Import table
advapi32.dll
GetCurrentHwProfileW, CloseServiceHandle, GetSecurityInfo, GetAce, AllocateAndInitializeSid, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, FreeSid, SetSecurityInfo, GetLengthSid, InitializeAcl, AddAccessAllowedAceEx, AddAccessAllowedAce, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegEnumValueW, RegDeleteValueW, RegOpenKeyExA, RegQueryValueExA, RegSetValueExW, RegQueryValueExW, EqualSid, GetTokenInformation, CryptVerifySignatureW, CryptHashData, CryptImportKey, CryptDestroyKey, CryptDestroyHash, RegEnumKeyExW, CryptReleaseContext, CryptAcquireContextW, CryptCreateHash, OpenSCManagerW, QueryServiceStatus, QueryServiceConfigW, DeleteService, ChangeServiceConfigW, SetServiceStatus, ChangeServiceConfig2W, CreateServiceW, RegisterServiceCtrlHandlerExW, EventWrite, EventEnabled, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegDeleteKeyW, OpenServiceW, CreateProcessAsUserW, SetThreadToken, RevertToSelf, ImpersonateLoggedOnUser, OpenProcessToken, OpenThreadToken, EventRegister, EventUnregister, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll
RaiseException, GetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter
api-ms-win-core-file-l1-2-0.dll
GetVolumePathNamesForVolumeNameW, CreateFileW, GetFileAttributesW, GetVolumeInformationW, GetVolumeNameForVolumeMountPointW, GetVolumePathNameW, FindFirstFileW, FindClose, ReadFile
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll
GetProcessHeap, HeapAlloc, HeapFree
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc, LocalFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedDecrement, InterlockedIncrement, InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-io-l1-1-1.dll
DeviceIoControl, CancelIo, GetOverlappedResult
api-ms-win-core-kernel32-legacy-l1-1-0.dll
WaitForMultipleObjects
api-ms-win-core-libraryloader-l1-1-1.dll
LoadLibraryExW, GetProcAddress, FreeLibrary, DisableThreadLibraryCalls
api-ms-win-core-memory-l1-1-1.dll
VirtualFreeEx, VirtualAllocEx, WriteProcessMemory
api-ms-win-core-path-l1-1-0.dll
PathCchAddBackslash
api-ms-win-core-privateprofile-l1-1-0.dll
GetPrivateProfileStringW, WritePrivateProfileStringW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll
OpenThreadToken, GetCurrentThread, CreateThread, GetCurrentProcessId, QueueUserAPC, GetCurrentProcess, TerminateProcess, GetCurrentThreadId, ProcessIdToSessionId, OpenProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegCloseKey, RegSetValueExW, RegGetValueW, RegQueryValueExW, RegEnumValueW, RegOpenKeyExW
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar, CompareStringW, CompareStringOrdinal
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcmpW, lstrcmpiW
api-ms-win-core-synch-l1-2-0.dll
WaitForSingleObject, CreateEventW, SetEvent, OpenEventW, WaitForSingleObjectEx, WaitForMultipleObjectsEx, EnterCriticalSection, ResetEvent, Sleep, InitializeCriticalSection, SetWaitableTimer, LeaveCriticalSection, DeleteCriticalSection
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount, GetLocalTime, GetSystemTimeAsFileTime
api-ms-win-core-threadpool-legacy-l1-1-0.dll
QueueUserWorkItem
api-ms-win-core-timezone-l1-1-0.dll
SystemTimeToFileTime
api-ms-win-devices-config-l1-1-0.dll
CM_Unregister_Notification, CM_Register_Notification, CM_Get_Device_IDW, CM_Get_Parent
api-ms-win-eventing-classicprovider-l1-1-0.dll
TraceMessage
api-ms-win-security-base-l1-2-0.dll
ImpersonateLoggedOnUser, RevertToSelf
