Import table
advapi32.dll
AddAccessAllowedAce, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, AdjustTokenPrivileges, RevertToSelf, ImpersonateLoggedOnUser, LookupPrivilegeValueW, OpenThreadToken, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, GetLengthSid, InitializeSecurityDescriptor, FreeSid, DuplicateToken, SetSecurityDescriptorOwner, OpenProcessToken, AllocateAndInitializeSid, InitializeAcl, AccessCheck
kernel32.dll
LeaveCriticalSection, CreateFileW, FlushFileBuffers, EnterCriticalSection, DeleteCriticalSection, GetCurrentProcess, GetCurrentThread, OpenThread, CreateToolhelp32Snapshot, GetCurrentProcessId, Process32FirstW, Process32NextW, GetSystemInfo, VirtualAlloc, VirtualFree, GetProcAddress, VirtualProtectEx, VirtualAllocEx, InitializeCriticalSection, ReadProcessMemory, VirtualFreeEx, Module32FirstW, Module32NextW, CreateNamedPipeA, ConnectNamedPipe, DisconnectNamedPipe, WriteFileEx, QueueUserAPC, QueueUserWorkItem, ReadFileEx, WaitForMultipleObjectsEx, CancelIo, SleepEx, GetOverlappedResult, CreateFileA, SetNamedPipeHandleState, ReadFile, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetLocaleInfoA, WriteFile, GetCurrentThreadId, GetModuleHandleW, TerminateThread, GetLastError, SetEvent, OpenProcess, WaitForSingleObject, GetVersionExW, CreateThread, CreateEventW, GetExitCodeThread, LocalFree, CloseHandle, LocalAlloc, WriteProcessMemory, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapFree, HeapAlloc, GetCommandLineA, GetVersionExA, GetProcessHeap, RaiseException, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, InterlockedDecrement, Sleep, HeapSize, ExitProcess, HeapDestroy, HeapCreate, HeapReAlloc, GetStdHandle, GetModuleFileNameA, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, MultiByteToWideChar, LCMapStringA, WideCharToMultiByte, LCMapStringW, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, RtlUnwind, SetFilePointer, InterlockedExchange, LoadLibraryA, GetConsoleCP, GetConsoleMode, GetStringTypeA, GetStringTypeW
psapi.dll
GetMappedFileNameW
user32.dll
DefWindowProcW, DispatchMessageW, DestroyWindow, GetMessageW, CreateWindowExW, UnregisterClassW, PostMessageW, TranslateMessage, RegisterClassExW, PostQuitMessage
wtsapi32.dll
WTSRegisterSessionNotification, WTSUnRegisterSessionNotification
Export table
FsUmi_Do_Nothing
FsUmi_Initialize
FsUmi_InjectRunningProcesses
FsUmi_Shutdown