Import table
advapi32.dll
OpenSCManagerW, DeleteService, OpenProcessToken, ChangeServiceConfigW, ControlService, CloseServiceHandle, StartServiceW, OpenServiceW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenThreadToken, QueryServiceStatus, RegEnumKeyW, RegDeleteValueW, RegSetValueExW, RegCreateKeyW, RegQueryValueExW, RegEnumValueW, RegEnumKeyExW, RegCloseKey, RegQueryInfoKeyW, RegOpenKeyExW, RegDeleteKeyW
kernel32.dll
SetLastError, GetModuleHandleW, CreateDirectoryW, FlushFileBuffers, GetDriveTypeW, GetLongPathNameW, GetFullPathNameW, GetProcAddress, RemoveDirectoryW, MoveFileW, ExpandEnvironmentStringsW, GetVersionExW, LoadLibraryW, GetCurrentProcess, GetCurrentThread, TerminateProcess, CreateProcessW, WaitForSingleObject, GetProcessHeap, GetExitCodeProcess, HeapAlloc, HeapFree, InterlockedDecrement, OpenProcess, GetVersion, GetCurrentThreadId, GetLocalTime, FormatMessageW, LocalFree, MultiByteToWideChar, lstrlenA, WideCharToMultiByte, GetDriveTypeA, WriteConsoleW, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSection, GetCurrentProcessId, GetLastError, FindNextFileW, FindClose, FindFirstFileW, SetFilePointer, DeleteFileW, WriteFile, ReadFile, GetTempFileNameW, GetTempPathW, SetEnvironmentVariableA, SetEndOfFile, CopyFileW, CloseHandle, CreateFileW, SetFileAttributesW, GetFileAttributesW, CreateFileA, CompareStringA, CompareStringW, FreeLibrary, GetConsoleOutputCP, WriteConsoleA, GetTimeZoneInformation, GetLocaleInfoA, GetStringTypeW, GetStringTypeA, GetConsoleMode, GetConsoleCP, SetStdHandle, LoadLibraryA, GetTickCount, QueryPerformanceCounter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetSystemTimeAsFileTime, FileTimeToSystemTime, FileTimeToLocalFileTime, GetCommandLineA, GetVersionExA, RtlUnwind, RaiseException, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, VirtualFree, VirtualAlloc, HeapReAlloc, HeapDestroy, HeapCreate, ExitProcess, GetStdHandle, GetModuleFileNameA, Sleep, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, LCMapStringA, LCMapStringW, SetHandleCount, GetFileType, GetStartupInfoA, GetCurrentDirectoryA, FreeEnvironmentStringsA
netapi32.dll
NetScheduleJobDel, NetApiBufferFree, NetScheduleJobEnum
ole32.dll
StringFromGUID2, CoTaskMemFree
Export table
RemFileAppend
RemFileClose
RemFileCopy
RemFileDelete
RemFileGetADSInfo
RemFileGetAttrib
RemFileGetExpandedPath
RemFileGetExpandedPathCount
RemFileInsertChunk
RemFileOpen
RemFileRead
RemFileRemoveChunk
RemFileSeek
RemFileSetAttrib
RemFileTruncate
RemFileWrite
RemFolderCopy
RemFolderCreate
RemFolderDelete
RemFolderFindFileClose
RemFolderFindFirstFile
RemFolderFindNextFile
RemInitialize
RemProcessKill
RemProcessResume
RemProcessSnapshot
RemProcessSuspend
RemRegistryEnumKey
RemRegistryEnumValue
RemRegistryGetUserKey
RemRegistryGetUserKeyCount
RemRegistryKeyCreate
RemRegistryKeyDelete
RemRegistryKeyQueryInfo
RemRegistryTreeDelete
RemRegistryValueDelete
RemRegistryValueGet
RemRegistryValueSet
RemServiceDelete
RemServiceDisable
RemServiceEnable
RemServicePause
RemServiceQueryStatus
RemServiceResume
RemServiceStart
RemServiceStop
RemShutdown
RemSystemDeleteScheduledJob
RemSystemExec
RemSystemGetScheduledJobsEnum