- GetModuleHandleW.KERNEL32(00000000), ref: 00412797
- strncpy.NTDLL(?,?), ref: 004127C7
- lstrlen.KERNEL32(?), ref: 004127D4
- CreateFileA.KERNEL32(?,00000000,00000000,00000000,00000003,00000000,00000000), ref: 004127F2
- Part of subcall function 00413DD0: lstrlen.KERNEL32(?), ref: 00413E37
- Part of subcall function 00413DD0: CharUpperBuffA.USER32(?), ref: 00413E3F
- Part of subcall function 00413DD0: lstrlen.KERNEL32(?), ref: 00413E49
- Part of subcall function 00413DD0: CharUpperBuffA.USER32(?), ref: 00413E54
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413E60
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413E7A
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413E94
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413EAE
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413EC8
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413EE2
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413EFF
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413F1C
- Part of subcall function 00413DD0: GetModuleHandleW.KERNEL32(00000000), ref: 00413F4C
- Part of subcall function 00413DD0: strncpy.NTDLL(?,?), ref: 00413F85
- Part of subcall function 00413DD0: lstrlen.KERNEL32(?), ref: 00413F95
- Part of subcall function 00413DD0: lstrlen.KERNEL32(?), ref: 00413FA3
- Part of subcall function 00413DD0: CharUpperBuffA.USER32(?), ref: 00413FAE
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413FBD
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413FD6
- Part of subcall function 00413DD0: strstr.NTDLL(?), ref: 00413FEF
- Part of subcall function 004010C0: GetModuleHandleW.KERNEL32(00000000), ref: 004010D0
- Part of subcall function 004010C0: strncpy.NTDLL(?,?), ref: 00401106
- Part of subcall function 004010C0: lstrlen.KERNEL32(?), ref: 00401116
- Part of subcall function 004010C0: MoveFileExA.KERNEL32(?,00000000,00000004(MOVEFILE_DELAY_UNTIL_REBOOT)), ref: 00401125
- Part of subcall function 004010C0: _snprintf.NTDLL ref: 00401145
- Part of subcall function 004010C0: GetEnvironmentVariableA.KERNEL32(ComSpec,?,00000104), ref: 0040115C
- Part of subcall function 004010C0: ShellExecuteA.SHELL32(00000000,00000000,?,?,00000000,00000000), ref: 00401177
- ExitProcess.KERNEL32(00000661), ref: 0041281D
- WSAStartup.WS2_32(00000202,?), ref: 00412830
- RtlGetLastWin32Error.NTDLL ref: 00412839
- Part of subcall function 00401940: VirtualAlloc.KERNEL32(00000000,0000EB59,00001000,00000004), ref: 00401970
- Part of subcall function 00401940: VirtualAlloc.KERNEL32(00000000,01010008,00001000,00000004), ref: 004019E4
- Part of subcall function 00401940: VirtualFree.KERNEL32(?,00000000,00008000), ref: 00401A18
- Part of subcall function 00401940: VirtualFree.KERNEL32(?,00000000,00008000), ref: 00401A48
- Part of subcall function 00401940: VirtualFree.KERNEL32(01010000,00000000,00008000), ref: 00401A52
- OleUninitialize.OLE32 ref: 00412A88
- Part of subcall function 00414010: CreateToolhelp32Snapshot.KERNEL32(00000002,00000000), ref: 0041401B
- Part of subcall function 00414010: memset.NTDLL(?,00000000), ref: 0041403E
- Part of subcall function 00414010: Process32FirstW.KERNEL32(?,?), ref: 00414056
- Part of subcall function 00414010: lstrcmpiW.KERNEL32(?,0041B01C), ref: 0041407C
- Part of subcall function 00414010: Process32NextW.KERNEL32(?,?), ref: 00414094
- Part of subcall function 00414010: CloseHandle.KERNEL32 ref: 004140A0
- Part of subcall function 004140C0: GetModuleHandleA.KERNEL32(0041B020), ref: 004140D7
- ExitProcess.KERNEL32(00000663), ref: 00412887
- Part of subcall function 004107C0: GetSystemTime.KERNEL32(?), ref: 004107D0
- Part of subcall function 004107C0: SystemTimeToFileTime.KERNEL32(?,?), ref: 004107E0
- Part of subcall function 004107C0: RtlTimeToSecondsSince1970.NTDLL ref: 004107F8
- SetTimer.USER32(00000000,00000000,0000000A,00413B80), ref: 004128B2
