Import table
advapi32.dll
RegQueryValueExW, SetFileSecurityW, SetFileSecurityA, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, RegCloseKey, RegOpenKeyExW
kernel32.dll
IsValidLocale, EnumSystemLocalesA, SetLastError, GetLastError, GetVersionExW, WideCharToMultiByte, MultiByteToWideChar, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, GetProcAddress, GetModuleHandleW, lstrlenA, lstrlenW, GetVersion, DeleteFileW, FreeLibrary, LoadLibraryW, CloseHandle, FlushFileBuffers, SetFilePointer, SetEndOfFile, SetFileTime, GetFileType, CreateFileA, CreateFileW, ReadFile, GetStdHandle, WriteFile, IsDBCSLeadByte, GetCPInfo, Sleep, LocalFileTimeToFileTime, SystemTimeToFileTime, FileTimeToSystemTime, FileTimeToLocalFileTime, GetCurrentProcess, GetFileAttributesA, GetFileAttributesW, SetFileAttributesA, SetFileAttributesW, GetFullPathNameA, DeviceIoControl, CreateDirectoryA, CreateDirectoryW, MoveFileA, FindClose, FindNextFileA, FindFirstFileA, FindNextFileW, FindFirstFileW, GetLocaleInfoA, GetUserDefaultLCID, SetStdHandle, InterlockedExchange, LCMapStringW, GetConsoleMode, GetConsoleCP, InitializeCriticalSection, GetModuleFileNameA, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, HeapCreate, GetLocaleInfoW, GetStringTypeW, IsValidCodePage, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, DecodePointer, EncodePointer, RtlUnwind, GetCurrentThreadId, GetCommandLineA, ExitProcess, GetSystemTimeAsFileTime, DeleteFileA, WriteConsoleW, GetModuleFileNameW, IsProcessorFeaturePresent, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, InterlockedIncrement, InterlockedDecrement, SetHandleCount, GetStartupInfoW, GetACP, GetOEMCP
shlwapi.dll
UrlEscapeW
urlmon.dll
IsValidURL
user32.dll
CharToOemBuffA, OemToCharBuffA, CharUpperW, CharLowerW, OemToCharA
winhttp.dll
WinHttpOpen, WinHttpSetTimeouts, WinHttpCloseHandle, WinHttpConnect, WinHttpOpenRequest, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpQueryHeaders, WinHttpQueryAuthSchemes, WinHttpSetCredentials, WinHttpQueryDataAvailable, WinHttpReadData
Export table
_FirewallUpdate@88
GetNextVersionNumber
ProxyGetNextVersionNumber
SetSpursLoggingCallback
SpursDownload
SpursProxyDownload
ThreatUpdate
ThreatUpdateViaProxy