Import table
advapi32.dll
CheckTokenMembership, RegNotifyChangeKeyValue, RegQueryValueExW, RegSetValueExW, RegCloseKey, RegOpenKeyExW, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, CreateWellKnownSid, RegEnumKeyExW, RegEnumValueW
kernel32.dll
GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, InterlockedCompareExchange, Sleep, InterlockedExchange, RtlUnwind, CreateThread, CloseHandle, WaitForMultipleObjects, CreateEventW, EnterCriticalSection, LeaveCriticalSection, LoadLibraryW, FreeLibrary, GetLastError, GetModuleFileNameW, InitializeCriticalSection, InterlockedDecrement, InterlockedIncrement, GetModuleHandleW, GetProcAddress, DisableThreadLibraryCalls, QueryDosDeviceW, GetVersionExW, ReadProcessMemory, OpenProcess, GetLogicalDriveStringsW, FindNextFileW, FindClose, FindFirstFileW, MultiByteToWideChar, WideCharToMultiByte, DeviceIoControl, GetExitCodeThread, ProcessIdToSessionId, ResetEvent, ExitThread, CreateFileW, TerminateThread, WaitForSingleObject, CreateMutexW
msvcrt.dll
DllMain
ole32.dll
CoInitialize, CoUninitialize, CoCreateInstance
shell32.dll
SHChangeNotify, SHLoadNonloadedIconOverlayIdentifiers
user32.dll
GetWindowTextW, EnumChildWindows, IsRectEmpty, EnumWindows, MessageBoxW, MsgWaitForMultipleObjects, CallNextHookEx, TranslateMessage, FindWindowW, GetWindowInfo, GetParent, SendMessageW, GetForegroundWindow, PeekMessageW, PostThreadMessageW, SetWindowsHookExW, UnhookWindowsHookEx, GetWindowThreadProcessId, DispatchMessageW, GetWindowTextLengthW
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
Export table
ControlMonitoring
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer