sub_outside(): MSVCRT.memcpy KERNEL32.GetVersion MSVCRT.sprintf KERNEL32.IsDebuggerPresent MSVCRT.strcat KERNEL32.GlobalFindAtomA KERNEL32.GlobalDeleteAtom KERNEL32.GetTickCount KERNEL32.GetCurrentProcessId |
sub_4054C8(0985): KERNEL32.GetCurrentThreadId KERNEL32.LocalFree KERNEL32.lstrlenA KERNEL32.LocalAlloc KERNEL32.GetCurrentProcessId KERNEL32.GetTempPathA KERNEL32.GetProcessHeap KERNEL32.GetVersion MSVCRT.strcat MSVCRT.sprintf KERNEL32.GetTickCount MSVCRT.rand KERNEL32.IsDebuggerPresent KERNEL32.CreateFileA KERNEL32.WriteFile KERNEL32.CloseHandle "70cg" |
sub_406D2E(09a2): MSVCRT._sleep KERNEL32.IsDebuggerPresent USER32.GetForegroundWindow KERNEL32.GetTickCount KERNEL32.GetCurrentProcessId KERNEL32.GetVersion KERNEL32.GetProcessHeap KERNEL32.GetCurrentThreadId MSVCRT.sprintf MSVCRT.strcat "value" "name" "4Yk3" "~" "ZRSH" "TxN‚e" "Á°¼´³ºÐ»²¯°¢Ø¥ÃÝ" "Á»¯¼°¸¢Ø¥Ð»²¯°¢Ø¥ÃÝ" "1o8QZ" "k*x0" |
sub_408048(0ba8): KERNEL32.GetVersion KERNEL32.IsDebuggerPresent KERNEL32.GetCurrentProcessId KERNEL32.CreateFileA KERNEL32.SetFilePointer KERNEL32.WriteFile KERNEL32.GetTickCount KERNEL32.CloseHandle |
sub_40844F(0c80): KERNEL32.GetVersion KERNEL32.CreateFileA KERNEL32.WriteFile KERNEL32.GetCurrentThreadId KERNEL32.CloseHandle KERNEL32.GetSystemDirectoryA MSVCRT.sprintf MSVCRT.strcat KERNEL32.DeleteFileA KERNEL32.WinExec |
sub_4024A8(1463): NTDLL.ZwUnmapViewOfSection |
sub_408E12(1c77): USER32.GetWindow USER32.GetClassNameA KERNEL32.GetCurrentProcessId "hJVmnIA" "p+_R'X" |
sub_4051C3(1db5): KERNEL32.GetCurrentThreadId KERNEL32.CreateFileA KERNEL32.GetVersion KERNEL32.SetFilePointer KERNEL32.WriteFile KERNEL32.CloseHandle |
sub_4037CA(1dbb): KERNEL32.GetTickCount MSVCRT.sprintf MSVCRT.strcat KERNEL32.GlobalAddAtomA |
sub_40129C(1eaf): MSVCRT.memcpy |
sub_406A40(1fd4): KERNEL32.GetCurrentProcessId USER32.GetWindowTextA KERNEL32.GetProcessHeap KERNEL32.GetCurrentThreadId KERNEL32.IsDebuggerPresent MSVCRT._sleep |
sub_408ED0(25a7): KERNEL32.GetCurrentProcessId USER32.ShowWindow KERNEL32.GetTickCount USER32.GetWindowRect USER32.CreateWindowExA KERNEL32.GetProcessHeap KERNEL32.GetCurrentThreadId GDI32.CreateFontA USER32.SendMessageA KERNEL32.IsDebuggerPresent MSVCRT.sprintf KERNEL32.GetVersion USER32.GetWindowLongA USER32.SetWindowLongA USER32.SetFocus "»·›¶¾±· " "‘¬¤¸»¦±¦" "KKQHOOK" "fX $t!E" "qA" "z.y9aM4" "3h" " oi%6" |
sub_4061F7(28b5): KERNEL32.InterlockedIncrement MSVCRT.memset KERNEL32.GetProcessHeap KERNEL32.LocalFree KERNEL32.ExpandEnvironmentStringsA MSVCRT.strcat KERNEL32.IsDebuggerPresent KERNEL32.CreateProcessA KERNEL32.CloseHandle MSVCRT.sprintf KERNEL32.GetTickCount USER32.FindWindowA KERNEL32.Sleep KERNEL32.GetCurrentProcessId USER32.GetWindowTextA KERNEL32.GetCurrentThreadId KERNEL32.CopyFileA KERNEL32.DeleteFileA KERNEL32.lstrlenA MSVCRT.strncmp KERNEL32.TerminateProcess "uyzN]QY" "X-okRecv11" " |