Import table
advapi32.dll
RegCloseKey, RegQueryValueExW, AddAce, GetSidSubAuthority, InitializeSid, InitializeAcl, GetSidLengthRequired, SetNamedSecurityInfoW, GetTokenInformation, OpenProcessToken, ConvertSidToStringSidW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegCreateKeyExW, RegSetValueExW, RegOpenKeyExW, SetFileSecurityW, CryptDestroyKey, RegQueryInfoKeyW, RegEnumValueW, LookupAccountSidW, CryptGenRandom, CryptDestroyHash, CryptCreateHash, CryptHashData, CryptDeriveKey, CryptSetHashParam, CryptGetHashParam, CryptAcquireContextW, CryptReleaseContext, DuplicateTokenEx, ConvertStringSidToSidW, SetTokenInformation, GetLengthSid, CreateProcessAsUserW, GetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorA
kernel32.dll
ExitProcess, InterlockedCompareExchange, GetEnvironmentVariableW, ReadFile, SetFilePointer, GetFileSize, FlushFileBuffers, CreateFileW, CreateDirectoryW, GetCurrentProcess, GetCurrentThreadId, ReadProcessMemory, OpenProcess, SetErrorMode, lstrcpynA, CreateEventW, LocalFree, VirtualQuery, ExpandEnvironmentStringsW, UnmapViewOfFile, MapViewOfFile, FindClose, FindFirstFileW, CreateProcessW, GetFileAttributesExW, GetSystemTimeAsFileTime, CreateMutexW, ReleaseMutex, TryEnterCriticalSection, CreateFileMappingA, VirtualProtect, lstrcmpA, OpenMutexW, HeapFree, HeapAlloc, GetProcessHeap, GetLongPathNameW, GetComputerNameW, GetTempPathW, GetDiskFreeSpaceExW, GetSystemTime, IsBadReadPtr, QueryPerformanceCounter, QueryPerformanceFrequency, InterlockedExchange, HeapReAlloc, HeapSize, RtlUnwind, GetVersionExA, HeapDestroy, GetACP, GetLocaleInfoA, GetThreadLocale, LocalAlloc, LoadLibraryExW, GetModuleFileNameW, SetLastError, GetLastError, GetTickCount, lstrcpynW, lstrcmpW, GetProcAddress, Sleep, lstrlenA, WideCharToMultiByte, lstrlenW, MultiByteToWideChar, GetStringTypeExW, lstrcmpiA, DisableThreadLibraryCalls, GetCurrentProcessId, FreeLibrary, CreateThread, GetShortPathNameW, GetCurrentThread, QueueUserAPC, LoadLibraryW, GlobalFindAtomW, GetModuleHandleW, GetCommandLineW, lstrcmpiW, InterlockedDecrement, InterlockedIncrement, OpenEventW, WaitForSingleObject, FreeLibraryAndExitThread, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, RaiseException, CloseHandle, LoadLibraryA, GetVersionExW, CreateFileMappingW, SetFileAttributesW, FindNextFileW, RemoveDirectoryW, SetEvent, OutputDebugStringW, GetOverlappedResult, DeviceIoControl, GetLogicalDriveStringsW, GetDriveTypeW, GetUserDefaultLCID, GetLocaleInfoW, GetNumberFormatW, GlobalUnlock, GlobalLock, GlobalAlloc, GlobalFree
user32.dll
CharNextA, EnumChildWindows, UnregisterClassA, GetWindowTextW, EnumWindows, GetClassNameW, CharLowerBuffW, CharUpperBuffW, GetForegroundWindow, CallNextHookEx, GetDoubleClickTime, GetAsyncKeyState, CharLowerW, FindWindowW, SendMessageW, MessageBoxW, SendMessageTimeoutW, wvsprintfW, GetLastInputInfo, FindWindowExW, wsprintfW, PostMessageW, AllowSetForegroundWindow, SetWindowsHookExW, UnhookWindowsHookEx, MsgWaitForMultipleObjectsEx, PeekMessageW, TranslateMessage, DispatchMessageW, CharUpperW, CloseClipboard, SetClipboardData, EmptyClipboard, OpenClipboard, IsWindow
Export table
DllGetClassObject
DllRegisterServer
DllUnregisterServer
SetByPassSocket