Import table
advapi32.dll
OpenProcessToken, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, RegEnumKeyExW, RegEnumValueW, RegQueryInfoKeyA, LookupPrivilegeValueW, LookupPrivilegeValueA, LookupPrivilegeNameW, LookupPrivilegeNameA, CryptReleaseContext, CryptDestroyKey, RegQueryInfoKeyW, CryptAcquireContextA, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptDeriveKey, CryptDestroyHash, CryptDecrypt, GetTokenInformation
imagehlp.dll
CheckSumMappedFile
kernel32.dll
GetFileAttributesExW, lstrcatA, CreateFileA, SetFilePointer, WriteFile, VirtualAlloc, VirtualFree, VirtualProtect, lstrcpynA, IsBadReadPtr, GetFullPathNameW, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, SystemTimeToFileTime, GetShortPathNameA, GetShortPathNameW, GetLongPathNameA, GetLongPathNameW, GetFullPathNameA, GetFileAttributesA, GetFileAttributesW, GetTempPathA, GetTempFileNameA, FreeEnvironmentStringsW, GetACP, GetUserDefaultLCID, GetCPInfo, GetLocaleInfoA, OpenEventA, OpenEventW, IsValidLocale, IsProcessorFeaturePresent, GetSystemDefaultLCID, CompareStringA, CompareStringW, FileTimeToDosDateTime, LocalFileTimeToFileTime, GetTimeZoneInformation, GetConsoleCP, GetLogicalDrives, GetSystemDefaultLangID, GetProcessVersion, GetOEMCP, GetProfileIntA, GetProfileIntW, GetUserDefaultUILanguage, IsValidCodePage, DosDateTimeToFileTime, GetUserDefaultLangID, GetConsoleOutputCP, GetSystemDefaultUILanguage, GetCPInfoExA, GetCPInfoExW, CompareFileTime, IsBadWritePtr, IsDBCSLeadByte, GetTempFileNameW, CreateFileW, GetFileSize, ReadFile, CreateFileMappingW, MapViewOfFile, GetWindowsDirectoryA, GetSystemDirectoryA, GetSystemDirectoryW, FindFirstFileA, FindClose, FindFirstFileW, GetLastError, HeapFree, HeapAlloc, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCurrentThreadId, GetCommandLineA, RaiseException, RtlUnwind, HeapCreate, HeapDestroy, HeapReAlloc, Sleep, ExitProcess, GetStdHandle, GetModuleFileNameA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, InterlockedDecrement, GetConsoleMode, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, HeapSize, InitializeCriticalSectionAndSpinCount, LoadLibraryA, WriteConsoleA, WriteConsoleW, SetStdHandle, FlushFileBuffers, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetModuleHandleA, GetTempPathW, LocalFree, CloseHandle, GetProcAddress, LoadLibraryW, GetModuleHandleW, GetCurrentProcess, DeleteFileW, MultiByteToWideChar, WideCharToMultiByte, UnmapViewOfFile, DisableThreadLibraryCalls, VirtualQuery
ole32.dll
StgCreateDocfile, CoTaskMemFree
shlwapi.dll
PathFileExistsW
user32.dll
wsprintfW, CharLowerA, CharUpperW, CharUpperA, CharLowerW, CharUpperBuffW, CharUpperBuffA, CharLowerBuffW, CharLowerBuffA, GetKeyboardType, GetKeyboardLayoutList, GetKeyboardLayout, OemToCharA, OemToCharBuffW, GetKeyboardState, GetKeyState
Export table
CreateInstance
CreateInstanceVM32