Import table
advapi32.dll
CreateProcessAsUserW, DuplicateTokenEx, OpenProcessToken, RegSetValueExA, RegCreateKeyExA, RevertToSelf, ImpersonateLoggedOnUser, RegCreateKeyW, RegQueryValueExW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegEnumKeyExW, RegQueryInfoKeyW, RegCloseKey, RegDeleteKeyW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegLoadKeyW, ConvertSidToStringSidW, GetTokenInformation, OpenThreadToken, RegOpenKeyW, RegQueryValueExA, RegOpenKeyExA, SetSecurityInfo, GetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, InitializeAcl, AddAccessAllowedAce
crypt32.dll
CertFreeCertificateContext, CryptMsgClose, CertGetSubjectCertificateFromStore, CryptMsgGetParam, CryptQueryObject, CertGetNameStringW, CertCloseStore, CryptDecodeObject, CertGetCertificateContextProperty, CertGetCertificateChain, CertFreeCertificateChain, CertVerifyCertificateChainPolicy
kernel32.dll
DllMain, GetModuleFileNameW, GetFileAttributesW, GetSystemDirectoryW, GetLastError, Sleep, InterlockedIncrement, InterlockedDecrement, lstrlenW, GetModuleHandleW, lstrcmpiW, RaiseException, LeaveCriticalSection, EnterCriticalSection, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, InitializeCriticalSection, DeleteCriticalSection, DisableThreadLibraryCalls, GetVersionExW, GetLongPathNameW, CreateThread, CloseHandle, LockResource, FindResourceExW, WaitForMultipleObjects, WaitForSingleObject, CreateEventW, SetProcessWorkingSetSize, GetCurrentProcess, GlobalFree, WideCharToMultiByte, lstrlenA, OpenProcess, MoveFileW, CreateProcessW, FindFirstFileW, FindNextFileW, FindClose, RemoveDirectoryW, DeleteFileW, MoveFileExW, LoadLibraryW, GetDateFormatW, GetThreadLocale, FreeLibrary, GetACP, GetUserDefaultLangID, GetUserDefaultUILanguage, GetUserDefaultLCID, GetSystemDefaultLCID, GetPrivateProfileStringW, GetPrivateProfileStructW, SystemTimeToFileTime, LocalFileTimeToFileTime, GetSystemTimeAsFileTime, GetExitCodeProcess, CreateDirectoryW, GetTickCount, CreateFileW, GetFileSize, ReadFile, GetCurrentThreadId, SetFilePointer, ExpandEnvironmentStringsW, QueryPerformanceCounter, WriteFile, FlushFileBuffers, GlobalAlloc, GetShortPathNameW, SetFileAttributesW, GetTempFileNameW, CopyFileW, GetWindowsDirectoryA, CreateFileA, GlobalLock, GlobalUnlock, GetCurrentDirectoryW, GetStartupInfoA, GetFileType, SetHandleCount, GetTimeZoneInformation, LCMapStringW, LCMapStringA, IsValidCodePage, GetOEMCP, GetCPInfo, GetModuleFileNameA, GetStdHandle, HeapCreate, VirtualFree, GetProcAddress, GetConsoleCP, GetConsoleMode, SetStdHandle, InitializeCriticalSectionAndSpinCount, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCurrentProcessId, GetStringTypeA, GetStringTypeW, GetModuleHandleA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetEndOfFile, CompareStringA, CompareStringW, SetEnvironmentVariableA, GetLocaleInfoA, SetLastError, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, RtlUnwind, LoadLibraryA, InterlockedExchange, GetCommandLineA, ExitProcess, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, ReleaseMutex, GetPrivateProfileStructA, GetPrivateProfileStringA, WritePrivateProfileStructA, GetLocalTime, OutputDebugStringW, CreateMutexW, GetSystemDefaultLangID, FileTimeToLocalFileTime, FileTimeToSystemTime, GetVersionExA, DuplicateHandle, GetCurrentThread, LocalFree, ExitThread, lstrcmpW
ole32.dll
CreateStreamOnHGlobal, CLSIDFromString, CLSIDFromProgID, StringFromGUID2, StringFromCLSID, CoCreateGuid, CoInitialize, CoGetClassObject, CoRegisterClassObject, CoInitializeEx, CoUninitialize, CoRevokeClassObject, CoCreateInstance, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoImpersonateClient, CoRevertToSelf
psapi.dll
GetModuleBaseNameW, EnumProcessModules, EnumProcesses
shell32.dll
SHGetSpecialFolderPathW, SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHGetFolderPathW, ShellExecuteW
shlwapi.dll
StrCmpIW, SHDeleteKeyW, StrCatW, StrRChrW, StrCmpNW, StrCmpW, StrStrIW, StrCmpNIW, wnsprintfW
user32.dll
DispatchMessageW, PeekMessageW, MsgWaitForMultipleObjects, CharNextW, TranslateMessage, wsprintfW, UnregisterClassA
userenv.dll
CreateEnvironmentBlock
winhttp.dll
WinHttpAddRequestHeaders, WinHttpSendRequest, WinHttpSetOption, WinHttpSetStatusCallback, WinHttpOpen, WinHttpConnect, WinHttpReceiveResponse, WinHttpQueryHeaders, WinHttpOpenRequest, WinHttpGetIEProxyConfigForCurrentUser, WinHttpReadData, WinHttpCloseHandle, WinHttpGetProxyForUrl, WinHttpQueryDataAvailable
wintrust.dll
WinVerifyTrust
wtsapi32.dll
WTSEnumerateProcessesW, WTSFreeMemory
Export table
CheckUpdate
CreateUpdateManager
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
MsacThreadMain
saReg
saRegXW
saSendStats
saSync
ScanUpSell
SendInstallPing
SvcEventHandler