Import table
advapi32.dll
RevertToSelf, ImpersonateNamedPipeClient
kernel32.dll
QueryPerformanceCounter, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, SetUnhandledExceptionFilter, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, GetFileSize, GetModuleHandleA, GetSystemDefaultLCID, CompareStringW, CreateProcessW, DuplicateHandle, DeleteFileW, GetCurrentDirectoryW, GetTempPathW, WriteFile, CreateNamedPipeW, FlushFileBuffers, ConnectNamedPipe, DisconnectNamedPipe, ReadFile, GetSystemTimeAsFileTime, GetTickCount, Sleep, SetFileAttributesW, GetFileAttributesW, SetEndOfFile, SetFilePointer, SetEvent, CreateEventW, ResetEvent, CreateMutexW, ReleaseMutex, GetSystemDirectoryW, CloseHandle, GetLastError, GetOverlappedResult, CancelIo, GetCurrentProcess, GetProcAddress, CreateFileW, DeviceIoControl, WaitForMultipleObjects, SetLastError, WaitForSingleObject, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, InterlockedExchange, TerminateThread, ResumeThread, SetThreadPriority, LoadLibraryW, LocalAlloc, GetCurrentThreadId, GetVersionExW, SetProcessWorkingSetSize, GetWindowsDirectoryW, OpenThread, GetCurrentProcessId, GetSystemInfo, LocalFree, FreeLibrary, LoadLibraryA, GetThreadPriority, OpenProcess, CreateProcessA
msvcr80.dll
DllMain
ntdll.dll
ZwQueryVirtualMemory, RtlAreBitsSet, RtlAcquirePebLock, RtlFindClearBitsAndSet, RtlClearBits, RtlReleasePebLock, RtlUnwind, RtlDeleteCriticalSection, RtlInitializeCriticalSection, RtlEnterCriticalSection, RtlLeaveCriticalSection, ZwCreateSection, ZwMapViewOfSection, ZwFsControlFile, ZwUnmapViewOfSection, ZwQuerySystemInformation, ZwFlushBuffersFile, ZwWriteFile, ZwReadFile, ZwQueryInformationToken, RtlEqualSid, ZwFilterToken, RtlCreateProcessParameters, ZwOpenProcess, RtlCreateUserProcess, RtlDestroyProcessParameters, ZwOpenThreadToken, ZwDuplicateToken, RtlImpersonateSelf, RtlAdjustPrivilege, ZwSetInformationProcess, ZwQueryInformationFile, ZwCreateFile, ZwSetInformationFile, RtlFreeUnicodeString, ZwResetEvent, ZwSetEvent, ZwCreateEvent, RtlInitUnicodeString, ZwReleaseMutant, RtlCreateUserThread, CsrClientCallServer, LdrShutdownThread, ZwDuplicateObject, ZwQueryInformationProcess, RtlRaiseException, ZwTerminateThread, ZwResumeThread, ZwDelayExecution, ZwSetInformationThread, ZwQueryInformationThread, ZwOpenThread, ZwTerminateProcess, ZwWaitForSingleObject, ZwClose, RtlNtStatusToDosError, RtlReAllocateHeap, RtlFreeHeap, RtlAllocateHeap, _strnicmp, _stricmp, _aullrem, DbgPrint, _aulldiv, ZwCreateKey, RtlOpenCurrentUser, ZwQueryValueKey, ZwOpenKey, ZwQueryKey, ZwWaitForMultipleObjects, ZwCreateNamedPipeFile, _allmul, ZwCancelIoFile, ZwReadVirtualMemory, ZwDeviceIoControlFile, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, _chkstk, memset, memmove, memcpy, NtRaiseException, RtlCreateUnicodeString, LdrLoadDll, LdrUnloadDll, LdrGetProcedureAddress, RtlInitAnsiString, NtTerminateThread, NtResumeThread, RtlCompareUnicodeString, RtlUpcaseUnicodeString, _allrem, RtlOemStringToUnicodeString, RtlUnicodeStringToOemString, RtlxOemStringToUnicodeSize, NlsMbOemCodePageTag, RtlxUnicodeStringToOemSize, RtlxAnsiStringToUnicodeSize, RtlAnsiStringToUnicodeString, RtlxUnicodeStringToAnsiSize, RtlUnicodeStringToAnsiString, _aullshr, _allshl, LdrGetDllHandle, DbgBreakPoint, _ftol, ZwDisplayString
Export table
AvgModuleFinish
AvgModuleInit
CoreSdkCliGetInstance
CoreSdkCliGetInstance_V2
CoreSdkCliSetAviLoaderName
CoreSdkCliSetBinaryPath
CoreSdkCliSetChjwPipeName
CoreSdkCliSetDataPath
CoreSdkCliSetLogger
CoreSdkCliSetLogPath
CoreSdkCliSetRegistryPath
CoreSdkCliSetTempPath