Skip to content

Instantly share code, notes, and snippets.

@marek-saji
Created April 15, 2015 09:09
Show Gist options
  • Save marek-saji/a7eab158883e49592c79 to your computer and use it in GitHub Desktop.
Save marek-saji/a7eab158883e49592c79 to your computer and use it in GitHub Desktop.
0x0041ce10: int $3
Modules:
Module Address Debug info Name (146 modules)
PE 400000- 4b1000 Export maelstrom
PE 1c20000- 1c45000 Deferred chrome_elf
PE 1c50000- 405b000 Export chrome
ELF 7b800000-7ba62000 Deferred kernel32<elf>
\-PE 7b810000-7ba62000 \ kernel32
ELF 7bc00000-7bce7000 Dwarf ntdll<elf>
\-PE 7bc10000-7bce7000 \ ntdll
ELF 7bf00000-7bf04000 Deferred <wine-loader>
ELF 7e46a000-7e48f000 Deferred imm32<elf>
\-PE 7e470000-7e48f000 \ imm32
ELF 7e58b000-7e5b4000 Deferred libexpat.so.1
ELF 7e5b4000-7e5f0000 Deferred libfontconfig.so.1
ELF 7e5f0000-7e61c000 Deferred libpng12.so.0
ELF 7e61c000-7e636000 Deferred libz.so.1
ELF 7e636000-7e6e6000 Deferred libfreetype.so.6
ELF 7e711000-7e729000 Deferred wtsapi32<elf>
\-PE 7e720000-7e729000 \ wtsapi32
ELF 7e729000-7e742000 Deferred userenv<elf>
\-PE 7e730000-7e742000 \ userenv
ELF 7e742000-7e7bc000 Deferred shlwapi<elf>
\-PE 7e750000-7e7bc000 \ shlwapi
ELF 7e7bc000-7e7e7000 Deferred msacm32<elf>
\-PE 7e7c0000-7e7e7000 \ msacm32
ELF 7e7e7000-7e86b000 Deferred rpcrt4<elf>
\-PE 7e7f0000-7e86b000 \ rpcrt4
ELF 7e86b000-7e9ae000 Deferred ole32<elf>
\-PE 7e880000-7e9ae000 \ ole32
ELF 7e9ae000-7eacd000 Deferred gdi32<elf>
\-PE 7e9c0000-7eacd000 \ gdi32
ELF 7eacd000-7ec29000 Deferred user32<elf>
\-PE 7eae0000-7ec29000 \ user32
ELF 7ec29000-7ece2000 Deferred winmm<elf>
\-PE 7ec30000-7ece2000 \ winmm
ELF 7ece2000-7ed5d000 Deferred advapi32<elf>
\-PE 7ecf0000-7ed5d000 \ advapi32
ELF 7ed5d000-7ed6a000 Deferred libnss_files.so.2
ELF 7ed6a000-7ed76000 Deferred libnss_nis.so.2
ELF 7ed76000-7ed8f000 Deferred libnsl.so.1
ELF 7ef8f000-7efd5000 Deferred libm.so.6
ELF 7efe6000-7f000000 Deferred version<elf>
\-PE 7eff0000-7f000000 \ version
ELF f14f2000-f150b000 Deferred msacm32<elf>
\-PE f1500000-f150b000 \ msacm32
ELF f150b000-f154b000 Deferred winhttp<elf>
\-PE f1510000-f154b000 \ winhttp
ELF f154b000-f1641000 Deferred libasound.so.2
ELF f164f000-f166c000 Deferred jsproxy<elf>
\-PE f1650000-f166c000 \ jsproxy
ELF f166c000-f169e000 Deferred winealsa<elf>
\-PE f1670000-f169e000 \ winealsa
ELF f169e000-f16ca000 Deferred msvfw32<elf>
\-PE f16a0000-f16ca000 \ msvfw32
ELF f16ca000-f1714000 Deferred dsound<elf>
\-PE f16d0000-f1714000 \ dsound
ELF f1714000-f180e000 Deferred quartz<elf>
\-PE f1730000-f180e000 \ quartz
ELF f1b89000-f1b9e000 Deferred avicap32<elf>
\-PE f1b90000-f1b9e000 \ avicap32
ELF f5b9f000-f5ba8000 Deferred libogg.so.0
ELF f5ba8000-f5bd3000 Deferred libvorbis.so.0
ELF f5bd3000-f5d4a000 Deferred libvorbisenc.so.2
ELF f5d4a000-f5d82000 Deferred libflac.so.8
ELF f5d82000-f5d8b000 Deferred librt.so.1
ELF f5d8b000-f5dfc000 Deferred libsndfile.so.1
ELF f5dfc000-f5e06000 Deferred libwrap.so.0
ELF f5e06000-f5e5c000 Deferred libdbus-1.so.3
ELF f5e5c000-f5ed3000 Deferred libpulsecommon-4.0.so
ELF f5ed3000-f5ede000 Deferred libjson-c.so.2
ELF f5ede000-f5f34000 Deferred libpulse.so.0
ELF f5f37000-f5f5f000 Deferred devenum<elf>
\-PE f5f40000-f5f5f000 \ devenum
ELF f5f5f000-f5f87000 Deferred winepulse<elf>
\-PE f5f70000-f5f87000 \ winepulse
ELF f5f87000-f5fbe000 Deferred msctf<elf>
\-PE f5f90000-f5fbe000 \ msctf
ELF f5fbe000-f5fd5000 Deferred libresolv.so.2
ELF f5fdc000-f6000000 Deferred mmdevapi<elf>
\-PE f5fe0000-f6000000 \ mmdevapi
ELF f6702000-f6709000 Deferred libasyncns.so.0
ELF f6709000-f6710000 Deferred libnss_dns.so.2
ELF f6710000-f6781000 Deferred setupapi<elf>
\-PE f6720000-f6781000 \ setupapi
ELF f67c7000-f67f7000 Deferred p11-kit-trust.so
ELF f67f7000-f6800000 Deferred libffi.so.6
ELF f6800000-f6806000 Deferred libgpg-error.so.0
ELF f6806000-f6842000 Deferred libp11-kit.so.0
ELF f6842000-f6856000 Deferred libtasn1.so.6
ELF f6856000-f68e8000 Deferred libgcrypt.so.11
ELF f68e8000-f69ae000 Deferred libgnutls.so.26
ELF f69b1000-f69c6000 Deferred wlanapi<elf>
\-PE f69c0000-f69c6000 \ wlanapi
ELF f69c6000-f69d9000 Deferred gnome-keyring-pkcs11.so
ELF f69d9000-f6a10000 Deferred uxtheme<elf>
\-PE f69e0000-f6a10000 \ uxtheme
ELF f6a10000-f6a26000 Deferred hid<elf>
\-PE f6a20000-f6a26000 \ hid
ELF f6a26000-f6a77000 Deferred oleacc<elf>
\-PE f6a30000-f6a77000 \ oleacc
ELF f6a77000-f6aaa000 Deferred secur32<elf>
\-PE f6a80000-f6aaa000 \ secur32
ELF f6aaa000-f6b7a000 Deferred crypt32<elf>
\-PE f6ab0000-f6b7a000 \ crypt32
ELF f6b7a000-f6bb1000 Deferred wintrust<elf>
\-PE f6b80000-f6bb1000 \ wintrust
ELF f6bb1000-f6bea000 Deferred ws2_32<elf>
\-PE f6bc0000-f6bea000 \ ws2_32
ELF f6bea000-f6c11000 Deferred iphlpapi<elf>
\-PE f6bf0000-f6c11000 \ iphlpapi
ELF f6c11000-f6c40000 Deferred netapi32<elf>
\-PE f6c20000-f6c40000 \ netapi32
ELF f6c40000-f6d4b000 Deferred comctl32<elf>
\-PE f6c50000-f6d4b000 \ comctl32
ELF f6d4b000-f6d7b000 Deferred credui<elf>
\-PE f6d50000-f6d7b000 \ credui
