Import table
advapi32.dll
TraceMessage, EventWrite, EventEnabled, InitiateShutdownW, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, QueryTraceW, EnableTrace, ControlTraceW, StartTraceW, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, RegDeleteValueW, EventRegister, EventUnregister, EventWriteEndScenario, EventWriteStartScenario, EventActivityIdControl, RegEnumValueW, RegQueryInfoKeyW, RegSetValueExW, RegOpenKeyW, GetTokenInformation, OpenProcessToken, ConvertStringSidToSidW, LsaFreeMemory, LsaGetUserName, RevertToSelf, ImpersonateLoggedOnUser, CloseEventLog, GetEventLogInformation, OpenEventLogW, RegisterEventSourceW, DeregisterEventSource, LsaNtStatusToWinError, RegCreateKeyExW, CheckTokenMembership, DuplicateTokenEx, ConvertSidToStringSidW, CreateProcessAsUserW, AllocateLocallyUniqueId, ReportEventW, LogonUserW, RegSetKeySecurity, RegDeleteKeyW, RegGetValueA, EqualSid, CredFree, NotifyServiceStatusChangeW, NotifyBootConfigStatus, CreateWellKnownSid, LookupAccountSidW, RegDeleteTreeW, OpenSCManagerW, RegEnumKeyExW, CloseServiceHandle, OpenServiceW, QueryServiceConfigW, QueryServiceStatus, MD5Init, MD5Update, MD5Final, CredReadByTokenHandle, CheckForHiberboot, LsaOpenPolicy, LsaAddPrivilegesToAccount, LsaCreateAccount, LsaOpenAccount, LsaClose, LookupAccountNameW, LsaSetSystemAccessAccount
api-ms-win-base-bootconfig-l1-1-0.dll
NotifyBootConfigStatus
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-appcompat-l1-1-1.dll
BaseInitAppcompatCacheSupport
api-ms-win-core-datetime-l1-1-1.dll
GetTimeFormatW, GetDateFormatW
api-ms-win-core-debug-l1-1-1.dll
DebugBreak, IsDebuggerPresent
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, SetLastError, SetErrorMode, SetUnhandledExceptionFilter, GetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, SetErrorMode, GetLastError, UnhandledExceptionFilter, SetLastError
api-ms-win-core-file-l1-1-1.dll
FileTimeToSystemTime, CompareFileTime, ReadFile, CreateFileW, GetShortPathNameW, GetFileAttributesW
api-ms-win-core-file-l1-2-0.dll
ReadFile, GetShortPathNameW, CompareFileTime, GetFileAttributesW, CreateFileW
api-ms-win-core-file-l1-2-1.dll
GetFileAttributesW, CreateFileW, CompareFileTime, GetShortPathNameW, ReadFile
api-ms-win-core-file-l2-1-0.dll
MoveFileExW
api-ms-win-core-file-l2-1-1.dll
MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-1-0.dll
HeapSize, HeapFree, GetProcessHeap, HeapAlloc, HeapSetInformation
api-ms-win-core-heap-l1-2-0.dll
GetProcessHeap, HeapSize, HeapFree, HeapSetInformation, HeapAlloc
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalReAlloc, LocalSize, LocalFree, LocalAlloc
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange, InterlockedDecrement, InterlockedIncrement, InterlockedExchange
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedExchange, InterlockedDecrement, InterlockedCompareExchange, InterlockedIncrement
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange
api-ms-win-core-job-l2-1-0.dll
QueryInformationJobObject, TerminateJobObject, AssignProcessToJobObject, CreateJobObjectW, SetInformationJobObject
api-ms-win-core-kernel32-legacy-l1-1-1.dll
GetComputerNameW, RegisterWaitForSingleObject, UnregisterWait, GetStartupInfoA
api-ms-win-core-libraryloader-l1-1-1.dll
LoadLibraryExW, GetModuleHandleA, FindResourceExW, GetProcAddress, FreeLibrary, LoadResource, LockResource, GetModuleHandleW, GetModuleFileNameW, LoadStringW
api-ms-win-core-localization-l1-1-1.dll
FormatMessageW, GetThreadUILanguage
api-ms-win-core-localization-l1-2-0.dll
FormatMessageW, GetThreadUILanguage
api-ms-win-core-localization-l1-2-1.dll
FormatMessageW, GetThreadUILanguage
api-ms-win-core-localregistry-l1-1-0.dll
RegCloseKey, RegOpenKeyExW, RegDeleteValueW, RegEnumValueW, RegQueryInfoKeyW, RegSetValueExW, RegCreateKeyExW, RegSetKeySecurity, RegDeleteKeyExW, RegQueryValueExW
api-ms-win-core-memory-l1-1-1.dll
VirtualAlloc, VirtualUnlock, VirtualLock, VirtualFree
api-ms-win-core-memory-l1-1-2.dll
VirtualAlloc, VirtualFree, VirtualLock, VirtualUnlock, GetProcessWorkingSetSizeEx, SetProcessWorkingSetSizeEx
api-ms-win-core-processenvironment-l1-1-0.dll
SearchPathW, ExpandEnvironmentStringsW, GetCommandLineW, SetEnvironmentVariableW
api-ms-win-core-processenvironment-l1-1-1.dll
SetEnvironmentVariableW, ExpandEnvironmentStringsW, SearchPathW, GetCommandLineW
api-ms-win-core-processenvironment-l1-2-0.dll
SearchPathW, GetCommandLineW, SetEnvironmentVariableW, ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll
OpenProcessToken, GetProcessTimes, ExitProcess, CreateThread, GetCurrentProcessId, SetThreadToken, GetCurrentThreadId, CreateRemoteThread, GetExitCodeProcess, CreateProcessW, CreateProcessAsUserW, ResumeThread, OpenThreadToken, SetPriorityClass, GetCurrentProcess, GetProcessId, TerminateThread, SetThreadPriority, GetCurrentThread, OpenProcess, TerminateProcess, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
TerminateThread, SetPriorityClass, GetCurrentProcess, SetThreadPriority, CreateProcessAsUserW, ResumeThread, OpenThreadToken, ExitProcess, TerminateProcess, GetProcessId, OpenProcess, CreateRemoteThread, GetCurrentThread, GetCurrentThreadId, GetProcessTimes, OpenProcessToken, GetCurrentProcessId, GetExitCodeProcess, CreateProcessW, CreateThread, SetThreadToken
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
QueryFullProcessImageNameW
api-ms-win-core-registry-l1-1-0.dll
RegSetKeySecurity, RegFlushKey, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegDeleteTreeW, RegQueryInfoKeyW, RegEnumValueW, RegGetValueA, RegEnumKeyExW, RegOpenCurrentUser, RegSetValueExW, RegCreateKeyExW, RegDeleteKeyExW, RegDeleteValueW, RegGetValueW
api-ms-win-core-shutdown-l1-1-1.dll
InitiateShutdownW
api-ms-win-core-string-l1-1-0.dll
CompareStringW, WideCharToMultiByte
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrlenW
api-ms-win-core-synch-l1-1-1.dll
InitializeCriticalSection, LeaveCriticalSection, TryEnterCriticalSection, DeleteCriticalSection, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, ResetEvent, EnterCriticalSection, ReleaseSRWLockShared, InitializeSRWLock, AcquireSRWLockShared, SleepEx, WaitForSingleObject, CreateEventW, SetEvent, OpenEventW, Sleep, WaitForSingleObjectEx
api-ms-win-core-synch-l1-2-0.dll
EnterCriticalSection, DeleteCriticalSection, ResetEvent, LeaveCriticalSection, SleepEx, ReleaseSRWLockExclusive, AcquireSRWLockExclusive, TryEnterCriticalSection, ReleaseSRWLockShared, OpenEventW, WaitForSingleObject, CreateEventW, InitializeSRWLock, SetEvent, WaitForSingleObjectEx, InitializeCriticalSection, AcquireSRWLockShared, Sleep
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTimeAsFileTime, GetSystemWindowsDirectoryW, GetSystemDirectoryW, SystemTimeToTzSpecificLocalTime, GetVersionExW, GetTickCount64, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount64, GetVersionExW, GetSystemTimeAsFileTime, GetTickCount, GetSystemWindowsDirectoryW, GetSystemDirectoryW
