Import table
advapi32.dll
BuildExplicitAccessWithNameW, RevertToSelf, SetEntriesInAclW, GetNamedSecurityInfoW, ImpersonateLoggedOnUser, LookupPrivilegeValueW, SetNamedSecurityInfoW, LookupAccountNameW, AccessCheck, GetExplicitEntriesFromAclW, DeleteAce, GetUserNameW, OpenThreadToken, OpenProcessToken, RegSetValueExW, RegCloseKey, RegOpenKeyExW, RegDeleteValueW, StartServiceW, RegQueryValueExW, RegCreateKeyW, OpenServiceW, OpenSCManagerW, DeleteService, CloseServiceHandle, CreateServiceW, AdjustTokenPrivileges
kernel32.dll
GetModuleHandleA, WaitForSingleObject, GetTickCount, TerminateThread, GetVersionExW, ExitThread, ReleaseMutex, CreateThread, FreeLibrary, MoveFileExW, LoadLibraryW, CopyFileW, GetFileAttributesW, DefineDosDeviceW, DeleteFileW, SetFileAttributesW, GetCurrentProcess, VirtualFreeEx, VirtualAllocEx, UnlockFile, LockFile, OpenProcess, EnterCriticalSection, LocalFree, GetFileSize, ReadFile, CreateFileA, SearchPathW, FindFirstFileW, GetFileAttributesExA, GetFileAttributesA, GetShortPathNameA, FindFirstFileA, GetLongPathNameA, RemoveDirectoryA, CopyFileA, SearchPathA, SetFileAttributesA, FindClose, RemoveDirectoryW, FindNextFileA, FindNextFileW, GetFileAttributesExW, DeleteFileA, LeaveCriticalSection, GetShortPathNameW, GetLongPathNameW, GetCurrentDirectoryW, GetLastError, MultiByteToWideChar, GetModuleFileNameW, IsDBCSLeadByte, WideCharToMultiByte, GetSystemDirectoryW, GetSystemWindowsDirectoryW, SetErrorMode, GetEnvironmentVariableW, GetFullPathNameW, GetWindowsDirectoryW, CloseHandle, TlsAlloc, GetProcAddress, SetLastError, CreateFileW, TlsSetValue, InitializeCriticalSection, GetProcessHeap, GetCurrentThread, GetModuleHandleW, TlsGetValue, GetCurrentProcessId, CreateMutexW, FlushFileBuffers, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, HeapSize, LoadLibraryA, RtlUnwind, InitializeCriticalSectionAndSpinCount, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetConsoleMode, GetConsoleCP, SetFilePointer, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetFileType, SetHandleCount, RaiseException, InterlockedDecrement, InterlockedIncrement, TlsFree, GetModuleFileNameA, GetStdHandle, WriteFile, ExitProcess, Sleep, HeapReAlloc, VirtualAlloc, DeleteCriticalSection, VirtualFree, HeapDestroy, HeapCreate, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetCommandLineA, GetCurrentThreadId, GetSystemTimeAsFileTime, HeapFree, HeapAlloc
netapi32.dll
NetShareGetInfo
ntdll.dll
