Import table
advapi32.dll
OpenProcessToken, RegEnumKeyExA, RegOpenKeyExA, RegEnumValueA, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, CryptGetHashParam, CryptAcquireContextW, CryptReleaseContext, CryptCreateHash, CryptGenRandom, CryptAcquireContextA, CryptExportKey, CryptSetKeyParam, CryptGetKeyParam, CryptDuplicateKey, CryptGetProvParam, CryptImportKey, CryptEncrypt, CryptGenKey, CryptDestroyKey, CryptDecrypt, CryptDestroyHash, RevertToSelf, ImpersonateLoggedOnUser, LookupAccountSidW, GetSidSubAuthorityCount, SetThreadToken, GetSidSubAuthority, GetSidIdentifierAuthority, RegSetValueExW, RegOpenCurrentUser, RegQueryInfoKeyW, RegCreateKeyExW, OpenSCManagerA, QueryServiceStatus, CloseServiceHandle, OpenServiceA, FreeSid, AllocateAndInitializeSid, EqualSid, GetTokenInformation, OpenThreadToken, AdjustTokenPrivileges, DuplicateTokenEx, LookupPrivilegeValueW, CryptHashData
comdlg32.dll
GetSaveFileNameW
crypt32.dll
CertFindCertificateInStore, CryptQueryObject, CertGetNameStringW, CertFreeCertificateContext, CryptMsgGetParam, CertCloseStore, CryptMsgClose
iphlpapi.dll
GetIpForwardTable, GetAdaptersInfo, NotifyRouteChange, NotifyAddrChange, GetBestRoute
kernel32.dll
Process32FirstW, Process32NextW, DuplicateHandle, GetSystemInfo, GetModuleHandleA, GetCurrentThread, GlobalAlloc, GlobalFree, GetComputerNameW, GetComputerNameExW, HeapAlloc, HeapFree, GetTickCount, GetProcessHeap, CreateToolhelp32Snapshot, FileTimeToSystemTime, ExpandEnvironmentStringsW, lstrlenW, VirtualQuery, DebugBreak, RaiseException, EnterCriticalSection, TlsAlloc, LoadLibraryA, TerminateProcess, GetExitCodeProcess, GetCurrentProcess, CreateProcessW, SetFileAttributesW, FileTimeToLocalFileTime, FindNextFileW, RemoveDirectoryW, SetCurrentDirectoryW, SetFileApisToOEM, FindClose, MoveFileW, GetCurrentDirectoryW, GetTempPathW, GetModuleFileNameW, ReadFile, CopyFileW, CreateDirectoryW, FindFirstFileW, SystemTimeToFileTime, OpenProcess, GetVersionExW, GetLocaleInfoW, GetUserDefaultLangID, GetModuleHandleW, DeleteFileW, SetLastError, WriteFile, MoveFileExW, ResetEvent, GetLastError, CreateFileW, FormatMessageW, SetEvent, GetSystemTime, GetProcAddress, MultiByteToWideChar, LoadLibraryW, WideCharToMultiByte, FreeLibrary, LocalFree, FormatMessageA, GetSystemTimeAsFileTime, InterlockedExchange, InterlockedCompareExchange, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, GetTimeZoneInformation, GetLocalTime, GetLocaleInfoA, GetUserDefaultLCID, LocalAlloc, DosDateTimeToFileTime, SetFilePointer, SetFileTime, GetFileType, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, CreateEventW, CloseHandle, TlsFree, SetThreadPriority, WaitForSingleObject, TlsSetValue, CreateThread, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, Sleep, LeaveCriticalSection
msvcp90.dll
DllMain
msvcr90.dll
DllMain
ole32.dll
CoCreateGuid, CoInitializeEx
secur32.dll
GetUserNameExW, DeleteSecurityContext, CompleteAuthToken, FreeCredentialsHandle, QueryCredentialsAttributesW, FreeContextBuffer, AcquireCredentialsHandleW, InitializeSecurityContextW
shell32.dll
SHGetFolderPathW, ShellExecuteExW, ShellExecuteExA
shlwapi.dll
PathFindFileNameA, PathUnquoteSpacesA, PathRemoveFileSpecA, PathRemoveArgsA, PathFileExistsA
user32.dll
GetSystemMetrics, wsprintfW, FindWindowW, GetTopWindow
userenv.dll
ExpandEnvironmentStringsForUserW, RefreshPolicy
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wininet.dll
InternetErrorDlg, InternetOpenW, HttpQueryInfoW, InternetSetOptionW, InternetReadFile, InternetCrackUrlW, InternetQueryOptionW, HttpQueryInfoA, InternetConnectW, HttpOpenRequestW, InternetSetStatusCallbackW, InternetReadFileExA, InternetCloseHandle, HttpSendRequestA, HttpAddRequestHeadersA
wintrust.dll
WinVerifyTrust
ws2_32.dll
WSAIoctl, WSAWaitForMultipleEvents, WSACloseEvent, WSACreateEvent, WSAResetEvent, WSAEnumNetworkEvents, WSAEventSelect
Export table
finalize
initialize
processMessage