Import table
advapi32.dll
RegOpenKeyW, RegEnumValueW, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegEnumKeyW
fltlib.dll
FilterSendMessage, FilterGetDosName, FilterReplyMessage, FilterGetMessage, FilterConnectCommunicationPort
kernel32.dll
CreateFileW, lstrlenW, GetLastError, Process32FirstW, QueryDosDeviceW, DeviceIoControl, Process32NextW, CreateToolhelp32Snapshot, GetCurrentThreadId, CloseHandle, GetCurrentProcessId, ExpandEnvironmentStringsW, FindFirstFileW, GetModuleFileNameW, FindClose, WaitForSingleObject, TerminateThread, lstrcmpW, lstrcatW, lstrcpyW, CreateThread, UnhandledExceptionFilter, GetCurrentProcess, GetFileAttributesW, CreateEventA, Sleep, GetProcessHeap, HeapFree, QueryPerformanceCounter, HeapAlloc, SetUnhandledExceptionFilter, IsDebuggerPresent, TerminateProcess, GetTickCount, InterlockedCompareExchange, EncodePointer, GetSystemTimeAsFileTime, InterlockedDecrement, InterlockedExchange, GetQueuedCompletionStatus, InterlockedIncrement, CreateIoCompletionPort, OpenMutexW, lstrlenA, DecodePointer
msvcr100.dll
DllMain
ntdll.dll
RtlDosPathNameToNtPathName_U, RtlFreeHeap
shlwapi.dll
PathMatchSpecW, PathIsNetworkPathW, PathFindFileNameW
user32.dll
CharUpperW
wintrust.dll
WinVerifyTrust
Export table
DRV_AddProcessBlockHash
DRV_AddSysRule
DRV_AITH
DRV_BuildMultipleWait
DRV_CHCAST
DRV_ClientBreakConnection
DRV_ClientRegister
DRV_DeleteProcessBlockHash
DRV_DeleteProcessBlockHashByValue
DRV_DICLF
DRV_DICRF
DRV_DIGFA
DRV_DIGFI
DRV_DIGFS
DRV_DIRF
DRV_DisableProcessBlockHashOnBoot
DRV_EnableProcessBlockHashOnBoot
DRV_EnableScreenshotProtection
DRV_EnumModuleInfo
DRV_EPRIN
DRV_EXPA
DRV_EXPC
DRV_EXPD
DRV_FetchBlockedProcessLog
DRV_FIDI
DRV_FIEN
DRV_ForceDep
DRV_GDOAN
DRV_GetAppId
DRV_GetDriverApiVersion
DRV_GetFileStatusByHandle
DRV_GetFilterNext
DRV_GETPPA
DRV_GetProcessBlockHash
DRV_GetRuningProcInfo
DRV_GetSingleMessageEx
DRV_GetUserSidByProcessId
DRV_GFADON
DRV_GSCou
DRV_GSIM
DRV_GSP
DRV_GSTRAN
DRV_HIPS_AddApplRule
DRV_HIPS_ApplyNewResetOldRulesByPid
DRV_HIPS_ApplyRules
DRV_HIPS_ApplyRulesByPid
DRV_HIPS_ApplySysRulesByPid
DRV_HIPS_AppRulExclAdd
DRV_HIPS_AppRulExclApply
DRV_HIPS_AppRulExclResetClientRules
DRV_HIPS_RemoveApplRule
DRV_HIPS_ResetClientRules
DRV_HIPS_ResetClientRulesbyPid
DRV_HIPS_ResetSysClientRulesbyPid
DRV_InstallCustomSDTHandler
DRV_IsProcessBlockHashOnBootEnabled
