Import table
advapi32.dll
RegOpenKeyA, RegQueryValueExA, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, RegSetValueExW, RegQueryValueExW, RegCreateKeyExW, GetSecurityDescriptorDacl, OpenProcessToken, GetTokenInformation, AllocateAndInitializeSid, FreeSid, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegEnumKeyW, RegOpenKeyExW, RegDeleteValueW, RegDeleteKeyW, RegCloseKey, LookupPrivilegeValueW
kernel32.dll
VirtualAlloc, MapViewOfFile, GetLastError, CreateFileMappingW, OpenFileMappingW, InterlockedIncrement, WaitForMultipleObjects, DuplicateHandle, OpenProcess, OpenMutexW, FreeLibrary, GetProcAddress, LoadLibraryW, LocalFree, LocalAlloc, SetThreadPriority, GetCurrentThread, FindClose, FindFirstFileW, GetShortPathNameW, ReleaseMutex, HeapFree, HeapAlloc, GetModuleHandleW, GetVersionExW, GetModuleHandleA, GetVersion, lstrlenA, lstrcmpA, GetModuleFileNameW, SetLastError, GetLocalTime, LoadLibraryA, GetOEMCP, GetACP, CreateFileA, SetStdHandle, IsBadCodePtr, IsBadReadPtr, SetUnhandledExceptionFilter, GetStringTypeW, CreateMutexW, UnmapViewOfFile, GetCurrentProcessId, SetEvent, GetCurrentThreadId, TerminateThread, ResetEvent, CreateThread, WaitForSingleObject, GetCurrentProcess, CreateEventW, GetFileSize, ReadFile, GetFileTime, GetSystemTimeAsFileTime, SetEndOfFile, SetFilePointer, WriteFile, FlushFileBuffers, MultiByteToWideChar, WideCharToMultiByte, GetLogicalDrives, GetLogicalDriveStringsW, GetDriveTypeW, DeleteCriticalSection, InitializeCriticalSection, CreateProcessW, ResumeThread, DeleteFileW, EnterCriticalSection, LeaveCriticalSection, CreateFileW, CloseHandle, GetTickCount, GetStringTypeA, GetCPInfo, GetEnvironmentStringsW, GetEnvironmentStrings, InterlockedDecrement, HeapReAlloc, RtlUnwind, GetCommandLineA, ExitProcess, TerminateProcess, HeapSize, TlsSetValue, TlsAlloc, TlsFree, TlsGetValue, GetModuleFileNameA, GetEnvironmentVariableA, GetVersionExA, HeapDestroy, HeapCreate, VirtualFree, IsBadWritePtr, LCMapStringA, LCMapStringW, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, FreeEnvironmentStringsW, OpenEventW
ole32.dll
CoCreateInstance, CoInitialize, CoUninitialize
shell32.dll
SHGetMalloc, SHGetSpecialFolderLocation, SHGetDesktopFolder
user32.dll
DispatchMessageW, LoadStringW, PeekMessageW, TranslateMessage, MsgWaitForMultipleObjects
Export table
exeProc
NOD32Ioctl