetProxyBlanket 00007ffcb8629318 7 bytes JMP 00007ffdb65e0538 .text C:\Windows\system32\igfxHK.exe[3672] C:\Windows\SYSTEM32\combase.dll!CoCreateInstance 00007ffcb862cbe0 7 bytes JMP 00007ffdb65e0500 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, DE, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, DE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, DE, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, DE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, DE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3756] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, DE, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, 45, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, 45, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, 45, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, 45, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, 45, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera_crashreporter.exe[4224] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, 45, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, 71, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, 71, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, 71, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, 71, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, 71, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[96] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, 71, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, 63, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, 63, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, 63, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, 63, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, 63, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3040] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, 63, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, 95, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, 95, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, 95, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, 95, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, 95, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1776] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, 95, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, 19, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, 19, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, 19, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, 19, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, 19, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[1072] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, 19, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, D2, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, D2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, D2, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, D2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, D2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[5000] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, D2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, 02, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, 02, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, 02, FF, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, 02, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, 02, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[2496] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, 02, FF, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, 3F, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, 3F, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, 3F, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, 3F, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, 3F, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[3780] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, 3F, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, B2, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, B2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, B2, FE, 00, 00, 00, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, B2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, B2, FE, 00, 00, 00, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Program Files (x86)\Opera\25.0.1614.50\opera.exe[4464] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, B2, FE, 00, 00, 00, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 112 00007ffcb9112bd4 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlDecompressBuffer + 432 00007ffcb9112d14 8 bytes {JMP 0xffffffffffffffd8} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlPrefixString + 428 00007ffcb9112ee8 16 bytes {JMP 0xffffffffffffffb8} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 415 00007ffcb9113757 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!LdrGetDllPath + 704 00007ffcb9113878 8 bytes {JMP 0xffffffffffffffd3} .text ... * 2 .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!LdrLoadDll + 280 00007ffcb911425c 8 bytes {JMP 0xffffffffffffffbb} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 91 00007ffcb9114a2b 8 bytes {JMP 0xffffffffffffffde} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlReleasePath + 132 00007ffcb9114a54 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateTagHeap + 312 00007ffcb9114cfc 8 bytes {JMP 0xffffffffffffffb1} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 52 00007ffcb9115030 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlTryEnterCriticalSection + 291 00007ffcb911511f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!CsrCaptureMessageBuffer + 75 00007ffcb9116693 8 bytes {JMP 0xffffffffffffffde} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!EtwRegisterTraceGuidsA + 48 00007ffcb9116964 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!CsrClientConnectToServer + 412 00007ffcb9116b08 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryResourcePolicy + 199 00007ffcb911740f 8 bytes {JMP 0xffffffffffffffe8} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!EtwEventRegister + 67 00007ffcb91175c7 8 bytes {JMP 0xffffffffffffffe5} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!EtwNotificationRegister + 559 00007ffcb911a8b3 8 bytes {JMP 0xffffffffffffff9e} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 12 00007ffcb911a8c8 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlDllShutdownInProgress + 264 00007ffcb911a9c4 8 bytes {JMP 0xffffffffffffffe1} .text ... * 3 .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlRandomEx + 160 00007ffcb911ad90 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 543 00007ffcb911b157 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlRunOnceComplete + 736 00007ffcb911b218 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 244 00007ffcb911b57c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeResource + 448 00007ffcb911b648 8 bytes [10, 6A, F8, 7F, 00, 00, 00, ...] .text ... * 2 .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 448 00007ffcb911b88c 8 bytes [F0, 69, F8, 7F, 00, 00, 00, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlInitializeCriticalSectionEx + 704 00007ffcb911b98c 8 bytes [E0, 69, F8, 7F, 00, 00, 00, ...] .text ... * 2 .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlAllocateActivationContextStack + 288 00007ffcb911bc38 8 bytes [B0, 69, F8, 7F, 00, 00, 00, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!RtlRegisterWait + 596 00007ffcb911be94 8 bytes [A0, 69, F8, 7F, 00, 00, 00, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 00007ffcb9191740 8 bytes {JMP QWORD [RIP-0x75dba]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 00007ffcb91918c0 8 bytes {JMP QWORD [RIP-0x75eda]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 00007ffcb91918f0 8 bytes {JMP QWORD [RIP-0x762ae]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 00007ffcb9191a10 8 bytes {JMP QWORD [RIP-0x7618a]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 00007ffcb9191ac0 8 bytes {JMP QWORD [RIP-0x76403]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 00007ffcb9192180 8 bytes {JMP QWORD [RIP-0x762f2]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 00007ffcb9192480 8 bytes {JMP QWORD [RIP-0x7684e]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 00007ffcb9192d00 8 bytes {JMP QWORD [RIP-0x771f6]} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuSetContext + 381 0000000077bc137d 16 bytes {JMP 0xffffffffffffffd3} .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuGetContext + 386 0000000077bc1512 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuSetInstructionPointer + 49 0000000077bc1551 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuSetStackPointer + 23 0000000077bc1577 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuResetToConsistentState + 516 0000000077bc1784 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuThreadInit + 50 0000000077bc17c2 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuGetStackPointer + 23 0000000077bc17e7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuProcessInit + 68 0000000077bc1834 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 1 0000000077bc1841 24 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuNotifyAffinityChange + 513 0000000077bc1a41 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuFlushInstructionCache + 16 0000000077bc2ae0 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuInitializeStartupContext + 308 0000000077bc2c1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\User\Downloads\rl6jt5r5.exe[2768] C:\Windows\system32\wow64cpu.dll!CpuProcessDebugEvent + 3 0000000077bc2c43 8 bytes [7C, 68, F8, 7F, 00, 00, 00, ...] ---- User IAT/EAT - GMER 2.1 ---- IAT C:\Windows\Explorer.EXE[2852] @ C:\Windows\system32\RPCRT4.dll[ntdll.dll!NtAlpcConnectPortEx] [750b1250] C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\prremote.dll ---- Threads - GMER 2.1 ---- Thread C:\Windows\system32\csrss.exe [672:696] fffff9600090fb90 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\Kernel\RNG@RNGAuxiliarySeed 1467429648 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\c8f733e68475 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\c8f733e68475@68489839b3d2 0x79 0xA4 0xAA 0x1A ... Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIF\Parameters@LastProcessedRevision 49903791 Reg HKLM\SYSTEM\CurrentControlSet\Services\KLIF\Parameters@CheckVersion 584 Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch@Epoch 9600 Reg HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch2@Epoch 3011 Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug@StoreLocation C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_compatibilityche_d5aff0462131104faecf643b37b725d5b25da70_27e9c2bc_165a2fda Reg HKCU\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles@CheckingForSolutionDialog 0x58 0x04 0x1C 0x00 ... ---- EOF - GMER 2.1 ----