Import table
advapi32.dll
ReportEventW, SetThreadToken, DuplicateToken, DuplicateTokenEx, CreateProcessAsUserW, GetLengthSid, AddAccessAllowedAce, SetTokenInformation, EnumServicesStatusW, QueryServiceConfigW, QueryServiceConfig2W, QueryServiceStatusEx, CloseServiceHandle, StartServiceW, OpenThreadToken, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptReleaseContext, CheckTokenMembership, FreeSid, ConvertStringSidToSidW, LookupAccountSidW, LookupPrivilegeValueW, AdjustTokenPrivileges, RevertToSelf, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetEntriesInAclW, SetSecurityDescriptorDacl, OpenProcessToken, GetTokenInformation, AllocateAndInitializeSid, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerExW, SetServiceStatus, OpenSCManagerW, OpenServiceW, OpenEventLogW, ControlService
crypt32.dll
CryptUnprotectData, CryptProtectData
gdi32.dll
SetBkColor, CreateFontW, TextOutW, CreateSolidBrush, GetDeviceCaps, SetTextColor, SelectObject
kernel32.dll
GlobalFree, GlobalUnlock, GlobalLock, GlobalAlloc, GetModuleFileNameW, ReadProcessMemory, WriteProcessMemory, DeleteCriticalSection, DuplicateHandle, TryEnterCriticalSection, CreateMutexW, OpenEventW, OpenMutexW, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetStartupInfoA, CreateProcessW, MulDiv, HeapReAlloc, GetFileAttributesW, SetFileAttributesW, CopyFileW, UnmapViewOfFile, SetEndOfFile, CancelIo, VirtualAlloc, ExitProcess, RaiseException, VirtualFree, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, OutputDebugStringW, EnterCriticalSection, GetLastError, QueueUserWorkItem, Sleep, ProcessIdToSessionId, GetCommandLineW, CloseHandle, HeapAlloc, GetProcessHeap, GetCurrentProcess, HeapFree, SetLastError, MapViewOfFile, CreateFileMappingW, OpenFileMappingW, HeapDestroy, HeapCreate, WaitForMultipleObjects, TerminateThread, WaitForSingleObject, SetEvent, InterlockedExchange, GetProcessTimes, OpenProcess, OpenThread, GetProcAddress, GetModuleHandleW, CreateEventW, SetThreadPriority, GetCurrentThread, InterlockedIncrement, CreateThread, GetVersionExW, LocalFree, WriteFile, SetFilePointer, CreateFileW, GetLocalTime, LocalAlloc, TerminateProcess, InitializeCriticalSection, GetSystemTimeAsFileTime, GetTickCount, GetSystemWindowsDirectoryW, DeleteFileW, LoadLibraryW, GetWindowsDirectoryW
msvcrt.dll
DllMain
ntdll.dll
RtlCreateSecurityDescriptor, RtlSetDaclSecurityDescriptor, NtQueryFullAttributesFile, NtSetInformationFile, NtQueryDirectoryFile, NtQueryInformationFile, NtClose, NtSetInformationThread, NtDuplicateToken, NtFilterToken, NtQueryInformationToken, NtOpenProcessToken, NtOpenThreadToken, NtCompleteConnectPort, NtAcceptConnectPort, NtImpersonateClientOfPort, NtReplyWaitReceivePort, NtCreatePort, NtReadFile, NtWriteFile, NtCreateFile, NtLoadKey, NtUnloadKey, NtOpenKey, NtLoadDriver, RtlInitString, RtlInitUnicodeString
ole32.dll
CoInitializeEx, CoInitializeSecurity, CoUninitialize, CoMarshalInterface, CoCopyProxy, CoSetProxyBlanket, CoQueryProxyBlanket, CreateStreamOnHGlobal, CoUnmarshalInterface, CoGetClassObject, CoTaskMemFree
sbiedll.dll
SbieApi_Log, _SbieApi_PortName@0, _SbieApi_SetLsaAuthPkg@8, _SbieApi_CallZero@4, _SbieApi_GetVersion@4, SbieApi_LogEx, _SbieApi_GetUnmountHive@4, _SbieApi_EnumProcessEx@16, _SbieApi_SetUserName@8, _SbieDll_FormatMessage2@12, _SbieDll_GetServiceRegistryValue@12, _SbieApi_QueryProcess@20, _SbieApi_GetWork@12, _SbieApi_QueryProcessPath@28, _SbieApi_CheckInternetAccess@12, _SbieApi_QueryConf@20, _SbieDll_RunFromHome@16, _SbieApi_ReloadConf@4, _SbieDll_FormatMessage0@4, _SbieDll_ComCreateStub@16, _SbieDll_IsOpenClsid@12
secur32.dll
LsaDeregisterLogonProcess, LsaConnectUntrusted, LsaLookupAuthenticationPackage
setupapi.dll
SetupDiClassNameFromGuidExW, SetupDiBuildClassInfoList, CM_Get_Device_ID_ListW, CM_Get_Device_ID_List_SizeW, CM_Get_Device_Interface_ListA, CM_Get_Device_Interface_ListW, CM_Get_Device_Interface_List_SizeA, CM_Get_Device_Interface_List_SizeW, CM_Get_Device_Interface_Alias_ExW, SetupDiDestroyDeviceInfoList, SetupDiOpenDeviceInfoW, SetupDiCreateDeviceInfoList, SetupDiOpenDeviceInterfaceW, CM_Get_DevNode_Status, CM_Locate_DevNodeW
user32.dll
ShowWindow, DispatchMessageW, RegisterClassW, DefWindowProcW, BeginPaint, CreateWindowExW, GetMessageW, EndPaint, wsprintfW