Import table
advapi32.dll
CryptAcquireContextW, RegCloseKey, RegOpenKeyExW, RegQueryValueExW, CopySid, CryptSetProvParam, CryptReleaseContext, GetLengthSid, LookupAccountNameW, SetSecurityDescriptorSacl, RegEnumKeyExW, RegQueryInfoKeyW, GetSecurityDescriptorSacl, CryptSignHashW, CryptVerifySignatureW, RegGetKeySecurity, RegSetKeySecurity, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetTokenInformation, QueryServiceStatus, SetThreadToken, ImpersonateSelf, GetSecurityDescriptorLength, MakeSelfRelativeSD, GetNamedSecurityInfoW, GetSecurityDescriptorOwner, RegOpenKeyW, AddAce, InitializeAcl, AddAccessAllowedAce, AddAccessDeniedAce, OpenThreadToken, CloseEventLog, GetEventLogInformation, OpenEventLogW, SetFileSecurityW, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, GetSecurityDescriptorDacl, RegSetValueExW, GetAclInformation, CryptCreateHash, CryptSetHashParam, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptEncrypt, CryptImportKey, EqualSid, LookupAccountSidW, CryptGetKeyParam, QueryServiceStatusEx, CloseServiceHandle, OpenSCManagerW, OpenServiceW, CryptGenKey, CryptGetUserKey, CryptExportKey, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, ConvertSidToStringSidW, ImpersonateLoggedOnUser, GetUserNameW, AllocateLocallyUniqueId, LsaNtStatusToWinError, AdjustTokenPrivileges, LookupPrivilegeValueW, CryptDecrypt, ImpersonateNamedPipeClient, CryptDestroyKey, RevertToSelf, InitializeSecurityDescriptor, GetSecurityDescriptorGroup, GetSecurityDescriptorControl, MakeAbsoluteSD, SetSecurityDescriptorControl, GetAce, OpenProcessToken, IsValidSid, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, SetSecurityDescriptorDacl
biolsp.dll
SetBiometricData
crypt32.dll
CryptUnprotectData, CryptProtectData, CertGetNameStringW, CertCreateCertificateContext, CertFreeCertificateContext
gdi32.dll
GetStockObject
kernel32.dll
CreateEventW, GetComputerNameW, ResetEvent, InterlockedIncrement, LocalAlloc, lstrlenW, FormatMessageW, InterlockedDecrement, LocalFree, GetLastError, CloseHandle, OpenProcess, OutputDebugStringA, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, SetEvent, VirtualFreeEx, WaitForSingleObject, CreateRemoteThread, WriteProcessMemory, VirtualAllocEx, GetWindowsDirectoryW, MultiByteToWideChar, lstrlenA, WideCharToMultiByte, GetModuleHandleW, GetProcAddress, DeleteCriticalSection, InitializeCriticalSection, GetFileType, RaiseException, GetVersionExW, GetLocaleInfoA, GetACP, InterlockedExchange, SetEnvironmentVariableA, CompareStringW, GetCommandLineA, IsBadReadPtr, RtlUnwind, HeapSize, HeapReAlloc, HeapFree, HeapDestroy, LeaveCriticalSection, EnterCriticalSection, GetVersionExA, ExitProcess, GetProcessHeap, HeapAlloc, GetCurrentProcessId, GetTickCount, FileTimeToSystemTime, SystemTimeToFileTime, GetSystemTimeAsFileTime, CreateDirectoryA, CreateFileW, ReadFile, GetCurrentThreadId, GetModuleFileNameA, LCMapStringW, GetCPInfo, CompareStringA, HeapCreate, VirtualFree, CreateFileA, GetLocaleInfoW, GetOEMCP, LoadLibraryA, GetTimeZoneInformation, IsBadCodePtr, IsValidCodePage, IsValidLocale, EnumSystemLocalesA, GetUserDefaultLCID, GetStringTypeW, GetStringTypeA, GetSystemInfo, VirtualProtect, SetEndOfFile, SetStdHandle, SetFilePointer, FlushFileBuffers, LCMapStringA, WriteFile, UnhandledExceptionFilter, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetStartupInfoA, GetStdHandle, SetHandleCount, QueryPerformanceCounter, GetCurrentProcess, TerminateProcess, SetUnhandledExceptionFilter, GetModuleHandleA, TlsGetValue, TlsSetValue, TlsFree, SetLastError, TlsAlloc, VirtualAlloc, IsBadWritePtr, VirtualQuery, CopyFileW, FindFirstFileW, DeleteFileW, FindNextFileW, OpenEventW, MoveFileExW, CompareFileTime, SetDllDirectoryW, GetModuleFileNameW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, FreeLibrary, Sleep, CreateNamedPipeW, ConnectNamedPipe, CreateThread, DisconnectNamedPipe, lstrcmpiW, FlushInstructionCache, WaitForMultipleObjects, OutputDebugStringW, CreateMutexW, ReleaseMutex, GetCurrentThread, GetComputerNameExW, OpenFileMappingW, MoveFileW, FormatMessageA, LoadLibraryW, CreateSemaphoreW, ReleaseSemaphore, InterlockedCompareExchange, IsProcessorFeaturePresent, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, InitializeCriticalSectionAndSpinCount, GetConsoleMode, GetConsoleCP, GetDateFormatA, IsDebuggerPresent, GetTimeFormatA, CreateDirectoryW, GetFileAttributesW, ExitThread
netapi32.dll
DsGetDcNameW, NetApiBufferFree, NetServerGetInfo, NetUserGetGroups, NetGetJoinInformation
ole32.dll
CoCreateInstance, OleRun, CoUninitialize, CLSIDFromProgID, CLSIDFromString, CoInitialize, CoTaskMemRealloc, CoTaskMemFree, CoWaitForMultipleHandles, CoReleaseMarshalData, CoMarshalInterface, CreateStreamOnHGlobal, CoUnmarshalInterface, CoCreateGuid, StringFromGUID2, CoTaskMemAlloc
psapi.dll
EnumProcesses, EnumProcessModules, GetModuleFileNameExW
secur32.dll
LsaConnectUntrusted, LsaCallAuthenticationPackage, LsaLogonUser, LsaFreeReturnBuffer, LsaLookupAuthenticationPackage, LsaRegisterLogonProcess, LsaDeregisterLogonProcess, GetComputerObjectNameW, GetUserNameExW
setupapi.dll
SetupDiEnumDeviceInterfaces, SetupDiDestroyDeviceInfoList, SetupDiGetClassDevsExW, SetupDiCreateDeviceInfoList, SetupDiGetDeviceInstanceIdW, SetupDiGetDeviceInterfaceDetailW
shell32.dll
SHGetFolderPathA, SHGetFolderPathW
shlwapi.dll
PathAppendA, PathIsDirectoryA, PathFileExistsA, PathAppendW
user32.dll
wsprintfW, UnregisterDeviceNotification, RegisterDeviceNotificationW, DispatchMessageW, GetMessageW, UnregisterClassA, PostMessageW, SendMessageW, UnregisterClassW, RegisterClassW, ReplyMessage, RegisterClassExW, LoadCursorW, GetClassInfoExW, CreateWindowExW, CallWindowProcW, GetWindowLongW, SetWindowLongW, DefWindowProcW, IsWindow, DestroyWindow, PeekMessageW, MsgWaitForMultipleObjects, CharNextW, TranslateMessage
userenv.dll
GetGPOListW, FreeGPOListW, UnloadUserProfile
wininet.dll
HttpSendRequestA, HttpAddRequestHeadersA, HttpOpenRequestA, InternetOpenA, InternetSetStatusCallbackW, InternetReadFile, InternetCrackUrlA, InternetConnectA, InternetCloseHandle, HttpQueryInfoW, InternetSetOptionW
winscard.dll
SCardGetStatusChangeW, SCardReleaseContext, SCardEstablishContext
ws2_32.dll
WSASocketW
Export table
LsaApCallPackage
LsaApCallPackagePassthrough
LsaApCallPackageUntrusted
LsaApInitializePackage
LsaApLogonTerminated
LsaApLogonUserEx2