Import table
advapi32.dll
RevertToSelf, ImpersonateLoggedOnUser, OpenProcessToken
kernel32.dll
SetEvent, WaitForSingleObject, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, CreateSemaphoreW, GetCurrentThreadId, ReleaseSemaphore, InterlockedExchange, InterlockedCompareExchange, InitializeCriticalSectionAndSpinCount, InterlockedIncrement, GetLocalTime, GetTickCount, GetCurrentProcessId, OutputDebugStringA, QueryPerformanceCounter, QueryPerformanceFrequency, DeviceIoControl, CreateFileW, OutputDebugStringW, CancelWaitableTimer, SetWaitableTimer, GetLastError, InterlockedDecrement, CloseHandle, LoadLibraryW, GetProcAddress, FreeLibrary, OpenProcess, SetLastError, GetCurrentProcess, GetVersionExW, SetFilePointer, ReadFile, WriteFile, SetEndOfFile, GetModuleFileNameW, CreateEventW, GetModuleHandleA, CreateToolhelp32Snapshot, Process32FirstW, ProcessIdToSessionId, Process32NextW, CreateThread, GetTempPathW, DeleteFileW, Sleep, WaitForMultipleObjects, HeapFree, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapAlloc, HeapReAlloc, GetCommandLineA, RaiseException, RtlUnwind, GetModuleHandleW, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, HeapSize, ExitProcess, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, FlushFileBuffers, HeapCreate, HeapDestroy, VirtualFree, VirtualAlloc, LCMapStringW, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetSystemTimeAsFileTime, LoadLibraryA, SetStdHandle, LCMapStringA, MultiByteToWideChar, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, CreateFileA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, GetProcessHeap, ResetEvent, CreateWaitableTimerW, GetSystemDirectoryW, GetLogicalDrives, GetDriveTypeW, GetVolumeInformationW, DuplicateHandle, GetWindowsDirectoryW
psapi.dll
GetModuleFileNameExW, EnumProcesses
Export table
BdCreateObject
BdDestroyObject