库 ADVAPI32.dll:
• 0x1001000 - RegQueryValueExW
• 0x1001004 - SetSecurityDescriptorDacl
• 0x1001008 - SetEntriesInAclW
• 0x100100c - SetSecurityDescriptorGroup
• 0x1001010 - SetSecurityDescriptorOwner
• 0x1001014 - InitializeSecurityDescriptor
• 0x1001018 - GetTokenInformation
• 0x100101c - OpenProcessToken
• 0x1001020 - OpenThreadToken
• 0x1001024 - SetServiceStatus
• 0x1001028 - RegisterServiceCtrlHandlerW
• 0x100102c - RegCloseKey
• 0x1001030 - RegOpenKeyExW
• 0x1001034 - StartServiceCtrlDispatcherW
库 KERNEL32.dll:
• 0x100103c - HeapFree
• 0x1001040 - GetLastError
• 0x1001044 - WideCharToMultiByte
• 0x1001048 - lstrlenW
• 0x100104c - LocalFree
• 0x1001050 - GetCurrentProcess
• 0x1001054 - GetCurrentThread
• 0x1001058 - GetProcAddress
• 0x100105c - LoadLibraryExW
• 0x1001060 - LeaveCriticalSection
• 0x1001064 - HeapAlloc
• 0x1001068 - EnterCriticalSection
• 0x100106c - LCMapStringW
• 0x1001070 - FreeLibrary
• 0x1001074 - lstrcpyW
• 0x1001078 - ExpandEnvironmentStringsW
• 0x100107c - lstrcmpiW
• 0x1001080 - ExitProcess
• 0x1001084 - GetCommandLineW
• 0x1001088 - InitializeCriticalSection
• 0x100108c - GetProcessHeap
• 0x1001090 - SetErrorMode
• 0x1001094 - SetUnhandledExceptionFilter
• 0x1001098 - RegisterWaitForSingleObject
• 0x100109c - InterlockedCompareExchange
• 0x10010a0 - LoadLibraryA
• 0x10010a4 - QueryPerformanceCounter
• 0x10010a8 - GetTickCount
• 0x10010ac - GetCurrentThreadId
• 0x10010b0 - GetCurrentProcessId
• 0x10010b4 - GetSystemTimeAsFileTime
• 0x10010b8 - TerminateProcess
• 0x10010bc - UnhandledExceptionFilter
• 0x10010c0 - LocalAlloc
• 0x10010c4 - lstrcmpW
• 0x10010c8 - DelayLoadFailureHook
库 ntdll.dll:
• 0x10010d0 - NtQuerySecurityObject
• 0x10010d4 - RtlFreeHeap
• 0x10010d8 - NtOpenKey
• 0x10010dc - wcscat
• 0x10010e0 - wcscpy
• 0x10010e4 - RtlAllocateHeap
• 0x10010e8 - RtlCompareUnicodeString
• 0x10010ec - RtlInitUnicodeString
• 0x10010f0 - RtlInitializeSid
• 0x10010f4 - RtlLengthRequiredSid
• 0x10010f8 - RtlSubAuthoritySid
• 0x10010fc - NtClose
• 0x1001100 - RtlSubAuthorityCountSid
• 0x1001104 - RtlGetDaclSecurityDescriptor
• 0x1001108 - RtlQueryInformationAcl
• 0x100110c - RtlGetAce
• 0x1001110 - RtlImageNtHeader
• 0x1001114 - wcslen
• 0x1001118 - RtlUnhandledExceptionFilter
• 0x100111c - RtlCopySid
库 RPCRT4.dll:
• 0x1001124 - RpcServerUnregisterIfEx
• 0x1001128 - RpcMgmtWaitServerListen
• 0x100112c - RpcMgmtSetServerStackSize
• 0x1001130 - RpcServerUnregisterIf
• 0x1001134 - RpcServerListen
• 0x1001138 - RpcServerUseProtseqEpW
• 0x100113c - RpcServerRegisterIf
• 0x1001140 - I_RpcMapWin32Status
• 0x1001144 - RpcMgmtStopServerListening