Import table
advapi32.dll
AdjustTokenPrivileges, AllocateAndInitializeSid, FreeSid, GetLengthSid, GetTokenInformation, InitializeSecurityDescriptor, LookupPrivilegeValueA, OpenProcessToken, RegCreateKeyExW, RegDeleteKeyW, RegEnumKeyW, RegOpenKeyExW, RegSetValueExW, SetSecurityDescriptorDacl, RegCloseKey, RegOpenKeyA, RegOpenKeyExA, RegCreateKeyExA, RegQueryValueExA, RegSetValueExA, GetKernelObjectSecurity
kernel32.dll
SetFilePointer, WriteFile, GetFileAttributesA, ReadFile, GetCurrentDirectoryA, InitializeCriticalSection, DeleteCriticalSection, CreateThread, LeaveCriticalSection, EnterCriticalSection, MapViewOfFile, UnmapViewOfFile, GetCurrentThreadId, OpenFileMappingA, VirtualFree, VirtualAlloc, LocalAlloc, GetVersion, WideCharToMultiByte, MultiByteToWideChar, GetThreadLocale, GetStartupInfoA, GetLocaleInfoA, GetCommandLineA, FreeLibrary, ExitProcess, UnhandledExceptionFilter, RtlUnwind, RaiseException, GetStdHandle, TlsSetValue, TlsGetValue, TlsFree, TlsAlloc, lstrlenW, lstrlenA, lstrcpyW, lstrcpyA, lstrcmpiA, lstrcmpA, lstrcatW, WriteProcessMemory, WaitForSingleObject, WaitForMultipleObjects, VirtualQueryEx, VirtualQuery, VirtualProtectEx, VirtualProtect, TerminateThread, TerminateProcess, SetThreadPriority, SetLastError, LocalFree, ResumeThread, ReleaseSemaphore, ReleaseMutex, ReadProcessMemory, OpenProcess, OpenMutexW, OpenFileMappingW, OpenEventW, OpenEventA, LoadLibraryExA, LoadLibraryW, LoadLibraryA, IsBadWritePtr, IsBadReadPtr, GetWindowsDirectoryW, GetVersionExW, GetThreadContext, GetSystemDirectoryW, GetSystemDirectoryA, GetModuleHandleW, GetModuleFileNameW, GetFileAttributesW, GetExitCodeThread, GetCurrentThread, GetCurrentProcessId, GetCurrentDirectoryW, InterlockedExchange, DuplicateHandle, DeviceIoControl, CreateSemaphoreA, CreateProcessW, CreateProcessA, CreatePipe, CreateMutexW, CreateFileMappingW, CreateFileMappingA, CreateFileW, CreateEventW, CreateEventA, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetStringTypeW, GetStringTypeA, InitializeCriticalSectionAndSpinCount, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, HeapSize, CloseHandle, GetVersionExA, CreateMutexA, GetModuleHandleA, GetModuleFileNameA, OpenMutexA, GlobalFree, GetProcAddress, GetLastError, Sleep, GlobalAlloc, GetTickCount, GetCurrentProcess, CreateFileA, WriteConsoleW, FlushFileBuffers, SetEndOfFile, GetProcessHeap, SetEvent, FormatMessageA, GetFileType, SetHandleCount, GetConsoleMode, GetConsoleCP, LCMapStringW, HeapFree, HeapAlloc, SetUnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, HeapCreate, HeapDestroy, HeapReAlloc, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, LCMapStringA
shell32.dll
SHGetFolderPathA
user32.dll
CloseDesktop, GetSystemMetrics, GetThreadDesktop, GetUserObjectInformationA, MsgWaitForMultipleObjects, OpenInputDesktop, MessageBoxA, GetKeyboardType, CallNextHookEx, SetWindowsHookExA, BroadcastSystemMessageA, UnhookWindowsHookEx, LoadStringA, TranslateMessage, PeekMessageA, DispatchMessageA
version.dll
GetFileVersionInfoSizeA, GetFileVersionInfoA, VerQueryValueA
Export table
Attach
Detach
GCL
GPL
GTI