Import table
advapi32.dll
OpenProcessToken, CheckTokenMembership, AllocateAndInitializeSid, SetEntriesInAclW, SetTokenInformation, GetLengthSid, ConvertStringSidToSidW, CreateRestrictedToken, DuplicateTokenEx, DuplicateToken, GetTokenInformation, EqualSid, LookupPrivilegeValueW, CopySid, CreateWellKnownSid, InitializeSecurityDescriptor, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, AdjustTokenPrivileges, GetKernelObjectSecurity, FreeSid, SetSecurityDescriptorDacl
gdi32.dll
DeleteObject, CreateSolidBrush, CreateRectRgn, FrameRgn, CreatePen, MoveToEx, LineTo, SelectObject, CombineRgn, CreateRoundRectRgn, ExcludeClipRect
kernel32.dll
DuplicateHandle, ResumeThread, SetLastError, FlushInstructionCache, GetVersionExW, ExpandEnvironmentStringsW, GetCurrentDirectoryW, GetDriveTypeW, GetLongPathNameW, CreateJobObjectW, GetLastError, SetInformationJobObject, IsBadReadPtr, VirtualProtect, DeleteCriticalSection, GetTickCount, GetModuleFileNameA, GetSystemDirectoryA, GetCommandLineA, SetFilePointer, InterlockedExchange, CreateToolhelp32Snapshot, Thread32First, Thread32Next, InterlockedCompareExchange, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapAlloc, HeapFree, RaiseException, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, Sleep, HeapSize, AssignProcessToJobObject, HeapReAlloc, HeapCreate, HeapDestroy, WriteFile, GetStdHandle, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetSystemTimeAsFileTime, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, RtlUnwind, InitializeCriticalSectionAndSpinCount, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, GetProcessHeap, SuspendThread, SetThreadContext, GetThreadContext, GlobalMemoryStatusEx, LocalFree, LocalAlloc, GetFileAttributesW, SearchPathW, GetModuleHandleW, LoadLibraryW, FreeLibrary, LoadLibraryA, WideCharToMultiByte, GetCurrentProcess, GetModuleHandleA, GetProcAddress, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, MultiByteToWideChar, GetCurrentThread, VirtualFree, VirtualAlloc, CloseHandle, CreateThread, GetModuleFileNameW, ExitThread, VirtualQuery, ExitProcess, GetCurrentThreadId, GetCurrentProcessId, IsProcessorFeaturePresent, GetEnvironmentVariableW, GetNativeSystemInfo, CreateFileW, ReadProcessMemory, lstrlenW, EncodePointer, DecodePointer, GetStartupInfoW, InterlockedPopEntrySList, InterlockedPushEntrySList, lstrcpyW, lstrcpyA, OpenEventW, CreateEventW, OpenFileMappingW, lstrlenA, OpenMutexW, lstrcatA, CreateMutexW, GetExitCodeThread, CreateRemoteThread, OpenProcess, VirtualFreeEx, CreateFileMappingW, ReleaseMutex, WaitForSingleObject, CreateFileMappingA, MapViewOfFile, UnmapViewOfFile, GetVersion, VirtualProtectEx, WriteProcessMemory, VirtualAllocEx, VirtualQueryEx, GetWindowsDirectoryW, ProcessIdToSessionId, GetSystemDirectoryW
ntdll.dll
NtQueryObject, NtQuerySystemInformation, NtQueryInformationThread, NtQueryInformationProcess, RtlCompareUnicodeString, RtlStringFromGUID, RtlAppendUnicodeStringToString, RtlAppendUnicodeToString, RtlCopyUnicodeString, RtlEqualUnicodeString, ZwAcceptConnectPort, RtlSetLastWin32Error, RtlGetLastWin32Error, ZwRequestWaitReplyPort, RtlLeaveCriticalSection, RtlEnterCriticalSection, ZwConnectPort, RtlDeleteCriticalSection, RtlInitializeCriticalSection, ZwFreeVirtualMemory, ZwAllocateVirtualMemory, ZwClose, ZwCreateSection
user32.dll
EnumWindows, GetClassNameW, GetWindow, wsprintfA, UnhookWindowsHookEx, SetWindowsHookExW, UserHandleGrantAccess, CallWindowProcW, GetSystemMetrics, DestroyIcon, GetWindowRgn, KillTimer, WindowFromDC, GetWindowThreadProcessId, GetDesktopWindow, SetWindowLongW, GetWindowLongW, SendMessageW, IsZoomed, GetWindowRect, GetWindowDC, ReleaseDC, SetTimer, CallNextHookEx, DefWindowProcW, GetThreadDesktop, GetUserObjectInformationW, RegisterWindowMessageW, wsprintfW, UnregisterClassA, OpenInputDesktop, SendMessageTimeoutW, DestroyWindow, GetActiveWindow, SetLayeredWindowAttributes, GetUserObjectInformationA, GetForegroundWindow, CloseDesktop, CreateWindowExW, LoadCursorW, GetClassInfoExW, RegisterClassExW, IsWindowVisible, FillRect, GetClientRect, InvalidateRect, SetWindowRgn, SetWindowPos, SystemParametersInfoW, IsWindow
version.dll
VerQueryValueA