Suite 5
.text C:\WINDOWS\system32\services.exe[736] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9271AA 1 Byte [62]
.text C:\WINDOWS\system32\services.exe[736] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62]
.text C:\WINDOWS\system32\savedump.exe[748] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9271AA 1 Byte [62]
.text C:\WINDOWS\system32\savedump.exe[748] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[760] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9271AA 1 Byte [62]
.text C:\WINDOWS\system32\lsass.exe[760] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[948] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9271AA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[948] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1036] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9271AA 1 Byte [62]
.text C:\WINDOWS\system32\svchost.exe[1036] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtCreateFile + 6 7C91D096 4 Bytes [28, 00, 30, 00] {SUB [EAX], AL; XOR [EAX], AL}
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtCreateFile + B 7C91D09B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtMapViewOfSection + 6 7C91D506 1 Byte [28]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtMapViewOfSection + 6 7C91D506 4 Bytes [28, 03, 30, 00] {SUB [EBX], AL; XOR [EAX], AL}
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtMapViewOfSection + B 7C91D50B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenFile + 6 7C91D586 4 Bytes [68, 00, 30, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenFile + B 7C91D58B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenProcess + 6 7C91D5E6 4 Bytes [A8, 01, 30, 00] {TEST AL, 0x1; XOR [EAX], AL}
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenProcess + B 7C91D5EB 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenProcessToken + 6 7C91D5F6 4 Bytes CALL 7B9205FC
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenProcessToken + B 7C91D5FB 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D606 4 Bytes [A8, 02, 30, 00] {TEST AL, 0x2; XOR [EAX], AL}
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenProcessTokenEx + B 7C91D60B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenThread + 6 7C91D646 4 Bytes [68, 01, 30, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenThread + B 7C91D64B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenThreadToken + 6 7C91D656 4 Bytes [68, 02, 30, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenThreadToken + B 7C91D65B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D666 4 Bytes CALL 7B92066D
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtOpenThreadTokenEx + B 7C91D66B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtQueryAttributesFile + 6 7C91D6F6 4 Bytes [A8, 00, 30, 00] {TEST AL, 0x0; XOR [EAX], AL}
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtQueryAttributesFile + B 7C91D6FB 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtQueryFullAttributesFile + 6 7C91D796 4 Bytes CALL 7B92079B
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtQueryFullAttributesFile + B 7C91D79B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtSetInformationFile + 6 7C91DC46 4 Bytes [28, 01, 30, 00] {SUB [ECX], AL; XOR [EAX], AL}
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtSetInformationFile + B 7C91DC4B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtSetInformationThread + 6 7C91DC96 4 Bytes [28, 02, 30, 00] {SUB [EDX], AL; XOR [EAX], AL}
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtSetInformationThread + B 7C91DC9B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtUnmapViewOfSection + 6 7C91DEF6 1 Byte [68]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtUnmapViewOfSection + 6 7C91DEF6 4 Bytes [68, 03, 30, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!NtUnmapViewOfSection + B 7C91DEFB 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!LdrLoadDll 7C9263A3 5 Bytes JMP 003F01F8
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9271AA 1 Byte [62]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] ntdll.dll!LdrUnloadDll 7C92736B 5 Bytes JMP 003F03FC
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1072] KERNEL32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1132] ntdll.dll!RtlDosSearchPath_U + 1D1 7C9271AA 1 Byte [62]
.text C:\WINDOWS\System32\svchost.exe[1132] kernel32.dll!GetBinaryTypeW + 80 7C868C2C 1 Byte [62]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtCreateFile + 6 7C91D096 4 Bytes [28, 00, 54, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtCreateFile + B 7C91D09B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtMapViewOfSection + 6 7C91D506 1 Byte [28]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtMapViewOfSection + 6 7C91D506 4 Bytes [28, 03, 54, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtMapViewOfSection + B 7C91D50B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenFile + 6 7C91D586 4 Bytes [68, 00, 54, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenFile + B 7C91D58B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenProcess + 6 7C91D5E6 4 Bytes [A8, 01, 54, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenProcess + B 7C91D5EB 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenProcessToken + 6 7C91D5F6 4 Bytes CALL 7B9229FC
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenProcessToken + B 7C91D5FB 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenProcessTokenEx + 6 7C91D606 4 Bytes [A8, 02, 54, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenProcessTokenEx + B 7C91D60B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenThread + 6 7C91D646 4 Bytes [68, 01, 54, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenThread + B 7C91D64B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenThreadToken + 6 7C91D656 4 Bytes [68, 02, 54, 00]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenThreadToken + B 7C91D65B 1 Byte [E2]
.text C:\Documents and Settings\dzcomp\Local Settings\Application Data\Google\Chrome\Application\chrome.exe[1212] ntdll.dll!NtOpenThreadTokenEx + 6 7C91D666 4 Bytes CALL 7B922A6D