Import table
advapi32.dll
RegCloseKey, AdjustTokenPrivileges, LookupPrivilegeValueW, RegQueryValueExW, OpenProcessToken, RegOpenKeyExW
crypt32.dll
CryptMsgClose, CryptMsgGetParam, CertCloseStore, CertFindCertificateInStore, CertFreeCertificateContext, CertGetNameStringW, CryptQueryObject, CryptDecodeObject
kernel32.dll
DecodePointer, InterlockedExchange, InterlockedCompareExchange, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, EncodePointer, FreeLibrary, InterlockedIncrement, InterlockedDecrement, WaitForSingleObject, InitializeCriticalSection, LoadLibraryW, Sleep, QueryPerformanceCounter, ReleaseSemaphore, GetLastError, GetProcAddress, EnterCriticalSection, CreateSemaphoreW, DeleteCriticalSection, GetCurrentThreadId, CloseHandle, ResumeThread, CreateThread, GetLogicalDrives, WideCharToMultiByte, QueryDosDeviceW, LoadLibraryExW, lstrcmpA, CreateFileW, GetCurrentProcess, GetModuleHandleW, OpenProcess, GetModuleFileNameW, FindFirstFileW, CreateDirectoryW, CopyFileW, GetFileAttributesW, FindClose, FindNextFileW, SetFileAttributesW, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, GetVersionExW, Process32FirstW, Process32NextW, CreateToolhelp32Snapshot
msvcp100.dll
DllMain
msvcr100.dll
DllMain
psapi.dll
GetModuleFileNameExW, GetProcessImageFileNameW
shlwapi.dll
PathFileExistsW, PathRemoveFileSpecW, PathIsRelativeW, PathAppendW, PathIsDirectoryW
winmm.dll
timeGetTime
wintrust.dll
CryptCATAdminCalcHashFromFileHandle, CryptCATAdminReleaseContext, CryptCATCatalogInfoFromContext, CryptCATAdminEnumCatalogFromHash, WinVerifyTrust, CryptCATAdminAcquireContext
Export table
BdCreateObject
BdDestroyObject