Import table
advapi32.dll
TraceMessage, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, RegCloseKey, RegDeleteValueW, RegOpenKeyExW, RegSetValueExW, RegQueryValueExW, EventRegister, EventUnregister, EventWrite, EventEnabled, RegOpenKeyW, LsaGetUserName, EventWriteEndScenario, EventWriteStartScenario, EventActivityIdControl, CheckTokenMembership, RevertToSelf, ImpersonateLoggedOnUser, EqualSid, GetTokenInformation, DeregisterEventSource, RegisterEventSourceW, RegEnumValueW, RegQueryInfoKeyW, RegQueryInfoKeyA, RegQueryValueExA, QueryTraceW, EnableTrace, ControlTraceW, StartTraceW, OpenSCManagerW, OpenServiceW, QueryServiceStatus, NotifyServiceStatusChangeW, CloseServiceHandle, NotifyBootConfigStatus, OpenProcessToken, CreateWellKnownSid, LookupAccountSidW, RegDeleteTreeW, CreateProcessAsUserW, DuplicateTokenEx, I_ScSendTSMessage, ReportEventW, SetNamedSecurityInfoW, GetSecurityDescriptorSacl, GetSecurityDescriptorDacl, GetSecurityDescriptorGroup, GetSecurityDescriptorOwner, GetSecurityDescriptorControl, ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-datetime-l1-1-1.dll
GetDateFormatW, GetTimeFormatW
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
GetLastError, SetLastError, SetErrorMode, SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, SetLastError, UnhandledExceptionFilter, SetErrorMode, SetUnhandledExceptionFilter
api-ms-win-core-file-l1-1-1.dll
FindFirstVolumeW, GetDriveTypeW, DeleteFileW, FindNextVolumeW, FindVolumeClose, CreateFileW, CreateDirectoryW, GetShortPathNameW, FileTimeToSystemTime, FindFirstFileW, ReadFile, FindClose, GetFileAttributesW
api-ms-win-core-file-l1-2-0.dll
GetDriveTypeW, DeleteFileW, FindNextVolumeW, FindVolumeClose, FindFirstVolumeW, CreateFileW, CreateDirectoryW, GetShortPathNameW, FindFirstFileW, ReadFile, FindClose, GetFileAttributesW
api-ms-win-core-file-l1-2-1.dll
DeleteFileW, FindNextVolumeW, FindVolumeClose, GetDriveTypeW, ReadFile, CreateFileW, CreateDirectoryW, FindClose, FindFirstVolumeW, FindFirstFileW, GetFileAttributesW, GetShortPathNameW
api-ms-win-core-file-l2-1-0.dll
MoveFileExW
api-ms-win-core-file-l2-1-1.dll
MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-1-0.dll
HeapSetInformation, HeapDestroy, HeapCreate, HeapFree, GetProcessHeap, HeapAlloc
api-ms-win-core-heap-l1-2-0.dll
HeapCreate, GetProcessHeap, HeapFree, HeapDestroy, HeapSetInformation, HeapAlloc
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc, LocalFree, LocalReAlloc, LocalSize
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange, InterlockedExchange
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-kernel32-legacy-l1-1-0.dll
WTSGetActiveConsoleSessionId, GetStartupInfoA
api-ms-win-core-kernel32-legacy-l1-1-1.dll
GetStartupInfoA, WTSGetActiveConsoleSessionId
api-ms-win-core-libraryloader-l1-1-1.dll
GetProcAddress, FindResourceExW, LoadLibraryExW, GetModuleHandleW, GetModuleHandleA, LoadResource, FreeLibrary, LockResource
api-ms-win-core-libraryloader-l1-2-0.dll
LoadLibraryExW, GetModuleHandleA, LoadResource, FindResourceExW, GetModuleHandleW, LockResource, FreeLibrary, GetProcAddress
api-ms-win-core-localregistry-l1-1-0.dll
RegDeleteValueW, RegQueryValueExA, RegQueryInfoKeyA, RegQueryInfoKeyW, RegEnumValueW, RegGetValueW, RegQueryValueExW, RegSetValueExW, RegOpenKeyExW, RegCloseKey
api-ms-win-core-processenvironment-l1-1-0.dll
SetEnvironmentVariableW, ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-1-1.dll
SetEnvironmentVariableW, ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW, SetEnvironmentVariableW
api-ms-win-core-processthreads-l1-1-1.dll
SetThreadPriority, OpenProcess, GetCurrentProcess, SetPriorityClass, OpenProcessToken, TerminateProcess, GetCurrentThreadId, CreateProcessAsUserW, CreateRemoteThread, CreateThread, ResumeThread, GetExitCodeProcess, CreateProcessW, GetCurrentThread, GetCurrentProcessId, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
