Import table
advapi32.dll
CryptEncrypt, CryptAcquireContextW, CryptGenKey, CryptReleaseContext, CloseServiceHandle, AllocateAndInitializeSid, EqualSid, FreeSid, OpenProcessToken, GetTokenInformation, OpenServiceW, OpenSCManagerW, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, CryptDestroyKey, CryptExportKey, CryptImportKey
kernel32.dll
InterlockedExchange, GetCurrentProcessId, OutputDebugStringA, GetTickCount, GetCurrentThread, CloseHandle, FlushInstructionCache, OpenProcess, InterlockedExchangeAdd, CreateEventW, WaitForSingleObject, SetEvent, ResetEvent, MultiByteToWideChar, WideCharToMultiByte, GetModuleFileNameW, DeleteFileW, MoveFileW, CreateDirectoryW, FindClose, FindNextFileW, FindFirstFileW, CompareFileTime, ProcessIdToSessionId, VirtualQuery, RtlCaptureContext, GetSystemInfo, TerminateProcess, GetModuleHandleW, GetSystemTime, SetLastError, GetLastError, GetCurrentThreadId, QueryPerformanceFrequency, GetModuleHandleA, GetCurrentProcess, QueryPerformanceCounter, GetProcAddress, InitializeCriticalSection, InterlockedIncrement, TlsGetValue, TlsSetValue, TlsAlloc, LeaveCriticalSection, EnterCriticalSection, Sleep, InterlockedCompareExchange, UnhandledExceptionFilter, IsDebuggerPresent, SetUnhandledExceptionFilter, GetSystemTimeAsFileTime, LoadLibraryA, FreeLibrary, GetModuleFileNameA, DeleteCriticalSection, GetVersionExW, InitializeCriticalSectionAndSpinCount, CreateSemaphoreW, ReleaseSemaphore, InterlockedDecrement
msvcp80.dll
DllMain
msvcr80.dll
DllMain
shell32.dll
SHGetFolderPathA, SHGetFolderPathW
shlwapi.dll
PathAppendA
user32.dll
GetDesktopWindow
Export table
rooks_ext_get_rooks_extension