Import table
advapi32.dll
RegSetValueExW, LookupAccountNameW, ConvertSidToStringSidW, RegCreateKeyExW, IsValidSid, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegSetValueExA, RegEnumKeyExW, RegQueryInfoKeyW, RegCloseKey, RegQueryValueExA, RegQueryValueExW, RegOpenKeyExW
dbghelp.dll
ImageNtHeader
kernel32.dll
IsBadWritePtr, TlsGetValue, TlsSetValue, GetCurrentThreadId, TlsAlloc, GetCurrentThread, GetCommandLineW, CreateEventW, CreateSemaphoreA, GetSystemTimeAsFileTime, ReleaseSemaphore, OpenMutexW, PulseEvent, GetCurrentProcessId, WaitForMultipleObjects, GetProcessHeap, HeapFree, LocalFree, HeapAlloc, LoadLibraryA, DuplicateHandle, GetCurrentProcess, lstrlenW, CopyFileW, DeleteFileW, FreeLibrary, VirtualQuery, SetLastError, GetModuleHandleA, VirtualAlloc, InterlockedCompareExchange, ResumeThread, FlushInstructionCache, GetThreadContext, SetThreadContext, SuspendThread, WideCharToMultiByte, OpenEventW, lstrlenA, GetModuleFileNameW, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetVersionExW, AreFileApisANSI, SetFilePointer, SetEndOfFile, FlushFileBuffers, UnlockFile, LockFile, GetFileAttributesA, DeleteFileA, GetFileAttributesW, LoadLibraryW, QueryPerformanceCounter, GetTickCount, GetSystemTime, LockFileEx, GetTempPathA, GetTempPathW, FormatMessageA, FormatMessageW, GetFullPathNameA, GetFullPathNameW, GetDiskFreeSpaceA, GetDiskFreeSpaceW, CreateFileA, DeviceIoControl, WriteFile, ReadFile, GetLastError, GetFileSize, GetDateFormatA, CreateFileW, GetProcAddress, GetModuleHandleW, RemoveVectoredExceptionHandler, InterlockedExchange, VirtualProtect, IsBadReadPtr, AddVectoredExceptionHandler, SetEvent, CreateEventA, CloseHandle, WaitForSingleObject, GetTimeFormatA, MultiByteToWideChar, SetEnvironmentVariableA, InterlockedIncrement, InterlockedDecrement, GetStringTypeW, EncodePointer, DecodePointer, HeapDestroy, HeapReAlloc, HeapSize, TlsFree, OpenEventA, ResetEvent, SystemTimeToFileTime, SetWaitableTimer, CreateWaitableTimerA, GetUserDefaultLCID, GetStringTypeExA, LCMapStringA, LCMapStringW, GetCommandLineA, RaiseException, RtlUnwind, GetCPInfo, ExitThread, CreateThread, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, ExitProcess, GetStdHandle, GetLocaleInfoW, IsProcessorFeaturePresent, HeapCreate, GetACP, GetOEMCP, IsValidCodePage, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, GetStartupInfoW, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetTimeZoneInformation, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleW, CompareStringW, FindClose, FindFirstFileW, lstrcpyW, lstrcatW, FindNextFileW, LocalAlloc
ntdll.dll
ZwClose, RtlCreateUserThread, NtQueryInformationProcess, NtAllocateVirtualMemory, NtFreeVirtualMemory
user32.dll
LoadStringA, GetWindowThreadProcessId, FindWindowExW
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory