Import table
advapi32.dll
RegisterTraceGuidsA, RegSetValueExW, GetTraceEnableLevel, UnregisterTraceGuids, TraceEvent, GetTraceLoggerHandle, GetTraceEnableFlags, RegCreateKeyExW, RegOpenKeyW, SetThreadToken, RegCloseKey, RegOpenKeyExW, RegQueryValueExW
kernel32.dll
OpenProcess, GlobalAlloc, Sleep, CreateProcessA, TerminateProcess, InterlockedExchange, GetLastError, SetLastError, GlobalFree, OpenEventW, CloseHandle, GetCurrentProcessId, LocalAlloc, LocalFree, HeapReAlloc, HeapAlloc, HeapFree, GetProcessHeap, HeapDestroy, HeapCreate, WaitForSingleObject, WaitForMultipleObjects, GetCurrentThreadId, ResumeThread, CreateThread, WideCharToMultiByte, MultiByteToWideChar, GetModuleFileNameW, DeleteCriticalSection, FlushFileBuffers, CreateFileA, WriteConsoleW, GetConsoleOutputCP, CreateProcessW, CreateEventW, ResetEvent, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, SetEvent, GetStringTypeA, TerminateThread, WriteConsoleA, SetStdHandle, LCMapStringW, LCMapStringA, GetCommandLineA, GetVersionExA, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetProcAddress, GetModuleHandleA, ExitProcess, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, InterlockedDecrement, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, VirtualFree, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, WriteFile, LoadLibraryA, GetCPInfo, GetACP, GetOEMCP, VirtualAlloc, RtlUnwind, SetFilePointer, GetConsoleCP, GetConsoleMode, HeapSize, GetLocaleInfoA, GetStringTypeW, FreeLibrary, LoadLibraryW, IsValidCodePage
ole32.dll
HGLOBAL_UserFree, HGLOBAL_UserSize, HGLOBAL_UserMarshal, HGLOBAL_UserUnmarshal
rpcrt4.dll
NdrClientCall2, RpcMgmtIsServerListening, RpcStringFreeA, RpcBindingFromStringBindingA, RpcStringBindingComposeA
Export table
AvRtlAddDiscard
AvRtlAsynchronousResult
AvRtlDeleteFile
AvRtlDisinfectBoot
AvRtlDisinfectFile
AvRtlFinishAnalyzer
AvRtlInitializeAnalyzer
AvRtlMoveFile
AvRtlNeutralizeFile
AvRtlReadInformation
AvRtlRenameFile
AvRtlScanBoot
AvRtlScanFile
AvRtlScanMappedFile
AvRtlScanSystem
AvRtlSendExclusions
AvRtlSendExtensions
AvRtlSendWLNames
AvRtlSetNotifyRoutine
AvRtlWriteConfig
AvRtlWriteNeutralizeConfig
RtlFreeMemory
RtlGetHealthStatus