Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 000000011138 HeapCreate // DEP violance
- 000000011146 HeapDestroy //DEP Violanve
- Calls analysis:
- MSVCRT.dll.memset Hint[665]
- MSVCRT.dll.memcpy Hint[663]
- MSVCRT.dll.fopen Hint[599]
- MSVCRT.dll.fseek Hint[610] //grep...
- MSVCRT.dll.fclose Hint[588]
- MSVCRT.dll.fabs Hint[587]
- MSVCRT.dll.ceil Hint[577]
- MSVCRT.dll.malloc Hint[657]
- MSVCRT.dll.floor Hint[597]
- MSVCRT.dll.free Hint[606]
- MSVCRT.dll.ftell Hint[612]
- MSVCRT.dll.fread Hint[605]
- MSVCRT.dll.longjmp Hint[656]
- MSVCRT.dll._setjmp3 Hint[424]
- MSVCRT.dll.strlen Hint[702]
- MSVCRT.dll.exit Hint[585]
- MSVCRT.dll.__p__iob Hint[112]
- MSVCRT.dll.fprintf Hint[600]
- MSVCRT.dll.sprintf Hint[690]
- MSVCRT.dll.getenv Hint[618]
- MSVCRT.dll.sscanf Hint[693]
- MSVCRT.dll.memmove Hint[664]
- KERNEL32.dll.GetModuleHandleA Hint[503]
- KERNEL32.dll.HeapCreate Hint[676]
- KERNEL32.dll.HeapDestroy Hint[677]
- KERNEL32.dll.ExitProcess Hint[261]
- KERNEL32.dll.Sleep Hint[1067]
- KERNEL32.dll.CreateThread Hint[164]
- KERNEL32.dll.CloseHandle Hint[68]
- KERNEL32.dll.FreeLibrary Hint[333]
- KERNEL32.dll.HeapAlloc Hint[674]
- KERNEL32.dll.HeapFree Hint[678]
- KERNEL32.dll.GetProcAddress Hint[546]
- KERNEL32.dll.LoadLibraryA Hint[758]
- KERNEL32.dll.TlsAlloc Hint[1084]
- KERNEL32.dll.GetVersionExA Hint[634]
- KERNEL32.dll.EnterCriticalSection Hint[218]
- KERNEL32.dll.HeapReAlloc Hint[681]
- KERNEL32.dll.LeaveCriticalSection Hint[756]
- KERNEL32.dll.InitializeCriticalSection Hint[697]
- KERNEL32.dll.TlsGetValue Hint[1086]
- KERNEL32.dll.TlsSetValue Hint[1087]
- KERNEL32.dll.WaitForMultipleObjects Hint[1132]
- KERNEL32.dll.GetCurrentThreadId Hint[430] // get process
- KERNEL32.dll.GetCurrentProcess Hint[426]// get process
- KERNEL32.dll.GetCurrentThread Hint[429]// get process
- KERNEL32.dll.DuplicateHandle Hint[213]
- KERNEL32.dll.CreateSemaphoreA Hint[154] //To specify an access mask for the object
- KERNEL32.dll.ReleaseSemaphore Hint[897] ////To release an access mask for the object
- USER32.DLL.ShowCursor Hint[0]
- USER32.DLL.DestroyWindow Hint[0]
- USER32.DLL.InvalidateRect Hint[0]
- USER32.DLL.ShowWindow Hint[0]
- USER32.DLL.DestroyIcon Hint[0]
- USER32.DLL.FillRect Hint[0]
- USER32.DLL.BeginPaint Hint[0]
- USER32.DLL.EndPaint Hint[0]
- USER32.DLL.DefWindowProcA Hint[0]
- USER32.DLL.LoadIconA Hint[0]
- USER32.DLL.RegisterClassExA Hint[0] //Window class for subsequent use in calls to CreateWindowEx
- USER32.DLL.CreateWindowExA Hint[0] //Creates an overlapped, pop-up, or child window with an extended window style
- GDI32.DLL.GetObjectType Hint[0]
- GDI32.DLL.DeleteObject Hint[0]
- GDI32.DLL.GetObjectA Hint[0]
- GDI32.DLL.CreateCompatibleDC Hint[0]
- GDI32.DLL.GetDIBits Hint[0]
- GDI32.DLL.DeleteDC Hint[0]
- GDI32.DLL.CreateDIBSection Hint[0]
- GDI32.DLL.SelectObject Hint[0]
- GDI32.DLL.BitBlt Hint[0]
- GDI32.DLL.CreateBitmap Hint[0]
- GDI32.DLL.SetPixel Hint[0]
- GDI32.DLL.GetStockObject Hint[0]
- WINMM.DLL.timeEndPeriod Hint[0] <--- timer
- WSOCK32.DLL.closesocket Hint[0] <---socket close
- WSOCK32.DLL.WSACleanup Hint[0]
- WSOCK32.DLL.WSAStartup Hint[0]
- Note:
- int WSAStartup(
- __in WORD wVersionRequested,
- __out LPWSADATA lpWSAData
- ); //the highest version of Windows Sockets specification that the caller can use
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement