Import table
advapi32.dll
AddAccessAllowedAce, GetUserNameW, InitializeAcl, GetLengthSid, AllocateAndInitializeSid, GetCurrentHwProfileW, RegCloseKey, RegQueryValueExW, FreeSid, SetSecurityDescriptorDacl, LookupAccountNameW, ConvertSidToStringSidW, RegEnumValueW, RegEnumKeyExW, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, InitializeSecurityDescriptor, RegRestoreKeyW, RegSaveKeyW, RegUnLoadKeyW, RegLoadKeyW, RegCreateKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegOpenKeyExW
arclib.dll
ArcTk2_OpenArchive, ArcTk2_SetGlobalTempFileDirectory, ArcTk2_SetToolkitLimits, ArcTk2_Init, ArcTk2_ExtractToStream, ArcTk2_SetTypeEnabled, ArcTk2_GetNextFile, ArcTk2_CloseArchive, ArcTk2_Close, GetArcList, ArcTk2_OpenArchiveStream, ArcTk2_SetAllTypesEnabled, ArcTk2_ExtractToTempFile, ArcTk2_GetDepth, ArcVersion, GetArcFileType
crux_1_0.dll
CruxFileReadLine, CruxStrDup, CruxStrFree, CruxStrFormat, CruxFileSetAttributes, CruxInitialize, CruxTerminate, CruxStrStr, CruxFileGetAttributes, CruxStrCmp, CruxProcGetFirst, CruxProcGetFirstModule, CruxProcPPid2Native, CruxProcGetNextModule, CruxProcGetModuleClose, CruxProcGetNext, CruxProcGetClose, CruxProcGetModuleName, CruxProcGetExecutableName, CruxFileRemoveDir, CruxFileGetPos, CruxFileSetSize, CruxFileGetSize, CruxFileGetTime, CruxTimeCmp, CruxFileCreateDir, CruxStrChr, CruxUtf16ToUtf8, CruxThreadSelf, CruxThreadEqual, CruxStrRChr, CruxFileClose, CruxFileCreate, CruxFileFlush, CruxFileSeek, CruxFileFindFirst, CruxFileFindGetFullName, CruxFileExistsDir, CruxFileGetSizeByName, CruxFileFindNext, CruxFileFindClose, CruxGetLastError, CruxFileGetTimeByName, CruxFileExistsFile, CruxFileDelete, CruxFileRead, CruxFileWrite, CruxStrLen, CruxFileSetTimeByName
flipster.dll
InitFlipster, SetScanCallback, SetScanParams, Scan, GetData, Action, CleanBuffer
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
InterlockedExchange, GetACP, LoadLibraryExW, RaiseException, InterlockedCompareExchange, GetProcAddress, CreateFileW, DeviceIoControl, FormatMessageW, FreeLibrary, lstrlenA, MultiByteToWideChar, GetFileAttributesW, ExpandEnvironmentStringsW, GetLogicalDriveStringsW, GetDriveTypeW, GetPrivateProfileStringW, OutputDebugStringA, FindResourceW, GetLocaleInfoA, LoadResource, LockResource, SearchPathW, UnmapViewOfFile, CreateFileMappingW, MapViewOfFile, GetFileType, SetErrorMode, WritePrivateProfileStringW, IsDebuggerPresent, OutputDebugStringW, DebugBreak, DeleteFileW, GetProcessHeap, HeapFree, GetCurrentProcessId, OpenProcess, TerminateProcess, MoveFileExW, TryEnterCriticalSection, GetTempPathW, GetTickCount, WaitForMultipleObjects, GetOverlappedResult, CancelIo, DisconnectNamedPipe, GetThreadLocale, FileTimeToSystemTime, CreateEventW, ResetEvent, SetEvent, QueryPerformanceCounter, GetModuleFileNameW, QueryPerformanceFrequency, SetEndOfFile, SetFilePointerEx, WriteFile, ReadFile, GetFileSizeEx, GetTempFileNameW, GetCurrentThreadId, GetCurrentProcess, GetProcessAffinityMask, GetCurrentThread, SetThreadAffinityMask, Sleep, GetVersionExW, WideCharToMultiByte, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, GetComputerNameW, GetWindowsDirectoryW, GetVolumeInformationW, CreateMutexW, CloseHandle, InterlockedDecrement, ReleaseMutex, WaitForSingleObject, GetLastError, InterlockedIncrement, LocalAlloc, LocalFree, GetVersionExA, GetSystemTime, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetSystemTimeAsFileTime, SizeofResource, LoadLibraryW
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoCreateGuid, OleRun, CoInitializeEx, CoInitializeSecurity, CoCreateInstance, CoSetProxyBlanket, CoUninitialize
rpcrt4.dll
UuidToStringW, RpcStringFreeW
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathSearchAndQualifyW, SHSetValueW, SHDeleteValueW, SHDeleteKeyW
user32.dll
wsprintfW, MsgWaitForMultipleObjects, PeekMessageW, TranslateMessage, DispatchMessageW, UnregisterClassA
wininet.dll
InternetQueryDataAvailable, InternetWriteFile, HttpOpenRequestW, HttpAddRequestHeadersW, InternetCrackUrlW, InternetConnectW, HttpEndRequestW, InternetOpenW, InternetReadFile, InternetCloseHandle, InternetSetOptionW, HttpSendRequestExW, HttpSendRequestW, HttpQueryInfoW
Export table
_SetAMSTraceOptions@8
CreateMalwareSDK
CreateMalwareSDK2
CreateMalwareSDK3
InitializeMalwareSDK
UninitializeMalwareSDK
UseAMService