Import table
advapi32.dll
RegisterEventSourceA, RegNotifyChangeKeyValue, RegCreateKeyExW, RegSetValueExW, RegDeleteValueW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegQueryValueExW, RegCloseKey, RegOpenKeyExW, RegEnumKeyExW, RegDeleteKeyW, RegEnumValueW, RegEnumKeyW, SetSecurityInfo, DeleteAce, GetAce, GetAclInformation, GetSecurityInfo, OpenProcessToken, OpenThreadToken, AddAce, InitializeAcl, GetLengthSid, GetTokenInformation, DeregisterEventSource, ReportEventA
imagehlp.dll
ImageDirectoryEntryToData
kernel32.dll
DllMain
ole32.dll
CoUninitialize, CoInitialize, CoCreateInstance
psapi.dll
GetModuleInformation, EnumProcessModules
rpcrt4.dll
UuidToStringW, RpcStringFreeW
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
PathAddExtensionW, PathAppendW, PathFindExtensionW, PathRemoveExtensionW, PathStripToRootW, PathFileExistsW, PathStripPathW, PathFindFileNameW, PathIsDirectoryW, PathRemoveFileSpecW, StrCmpW
user32.dll
GetWindowTextW, FindWindowW, SendMessageW, GetUserObjectInformationW, GetProcessWindowStation, GetWindowLongW, MessageBoxA, UnregisterClassA, LoadStringA, EndDialog, SetWindowLongW, IsWindow, GetDesktopWindow, GetClassNameA, KillTimer, GetDlgItem, GetClassNameW, RegisterWindowMessageW, CallNextHookEx
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
Export table
InitMonitor
ProtectedDebugProc
ProtectedShellProc
TrackFile