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount, GetSystemDirectoryW, GetTickCount64, GetSystemWindowsDirectoryW, GetVersionExW, GetSystemTimeAsFileTime
api-ms-win-core-threadpool-l1-1-1.dll
CreateTimerQueueTimer, QueueUserWorkItem, UnregisterWaitEx, DeleteTimerQueueTimer
api-ms-win-core-threadpool-l1-2-0.dll
CreateThreadpool, CreateThreadpoolWork, SetThreadpoolThreadMinimum, SetThreadpoolThreadMaximum, SubmitThreadpoolWork, TrySubmitThreadpoolCallback, CreateThreadpoolCleanupGroup, CloseThreadpool, CloseThreadpoolCleanupGroupMembers, CloseThreadpoolCleanupGroup, CloseThreadpoolWork
api-ms-win-core-threadpool-legacy-l1-1-0.dll
DeleteTimerQueueTimer, CreateTimerQueueTimer, QueueUserWorkItem, UnregisterWaitEx
api-ms-win-core-timezone-l1-1-0.dll
FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime
api-ms-win-core-wow64-l1-1-0.dll
IsWow64Process
api-ms-win-eventing-classicprovider-l1-1-0.dll
TraceMessage
api-ms-win-eventing-controller-l1-1-0.dll
StartTraceW, ControlTraceW, EnableTraceEx2
api-ms-win-eventlog-legacy-l1-1-0.dll
ReportEventW, RegisterEventSourceW, DeregisterEventSource, GetEventLogInformation
api-ms-win-obsolete-kernelbase-l1-1-0.dll
LocalAlloc, lstrlenW, LocalFree
api-ms-win-power-base-l1-1-0.dll
PowerDeterminePlatformRoleEx
api-ms-win-power-setting-l1-1-0.dll
PowerSettingUnregisterNotification, PowerSettingRegisterNotification
api-ms-win-security-base-l1-1-0.dll
GetLengthSid, RevertToSelf, ImpersonateLoggedOnUser, CheckTokenMembership, DuplicateTokenEx, AllocateLocallyUniqueId, EqualSid, CreateWellKnownSid, GetTokenInformation, DuplicateToken, SetTokenInformation, GetSidIdentifierAuthority
api-ms-win-security-base-l1-2-0.dll
RevertToSelf, DuplicateToken, DuplicateTokenEx, CreateWellKnownSid, ImpersonateLoggedOnUser, SetTokenInformation, CheckTokenMembership, GetLengthSid, GetTokenInformation, IsValidSid, GetSidIdentifierAuthority, AllocateLocallyUniqueId, EqualSid
api-ms-win-security-credentials-l1-1-0.dll
CredUnmarshalCredentialW, CredFree
api-ms-win-security-credentials-l2-1-0.dll
CredReadByTokenHandle
api-ms-win-security-lsalookup-l1-1-1.dll
LsaLookupFreeMemory, LookupAccountSidLocalW, LsaLookupManageSidNameMapping
api-ms-win-security-lsalookup-l2-1-0.dll
LookupAccountNameW, LookupAccountSidW
api-ms-win-security-lsalookup-l2-1-1.dll
LookupAccountNameW, LookupAccountSidW
api-ms-win-security-lsapolicy-l1-1-0.dll
LsaClose, LsaStorePrivateData, LsaOpenPolicy
api-ms-win-service-management-l1-1-0.dll
StartServiceW, OpenServiceW, OpenSCManagerW, CloseServiceHandle
api-ms-win-service-management-l2-1-0.dll
QueryServiceConfigW, NotifyServiceStatusChangeW
api-ms-win-service-winsvc-l1-2-0.dll
QueryServiceStatus
kernel32.dll
DllMain, RegDeleteTreeW, RegEnumKeyExW, CreateProcessInternalW, BaseInitAppcompatCacheSupport, SleepEx, GetFileAttributesW, SetTimerQueueTimer, CreateRemoteThread, GetThreadUILanguage, GetVersionExW, GetTickCount64, WideCharToMultiByte, DebugBreak, UnhandledExceptionFilter, GetCurrentThreadId, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, GetStartupInfoA, LoadLibraryExA, DelayLoadFailureHook, GetSystemDirectoryW, SetInformationJobObject, WaitForMultipleObjects, CreateThread, SetErrorMode, CreateFileW, ReadFile, GetModuleHandleW, GetProcessId, OpenEventW, CreateTimerQueueTimer, DeleteTimerQueueTimer, CreateProcessW, SearchPathW, AssignProcessToJobObject, TerminateProcess, GetTickCount, CompareFileTime, ResumeThread, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, GetTimeFormatW, VirtualLock, GetProcessWorkingSetSize, SetProcessWorkingSetSize, VirtualUnlock, VirtualFree, CreateJobObjectW, GetCommandLineW, TerminateJobObject, ResetEvent, InterlockedCompareExchange, GetComputerNameW, InterlockedIncrement, InterlockedDecrement, DuplicateHandle, QueryInformationJobObject, RegisterWaitForSingleObject, OpenProcess, UnregisterWait, QueryFullProcessImageNameW, GetExitCodeProcess, GetProcessHeap, SetEnvironmentVariableW, CompareStringW, GetShortPathNameW, lstrlenW, ExpandEnvironmentStringsW, VirtualAlloc, GetCurrentProcessId, HeapSetInformation, LoadLibraryW, GetProcAddress, FreeLibrary, WaitForSingleObjectEx, InterlockedExchange, UnregisterWaitEx, Sleep, GetSystemTimeAsFileTime, MoveFileExW, LocalSize, LocalReAlloc, CreateEventW, SetEvent, CloseHandle, WaitForSingleObject, GetModuleFileNameW, LocalAlloc, LocalFree, SetLastError, FormatMessageW, FindResourceExW, LoadResource, LockResource, GetCurrentProcess, SetPriorityClass, GetCurrentThread, SetThreadPriority, HeapSize, HeapFree, HeapAlloc, HeapDestroy, HeapCreate, GetLastError, RegGetValueA, GetDateFormatW, LoadLibraryA, MultiByteToWideChar, GetSystemInfo, lstrcmpW, IsWow64Process, ResolveDelayLoadedAPI, QueueUserWorkItem, GetComputerNameExW
msvcrt.dll
DllMain
ntdll.dll
RtlEnterCriticalSection, EtwTraceMessage, NtShutdownSystem, RtlNtStatusToDosError, NtClose, NtQueryInformationToken, NtOpenProcessToken, WinSqmStartSession, WinSqmEndSession, EtwEventWrite, EtwEventEnabled, RtlGetNtProductType, NtQuerySystemInformation, NtSystemDebugControl, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, RtlRemovePrivileges, EtwEventRegister, EtwEventUnregister, RtlDeleteCriticalSection, WinSqmSetDWORD, RtlpVerifyAndCommitUILanguageSettings, EtwEventWriteEndScenario, EtwEventWriteStartScenario, EtwEventActivityIdControl, NtOpenThreadToken, RtlCompareUnicodeString, RtlInitUnicodeStringEx, RtlSetEnvironmentVariable, RtlQueryEnvironmentVariable_U, RtlInitUnicodeString, RtlInitializeCriticalSection, RtlLengthSid, RtlInitString, NtAllocateLocallyUniqueId, WinSqmAddToStream, RtlDestroyEnvironment, TpSimpleTryPost, TpReleaseWork, TpWaitForWork, TpReleaseWait, TpWaitForWait, TpSetWait, TpPostWork, TpAllocWork, TpAllocWait, RtlExpandEnvironmentStrings_U, RtlCreateEnvironment, NtSetInformationToken, NtCreateToken, RtlAdjustPrivilege, TpWaitForTimer, RtlGetDaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlAddAce, NtAdjustPrivilegesToken, NtDuplicateToken, RtlUnhandledExceptionFilter, NtQueryInformationProcess, TpReleaseTimer, NtReplyPort, NtCompleteConnectPort, NtReplyWaitReceivePort, NtAcceptConnectPort, NtCreatePort, NtCreateEvent, RtlNtStatusToDosErrorNoTeb, RtlCopySid, RtlOpenCurrentUser, RtlFreeSid, NtSetSecurityObject, RtlSetSaclSecurityDescriptor, RtlAddMandatoryAce, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlAllocateAndInitializeSid, RtlTimeToSecondsSince1980, TpSetTimer, TpAllocTimer, NtOpenDirectoryObject, NtInitiatePowerAction, RtlFreeUnicodeString, RtlDuplicateUnicodeString, NtFilterToken, RtlEqualSid, RtlLeaveCriticalSection, DbgBreakPoint, NtSetInformationProcess, DbgPrint, RtlFreeHeap, RtlAllocateHeap, NtOpenFile, RtlGUIDFromString, RtlStringFromGUID, NtOpenKey, NtEnumerateKey, NtQueryKey, NtQueryAttributesFile, NtUnloadKey, NtLoadKey, RtlSetOwnerSecurityDescriptor, RtlLengthSecurityDescriptor, RtlAddAccessAllowedAceEx, NtCreateKey, NtDeleteValueKey, NtQueryValueKey, NtSetValueKey, NtDeleteKey, LdrGetProcedureAddress