Import table
advapi32.dll
RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, SetServiceStatus, DeregisterEventSource, ReportEventW, RegisterEventSourceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegQueryInfoKeyW, RegEnumKeyExW, CreateServiceW, DeleteService, ControlService, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, AuditSetSystemPolicy, ChangeServiceConfigW, StartServiceW, QueryServiceStatus, LogonUserW, AllocateAndInitializeSid, FreeSid, LookupAccountSidW, OpenProcessToken, CheckTokenMembership, RegEnumValueW, LookupAccountNameW, ConvertStringSidToSidW, ConvertSidToStringSidW, CreateWellKnownSid, AdjustTokenPrivileges, LookupPrivilegeValueW, EventWrite, EventUnregister, EventRegister, CreateProcessAsUserW, EqualSid, GetTokenInformation, RegOpenKeyExA, OpenThreadToken, SetThreadToken, RevertToSelf, RegOpenCurrentUser, DuplicateToken, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, CopySid, IsValidSid, GetLengthSid, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage, GetSecurityDescriptorLength, MakeSelfRelativeSD, InitializeSecurityDescriptor, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, MakeAbsoluteSD, GetSecurityDescriptorControl, GetAclInformation, InitializeAcl, AddAce, CryptDecrypt, CryptCreateHash, CryptDeriveKey, CryptHashData, ImpersonateLoggedOnUser, GetUserNameW, CryptDestroyKey, CryptDestroyHash, CryptGenRandom, CryptAcquireContextW, CryptReleaseContext
crypt32.dll
CertGetNameStringA, CertFreeCertificateContext, CryptUnprotectData, CryptProtectData, CertCreateCertificateContext, CertVerifyCertificateChainPolicy, CryptHashPublicKeyInfo
fwpuclnt.dll
FwpmTransactionBegin0, FwpmEngineOpen0, FwpmTransactionCommit0, FwpmSubLayerDeleteByKey0, FwpmCalloutDeleteByKey0, FwpmFilterDeleteByKey0, FwpmTransactionAbort0, FwpmSubLayerAdd0, FwpmFilterAdd0, FwpmEngineClose0, FwpmCalloutAdd0
iphlpapi.dll
CancelIPChangeNotify, NotifyAddrChange
kernel32.dll
CallbackMayRunLong, CreateThreadpool, SetThreadpoolThreadMinimum, SetThreadpoolThreadMaximum, CloseThreadpool, ResetEvent, GlobalFree, LCMapStringEx, ExpandEnvironmentStringsW, GetFileAttributesW, SetFileAttributesW, CreateDirectoryW, ConvertFiberToThread, WaitForMultipleObjectsEx, OpenThread, SetThreadpoolTimer, TlsSetValue, TlsGetValue, TlsFree, TlsAlloc, VirtualLock, VirtualUnlock, IsWow64Process, GetComputerNameW, EnumResourceNamesW, GetSystemDefaultLCID, GetSystemDefaultUILanguage, QueryPerformanceFrequency, CloseThreadpoolWait, WaitForThreadpoolWaitCallbacks, CreateThreadpoolTimer, SetThreadpoolWait, CloseThreadpoolTimer, LocalFree, TrySubmitThreadpoolCallback, CreateThreadpoolWait, QueueUserAPC, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, VirtualQuery, VirtualProtect, VirtualAlloc, ResumeThread, FlushInstructionCache, GetThreadContext, SetThreadContext, SuspendThread, SetLastError, SetDllDirectoryW, GetCommandLineW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, FreeLibrary, GetModuleFileNameW, lstrcmpiW, GetModuleHandleW, GetProcAddress, GetLastError, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, RaiseException, lstrlenW, WaitForThreadpoolTimerCallbacks, InterlockedExchange, Sleep, InterlockedCompareExchange, GetStartupInfoW, SetUnhandledExceptionFilter, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, IsDebuggerPresent, CompareStringW, LockResource, FindResourceExW, CloseHandle, WaitForSingleObject, GetThreadUILanguage, CreateThread, CreateEventW, SetEvent, InterlockedIncrement, InterlockedDecrement, GetCurrentThread, HeapSetInformation, GetOverlappedResult, InitializeSRWLock, AcquireSRWLockShared, ReleaseSRWLockShared, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, MoveFileExW, DeleteFileW, GetTempFileNameW, GetTempPathW, GetTickCount64, GetVersionExW, WideCharToMultiByte, CreateFileW, ReadFile, WriteFile, GetFileSize, SetFilePointer, FindFirstFileW, FindNextFileW, FindClose, GetSystemInfo, DeviceIoControl, SleepEx, WakeAllConditionVariable, SetThreadPriority, InitializeConditionVariable, OpenProcess, QueryFullProcessImageNameW, SwitchToFiber, DeleteFiber, IsThreadAFiber, SleepConditionVariableSRW, CreateFiberEx, ConvertThreadToFiber, InitializeCriticalSectionAndSpinCount, DecodePointer, EncodePointer, IsProcessorFeaturePresent, LoadLibraryW, GlobalAlloc, GetLongPathNameW, GetShortPathNameW, GetFullPathNameW, FileTimeToSystemTime, FileTimeToLocalFileTime, SystemTimeToFileTime, GetLocalTime, CreateMutexW, ReleaseMutex, DeleteTimerQueueTimer, ChangeTimerQueueTimer, CreateTimerQueueTimer, CreateTimerQueue, DeleteTimerQueueEx, InterlockedExchangeAdd, GetSystemDirectoryW, GetACP, GetLocaleInfoA, GetThreadLocale, GetVersionExA, lstrlenA, WaitForMultipleObjects, CreateIoCompletionPort, ReadDirectoryChangesW, PostQueuedCompletionStatus, CancelIo, GetQueuedCompletionStatus, BindIoCompletionCallback, QueueUserWorkItem, LCMapStringW, CompareFileTime, GetFileTime
msvcp110.dll
DllMain
msvcp80.dll
DllMain
msvcp90.dll
DllMain
msvcr110.dll
DllMain
msvcr80.dll
DllMain
msvcr90.dll
DllMain
netapi32.dll
NetGetJoinInformation, NetUserGetLocalGroups, NetApiBufferFree
ole32.dll
CoTaskMemRealloc, CoTaskMemAlloc, CoUninitialize, CoTaskMemFree, CoInitializeEx, CoSetProxyBlanket, StringFromGUID2, OleRun, CoRevokeClassObject, CoRegisterClassObject, CoResumeClassObjects, CoInitializeSecurity, CoDisconnectObject, CoCreateGuid, CoCreateInstance, StringFromCLSID, CreateStreamOnHGlobal, CoRevertToSelf, CoImpersonateClient, CLSIDFromProgID, CoSuspendClassObjects, CLSIDFromString, CoReleaseServerProcess, CoAddRefServerProcess, CoGetCallContext
psapi.dll
GetModuleFileNameExW
rpcrt4.dll
MesDecodeBufferHandleCreate, NdrMesTypeFree2, NdrMesTypeDecode2, MesHandleFree, MesEncodeDynBufferHandleCreate, NdrMesTypeEncode2
secur32.dll
LsaGetLogonSessionData, LsaFreeReturnBuffer
shell32.dll
SHFileOperationW, SHGetKnownFolderPath, SHGetFolderPathW
shlwapi.dll
UrlCanonicalizeA, UrlEscapeA, PathCombineW, PathFindExtensionW, PathRemoveBackslashW, PathIsDirectoryW, PathCanonicalizeW, PathRemoveFileSpecW, PathFindFileNameW, StrRChrW, SHCreateStreamOnFileEx, UrlApplySchemeW, UrlGetPartW, UrlCombineW, UrlCanonicalizeW, PathAppendW
urlmon.dll
CoInternetCreateSecurityManager
user32.dll
DispatchMessageW, TranslateMessage, CharUpperW, CharNextW, LoadStringW, GetMessageW, PostThreadMessageW, MessageBoxW, UnregisterClassA
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
webservices.dll
WsAddCustomHeader, WsWriteXmlBufferToBytes, WsFreeWriter, WsCreateWriter, WsGetFaultErrorProperty, WsCall, WsCreateServiceProxyFromTemplate, WsFreeHeap, WsFreeError, WsFreeServiceProxy, WsCloseServiceProxy, WsOpenServiceProxy, WsAbandonCall, WsCreateHeap, WsCreateError, WsAlloc, WsGetErrorProperty, WsGetErrorString
wevtapi.dll
EvtClose, EvtRender, EvtSubscribe
winhttp.dll
WinHttpConnect, WinHttpOpenRequest, WinHttpOpen, WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpCrackUrl, WinHttpCloseHandle, WinHttpSendRequest, WinHttpReadData, WinHttpQueryDataAvailable, WinHttpReceiveResponse, WinHttpQueryHeaders, WinHttpSetOption, WinHttpSetCredentials
wininet.dll
InternetCrackUrlA, DetectAutoProxyUrl, InternetCreateUrlA
wintrust.dll
WTHelperGetProvCertFromChain, WTHelperGetProvSignerFromChain, WinVerifyTrust, WTHelperProvDataFromStateData
ws2_32.dll
InetNtopW, getaddrinfo, freeaddrinfo, WSAAddressToStringA, WSAAddressToStringW
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory, WTSQueryUserToken, WTSEnumerateSessionsW