Source: C:\Users\user\Desktop\5390d36a371f0598b86301961d5fdb329e368e7a.exe |
Code function: 0_2_00000001400031F0 SetProcessDpiAwarenessContext,CommandLineToArgvW,CreateDirectoryW,GetCurrentDirectoryW,GetModuleHandleW,GetProcAddress,GetCurrentProcess,GetModuleFileNameW,PathStripPathW,GetModuleFileNameW,LoadStringW,MessageBoxW,AllocateAndInitializeSid,CheckTokenMembership,GetLastError,FreeSid,RegGetValueW,LoadStringW,MessageBoxW,RegDeleteKeyValueW,CreateEventW,SHGetFolderPathW,CreateDirectoryW,GetLastError,FindWindowW,GetWindowThreadProcessId,OpenProcess,OpenProcessToken,CloseHandle,GetCurrentProcess,OpenProcessToken,SetLastError,GetTokenInformation,GetLastError,GetTokenInformation,SetLastError,GetTokenInformation,GetLastError,GetTokenInformation,EqualSid,CloseHandle,CloseHandle,SendMessageTimeoutW,CreateThread,WaitForSingleObject,CloseHandle,Sleep,GetSystemDirectoryW,ShellExecuteExW,WaitForSingleObject,CloseHandle,Sleep,CreateEventW,GetLastError,CloseHandle,GetLastError,GetSystemDirectoryW,ShellExecuteExW,WaitForSingleObject,GetExitCodeProcess,CloseHandle,FindWindowW,GetWindowThreadProcessId,OpenProcess,SendMessageW,TerminateProcess,CloseHandle,RegCreateKeyExW,RegSetValueExW,RegCloseKey,Sleep,SHGetFolderPathW,RegOpenKeyExW,RegCloseKey,SHGetFolderPathW,GetSystemDirectoryW,ShellExecuteExW,WaitForSingleObject,GetExitCodeProcess,SetLastError,CloseHandle,FindFirstFileW,FindClose,GetUserPreferredUILanguages,GetUserPreferredUILanguages,RegCreateKeyExW,RegSetValueExW,RegCloseKey,RegDeleteKeyW,GetWindowsDirectoryW,GetWindowsDirectoryW,GetSystemDirectoryW,CreateSymbolicLinkW,FindFirstFileW,FindClose,RemoveDirectoryW,FindFirstFileW,FindClose,RemoveDirectoryW,GetWindowsDirectoryW,GetSystemDirectoryW,SHGetFolderPathW,SHGetFolderPathW,ShellExecuteExW,WaitForSingleObject,GetExitCodeProcess,CloseHandle,SHGetFolderPathW,GetSystemDirectoryW,ShellExecuteExW,WaitForSingleObject,GetExitCodeProcess,SetLastError,CloseHandle,SHGetFolderPathW,GetSystemDirectoryW,ShellExecuteExW,WaitForSingleObject,GetExitCodeProcess,SetLastError,CloseHandle,RegCreateKeyExW,RegCloseKey,RegCreateKeyExW,RegCloseKey,SHGetFolderPathW,SHGetFolderPathW,SHGetFolderPathW,RegCreateKeyExW,RegSetValueExW,RegCloseKey,LoadStringW,MessageBoxW,GetCurrentProcess,OpenProcessToken,LookupPrivilegeValueW,AdjustTokenPrivileges,GetLastError,ExitWindowsEx,LoadStringW,MessageBoxW,RegCreateKeyExW,RegSetValueExW,RegCloseKey,LoadStringW,MessageBoxW,GetWindowsDirectoryW,Sleep,ImpersonateLoggedOnUser,DuplicateTokenEx,RevertToSelf,CreateProcessWithTokenW,CloseHandle,Clo |