Import table
advapi32.dll
RegCreateKeyExW, RegQueryInfoKeyW, RegDeleteValueW, RegOpenKeyExW, RegEnumKeyExW, RegCloseKey, RegSetValueExW, TraceMessage, DuplicateTokenEx, RegQueryValueExW, GetUserNameW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, SetServiceStatus, GetSecurityDescriptorSacl, GetSecurityDescriptorDacl, GetSecurityDescriptorGroup, GetSecurityDescriptorOwner, GetSecurityDescriptorControl, GetLengthSid, IsValidSid, CopySid, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, MakeAbsoluteSD, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, AddAce, InitializeAcl, GetAclInformation, IsValidSecurityDescriptor, RegEnumValueW, LookupAccountNameW, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, OpenSCManagerW, OpenServiceW, CloseServiceHandle, CreateServiceW, ControlService, DeleteService, InitiateShutdownW, RegGetValueW, RegUnLoadKeyW, RegLoadKeyW, CheckTokenMembership, SetSecurityInfo, LsaNtStatusToWinError, GetSecurityDescriptorLength, GetSecurityInfo, EventRegister, EventEnabled, EventUnregister, EventWrite, SetThreadToken, OpenThreadToken, StartTraceW, EnableTrace, ControlTraceW, LsaFreeMemory, GetWindowsAccountDomainSid, ConvertSidToStringSidW, AdjustTokenPrivileges, RevertToSelf, ConvertStringSecurityDescriptorToSecurityDescriptorW, ImpersonateLoggedOnUser, LsaClose, SetFileSecurityW, LogonUserExExW, LookupPrivilegeValueW, EqualSid, LsaOpenPolicy, LsaQueryInformationPolicy, OpenProcessToken, QueryServiceStatus, EnumDependentServicesW, TraceEvent, LogonUserW, SetNamedSecurityInfoW
bcrypt.dll
BCryptOpenAlgorithmProvider, BCryptHashData, BCryptFinishHash, BCryptCloseAlgorithmProvider, BCryptCreateHash, BCryptGetProperty, BCryptDestroyHash
clusapi.dll
GetNodeClusterState
kernel32.dll
CreateThread, GetTickCount, RemoveDirectoryW, HeapSetInformation, CreateWaitableTimerW, WaitForSingleObjectEx, GetCommandLineW, GetCurrentThreadId, CopyFileW, DeviceIoControl, GetFullPathNameW, GetDriveTypeW, GetSystemWindowsDirectoryW, lstrlenW, GetVolumePathNameW, FindVolumeClose, OutputDebugStringW, GlobalAlloc, GlobalLock, GlobalFree, GlobalUnlock, SetErrorMode, CancelIoEx, GetFileAttributesExW, QueryDosDeviceW, DeleteVolumeMountPointW, GetLogicalDrives, SetVolumeMountPointW, SetWaitableTimer, GetLocalTime, GetFileSize, GetLongPathNameW, SetFileValidData, SetFilePointerEx, SetEndOfFile, GetVolumeInformationW, CancelIo, GetOverlappedResult, GetCurrentThread, SleepEx, SetFilePointer, CompareStringOrdinal, CopyFileExW, LocalAlloc, SetLastError, FormatMessageW, GetSystemDirectoryW, GetTickCount64, ExpandEnvironmentStringsW, GetWindowsDirectoryW, GetSystemInfo, GetProductInfo, GetComputerNameExW, GetTempPathW, GetVersionExW, SetFileAttributesW, GetFileInformationByHandle, GetVolumeNameForVolumeMountPointW, FindNextFileW, SetFileInformationByHandle, GetFileInformationByHandleEx, CreateDirectoryW, FindFirstFileW, GetVolumePathNamesForVolumeNameW, GetDiskFreeSpaceExW, GetFileAttributesW, OutputDebugStringA, GetCurrentProcessId, QueryPerformanceCounter, GetModuleHandleA, TerminateProcess, GetCurrentProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStartupInfoW, InterlockedCompareExchange, FindNextVolumeW, FindFirstVolumeW, GetTimeZoneInformation, SetThreadExecutionState, FileTimeToLocalFileTime, Sleep, SetVolumeLabelW, FileTimeToSystemTime, CompareFileTime, FindClose, MoveFileW, ReadFile, MoveFileExW, FlushFileBuffers, WriteFile, DeleteFileW, GetSystemTimeAsFileTime, SystemTimeToFileTime, GetSystemTime, LocalFree, GetFileSizeEx, CreateFileW, ResetEvent, WaitForSingleObject, SetEvent, CloseHandle, CreateEventW, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, lstrcmpiW, EnterCriticalSection, GetProcAddress, GetLastError, RaiseException, MultiByteToWideChar, GetModuleFileNameW, LeaveCriticalSection, SizeofResource, InitializeCriticalSection, GetModuleHandleW, InterlockedDecrement, InterlockedIncrement, LoadLibraryExW, LoadResource, FreeLibrary, FindResourceExW, TlsGetValue, HeapDestroy, HeapAlloc, HeapReAlloc, HeapFree, HeapSize, GetProcessHeap, GetEnvironmentVariableW, InterlockedExchange, CreateSymbolicLinkW, CompareStringW, FindResourceW, LoadLibraryW, GetVersionExA
