Import table
advapi32.dll
RegEnumValueW, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, AddAccessAllowedAce, AddAccessDeniedAce, GetAce, AddAce, GetSidLengthRequired, InitializeSid, IsValidSid, CopySid, GetSecurityDescriptorControl, MakeAbsoluteSD, SetSecurityDescriptorDacl, RevertToSelf, GetTokenInformation, ConvertStringSecurityDescriptorToSecurityDescriptorW, ConvertSidToStringSidW, ImpersonateNamedPipeClient, RegOpenKeyW, RegNotifyChangeKeyValue, RegEnumKeyW, RegConnectRegistryW, TraceEvent, OpenSCManagerW, OpenServiceW, OpenProcessToken, GetSidSubAuthority, MakeSelfRelativeSD, GetSecurityDescriptorLength, OpenThreadToken, ImpersonateLoggedOnUser, GetLengthSid, RegisterEventSourceW, ReportEventW, DeregisterEventSource, InitializeSecurityDescriptor, InitializeAcl, GetUserNameW, AccessCheck, GetAclInformation, EqualSid, ControlService, CloseServiceHandle, RegSetValueExW, RegCreateKeyExW, RegDeleteValueW, RegQueryInfoKeyW, RegEnumKeyExW, RegQueryValueExW, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetTraceEnableLevel, GetTraceEnableFlags, RegOpenKeyExW, RegCloseKey, RegDeleteKeyW
kernel32.dll
DllMain
msvcrt.dll
DllMain
netapi32.dll
NetShareGetInfo, NetApiBufferFree
ntdll.dll
NtClose, NtQuerySystemInformation, VerSetConditionMask, RtlNtStatusToDosError, RtlUnwind, RtlUpcaseUnicodeChar
ole32.dll
CoGetClassObject, StgConvertPropertyToVariant, StgConvertVariantToProperty, PropVariantCopy, CreateStreamOnHGlobal, StgOpenStorage, CoCreateFreeThreadedMarshaler, CoFileTimeNow, PropVariantClear, CoTaskMemFree, CoTaskMemRealloc, CoTaskMemAlloc, CoCreateInstance, StringFromGUID2, CLSIDFromString, StringFromCLSID, CLSIDFromProgID
propsys.dll
PSGetPropertyDescriptionByName, PSGetPropertyDescription, PropVariantCompareEx
shlwapi.dll
PathFindFileNameW, PathRemoveFileSpecW, PathAppendW, PathIsDirectoryW, SHRegGetValueW, SHSetValueW, PathFindExtensionW, SHGetValueW
user32.dll
CharNextW, UnregisterClassA, CharLowerW, CharUpperW, CharLowerBuffW, LoadImageW, LoadMenuW, LoadStringW
wintrust.dll
WinVerifyTrust
Export table
_ForceMasterMerge@16
_NtQuerySystemInformation@16
AccessDebugTracer
AccessRetailTracer
ChangeToInitialDirectory
CIState
CreatePropMapperStorage
CreateSecurityStoreStorage
DllCanUnloadNow
DllGetClassObject
DllRegisterServer
DllUnregisterServer
ExceptInitialize
GetFTEInstanceInfo
PerfmonClose
PerfmonCollect
PerfmonIDXClose
PerfmonIDXCollect
PerfmonIDXOpen
PerfmonOpen
RetailTracerDisable
RetailTracerEnable
RetailTracerReleaseAll
SetInitialDirectory
UseLowFragmentationHeap