Import table
advapi32.dll
DeleteService, CreateProcessAsUserW, GetTokenInformation, OpenProcessToken, LookupPrivilegeValueW, RegCloseKey, RegCreateKeyExW, RegSetValueExW, RegDeleteValueW, OpenServiceA, RegOpenKeyExA, RegDeleteValueA, RegSetValueExA, RegQueryValueExW, AdjustTokenPrivileges, OpenSCManagerW, OpenServiceW, StartServiceW, CloseServiceHandle, CreateServiceW, RegOpenKeyExW
iphlpapi.dll
GetIpAddrTable, NotifyAddrChange
kernel32.dll
QueryDosDeviceW, GetLogicalDriveStringsW, GetProcessHeap, CopyFileW, GetModuleFileNameW, GetSystemDirectoryW, DeleteFileW, CreateFileA, SetLastError, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, RtlUnwind, InterlockedCompareExchange, Sleep, InterlockedExchange, GetFileSize, GetSystemDirectoryA, DeleteFileA, MoveFileExW, TerminateThread, GetModuleHandleA, CreateFileW, ReadFile, HeapAlloc, HeapFree, CreateEventW, SetEvent, WaitForSingleObject, CloseHandle, SleepEx, VirtualFree, GetCurrentProcess, GetProcAddress, GetModuleHandleW, GetLastError, OpenProcess, GetOverlappedResult, VirtualAlloc, CreateThread, GetVersionExW, FreeLibrary, LoadLibraryW, DeviceIoControl
msvcrt.dll
DllMain
shlwapi.dll
SHDeleteKeyW, SHDeleteKeyA, StrCmpIW, PathFindExtensionW, PathFileExistsW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
ws2_32.dll
WSACreateEvent, WSACloseEvent, WSAResetEvent
Export table
AddAntiInjectDllName
AddAntiInjectWhiteProcessName
AddBlackFileName
AddBlackProcessByPid
AddClientRule
AddClientRule2
AddExceptionRule
AddInjectBlockRule
AddInjectRule
AddKernelRule
AddProtectedFile
AddProtectedFile2
AddRule
AddRule2
AddTraceRule
AddWhiteFileName
AddWhiteProcessByPid
aklSetProcess
aklStart
aklStop
CleanInjectRule
CleanupAllClientRules
CleanupAllRules
ClearAntiInjectRule
ClearBlackFileList
ClearBlackProcessList
ClearWhiteFileList
ClearWhiteProcessList
CloseClientSession
ConfigObjectTracer
ConfigObjectTraceRule
CreateClientSession
dcAddProcessDllRule
dcCleanAll
dcDeclare
dcRemoveProcessDllRule
dcSetDllCache
FlushObjectTracerLogs
GetClientSessionHandle
GetLastProcessCreationTime
GetObjectTracerConfig
InsertBrowserProcess
InsertProtectionModule
InsertProtectionProcess
Install
NotifyDriverClientResult
NotifyDriverResult
pslClearRecord
pslDisablePerpetually
pslEnablePerpetually
pslFindClose
pslFindFirstProcess
pslFindFirstSection
pslFindNextProcess
pslFindNextSection
pslGetCurrentProcessTimesInfo
pslStartRecord
pslStopRecord
pslStopRecordTimesInfo
QueryDriverVersion
QueryProtectedInformation
ReloadObjectTracerRules
RemoveAllBrowserProcess
RemoveAllKernelRule
RemoveAllProtectedFile
RemoveAllProtectedFile2
RemoveAllProtectionModule
RemoveAllProtectionProcess
RemoveAllTraceRules
RemoveBlackFileName
RemoveBlackProcessByPid
RemoveProtectedFile
RemoveProtectedFile2
RemoveTraceRule
RemoveWhiteFileName
RemoveWhiteProcessByPid
SetAppdVersion
SetProcessContext
SetProcessProtection
SetProtectionState
SetProtectionState2
SetupInstall
StartHook
StartHook2
StartHookEx
StopHook
swSetMessage
swSetProcess
Uninstall
UserConfigObjectTracer