Import table
advapi32.dll
RegCloseKey, GetKernelObjectSecurity, ConvertStringSidToSidA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, FreeSid, EqualSid, ConvertSidToStringSidA, AllocateAndInitializeSid, CryptDestroyKey, CryptGenKey, CryptEncrypt, CryptImportKey, CryptReleaseContext, CryptAcquireContextW, CryptExportKey, AdjustTokenPrivileges, LookupPrivilegeValueW, GetTokenInformation, OpenProcessToken, GetLengthSid, RegQueryValueExW, RegOpenKeyExW, RegQueryValueExA, RegOpenKeyExA, CloseServiceHandle, OpenSCManagerW, OpenServiceW, RegCreateKeyExA, RegDeleteKeyA, GetSecurityDescriptorDacl, GetAce, RegOpenKeyA, RegEnumValueA, RegQueryMultipleValuesA, ConvertStringSecurityDescriptorToSecurityDescriptorA, RegGetKeySecurity, AddAce, RegEnumKeyExA, ConvertSecurityDescriptorToStringSecurityDescriptorA, RegSetValueExA, RegDeleteValueA, RegSetKeySecurity, InitializeAcl
crypt32.dll
CertGetNameStringW, CertFindCertificateInStore, CryptMsgGetParam, CryptQueryObject, CryptDecodeObject
kernel32.dll
GetTickCount, SearchPathW, VirtualProtect, WaitForSingleObjectEx, WaitForSingleObject, CreateEventW, CloseHandle, SetEvent, CreateThread, ResetEvent, MapViewOfFileEx, CreateFileW, CreateFileMappingW, UnmapViewOfFile, GetExitCodeThread, GetCurrentProcessId, Thread32Next, RemoveVectoredExceptionHandler, Thread32First, OpenThread, MultiByteToWideChar, CreateToolhelp32Snapshot, AddVectoredExceptionHandler, Sleep, GetCurrentThreadId, GetThreadContext, GetProcessId, DuplicateHandle, FreeLibrary, GetFileAttributesExW, LoadLibraryA, QueryDosDeviceW, FileTimeToSystemTime, GetLogicalDriveStringsW, GetFileSize, MapViewOfFile, VirtualQuery, GetVersionExW, FindNextFileW, GetModuleFileNameW, DeleteFileW, FindFirstFileW, CompareFileTime, MoveFileW, CreateDirectoryW, FindClose, OutputDebugStringA, InterlockedExchange, SetLastError, SuspendThread, ResumeThread, GetCurrentThread, GetSystemDirectoryW, TlsSetValue, OpenProcess, GetModuleFileNameA, FindResourceW, LoadResource, ReadProcessMemory, TlsAlloc, ProcessIdToSessionId, TerminateProcess, LocalFree, TlsFree, LockResource, InterlockedDecrement, GetSystemInfo, TlsGetValue, RtlCaptureContext, QueryPerformanceFrequency, QueryPerformanceCounter, InterlockedCompareExchange, SleepEx, IsBadReadPtr, lstrcpynW, IsBadWritePtr, GetSystemTime, InterlockedExchangeAdd, VirtualFree, CreateFileMappingA, LocalAlloc, ReleaseMutex, LoadLibraryW, CreateMutexW, lstrcatA, OpenMutexW, OpenFileMappingW, OpenEventW, lstrcpyA, VirtualAllocEx, VirtualQueryEx, VirtualFreeEx, WriteProcessMemory, HeapAlloc, GetProcessHeap, HeapFree, CreateRemoteThread, VerifyVersionInfoW, VerSetConditionMask, GetVersion, GetWindowsDirectoryW, lstrcpyW, lstrlenW, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RaiseException, VirtualProtectEx, GetCurrentProcess, GetModuleHandleA, FlushInstructionCache, WideCharToMultiByte, GetLastError, InterlockedIncrement, GetProcAddress, GetModuleHandleW, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeviceIoControl, ReadFile, GetVolumeInformationA, MoveFileA, SetFileAttributesA, WaitNamedPipeA, WriteFile, GetFileAttributesExA, GetExitCodeProcess, DeleteFileA, GetVersionExA, MoveFileExA, CreateMutexA, CreateFileA, OpenMutexA, CreateProcessA, GetVolumeNameForVolumeMountPointA, ExpandEnvironmentStringsA, LoadLibraryExA, GetProcessTimes, InitializeCriticalSectionAndSpinCount, CreateSemaphoreW, ReleaseSemaphore, lstrcmpA, FindFirstFileA, lstrlenA, VirtualAlloc, FindNextFileA, TerminateThread
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ole32.dll
CoUninitialize, CoInitializeEx, CoInitialize, CoSetProxyBlanket, CoCreateInstance
psapi.dll
EnumDeviceDrivers, GetModuleFileNameExA, GetDeviceDriverBaseNameA, GetModuleBaseNameW, GetModuleFileNameExW, GetMappedFileNameW, EnumProcessModules, GetModuleInformation, GetMappedFileNameA
shell32.dll
SHGetFolderPathW, SHGetFolderPathA
shlwapi.dll
PathAppendA, PathFindFileNameW
user32.dll
GetFocus, OpenInputDesktop, wsprintfW, FindWindowExA, GetUserObjectInformationA, CloseDesktop, GetThreadDesktop, GetClientRect, FindWindowExW, GetDesktopWindow, GetWindowLongW, GetWindowTextA, GetForegroundWindow, IsWindowVisible, GetClassNameA, EnumChildWindows, GetParent, GetAncestor, GetWindowPlacement, GetGUIThreadInfo, IsChild, MapVirtualKeyW, EnumWindows, GetWindowThreadProcessId, RegisterWindowMessageW, SetWindowsHookExW, PostMessageW, CallNextHookEx, UnhookWindowsHookEx, RegisterWindowMessageA, UnhookWinEvent, PostThreadMessageW, SetWinEventHook, GetWindowTextW, GetMessageW, PeekMessageW
version.dll
GetFileVersionInfoSizeA, VerQueryValueA, VerQueryValueW, GetFileVersionInfoA, GetFileVersionInfoSizeW, GetFileVersionInfoW
Export table
_Agent_OnLoad@12
on_construct_sink
on_resolve_sink
prepare_for_update
register_components