Import table
advapi32.dll
RegOpenKeyExW, RegEnumValueW, RegCloseKey, QueryServiceLockStatusW, ControlService, QueryServiceStatus, StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle, RegSetValueExW
kernel32.dll
SetEndOfFile, SetFilePointer, ReadConsoleW, SetConsoleMode, ReadConsoleInputA, ReadFile, WaitForMultipleObjectsEx, GetTickCount, lstrlenW, FlushConsoleInputBuffer, LoadLibraryExA, DisableThreadLibraryCalls, CreateFileW, CloseHandle, WriteConsoleW, SetFilePointerEx, SetStdHandle, SetEnvironmentVariableA, GetConsoleMode, GetConsoleCP, FlushFileBuffers, LoadLibraryW, HeapReAlloc, SetConsoleCtrlHandler, LoadLibraryExW, FreeLibrary, InterlockedExchange, LeaveCriticalSection, EnterCriticalSection, GetStringTypeW, LCMapStringW, CompareStringW, GetTimeFormatW, GetDateFormatW, HeapAlloc, GetTimeZoneInformation, IsDebuggerPresent, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, GetModuleHandleW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, TerminateProcess, GetCurrentProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, WideCharToMultiByte, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetSystemTimeAsFileTime, QueryPerformanceCounter, GetModuleFileNameA, GetStartupInfoW, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, GetFileType, GetProcessHeap, InterlockedIncrement, SetLastError, GetModuleFileNameW, WriteFile, GetStdHandle, Sleep, HeapSize, MultiByteToWideChar, AreFileApisANSI, GetProcAddress, GetModuleHandleExW, ExitProcess, InterlockedDecrement, HeapFree, IsProcessorFeaturePresent, RtlUnwind, RaiseException, GetCurrentThreadId, GetCommandLineA, DecodePointer, EncodePointer, GetCurrentProcessId, GetLastError, MoveFileExW, OutputDebugStringW
ntdll.dll
ZwQuerySystemInformation, ZwWriteFile, ZwQueryInformationFile, ZwDeviceIoControlFile, ZwCreateFile, ZwWaitForSingleObject, ZwSetInformationFile, ZwReadFile, ZwFsControlFile, RtlGetFullPathName_U, RtlLocalTimeToSystemTime, RtlxUnicodeStringToOemSize, NlsMbOemCodePageTag, RtlxUnicodeStringToAnsiSize, RtlOemStringToUnicodeString, RtlxAnsiStringToUnicodeSize, RtlxOemStringToUnicodeSize, RtlUnicodeStringToOemString, RtlUnicodeStringToAnsiString, RtlAnsiStringToUnicodeString, ZwAllocateUuids, RtlDowncaseUnicodeString, RtlUpcaseUnicodeString, RtlSetOwnerSecurityDescriptor, LdrUnloadDll, ZwQueryKey, RtlCreateSecurityDescriptor, ZwSetInformationToken, ZwEnumerateKey, ZwDeleteKey, RtlGetOwnerSecurityDescriptor, ZwOpenFile, ZwLoadKey, RtlAddAccessAllowedAceEx, RtlGetDaclSecurityDescriptor, ZwDuplicateToken, ZwEnumerateValueKey, ZwSetInformationProcess, ZwCancelIoFile, ZwShutdownSystem, ZwCreateNamedPipeFile, ZwFlushBuffersFile, ZwOpenMutant, ZwMapViewOfSection, ZwFlushVirtualMemory, ZwUnmapViewOfSection, ZwCreateSection, RtlInitUnicodeString, RtlInitAnsiString, LdrGetProcedureAddress, LdrLoadDll, ZwCreateEvent, ZwSetEvent, RtlQueryEnvironmentVariable_U, ZwTerminateThread, ZwResumeThread, CsrClientCallServer, LdrShutdownThread, ZwOpenThread, ZwSetInformationThread, ZwDuplicateObject, ZwTerminateProcess, ZwQueryInformationThread, RtlCreateUserThread, ZwDelayExecution, RtlUpcaseUnicodeChar, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, RtlExpandEnvironmentStrings_U, RtlCreateUnicodeString, RtlDosPathNameToNtPathName_U, RtlGetCurrentDirectory_U, ZwQueryVolumeInformationFile, ZwQueryValueKey, RtlFreeUnicodeString, ZwOpenThreadToken, RtlAddAccessDeniedAceEx, RtlCopySid, ZwQueryDirectoryFile, RtlIsDosDeviceName_U, ZwReleaseMutant, ZwResetEvent, RtlInitializeCriticalSection, RtlDeleteCriticalSection, LdrGetDllHandle, ZwOpenKey, RtlSetSaclSecurityDescriptor, RtlGetGroupSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlGetSaclSecurityDescriptor, ZwSetValueKey, ZwDeleteValueKey, ZwQuerySecurityObject, RtlEqualSid, RtlSetDaclSecurityDescriptor, RtlValidSecurityDescriptor, RtlCreateAcl, ZwCreateKey, ZwUnloadKey, RtlGetAce, RtlLeaveCriticalSection, RtlEnterCriticalSection, ZwQueryInformationToken, RtlTimeToTimeFields, RtlTimeFieldsToTime, RtlOpenCurrentUser, NtClose, ZwAdjustPrivilegesToken, ZwQueryInformationProcess, ZwOpenProcess, ZwClose, RtlNtStatusToDosError, ZwQueryVirtualMemory, ZwReadVirtualMemory, RtlAllocateHeap, RtlReAllocateHeap, ZwSetSecurityObject, RtlAppendUnicodeToString, RtlAppendUnicodeStringToString, RtlFreeAnsiString, RtlFreeHeap
shell32.dll
SHGetSpecialFolderPathW
Export table
GetAvgObject2
GetLockCount