RtlInitString, NtCreateSection, NtUnmapViewOfSection, NtMapViewOfSection, RtlCompareString, _wcsicmp, NtFreeVirtualMemory, RtlNtStatusToDosError, wcschr, wcsrchr, NtAllocateVirtualMemory, RtlDosPathNameToNtPathName_U, RtlInitializeCriticalSection, wcsncmp, RtlCopyUnicodeString, RtlCompareMemory, RtlLeaveCriticalSection, RtlDeleteCriticalSection, RtlAllocateHeap, RtlAppendUnicodeStringToString, RtlPrefixUnicodeString, RtlOemStringToUnicodeString, RtlFreeUnicodeString, NtWaitForSingleObject, RtlUnicodeStringToOemString, RtlUnicodeStringToAnsiString, RtlInitAnsiString, NtFsControlFile, RtlInitUnicodeString, RtlFreeHeap, NtDeviceIoControlFile, RtlAnsiStringToUnicodeString, RtlEnterCriticalSection, memmove, RtlIsDosDeviceName_U, wcsncpy, RtlFreeAnsiString, RtlEqualUnicodeString, _wcsnicmp
psapi.dll
EnumProcesses, GetModuleFileNameExW, EnumProcessModules
shlwapi.dll
PathIsDirectoryW, PathFindExtensionW, PathAppendW, PathIsRootW, SHDeleteKeyW, PathFileExistsW, StrRChrW, StrCmpIW, PathFileExistsA, PathIsDirectoryA
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
Export table
AcquireArCk01
AcquireArCk02
AcquireArDs01
AcquireArDs02
AcquireArDs03
AcquireArDs04
AcquireArDs05
AcquireArLd01
AcquireArLd03
AcquireArMk01
AcquireArUf01
AcquireArUf02
AcquireArUf03
AcquireDispatch
AcquireMiniportStartIo
AcquireService
AcquireStartIoHook
BapiCreateToolhelp32Snapshot
BapiDriver32First
BapiDriver32Next
BapiModule32First
BapiModule32Next
BapiProcess32First
BapiProcess32Next
BfsSetFileApisToANSI
BfsSetFileApisToOEM
BRegCloseKey
BRegCreateKey
BRegCreateKeyEx
BRegCreateKeyExW
BRegCreateKeyW
BRegDeleteKey
BRegDeleteKeyEx
BRegDeleteKeyExW
BRegDeleteKeyW
BRegDeleteValue
BRegDeleteValueW
BRegEnumKey
BRegEnumKeyEx
BRegEnumKeyExW
BRegEnumKeyW
BRegEnumValue
BRegEnumValueW
BRegOpenKey
BRegOpenKeyEx
BRegOpenKeyExW
BRegOpenKeyW
BRegQueryValueEx
BRegQueryValueExW
BRegSetValueEx
BRegSetValueExW
DllRegisterServer
DriverVersion
DsFileUnlock
DsGetFileLockType
DsSetTargetAccess
EnumerateFilterDriver
ExpandFilePath
ExpandFilePathW
FSCloseHandle
FSCopyFile
FSCopyFileW
FSCreateFile
FSCreateFileW
FSDeleteFile
FSDeleteFileW
FSFindClose
FSFindFirstFile
FSFindFirstFileW
FSFindNextFile
FSFindNextFileW
FsForceKill
FSGetFileAttributes
FSGetFileAttributesEx
FSGetFileAttributesExW
FSGetFileAttributesW
FSGetFileSize
FSGetFileSizeEx
FSGetLongPathName
FSGetLongPathNameW
FSGetShortPathName
FSGetShortPathNameW
FSMoveFileA
FSMoveFileExA
FSMoveFileExW
FSMoveFileW
FSPathFileExists
FSPathFileExistsW
FSPathIsDirectory
FSPathIsDirectoryW
FSReadFile
FSRemoveDirectory
FSRemoveDirectoryW
FSSearchPath
FsSearchPathExW
FSSearchPathW
FSSetFileAttributes
FSSetFileAttributesW
FSSetFilePointer
FSSetFilePointerEx
FSUnlockAll
FSWriteFile
InitEngine
InitRegEngine
Install
IsConnect
JudgeVersion
ModuleDump
ModuleInformation
QueryFileLock
QueryFileLockEx
RemoveFilterDriver
RestoreArCk01
RestoreArCk02
RestoreArDs01
RestoreArDs02
RestoreArDs03
RestoreArDs04
RestoreArDs05
RestoreArLd01
RestoreArLd02
RestoreArLd03
RestoreArMk01
RestoreArUf01
RestoreArUf02
RestoreArUf03
RestoreDispatch
RestoreService
RestoreStartIoHook
SetBapiWorkingMode
SetDllBase
SetupInstall
UninitEngine
UninitRegEngine
Uninstall
UnregisterShutdown