Import table
advapi32.dll
RevertToSelf, ImpersonateNamedPipeClient
kernel32.dll
VirtualFree, VirtualAlloc, InterlockedIncrement, GetModuleHandleW, InterlockedExchange, VirtualProtect, DeleteCriticalSection, GetProcAddress, LoadLibraryW, GetCurrentProcess, GetCurrentThreadId, GetCurrentThread, GetModuleHandleA, LoadLibraryExA, LoadLibraryExW, LoadLibraryA, LocalFree, LocalAlloc, InitializeCriticalSection, OpenMutexW, LeaveCriticalSection, GetModuleFileNameA, EnterCriticalSection, QueryPerformanceCounter, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, GetStartupInfoW, DeviceIoControl, LockFileEx, UnlockFileEx, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, GetFileSize, SetEndOfFile, SetFilePointer, CancelIo, GetOverlappedResult, OpenEventW, TerminateThread, ResumeThread, GetExitCodeThread, SetPriorityClass, GetPriorityClass, GetThreadPriority, SetThreadPriority, SetProcessWorkingSetSize, GetModuleFileNameW, GlobalMemoryStatusEx, GetCommandLineW, GetComputerNameW, GetWindowsDirectoryW, ProcessIdToSessionId, OpenThread, GetVersionExW, GetComputerNameExW, GetSystemDirectoryW, GetTempPathW, GetFileAttributesW, FindFirstFileW, GetFileTime, FindNextFileW, CopyFileW, RemoveDirectoryW, SetCurrentDirectoryW, FindClose, MoveFileW, GetLongPathNameW, CreateDirectoryW, GetCurrentDirectoryW, SetFileAttributesW, MoveFileExW, WideCharToMultiByte, GetSystemDefaultLCID, MultiByteToWideChar, GetACP, CompareStringW, DuplicateHandle, GetSystemInfo, DeleteFileW, Sleep, GetSystemTimeAsFileTime, GetTickCount, GetLocalTime, SystemTimeToFileTime, GetSystemTime, FileTimeToSystemTime, CreateMutexW, ReleaseMutex, FreeLibrary, ResetEvent, SetEvent, OpenProcess, SetNamedPipeHandleState, SetUnhandledExceptionFilter, CreateProcessW, WaitForSingleObject, GetCurrentProcessId, CreateEventW, WaitForMultipleObjects, GetLastError, SetLastError, CloseHandle, InterlockedDecrement, InterlockedCompareExchange, ReadFile, CreateFileW, ConnectNamedPipe, CreateNamedPipeW, DisconnectNamedPipe, WaitNamedPipeW, FlushFileBuffers, WriteFile
msvcr80.dll
DllMain
ntdll.dll
memcpy, memset, RtlNtStatusToDosError, _chkstk, memmove, RtlInitAnsiString, LdrUnloadDll, LdrGetProcedureAddress, LdrLoadDll, RtlInitUnicodeString, LdrGetDllHandle, RtlAllocateHeap, RtlFreeHeap, ZwWaitForMultipleObjects, RtlFreeUnicodeString, RtlCreateUnicodeString, _allmul, _aullrem, _aulldiv, ZwDelayExecution, LdrShutdownThread, NtTerminateThread, NtResumeThread, CsrClientCallServer, RtlCreateUserThread, RtlCompareUnicodeString, RtlUpcaseUnicodeString, _allrem, RtlOemStringToUnicodeString, RtlUnicodeStringToOemString, RtlxOemStringToUnicodeSize, NlsMbOemCodePageTag, RtlxUnicodeStringToOemSize, RtlxAnsiStringToUnicodeSize, RtlAnsiStringToUnicodeString, RtlxUnicodeStringToAnsiSize, RtlUnicodeStringToAnsiString, _aullshr, RtlClearBits, RtlAreBitsSet, _allshl, RtlUnwind, ZwClose, ZwCreateFile, ZwDeviceIoControlFile, DbgBreakPoint, DbgPrint, _stricmp, _strnicmp, _ftol, RtlReAllocateHeap, ZwTerminateProcess, RtlRaiseException, ZwDisplayString