库 KERNEL32.dll:
• 0x140098118 - LeaveCriticalSection
• 0x140098120 - DeleteCriticalSection
• 0x140098128 - GetProcessId
• 0x140098130 - OpenProcess
• 0x140098138 - GetTickCount
• 0x140098140 - GetVersionExA
• 0x140098148 - FreeLibrary
• 0x140098150 - GetModuleHandleA
• 0x140098158 - GetProcAddress
• 0x140098160 - LoadLibraryA
• 0x140098168 - SetCurrentDirectoryA
• 0x140098170 - GetCommandLineA
• 0x140098178 - GetFileSize
• 0x140098180 - ReadFile
• 0x140098188 - SetFilePointer
• 0x140098190 - OutputDebugStringA
• 0x140098198 - DeviceIoControl
• 0x1400981a0 - GetProcessTimes
• 0x1400981a8 - GetSystemTimeAsFileTime
• 0x1400981b0 - GetSystemInfo
• 0x1400981b8 - MapViewOfFile
• 0x1400981c0 - UnmapViewOfFile
• 0x1400981c8 - GetLargePageMinimum
• 0x1400981d0 - LoadResource
• 0x1400981d8 - LockResource
• 0x1400981e0 - SizeofResource
• 0x1400981e8 - GlobalAlloc
• 0x1400981f0 - GlobalFree
• 0x1400981f8 - LocalAlloc
• 0x140098200 - CreateFileMappingA
• 0x140098208 - OpenFileMappingA
• 0x140098210 - FindResourceA
• 0x140098218 - WideCharToMultiByte
• 0x140098220 - CreateToolhelp32Snapshot
• 0x140098228 - Process32First
• 0x140098230 - Process32Next
• 0x140098238 - K32GetModuleFileNameExA
• 0x140098240 - FindClose
• 0x140098248 - FindFirstFileA
• 0x140098250 - FindNextFileA
• 0x140098258 - GetFileAttributesA
• 0x140098260 - WriteFile
• 0x140098268 - EnterCriticalSection
• 0x140098270 - GetFullPathNameA
• 0x140098278 - WaitForSingleObject
• 0x140098280 - CreateEventA
• 0x140098288 - CopyFileA
• 0x140098290 - GetCurrentDirectoryA
• 0x140098298 - CreateDirectoryA
• 0x1400982a0 - LocalFileTimeToFileTime
• 0x1400982a8 - SetFileTime
• 0x1400982b0 - SystemTimeToFileTime
• 0x1400982b8 - GlobalMemoryStatusEx
• 0x1400982c0 - GetFileInformationByHandle
• 0x1400982c8 - FileTimeToSystemTime
• 0x1400982d0 - SetEnvironmentVariableA
• 0x1400982d8 - FreeEnvironmentStringsW
• 0x1400982e0 - GetEnvironmentStringsW
• 0x1400982e8 - GetCommandLineW
• 0x1400982f0 - GetCPInfo
• 0x1400982f8 - GetOEMCP
• 0x140098300 - IsValidCodePage
• 0x140098308 - FindNextFileW
• 0x140098310 - FindFirstFileExW
• 0x140098318 - FindFirstFileExA
• 0x140098320 - GetTimeZoneInformation
• 0x140098328 - FlushFileBuffers
• 0x140098330 - ReadConsoleW
• 0x140098338 - GetConsoleMode
• 0x140098340 - GetConsoleCP
• 0x140098348 - GetFileType
• 0x140098350 - EnumSystemLocalesW
• 0x140098358 - GetUserDefaultLCID
• 0x140098360 - IsValidLocale
• 0x140098368 - EncodePointer
• 0x140098370 - SetLastError
• 0x140098378 - InterlockedFlushSList
• 0x140098380 - InterlockedPushEntrySList
• 0x140098388 - RtlUnwindEx
• 0x140098390 - InitializeCriticalSection
• 0x140098398 - QueryPerformanceFrequency
• 0x1400983a0 - QueryPerformanceCounter
• 0x1400983a8 - GetLocalTime
• 0x1400983b0 - GetCurrentThreadId
• 0x1400983b8 - GetCurrentProcessId
• 0x1400983c0 - GetCurrentProcess
• 0x1400983c8 - SetUnhandledExceptionFilter
• 0x1400983d0 - RaiseException
• 0x1400983d8 - CloseHandle
• 0x1400983e0 - CreateFileA
• 0x1400983e8 - MultiByteToWideChar
• 0x1400983f0 - MoveFileA
• 0x1400983f8 - LocalFree
• 0x140098400 - GetLastError
• 0x140098408 - SetFileAttributesA
• 0x140098410 - DeleteFileA
• 0x140098418 - GetComputerNameA
• 0x140098420 - Sleep
• 0x140098428 - SetEnvironmentVariableW
• 0x140098430 - GetProcessHeap
• 0x140098438 - SetConsoleCtrlHandler
• 0x140098440 - OutputDebugStringW
• 0x140098448 - WaitForSingleObjectEx
• 0x140098450 - SetStdHandle
• 0x140098458 - CreateFileW
• 0x140098460 - SetFilePointerEx
• 0x140098468 - WriteConsoleW
• 0x140098470 - HeapSize
• 0x140098478 - GetLocaleInfoW
• 0x140098480 - LCMapStringW
• 0x140098488 - CompareStringW
• 0x140098490 - GetTimeFormatW
• 0x140098498 - HeapReAlloc
• 0x1400984a0 - SetEndOfFile
• 0x1400984a8 - InitializeCriticalSectionAndSpinCount
• 0x1400984b0 - TlsAlloc
• 0x1400984b8 - TlsGetValue
• 0x1400984c0 - TerminateProcess
• 0x1400984c8 - GetDateFormatW
• 0x1400984d0 - GetStringTypeW
• 0x1400984d8 - GetCurrentThread
• 0x1400984e0 - HeapAlloc
• 0x1400984e8 - HeapFree
• 0x1400984f0 - GetACP
• 0x1400984f8 - GetStdHandle
• 0x140098500 - GetModuleFileNameW
• 0x140098508 - GetModuleFileNameA
• 0x140098510 - ExitProcess
• 0x140098518 - GetModuleHandleExW
• 0x140098520 - FreeLibraryAndExitThread
• 0x140098528 - ResumeThread
• 0x140098530 - ExitThread
• 0x140098538 - CreateThread
• 0x140098540 - LoadLibraryExW
• 0x140098548 - TlsFree
• 0x140098550 - RtlCaptureContext
• 0x140098558 - RtlLookupFunctionEntry
• 0x140098560 - RtlVirtualUnwind
• 0x140098568 - IsDebuggerPresent
• 0x140098570 - UnhandledExceptionFilter
• 0x140098578 - GetStartupInfoW
• 0x140098580 - IsProcessorFeaturePresent
• 0x140098588 - GetModuleHandleW
• 0x140098590 - InitializeSListHead
• 0x140098598 - RtlPcToFileHeader
• 0x1400985a0 - TlsSetValue
库 ADVAPI32.dll:
• 0x140098000 - StartServiceCtrlDispatcherA
• 0x140098008 - GetNamedSecurityInfoA
• 0x140098010 - SetNamedSecurityInfoA
• 0x140098018 - BuildExplicitAccessWithNameA
• 0x140098020 - OpenProcessToken
• 0x140098028 - AdjustTokenPrivileges
• 0x140098030 - RegSetValueExW
• 0x140098038 - RegFlushKey
• 0x140098040 - StartServiceA
• 0x140098048 - QueryServiceStatus
• 0x140098050 - QueryServiceConfigA
• 0x140098058 - OpenServiceA
• 0x140098060 - OpenSCManagerA
• 0x140098068 - DeleteService
• 0x140098070 - CreateServiceA
• 0x140098078 - ControlService
• 0x140098080 - CloseServiceHandle
• 0x140098088 - ChangeServiceConfigA
• 0x140098090 - RegSetValueExA
• 0x140098098 - RegCreateKeyExA
• 0x1400980a0 - RegQueryValueExA
• 0x1400980a8 - RegOpenKeyExA
• 0x1400980b0 - RegCloseKey
• 0x1400980b8 - SetSecurityDescriptorDacl
• 0x1400980c0 - InitializeSecurityDescriptor
• 0x1400980c8 - SetServiceStatus
• 0x1400980d0 - RegisterServiceCtrlHandlerA
• 0x1400980d8 - SetEntriesInAclA