Import table
advapi32.dll
RegCreateKeyExW, LookupPrivilegeValueW, RegOpenCurrentUser, RegOpenKeyW, RegEnumValueW, RegQueryInfoKeyW, OpenProcessToken, CreateServiceW, OpenServiceW, CloseServiceHandle, RevertToSelf, QueryServiceStatusEx, SetThreadToken, StartServiceA, EqualSid, LookupPrivilegeValueA, OpenSCManagerA, OpenThreadToken, GetTokenInformation, ControlService, AdjustTokenPrivileges, DeleteService, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetSecurityDescriptorGroup, SetEntriesInAclA, CreateWellKnownSid, SetSecurityDescriptorOwner, FreeSid, RegEnumKeyExW, RegSaveKeyW, RegSetValueExW, AllocateAndInitializeSid, RegDeleteKeyW, SetNamedSecurityInfoW, RegRestoreKeyW, RegDeleteValueW, SetEntriesInAclW, RegQueryValueExW, ConvertSecurityDescriptorToStringSecurityDescriptorW, RegUnLoadKeyW, RegLoadKeyW, GetNamedSecurityInfoW, BuildTrusteeWithSidW, RegOpenKeyExW, RegQueryInfoKeyA, RegCloseKey
kernel32.dll
DllMain
ole32.dll
CoInitializeSecurity, CoUninitialize, CoCreateInstance, CoInitializeEx
psapi.dll
GetProcessImageFileNameW, GetModuleFileNameExW, EnumProcessModules
shell32.dll
SHGetSpecialFolderPathW, SHGetFolderPathW
shlwapi.dll
PathCombineW
user32.dll
LoadStringA, LoadStringW
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
wintrust.dll
CryptCATAdminAcquireContext, CryptCATAdminReleaseContext, CryptCATCatalogInfoFromContext, CryptCATAdminAddCatalog, CryptCATAdminReleaseCatalogContext
ws2_32.dll
WSCGetProviderPath, WSCDeinstallProvider, WSCEnumProtocols
Export table
FPI_AutoReloadOff
FPI_AutoReloadOn
FPI_CustomSettings
FPI_GetModuleInformation
FPI_Initialize
FPI_QuerySignatureCount
FPI_ReloadDatabases
FPI_ReportScanningStatus
FPI_ScanBootBlock
FPI_ScanFile
FPI_ScanFileEx
FPI_ScanMemory
FPI_SetProgramDirectory
FPI_SetProgramDirectoryW
FPI_Uninitialize
FPI_ValidateDatabases
FPISE_CleanSystem
FPISE_FreeBuffer
FPISE_Initialize
FPISE_RestoreObject
FPISE_ScanFile
FPISE_ScanSystem
USS_ConsistencyScanRequest
USS_ExecuteDynamicMethod
USS_Initialize
USS_IsSystemWideInfection
USS_TranslateFpiInfToFpiSE