Import table
advapi32.dll
RegisterEventSourceA, RegEnumKeyExW, RegDeleteKeyW, RegEnumKeyW, RegEnumValueW, SetSecurityInfo, DeleteAce, GetAce, RegCreateKeyExW, RegNotifyChangeKeyValue, RegDeleteValueW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, GetAclInformation, GetSecurityInfo, OpenProcessToken, OpenThreadToken, AddAce, InitializeAcl, GetLengthSid, GetTokenInformation, DeregisterEventSource, ReportEventA
imagehlp.dll
ImageDirectoryEntryToData
kernel32.dll
DllMain
ole32.dll
CoCreateInstance, CoInitialize, CoUninitialize
psapi.dll
EnumProcessModules, GetModuleInformation
rpcrt4.dll
UuidCreate, UuidToStringW, RpcStringFreeW
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
PathAppendW, PathStripPathW, PathFileExistsW, PathRemoveExtensionW, PathRenameExtensionW, StrCmpW, PathFindExtensionW, PathAddExtensionW, PathFindFileNameW, PathIsDirectoryW, PathIsFileSpecW
user32.dll
KillTimer, CallNextHookEx, LoadStringA, MessageBoxA, GetDesktopWindow, GetClassNameA, IsWindow, GetClassNameW, RegisterWindowMessageW, GetProcessWindowStation, GetUserObjectInformationW
winhttp.dll
WinHttpReadData, WinHttpQueryHeaders, WinHttpAddRequestHeaders, WinHttpConnect, WinHttpSetStatusCallback, WinHttpSendRequest, WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpOpenRequest, WinHttpSetOption, WinHttpReceiveResponse, WinHttpCloseHandle, WinHttpOpen, WinHttpQueryDataAvailable
Export table
InitMonitor
ProtectedDebugProc
ProtectedShellProc