库 ADVAPI32.dll:
• 0x140076ae0 - RegEnumKeyW
• 0x140076ae8 - RegSetKeySecurity
• 0x140076af0 - RegDeleteKeyW
• 0x140076af8 - RegCreateKeyExW
• 0x140076b00 - RegQueryInfoKeyW
• 0x140076b08 - CryptAcquireContextW
• 0x140076b10 - CryptReleaseContext
• 0x140076b18 - CryptGenRandom
• 0x140076b20 - RegQueryValueExW
• 0x140076b28 - RegSetValueExW
• 0x140076b30 - RegOpenKeyExW
• 0x140076b38 - RegCloseKey
库 KERNEL32.dll:
• 0x140076b70 - EncodePointer
• 0x140076b78 - GetCurrentProcessId
• 0x140076b80 - CreateProcessW
• 0x140076b88 - OpenEventW
• 0x140076b90 - DecodePointer
• 0x140076b98 - LocalAlloc
• 0x140076ba0 - LocalFree
• 0x140076ba8 - SetLastError
• 0x140076bb0 - CreateEventW
• 0x140076bb8 - GetCurrentProcess
• 0x140076bc0 - VirtualAlloc
• 0x140076bc8 - RtlAddFunctionTable
• 0x140076bd0 - InitializeCriticalSection
• 0x140076bd8 - HeapSetInformation
• 0x140076be0 - RaiseFailFastException
• 0x140076be8 - GetCurrentThread
• 0x140076bf0 - DeleteCriticalSection
• 0x140076bf8 - GetModuleHandleW
• 0x140076c00 - RtlDeleteFunctionTable
• 0x140076c08 - LoadLibraryExW
• 0x140076c10 - SetThreadPriority
• 0x140076c18 - SetEvent
• 0x140076c20 - CloseHandle
• 0x140076c28 - GetModuleFileNameW
• 0x140076c30 - GetLastError
• 0x140076c38 - GetCommandLineW
• 0x140076c40 - GetSystemDirectoryW
• 0x140076c48 - FreeLibrary
• 0x140076c50 - WaitForMultipleObjects
• 0x140076c58 - CreateThread
• 0x140076c60 - EnterCriticalSection
• 0x140076c68 - LeaveCriticalSection
• 0x140076c70 - InitializeCriticalSectionAndSpinCount
• 0x140076c78 - GetComputerNameExW
• 0x140076c80 - VirtualQuery
• 0x140076c88 - GetProcessHeap
• 0x140076c90 - GetProcAddress
• 0x140076c98 - HeapAlloc
• 0x140076ca0 - GetModuleHandleExW
• 0x140076ca8 - HeapFree
• 0x140076cb0 - WaitForSingleObject
• 0x140076cb8 - VirtualFree
• 0x140076cc0 - FreeLibraryAndExitThread
库 msvcrt.dll:
• 0x140076fd0 - memcmp
• 0x140076fd8 - memmove
• 0x140076fe0 - memcpy
• 0x140076fe8 - _vsnwprintf
• 0x140076ff0 - memset
• 0x140076ff8 - _unlock
• 0x140077000 - _wcsicmp
• 0x140077008 - _purecall
• 0x140077010 - srand
• 0x140077018 - rand
• 0x140077020 - wcschr
• 0x140077028 - towupper
• 0x140077030 - __C_specific_handler
• 0x140077038 - _XcptFilter
• 0x140077040 - ?terminate@@YAXXZ
• 0x140077048 - _onexit
• 0x140077050 - __dllonexit
• 0x140077058 - wcscmp
• 0x140077060 - _lock
• 0x140077068 - _commode
• 0x140077070 - _fmode
• 0x140077078 - _acmdln
• 0x140077080 - _initterm
• 0x140077088 - __setusermatherr
• 0x140077090 - _ismbblead
• 0x140077098 - _cexit
• 0x1400770a0 - _exit
• 0x1400770a8 - exit
• 0x1400770b0 - __set_app_type
• 0x1400770b8 - __getmainargs
• 0x1400770c0 - _amsg_exit
库 ntdll.dll:
• 0x1400770d0 - RtlCaptureContext
• 0x1400770d8 - RtlLookupFunctionEntry
• 0x1400770e0 - RtlVirtualUnwind
• 0x1400770e8 - NtQuerySystemInformation
库 RPCRT4.dll:
• 0x140076db0 - UuidToStringW
• 0x140076db8 - I_RpcMapWin32Status
• 0x140076dc0 - CStdStubBuffer_Invoke
• 0x140076dc8 - IUnknown_AddRef_Proxy
• 0x140076dd0 - CStdStubBuffer_DebugServerQueryInterface
• 0x140076dd8 - NdrOleFree
• 0x140076de0 - CStdStubBuffer_AddRef
• 0x140076de8 - UuidFromStringW
• 0x140076df0 - IUnknown_Release_Proxy
• 0x140076df8 - CStdStubBuffer_CountRefs
• 0x140076e00 - CStdStubBuffer_QueryInterface
• 0x140076e08 - NdrOleAllocate
