sub_outside(): KERNEL32.LoadLibraryA KERNEL32.GetProcAddress KERNEL32.FreeLibrary KERNEL32.TerminateProcess KERNEL32.ResumeThread KERNEL32.GetModuleFileNameA KERNEL32.GetModuleHandleA KERNEL32.VirtualFree NTDLL.RtlFreeHeap KERNEL32.HeapDestroy |
_WinMain16(): KERNEL32.GetModuleFileNameA KERNEL32.SetFileAttributesA KERNEL32.GetModuleHandleA KERNEL32.GetProcAddress KERNEL32.TerminateProcess KERNEL32.ResumeThread |
sub_401820(086f): KERNEL32.VirtualProtectEx NTDLL.ZwUnmapViewOfSection KERNEL32.VirtualAllocEx KERNEL32.GetModuleHandleA KERNEL32.GetProcAddress KERNEL32.SetThreadContext "WriteProcessMemory" "kernel32.dll" |
sub_401700(460c): KERNEL32.CreateProcessA KERNEL32.GetThreadContext KERNEL32.ReadProcessMemory KERNEL32.VirtualQueryEx |
sub_4010B0(4b6c): "Fsd789f 7s89d67f78 as6d78f6 as78dytg i4"... |
sub_408420(9db0): KERNEL32.GetModuleHandleA KERNEL32.GetProcAddress "kernel32.dll" |
sub_408400(9db0): KERNEL32.GetModuleHandleA KERNEL32.GetProcAddress "ZwUnmapViewOfSection" "ntdll.dll" |