UpdateProcThreadAttribute, DeleteProcThreadAttributeList, CreateThread, InitializeProcThreadAttributeList, GetCurrentProcess, SetThreadPriority, GetCurrentThread, GetExitCodeProcess, GetCurrentProcessId, ResumeThread, SetPriorityClass, CreateRemoteThread, OpenProcessToken, CreateProcessW, OpenProcess, CreateProcessAsUserW, TerminateProcess, GetCurrentThreadId
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-obsolete-l1-1-0.dll
K32GetModuleFileNameExW
api-ms-win-core-registry-l1-1-0.dll
RegEnumValueW, RegDeleteTreeW, RegOpenKeyExW, RegGetValueW, RegCloseKey, RegQueryValueExW, RegQueryValueExA, RegSetValueExW, RegDeleteValueW, RegQueryInfoKeyA, RegQueryInfoKeyW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcmpiW, lstrlenW
api-ms-win-core-synch-l1-1-1.dll
WaitForSingleObjectEx, TryEnterCriticalSection, Sleep, SetEvent, CreateEventW, InitializeCriticalSection, LeaveCriticalSection, ResetEvent, DeleteCriticalSection, EnterCriticalSection, SleepEx, WaitForMultipleObjectsEx, WaitForSingleObject
api-ms-win-core-synch-l1-2-0.dll
ResetEvent, CreateEventW, SetEvent, WaitForSingleObjectEx, InitializeCriticalSection, LeaveCriticalSection, SleepEx, DeleteCriticalSection, TryEnterCriticalSection, WaitForMultipleObjectsEx, EnterCriticalSection, Sleep, WaitForSingleObject
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTimeAsFileTime, GetLocalTime, GetWindowsDirectoryW, SystemTimeToFileTime, GetVersionExW, GetComputerNameExW, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetComputerNameExW, GetSystemTimeAsFileTime, GetLocalTime, GetWindowsDirectoryW, GetTickCount, GetVersionExW
api-ms-win-core-sysinfo-l1-2-1.dll
GetWindowsDirectoryW, GetComputerNameExW, GetSystemTimeAsFileTime, GetTickCount, GetLocalTime, GetVersionExW
api-ms-win-core-threadpool-l1-1-1.dll
CreateTimerQueueTimer, DeleteTimerQueueTimer, QueueUserWorkItem
api-ms-win-core-threadpool-legacy-l1-1-0.dll
QueueUserWorkItem, DeleteTimerQueueTimer, CreateTimerQueueTimer
api-ms-win-core-timezone-l1-1-0.dll
SystemTimeToFileTime, FileTimeToSystemTime
api-ms-win-core-version-l1-1-0.dll
GetFileVersionInfoSizeExW, GetFileVersionInfoExW, VerQueryValueW
api-ms-win-eventing-controller-l1-1-0.dll
StartTraceW, ControlTraceW, EnableTraceEx2
api-ms-win-legacy-kernel32-l1-1-0.dll
GetStartupInfoA
api-ms-win-obsolete-kernelbase-l1-1-0.dll
LocalFree, LocalAlloc, lstrlenW, lstrcmpiW
api-ms-win-security-base-l1-1-0.dll
ImpersonateLoggedOnUser, EqualSid, RevertToSelf, GetTokenInformation, GetSecurityDescriptorOwner, GetSecurityDescriptorControl, SetFileSecurityW, GetSecurityDescriptorSacl, CheckTokenMembership, GetSecurityDescriptorDacl, CreateWellKnownSid, SetTokenInformation, DuplicateTokenEx, GetSecurityDescriptorGroup
api-ms-win-security-base-l1-2-0.dll
ImpersonateLoggedOnUser, EqualSid, GetSecurityDescriptorOwner, GetSecurityDescriptorControl, SetFileSecurityW, CheckTokenMembership, CreateWellKnownSid, SetTokenInformation, GetSecurityDescriptorSacl, DuplicateTokenEx, GetSecurityDescriptorDacl, RevertToSelf, GetTokenInformation, GetSecurityDescriptorGroup
api-ms-win-security-lsalookup-l1-1-0.dll
LookupAccountSidLocalW
kernel32.dll
SetEvent, CreateTimerQueueTimer, SetErrorMode, GetTickCount, GetWindowsDirectoryW, FindFirstFileW, FindClose, HeapSetInformation, CreateProcessW, InterlockedExchange, CreateThread, SleepEx, GetCurrentProcessId, SetThreadExecutionState, Sleep, ResetEvent, WaitForSingleObject, QueueUserWorkItem, WaitForSingleObjectEx, HeapFree, HeapAlloc, HeapDestroy, HeapCreate, LoadLibraryW, GetProcAddress, GetFileAttributesW, SetTimerQueueTimer, OpenProcess, GetModuleHandleW, CreateRemoteThread, ResumeThread, DeleteTimerQueueTimer, RegDeleteTreeW, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentThreadId, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoA, LoadLibraryExA, InterlockedCompareExchange, DelayLoadFailureHook, MoveFileExW, LocalSize, LocalReAlloc, FindFirstVolumeW, GetDriveTypeW, DeleteFileW, FindNextVolumeW, FindVolumeClose, lstrcmpiW, GetShortPathNameW, CreateFileW, LocalAlloc, ReadFile, CreateDirectoryW, LocalFree, SetLastError, lstrlenW, GetVersionExW, CreateEventW, GetDateFormatW, GetTimeFormatW, FileTimeToSystemTime, SystemTimeToFileTime, GetLocalTime, LockResource, LoadResource, FindResourceExW, GetProcessHeap, FreeLibrary, GetComputerNameW, SetEnvironmentVariableW, GetLastError, GetCurrentProcess, SetPriorityClass, GetCurrentThread, SetThreadPriority, GetExitCodeProcess, CloseHandle, WaitForMultipleObjectsEx, ExpandEnvironmentStringsW, GetSystemDirectoryW, LoadLibraryA
msvcrt.dll
DllMain
ntdll.dll
RtlNtStatusToDosError, RtlInitUnicodeString, NtShutdownSystem, RtlDeregisterWaitEx, RtlFreeHeap, RtlAllocateHeap, EtwEventEnabled, EtwEventWrite, EtwEventUnregister, EtwEventRegister, NtOpenProcessToken, RtlRemovePrivileges, NtClose, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwTraceMessage, RtlRegisterWait, RtlDestroyEnvironment, NtSetValueKey, NtReplyPort, NtCreateKey, NtReplyWaitReceivePort, NtAcceptConnectPort, NtCreatePort, NtAllocateLocallyUniqueId, TpSimpleTryPost, RtlFreeSid, RtlSetSaclSecurityDescriptor, RtlAddMandatoryAce, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlGetDaclSecurityDescriptor, RtlCopySid, RtlLengthSid, RtlSetDaclSecurityDescriptor, RtlAddAce, RtlUnhandledExceptionFilter, NtQueryInformationProcess, NtQuerySystemInformation, RtlSetThreadIsCritical, RtlSetProcessIsCritical, RtlLeaveCriticalSection, RtlEnterCriticalSection, RtlCompareUnicodeString, NtPrivilegeObjectAuditAlarm, EtwEventWriteEndScenario, EtwEventWriteStartScenario, EtwEventActivityIdControl, NtPrivilegeCheck, NtOpenThreadToken, RtlAllocateAndInitializeSid, RtlInitializeCriticalSection, NtQueryInformationToken, RtlSetEnvironmentVariable, RtlQueryEnvironmentVariable_U, RtlInitUnicodeStringEx, RtlCreateEnvironment, NtCreateEvent, RtlAdjustPrivilege, NtSystemDebugControl, NtCompleteConnectPort, NtCreatePagingFile, RtlDosPathNameToNtPathName_U, DbgBreakPoint, RtlConnectToSm, RtlSendMsgToSm, NtDelayExecution, RtlDeregisterWait, NtPowerInformation, NtSetThreadExecutionState, NtSetInformationProcess, WinSqmAddToStream, WinSqmIsOptedIn, CsrClientCallServer, NtQuerySystemEnvironmentValueEx
rpcrt4.dll
RpcBindingFree, RpcStringBindingParseW, RpcBindingToStringBindingW, RpcBindingServerFromClient, RpcRevertToSelf, RpcImpersonateClient, RpcServerInqCallAttributesW, RpcServerListen, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcExceptionFilter, RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, RpcStringFreeW, RpcServerInqBindings, UuidFromStringW, RpcEpRegisterW, RpcServerUnregisterIf, RpcEpUnregister, RpcBindingVectorFree, NdrAsyncServerCall, RpcServerTestCancel, RpcAsyncAbortCall, I_RpcBindingIsClientLocal, NdrAsyncClientCall, RpcBindingCopy, RpcBindingCreateW, RpcBindingBind, RpcServerUseProtseqW, RpcAsyncInitializeHandle, RpcAsyncCancelCall, RpcAsyncCompleteCall, RpcBindingUnbind, NdrClientCall2, NdrServerCall2, I_RpcExceptionFilter, RpcBindingSetAuthInfoExW, RpcBindingFromStringBindingW, RpcStringBindingComposeW, RpcMgmtIsServerListening
user32.dll
SetWindowStationUser, SwitchDesktopWithFade, LoadLocalFonts, SetWindowsHookExW, RegisterLogonProcess, SetProcessWindowStation, CreateDesktopW, CloseDesktop, CloseWindowStation, SetUserObjectSecurity, SwitchDesktop, UpdatePerUserSystemParameters, RecordShutdownReason, GetAsyncKeyState, ExitWindowsEx, UnhookWindowsHookEx, SetThreadDesktop, CreateWindowStationW
userenv.dll
GetAllUsersProfileDirectoryW, GetUserProfileDirectoryW