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW, EnumDependentServicesW
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenServiceW, OpenSCManagerW
api-ms-win-service-private-l1-1-0.dll
I_ScUnregisterDeviceNotification, I_ScRegisterDeviceNotification
api-ms-win-service-winsvc-l1-1-0.dll
QueryServiceStatus, ControlService
api-ms-win-service-winsvc-l1-2-0.dll
ControlService, QueryServiceStatus
hid.dll
HidD_GetHidGuid, HidD_GetInputReport, HidP_GetSpecificButtonCaps, HidD_FreePreparsedData, HidP_GetCaps, HidP_GetUsages, HidP_MaxUsageListLength, HidD_GetPreparsedData
kernel32.dll
CompareStringW, QueueUserAPC, VirtualAllocEx, WriteProcessMemory, VirtualFreeEx, OpenProcess, ProcessIdToSessionId, OpenEventW, VirtualAlloc, ReadFile, VirtualFree, GetSystemDirectoryW, HeapReAlloc, LocalAlloc, LocalFree, GetProcessHeap, DisableThreadLibraryCalls, DelayLoadFailureHook, GetProcAddress, GetLastError, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, InitializeCriticalSectionAndSpinCount, EnterCriticalSection, LeaveCriticalSection, InterlockedIncrement, InterlockedDecrement, DeleteCriticalSection, GetVolumePathNamesForVolumeNameW, CompareStringOrdinal, WaitForSingleObject, CloseHandle, Sleep, HeapCreate, HeapDestroy, SystemTimeToFileTime, GetLocalTime, GetTickCount, lstrlenW, GetCurrentThreadId, HeapAlloc, HeapFree, QueueUserWorkItem, DuplicateHandle, GetCurrentProcess, GetCurrentThread, GetCurrentProcessId, InterlockedExchange, QueryPerformanceCounter, GetSystemTimeAsFileTime, LoadLibraryW, UnhandledExceptionFilter, SetUnhandledExceptionFilter, ResetEvent, lstrcmpW, ExpandEnvironmentStringsW, GetVolumePathNameW, GetVolumeNameForVolumeMountPointW, lstrcmpiW, FindClose, FindFirstFileW, DeviceIoControl, SetEvent, CreateFileW, GetPrivateProfileStringW, WritePrivateProfileStringW, CreateEventW, TerminateProcess, MultiByteToWideChar, GetVolumeInformationW, GetFileAttributesW, RegisterWaitForSingleObject, UnregisterWait, WaitForMultipleObjects, GetVersionExA, GetModuleHandleW, GetFullPathNameW, GetModuleFileNameW, GetMailslotInfo, GetOverlappedResult, CancelIo, SetLastError, CreateMailslotW, LoadLibraryA, UnmapViewOfFile, GetFileSize, MapViewOfFile, CreateFileMappingW, SetFilePointer, ReadProcessMemory, CreateWaitableTimerW, GetModuleHandleExW
kernelbase.dll
ResolveDelayLoadedAPI
msvcrt.dll
DllMain
ntdll.dll
NtOpenProcessToken, EtwEventUnregister, NtQueryVolumeInformationFile, EtwEventEnabled, EtwEventWrite, RtlAllocateAndInitializeSid, RtlCompareMemory, NtFilterToken, NtClose, RtlFreeSid, RtlNtStatusToDosError, EtwEventRegister, NtOpenThread, NtOpenThreadToken, RtlUnhandledExceptionFilter, NtReplyPort, NtReplyWaitReceivePort, NtAcceptConnectPort, NtCompleteConnectPort, NtCreatePort, NtDuplicateToken, NtSetInformationThread, RtlInitializeCriticalSection, NtConnectPort, NtOpenProcess, NtOpenEvent, RtlInitUnicodeString, NtCreateEvent, NtQueryInformationProcess, NtQuerySystemInformation, RtlImageNtHeader, NtRequestWaitReplyPort, RtlDeleteCriticalSection, EtwTraceMessage, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle
rpcrt4.dll
I_RpcBindingInqLocalClientPID
slc.dll
SLGetWindowsInformationDWORD
user32.dll
RegisterDeviceNotificationW, UnregisterDeviceNotification, GetSystemMetrics, CloseDesktop, SetThreadDesktop, GetThreadDesktop, OpenInputDesktop, UnregisterUserApiHook
Export table
CreateHardwareEventMoniker
DllInstall
DllRegisterServer
DllUnregisterServer
HardwareDetectionServiceMain
ThemeServiceMain