Import table
advapi32.dll
TraceEvent, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, CreateProcessAsUserW, CreateRestrictedToken, LogonUserW, GetUserNameW, OpenProcessToken, RegCloseKey, ReadEventLogW, RegQueryValueExW, RegOpenKeyExW, CloseEventLog, GetNumberOfEventLogRecords, GetOldestEventLogRecord, OpenEventLogW, CloseServiceHandle, QueryServiceStatusEx, OpenServiceW, OpenSCManagerW, CheckTokenMembership, GetLengthSid, FreeSid, AllocateAndInitializeSid, RegEnumKeyExW, RegEnumValueW, CopySid, LookupPrivilegeValueW, AdjustTokenPrivileges, ConvertStringSidToSidW, RegCreateKeyExW, RegSetValueExW, QueryServiceConfigW, QueryServiceStatus, ControlService, StartServiceW, ChangeServiceConfigW
kernel32.dll
LocalAlloc, LocalFree, GetProcAddress, LoadLibraryW, FreeLibrary, DeleteFileW, SetFileAttributesW, GetFileInformationByHandle, FileTimeToDosDateTime, GetSystemPowerStatus, MultiByteToWideChar, WideCharToMultiByte, CreateProcessW, GetModuleHandleW, GetFileAttributesW, CreateTimerQueueTimer, SetFilePointerEx, WriteFile, GetSystemDirectoryW, WaitForSingleObject, CreateEventW, UnhandledExceptionFilter, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, RtlUnwind, OutputDebugStringA, InterlockedCompareExchange, HeapFree, HeapAlloc, CompareFileTime, Sleep, ExpandEnvironmentStringsW, LoadLibraryExW, FileTimeToLocalFileTime, FileTimeToSystemTime, InterlockedExchange, FindFirstFileW, FindNextFileW, FindClose, CopyFileW, CreateDirectoryW, CreateFileW, DeleteTimerQueueTimer, TerminateProcess, GetSystemTime, GetCurrentProcess, GetExitCodeProcess, SetEvent, FormatMessageW, SetErrorMode, CloseHandle, GetLastError, SetLastError, GetTimeFormatW, GetDateFormatW, GetLocalTime, GetTickCount, GetCommandLineW, InterlockedIncrement, InterlockedDecrement, GetTempPathW, GetFileSizeEx, DeviceIoControl, ConvertDefaultLocale, GetLocaleInfoW, IsValidLanguageGroup, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, HeapSetInformation, RemoveDirectoryW, GetNativeSystemInfo, SetEnvironmentVariableW, GetSystemDefaultUILanguage, LeaveCriticalSection, EnterCriticalSection, MoveFileExW, DebugBreak
mpclient.dll
MpManagerVersionQuery, MpAddDynamicSignatureFile, MpRemoveDynamicSignatureFile, MpUpdateStart, MpConfigGetValueAlloc, MpConfigIteratorClose, MpConfigIteratorEnum, MpConfigIteratorOpen, MpConfigDelValue, MpManagerEnable, MpQuarantineRequest, MpThreatEnumerate, MpThreatOpen, MpUtilsExportFunctions, MpScanStart, MpCleanOpen, MpCleanStart, MpConfigOpen, MpConfigClose, MpScanResult, MpConfigGetValue, MpHandleClose, MpConfigUninitialize, MpConfigInitialize, MpFreeMemory, MpClientUtilExportFunctions, MpConfigSetValue, MpManagerOpen, MpTelemetrySetDWORD, MpUpdateStartEx, MpDynamicSignatureOpen, MpDynamicSignatureEnumerate, MpTelemetryInitialize, MpManagerStatusQuery, MpSampleSubmit, MpSampleQuery, WDEnable, MpAllocMemory, MpManagerStatusQueryEx, MpTelemetryUninitialize, MpTelemetryUpload
msvcrt.dll
DllMain
ole32.dll
CoInitializeEx, StringFromGUID2, CoUninitialize, CoCreateInstance, CoSetProxyBlanket, CoWaitForMultipleHandles, CoTaskMemAlloc
rpcrt4.dll
UuidFromStringW
secur32.dll
GetUserNameExW
setupapi.dll
SetupCloseInfFile, SetupCloseFileQueue, SetupPromptReboot, SetupInitDefaultQueueCallbackEx, SetupCommitFileQueueW, SetupInstallFilesFromInfSectionW, SetupOpenFileQueue, SetupInstallServicesFromInfSectionW, SetupInstallFromInfSectionW, SetupOpenAppendInfFileW, SetupOpenInfFileW, SetupDefaultQueueCallbackW, SetupTermDefaultQueueCallback
userenv.dll
LoadUserProfileW, CreateEnvironmentBlock, UnloadUserProfile, DestroyEnvironmentBlock
wintrust.dll
CryptCATAdminReleaseContext, CryptCATAdminAcquireContext, CryptCATAdminAddCatalog, CryptCATAdminReleaseCatalogContext