- RtlGetLastWin32Error.NTDLL ref: 004128C2
- ExitProcess.KERNEL32(00000001), ref: 004128D7
- Part of subcall function 00410BB0: strncmp.NTDLL(Anonymous Proxy, , ), ref: 00410CF3
- Part of subcall function 00410BB0: GetProcessHeap.KERNEL32 ref: 00410D84
- Part of subcall function 00410BB0: RtlFreeHeap.NTDLL ref: 00410D8B
- Part of subcall function 00401410: GetVersionExW.KERNEL32(?), ref: 00401444
- Part of subcall function 00401410: SHDeleteKeyA.SHLWAPI(80000001), ref: 0040147A
- Part of subcall function 00401410: SHDeleteKeyA.SHLWAPI(80000002), ref: 0040148D
- Part of subcall function 00401410: CopyFileA.KERNEL32(?,?,00000000), ref: 004014A9
- Part of subcall function 00401410: lstrcmpi.KERNEL32(?), ref: 004014BB
- Part of subcall function 00401410: DeleteFileA.KERNEL32 ref: 004014EC
- memset.NTDLL(?,00000000), ref: 004128FD
- GetVersionExW.KERNEL32(?), ref: 00412912
- Part of subcall function 00413930: memset.NTDLL(?,00000000), ref: 00413942
- Part of subcall function 00413930: GetCurrentHwProfileW.ADVAPI32 ref: 0041394E
- GetSystemDefaultLangID.KERNEL32(?,?,00000001), ref: 00412933
- GetSystemMetrics.USER32(00000000), ref: 00412944
- GetSystemMetrics.USER32(00000001), ref: 0041294A
- Part of subcall function 00410E10: _vsnprintf.NTDLL(ver=0.0.0.3&subid=6369&os=2600&idx=2206633207&langid=1033&width=800&height=600&ip=178.18.17.204&loc=Anonymous Proxy&isp=FiberMax Networks BV,000003FF,?,?,?,7E418F9C,00412995,?,00000000,00000000,00000000,00000003,000018E1,?,83868CF7), ref: 00410E3A
- RtlGetLastWin32Error.NTDLL ref: 0041299C
- Part of subcall function 00412660: GetProcessHeap.KERNEL32 ref: 00412677
- Part of subcall function 00412660: RtlAllocateHeap.NTDLL(?,?,7E418F9C), ref: 0041267A
- Part of subcall function 00412660: memset.NTDLL(?,00000000), ref: 0041268E
- Part of subcall function 00412660: ExitProcess.KERNEL32(00001B8B), ref: 004126B6
- Part of subcall function 00412660: GetProcessHeap.KERNEL32 ref: 004126E9
- Part of subcall function 00412660: RtlFreeHeap.NTDLL ref: 004126EC
- Part of subcall function 00412660: lstrlen.KERNEL32 ref: 00412715
- Part of subcall function 00412660: lstrlen.KERNEL32 ref: 00412737
- Part of subcall function 00412660: lstrlen.KERNEL32 ref: 00412759
- Part of subcall function 00412660: GetProcessHeap.KERNEL32 ref: 0041276A
- Part of subcall function 00412660: RtlFreeHeap.NTDLL ref: 00412771
- GetModuleHandleW.KERNEL32(00000000), ref: 004129B8
- Part of subcall function 00418310: OleInitialize.OLE32(00000000), ref: 00418315
- Part of subcall function 00418310: LoadCursorW.USER32 ref: 0041835D
- Part of subcall function 00418310: RegisterClassW.USER32 ref: 0041837F
- LocalAlloc.KERNEL32(00000040,000000D4), ref: 004129DA
- LocalAlloc.KERNEL32(00000040,00000008), ref: 004129F9
- GetSystemMetrics.USER32(00000000), ref: 00412A0C
- GetSystemMetrics.USER32(00000001), ref: 00412A12
- Part of subcall function 004183A0: DestroyWindow.USER32(00000008), ref: 004183BD
- Part of subcall function 004183A0: CreateWindowExW.USER32 ref: 00418406
- Part of subcall function 004183A0: RtlGetLastWin32Error.NTDLL ref: 00418418
- Part of subcall function 00418430: GetWindow.USER32(00000008,00000004), ref: 00418448
- Part of subcall function 00418430: EnableWindow.USER32(?,00000000), ref: 00418458
- Part of subcall function 00418430: GetMessageW.USER32(00000008,00000005), ref: 0041846F
- Part of subcall function 00418430: KiUserApcDispatcher.NTDLL(?,00000000,00000000,00000000), ref: 0041848B
- Part of subcall function 00418430: TranslateMessage.USER32(?), ref: 004184AD
- Part of subcall function 00418430: DispatchMessageW.USER32(?), ref: 004184B8
- Part of subcall function 00418430: EnableWindow.USER32(?,00000001), ref: 004184C7
- Part of subcall function 00412BC0: LocalFree.KERNEL32 ref: 00412BE3
- UnregisterClassW.USER32(59FFB769-5787-4181-A4F0-949BF67A7793,00400000), ref: 00412A82
|