ELF f6d7b000-f6ec0000 Deferred oleaut32<elf>
\-PE f6d90000-f6ec0000 \ oleaut32
ELF f6ec0000-f6f04000 Deferred usp10<elf>
\-PE f6ed0000-f6f04000 \ usp10
ELF f6f04000-f6f0b000 Deferred libxfixes.so.3
ELF f6f0b000-f6f16000 Deferred libxcursor.so.1
ELF f6f16000-f6f28000 Deferred libxi.so.6
ELF f6f28000-f6f2c000 Deferred libxcomposite.so.1
ELF f6f2c000-f6f37000 Deferred libxrandr.so.2
ELF f6f37000-f6f43000 Deferred libxrender.so.1
ELF f6f43000-f6f49000 Deferred libxxf86vm.so.1
ELF f6f49000-f6f4d000 Deferred libxinerama.so.1
ELF f6f4d000-f6f6f000 Deferred libxcb.so.1
ELF f6f6f000-f70ba000 Deferred libx11.so.6
ELF f70ba000-f70d1000 Deferred ntdsapi<elf>
\-PE f70c0000-f70d1000 \ ntdsapi
ELF f70d1000-f70e5000 Deferred psapi<elf>
\-PE f70e0000-f70e5000 \ psapi
ELF f70e5000-f7179000 Deferred winex11<elf>
\-PE f70f0000-f7179000 \ winex11
ELF f7179000-f73b0000 Deferred shell32<elf>
\-PE f7190000-f73b0000 \ shell32
ELF f73b2000-f73bb000 Deferred libnss_compat.so.2
ELF f73bc000-f7569000 Dwarf libc.so.6
ELF f7569000-f756e000 Deferred libdl.so.2
ELF f756f000-f758c000 Dwarf libpthread.so.0
ELF f7592000-f7599000 Deferred libxdmcp.so.6
ELF f7599000-f759d000 Deferred libxau.so.6
ELF f759d000-f75b0000 Deferred libxext.so.6
ELF f75b7000-f776d000 Dwarf libwine.so.1
ELF f776f000-f7791000 Deferred ld-linux.so.2
ELF f7791000-f7792000 Deferred [vdso].so
Threads:
process tid prio (all id:s are in hex)
00000008 winecfg.exe
00000009 0
0000000e services.exe
0000001d 0
0000001c 0
00000016 0
00000014 0
00000010 0
0000000f 0
00000012 winedevice.exe
0000001b 0
00000018 0
00000017 0
00000013 0
00000019 plugplay.exe
0000001f 0
0000001e 0
0000001a 0
00000020 explorer.exe
00000021 0
00000022 winecfg.exe
00000023 0
00000026 (D) C:\users\saji\Local Settings\Application Data\Maelstrom\Application\maelstrom.exe
00000055 0
00000054 0
0000004f 0
0000004e 0
0000004d 0
0000004c 0
0000004b 15
0000004a 0
00000025 0
0000000d 0
0000000b 0
00000047 0
00000046 0
00000045 0
00000044 0
00000043 0
00000042 0
00000041 0
00000040 0
0000003f 0
0000003e 0
0000003d 0
0000003c 0
0000003b 0
0000003a 0
00000039 0
00000038 0
00000037 0
00000036 0
00000035 0
00000034 0 <==
00000033 0
00000032 0
00000031 0
00000030 0
0000002f 0
0000002e 0
0000002d 0
0000002c 0
0000002b 0
0000002a 0
00000029 0
00000028 0
00000027 0
00000056 maelstrom.exe
00000057 0
System information:
Wine build: wine-1.7.38
Platform: i386 (WOW64)
Host system: Linux
Host version: 3.16.0-33-generic
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment