库 KERNEL32.dll:
• 0x5d9124 - FreeLibraryAndExitThread
• 0x5d9128 - GetCurrentDirectoryW
• 0x5d912c - ExitThread
• 0x5d9130 - FileTimeToSystemTime
• 0x5d9134 - SystemTimeToTzSpecificLocalTime
• 0x5d9138 - GetDriveTypeW
• 0x5d913c - ExpandEnvironmentStringsW
• 0x5d9140 - PeekNamedPipe
• 0x5d9144 - WaitForMultipleObjects
• 0x5d9148 - GetSystemDirectoryA
• 0x5d914c - SleepEx
• 0x5d9150 - ResetEvent
• 0x5d9154 - SetEvent
• 0x5d9158 - lstrlenA
• 0x5d915c - CreateFileMappingW
• 0x5d9160 - UnmapViewOfFile
• 0x5d9164 - MapViewOfFile
• 0x5d9168 - GetFileInformationByHandle
• 0x5d916c - InterlockedCompareExchange
• 0x5d9170 - CreateEventW
• 0x5d9174 - WideCharToMultiByte
• 0x5d9178 - OutputDebugStringA
• 0x5d917c - GlobalUnlock
• 0x5d9180 - GlobalLock
• 0x5d9184 - DeleteFileW
• 0x5d9188 - GetTempPathW
• 0x5d918c - FindResourceW
• 0x5d9190 - WriteFile
• 0x5d9194 - SizeofResource
• 0x5d9198 - LoadResource
• 0x5d919c - LockResource
• 0x5d91a0 - SetCurrentDirectoryW
• 0x5d91a4 - Process32NextW
• 0x5d91a8 - Process32FirstW
• 0x5d91ac - CreateToolhelp32Snapshot
• 0x5d91b0 - GetModuleHandleW
• 0x5d91b4 - GetLastError
• 0x5d91b8 - GetCurrentProcessId
• 0x5d91bc - VirtualFree
• 0x5d91c0 - VirtualAlloc
• 0x5d91c4 - LocalFree
• 0x5d91c8 - LocalAlloc
• 0x5d91cc - DeleteCriticalSection
• 0x5d91d0 - LeaveCriticalSection
• 0x5d91d4 - EnterCriticalSection
• 0x5d91d8 - InitializeCriticalSection
• 0x5d91dc - InterlockedDecrement
• 0x5d91e0 - InterlockedIncrement
• 0x5d91e4 - CreateFileW
• 0x5d91e8 - WritePrivateProfileStringW
• 0x5d91ec - GetModuleFileNameW
• 0x5d91f0 - ReadFile
• 0x5d91f4 - GetFileSize
• 0x5d91f8 - CreateThread
• 0x5d91fc - Sleep
• 0x5d9200 - GetCurrentProcess
• 0x5d9204 - GlobalFree
• 0x5d9208 - GlobalAlloc
• 0x5d920c - QueryDosDeviceW
• 0x5d9210 - GetWindowsDirectoryW
• 0x5d9214 - LoadLibraryW
• 0x5d9218 - GetLogicalDriveStringsW
• 0x5d921c - lstrlenW
• 0x5d9220 - lstrcmpiW
• 0x5d9224 - CloseHandle
• 0x5d9228 - OpenProcess
• 0x5d922c - GetProcAddress
• 0x5d9230 - FreeLibrary
• 0x5d9234 - MulDiv
• 0x5d9238 - MultiByteToWideChar
• 0x5d923c - UnhandledExceptionFilter
• 0x5d9240 - SetUnhandledExceptionFilter
• 0x5d9244 - TerminateProcess
• 0x5d9248 - IsProcessorFeaturePresent
• 0x5d924c - IsDebuggerPresent
• 0x5d9250 - GetStartupInfoW
• 0x5d9254 - QueryPerformanceCounter
• 0x5d9258 - GetCurrentThreadId
• 0x5d925c - GetSystemTimeAsFileTime
• 0x5d9260 - InitializeSListHead
• 0x5d9264 - WaitForSingleObject
• 0x5d9268 - CreateProcessW
• 0x5d926c - MoveFileExW
• 0x5d9270 - DecodePointer
• 0x5d9274 - HeapDestroy
• 0x5d9278 - HeapAlloc
• 0x5d927c - HeapReAlloc
• 0x5d9280 - HeapFree
• 0x5d9284 - HeapSize
• 0x5d9288 - GetProcessHeap
• 0x5d928c - RaiseException
• 0x5d9290 - InitializeCriticalSectionAndSpinCount
• 0x5d9294 - GetSystemInfo
• 0x5d9298 - FormatMessageW
• 0x5d929c - GetVersionExW
• 0x5d92a0 - GetPrivateProfileIntW
• 0x5d92a4 - GetPrivateProfileStringW
• 0x5d92a8 - FindClose
• 0x5d92ac - CreateDirectoryW
• 0x5d92b0 - FindFirstFileW
• 0x5d92b4 - FindNextFileW
• 0x5d92b8 - ReleaseMutex
• 0x5d92bc - CreateMutexW
• 0x5d92c0 - GetFileSizeEx
• 0x5d92c4 - GetTickCount
• 0x5d92c8 - AreFileApisANSI
• 0x5d92cc - SetErrorMode
• 0x5d92d0 - GetLocalTime
• 0x5d92d4 - FlushInstructionCache
• 0x5d92d8 - HeapCreate
• 0x5d92dc - FreeResource
• 0x5d92e0 - SetLastError
• 0x5d92e4 - GetFullPathNameW
• 0x5d92e8 - GetVersionExA
• 0x5d92ec - LoadLibraryA
• 0x5d92f0 - GetModuleHandleA
• 0x5d92f4 - EncodePointer
• 0x5d92f8 - RtlUnwind
• 0x5d92fc - TlsAlloc
• 0x5d9300 - TlsGetValue
• 0x5d9304 - TlsSetValue
• 0x5d9308 - TlsFree
• 0x5d930c - LoadLibraryExW
• 0x5d9310 - ExitProcess
• 0x5d9314 - GetModuleHandleExW
• 0x5d9318 - GetStdHandle
• 0x5d931c - GetACP
• 0x5d9320 - GetFileType
• 0x5d9324 - GetStringTypeW
• 0x5d9328 - CompareStringW
• 0x5d932c - LCMapStringW
• 0x5d9330 - GetConsoleMode
• 0x5d9334 - ReadConsoleW
• 0x5d9338 - SetFilePointerEx
• 0x5d933c - FindFirstFileExW
• 0x5d9340 - IsValidCodePage
• 0x5d9344 - GetOEMCP
• 0x5d9348 - GetCPInfo
• 0x5d934c - GetCommandLineA
• 0x5d9350 - GetCommandLineW
• 0x5d9354 - GetEnvironmentStringsW
• 0x5d9358 - FreeEnvironmentStringsW
• 0x5d935c - SetEnvironmentVariableA
• 0x5d9360 - OutputDebugStringW
• 0x5d9364 - WaitForSingleObjectEx
• 0x5d9368 - SetStdHandle
• 0x5d936c - GetConsoleCP
• 0x5d9370 - GetTimeZoneInformation
• 0x5d9374 - FlushFileBuffers
• 0x5d9378 - WriteConsoleW
• 0x5d937c - SetEndOfFile
库 USER32.dll:
• 0x5d93c8 - MonitorFromWindow
• 0x5d93cc - GetMonitorInfoW
• 0x5d93d0 - TrackMouseEvent
• 0x5d93d4 - PostMessageW
• 0x5d93d8 - PostQuitMessage
• 0x5d93dc - AnimateWindow
• 0x5d93e0 - SetLayeredWindowAttributes
• 0x5d93e4 - IsIconic
• 0x5d93e8 - IsZoomed
• 0x5d93ec - GetCapture
• 0x5d93f0 - SetCapture
