Import table
kernel32.dll
lstrcpynW, lstrcatW, GetModuleHandleW, GetProcAddress, GetCurrentThread, GetLogicalDriveStringsW, QueryDosDeviceW, GetLongPathNameW, GetShortPathNameW, GetStringTypeW, MultiByteToWideChar, LCMapStringW, HeapSize, VirtualQuery, InterlockedCompareExchange, GetCurrentThreadId, VirtualProtect, ResumeThread, FlushInstructionCache, GetCurrentProcess, SetThreadContext, GetThreadContext, VirtualFree, GetLastError, SuspendThread, VirtualAlloc, SetLastError, HeapAlloc, HeapFree, DecodePointer, GetCommandLineA, RaiseException, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameW, HeapCreate, HeapDestroy, EncodePointer, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, IsProcessorFeaturePresent, Sleep, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, GetStartupInfoW, DeleteCriticalSection, GetModuleFileNameA, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, RtlUnwind, LeaveCriticalSection, EnterCriticalSection, LoadLibraryW, HeapReAlloc
ntdll.dll
NtQueryObject, NtClose, NtDuplicateObject, NtQueryInformationFile, LdrEnumerateLoadedModules, NtQueryInformationProcess, NtFreeVirtualMemory, NtAllocateVirtualMemory
Export table
BZFreeMem
BZInvoke