You are on page 1of 4

---------------EX--------------------------------------

Call from: 9051DA | API: 7C809AF1 | NAME: VirtualAlloc


-------------------------------------------------------
---------------EX--------------------------------------
Call from: 90636D | API: 7C809B84 | NAME: VirtualFree
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9064DB | API: 7C809AF1 | NAME: VirtualAlloc
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99365C | API: 7C801D7B | NAME: LoadLibraryA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 993A56 | API: 7C801D7B | NAME: LoadLibraryA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 993D25 | API: 7C80A874 | NAME: GetLocalTime
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9950FD | API: 77D5085C | NAME: MessageBoxExA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 995E15 | API: 77DCBCC3 | NAME: RegCreateKeyA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 995E34 | API: 77DC4CB0 | NAME: RegFlushKey
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 995E53 | API: 77DAEAD7 | NAME: RegSetValueExA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 995E72 | API: 77DA6C17 | NAME: RegCloseKey
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 995E91 | API: 77DA7AAB | NAME: RegQueryValueExA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 996CE6 | API: 7C801A28 | NAME: CreateFileA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99DBA6 | API: 7C810C6D | NAME: GetCommandLineA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99DFE0 | API: 7C809EA1 | NAME: IsBadReadPtr
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99E002 | API: 7C809F19 | NAME: IsBadWritePtr
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F3E5 | API: 7C80A0B7 | NAME: SetEvent
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F403 | API: 7C802530 | NAME: WaitForSingleObject
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F421 | API: 7C813366 | NAME: CreateEventA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F43F | API: 7C801D7B | NAME: LoadLibraryA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F45D | API: 7C80AC7E | NAME: FreeLibrary
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F47B | API: 7C80AE40 | NAME: GetProcAddress
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F499 | API: 7C81584A | NAME: GetEnvironmentVariableA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F4B7 | API: 77D1A8AD | NAME: wsprintfA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F4D5 | API: 7C811752 | NAME: GetVersion
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F4F3 | API: 7C801A28 | NAME: CreateFileA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F511 | API: 7C81D20A | NAME: ExitProcess
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F52F | API: 7C801629 | NAME: DeviceIoControl
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F546 | API: 77DAEFB8 | NAME: RegOpenKeyA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F564 | API: 7C809BE7 | NAME: CloseHandle
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F582 | API: 7C809B84 | NAME: VirtualFree
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 99F5A0 | API: 7C802446 | NAME: Sleep
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9A4B5C | API: 7C810830 | NAME: GetVersionExA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9A29CE | API: 77DA6C17 | NAME: RegCloseKey
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9A2A48 | API: 77DA7AAB | NAME: RegQueryValueExA
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9A2A61 | API: 7C83794D | NAME: GetNativeSystemInfo
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9A4C0E | API: 76B14E4F | NAME: timeGetTime
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9A8D8C | API: 7C802446 | NAME: Sleep
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9B349A | API: 7C801A28 | NAME: CreateFileA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9B35D2 | API: 7C810FEF | NAME: GetFileSize
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9B3743 | API: 7C809AF1 | NAME: VirtualAlloc
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9B38B2 | API: 7C801812 | NAME: ReadFile
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9B39DA | API: 7C810830 | NAME: GetVersionExA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9B3C93 | API: 7C81F006 | NAME: GetSystemDirectoryA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9B4546 | API: 7C809BE7 | NAME: CloseHandle
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C2C14 | API: 7C92D640 | NAME: NtOpenThread
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C3255 | API: 76B14E4F | NAME: timeGetTime
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9EC0AE | API: 7C865140 | NAME: Process32Next
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9F8452 | API: 7C809EA1 | NAME: IsBadReadPtr
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0B59 | API: 7C80BB41 | NAME: lstrcmpiA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0C60 | API: 7C809EA1 | NAME: IsBadReadPtr
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C0ED2 | API: 7C92D910 | NAME: NtQuerySystemInformation
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0B59 | API: 7C80BB41 | NAME: lstrcmpiA
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C0ED2 | API: 7C92D910 | NAME: NtQuerySystemInformation
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0B59 | API: 7C80BB41 | NAME: lstrcmpiA
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C0ED2 | API: 7C92D910 | NAME: NtQuerySystemInformation
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0B59 | API: 7C80BB41 | NAME: lstrcmpiA
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C0ED2 | API: 7C92D910 | NAME: NtQuerySystemInformation
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0B59 | API: 7C80BB41 | NAME: lstrcmpiA
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C0ED2 | API: 7C92D910 | NAME: NtQuerySystemInformation
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0B59 | API: 7C80BB41 | NAME: lstrcmpiA
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C0ED2 | API: 7C92D910 | NAME: NtQuerySystemInformation
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9C0B59 | API: 7C80BB41 | NAME: lstrcmpiA
-------------------------------------------------------
---------------GPA---------------------------------
Call from: 9C0ED2 | API: 7C92D910 | NAME: NtQuerySystemInformation
-------------------------------------------------------
---------------EX--------------------------------------
Call from: 9FFE37 | API: 7C92D7E0 | NAME: ZwQueryInformationProcess
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A037D0 | API: 7C92DC90 | NAME: ZwSetInformationThread
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A09F54 | API: 7C92D7E0 | NAME: ZwQueryInformationProcess
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A11903 | API: 7C809F19 | NAME: IsBadWritePtr
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A11A53 | API: 7C96FFE3 | NAME: DbgUiRemoteBreakin
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A11F55 | API: 7C943BB8 | NAME: LdrShutdownProcess
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A12229 | API: 7C92120E | NAME: DbgBreakPoint
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A1A1FD | API: 7C8140DE | NAME: GetCurrentDirectoryA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A1A633 | API: 7C8360E5 | NAME: SetCurrentDirectoryA
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A174F3 | API: 7C80AC61 | NAME: GetProcessHeap
-------------------------------------------------------
---------------GPA---------------------------------
Call from: A178F8 | API: 7C9300A4 | NAME: RtlAllocateHeap
-------------------------------------------------------
---------------GPA---------------------------------
Call from: A2C32C | API: 76C673E9 | NAME: CheckSumMappedFile
-------------------------------------------------------
---------------EX--------------------------------------
Call from: A43C85 | API: 7C80A0B7 | NAME: SetEvent
-------------------------------------------------------

You might also like