Import table
advapi32.dll
MapGenericMask, CreateProcessAsUserW, CreateRestrictedToken, IsValidSid, GetLengthSid, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, GetSecurityDescriptorControl, SetNamedSecurityInfoW, GetSecurityInfo, LookupPrivilegeValueW, AdjustTokenPrivileges, ConvertStringSidToSidW, LookupAccountSidW, EventUnregister, EventRegister, EventActivityIdControl, EventWriteTransfer, EventEnabled, EventWrite, RevertToSelf, IsTokenRestricted, RegOpenKeyExW, RegSetValueExW, RegCloseKey, RegQueryValueExW, QueryAllTracesW, ConvertSidToStringSidW, RegDeleteValueW, StartTraceW, EnableTrace, ControlTraceW, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegCreateKeyExW, CopySid, TraceEvent, ChangeServiceConfigW, RegOpenKeyW, TraceMessage, SetServiceStatus, CloseServiceHandle, QueryServiceConfigW, OpenServiceW, OpenSCManagerW, RegisterServiceCtrlHandlerExW, GetSidSubAuthority, GetSidSubAuthorityCount, SetThreadToken, ImpersonateLoggedOnUser, GetTokenInformation, OpenThreadToken, OpenProcessToken, GetWindowsAccountDomainSid, CreateWellKnownSid, SetTokenInformation, FreeSid, AllocateAndInitializeSid, DuplicateTokenEx, EqualSid, ImpersonateSelf, CheckTokenMembership, LookupAccountNameW, AddMandatoryAce, InitializeAcl, SetSecurityDescriptorSacl, SetSecurityDescriptorDacl, SetEntriesInAclW, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, AccessCheck, MakeAbsoluteSD, MakeSelfRelativeSD, LogonUserW
api-ms-win-core-debug-l1-1-0.dll
OutputDebugStringA
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll
GetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter, SetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter, SetLastError
api-ms-win-core-file-l1-1-0.dll
ReadFile, GetFileSizeEx, SetFilePointerEx, WriteFile, CreateFileW, GetLongPathNameW, FlushFileBuffers, FileTimeToSystemTime, SetFileInformationByHandle, DeleteFileW, GetFileInformationByHandle, GetFileAttributesExW, SetFileTime, GetFileType, GetFileTime, GetDiskFreeSpaceW, LocalFileTimeToFileTime, SetFilePointer, SetFileAttributesW, GetVolumeInformationW, GetFileAttributesW, GetVolumePathNameW, GetTempFileNameW, GetFullPathNameW, GetDriveTypeW, SetEndOfFile, CreateDirectoryW
api-ms-win-core-file-l1-2-0.dll
DeleteFileW, SetFileAttributesW, GetFileAttributesW, GetDriveTypeW, GetTempFileNameW, GetVolumeInformationW, GetVolumeNameForVolumeMountPointW, CreateDirectoryW, FlushFileBuffers, CreateFileW, GetLongPathNameW, SetEndOfFile, SetFilePointerEx, GetFileSizeEx, ReadFile, WriteFile, GetDiskFreeSpaceW, SetFileTime, GetFileType, GetFileTime, SetFileInformationByHandle, GetVolumePathNameW, GetFileAttributesExW, GetFileInformationByHandle, LocalFileTimeToFileTime, GetFullPathNameW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-1-0.dll
HeapFree, HeapCreate, HeapDestroy, HeapAlloc
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapFree, HeapDestroy, HeapCreate
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange, InterlockedIncrement, InterlockedDecrement, InterlockedExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedExchange, InterlockedCompareExchange, InterlockedDecrement
api-ms-win-core-libraryloader-l1-1-0.dll
DisableThreadLibraryCalls, GetModuleFileNameW, GetProcAddress, FreeLibrary, LoadLibraryExA, LoadLibraryExW, LoadStringW
api-ms-win-core-libraryloader-l1-1-1.dll
LoadLibraryExW, GetProcAddress, FreeLibrary, LoadStringW, DisableThreadLibraryCalls, GetModuleFileNameW
