Import table
advapi32.dll
AddAce, ReportEventA, DeregisterEventSource, RegEnumKeyW, RegEnumValueW, RegEnumKeyExW, RegNotifyChangeKeyValue, RegDeleteKeyW, RegCreateKeyExW, RegSetValueExW, RegDeleteValueW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, RegQueryValueExW, RegCloseKey, RegOpenKeyExW, SetSecurityInfo, DeleteAce, GetAce, GetAclInformation, GetSecurityInfo, OpenProcessToken, OpenThreadToken, GetTokenInformation, InitializeAcl, GetLengthSid, RegisterEventSourceA
imagehlp.dll
ImageDirectoryEntryToData
kernel32.dll
DllMain
ole32.dll
CoInitializeSecurity, CoUninitialize, CoInitializeEx, CoInitialize, CoCreateInstance, CLSIDFromString
psapi.dll
GetModuleInformation, EnumProcessModules, GetModuleFileNameExW
rpcrt4.dll
UuidToStringW, RpcStringFreeW
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
PathStripPathW, PathAddExtensionW, PathAppendW, PathFileExistsW, PathFindFileNameW, PathIsDirectoryW, PathRemoveFileSpecW, PathStripPathA, StrCmpW, PathStripToRootW, PathRemoveExtensionW, PathFindExtensionW
user32.dll
IsWindow, GetClassNameA, KillTimer, CallNextHookEx, SetWindowLongW, MessageBoxW, FindWindowW, SendMessageW, GetUserObjectInformationW, GetProcessWindowStation, GetDesktopWindow, MessageBoxA, UnregisterClassA, LoadStringA, GetWindowTextW, GetWindowLongW, GetDlgItem, GetClassNameW, RegisterWindowMessageW, EndDialog, LoadStringW
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
winhttp.dll
WinHttpReadData, WinHttpSendRequest, WinHttpOpenRequest, WinHttpQueryHeaders, WinHttpSetStatusCallback, WinHttpSetOption, WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpQueryDataAvailable, WinHttpAddRequestHeaders, WinHttpCloseHandle, WinHttpOpen, WinHttpConnect, WinHttpReceiveResponse
Export table
InitMonitor
ProtectedDebugProc
ProtectedShellProc
RunChMonitor
StopChMonitor
TrackFile