Import table
advapi32.dll
RegOpenKeyExA, RegQueryValueExW, AdjustTokenPrivileges, RevertToSelf, ImpersonateLoggedOnUser, LookupPrivilegeValueW, OpenThreadToken, OpenProcessToken, RegCloseKey, RegNotifyChangeKeyValue, RegOpenKeyExW, RegQueryValueExA
kernel32.dll
GetLastError, GetProcAddress, GetSystemDirectoryW, LoadLibraryW, FreeLibrary, GetFileTime, GetCurrentProcess, CloseHandle, GetVersion, GetLocalTime, GetModuleHandleW, GetTickCount, CreateFileW, GetCurrentThreadId, FlushFileBuffers, GetCurrentProcessId, CreateDirectoryW, WideCharToMultiByte, EnterCriticalSection, LeaveCriticalSection, CreateEventW, SetUnhandledExceptionFilter, WaitForSingleObject, SetEvent, CreateTimerQueue, Sleep, QueueUserWorkItem, DeleteTimerQueueEx, DeleteTimerQueueTimer, InterlockedIncrement, InterlockedDecrement, ChangeTimerQueueTimer, CreateTimerQueueTimer, WaitForMultipleObjects, DeleteCriticalSection, InitializeCriticalSection, GetCurrentThread, VirtualQuery, IsBadReadPtr, GetModuleFileNameA, IsBadWritePtr, ResetEvent, GetModuleFileNameW, HeapAlloc, GetProcessHeap, HeapFree, GetFullPathNameA, LocalAlloc, GetModuleHandleA, InterlockedExchange, RaiseException, LoadLibraryA, WriteFile, GetSystemTime, QueryPerformanceCounter, QueryPerformanceFrequency, MultiByteToWideChar, FindClose, FindNextFileW, FindFirstFileW, GetVersionExW, GetSystemInfo, GetSystemPowerStatus, GlobalMemoryStatusEx, SetLastError, FormatMessageA, SleepEx, ExpandEnvironmentStringsA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CompareStringA, CompareStringW, SetEnvironmentVariableA, CreateFileA, TlsFree, SetEndOfFile, TlsSetValue, GetStringTypeW, GetStringTypeA, GetLocaleInfoA, GetTimeZoneInformation, ReadFile, GetCurrentDirectoryA, SetStdHandle, GetConsoleMode, GetConsoleCP, LCMapStringW, LCMapStringA, IsValidCodePage, GetOEMCP, GetACP, GetCPInfo, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, SetFilePointer, GetStartupInfoA, SetHandleCount, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, IsDebuggerPresent, HeapReAlloc, ExitThread, CreateThread, GetCommandLineA, GetVersionExA, RtlUnwind, DeleteFileW, FileTimeToSystemTime, FileTimeToLocalFileTime, GetFileType, GetDriveTypeA, FindFirstFileA, VirtualFree, VirtualAlloc, HeapDestroy, HeapCreate, ExitProcess, GetStdHandle, TlsGetValue, TlsAlloc, HeapSize, GetSystemDirectoryA
psapi.dll
EmptyWorkingSet
rpcrt4.dll
NdrAsyncServerCall, RpcServerUnregisterIfEx, RpcServerListen, RpcMgmtWaitServerListen, RpcMgmtStopServerListening, RpcSsDontSerializeContext, RpcServerUseProtseqEpW, RpcServerRegisterIfEx, RpcAsyncCompleteCall, NdrServerCall2
ws2_32.dll
WSACreateEvent, WSACloseEvent
Export table
Orsp_Main
Orsp_Stop
Orsp_Suspend