• 0x5d93f4 - ReleaseCapture
• 0x5d93f8 - UpdateWindow
• 0x5d93fc - BeginPaint
• 0x5d9400 - EndPaint
• 0x5d9404 - InvalidateRect
• 0x5d9408 - CreateCaret
• 0x5d940c - GetCaretBlinkTime
• 0x5d9410 - HideCaret
• 0x5d9414 - SetCaretPos
• 0x5d9418 - ScreenToClient
• 0x5d941c - GetClassNameW
• 0x5d9420 - DestroyIcon
• 0x5d9424 - LoadBitmapW
• 0x5d9428 - CreateIconFromResource
• 0x5d942c - LoadImageW
• 0x5d9430 - CharNextW
• 0x5d9434 - GetMessageW
• 0x5d9438 - TranslateMessage
• 0x5d943c - DispatchMessageW
• 0x5d9440 - PeekMessageW
• 0x5d9444 - ClientToScreen
• 0x5d9448 - EnableMenuItem
• 0x5d944c - GetSysColor
• 0x5d9450 - IsWindowVisible
• 0x5d9454 - DrawTextW
• 0x5d9458 - SystemParametersInfoA
• 0x5d945c - CharLowerBuffW
• 0x5d9460 - GetWindowRect
• 0x5d9464 - UpdateLayeredWindow
• 0x5d9468 - IsMenu
• 0x5d946c - IsWindowEnabled
• 0x5d9470 - CreatePopupMenu
• 0x5d9474 - DestroyMenu
• 0x5d9478 - GetMenuItemCount
• 0x5d947c - GetWindow
• 0x5d9480 - AppendMenuW
• 0x5d9484 - TrackPopupMenu
• 0x5d9488 - GetMenuInfo
• 0x5d948c - SetMenuInfo
• 0x5d9490 - GetMenuItemInfoW
• 0x5d9494 - SetMenuContextHelpId
• 0x5d9498 - MsgWaitForMultipleObjects
• 0x5d949c - GetForegroundWindow
• 0x5d94a0 - GetClientRect
• 0x5d94a4 - GetDlgItem
• 0x5d94a8 - CreateWindowExW
• 0x5d94ac - RegisterClassExW
• 0x5d94b0 - CallWindowProcW
• 0x5d94b4 - DefWindowProcW
• 0x5d94b8 - GetKeyState
• 0x5d94bc - GetFocus
• 0x5d94c0 - SendMessageW
• 0x5d94c4 - IsWindow
• 0x5d94c8 - GetActiveWindow
• 0x5d94cc - GetSystemMetrics
• 0x5d94d0 - GetCursorPos
• 0x5d94d4 - OffsetRect
• 0x5d94d8 - GetWindowLongW
• 0x5d94dc - GetDC
• 0x5d94e0 - SystemParametersInfoW
• 0x5d94e4 - ShowWindow
• 0x5d94e8 - SetWindowPos
• 0x5d94ec - SetWindowTextW
• 0x5d94f0 - SetForegroundWindow
• 0x5d94f4 - FindWindowW
• 0x5d94f8 - SetFocus
• 0x5d94fc - PtInRect
• 0x5d9500 - EqualRect
• 0x5d9504 - IsRectEmpty
• 0x5d9508 - UnionRect
• 0x5d950c - CopyRect
• 0x5d9510 - SetRect
• 0x5d9514 - SetCursor
• 0x5d9518 - KillTimer
• 0x5d951c - GetParent
• 0x5d9520 - SetWindowLongW
• 0x5d9524 - MapWindowPoints
• 0x5d9528 - SetTimer
• 0x5d952c - DestroyWindow
• 0x5d9530 - DestroyCursor
• 0x5d9534 - LoadCursorW
• 0x5d9538 - IntersectRect
• 0x5d953c - UnregisterClassW
• 0x5d9540 - GetIconInfo
• 0x5d9544 - DrawIconEx
• 0x5d9548 - InflateRect
• 0x5d954c - ReleaseDC
• 0x5d9550 - MapVirtualKeyA
库 ADVAPI32.dll:
• 0x5d9000 - RegOpenKeyExW
• 0x5d9004 - RegQueryValueExW
• 0x5d9008 - RegCreateKeyExW
• 0x5d900c - RegSetValueExW
• 0x5d9010 - ImpersonateLoggedOnUser
• 0x5d9014 - RevertToSelf
• 0x5d9018 - RegOpenKeyW
• 0x5d901c - RegEnumKeyW
• 0x5d9020 - DuplicateTokenEx
• 0x5d9024 - CreateProcessAsUserW
• 0x5d9028 - LookupAccountSidW
• 0x5d902c - RegCloseKey
• 0x5d9030 - SetSecurityDescriptorDacl
• 0x5d9034 - InitializeSecurityDescriptor
• 0x5d9038 - SetTokenInformation
• 0x5d903c - GetTokenInformation
• 0x5d9040 - OpenProcessToken
库 SHELL32.dll:
• 0x5d93a4 - ShellExecuteW
• 0x5d93a8 - SHGetSpecialFolderPathW
• 0x5d93ac - SHGetFolderPathW
• 0x5d93b0 - SHGetPathFromIDListW
• 0x5d93b4 - SHBrowseForFolderW
库 ole32.dll:
• 0x5d9664 - CoCreateGuid
• 0x5d9668 - OleLockRunning
• 0x5d966c - CLSIDFromString
• 0x5d9670 - CLSIDFromProgID
• 0x5d9674 - CoCreateInstance
• 0x5d9678 - OleInitialize
• 0x5d967c - OleUninitialize
• 0x5d9680 - CreateStreamOnHGlobal
• 0x5d9684 - CoInitialize
• 0x5d9688 - CoUninitialize
• 0x5d968c - CreateBindCtx
库 SHLWAPI.dll:
• 0x5d93bc - PathFileExistsW
• 0x5d93c0 - StrToIntExW
库 PSAPI.DLL:
• 0x5d9390 - GetModuleFileNameExW
• 0x5d9394 - EnumProcessModules
• 0x5d9398 - EnumProcesses
• 0x5d939c - GetProcessImageFileNameW
库 CRYPT32.dll:
• 0x5d9048 - CryptMsgGetParam
• 0x5d904c - CertCloseStore
• 0x5d9050 - CertFindCertificateInStore
• 0x5d9054 - CertFreeCertificateContext
• 0x5d9058 - CertGetNameStringW
• 0x5d905c - CryptQueryObject
• 0x5d9060 - CryptMsgClose
库 gdiplus.dll:
• 0x5d95f4 - GdipImageGetFrameCount
• 0x5d95f8 - GdipGetImageEncoders
• 0x5d95fc - GdipAlloc
• 0x5d9600 - GdipFree
• 0x5d9604 - GdiplusStartup
• 0x5d9608 - GdiplusShutdown
• 0x5d960c - GdipCloneImage
• 0x5d9610 - GdipDisposeImage
• 0x5d9614 - GdipGetImageGraphicsContext
• 0x5d9618 - GdipGetImageWidth
• 0x5d961c - GdipGetImageHeight
• 0x5d9620 - GdipImageGetFrameDimensionsCount
• 0x5d9624 - GdipImageGetFrameDimensionsList
• 0x5d9628 - GdipImageSelectActiveFrame
• 0x5d962c - GdipGetPropertyItemSize
• 0x5d9630 - GdipGetPropertyItem
• 0x5d9634 - GdipCreateBitmapFromStream
• 0x5d9638 - GdipCreateBitmapFromFile
• 0x5d963c - GdipCreateBitmapFromScan0
• 0x5d9640 - GdipBitmapLockBits
• 0x5d9644 - GdipBitmapUnlockBits
• 0x5d9648 - GdipDeleteGraphics
• 0x5d964c - GdipDrawImageI
• 0x5d9650 - GdipSaveImageToFile
• 0x5d9654 - GdipGraphicsClear
• 0x5d9658 - GdipGetImageEncodersSize
• 0x5d965c - GdipDrawImageRectI
库 IMM32.dll:
• 0x5d9114 - ImmAssociateContext
• 0x5d9118 - ImmReleaseContext
• 0x5d911c - ImmGetContext
库 GDI32.dll:
• 0x5d9068 - SetBkMode
• 0x5d906c - StretchBlt
• 0x5d9070 - Rectangle
• 0x5d9074 - EnumFontsW
• 0x5d9078 - BitBlt
• 0x5d907c - GetViewportOrgEx
• 0x5d9080 - GetCurrentObject
• 0x5d9084 - SetViewportOrgEx
• 0x5d9088 - GetStockObject
• 0x5d908c - CreateSolidBrush
• 0x5d9090 - CreateFontIndirectW
• 0x5d9094 - SetGraphicsMode
• 0x5d9098 - GetDeviceCaps
• 0x5d909c - CreateRoundRectRgn
• 0x5d90a0 - GetObjectW
• 0x5d90a4 - CreateDIBSection
• 0x5d90a8 - SelectObject
• 0x5d90ac - SelectClipRgn
• 0x5d90b0 - IntersectClipRect
• 0x5d90b4 - GetRegionData
• 0x5d90b8 - ExtCreateRegion
• 0x5d90bc - DeleteObject
• 0x5d90c0 - DeleteDC
• 0x5d90c4 - GdiFlush
• 0x5d90c8 - GetTextFaceW
• 0x5d90cc - ExtTextOutW
• 0x5d90d0 - SetWorldTransform
• 0x5d90d4 - GetTextMetricsW
• 0x5d90d8 - SetTextAlign
• 0x5d90dc - SetTextColor
• 0x5d90e0 - RemoveFontMemResourceEx
• 0x5d90e4 - AddFontMemResourceEx
• 0x5d90e8 - GetTextExtentPointI
• 0x5d90ec - GetGlyphIndicesW
• 0x5d90f0 - GetFontUnicodeRanges
• 0x5d90f4 - GetOutlineTextMetricsW
• 0x5d90f8 - GetGlyphOutlineW
• 0x5d90fc - GetFontData
• 0x5d9100 - GetCharABCWidthsW
• 0x5d9104 - EnumFontFamiliesExW
• 0x5d9108 - CreateCompatibleDC
• 0x5d910c - CreateBitmap
库 OLEAUT32.dll:
• 0x5d9384 - SysAllocString
• 0x5d9388 - SysFreeString
库 USERENV.dll:
• 0x5d9558 - DestroyEnvironmentBlock
• 0x5d955c - CreateEnvironmentBlock
库 WS2_32.dll:
• 0x5d9574 - getsockopt
• 0x5d9578 - htons
• 0x5d957c - ntohs
• 0x5d9580 - setsockopt
• 0x5d9584 - WSASetLastError
• 0x5d9588 - htonl
• 0x5d958c - inet_addr
• 0x5d9590 - inet_ntoa
• 0x5d9594 - gethostbyaddr
• 0x5d9598 - gethostbyname
• 0x5d959c - getsockname
• 0x5d95a0 - getservbyname
• 0x5d95a4 - __WSAFDIsSet
• 0x5d95a8 - select
• 0x5d95ac - recvfrom
• 0x5d95b0 - sendto
• 0x5d95b4 - accept
• 0x5d95b8 - listen
• 0x5d95bc - ioctlsocket
• 0x5d95c0 - gethostname
• 0x5d95c4 - getpeername
• 0x5d95c8 - connect
• 0x5d95cc - bind
• 0x5d95d0 - send
• 0x5d95d4 - recv
• 0x5d95d8 - WSAGetLastError
• 0x5d95dc - socket
• 0x5d95e0 - closesocket
• 0x5d95e4 - WSACleanup
• 0x5d95e8 - getservbyport
• 0x5d95ec - WSAStartup
库 USP10.dll:
• 0x5d9564 - ScriptFreeCache
• 0x5d9568 - ScriptItemize
• 0x5d956c - ScriptShape