, RtlInitAnsiString, LdrGetDllHandle, NtResetEvent, NtWaitForSingleObject, NtDeviceIoControlFile, RtlGetVersion, NtQuerySymbolicLinkObject, NtOpenSymbolicLinkObject, NtAllocateUuids, RtlConnectToSm, RtlSendMsgToSm, WinSqmIsOptedIn, RtlCompareMemory, RtlInitializeResource, RtlAcquireResourceExclusive, RtlReleaseResource, RtlDeleteResource, RtlLockBootStatusData, NtPowerInformation, RtlGetSetBootStatusData, RtlUnlockBootStatusData, RtlRegisterWait, RtlDeregisterWait, RtlGetAce, RtlAppendUnicodeToString, RtlCaptureStackBackTrace, NtSetEvent, NtOpenEvent, NtUnmapViewOfSection, DbgPrintEx, DbgPrompt, NtRequestPort, NtConnectPort, NtRequestWaitReplyPort, NtGetCachedSigningLevel, WinSqmSetString, RtlCopyLuid
powrprof.dll
PowerDeterminePlatformRoleEx, PowerSettingUnregisterNotification, PowerSettingRegisterNotification
psapi.dll
EnumProcessModules, GetModuleBaseNameW
rpcrt4.dll
RpcAsyncInitializeHandle, RpcAsyncCancelCall, RpcMgmtIsServerListening, RpcStringFreeW, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcBindingSetAuthInfoExW, UuidFromStringW, NdrAsyncClientCall, RpcServerUnsubscribeForNotification, RpcServerSubscribeForNotification, I_RpcBindingIsClientLocal, RpcServerUnregisterIf, RpcBindingVectorFree, RpcEpUnregister, RpcServerListen, RpcEpRegisterW, RpcServerInqBindings, RpcServerRegisterIfEx, RpcServerUseProtseqW, NdrServerCall2, NdrAsyncServerCall, RpcRaiseException, RpcServerInqCallAttributesW, RpcServerTestCancel, I_RpcMapWin32Status, NdrClientCall2, RpcBindingCreateW, RpcBindingBind, RpcBindingUnbind, RpcBindingFree, I_RpcExceptionFilter, RpcAsyncAbortCall, RpcAsyncCompleteCall, RpcServerUseProtseqEpW, I_RpcBindingInqLocalClientPID, RpcImpersonateClient, RpcRevertToSelf
samcli.dll
NetUserGetInfo, NetUserGetInternetIdentityInfo
secur32.dll
LsaCallAuthenticationPackage, LsaFreeReturnBuffer, SeciAllocateAndSetIPAddress, SeciAllocateAndSetCallFlags, LsaLogonUser, SeciFreeCallContext, LsaRegisterLogonProcess, LsaLookupAuthenticationPackage, LsaGetLogonSessionData, ChangeAccountPasswordW, GetUserNameExW
user32.dll
CloseDesktop, FindWindowW, EnumWindows, RealGetWindowClassW, ShowWindow, DialogBoxParamW, GetDlgItemTextW, EndDialog, LoadImageW, GetDlgItem, SetThreadDesktop, LockWindowStation, UnlockWindowStation, SetWindowStationUser, UpdatePerUserSystemParameters, GetUserObjectInformationW, OpenInputDesktop, MessageBoxW, GetSystemMetrics, ExitWindowsEx, GetAsyncKeyState, CancelShutdown, CreateDesktopW, SystemParametersInfoW, GetKeyState, GetLastInputInfo, SetForegroundWindow, SetWindowPos, GetDesktopWindow, GetParent, GetWindowLongW, SwitchDesktopWithFade, LoadLocalFonts, RegisterLogonProcess, GetWindowRect, LoadStringW, SendMessageW, CreateWindowStationW, SetProcessWindowStation, CloseWindowStation, SetUserObjectSecurity, SwitchDesktop, EnumDisplayDevicesW, WaitForInputIdle, DwmLockScreenUpdates, LoadCursorW, CopyIcon, SetSystemCursor, DestroyCursor, RegisterSessionProcess
userenv.dll
GetUserProfileDirectoryW, GetAllUsersProfileDirectoryW
winsta.dll
WinStationGetUserCredentials, WinStationDisconnect, WinStationIsSessionRemoteable, _WinStationWaitForConnect, WinStationIsSessionPermitted, WinStationQueryInformationW, WinStationFreeMemory, WinStationNegotiateSession, WinStationFreeUserCredentials, WinStationReportUIResult, WinStationRedirectErrorMessage, WinStationPreCreateGlassReplacementSession, WinStationTerminateGlassReplacementSession
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory