"WFP_IDLE_TRIGGER" "DecryptFileA" "temp\ext" "%02x" "%s" "backofficestorage" "cdtag.1" "_SFX_CAB_EXE_PATH" "\update\update.exe" "InitiateSystemShutdownA" "GetLengthSid" "tTokenInformation" "OpenProcessToken" "AllocateAndInitializeSid" "Ÿ" "CryptReleaseContext" "CryptGenRandom" "„" "CryptAcquireContextA" "SetSecurityDescriptorDacl" "AddAccessAllowedAce" "itializeAcl" "itializeSecurityDescriptor" "ADVAPI32.dll" "ReadFile" "SetFilePointer" "apFree" "CloseHandle" "à" "FormatMessageA" "aveCriticalSection" "moveDirectoryA" "tLastError" "DeleteFileA" "MoveFileExA" "EnterCriticalSection" "rminateProcess" "tEvent" "tEnvironmentVariableA" "GetEnvironmentVariableA" "deCharToMultiByte" "HeapAlloc" "J" "CreateFileA" "DeleteCriticalSection" "FreeLibrary" "FlushFileBuffers" "tSystemDirectoryA" "GetVersionExA" "GetProcAddress" "adLibraryA" "itForSingleObject" "OpenEventA" "tCurrentProcess" "tFileAttributesA" "GetCommandLineA" "tModuleFileNameA" "B" "CreateDirectoryA" "SystemTimeToFileTime" "GetSystemTime" "GetDiskFreeSpaceA" "QueryDosDeviceA" "tDriveTypeA" "tCurrentDirectoryA" "LocalFileTimeToFileTime" "„" "DosDateTimeToFileTime" "tExitCodeProcess" "CreateProcessA" "e" "CreateThread" "F" "CreateEventA" "InitializeCriticalSectionAndSpinCount" "KERNEL32.dll" "SendDlgItemMessageA" "owWindow" "USER32.dll" "b" "NtClose" "T" "NtAdjustPrivilegesToken" "NtOpenProcessToken" "ShutdownSystem" "ntdll.dll" "COMCTL32.dll" "j" "SHGetPathFromIDListA" "@" "SHBrowseForFolderA" "SHELL32.dll"