_WinMain16(): KERNEL32.GetModuleFileNameA KERNEL32.SetFileAttributesA KERNEL32.VirtualAlloc KERNEL32.TerminateProcess KERNEL32.GetModuleHandleA KERNEL32.GetProcAddress KERNEL32.ResumeThread |
sub_outside(): KERNEL32.TerminateProcess KERNEL32.ResumeThread KERNEL32.GetModuleHandleA KERNEL32.VirtualFree NTDLL.RtlFreeHeap KERNEL32.HeapDestroy |
sub_4015A0(460c): KERNEL32.CreateProcessA KERNEL32.GetThreadContext KERNEL32.ReadProcessMemory KERNEL32.VirtualQueryEx |
sub_4016C0(83ae): KERNEL32.VirtualProtectEx KERNEL32.GetModuleHandleA KERNEL32.GetProcAddress KERNEL32.VirtualAllocEx KERNEL32.SetThreadContext "ZwUnmapViewOfSection" "ntdll.dll" "gjfdktnremtn,mrentn mtn,mrewtn ,mrewn,m"... "WriteProcessMemory" "kernel32.dll" |
sub_408270(9db0): KERNEL32.GetModuleHandleA KERNEL32.GetProcAddress "SetThreadContext" "kernel32.dll" |