Import table
advapi32.dll
SetServiceStatus, EnumServicesStatusW, QueryServiceConfigW, QueryServiceConfig2W, QueryServiceStatusEx, CloseServiceHandle, StartServiceW, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptReleaseContext, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, DuplicateToken, SetThreadToken, OpenThreadToken, GetLengthSid, AddAccessAllowedAce, GetTokenInformation, GetSecurityDescriptorSacl, SetSecurityInfo, DuplicateTokenEx, SetTokenInformation, CreateProcessAsUserW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RevertToSelf, ConvertStringSecurityDescriptorToSecurityDescriptorW, LookupPrivilegeValueW, OpenProcessToken, AdjustTokenPrivileges, ConvertStringSidToSidW, LookupAccountSidW, RegOpenKeyExW, OpenEventLogW, ReportEventW, ControlService, OpenServiceW, OpenSCManagerW, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, RegCloseKey, RegQueryValueExW
crypt32.dll
CryptUnprotectData, CryptProtectData
gdi32.dll
GetDeviceCaps, CreateFontW, SelectObject, SetBkColor, SetTextColor, TextOutW, CreateSolidBrush
kernel32.dll
MulDiv, GetModuleFileNameW, SuspendThread, DeleteCriticalSection, TryEnterCriticalSection, CreateMutexW, CreateProcessW, OpenMutexW, DefineDosDeviceW, QueryPerformanceCounter, GetSystemTimeAsFileTime, UnhandledExceptionFilter, GetStartupInfoA, QueueUserWorkItem, CancelIo, HeapCreate, GetSystemWindowsDirectoryW, HeapReAlloc, GetFileAttributesW, CopyFileW, SetFileAttributesW, SetEndOfFile, OpenFileMappingW, DeleteFileW, SetUnhandledExceptionFilter, VirtualAlloc, ExitProcess, RaiseException, VirtualFree, InitializeCriticalSectionAndSpinCount, InterlockedExchange, GetCurrentThreadId, LeaveCriticalSection, OutputDebugStringW, EnterCriticalSection, InterlockedCompareExchange, InterlockedIncrement, SetCurrentDirectoryW, InterlockedDecrement, HeapAlloc, GetProcessHeap, GetPrivateProfileStringW, GetFullPathNameW, GlobalFree, GlobalUnlock, GlobalLock, Sleep, GetEnvironmentVariableW, GetLastError, HeapFree, GetCommandLineW, GetSystemInfo, GetModuleHandleW, InitializeCriticalSection, TerminateThread, WaitForMultipleObjects, CloseHandle, TerminateProcess, GetProcessTimes, OpenProcess, WaitForSingleObject, GlobalAlloc, DuplicateHandle, ReadProcessMemory, WriteProcessMemory, VirtualAllocEx, SetLastError, VirtualProtectEx, WriteFile, SetFilePointer, CreateFileW, LocalFree, GetProcAddress, LockResource, LoadResource, SizeofResource, FindResourceW, GetLocalTime, LocalAlloc, SetThreadPriority, GetCurrentThread, GetCurrentProcess, GetVersionExW, CreateThread, GetTickCount, TlsSetValue, TlsGetValue, ProcessIdToSessionId, OpenThread, TlsAlloc, GetCurrentProcessId, CreateEventW, ResetEvent, SetInformationJobObject, CreateJobObjectW, QueryInformationJobObject, AssignProcessToJobObject, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, UnregisterWait, GetConsoleWindow, LoadLibraryW, GlobalSize, IsProcessInJob, RegisterWaitForSingleObject, GetConsoleProcessList, SetEvent, AllocConsole, OpenEventW, ResumeThread, GetWindowsDirectoryW
msvcrt.dll
DllMain
netapi32.dll
NetUseAdd
ntdll.dll
NtWriteFile, NtClose, NtSetInformationThread, NtDuplicateToken, NtFilterToken, NtQueryInformationToken, NtOpenProcessToken, NtOpenThreadToken, NtRequestPort, NtUnloadKey, NtOpenKey, RtlInitUnicodeString, LdrFindEntryForAddress, NtOpenFile, RtlNtStatusToDosError, NtAllocateVirtualMemory, NtDuplicateObject, NtOpenProcess, NtRequestWaitReplyPort, NtConnectPort, RtlCreateSecurityDescriptor, RtlSetDaclSecurityDescriptor, NtSetInformationFile, NtQueryDirectoryFile, NtCreateFile, NtQueryInformationFile, NtCreatePort, NtReadFile, NtLoadKey, NtOpenDirectoryObject, NtSetInformationProcess, NtQueryInformationProcess, NtImpersonateClientOfPort, NtAcceptConnectPort, NtCompleteConnectPort, NtLoadDriver, RtlInitString, NtReplyWaitReceivePort
ole32.dll
CoRevokeClassObject, CoRegisterClassObject, CoInitialize, CoTaskMemFree, CoInitializeEx, CoInitializeSecurity, CoMarshalInterface, CoCopyProxy, CoSetProxyBlanket, CoQueryProxyBlanket, CreateStreamOnHGlobal, CoUnmarshalInterface, StringFromGUID2, CoGetObject, CoGetClassObject
sbiedll.dll
_SbieApi_QueryConfBool@12, SbieApi_LogEx, _SbieApi_GetUnmountHive@4, _SbieApi_EnumProcessEx@16, _SbieApi_QueryProcess@20, _SbieApi_CallOne@8, _SbieApi_GetHomePath@16, _SbieApi_SetUserName@8, _SbieDll_GetServiceRegistryValue@12, _SbieDll_FormatMessage2@12, _SbieApi_GetWork@12, _SbieApi_CallZero@4, _SbieApi_GetVersion@4, _SbieDll_PortName@0, _SbieDll_FreeMem@4, _SbieDll_QueuePutRpl@16, _SbieDll_QueueGetReq@24, _SbieApi_IsBoxEnabled@4, _SbieApi_QueryPathList@16, _SbieDll_KillOne@4, _SbieApi_QueryProcessEx2@28, _SbieDll_QueueCreate@8, _SbieApi_CallTwo@12, _SbieApi_QueryConf@20, _SbieDll_RunFromHome@16, _SbieApi_SessionLeader@8, _SbieApi_ReloadConf@4, _SbieApi_QueryProcessPath@28, _SbieDll_FormatMessage0@4, _SbieApi_OpenProcess@8, _SbieDll_GetLanguage@4, _SbieDll_RunSandboxed@24, _SbieDll_ComCreateStub@16, _SbieDll_IsOpenClsid@12, _SbieApi_CheckInternetAccess@12, _SbieApi_QueryProcessInfo@8, SbieApi_Log
secur32.dll
LsaDeregisterLogonProcess, LsaConnectUntrusted, LsaLookupAuthenticationPackage
user32.dll
SetThreadDesktop, CreateDesktopW, SetProcessWindowStation, CreateWindowStationW, GetThreadDesktop, GetProcessWindowStation, IsZoomed, IsIconic, IsWindowUnicode, IsWindowEnabled, IsWindowVisible, IsWindow, GetWindowLongA, GetWindowLongW, GetClassLongA, GetClassLongW, GetPropA, GetPropW, GetWindow, GetParent, GetShellWindow, GetClassNameA, GetClassNameW, GetClientRect, GetWindowRect, GetWindowInfo, GetIconInfo, FindWindowExA, FindWindowExW, FindWindowA, FindWindowW, MapWindowPoints, ScreenToClient, ClientToScreen, EnumClipboardFormats, UserHandleGrantAccess, GetClipboardSequenceNumber, ClipCursor, SetForegroundWindow, MonitorFromWindow, ChangeDisplaySettingsExA, ChangeDisplaySettingsExW, GetWindowThreadProcessId, DestroyWindow, KillTimer, PostMessageW, SetPropW, SendMessageW, CreateWindowExW, RegisterClassW, DefWindowProcW, SetWindowPos, SendMessageTimeoutW, SendNotifyMessageA, SendNotifyMessageW, SendMessageA, PostMessageA, PackDDElParam, EnumThreadWindows, EnumChildWindows, EnumWindows, EndPaint, BeginPaint, ShowWindow, GetMonitorInfoW, RegisterClassExW, DispatchMessageW, GetMessageW, SetTimer, CloseClipboard, SetClipboardData, GetDesktopWindow, OpenClipboard, GetClipboardData, EmptyClipboard, wsprintfW
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
wtsapi32.dll
WTSQueryUserToken