Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_00401063 CryptImportKey,CryptDecrypt,CryptDestroyKey,CryptReleaseContext, | 0_2_00401063 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_00401000 EntryPoint,CryptAcquireContextA,lstrcpyW,lstrlenW,lstrcatW,GetFileAttributesW,CreateFileW,WriteFile,CloseHandle,SetFileAttributesW,GlobalFree, | 0_2_00401000 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_004017A2 GetModuleFileNameA,lstrcmpiA,RegOpenKeyExA,lstrlenA,RegSetValueExA,lstrlenA,RegSetValueExA,RegCloseKey,CopyFileA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,CryptAcquireContextA,GetLastError,GetEnvironmentVariableA,ShellExecuteA,Sleep,CryptAcquireContextA,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_2_004017A2 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_0040128D MoveFileW,CreateFileW,MoveFileW,Sleep,CreateFileMappingA,CloseHandle,CryptAcquireContextA,CloseHandle,CryptGenKey,CryptReleaseContext,CryptExportKey,CryptDestroyKey,MapViewOfFile,CryptEncrypt,CryptEncrypt,UnmapViewOfFile,CloseHandle,CryptDestroyKey,CryptReleaseContext,SetFilePointerEx,WriteFile,WriteFile,CloseHandle,SetFileAttributesW, | 0_2_0040128D |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_0040191C CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_2_0040191C |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_00401063 CryptImportKey,CryptDecrypt,CryptDestroyKey,CryptReleaseContext, | 0_1_00401063 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_00401000 EntryPoint,CryptAcquireContextA,lstrcpyW,lstrlenW,lstrcatW,GetFileAttributesW,CreateFileW,WriteFile,CloseHandle,SetFileAttributesW,GlobalFree, | 0_1_00401000 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_004017A2 GetModuleFileNameA,lstrcmpiA,RegOpenKeyExA,lstrlenA,RegSetValueExA,lstrlenA,RegSetValueExA,RegCloseKey,CopyFileA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,CryptAcquireContextA,GetLastError,GetEnvironmentVariableA,ShellExecuteA,Sleep,CryptAcquireContextA,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_1_004017A2 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_0040128D MoveFileW,CreateFileW,MoveFileW,Sleep,CreateFileMappingA,CloseHandle,CryptAcquireContextA,CloseHandle,CryptGenKey,CryptReleaseContext,CryptExportKey,CryptDestroyKey,MapViewOfFile,CryptEncrypt,CryptEncrypt,UnmapViewOfFile,CloseHandle,CryptDestroyKey,CryptReleaseContext,SetFilePointerEx,WriteFile,WriteFile,CloseHandle,SetFileAttributesW, | 0_1_0040128D |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_0040191C CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_1_0040191C |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_004014CC FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,GlobalMemoryStatus,Sleep,CreateThread,CloseHandle,lstrcmpiW,lstrlenW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,lstrcatW,SetFileAttributesW,FindNextFileW,FindClose,GlobalFree, | 0_2_004014CC |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_004014CC FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,GlobalMemoryStatus,Sleep,CreateThread,CloseHandle,lstrcmpiW,lstrlenW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,lstrcatW,SetFileAttributesW,FindNextFileW,FindClose,GlobalFree, | 0_1_004014CC |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_2_00E9A394 memset,FindFirstFileW,memset,PathRemoveFileSpecW,WerRegisterFile,FindNextFileW,FindClose, | 9_2_00E9A394 |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_2_00E95DAE FindFirstFileW, | 9_2_00E95DAE |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_1_00E9A394 memset,FindFirstFileW,memset,PathRemoveFileSpecW,WerRegisterFile,FindNextFileW,FindClose, | 9_1_00E9A394 |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_1_00E95DAE FindFirstFileW, | 9_1_00E95DAE |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: GetModuleFileNameA,lstrcmpiA,RegOpenKeyExA,lstrlenA,RegSetValueExA,lstrlenA,RegSetValueExA,RegCloseKey,CopyFileA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,CryptAcquireContextA,GetLastError,GetEnvironmentVariableA,ShellExecuteA,Sleep,CryptAcquireContextA,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_1_004017A2 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_0040128D MoveFileW,CreateFileW,MoveFileW,Sleep,CreateFileMappingA,CloseHandle,CryptAcquireContextA,CloseHandle,CryptGenKey,CryptReleaseContext,CryptExportKey,CryptDestroyKey,MapViewOfFile,CryptEncrypt,CryptEncrypt,UnmapViewOfFile,CloseHandle,CryptDestroyKey,CryptReleaseContext,SetFilePointerEx,WriteFile,WriteFile,CloseHandle,SetFileAttributesW, | 0_2_0040128D |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_0040128D MoveFileW,CreateFileW,MoveFileW,Sleep,CreateFileMappingA,CloseHandle,CryptAcquireContextA,CloseHandle,CryptGenKey,CryptReleaseContext,CryptExportKey,CryptDestroyKey,MapViewOfFile,CryptEncrypt,CryptEncrypt,UnmapViewOfFile,CloseHandle,CryptDestroyKey,CryptReleaseContext,SetFilePointerEx,WriteFile,WriteFile,CloseHandle,SetFileAttributesW, | 0_1_0040128D |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_00401063 CryptImportKey,CryptDecrypt,CryptDestroyKey,CryptReleaseContext, | 