Import table
advapi32.dll
IsValidSid, GetLengthSid, RegQueryInfoKeyW, RegQueryInfoKeyA, RegOpenKeyExA, RegQueryValueExA, RegSetValueExA, RegCreateKeyExA, WmiQuerySingleInstanceW, WmiQueryAllDataW, WmiQueryGuidInformation, WmiFreeBuffer, RegEnumValueW, WmiMofEnumerateResourcesW, WmiOpenBlock, WmiReceiveNotificationsW, WmiCloseBlock, RegDeleteKeyW, ChangeServiceConfig2W, CreateServiceW, RegCreateKeyExW, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, ChangeServiceConfigW, AllocateAndInitializeSid, FreeSid, CloseServiceHandle, RegOpenKeyW, LookupPrivilegeValueW, AdjustTokenPrivileges, ConvertStringSecurityDescriptorToSecurityDescriptorW, SetThreadToken, RevertToSelf, AddAce, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, MakeAbsoluteSD, LookupAccountNameW, GetTokenInformation, OpenProcessToken, GetSecurityDescriptorLength, InitializeSecurityDescriptor, GetSecurityDescriptorControl, MakeSelfRelativeSD, GetAclInformation, GetAce, InitializeAcl, RegDeleteValueW, GetNamedSecurityInfoW, AccessCheck, OpenThreadToken, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegisterServiceCtrlHandlerExW, SetServiceStatus, RegSetValueExW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, IsValidSecurityDescriptor, IsValidAcl, LookupAccountSidW, CopySid, TraceMessage, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, RegDeleteKeyExW
api-ms-win-core-com-l1-1-0.dll
CoGetCallContext, CoFreeUnusedLibrariesEx, CoInitializeEx, CoUninitialize, StringFromGUID2, CoRevokeClassObject, CoTaskMemFree, CoRegisterClassObject, CoDisconnectContext, CLSIDFromString, StringFromCLSID, CoCreateInstance
api-ms-win-core-console-l1-1-0.dll
SetConsoleCtrlHandler
api-ms-win-core-debug-l1-1-0.dll
OutputDebugStringA
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll
SetLastError, GetLastError, SetUnhandledExceptionFilter, RaiseException, SetErrorMode, UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter, RaiseException, SetLastError, GetLastError, SetErrorMode
api-ms-win-core-file-l1-1-0.dll
CreateFileW, FindClose, WriteFile, FindNextFileW, FindNextChangeNotification, SetFileAttributesW, GetFileAttributesW, FindFirstFileW, FindFirstChangeNotificationW, RemoveDirectoryW, GetFileType, CreateDirectoryW, DeleteFileW, GetFullPathNameW
api-ms-win-core-file-l1-1-1.dll
CreateDirectoryW, FindNextChangeNotification, GetFileTime, FileTimeToLocalFileTime, CreateFileW, RemoveDirectoryW, WriteFile, GetFileType, FindClose, FindFirstChangeNotificationW, GetFullPathNameW, FindNextFileW, FindFirstFileW, DeleteFileW, SetFileAttributesW, GetFileAttributesW
api-ms-win-core-file-l1-2-0.dll
FindNextChangeNotification, GetFileType, FileTimeToLocalFileTime, GetFileTime, CreateDirectoryW, FindFirstChangeNotificationW, FindNextFileW, CreateFileW, DeleteFileW, SetFileAttributesW, WriteFile, GetFileAttributesW, FindFirstFileW, RemoveDirectoryW, GetFullPathNameW, FindClose
api-ms-win-core-file-l1-2-1.dll
CreateDirectoryW, GetFileTime, FileTimeToLocalFileTime, RemoveDirectoryW, GetFileType, FindClose, FindFirstChangeNotificationW, FindNextFileW, DeleteFileW, SetFileAttributesW, GetFileAttributesW, FindFirstFileW, GetFullPathNameW, WriteFile, CreateFileW, FindNextChangeNotification
api-ms-win-core-file-l2-1-0.dll
MoveFileExW, CopyFileExW
api-ms-win-core-file-l2-1-1.dll
CopyFileExW, MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc, LocalFree
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedIncrement, InterlockedCompareExchange, InterlockedExchange, InterlockedDecrement
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedCompareExchange, InterlockedExchange, InterlockedIncrement, InterlockedDecrement
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedCompareExchange, InterlockedExchange, InterlockedDecrement
api-ms-win-core-libraryloader-l1-1-0.dll
FreeLibrary, DisableThreadLibraryCalls, GetProcAddress, LoadLibraryExW, GetModuleHandleExW, LoadStringW, LoadLibraryExA
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleExW, LockResource, LoadResource, FreeLibrary, GetProcAddress, LoadLibraryExW, SizeofResource, FindResourceExW, DisableThreadLibraryCalls, LoadStringW, FreeResource
api-ms-win-core-libraryloader-l1-2-0.dll
FreeResource, GetModuleHandleExW, FindResourceExW, LoadResource, FreeLibrary, SizeofResource, LockResource, GetProcAddress, LoadLibraryExW, LoadStringW, DisableThreadLibraryCalls
api-ms-win-core-localization-l1-1-0.dll
LCMapStringW
api-ms-win-core-localization-l1-1-1.dll
LCMapStringW
api-ms-win-core-localization-l1-2-0.dll
LCMapStringW
api-ms-win-core-localization-l1-2-1.dll
LCMapStringW
api-ms-win-core-localregistry-l1-1-0.dll
RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegSetValueExW, RegDeleteValueW, RegCreateKeyExW, RegDeleteKeyExW
api-ms-win-core-misc-l1-1-0.dll
Sleep, LocalFree, lstrlenW
api-ms-win-core-processenvironment-l1-1-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-1-1.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-0.dll
GetCurrentThreadId, SetProcessShutdownParameters, SetThreadPriority, GetThreadPriority, GetCurrentThread, OpenThreadToken, TerminateProcess, GetCurrentProcessId, GetCurrentProcess, CreateProcessW
api-ms-win-core-processthreads-l1-1-1.dll
IsProcessorFeaturePresent, GetCurrentThreadId, GetCurrentThread, TerminateProcess, GetCurrentProcessId, SetProcessShutdownParameters, OpenThreadToken, CreateProcessW, GetThreadPriority, SetThreadPriority, GetCurrentProcess
api-ms-win-core-processthreads-l1-1-2.dll
GetCurrentProcess, GetCurrentProcessId, GetThreadPriority, TerminateProcess, OpenThreadToken, GetCurrentThreadId, CreateProcessW, GetCurrentThread, SetProcessShutdownParameters, SetThreadPriority
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegDeleteValueW, RegEnumValueW, RegCreateKeyExW, RegQueryInfoKeyW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, RegDeleteKeyExW, RegSetValueExW
api-ms-win-core-rtlsupport-l1-1-0.dll
RtlCaptureStackBackTrace
api-ms-win-core-rtlsupport-l1-1-1.dll
RtlCaptureStackBackTrace
api-ms-win-core-rtlsupport-l1-2-0.dll
RtlCaptureStackBackTrace
api-ms-win-core-string-l1-1-0.dll
WideCharToMultiByte, CompareStringW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrlenW, lstrcmpW
api-ms-win-core-synch-l1-1-0.dll
CreateMutexW, CreateEventW, ReleaseMutex, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, WaitForSingleObject, SetEvent, LeaveCriticalSection
api-ms-win-core-synch-l1-1-1.dll
LeaveCriticalSection, ReleaseMutex, EnterCriticalSection, Sleep, CreateMutexW, InitializeCriticalSectionAndSpinCount, WaitForSingleObject, DeleteCriticalSection, CreateEventW, WaitForMultipleObjectsEx, SetEvent
api-ms-win-core-synch-l1-2-0.dll
Sleep, LeaveCriticalSection, WaitForSingleObject, ReleaseMutex, CreateEventW, SetEvent, CreateMutexW, WaitForMultipleObjectsEx, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EnterCriticalSection
api-ms-win-core-sysinfo-l1-1-0.dll
GetTickCount, GetSystemTimeAsFileTime, GetVersionExA, GetSystemDirectoryW
api-ms-win-core-sysinfo-l1-1-1.dll
GetWindowsDirectoryW, GetVersionExW, GetVersionExA, GetTickCount, GetSystemTimeAsFileTime, GetSystemDirectoryW
api-ms-win-core-sysinfo-l1-2-0.dll
GetVersionExW, GetVersionExA, GetWindowsDirectoryW, GetSystemDirectoryW, GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemDirectoryW, GetVersionExA, GetSystemTimeAsFileTime, GetTickCount, GetVersionExW, GetWindowsDirectoryW
api-ms-win-core-threadpool-l1-1-0.dll
DeleteTimerQueueTimer, UnregisterWaitEx, CreateTimerQueueTimer
api-ms-win-core-threadpool-l1-1-1.dll
RegisterWaitForSingleObjectEx, DeleteTimerQueueTimer, UnregisterWaitEx, CreateTimerQueueTimer
api-ms-win-core-threadpool-legacy-l1-1-0.dll
CreateTimerQueueTimer, UnregisterWaitEx, DeleteTimerQueueTimer
api-ms-win-core-threadpool-private-l1-1-0.dll
RegisterWaitForSingleObjectEx
api-ms-win-obsolete-kernelbase-l1-1-0.dll
LocalFree, lstrlenW, lstrcmpW, LocalAlloc
api-ms-win-security-base-l1-1-0.dll
FreeSid, AllocateAndInitializeSid, AccessCheck, GetFileSecurityW
api-ms-win-security-base-l1-2-0.dll
AllocateAndInitializeSid, GetFileSecurityW, AccessCheck, FreeSid
kernel32.dll
LoadLibraryExW, EnterCriticalSection, SetProcessShutdownParameters, CreateMutexW, GetModuleHandleExW, SetErrorMode, lstrlenW, SetEvent, GetTickCount, InterlockedIncrement, InterlockedDecrement, lstrcmpiW, FindClose, GetSystemTimeAsFileTime, GetFullPathNameW, FindNextFileW, MoveFileW, DeleteFileW, SetFileAttributesW, GetFileAttributesW, Sleep, CreateFileW, FindFirstFileW, FindFirstChangeNotificationW, GetSystemDirectoryW, LCMapStringW, InitializeCriticalSection, GetCurrentThread, LocalFree, ExpandEnvironmentStringsW, GetFileType, RemoveDirectoryW, CreateDirectoryW, CopyFileW, DeleteTimerQueueTimer, InterlockedCompareExchange, CreateTimerQueueTimer, UnregisterWaitEx, SetConsoleCtrlHandler, TerminateProcess, RegisterWaitForSingleObject, CreateProcessW, QueryPerformanceCounter, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetProcessHeap, HeapAlloc, HeapReAlloc, HeapFree, GetFileSizeEx, SetFilePointerEx, WriteFile, CreateMutexA, ReadFile, SetFilePointer, GetFileSize, GetVersionExA, MultiByteToWideChar, WideCharToMultiByte, FreeResource, FindResourceW, WaitForMultipleObjects, FindNextChangeNotification, GetCurrentProcessId, LoadLibraryW, GetProcAddress, FreeLibrary, CloseHandle, CreateEventW, GetCurrentThreadId, DisableThreadLibraryCalls, ReleaseMutex, WaitForSingleObject, DebugBreak, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, FindResourceExW, LoadResource, LockResource, SizeofResource, GetFileTime, FileTimeToLocalFileTime, IsBadReadPtr, GetWindowsDirectoryW, GetLastError, SetLastError, lstrcmpW, RaiseException, LocalAlloc, LoadLibraryA, OutputDebugStringA, SetThreadPriority, GetThreadPriority, InterlockedExchange, CompareStringW, DelayLoadFailureHook, LoadLibraryExA, WaitForMultipleObjectsEx, MoveFileExW, RtlCaptureStackBackTrace, CopyFileExW, RegisterWaitForSingleObjectEx, GetVersionExW, RegQueryInfoKeyW, RegEnumValueW
msvcrt.dll
DllMain
ntdll.dll
RtlCaptureStackBackTrace, EtwTraceMessage, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, EtwGetTraceLoggerHandle
ole32.dll
CoRegisterClassObject, CoRevokeClassObject, CoUninitialize, CoFreeUnusedLibrariesEx, CoInitializeEx, CoCreateInstance, CLSIDFromString, StringFromGUID2, StringFromCLSID, CoTaskMemFree, CoGetCallContext, CoDisconnectContext
user32.dll
LoadStringW
wmiclnt.dll
WmiOpenBlock, WmiReceiveNotificationsW, WmiQueryAllDataW, WmiCloseBlock, WmiQueryGuidInformation, WmiFreeBuffer, WmiQuerySingleInstanceW, WmiMofEnumerateResourcesW
Export table
DllRegisterServer
DllUnregisterServer
DredgeRA
GetSystemEventsForShutdown
IsImproperShutdownDetected
IsShutDown
MoveToAlone
MoveToShared
ServiceMain