DRV_ISwift3_Close
DRV_ISwift3_CommitRead
DRV_ISwift3_GetFileIdByHandle
DRV_ISwift3_InitializeDiag
DRV_ISwift3_LookupCacheEntry
DRV_ISwift3_LookupEntry
DRV_ISwift3_Reinitialize
DRV_ISXSF
DRV_KLMouFlt_GetCursorPos
DRV_KLMouFlt_GetDisplayMetrics
DRV_KLMouFlt_GetMouseSpeed
DRV_KLMouFlt_QueryMouseData
DRV_KLMouFlt_SetCapturingState
DRV_KLMouFlt_SetCursorPos
DRV_KLMouFlt_SetDisplayMetrics
DRV_KLMouFlt_SetMouseSpeed
DRV_LCHS
DRV_LDON
DRV_LFF
DRV_LFN
DRV_LGEX
DRV_LIN
DRV_LockFile
DRV_LockFileEx
DRV_Logger_GetInfo
DRV_MRIMP
DRV_MWIMP
DRV_OASTGH
DRV_OASTQ
DRV_OASTR
DRV_OASTU
DRV_ObjectRequest
DRV_PauseBlockingByHash
DRV_QFIH
DRV_QFNP
DRV_QPIN
DRV_QPRH
DRV_QueryProcessModules
DRV_REGDU
DRV_ReplyMessageEx
DRV_REPME
DRV_SetFileStatusByHandle
DRV_SetProcessBlockHash
DRV_SetVerdictEx
DRV_SFUND
DRV_StartBlockingByHash
DRV_StopBlockingByHash
DRV_TerminateProcess
DRV_TranslateToFileNativePath
DRV_UninstallCustomSDTHandler
DRV_UnlockFile
DRV_UnlockFileEx
DRV_UNREG
DRV_UnregisterInvisibleProcEx
DRV_VirtOpenFile
DRV_VirtOpenFile2
DRV_VirtOpenKey
DRV_VKRHW
FSDrv_IsFileProtected
FSDrv_ProactiveFindSystemProcessId
FSSync_ADF
FSSync_ADFE
FSSync_BRC
FSSYNC_CHFP
FSSync_D_E
FSSync_D_GDID
FSSync_D_GG
FSSync_D_GPI
FSSync_D_GT
FSSync_D_IL
FSSync_D_RE
FSSync_D_WR
FSSync_DACL
FSSync_DCS
FSSync_DISIA
FSSync_Done
FSSync_DQF
FSSync_DR
FSSync_DRC
FSSync_DT
FSSync_DTT
FSSync_DUR
FSSync_DURSR
FSSYNC_EF2V
FSSYNC_FB_GBH
FSSYNC_FB_SBH
FSSync_FBRES
FSSYNC_FC
FSSYNC_FD
FSSYNC_FE
FSSync_GEH
FSSYNC_GEI
FSSync_GEP
FSSync_GetDriveType
FSSync_GetUserFromSidW
FSSYNC_GEVM
FSSYNC_GFB2
FSSYNC_GFF
FSSYNC_GFH
FSSYNC_GFI
FSSYNC_GFN
FSSYNC_GFNP
FSSYNC_GHP
FSSYNC_GHV
FSSync_GVN
FSSync_IMSV
FSSync_Init
FSSync_INP
FSSync_INT
FSSync_IPM
FSSync_ISIA
FSSync_PEM
FSSync_PEn
FSSync_PEnM
FSSync_PMQ
FSSync_PRM
FSSync_RDUM
FSSync_Remove
FSSync_Ripe
FSSync_RSPA
FSSync_RTH
FSSync_RTHU
FSSYNC_SAF
FSSync_Scree2Notify1
FSSync_Scree2Notify2
FSSync_Scree2Notify3
FSSync_Scree2Notify4
FSSync_Scree2Notify5
FSSync_Scree2Notify6
FSSync_Scree2Notify7
FSSync_ScreeActive
FSSync_ScreeDown
FSSync_ScreeDownEx
FSSync_ScreeFState
FSSync_ScreeNotify
FSSync_ScreeSet
FSSync_ScreeState
FSSync_ScreeStateEx
FSSync_ScreeStateEx2
FSSync_ScreeUp
FSSync_ScreeUpEx
FSSync_SetCheck
FSSync_SFG
FSSync_SFR
FSSync_SV
FSSync_UDUM
FSSync_UNDO
FSSync_UNIN
FSSync_UNRI
FSSync_UNUR
FSSync_YLD