Import table
advapi32.dll
OpenProcessToken, LookupPrivilegeValueW, OpenThreadToken, DeleteService, ChangeServiceConfigW, ControlService, CloseServiceHandle, StartServiceW, OpenServiceW, OpenSCManagerW, AdjustTokenPrivileges, QueryServiceStatus, RegQueryValueExW, RegEnumKeyW, RegDeleteValueW, RegSetValueExW, RegCreateKeyW, RegDeleteKeyW, RegEnumValueW, RegEnumKeyExW, RegCloseKey, RegQueryInfoKeyW, RegOpenKeyExW
kernel32.dll
MoveFileW, GetWindowsDirectoryW, GetSystemDirectoryW, GetModuleHandleW, SetLastError, CreateDirectoryW, GetProcAddress, FlushFileBuffers, GetLongPathNameW, GetFullPathNameW, ExpandEnvironmentStringsW, TerminateProcess, LoadLibraryW, GetCurrentProcess, GetProcessHeap, FreeLibrary, HeapAlloc, HeapFree, CreateProcessW, RemoveDirectoryW, GetExitCodeProcess, OpenProcess, GetVersionExW, GetCurrentThread, GetCurrentThreadId, GetVersion, GetEnvironmentVariableW, GetLogicalDriveStringsW, DeviceIoControl, GetLocalTime, FormatMessageW, LocalFree, MultiByteToWideChar, lstrlenA, WideCharToMultiByte, GetDriveTypeA, WriteConsoleW, InterlockedDecrement, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, GetCurrentProcessId, FindNextFileW, FindClose, FindFirstFileW, GetLastError, CloseHandle, CreateFileW, SetFileAttributesW, SetFilePointer, DeleteFileW, WriteFile, ReadFile, GetTempFileNameW, GetTempPathW, SetEnvironmentVariableA, SetEndOfFile, GetFileAttributesW, CopyFileW, GetDriveTypeW, CreateFileA, CompareStringA, CompareStringW, WaitForSingleObject, GetConsoleOutputCP, WriteConsoleA, GetTimeZoneInformation, SetStdHandle, GetStringTypeW, GetStringTypeA, GetConsoleMode, GetConsoleCP, GetLocaleInfoA, LoadLibraryA, GetTickCount, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetCurrentDirectoryA, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, FileTimeToSystemTime, FileTimeToLocalFileTime, GetCommandLineA, GetVersionExA, RtlUnwind, RaiseException, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, VirtualFree, VirtualAlloc, HeapReAlloc, HeapDestroy, HeapCreate, ExitProcess, GetStdHandle, GetModuleFileNameA, Sleep, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, LCMapStringA, LCMapStringW, SetHandleCount, GetFileType, GetStartupInfoA, GetSystemInfo
netapi32.dll
NetScheduleJobEnum, NetApiBufferFree, NetScheduleJobDel
ole32.dll
CoCreateInstance, CoUninitialize, CoInitialize, CoTaskMemFree, StringFromGUID2
sfc.dll
SfcIsFileProtected
Export table
RemFileAppend
RemFileClose
RemFileCopy
RemFileDelete
RemFileExists
RemFileGetAbbreviatedPath
RemFileGetAbbreviatedPathCount
RemFileGetADSInfo
RemFileGetAttrib
RemFileGetExpandedPath
RemFileGetExpandedPathCount
RemFileInsertChunk
RemFileIsProtected
RemFileOpen
RemFileRead
RemFileRemoveChunk
RemFileSeek
RemFileSetAttrib
RemFileTruncate
RemFileWrite
RemFileXlateFromDrivePrefix
RemFolderCopy
RemFolderCreate
RemFolderDelete
RemFolderExists
RemFolderFindFileClose
RemFolderFindFirstFile
RemFolderFindNextFile
RemGetEnvironmentVariable
RemGetLogicalDrive
RemGetLogicalDriveCount
RemGetOSVersion
RemGetProcessorArchitecture
RemInitialize
RemProcessIsRunningAsWow64
RemProcessKill
RemProcessResume
RemProcessSnapshot
RemProcessSuspend
RemRegistryEnumKey
RemRegistryEnumValue
RemRegistryGetUserKey
RemRegistryGetUserKeyCount
RemRegistryKeyCreate
RemRegistryKeyDelete
RemRegistryKeyQueryInfo
RemRegistryTreeDelete
RemRegistryValueDelete
RemRegistryValueGet
RemRegistryValueSet
RemScanDerivatives
RemServiceDelete
RemServiceDisable
RemServiceEnable
RemServicePause
RemServiceQueryStatus
RemServiceResume
RemServiceStart
RemServiceStop
RemShutdown
RemSystemDeleteScheduledJob
RemSystemExec
RemSystemGetScheduledJobsEnum