Import table
advapi32.dll
RegCreateKeyExW, GetUserNameW, RegCloseKey, RegOpenKeyExW, RegDeleteKeyW, RegQueryValueExW, GetTraceEnableFlags, GetTraceEnableLevel, RegDisablePredefinedCache, RevertToSelf, EqualSid, ImpersonateLoggedOnUser, GetTokenInformation, OpenProcessToken, DuplicateTokenEx, RegDeleteValueW, RegQueryInfoKeyW, RegEnumKeyExW, RegEnumValueW, RegOpenKeyExA, RegQueryValueExA, TraceEvent, RegSetValueExW, OpenSCManagerW, OpenServiceW, QueryServiceStatus, CloseServiceHandle, GetSecurityDescriptorDacl, InitializeSecurityDescriptor, InitializeAcl, AllocateAndInitializeSid, AddAccessAllowedAce, FreeSid, SetSecurityDescriptorDacl, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle
dnsapi.dll
DnsQuery_A, DnsRecordListFree
kernel32.dll
OpenMutexW, MoveFileExW, CreateMutexW, CreateThread, GetSystemTimeAsFileTime, QueryPerformanceCounter, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RtlUnwind, DebugBreak, TerminateProcess, GetThreadLocale, GetUserDefaultLCID, GetSystemDefaultLCID, InterlockedExchange, LoadLibraryA, QueryDosDeviceW, InterlockedCompareExchange, GetCurrentDirectoryW, MoveFileA, SetFilePointerEx, GetDriveTypeW, GetDiskFreeSpaceExW, UnmapViewOfFile, CreateFileMappingW, MapViewOfFile, VirtualAlloc, VirtualFree, GetFileAttributesW, IsDebuggerPresent, OutputDebugStringW, GetTickCount, GetSystemDirectoryW, OpenProcess, GetProcessHeap, HeapAlloc, HeapFree, GetCurrentThread, GetThreadPriority, SetThreadPriorityBoost, SetProcessWorkingSetSize, ExpandEnvironmentStringsW, GetWindowsDirectoryW, FormatMessageW, CreateFileW, CloseHandle, DeviceIoControl, LocalFree, LocalAlloc, FreeLibrary, GetProcAddress, LoadLibraryW, InterlockedIncrement, GetCurrentProcessId, GetModuleFileNameW, GetComputerNameW, GetTimeZoneInformation, GetVersionExW, InterlockedDecrement, FileTimeToSystemTime, LocalFileTimeToFileTime, SystemTimeToFileTime, RaiseException, WriteFile, ReadFile, SetFilePointer, MoveFileW, DeleteFileW, GetLastError, SetEndOfFile, GetFileSize, WideCharToMultiByte, GetTimeFormatW, GetDateFormatW, Sleep, LockFile, UnlockFile, GetLocalTime, GetFileType, DeleteCriticalSection, SetEvent, GetVolumeInformationW, GetCurrentProcess, GetModuleHandleW, InitializeCriticalSection, CreateEventW, OpenEventW, LeaveCriticalSection, SetThreadPriority, EnterCriticalSection, GetCommandLineW, FindClose, FindFirstFileW, FindNextFileW, IsBadStringPtrW, IsBadWritePtr, MultiByteToWideChar, IsBadReadPtr, LoadLibraryExW, TerminateThread, WaitForSingleObject, ReleaseMutex, GetCurrentThreadId, WaitForMultipleObjects, ResetEvent, RemoveDirectoryW, CopyFileW, SetFileAttributesW, CreateDirectoryW, GetTempFileNameW, GetTempPathW, ResumeThread, GetSystemTime
lz32.dll
LZOpenFileW, LZRead, LZClose
msvcrt.dll
DllMain
ntdll.dll
_strnicmp, _stricmp
ole32.dll
CoCreateInstance, StgCreateDocfile, StgOpenStorage
shfolder.dll
SHGetFolderPathW
shlwapi.dll
wnsprintfW, SHDeleteKeyW, PathFindOnPathW
user32.dll
MessageBoxW, CharUpperW, LoadStringW, wsprintfW, wsprintfA
wininet.dll
InternetGetConnectedState
Export table
ApplyMicroIncrementals
CreateUpdateEvents
DebugPrintf
DebugPrintf2
DecompressDATs
GetAlerter
GetBackedUpDetection
GetBackedUpDetections
GetBackupFileNames
GetCommonShellVersion3
GetDatDelayEvents
GetDATInfo
GetDATVersion
GetDetectBUP
GetEngine2
GetEngineVersion
GetFilesStreams
GetLogger
GetLoggerEx
McShieldShuttingDown
SetDebugFile
SetDebugFlags