Import table
advapi32.dll
DuplicateTokenEx, GetSecurityDescriptorLength, RegCloseKey, RegisterEventSourceA, ReportEventA, DeregisterEventSource, CryptVerifySignatureA, CryptSignHashA, CryptExportKey, CryptGenKey, CryptGetKeyParam, CryptDestroyKey, RegQueryValueExA, CryptGenRandom, CryptReleaseContext, RegCreateKeyExA, RegSetValueExA, RegDeleteKeyA, CryptAcquireContextA, CryptImportKey, CryptHashData, CryptDestroyHash, RegOpenKeyExW, RegCreateKeyExW, RegSetValueExW, RegDeleteKeyW, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteValueW, OpenThreadToken, OpenProcessToken, GetTokenInformation, ConvertSidToStringSidW, RegQueryValueExW, CreateProcessAsUserW, ConvertStringSecurityDescriptorToSecurityDescriptorW, ImpersonateLoggedOnUser, CryptCreateHash, CryptGetHashParam, CryptDeriveKey, CryptSetKeyParam, CryptDecrypt, RegOpenCurrentUser, RegOpenKeyExA, IsValidSecurityDescriptor, GetSecurityDescriptorControl, MakeSelfRelativeSD, SetServiceStatus, RegisterServiceCtrlHandlerExW, RevertToSelf, RegEnumValueW, InitializeAcl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, GetSecurityDescriptorSacl, SetSecurityInfo, AddAccessAllowedAce
crypt32.dll
CertOpenSystemStoreA, CertFindChainInStore, CertSetCertificateContextProperty, CertNameToStrA, CertGetIssuerCertificateFromStore, CertCreateCertificateContext, CertFreeCertificateContext, CryptMsgClose, CertFreeCertificateChain, CertGetSubjectCertificateFromStore, CryptMsgGetParam, CryptQueryObject, CertGetNameStringW, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CertGetCertificateContextProperty, CryptDecodeObject, CertCloseStore, CertGetNameStringA
dnsapi.dll
DnsQuery_A, DnsRecordListFree
iphlpapi.dll
GetAdaptersInfo
kernel32.dll
DllMain, MultiByteToWideChar, SizeofResource, LoadResource, FindResourceW, LoadLibraryExW, DisableThreadLibraryCalls, InitializeCriticalSection, LockResource, FindResourceExW, GetTickCount, OpenEventW, SetFilePointer, ReadFile, OutputDebugStringA, WriteFile, WideCharToMultiByte, DeleteFileW, GetCurrentThread, GetCurrentProcess, GetExitCodeThread, CreateDirectoryW, lstrlenW, CreateProcessW, OpenProcess, lstrcmpW, IsBadReadPtr, IsBadCodePtr, HeapFree, GetProcessHeap, LoadLibraryW, HeapAlloc, CreateThread, TerminateThread, InterlockedExchange, GetCurrentThreadId, GlobalFree, CreateEventA, Sleep, ResetEvent, MapViewOfFile, CreateFileMappingA, EnterCriticalSection, LoadLibraryA, GetSystemDirectoryA, GetTimeZoneInformation, GetSystemTime, GetSystemTimeAsFileTime, GetVersionExA, GetSystemInfo, FormatMessageA, ConnectNamedPipe, CreateNamedPipeA, QueryPerformanceCounter, QueryPerformanceFrequency, LocalAlloc, CreateFileA, WriteConsoleW, SetFilePointerEx, FlushFileBuffers, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCurrentProcessId, LeaveCriticalSection, lstrcmpiW, FreeLibrary, GetModuleFileNameW, GetModuleHandleW, GetProcAddress, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, InterlockedDecrement, InterlockedIncrement, LocalFree, GetLastError, RaiseException, GetFileAttributesW, WaitForMultipleObjects, ReadDirectoryChangesW, GetOverlappedResult, CreateFileW, WaitForSingleObject, SetEvent, CreateEventW, CloseHandle, OutputDebugStringW, CompareStringW, SetEndOfFile, InterlockedCompareExchange, GetFullPathNameW, SetEnvironmentVariableA, GetFullPathNameA, WaitForSingleObjectEx, UnlockFileEx, UnlockFile, SystemTimeToFileTime, LockFileEx, LockFile, HeapValidate, HeapCreate, GetTempPathW, GetTempPathA, GetFileSize, GetFileAttributesExW, GetFileAttributesA, GetDiskFreeSpaceW, GetDiskFreeSpaceA, FormatMessageW, DeleteFileA, GetModuleFileNameA, GetStringTypeW, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, RtlUnwind, GetStdHandle, GetStartupInfoW, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, TerminateProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetModuleHandleExW, ExitProcess, AreFileApisANSI, ReadConsoleW, GetConsoleMode, GetConsoleCP, GetFileType, SetStdHandle, GetCommandLineA, VirtualQuery, VirtualProtect, VirtualAlloc, IsProcessorFeaturePresent, IsDebuggerPresent, ExitThread, LCMapStringW, EncodePointer, DecodePointer, HeapSize, CreateMutexW, CreateFileMappingW, UnmapViewOfFile, HeapReAlloc, HeapDestroy, SetLastError
ole32.dll
CoInitializeEx, CoUninitialize, CoRevertToSelf, CoRegisterClassObject, CoCreateInstance, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoResumeClassObjects, CoImpersonateClient, StringFromGUID2, CoRevokeClassObject, CoCreateGuid, StringFromCLSID
rpcrt4.dll
UuidCreate, UuidToStringA, RpcStringFreeA
secur32.dll
DeleteSecurityContext, FreeCredentialsHandle, AcquireCredentialsHandleA, QueryContextAttributesA, EncryptMessage, DecryptMessage, FreeContextBuffer, ApplyControlToken, InitializeSecurityContextA
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
StrSpnW, PathAppendA, StrStrIW, UrlGetPartW, StrRChrW, StrCmpW
urlmon.dll
CoInternetParseUrl
user32.dll
CharLowerBuffW, CharNextW, wsprintfW, PostThreadMessageW, GetMessageW, DispatchMessageW, GetUserObjectInformationW, GetProcessWindowStation, GetDesktopWindow, MessageBoxA, TranslateMessage
userenv.dll
CreateEnvironmentBlock
winhttp.dll
WinHttpConnect, WinHttpSetOption, WinHttpOpen, WinHttpAddRequestHeaders, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpQueryHeaders, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpCloseHandle, WinHttpCrackUrl, WinHttpGetProxyForUrl, WinHttpOpenRequest
wintrust.dll
WinVerifyTrust
ws2_32.dll
WSAEventSelect, WSACloseEvent, WSAEnumNetworkEvents, WSACreateEvent
wtsapi32.dll
WTSFreeMemory, WTSEnumerateProcessesW
Export table
_sa_list_count
_sa_list_destroy
_sa_regex_create
_sa_regex_execute
_sa_regex_release
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer