RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000 RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x0000000000000000 RDI = 0x0000000000000000 R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000 R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000 RIP = 0x0000000000200000 RFLAGS = 0x0000000000000202 Emulating: 0x0000000000200000 LEA rsi, [rel 0x20000e] RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000 RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x000000000020000e RDI = 0x0000000000000000 R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000 R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000 RIP = 0x0000000000200007 RFLAGS = 0x0000000000000202 Emulating: 0x0000000000200007 MOV rdi, rsi RAX = 0x0000000000000000 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000 RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x000000000020000e RDI = 0x000000000020000e R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000 R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000 RIP = 0x000000000020000a RFLAGS = 0x0000000000000202 Emulating: 0x000000000020000a LODSB RAX = 0x0000000000000090 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000 RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x000000000020000f RDI = 0x000000000020000e R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000 R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000 RIP = 0x000000000020000b RFLAGS = 0x0000000000000202 Emulating: 0x000000000020000b XOR al, cl RAX = 0x0000000000000090 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000 RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x000000000020000f RDI = 0x000000000020000e R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000 R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000 RIP = 0x000000000020000d RFLAGS = 0x0000000000000286 Emulating: 0x000000000020000d STOSB RAX = 0x0000000000000090 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000 RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x000000000020000f RDI = 0x000000000020000f R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000 R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000 RIP = 0x000000000020000e RFLAGS = 0x0000000000000286 Emulating: 0x000000000020000e NOP RAX = 0x0000000000000090 RCX = 0x0000000000000000 RDX = 0x0000000000000000 RBX = 0x0000000000000000 RSP = 0x0000000000101000 RBP = 0x0000000000000000 RSI = 0x000000000020000f RDI = 0x000000000020000f R8 = 0x0000000000000000 R9 = 0x0000000000000000 R10 = 0x0000000000000000 R11 = 0x0000000000000000 R12 = 0x0000000000000000 R13 = 0x0000000000000000 R14 = 0x0000000000000000 R15 = 0x0000000000000000 RIP = 0x000000000020000f RFLAGS = 0x0000000000000286 Emulating: 0x000000000020000f RETN Emulation terminated with status 0x00000002, flags: 0x4, 1 NOPs SHEMU_FLAG_WRITE_SELF