库 ADVAPI32.dll:
• 0x4b3000 - RegQueryValueExW
• 0x4b3004 - DuplicateTokenEx
• 0x4b3008 - RegOpenKeyExW
• 0x4b300c - CheckTokenMembership
• 0x4b3010 - FreeSid
• 0x4b3014 - OpenProcessToken
• 0x4b3018 - AllocateAndInitializeSid
• 0x4b301c - RegCloseKey
• 0x4b3020 - CreateProcessAsUserW
• 0x4b3024 - RegDeleteValueW
• 0x4b3028 - RegSetValueExW
• 0x4b302c - RegEnumKeyExW
• 0x4b3030 - RegCreateKeyExW
• 0x4b3034 - RegDeleteKeyW
• 0x4b3038 - GetTokenInformation
• 0x4b303c - ConvertSidToStringSidW
• 0x4b3040 - AdjustTokenPrivileges
• 0x4b3044 - LookupPrivilegeValueW
• 0x4b3048 - SystemFunction036
• 0x4b304c - InitializeSecurityDescriptor
• 0x4b3050 - SetSecurityDescriptorDacl
• 0x4b3054 - RegQueryValueExA
• 0x4b3058 - RegDisablePredefinedCache
• 0x4b305c - RevertToSelf
• 0x4b3060 - GetLengthSid
• 0x4b3064 - SetKernelObjectSecurity
• 0x4b3068 - ConvertStringSecurityDescriptorToSecurityDescriptorW
• 0x4b306c - GetKernelObjectSecurity
• 0x4b3070 - SetSecurityInfo
• 0x4b3074 - ConvertStringSidToSidW
• 0x4b3078 - SetTokenInformation
• 0x4b307c - GetAce
• 0x4b3080 - GetSecurityDescriptorSacl
• 0x4b3084 - SetThreadToken
• 0x4b3088 - DuplicateToken
• 0x4b308c - CreateRestrictedToken
• 0x4b3090 - EqualSid
• 0x4b3094 - CopySid
• 0x4b3098 - CreateWellKnownSid
• 0x4b309c - GetSecurityInfo
• 0x4b30a0 - SetEntriesInAclW
库 KERNEL32.dll:
• 0x4b30a8 - ReadFile
• 0x4b30ac - VirtualProtect
• 0x4b30b0 - GetModuleFileNameW
• 0x4b30b4 - CreateFileW
• 0x4b30b8 - GetLastError
• 0x4b30bc - CloseHandle
• 0x4b30c0 - GetFileSize
• 0x4b30c4 - GetModuleHandleW
• 0x4b30c8 - GetCurrentProcess
• 0x4b30cc - GetVersionExW
• 0x4b30d0 - GetCurrentThread
• 0x4b30d4 - LoadLibraryW
• 0x4b30d8 - VirtualQuery
• 0x4b30dc - TerminateProcess
• 0x4b30e0 - WaitForSingleObject
• 0x4b30e4 - GetSystemDirectoryW
• 0x4b30e8 - OpenProcess
• 0x4b30ec - CreateEventW
• 0x4b30f0 - Sleep
• 0x4b30f4 - GetUserDefaultLCID
• 0x4b30f8 - SetEvent
• 0x4b30fc - CreateThread
• 0x4b3100 - HeapSetInformation
• 0x4b3104 - ReplaceFileW
• 0x4b3108 - GetCurrentProcessId
• 0x4b310c - FreeLibrary
• 0x4b3110 - WritePrivateProfileStringW
• 0x4b3114 - SetLastError
• 0x4b3118 - GetPrivateProfileIntW
• 0x4b311c - ProcessIdToSessionId
• 0x4b3120 - DeleteFileW
• 0x4b3124 - SetCurrentDirectoryW
• 0x4b3128 - WTSGetActiveConsoleSessionId
• 0x4b312c - CreateProcessW
• 0x4b3130 - LoadLibraryExW
• 0x4b3134 - VirtualFree
