Import table
advapi32.dll
StartServiceCtrlDispatcherW, GetSecurityDescriptorOwner, RegCloseKey, AllocateAndInitializeSid, OpenSCManagerW, CloseServiceHandle, StartServiceW, GetSecurityDescriptorGroup, GetSecurityDescriptorSacl, GetSecurityDescriptorControl, MakeAbsoluteSD, GetAclInformation, GetSecurityDescriptorDacl, CryptImportKey, CryptDecrypt, CryptExportKey, CryptEncrypt, CryptGetUserKey, CryptGenKey, CryptDestroyKey, CryptSetProvParam, CryptGetProvParam, CryptAcquireContextW, CryptReleaseContext, OpenServiceW, ControlService, DeleteService, CreateServiceW, RevertToSelf, ImpersonateLoggedOnUser, OpenProcessToken, DuplicateTokenEx, LogonUserW, LookupAccountSidW, EnumServicesStatusW, QueryServiceStatus, SetServiceStatus, RegisterServiceCtrlHandlerExW, UnlockServiceDatabase, ChangeServiceConfigW, QueryServiceLockStatusW, LockServiceDatabase, RegQueryValueExA, RegOpenKeyExA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegOpenCurrentUser, LookupPrivilegeValueW, SetEntriesInAclW, CreateWellKnownSid, GetTokenInformation, AdjustTokenPrivileges, QueryServiceConfigW, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, CopySid, GetLengthSid, IsValidSid, SetSecurityInfo, AddAce, InitializeAcl
bdfltlib.dll
FlStartDriver, FlStartScanner2, FlQueryDriver, FlStopScanner, FlGetTraceFile, FlSetTraceFile, FlGetLogFile, FlSetLogFile, FlKillConnections, FlInvalidateCacheEntryOfFile, FlGetOpt, FlRegisterBypassPid, FlSetOpt, FlSetOptVarlen, FlGetDriverVersion, FlUnregisterBypassPid
crypt32.dll
CryptUnprotectData, CryptProtectData
iphlpapi.dll
NotifyAddrChange
kernel32.dll
InitializeCriticalSection, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, FreeLibrary, SetEvent, ResetEvent, CloseHandle, InitializeCriticalSectionAndSpinCount, ReleaseSemaphore, GetCurrentThreadId, lstrlenA, WaitForSingleObject, InterlockedExchangeAdd, MoveFileExW, GetCurrentProcessId, ReleaseMutex, GetTickCount, LocalFree, GetVersion, OpenProcess, GetCurrentProcess, SetProcessWorkingSetSize, CreateThread, GetExitCodeProcess, TerminateProcess, TryEnterCriticalSection, LocalAlloc, DeviceIoControl, ExitProcess, GetCommandLineW, WaitForMultipleObjects, FindClose, LeaveCriticalSection, GetSystemTime, FileTimeToSystemTime, GetFileTime, SetFilePointer, WriteFile, GlobalUnlock, GlobalLock, UnmapViewOfFile, TerminateThread, MapViewOfFile, GetSystemInfo, DuplicateHandle, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, InterlockedCompareExchange, PostQueuedCompletionStatus, GetQueuedCompletionStatus, CreateIoCompletionPort, ResumeThread, GetFileSize, ReadFile, LoadLibraryA, CompareStringA, GetModuleHandleA, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, EnterCriticalSection, RaiseException, GetLocalTime, InterlockedExchange, Sleep, LoadResource, LockResource, SizeofResource, GetLastError, UnhandledExceptionFilter, GetProcessHeap, HeapSize, SetLastError, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, SetThreadPriority, GetLogicalDrives
midascomm.dll
MdSetMidasDirectory, MdLoadInitAndActivateMdexSignatures, MdUninitialize, MdSetOptVarlen, MdGetOpt, MdSetOpt, MdSetTraceFile, MdSetLogFile, MdInitialize, MdLoadInitAndActivateNeurons
msvcp80.dll
DllMain
msvcr80.dll
DllMain
netapi32.dll
NetUserAdd, NetApiBufferFree, NetUserGetInfo, NetUserEnum, NetServerGetInfo, NetUserChangePassword, NetUserSetInfo, NetUserDel
ole32.dll
CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitializeEx, CoMarshalInterface, CoGetClassObject, CoTaskMemFree, CoTaskMemAlloc, CoTaskMemRealloc, OleRun, StringFromGUID2, CoRevokeClassObject, CoRegisterClassObject, GetHGlobalFromStream, CreateStreamOnHGlobal, CoSetProxyBlanket, CoGetObject, CLSIDFromProgID, CoReleaseMarshalData
psapi.dll
EnumProcesses, GetModuleFileNameExW
rpcrt4.dll
UuidFromStringW, UuidCreateSequential, UuidToStringW, RpcStringFreeW
setupapi.dll
SetupDiEnumDeviceInterfaces, SetupDiGetDeviceInterfaceDetailW, SetupDiDestroyDeviceInfoList
shell32.dll
SHGetFileInfoW, SHGetFolderPathW, SHGetSpecialFolderLocation, SHGetSpecialFolderPathW
shlwapi.dll
PathAppendW, PathRemoveBackslashW, PathFindExtensionW, UrlUnescapeW, PathAddBackslashW, PathFileExistsW, PathRemoveFileSpecW, PathIsRelativeW
user32.dll
GetUserObjectInformationW, GetForegroundWindow, AllowSetForegroundWindow, ShowWindow, TranslateMessage, PostQuitMessage, GetThreadDesktop, KillTimer, LoadImageW, UnregisterClassA
userenv.dll
ExpandEnvironmentStringsForUserW
wininet.dll
InternetCloseHandle, InternetOpenUrlA, InternetOpenA, InternetReadFile
wintrust.dll
WinVerifyTrust, CryptCATAdminCalcHashFromFileHandle, CryptCATAdminReleaseContext, CryptCATAdminAcquireContext, CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext
ws2_32.dll
WSARecvFrom, WSAGetOverlappedResult, WSASendTo, WSACreateEvent, WSASocketW
wslib.dll
WSLibNew, WSLibDelete