msvcrt.dll
DllMain
netapi32.dll
NetShareAdd, NetApiBufferFree, NetShareDel, NetShareGetInfo
ntdll.dll
ZwDeviceIoControlFile, ZwResetEvent, ZwQueryInformationFile, RtlStringFromGUID, RtlFreeUnicodeString, RtlGUIDFromString, NtQuerySystemInformation, ZwAllocateUuids, NtOpenKey, NtDeviceIoControlFile, NtOpenSymbolicLinkObject, NtQuerySymbolicLinkObject, NtWaitForSingleObject, NtClose, NtCreateEvent, NtQueryValueKey, NtSetValueKey, NtOpenFile, NtResetEvent, NtCreateKey, NtSetSecurityObject, NtDeleteKey, NtQueryInformationFile, NtQueryKey, NtQueryVolumeInformationFile, NtSetInformationKey, RtlSetAllBits, RtlSetBits, RtlInitializeBitMap, RtlSetBit, RtlNumberOfSetBits, RtlAreBitsSet, RtlClearAllBits, EtwTraceMessage, RtlNumberOfClearBits, RtlCompareMemory, RtlFindNextForwardRunClear, RtlClearBits, RtlAreBitsClear, NtCreateFile, RtlDosPathNameToNtPathName_U, WinSqmAddToStreamEx, RtlCreateSystemVolumeInformationFolder, RtlGetSetBootStatusData, RtlUnlockBootStatusData, ZwDeleteFile, ZwQueryVolumeInformationFile, ZwWaitForSingleObject, ZwOpenSymbolicLinkObject, LdrGetDllHandle, LdrGetProcedureAddress, RtlGetVersion, RtlInitAnsiString, ZwQuerySymbolicLinkObject, ZwCreateEvent, RtlSetOwnerSecurityDescriptor, ZwOpenKey, RtlCreateSecurityDescriptor, RtlLengthSid, ZwEnumerateKey, ZwDeleteKey, RtlAllocateAndInitializeSid, ZwLoadKey, RtlAddAccessAllowedAceEx, ZwSetSecurityObject, RtlLengthSecurityDescriptor, ZwQueryValueKey, ZwCreateFile, ZwOpenProcessTokenEx, ZwSaveKey, ZwAdjustPrivilegesToken, ZwSetValueKey, ZwDeleteValueKey, RtlSetDaclSecurityDescriptor, RtlFreeSid, ZwQueryAttributesFile, RtlCreateAcl, ZwOpenThreadTokenEx, ZwCreateKey, ZwUnloadKey, RtlInitUnicodeString, WinSqmAddToStream, RtlNtStatusToDosError, RtlGetLastNtStatus, RtlFreeHeap, ZwClose, ZwQuerySystemInformation, ZwOpenFile, RtlAllocateHeap, ZwQueryKey, NtDeleteFile, NtAllocateUuids, NtSaveKey, NtDeleteValueKey, NtOpenThreadToken, NtOpenProcessToken, NtAdjustPrivilegesToken, NtLoadKey, NtUnloadKey, NtQueryAttributesFile, NtEnumerateKey
ole32.dll
CoRegisterClassObject, CoRevokeClassObject, CoCreateGuid, CLSIDFromString, CreateStreamOnHGlobal, CoTaskMemRealloc, CoTaskMemFree, CoTaskMemAlloc, StringFromGUID2, CoCreateInstance, CoInitializeEx, CoUninitialize, CoInitializeSecurity, CoSuspendClassObjects, CoResumeClassObjects, CreateClassMoniker, CoDisconnectObject, GetRunningObjectTable, CoImpersonateClient, CoRevertToSelf
rpcrt4.dll
UuidToStringW, UuidCreate, UuidFromStringW, RpcStringFreeW
setupapi.dll
SetupDiGetDeviceRegistryPropertyW, SetupDiDestroyDeviceInfoList, SetupGetInfDriverStoreLocationW, SetupDiGetClassDevsW, SetupDiEnumDeviceInterfaces, SetupDiGetDeviceInterfaceDetailW, SetupEnumPublishedInfW
spp.dll
SppFreeBadWritersArray
user32.dll
CharUpperW, MessageBoxW, UnregisterClassA, CharUpperBuffW, CharNextW, LoadStringW, PostThreadMessageW, GetMessageW, TranslateMessage, DispatchMessageW
virtdisk.dll
CreateVirtualDisk, GetVirtualDiskOperationProgress, GetStorageDependencyInformation, AttachVirtualDisk, OpenVirtualDisk, GetVirtualDiskPhysicalPath, SetVirtualDiskInformation, CompactVirtualDisk, DetachVirtualDisk, GetVirtualDiskInformation
vssapi.dll
VssFreeSnapshotPropertiesInternal, CreateVssBackupComponentsInternal, CreateVssExamineWriterMetadataInternal
wer.dll
WerReportSetParameter, WerReportSubmit, WerReportCreate, WerReportAddFile, WerReportCloseHandle
xmllite.dll
CreateXmlReaderInputWithEncodingName, CreateXmlReader