Import table
advapi32.dll
GetTokenInformation, RegCreateKeyA, CryptHashData, GetSecurityDescriptorDacl, CryptGetUserKey, CryptDestroyHash, CryptDecrypt, GetLengthSid, CryptDestroyKey, CryptGenKey, IsValidSid, SetEntriesInAclW, AddAccessAllowedAce, CryptCreateHash, CryptEncrypt, InitializeAcl, CryptGetProvParam, CryptSignHashW, AddAccessDeniedAce, CryptReleaseContext, CryptDeriveKey, CryptVerifySignatureW, CryptSetProvParam, CryptAcquireContextW, CryptGetHashParam, SetSecurityInfo, RegCreateKeyW, RevertToSelf, QueryServiceStatusEx, ImpersonateLoggedOnUser, QueryServiceStatus, StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, LookupAccountSidW, AdjustTokenPrivileges, LookupPrivilegeValueW, CreateProcessAsUserW, RegNotifyChangeKeyValue, FreeSid, RegEnumValueW, AllocateAndInitializeSid, RegDeleteValueA, RegCreateKeyExA, RegEnumKeyExA, EqualSid, RegSetValueExA, OpenProcessToken, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegEnumKeyExW, RegOpenKeyExW, RegDeleteValueW, RegOpenKeyExA, SetSecurityDescriptorDacl, RegDeleteKeyW, InitializeSecurityDescriptor, RegQueryInfoKeyW, RegQueryValueExA, RegCreateKeyExW
kernel32.dll
GetCurrentThreadId, ReleaseMutex, DeleteFileW, GetCurrentProcessId, SetFileAttributesW, GetCurrentProcess, SetEvent, GetTickCount, IsBadReadPtr, GlobalAlloc, GetSystemDirectoryW, LoadLibraryW, OpenMutexW, GlobalFree, LocalAlloc, CreateEventW, WTSGetActiveConsoleSessionId, OpenEventW, LocalFree, OpenProcess, SetConsoleCtrlHandler, Sleep, IsBadWritePtr, SetLastError, SetProcessWorkingSetSize, lstrlenA, SetThreadLocale, CreateProcessW, OpenThread, HeapAlloc, SystemTimeToFileTime, FindNextFileW, GetProcessHeap, FileTimeToSystemTime, FileTimeToLocalFileTime, GetVersionExA, LoadLibraryA, GetSystemDirectoryA, GetShortPathNameA, Module32Next, Module32First, CreateToolhelp32Snapshot, FindFirstFileA, GetEnvironmentVariableW, InterlockedExchange, SwitchToThread, InterlockedCompareExchange, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetModuleFileNameA, GetStartupInfoW, GetFileType, SetHandleCount, LCMapStringW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, IsValidCodePage, GetOEMCP, GetPrivateProfileStructA, RemoveDirectoryW, GetLocalTime, GetPrivateProfileStringA, FindClose, GetCurrentDirectoryW, CreateFileW, ReadFile, GetFileAttributesW, WriteFile, GetWindowsDirectoryA, OutputDebugStringW, FlushFileBuffers, WaitForSingleObject, CreateDirectoryW, MoveFileExW, WritePrivateProfileStructA, SetFilePointer, FindFirstFileW, GetFileSize, CreateFileA, CloseHandle, GetShortPathNameW, DeleteCriticalSection, lstrcmpiW, WaitForMultipleObjects, EnterCriticalSection, GetProcAddress, GetThreadLocale, GetLastError, RaiseException, lstrlenW, MultiByteToWideChar, GetACP, GetModuleFileNameW, LeaveCriticalSection, GetVersionExW, SizeofResource, InitializeCriticalSectionAndSpinCount, WideCharToMultiByte, InitializeCriticalSection, GetModuleHandleW, InterlockedDecrement, InterlockedIncrement, LoadLibraryExW, LoadResource, FreeLibrary, FindResourceW, GetLocaleInfoA, CreateMutexW, GetConsoleCP, GetConsoleMode, GetStringTypeW, SetStdHandle, WriteConsoleW, HeapFree, GetCPInfo, GetStdHandle, ExitProcess, HeapCreate, IsProcessorFeaturePresent, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, RtlUnwind, GetCommandLineA, CreateThread, ExitThread, GetSystemTimeAsFileTime, DecodePointer, EncodePointer, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, HeapSize, HeapReAlloc, HeapDestroy
ole32.dll
CoInitializeEx, CreateBindCtx, CoRevokeClassObject, CLSIDFromString, CoCreateInstance, StringFromGUID2, CoGetClassObject, CoTaskMemFree, CoTaskMemRealloc, CoUninitialize, CoRegisterClassObject, CoTaskMemAlloc
psapi.dll
EnumProcessModules, EnumProcesses, GetModuleBaseNameW
shell32.dll
SHGetSpecialFolderLocation, SHGetMalloc, SHGetPathFromIDListW, SHGetFolderPathW
shlwapi.dll
PathFileExistsW, PathAppendW
urlmon.dll
MkParseDisplayNameEx
user32.dll
RegisterWindowMessageW, GetMessageW, TranslateMessage, SetTimer, GetSystemMetrics, LoadStringW, LoadImageW, DispatchMessageW, CharNextW, wsprintfW, PostThreadMessageW, KillTimer, LoadIconW, LoadBitmapW
wintrust.dll
WinVerifyTrust
wtsapi32.dll
WTSFreeMemory, WTSEnumerateSessionsW
Export table
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
McPlugInControlHandler
McPlugInMain