Import table
advapi32.dll
GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, ControlTraceW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegCloseKey, StartTraceW, CloseTrace, EnableTrace, LookupPrivilegeValueW, AdjustTokenPrivileges, GetSecurityDescriptorDacl, InitializeSecurityDescriptor, AllocateAndInitializeSid, SetEntriesInAclW, SetSecurityDescriptorDacl, FreeSid, TraceMessage, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, RegQueryValueExW, OpenProcessToken
gdi32.dll
GetStockObject
kernel32.dll
SetErrorMode, ExpandEnvironmentStringsW, GlobalHandle, FindFirstVolumeMountPointW, FindNextVolumeMountPointW, GetVolumeInformationW, lstrcmpW, GetDriveTypeW, GetVolumeNameForVolumeMountPointW, SystemTimeToFileTime, GetDateFormatW, GetTimeFormatW, ReleaseMutex, GetFileSize, ReadFile, FlushFileBuffers, GetFileInformationByHandle, CompareStringW, DeviceIoControl, GlobalReAlloc, InterlockedDecrement, InterlockedIncrement, LoadLibraryW, GetSystemPowerStatus, CreateThread, GetCommandLineW, HeapSetInformation, GlobalMemoryStatus, CreateEventW, GetVersionExW, CloseHandle, GetSystemWindowsDirectoryW, MoveFileExW, GetFileAttributesW, DeleteFileW, CreateDirectoryW, LocalFree, GetLastError, HeapFree, GetProcessHeap, HeapAlloc, SetLastError, FindVolumeMountPointClose, InterlockedExchange, Sleep, InterlockedCompareExchange, GetStartupInfoA, SetUnhandledExceptionFilter, GetModuleHandleA, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, WriteFile, CreateFileW, OutputDebugStringA, IsDebuggerPresent, SetFilePointer, GetLocalTime, EnterCriticalSection, LeaveCriticalSection, GlobalFree, GlobalUnlock, GlobalLock, GlobalAlloc, GlobalSize, GetTickCount64, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, lstrlenW, GetExitCodeThread, lstrcmpiW, WaitForSingleObject, SetEvent, QueryPerformanceFrequency, ExitThread, SizeofResource, FindResourceW, GetComputerNameW, FormatMessageW, OpenEventW
msvcrt.dll
DllMain
ntdll.dll
RtlInitUnicodeString, NtQueryInformationFile, RtlEnumerateGenericTableLikeADirectory, NtSetInformationProcess, RtlIsGenericTableEmptyAvl, NtWaitForSingleObject, NtQueryVolumeInformationFile, NtOpenFile, RtlNtStatusToDosError, RtlInsertElementGenericTableAvl, RtlNumberGenericTableElementsAvl, RtlEnumerateGenericTableAvl, NtFsControlFile, RtlDeleteElementGenericTableAvl, RtlInitializeGenericTableAvl
ole32.dll
CLSIDFromString, CoDisconnectObject, CoRevokeClassObject, CoRegisterClassObject, CoCreateGuid, ReleaseStgMedium, CoCreateInstanceEx, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoTaskMemFree, CoTaskMemAlloc
shell32.dll
SHGetPathFromIDListW, SHGetSpecialFolderLocation
user32.dll
DispatchMessageW, DefWindowProcW, MessageBoxW, DestroyWindow, PostQuitMessage, SetTimer, LoadStringW, PostMessageW, CharUpperW, GetMessageW, SendMessageW, CreateWindowExW, RegisterClassW, LoadCursorW, TranslateMessage
vssapi.dll
IsVolumeSnapshottedInternal