api-ms-win-core-localregistry-l1-1-0.dll
RegCloseKey, RegSetValueExW, RegOpenKeyExW, RegCreateKeyExW, RegQueryValueExW
api-ms-win-core-misc-l1-1-0.dll
Sleep, LocalFree, LocalAlloc, GlobalFree, FormatMessageW, lstrlenW
api-ms-win-core-processenvironment-l1-1-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-0.dll
SetThreadToken, OpenThreadToken, OpenProcessToken, GetCurrentProcess, SetThreadPriority, GetThreadPriority, GetCurrentThreadId, TlsFree, TlsGetValue, TlsSetValue, TlsAlloc, GetExitCodeThread, CreateThread, GetExitCodeProcess, CreateProcessAsUserW, GetCurrentProcessId, TerminateProcess, GetCurrentThread
api-ms-win-core-processthreads-l1-1-1.dll
TlsAlloc, TlsFree, TlsSetValue, CreateThread, GetCurrentThreadId, CreateProcessAsUserW, GetExitCodeProcess, GetCurrentProcessId, TerminateProcess, GetExitCodeThread, SetThreadPriority, TlsGetValue, GetThreadPriority, GetCurrentProcess, OpenProcessToken, GetCurrentThread, OpenThreadToken, SetThreadToken
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceFrequency, QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegCloseKey
api-ms-win-core-string-l1-1-0.dll
WideCharToMultiByte
api-ms-win-core-synch-l1-1-0.dll
WaitForSingleObject, OpenEventW, LeaveCriticalSection, SetEvent, EnterCriticalSection, CreateEventW, SetWaitableTimer, CancelWaitableTimer, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, ReleaseMutex, ReleaseSemaphore, WaitForMultipleObjectsEx, CreateMutexW, WaitForSingleObjectEx, SleepEx, InitializeCriticalSection, ResetEvent
api-ms-win-core-synch-l1-2-0.dll
Sleep, WaitForSingleObjectEx, SleepEx, InitializeCriticalSection, WaitForMultipleObjectsEx, ResetEvent, ReleaseSemaphore, WaitForSingleObject, SetEvent, ReleaseMutex, LeaveCriticalSection, EnterCriticalSection, CreateEventW, OpenEventW, SetWaitableTimer, CancelWaitableTimer, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, CreateMutexW
api-ms-win-core-sysinfo-l1-1-0.dll
GetTickCount, GetSystemTimeAsFileTime, SystemTimeToFileTime, GetTimeZoneInformation, GetVersionExW, GetSystemDirectoryW, GetLocalTime
api-ms-win-core-sysinfo-l1-2-0.dll
GetVersionExW, GetLocalTime, GetTickCount64, GetSystemTimeAsFileTime, GetTickCount, GetSystemDirectoryW
api-ms-win-core-threadpool-l1-1-0.dll
CloseThreadpoolWait, SetThreadpoolWait, CreateThreadpoolWait, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, CreateThreadpoolWork, SubmitThreadpoolWork, CloseThreadpoolWork, WaitForThreadpoolWorkCallbacks, WaitForThreadpoolWaitCallbacks, CancelThreadpoolIo, StartThreadpoolIo, WaitForThreadpoolIoCallbacks, CreateThreadpoolIo, CloseThreadpoolIo
api-ms-win-core-threadpool-l1-2-0.dll
WaitForThreadpoolIoCallbacks, CloseThreadpoolIo, CreateThreadpoolIo, StartThreadpoolIo, CancelThreadpoolIo, SubmitThreadpoolWork, WaitForThreadpoolWorkCallbacks, SetThreadpoolWait, CreateThreadpoolWait, CloseThreadpoolWait, WaitForThreadpoolWaitCallbacks, CloseThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, CreateThreadpoolCleanupGroup, CreateThreadpoolWork, CloseThreadpoolWork
api-ms-win-security-base-l1-1-0.dll
AllocateAndInitializeSid, FreeSid, SetTokenInformation, DuplicateTokenEx, ImpersonateLoggedOnUser, GetSidSubAuthorityCount, GetSidSubAuthority, ImpersonateSelf, CheckTokenMembership, AddMandatoryAce, InitializeAcl, SetSecurityDescriptorSacl, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, AccessCheck, MapGenericMask, MakeSelfRelativeSD, MakeAbsoluteSD, EqualSid, IsTokenRestricted, RevertToSelf, GetLengthSid, IsValidSid, AdjustTokenPrivileges, GetSecurityDescriptorControl, GetSecurityDescriptorSacl, GetSecurityDescriptorDacl, GetSecurityDescriptorGroup, GetSecurityDescriptorOwner, CreateRestrictedToken, CopySid, GetTokenInformation
api-ms-win-security-base-l1-2-0.dll
GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, GetSecurityDescriptorControl, CreateRestrictedToken, CopySid, IsValidSid, GetSecurityDescriptorGroup, GetSecurityDescriptorOwner, AdjustTokenPrivileges, GetLengthSid, MapGenericMask, IsTokenRestricted, RevertToSelf, EqualSid, ImpersonateLoggedOnUser, ImpersonateSelf, GetTokenInformation, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, DuplicateTokenEx, AccessCheck, MakeSelfRelativeSD, MakeAbsoluteSD, CheckTokenMembership, InitializeAcl, AddMandatoryAce, GetSidSubAuthorityCount, GetSidSubAuthority, SetTokenInformation, AllocateAndInitializeSid, FreeSid
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenSCManagerW, OpenServiceW
api-ms-win-service-management-l2-1-0.dll
QueryServiceConfigW, QueryServiceConfig2W, ChangeServiceConfigW, ChangeServiceConfig2W
crypt32.dll
CryptProtectData, CryptUnprotectData, CertFreeCertificateContext, CertDeleteCertificateFromStore, CertFindCertificateInStore, CertSetCertificateContextProperty, CertCompareCertificateName, CertGetSubjectCertificateFromStore, CertAddSerializedElementToStore, CertCloseStore, CertSerializeCertificateStoreElement, CertAddCertificateContextToStore, CertOpenStore, CertGetCertificateContextProperty, CertDuplicateCertificateContext, CertEnumCertificatesInStore, CryptDecodeObjectEx, CertStrToNameW, CertVerifyTimeValidity, CertAddEnhancedKeyUsageIdentifier, CertCreateSelfSignCertificate, CryptEncodeObjectEx, CertNameToStrW
iphlpapi.dll
GetIfTable, GetBestInterfaceEx, GetIfEntry, GetIfEntry2, GetAdaptersAddresses
kernel32.dll
DelayLoadFailureHook, CopyFileW, CreateWaitableTimerW, GetFileInformationByHandleEx, WaitForMultipleObjects, PostQueuedCompletionStatus, SwitchToThread, CreateIoCompletionPort, GetModuleHandleExW, GetQueuedCompletionStatus, FreeLibraryAndExitThread, GlobalMemoryStatus, RaiseFailFastException, GetVolumeNameForVolumeMountPointW, CreateSemaphoreW, LoadLibraryW, MoveFileExW, RegGetValueW, SetFilePointer, MultiByteToWideChar, GetComputerNameExW, GetVolumeInformationW, SetFileAttributesW, GetFileAttributesW, GetVolumePathNameW, GetFullPathNameW, GetTempFileNameW, GetDriveTypeW, FindClose, FindNextFileW, FindFirstFileW, VirtualFree, VirtualAlloc, RaiseException, UnhandledExceptionFilter, lstrlenW, QueryPerformanceFrequency, RemoveDirectoryW, GetFileSize, WaitForSingleObjectEx, InterlockedExchange, OutputDebugStringA, GetCurrentProcessId, TerminateProcess, SetUnhandledExceptionFilter, DeleteFileW, GetLastError, GetProcAddress, GetVersionExW, LoadLibraryExW, GetSystemDirectoryW, SetLastError, FreeLibrary, Sleep, CloseHandle, WaitForSingleObject, OpenEventW, DisableThreadLibraryCalls, SetEvent, GetTickCount, GetModuleFileNameW, EnterCriticalSection, CreateEventW, GetSystemTimeAsFileTime, GetCurrentThreadId, LeaveCriticalSection, HeapAlloc, HeapFree, HeapCreate, InterlockedCompareExchange, LoadLibraryA, InterlockedDecrement, InterlockedIncrement, LocalFree, GetCurrentThread, GetCurrentProcess, LocalAlloc, GlobalFree, UnregisterWait, SetThreadPriority, GetThreadPriority, SetWaitableTimer, CancelWaitableTimer, GetDiskFreeSpaceW, RegisterWaitForSingleObject, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, FormatMessageW, DuplicateHandle, ExpandEnvironmentStringsW, GetLongPathNameW, CreateFileW, SetEndOfFile, SetFilePointerEx, GetFileSizeEx, FlushFileBuffers, WriteFile, ReadFile, SetFileInformationByHandle, DeleteFileA, GetFileAttributesExW, GetFileInformationByHandle, SetFileTime, BindIoCompletionCallback, GetFileTime, GetFileType, SystemTimeToFileTime, FileTimeToSystemTime, WideCharToMultiByte, QueueUserWorkItem, QueryPerformanceCounter, GetSystemTime, TlsSetValue, ReleaseMutex, ReleaseSemaphore, TlsGetValue, TlsFree, WaitForMultipleObjectsEx, CreateMutexW, TlsAlloc, GetExitCodeThread, CreateThread, ResetEvent, InitializeCriticalSection, SleepEx, GetExitCodeProcess, GetTimeZoneInformation, LocalFileTimeToFileTime, GetLocalTime, GetComputerNameW, GetDiskFreeSpaceExW, CreateDirectoryW, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, InitializeSRWLock
mpr.dll
WNetGetConnectionW
msvcrt.dll
DllMain
netapi32.dll
NetApiBufferFree, NetWkstaGetInfo, NetGetJoinInformation
ntdll.dll
EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, WinSqmSetDWORD, WinSqmIncrementDWORD, WinSqmIsOptedIn, NtQueryInformationThread, RtlLengthSecurityDescriptor, EtwEventEnabled, EtwEventWrite, EtwEventUnregister, EtwEventRegister, EtwEventActivityIdControl, DbgPrint, EtwTraceMessage
ole32.dll
StringFromGUID2, CoRegisterClassObject, CoTaskMemAlloc, CoTaskMemFree, CoRevokeClassObject, CoCreateInstance, CoImpersonateClient, CoRevertToSelf, CoInitializeEx, CoInitializeSecurity, CoUninitialize, CoCreateGuid, IIDFromString, StringFromIID, CoDisconnectContext
rpcrt4.dll
RpcImpersonateClient, RpcBindingSetAuthInfoExW, UuidCreate, RpcBindingFromStringBindingW, RpcStringBindingComposeW, RpcBindingVectorFree, RpcEpUnregister, RpcServerInqBindings, RpcServerUnregisterIfEx, RpcServerRegisterIf2, RpcAsyncCancelCall, RpcBindingFree, RpcAsyncInitializeHandle, RpcAsyncCompleteCall, RpcStringFreeW, RpcRevertToSelfEx, RpcServerRegisterAuthInfoW, RpcServerInqDefaultPrincNameW, RpcEpRegisterW, RpcServerUseProtseqW, NdrAsyncClientCall, NdrAsyncServerCall, RpcBindingSetOption
shell32.dll
SHGetFolderPathW
shfolder.dll
SHGetFolderPathW
shlwapi.dll
UrlCombineW, PathFindExtensionW
user32.dll
MsgWaitForMultipleObjectsEx, UnregisterClassW, DestroyWindow, PostMessageW, DefWindowProcW, RegisterDeviceNotificationW, UnregisterDeviceNotification, RegisterClassExW, GetWindowLongW, SetWindowLongW, CreateWindowExW, TranslateMessage, DispatchMessageW, PeekMessageW, LoadStringW, CharNextW, RegisterPowerSettingNotification, UnregisterPowerSettingNotification
winhttp.dll
WinHttpQueryAuthSchemes, WinHttpSetCredentials, WinHttpOpenRequest, WinHttpTimeFromSystemTime, WinHttpReadData, WinHttpQueryDataAvailable, WinHttpWriteData, WinHttpReceiveResponse, WinHttpSetStatusCallback, WinHttpCrackUrl, WinHttpQueryOption, WinHttpCloseHandle, WinHttpAddRequestHeaders, WinHttpGetProxyForUrl, WinHttpGetIEProxyConfigForCurrentUser, WinHttpSetOption, WinHttpConnect, WinHttpOpen, WinHttpQueryHeaders, WinHttpSendRequest
ws2_32.dll
GetAddrInfoW, FreeAddrInfoW, WSASocketW, WSAIoctl, WSAStringToAddressW
wtsapi32.dll
WTSFreeMemory, WTSEnumerateSessionsW
Export table
BITSServiceMain
ServiceMain