Import table
advapi32.dll
GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AddAccessAllowedAce, InitializeAcl, RegCloseKey, RegSetValueExW, RegCreateKeyExW, RegQueryValueExW, RegOpenKeyExW, RegEnumKeyExW, LookupAccountSidW, ConvertSidToStringSidW, GetLengthSid, FreeSid, AllocateAndInitializeSid, RegQueryInfoKeyW, RegEnumValueW, RegDeleteValueW, LookupAccountNameW, GetSidSubAuthorityCount, EqualDomainSid, IsValidSid, CreateWellKnownSid, AccessCheck, AdjustTokenPrivileges, LookupPrivilegeValueW, PrivilegeCheck, CheckTokenMembership, DuplicateToken, EqualSid, ConvertStringSidToSidW, AddAccessAllowedAceEx, AddAccessDeniedAceEx, GetAclInformation, GetAce, AddAce, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, CopySid, RegisterEventSourceW, ReportEventW, DeregisterEventSource, OpenThreadToken, OpenProcessToken, GetTokenInformation, ConvertStringSecurityDescriptorToSecurityDescriptorW, TraceMessage
api-ms-win-core-com-l1-1-0.dll
CoGetObjectContext, CLSIDFromString, CoTaskMemFree, CoCreateGuid, CoFreeUnusedLibraries, StringFromCLSID, CoSetProxyBlanket, CoTaskMemRealloc, CoUninitialize, CoCreateInstance, CoInitializeSecurity, CoInitializeEx, CoDisconnectContext, CoImpersonateClient, CoRevokeClassObject, CoRegisterClassObject, CoRevertToSelf, CoTaskMemAlloc
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll
RaiseException, SetUnhandledExceptionFilter, SetLastError, UnhandledExceptionFilter, GetLastError, SetErrorMode
api-ms-win-core-file-l1-2-0.dll
GetDiskFreeSpaceW, GetFileAttributesW, DeleteFileW, WriteFile, SetFileAttributesW, CreateDirectoryW, FindFirstVolumeW, ReadFile, GetVolumePathNamesForVolumeNameW, GetVolumeNameForVolumeMountPointW, GetDriveTypeW, FindClose, FindVolumeClose, QueryDosDeviceW, GetVolumePathNameW, FindNextFileW, FindNextVolumeW, DefineDosDeviceW, DeleteVolumeMountPointW, GetVolumeInformationW, FlushFileBuffers, CreateFileW, FindFirstFileW
api-ms-win-core-file-l2-1-0.dll
MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapSetInformation, GetProcessHeap, HeapFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedCompareExchange, InterlockedDecrement, InterlockedExchange
api-ms-win-core-io-l1-1-1.dll
DeviceIoControl, GetOverlappedResult
api-ms-win-core-libraryloader-l1-1-1.dll
FreeLibrary, GetModuleHandleA, GetModuleFileNameW, FindResourceExW, LoadResource, GetModuleHandleW, GetProcAddress, SizeofResource, LoadStringW, LoadLibraryExW
api-ms-win-core-localization-l1-2-0.dll
FormatMessageW
api-ms-win-core-memory-l1-1-1.dll
VirtualQuery, VirtualAlloc, VirtualProtect
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW, GetCommandLineW, GetEnvironmentVariableW
api-ms-win-core-processthreads-l1-1-1.dll
CreateThread, ResumeThread, GetCurrentThread, GetCurrentProcessId, GetCurrentThreadId, OpenThreadToken, TerminateProcess, GetCurrentProcess, GetStartupInfoW, OpenProcessToken, OpenThread, SetThreadPriority
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegDeleteTreeW, RegCloseKey, RegEnumKeyExW, RegQueryValueExW, RegEnumValueW, RegSetValueExW, RegCreateKeyExW, RegOpenKeyExW, RegDeleteValueW, RegQueryInfoKeyW
