Import table
advapi32.dll
CloseServiceHandle, IsTextUnicode, GetSidSubAuthorityCount, GetSidSubAuthority, CreateServiceA, StartServiceA, ControlService, QueryServiceStatus, DeleteService, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, SetServiceStatus, OpenSCManagerA, OpenServiceA, ChangeServiceConfigA, RegEnumValueA, RegNotifyChangeKeyValue, RegEnumKeyA, RegQueryValueA, RegOpenKeyA, RegDeleteKeyA, RegDeleteValueA, RegCreateKeyExA, RegSetValueExA, GetUserNameA, OpenProcessToken, RegOpenCurrentUser, AddAccessAllowedAce, GetSecurityDescriptorDacl, GetAclInformation, InitializeAcl, AddAce, GetAce, DuplicateTokenEx, CreateProcessAsUserA, LookupPrivilegeValueA, AdjustTokenPrivileges, LookupAccountNameW, IsValidSid, RevertToSelf, ImpersonateLoggedOnUser, GetTokenInformation, GetLengthSid, CopySid, AllocateAndInitializeSid, FreeSid, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl, RegQueryInfoKeyA, RegQueryValueExA, RegEnumKeyExA, RegOpenKeyExA, RegCloseKey, InitializeSecurityDescriptor, SetSecurityDescriptorDacl
kernel32.dll
GetFileAttributesA, CreateFileA, ReleaseMutex, OpenMutexA, OutputDebugStringA, CreateMutexA, SizeofResource, LockResource, LoadResource, FindResourceA, GetShortPathNameA, WaitForMultipleObjects, RemoveDirectoryA, GetTempPathA, HeapFree, HeapAlloc, GetProcessHeap, Process32Next, OpenProcess, Process32First, CreateToolhelp32Snapshot, SetConsoleCtrlHandler, WaitForMultipleObjectsEx, TerminateProcess, GetLocalTime, MoveFileExA, GetCurrentDirectoryA, LocalAlloc, GetCommandLineA, VirtualProtect, SetEndOfFile, GetUserDefaultLangID, GetComputerNameA, GetExitCodeThread, PostQueuedCompletionStatus, FormatMessageA, SystemTimeToFileTime, FileTimeToSystemTime, CompareStringW, CompareStringA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetStringTypeW, GetStringTypeA, GetLocaleInfoA, PeekNamedPipe, GetFileInformationByHandle, GetFullPathNameA, VirtualAlloc, GetTimeZoneInformation, QueryPerformanceCounter, VirtualFree, HeapDestroy, HeapCreate, GetEnvironmentStringsW, FreeEnvironmentStringsW, FindFirstFileA, FindClose, DeleteFileA, MoveFileA, DeviceIoControl, GetFileType, FlushFileBuffers, SetFilePointer, GetFileSize, ReadFile, WriteFile, GetExitCodeProcess, CreateProcessA, OpenFileMappingA, CreateFileMappingA, MapViewOfFile, Sleep, OpenEventA, UnmapViewOfFile, GetTickCount, WideCharToMultiByte, MultiByteToWideChar, GetEnvironmentVariableA, GetSystemDirectoryA, CreateDirectoryA, LocalFree, GetVersionExA, GetModuleHandleA, GetModuleFileNameA, GetCurrentProcessId, GetCurrentThreadId, TerminateThread, SetThreadPriority, GetCurrentProcess, DuplicateHandle, ResetEvent, CreateThread, SetEvent, CloseHandle, LeaveCriticalSection, ExitThread, CreateEventA, FreeLibrary, LoadLibraryA, GetProcAddress, WaitForSingleObject, DeleteCriticalSection, InterlockedDecrement, GetLastError, InterlockedIncrement, InterlockedExchange, InitializeCriticalSection, EnterCriticalSection, GetTempFileNameA, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, SetHandleCount, LCMapStringW, LCMapStringA, InitializeCriticalSectionAndSpinCount, GetConsoleMode, GetConsoleCP, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, HeapSize, GetStdHandle, SetLastError, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, GetDriveTypeA, FileTimeToLocalFileTime, HeapReAlloc, ExitProcess, GetModuleHandleW, GetSystemTimeAsFileTime, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, RaiseException, RtlUnwind, SetEnvironmentVariableA, GetCurrentThread
psapi.dll
GetModuleBaseNameA, EnumProcesses, GetModuleFileNameExA, EnumProcessModules
shell32.dll
SHGetFolderPathA
user32.dll
PeekMessageA, MsgWaitForMultipleObjectsEx, CloseDesktop, CloseWindowStation, OpenDesktopA, OpenInputDesktop, SetProcessWindowStation, OpenWindowStationA, GetProcessWindowStation, SetUserObjectSecurity, GetMessageA, wsprintfA, GetSystemMetrics, DestroyWindow, FindWindowA, IsWindow, DefWindowProcA, UnregisterClassA, CreateWindowExA, RegisterClassA, TranslateMessage, DispatchMessageA, GetUserObjectSecurity, SendNotifyMessageA, PostMessageA
userenv.dll
LoadUserProfileA, CreateEnvironmentBlock, DestroyEnvironmentBlock, UnloadUserProfile
version.dll
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
wininet.dll
InternetSetCookieA, InternetGetCookieA, InternetGetConnectedState, InternetConnectA, HttpOpenRequestA, HttpAddRequestHeadersA, InternetQueryOptionA, InternetSetOptionA, InternetReadFile, HttpQueryInfoA, InternetCrackUrlA, InternetOpenA, InternetOpenUrlA, InternetCloseHandle, HttpSendRequestA
ws2_32.dll
WSAStringToAddressW, WSASendTo, WSASendDisconnect, WSARecvFrom, WSARecvDisconnect, WSAJoinLeaf, WSAGetQOSByName, WSADuplicateSocketW, WSAIoctl, WSAAddressToStringW, WSAAccept, WSARecv, WSASend, WSAConnect, WSAEnumNetworkEvents, WSAGetOverlappedResult, WSAEventSelect, WSASocketA
Export table
CreateIChangeManager
CreateILoader2
CreateILSPFilter
CreateILspLoader
DestroyIChangeManager
DestroyILoader2
DestroyILSPFilter
DestroyILspLoader