Import table
kernel32.dll
LocalFree, IsBadReadPtr, CloseHandle, GetFileSize, CreateFileW, GetLastError, ReadFile, GetSystemInfo, VirtualQuery, GetFileSizeEx, GetDiskFreeSpaceW, GetLongPathNameW, GetShortPathNameW, SetEndOfFile, WriteFile, MultiByteToWideChar, GetTickCount, IsBadStringPtrA, Sleep, WideCharToMultiByte, MapViewOfFile, GetModuleHandleW, UnmapViewOfFile, CreateFileMappingW, LoadLibraryW, GetModuleFileNameW, GetProcAddress, FindNextFileW, FreeLibrary, FindFirstFileW, FindClose, RemoveDirectoryW, SetEnvironmentVariableA, GetDriveTypeA, GetCurrentDirectoryA, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, HeapSize, SetLastError, IsValidCodePage, GetOEMCP, GetACP, GetModuleFileNameA, HeapCreate, HeapDestroy, PeekNamedPipe, GetFileInformationByHandle, FileTimeToLocalFileTime, FileTimeToSystemTime, GetStartupInfoA, SetHandleCount, RtlUnwind, RaiseException, ExitProcess, GetModuleHandleA, GetDateFormatA, GetTimeFormatA, CreateThread, ExitThread, SetEnvironmentVariableW, SetStdHandle, GetFullPathNameW, GetConsoleMode, GetConsoleCP, HeapReAlloc, GetCommandLineA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, CreateDirectoryW, GetVersionExA, GetStringTypeA, LCMapStringA, GetLocaleInfoA, InterlockedDecrement, InterlockedIncrement, GetThreadTimes, EnterCriticalSection, TlsSetValue, GetTimeZoneInformation, GetCurrentProcessId, InitializeCriticalSection, GetSystemTimeAsFileTime, TlsAlloc, CreateSemaphoreA, LeaveCriticalSection, OutputDebugStringA, TlsGetValue, TryEnterCriticalSection, DeleteCriticalSection, GetFileType, VirtualProtect, IsDebuggerPresent, OpenThread, DeleteFileA, GetCurrentProcess, LoadLibraryA, ResumeThread, CreateFileA, CreateFileMappingA, OutputDebugStringW, SetFilePointer, GetFileAttributesExW, GetFileAttributesW, GetDiskFreeSpaceExW, FlushFileBuffers, SetFileAttributesW, IsBadWritePtr, VirtualFree, FormatMessageA, LoadLibraryExW, VirtualAlloc, GetProcessHeap, HeapAlloc, HeapFree, GetCurrentThread, QueryPerformanceFrequency, QueryPerformanceCounter, GetSystemTime, GetStdHandle, GetStringTypeW, LCMapStringW, GetCPInfo, lstrcpynA, CompareStringA, MulDiv, CompareStringW, ReleaseMutex, WaitForSingleObject, CreateMutexW, GetCurrentThreadId, SetEvent, ResetEvent, CreateEventW, DeleteFileW, InterlockedExchangeAdd, InterlockedCompareExchange, GetTempPathA, GetThreadContext, GetTempFileNameA, TlsFree, ReleaseSemaphore, SuspendThread, SetFilePointerEx
remediation.dll
RemRegistryEnumKey, RemRegistryEnumValue, RemRegistryValueDelete, RemProcessResume, RemRegistryGetUserKeyCount, RemProcessSuspend, RemFileSeek, RemFolderDelete, RemGetOSVersion, RemFolderFindNextFile, RemFolderCopy, RemFileGetExpandedPathCount, RemGetProcessorArchitecture, RemFileExists, RemServiceDisable, RemRegistryGetUserKey, RemFileDelete, RemFileAppend, RemFolderFindFirstFile, RemSystemDeleteScheduledJob, RemFileInsertChunk, RemSystemExec, RemServiceStop, RemScanDerivatives, RemFileTruncate, RemFileCopy, RemProcessKill, RemServiceEnable, RemFolderExists, RemFileRead, RemFileSetAttrib, RemServiceStart, RemFileGetAbbreviatedPath, RemFileWrite, RemFileGetADSInfo, RemServiceQueryStatus, RemRegistryKeyCreate, RemProcessSnapshot, RemFileRemoveChunk, RemFolderCreate, RemFileIsProtected, RemRegistryTreeDelete, RemServiceResume, RemSystemGetScheduledJobsEnum, RemFileXlateFromDrivePrefix, RemServiceDelete, RemFileGetExpandedPath, RemFileOpen, RemRegistryKeyDelete, RemFolderFindFileClose, RemRegistryValueGet, RemGetLogicalDrive, RemFileGetAbbreviatedPathCount, RemProcessIsRunningAsWow64, RemFileClose, RemRegistryKeyQueryInfo, RemFileGetAttrib, RemGetLogicalDriveCount, RemShutdown, RemInitialize, RemRegistryValueSet, RemGetEnvironmentVariable, RemServicePause
user32.dll
CheckDlgButton, CharLowerA, OemToCharA, VkKeyScanA, MapVirtualKeyA, CharUpperA, CharLowerBuffA, IsCharAlphaA
winmm.dll
timeGetTime