Import table
advapi32.dll
SetSecurityInfo, RegCloseKey, RegOpenKeyExW, RegQueryValueExW, RegCreateKeyExW, RegSetValueExW, RegNotifyChangeKeyValue, CreateProcessAsUserW, GetLengthSid, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, CreateWellKnownSid, SetTokenInformation, CheckTokenMembership, GetTokenInformation, GetSecurityInfo, AllocateAndInitializeSid, SetEntriesInAclW, RegQueryInfoKeyW, RegEnumValueW, RegDeleteKeyW, RegDeleteValueW, RegEnumKeyExW, GetSidSubAuthorityCount, GetSidSubAuthority, DuplicateTokenEx, ConvertStringSidToSidW
gdi32.dll
CreateCompatibleBitmap, DeleteObject, SelectObject, GetDeviceCaps, GetObjectW, GetStockObject, DeleteDC, BitBlt, CreateCompatibleDC, CreateSolidBrush
kernel32.dll
DllMain
ole32.dll
OleLockRunning, CoTaskMemAlloc, CreateStreamOnHGlobal, CoGetClassObject, CLSIDFromProgID, CLSIDFromString, OleUninitialize, OleInitialize, StringFromGUID2, CoCreateGuid, CoTaskMemFree, OleRun, CoCreateInstance, CoInitialize, CoTaskMemRealloc
psapi.dll
GetModuleFileNameExW
rpcrt4.dll
UuidCreate
shell32.dll
SHBrowseForFolderW, Shell_NotifyIconW, SHCreateDirectoryExA, CommandLineToArgvW, SHGetSpecialFolderLocation, SHGetPathFromIDListW, ShellExecuteExW
shlwapi.dll
PathRemoveFileSpecA
user32.dll
InvalidateRgn, GetSysColor, SetWindowTextW, ShowWindow, GetWindowTextLengthW, IsWindowVisible, SystemParametersInfoW, CreateAcceleratorTableW, TranslateMessage, ReleaseCapture, SetForegroundWindow, RedrawWindow, GetWindow, IsWindowEnabled, IsChild, MoveWindow, EnableWindow, GetParent, IsWindow, PostMessageA, DestroyWindow, DestroyAcceleratorTable, CreateWindowExA, CharLowerW, PostMessageW, GetDesktopWindow, MessageBoxW, GetWindowTextW, GetClassNameW, EnumChildWindows, GetWindowThreadProcessId, EnumWindows, ExitWindowsEx, GetClientRect, GetWindowRect, GetMessageW, GetDlgItem, SetFocus, DefWindowProcA, SetCapture, SetWindowPos, LoadIconW, SetTimer, RegisterClassW, SendMessageTimeoutW, FindWindowExW, InvalidateRect, ReleaseDC, GetDC, EndPaint, BeginPaint, LoadCursorW, CharNextW, GetClassInfoExW, UnregisterClassA, wsprintfW, MsgWaitForMultipleObjects, PeekMessageW, DispatchMessageW, ScreenToClient, FillRect, ClientToScreen, GetFocus, FindWindowW, GetWindowPlacement, LoadImageW, SendMessageW, CallWindowProcW, DefWindowProcW, GetWindowLongW, SetWindowLongW, CreateWindowExW, RegisterClassExW, RegisterWindowMessageW, SetWindowLongA, KillTimer
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
wininet.dll
InternetSetStatusCallback, InternetGetCookieW, InternetCloseHandle, InternetCrackUrlA, InternetConnectA, HttpOpenRequestA, HttpAddRequestHeadersA, HttpSendRequestA, HttpQueryInfoA, InternetReadFileExA, InternetOpenA
Export table
CreateActionEngine
Run
RunPlug