Import table
advapi32.dll
SetFileSecurityA, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, SetFileSecurityW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey
kernel32.dll
WideCharToMultiByte, MultiByteToWideChar, GetLastError, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, lstrlenA, lstrlenW, SetLastError, DeleteFileW, FreeLibrary, GetProcAddress, LoadLibraryW, CloseHandle, FlushFileBuffers, SetFilePointer, SetEndOfFile, SetFileTime, GetFileType, CreateFileA, CreateFileW, ReadFile, GetStdHandle, WriteFile, GetModuleFileNameA, GetCPInfo, Sleep, LocalFileTimeToFileTime, SystemTimeToFileTime, FileTimeToSystemTime, FileTimeToLocalFileTime, GetCurrentProcess, GetModuleHandleA, GetFileAttributesA, GetFileAttributesW, SetFileAttributesA, SetFileAttributesW, GetFullPathNameA, DeviceIoControl, CreateDirectoryA, CreateDirectoryW, GetVersionExW, MoveFileA, FindClose, FindNextFileA, FindFirstFileA, FindNextFileW, FindFirstFileW, GetConsoleOutputCP, WriteConsoleA, GetLocaleInfoW, SetStdHandle, GetStringTypeW, GetStringTypeA, CreateMutexW, IsDBCSLeadByte, EnumSystemLocalesA, GetUserDefaultLCID, LoadLibraryA, IsValidCodePage, GetOEMCP, InterlockedIncrement, InterlockedDecrement, InterlockedExchange, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, GetACP, GetLocaleInfoA, GetThreadLocale, GetVersionExA, RaiseException, RtlUnwind, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCurrentThreadId, GetCommandLineA, ExitProcess, GetSystemTimeAsFileTime, DeleteFileA, LCMapStringA, LCMapStringW, WriteConsoleW, GetModuleFileNameW, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetHandleCount, GetStartupInfoA, HeapCreate, VirtualFree, VirtualAlloc, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetConsoleCP, GetConsoleMode, IsValidLocale, GetVersion
urlmon.dll
IsValidURL
user32.dll
CharToOemBuffA, OemToCharBuffA, CharUpperW, CharLowerW, OemToCharA, UnregisterClassA
winhttp.dll
WinHttpOpen, WinHttpConnect, WinHttpOpenRequest, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpQueryHeaders, WinHttpQueryAuthSchemes, WinHttpSetCredentials, WinHttpQueryDataAvailable, WinHttpCloseHandle, WinHttpReadData
Export table
_FirewallUpdate@88
GetNextVersionNumber
ProxyGetNextVersionNumber
SetSpursLoggingCallback
SpursDownload
SpursProxyDownload
ThreatUpdate
ThreatUpdateViaProxy