heres the log can i get an expert opinion thanks
GMER 2.2.19882 - http://www.gmer.net
Rootkit scan 2018-01-17 03:08:49
Windows 5.1.2600 Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 Hitachi_HDT721032SLA380 rev.ST2OA3BB 298.09GB
Running: 8u3w1c77.exe; Driver: C:\DOCUME~1\proj\LOCALS~1\Temp\uwliypob.sys
---- System - GMER 2.2 ----
SSDT \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys ZwOpenProcess [0xA6D27760]
SSDT \??\C:\WINDOWS\system32\drivers\mbamchameleon.sys ZwOpenThread [0xA6D27A7E]
---- User code sections - GMER 2.2 ----
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, DC, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, DF, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, DC, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, DD, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B9167F6
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, DE, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, DD, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, DE, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B916867
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, DC, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B916995
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, DD, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, DE, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, DF, 91, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1632] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 94, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 97, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 94, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 95, 76, 00] {TEST AL, 0x95; JBE 0x4}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B914CAE
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 96, 76, 00] {TEST AL, 0x96; JBE 0x4}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 95, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 96, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B914D1F
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 94, 76, 00] {TEST AL, 0x94; JBE 0x4}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B914E4D
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 95, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 96, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 97, 76, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[1772] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 04, DB, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 07, DB, 00] {SUB [EDI], AL; FILD DWORD [EAX]}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 04, DB, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 05, DB, 00] {TEST AL, 0x5; FILD DWORD [EAX]}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B91B11E
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 06, DB, 00] {TEST AL, 0x6; FILD DWORD [EAX]}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 05, DB, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 06, DB, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B91B18F
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 04, DB, 00] {TEST AL, 0x4; FILD DWORD [EAX]}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B91B2BD
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 05, DB, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 06, DB, 00] {SUB [ESI], AL; FILD DWORD [EAX]}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 07, DB, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2160] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 5C, B2, 00] {SUB [EDX+ESI*4+0x0], BL}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 5F, B2, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 5C, B2, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 5D, B2, 00] {TEST AL, 0x5d; MOV DL, 0x0}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B918876
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 5E, B2, 00] {TEST AL, 0x5e; MOV DL, 0x0}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 5D, B2, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 5E, B2, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B9188E7
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 5C, B2, 00] {TEST AL, 0x5c; MOV DL, 0x0}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B918A15
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 5D, B2, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 5E, B2, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 5F, B2, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2208] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 78, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 7B, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 78, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 79, D1, 00] {TEST AL, 0x79; ROL DWORD [EAX], 0x1}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B91A792
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 7A, D1, 00] {TEST AL, 0x7a; ROL DWORD [EAX], 0x1}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 79, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 7A, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B91A803
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 78, D1, 00] {TEST AL, 0x78; ROL DWORD [EAX], 0x1}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B91A931
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 79, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 7A, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 7B, D1, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[2236] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, B4, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, B7, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, B4, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, B5, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B9129CE
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, B6, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, B5, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, B6, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B912A3F
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, B4, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B912B6D
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, B5, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, B6, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, B7, 53, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3016] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, A8, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, AB, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, A8, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, A9, 89, 00] {TEST AL, 0xa9; MOV [EAX], EAX}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B915FC2
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, AA, 89, 00] {TEST AL, 0xaa; MOV [EAX], EAX}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, A9, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, AA, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B916033
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, A8, 89, 00] {TEST AL, 0xa8; MOV [EAX], EAX}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B916161
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, A9, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, AA, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, AB, 89, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3176] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
.text C:\Documents and Settings\proj\Desktop\hitmanpro.exe[3764] WS2_32.dll!GetAddrInfoW 71AB2899 5 Bytes JMP 0052BF80 C:\Documents and Settings\proj\Desktop\hitmanpro.exe
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtCreateFile + 6 7C90D0B4 4 Bytes [28, 78, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtCreateFile + B 7C90D0B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtMapViewOfSection + 6 7C90D524 4 Bytes [28, 7B, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtMapViewOfSection + B 7C90D529 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenFile + 6 7C90D5A4 4 Bytes [68, 78, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenFile + B 7C90D5A9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenProcess + 6 7C90D604 4 Bytes [A8, 79, 34, 00] {TEST AL, 0x79; XOR AL, 0x0}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenProcess + B 7C90D609 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenProcessToken + 6 7C90D614 4 Bytes CALL 7B910A92
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenProcessToken + B 7C90D619 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenProcessTokenEx + 6 7C90D624 4 Bytes [A8, 7A, 34, 00] {TEST AL, 0x7a; XOR AL, 0x0}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenProcessTokenEx + B 7C90D629 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenThread + 6 7C90D664 4 Bytes [68, 79, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenThread + B 7C90D669 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenThreadToken + 6 7C90D674 4 Bytes [68, 7A, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenThreadToken + B 7C90D679 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenThreadTokenEx + 6 7C90D684 4 Bytes CALL 7B910B03
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtOpenThreadTokenEx + B 7C90D689 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtQueryAttributesFile + 6 7C90D714 4 Bytes [A8, 78, 34, 00] {TEST AL, 0x78; XOR AL, 0x0}
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtQueryAttributesFile + B 7C90D719 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtQueryFullAttributesFile + 6 7C90D7B4 4 Bytes CALL 7B910C31
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtQueryFullAttributesFile + B 7C90D7B9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtSetInformationFile + 6 7C90DC64 4 Bytes [28, 79, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtSetInformationFile + B 7C90DC69 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtSetInformationThread + 6 7C90DCB4 4 Bytes [28, 7A, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtSetInformationThread + B 7C90DCB9 1 Byte [E2]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtUnmapViewOfSection + 6 7C90DF14 4 Bytes [68, 7B, 34, 00]
.text C:\Program Files\Opera\36.0.2130.80\opera.exe[3852] ntdll.dll!NtUnmapViewOfSection + B 7C90DF19 1 Byte [E2]
---- Devices - GMER 2.2 ----
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys
---- Registry - GMER 2.2 ----
Reg HKLM\SYSTEM\CurrentControlSet\Services\mbamchameleon@ProtectedRegistry ???D????????????0????????????????`???????????????????? ????????????????????? ???????????????????? ???????D?????D?????D????,?????.?????????s?????mbamchameleon Instance??????? ???????D???????????(?????????????????????????????????D????????????????s???? ?????????????D?????D???????????????????????????????????????????????????D??? ???????D???????????D??????????N??????????????D?&???????D???????e??mbamchameleon????D?????????????????????????????????s?????????D??????s???LegacyDriver??????N??D????????D?????{8ECC055D-047F-11D1-A537-0000F8753ED1}??????? ???D??????????????mbamchameleon????D?D?D?D?D?D?????????D???????????????????D???a???????s??USB\Vid_2357&Pid_0109&Rev_0200?USB\Vid_2357&Pid_0109?????D??????????????MBAMService?AegisP?WSH?WMIAdapter?WmdmPmSN?WinMgmt?Winlogon?Windows Product Activation?Windows 3.1 Migration?WebClient?VSS?VBRuntime?Userinit?Userenv?Tlntsvr?SysmonLog?Starter?SpoolerCtrs?Software Restriction Policies?Software Installation?SecurityCenter?SclgNtfy?SceSrv?SceCli?safrslv?SAFrdms?RPC?Remote Assistance