0_2_00401063 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_004017A2 GetModuleFileNameA,lstrcmpiA,RegOpenKeyExA,lstrlenA,RegSetValueExA,lstrlenA,RegSetValueExA,RegCloseKey,CopyFileA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,CryptAcquireContextA,GetLastError,GetEnvironmentVariableA,ShellExecuteA,Sleep,CryptAcquireContextA,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_2_004017A2 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_0040191C CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_2_0040191C |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_00401063 CryptImportKey,CryptDecrypt,CryptDestroyKey,CryptReleaseContext, | 0_1_00401063 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_004017A2 GetModuleFileNameA,lstrcmpiA,RegOpenKeyExA,lstrlenA,RegSetValueExA,lstrlenA,RegSetValueExA,RegCloseKey,CopyFileA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,CryptAcquireContextA,GetLastError,GetEnvironmentVariableA,ShellExecuteA,Sleep,CryptAcquireContextA,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_1_004017A2 |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_0040191C CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_1_0040191C |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00E94307 appears 246 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00EA29EC appears 34 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00E94E9D appears 328 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00EA31CA appears 74 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00EA3194 appears 116 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00E91E20 appears 34 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00E9851B appears 122 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00EA2BBA appears 262 times | |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: String function: 00EA3161 appears 176 times | |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_004014CC FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,GlobalMemoryStatus,Sleep,CreateThread,CloseHandle,lstrcmpiW,lstrlenW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,lstrcatW,SetFileAttributesW,FindNextFileW,FindClose,GlobalFree, | 0_2_004014CC |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_1_004014CC FindFirstFileW,lstrcmpW,lstrcmpW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,GlobalMemoryStatus,Sleep,CreateThread,CloseHandle,lstrcmpiW,lstrlenW,lstrcmpiW,lstrcatW,lstrlenW,lstrcatW,lstrcatW,lstrcatW,SetFileAttributesW,FindNextFileW,FindClose,GlobalFree, | 0_1_004014CC |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_2_00E9A394 memset,FindFirstFileW,memset,PathRemoveFileSpecW,WerRegisterFile,FindNextFileW,FindClose, | 9_2_00E9A394 |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_2_00E95DAE FindFirstFileW, | 9_2_00E95DAE |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_1_00E9A394 memset,FindFirstFileW,memset,PathRemoveFileSpecW,WerRegisterFile,FindNextFileW,FindClose, | 9_1_00E9A394 |
Source: C:\Users\user\AppData\Local\Microsoft\OneDrive\17.3.6816.0313_2\FileCoAuth.exe | Code function: 9_1_00E95DAE FindFirstFileW, | 9_1_00E95DAE |
Source: module.8144.18ffc90c0.400000.exe, 00000000.00000002.2315187273.0000000000EB0000.00000002.sdmp, FileCoAuth.exe, 00000009.00000002.2317512776.0000000001CA0000.00000002.sdmp | Binary or memory string: Program Manager |
Source: module.8144.18ffc90c0.400000.exe, 00000000.00000002.2315187273.0000000000EB0000.00000002.sdmp, FileCoAuth.exe, 00000009.00000002.2317512776.0000000001CA0000.00000002.sdmp | Binary or memory string: Shell_TrayWnd |
Source: module.8144.18ffc90c0.400000.exe, 00000000.00000002.2315187273.0000000000EB0000.00000002.sdmp, FileCoAuth.exe, 00000009.00000002.2317512776.0000000001CA0000.00000002.sdmp | Binary or memory string: Progman |
Source: module.8144.18ffc90c0.400000.exe, 00000000.00000002.2315187273.0000000000EB0000.00000002.sdmp, FileCoAuth.exe, 00000009.00000002.2317512776.0000000001CA0000.00000002.sdmp | Binary or memory string: Progmanlock |
Source: C:\Users\user\Desktop\module.8144.18ffc90c0.400000.exe | Code function: 0_2_004017A2 GetModuleFileNameA,lstrcmpiA,RegOpenKeyExA,lstrlenA,RegSetValueExA,lstrlenA,RegSetValueExA,RegCloseKey,CopyFileA,RegOpenKeyExA,RegQueryValueExA,RegQueryValueExA,CryptAcquireContextA,GetLastError,GetEnvironmentVariableA,ShellExecuteA,Sleep,CryptAcquireContextA,CryptGenKey,CryptExportKey,CryptExportKey,CryptDestroyKey,CryptReleaseContext,CryptAcquireContextA,CryptImportKey,CryptEncrypt,CryptEncrypt,CryptDestroyKey,KiUserExceptionDispatcher,CryptReleaseContext,RegSetValueExA,RegSetValueExA,RegCloseKey,RtlZeroMemory,RegOpenKeyExA,RegSetValueExA,RegSetValueExA,RegSetValueExA,RegCloseKey,CryptAcquireContextA,CryptImportKey,GetSystemTimeAsFileTime,FileTimeToSystemTime,GetDateFormatA,lstrlenA,MultiByteToWideChar,lstrcatA,RegCreateKeyA,lstrcatA,lstrcatA,lstrlenA,RegSetValueExA,RegCloseKey,SHChangeNotify,GetEnvironmentVariableA,ShellExecuteA,GlobalFree,SetErrorMode,Sleep,Sleep,ShellExecuteA,CreateFileA,WriteFile,CloseHandle,ShellExecuteA, | 0_2_004017A2 |