• 0x4b3138 - VirtualAlloc
• 0x4b313c - SetFilePointer
• 0x4b3140 - GetSystemInfo
• 0x4b3144 - GetFileAttributesW
• 0x4b3148 - GetSystemTime
• 0x4b314c - MultiByteToWideChar
• 0x4b3150 - WideCharToMultiByte
• 0x4b3154 - GetModuleHandleExW
• 0x4b3158 - lstrcmpiW
• 0x4b315c - DuplicateHandle
• 0x4b3160 - GetExitCodeProcess
• 0x4b3164 - SetEnvironmentVariableW
• 0x4b3168 - SetInformationJobObject
• 0x4b316c - SetHandleInformation
• 0x4b3170 - GetStdHandle
• 0x4b3174 - AssignProcessToJobObject
• 0x4b3178 - GetProcessId
• 0x4b317c - ResumeThread
• 0x4b3180 - GetCommandLineW
• 0x4b3184 - LocalFree
• 0x4b3188 - GetModuleHandleA
• 0x4b318c - GetNativeSystemInfo
• 0x4b3190 - ExpandEnvironmentStringsW
• 0x4b3194 - GetUserDefaultLangID
• 0x4b3198 - WriteFile
• 0x4b319c - GetLocalTime
• 0x4b31a0 - GetCurrentDirectoryW
• 0x4b31a4 - CreateDirectoryW
• 0x4b31a8 - QueryDosDeviceW
• 0x4b31ac - GetLongPathNameW
• 0x4b31b0 - RemoveDirectoryW
• 0x4b31b4 - GetTempPathW
• 0x4b31b8 - UnmapViewOfFile
• 0x4b31bc - SetFileAttributesW
• 0x4b31c0 - GetFileAttributesExW
• 0x4b31c4 - CopyFileW
• 0x4b31c8 - CreateFileMappingW
• 0x4b31cc - MapViewOfFile
• 0x4b31d0 - GetProcAddress
• 0x4b31d4 - SetThreadPriority
• 0x4b31d8 - QueryPerformanceFrequency
• 0x4b31dc - GetThreadPriority
• 0x4b31e0 - SystemTimeToFileTime
• 0x4b31e4 - GetSystemTimeAsFileTime
• 0x4b31e8 - QueryPerformanceCounter
• 0x4b31ec - HeapCreate
• 0x4b31f0 - HeapDestroy
• 0x4b31f4 - FormatMessageA
• 0x4b31f8 - GetTickCount
• 0x4b31fc - InitializeCriticalSectionAndSpinCount
• 0x4b3200 - RaiseException
• 0x4b3204 - DecodePointer
• 0x4b3208 - DeleteCriticalSection
• 0x4b320c - ReadProcessMemory
• 0x4b3210 - EnterCriticalSection
• 0x4b3214 - LeaveCriticalSection
• 0x4b3218 - GetFileSizeEx
• 0x4b321c - SetFilePointerEx
• 0x4b3220 - FlushFileBuffers
• 0x4b3224 - FindFirstFileW
• 0x4b3228 - FindFirstFileExW
• 0x4b322c - FindNextFileW
• 0x4b3230 - FindClose
• 0x4b3234 - CreateToolhelp32Snapshot
• 0x4b3238 - Process32NextW
• 0x4b323c - Process32FirstW
• 0x4b3240 - GetCurrentThreadId
• 0x4b3244 - GetProcessTimes
• 0x4b3248 - HeapFree
• 0x4b324c - InitializeCriticalSection
• 0x4b3250 - HeapSize
• 0x4b3254 - WritePrivateProfileStructW
• 0x4b3258 - HeapReAlloc
• 0x4b325c - HeapAlloc
• 0x4b3260 - GetProcessHeap
• 0x4b3264 - GlobalMemoryStatusEx
• 0x4b3268 - DebugBreak
• 0x4b326c - SetUnhandledExceptionFilter