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar, CompareStringW
api-ms-win-core-string-l2-1-0.dll
CharNextW, CharPrevW
api-ms-win-core-synch-l1-2-0.dll
CreateEventW, InitializeCriticalSectionAndSpinCount, ResetEvent, WaitForSingleObject, WaitForMultipleObjectsEx, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, Sleep, InitializeCriticalSection, CancelWaitableTimer, CreateWaitableTimerExW, SetWaitableTimer, SetEvent
api-ms-win-core-sysinfo-l1-2-0.dll
GetComputerNameExW, GetSystemTimeAsFileTime, GetTickCount64, GetSystemDirectoryW, GetVersionExW, GetSystemInfo, GetSystemWindowsDirectoryW, GetTickCount
api-ms-win-core-timezone-l1-1-0.dll
GetTimeZoneInformation
api-ms-win-core-util-l1-1-0.dll
EncodePointer
api-ms-win-security-base-l1-2-0.dll
AddAccessAllowedAce, SetSecurityDescriptorDacl, CheckTokenMembership, PrivilegeCheck, DuplicateToken, AdjustTokenPrivileges, CreateWellKnownSid, EqualSid, SetSecurityDescriptorOwner, CopySid, SetSecurityDescriptorGroup, GetAclInformation, GetAce, AddAce, AddAccessDeniedAceEx, AddAccessAllowedAceEx, IsValidSid, AccessCheck, GetSidSubAuthorityCount, EqualDomainSid, FreeSid, AllocateAndInitializeSid, GetTokenInformation, GetLengthSid, InitializeSecurityDescriptor, InitializeAcl
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, SetServiceStatus
api-ms-win-service-private-l1-1-0.dll
I_ScUnregisterDeviceNotification, I_ScRegisterDeviceNotification
authz.dll
AuthzReportSecurityEventFromParams, AuthzUnregisterSecurityEventSource, AuthzRegisterSecurityEventSource
clusapi.dll
OpenCluster, ClusterResourceControl, GetClusterResourceState, CloseClusterResource, CloseCluster, OpenClusterResource, GetNodeClusterState, ClusterSharedVolumeSetSnapshotState
kernel32.dll
InitializeCriticalSection, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, GetLastError, EncodePointer, GetComputerNameW, GetComputerNameExW, GetVolumeInformationW, GetVolumePathNamesForVolumeNameW, GetModuleHandleW, GetTimeZoneInformation, SetErrorMode, GetDiskFreeSpaceW, InitializeCriticalSectionAndSpinCount, InterlockedCompareExchange, Sleep, EnterCriticalSection, LeaveCriticalSection, DefineDosDeviceW, ReadFile, CreateDirectoryW, SetFileAttributesW, GetEnvironmentVariableW, GetSystemWindowsDirectoryW, LoadLibraryW, GetProcAddress, CreateThread, FindFirstVolumeW, FindNextVolumeW, FindFirstFileW, FindNextFileW, ExpandEnvironmentStringsW, FindClose, FindVolumeClose, SetLastError, GetVersionExW, LoadLibraryExW, FormatMessageW, FreeLibrary, GetCurrentThread, MultiByteToWideChar, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, WriteFile, DeleteFileW, MoveFileExW, GetFileAttributesW, GetProcessHeap, HeapAlloc, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoW, InterlockedExchange, WaitForSingleObject, CloseHandle, SetWaitableTimer, CancelWaitableTimer, GetCurrentThreadId, SetEvent, CreateEventW, CreateWaitableTimerW, OpenThread, CompareStringW, GetCommandLineW, HeapSetInformation, LocalAlloc, GetVolumeNameForVolumeMountPointW, GetVolumePathNameW, GetSystemDirectoryW, LocalFree, ResetEvent, DeviceIoControl, CreateFileW, GetDriveTypeW, HeapFree, GetSystemTimeAsFileTime, GetTickCount64, FlushFileBuffers, GetOverlappedResult, SetThreadPriority, WaitForMultipleObjects, ResumeThread, DeleteVolumeMountPointW, RaiseException, lstrlenW, QueryDosDeviceW, SetVolumeMountPointW, lstrcmpiW, lstrcpynW