• 0x140076e10 - CStdStubBuffer_DebugServerRelease
• 0x140076e18 - Ndr64AsyncServerCallAll
• 0x140076e20 - RpcStringFreeW
• 0x140076e28 - NdrAsyncServerCall
• 0x140076e30 - Ndr64AsyncClientCall
• 0x140076e38 - NdrDllGetClassObject
• 0x140076e40 - RpcStringBindingComposeW
• 0x140076e48 - RpcBindingFromStringBindingW
• 0x140076e50 - RpcAsyncInitializeHandle
• 0x140076e58 - I_RpcExceptionFilter
• 0x140076e60 - RpcAsyncCancelCall
• 0x140076e68 - RpcAsyncCompleteCall
• 0x140076e70 - RpcBindingFree
• 0x140076e78 - IUnknown_QueryInterface_Proxy
• 0x140076e80 - CStdStubBuffer_IsIIDSupported
• 0x140076e88 - CStdStubBuffer_Connect
• 0x140076e90 - RpcServerUseProtseqEpW
• 0x140076e98 - RpcServerRegisterIf2
• 0x140076ea0 - RpcServerUnregisterIf
• 0x140076ea8 - NdrCStdStubBuffer_Release
• 0x140076eb0 - CStdStubBuffer_Disconnect
库 OLEAUT32.dll:
• 0x140076cd0 - BSTR_UserUnmarshal
• 0x140076cd8 - BSTR_UserSize
• 0x140076ce0 - VariantClear
• 0x140076ce8 - VariantInit
• 0x140076cf0 - BSTR_UserFree
• 0x140076cf8 - LPSAFEARRAY_UserSize
• 0x140076d00 - BSTR_UserUnmarshal64
• 0x140076d08 - BSTR_UserMarshal
• 0x140076d10 - LPSAFEARRAY_UserMarshal64
• 0x140076d18 - SysFreeString
• 0x140076d20 - SysAllocString
• 0x140076d28 - LPSAFEARRAY_UserMarshal
• 0x140076d30 - BSTR_UserFree64
• 0x140076d38 - LPSAFEARRAY_UserFree
• 0x140076d40 - LPSAFEARRAY_UserUnmarshal
• 0x140076d48 - BSTR_UserSize64
• 0x140076d50 - SafeArrayDestroy
• 0x140076d58 - LPSAFEARRAY_UserUnmarshal64
• 0x140076d60 - LPSAFEARRAY_UserSize64
• 0x140076d68 - BSTR_UserMarshal64
• 0x140076d70 - LPSAFEARRAY_UserFree64
• 0x140076d78 - SafeArrayAccessData
• 0x140076d80 - SafeArrayUnaccessData
• 0x140076d88 - SafeArrayCreateVector
• 0x140076d90 - UnRegisterTypeLib
• 0x140076d98 - RegisterTypeLib
• 0x140076da0 - LoadTypeLib
库 api-ms-win-core-com-l1-1-0.dll:
• 0x140076f08 - CoResumeClassObjects
• 0x140076f10 - CoRegisterClassObject
• 0x140076f18 - CoRevertToSelf
• 0x140076f20 - CoImpersonateClient
• 0x140076f28 - CoReleaseServerProcess
• 0x140076f30 - CoRevokeClassObject
• 0x140076f38 - CoUninitialize
• 0x140076f40 - CoInitializeEx
• 0x140076f48 - CoAddRefServerProcess
• 0x140076f50 - CoSuspendClassObjects
库 api-ms-win-core-synch-l1-2-0.dll:
• 0x140076fa8 - Sleep
库 api-ms-win-core-processthreads-l1-1-0.dll:
• 0x140076f78 - TerminateProcess
• 0x140076f80 - GetCurrentThreadId
• 0x140076f88 - GetStartupInfoW
库 api-ms-win-core-errorhandling-l1-1-0.dll:
• 0x140076f60 - SetUnhandledExceptionFilter
• 0x140076f68 - UnhandledExceptionFilter
库 api-ms-win-core-profile-l1-1-0.dll:
• 0x140076f98 - QueryPerformanceCounter
库 api-ms-win-core-sysinfo-l1-1-0.dll:
• 0x140076fb8 - GetTickCount
• 0x140076fc0 - GetSystemTimeAsFileTime
库 ole32.dll:
• 0x1400770f8 - CoRegisterPSClsid
• 0x140077100 - ObjectStublessClient3
• 0x140077108 - ObjectStublessClient5
• 0x140077110 - ObjectStublessClient4
库 SHELL32.dll:
• 0x140076ec0 - CommandLineToArgvW
库 WS2_32.dll:
• 0x140076ed0 - FreeAddrInfoW
• 0x140076ed8 - WSAAddressToStringW
• 0x140076ee0 - WSAGetLastError
• 0x140076ee8 - WSACleanup
• 0x140076ef0 - WSAStartup
• 0x140076ef8 - GetAddrInfoW
库 DNSAPI.dll:
• 0x140076b48 - DnsQuery_W
• 0x140076b50 - DnsNameCompare_W
• 0x140076b58 - DnsModifyRecordsInSet_W
• 0x140076b60 - DnsFree
库 ACTIVEDS.dll:
• 0x140076ac0 - None
• 0x140076ac8 - None
• 0x140076ad0 - None