• 0x4b3270 - GetWindowsDirectoryW
• 0x4b3274 - RegisterWaitForSingleObject
• 0x4b3278 - UnregisterWaitEx
• 0x4b327c - SizeofResource
• 0x4b3280 - LockResource
• 0x4b3284 - LoadResource
• 0x4b3288 - FindResourceW
• 0x4b328c - IsDebuggerPresent
• 0x4b3290 - DeviceIoControl
• 0x4b3294 - TlsGetValue
• 0x4b3298 - lstrcmpA
• 0x4b329c - lstrcmpiA
• 0x4b32a0 - TlsSetValue
• 0x4b32a4 - TlsAlloc
• 0x4b32a8 - ResetEvent
• 0x4b32ac - TlsFree
• 0x4b32b0 - TryEnterCriticalSection
• 0x4b32b4 - RtlCaptureStackBackTrace
• 0x4b32b8 - VirtualQueryEx
• 0x4b32bc - HeapLock
• 0x4b32c0 - HeapWalk
• 0x4b32c4 - HeapUnlock
• 0x4b32c8 - GetQueuedCompletionStatus
• 0x4b32cc - PostQueuedCompletionStatus
• 0x4b32d0 - CreateIoCompletionPort
• 0x4b32d4 - CreateRemoteThread
• 0x4b32d8 - GetLocaleInfoW
• 0x4b32dc - SuspendThread
• 0x4b32e0 - GetThreadContext
• 0x4b32e4 - FlushInstructionCache
• 0x4b32e8 - SetThreadContext
• 0x4b32ec - CreateFileA
• 0x4b32f0 - GetTimeZoneInformation
• 0x4b32f4 - OutputDebugStringW
• 0x4b32f8 - VirtualAllocEx
• 0x4b32fc - TerminateJobObject
• 0x4b3300 - WriteProcessMemory
• 0x4b3304 - VirtualProtectEx
• 0x4b3308 - GetProcessHeaps
• 0x4b330c - GetProcessHandleCount
• 0x4b3310 - SignalObjectAndWait
• 0x4b3314 - GetFileType
• 0x4b3318 - VirtualFreeEx
• 0x4b331c - CreateJobObjectW
• 0x4b3320 - CreateNamedPipeW
• 0x4b3324 - CreateMutexW
• 0x4b3328 - SearchPathW
• 0x4b332c - LoadLibraryExA
• 0x4b3330 - WriteConsoleW
• 0x4b3334 - SetEnvironmentVariableA
• 0x4b3338 - FreeEnvironmentStringsW
• 0x4b333c - GetEnvironmentStringsW
• 0x4b3340 - GetCommandLineA
• 0x4b3344 - GetOEMCP
• 0x4b3348 - IsValidCodePage
• 0x4b334c - EnumSystemLocalesW
• 0x4b3350 - IsValidLocale
• 0x4b3354 - ReadConsoleW
• 0x4b3358 - GetACP
• 0x4b335c - GetEnvironmentVariableW
• 0x4b3360 - lstrlenW
• 0x4b3364 - GetConsoleMode
• 0x4b3368 - GetConsoleCP
• 0x4b336c - GetFullPathNameW
• 0x4b3370 - FormatMessageW
• 0x4b3374 - GetStringTypeW
• 0x4b3378 - EncodePointer
• 0x4b337c - GetCPInfo
• 0x4b3380 - CompareStringW
• 0x4b3384 - LCMapStringW
• 0x4b3388 - UnhandledExceptionFilter
• 0x4b338c - IsProcessorFeaturePresent
• 0x4b3390 - GetStartupInfoW
• 0x4b3394 - InitializeSListHead
• 0x4b3398 - LocalFileTimeToFileTime
• 0x4b339c - ReleaseMutex
• 0x4b33a0 - OpenThread
• 0x4b33a4 - RtlUnwind
• 0x4b33a8 - ExitProcess
• 0x4b33ac - GetDriveTypeW
• 0x4b33b0 - SetStdHandle