msvcrt.dll
DllMain
netapi32.dll
NetApiBufferFree, NetShareEnum, NetLocalGroupGetMembers, NetShareGetInfo, NetShareDel, NetShareAdd
ntdll.dll
NtThawTransactions, NtFreezeTransactions, NtQueryVolumeInformationFile, RtlNtStatusToDosErrorNoTeb, NtOpenSymbolicLinkObject, NtQuerySymbolicLinkObject, RtlNtStatusToDosError, NtUnloadKey, NtLoadKey, NtAdjustPrivilegesToken, NtOpenProcessToken, NtOpenThreadToken, EtwTraceMessage, RtlFreeSid, RtlSetOwnerSecurityDescriptor, RtlLengthSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAddAccessAllowedAceEx, NtClose, NtCreateSymbolicLinkObject, RtlInitUnicodeString, RtlCreateAcl, RtlLengthSid, RtlAllocateAndInitializeSid, NtSetSecurityObject, NtCreateKey, NtDeleteValueKey, NtQueryValueKey, NtSetValueKey, NtFreezeRegistry, NtThawRegistry, NtQuerySystemInformation, RtlFreeHeap, RtlAllocateHeap, NtOpenFile, RtlGUIDFromString, RtlFreeUnicodeString, RtlStringFromGUID, NtWaitForSingleObject, NtDeviceIoControlFile, NtCreateEvent, NtAllocateUuids, LdrGetProcedureAddress, RtlInitAnsiString, LdrGetDllHandle, NtResetEvent, RtlGetVersion, NtOpenKey, NtEnumerateKey, NtQueryKey, NtQueryAttributesFile, NtDeleteKey, ZwClose, ZwOpenFile, ZwQuerySystemInformation, ZwCreateEvent, ZwWaitForSingleObject, ZwDeviceIoControlFile, ZwUnloadKey, ZwCreateKey, ZwOpenThreadTokenEx, ZwQueryAttributesFile, ZwDeleteValueKey, ZwSetValueKey, ZwAdjustPrivilegesToken, ZwOpenProcessTokenEx, ZwQueryValueKey, ZwSetSecurityObject, ZwLoadKey, ZwDeleteKey, ZwEnumerateKey, ZwQueryKey, ZwOpenKey, ZwQuerySymbolicLinkObject, ZwOpenSymbolicLinkObject, ZwResetEvent, ZwAllocateUuids, RtlAdjustPrivilege, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, DbgBreakPoint
ole32.dll
CoRevertToSelf, CoImpersonateClient, CoDisconnectContext, CoCreateInstance, CoInitializeSecurity, CoInitializeEx, CoUninitialize, CoTaskMemFree, CoTaskMemAlloc, CoCreateGuid, CLSIDFromString, CoFreeUnusedLibraries, CoGetObjectContext, StringFromCLSID, CoSetProxyBlanket, CoTaskMemRealloc, CoInitialize
resutils.dll
ResUtilEnumResourcesEx, ResUtilGetResourceName
rpcrt4.dll
I_RpcBindingInqLocalClientPID, UuidToStringW, RpcStringFreeW
setupapi.dll
SetupDiGetDeviceInstallParamsW, SetupDiGetDeviceRegistryPropertyW, SetupDiEnumDeviceInfo, SetupDiSetClassInstallParamsW, SetupDiCallClassInstaller, SetupDiGetClassDevsW, SetupDiEnumDeviceInterfaces, SetupDiGetDeviceInterfaceDetailW, SetupDiDestroyDeviceInfoList, CM_Get_Parent, CM_Locate_DevNodeW, CM_Get_Device_IDW, CM_Get_Device_ID_Size_Ex, SetupDiOpenDeviceInfoW, CM_Reenumerate_DevNode_Ex, CM_Get_Device_ID_List_ExW, SetupDiCreateDeviceInfoList, CM_Get_Device_ID_List_Size_ExW
shlwapi.dll
SHDeleteKeyW
user32.dll
RegisterDeviceNotificationW, LoadStringW, UnregisterDeviceNotification
virtdisk.dll
GetStorageDependencyInformation
vssapi.dll
VssFreeSnapshotPropertiesInternal, CreateWriter, CreateWriterEx