库 ADVAPI32.dll:
• 0x2e001018 - GetTokenInformation
• 0x2e00101c - OpenThreadToken
• 0x2e001020 - UnregisterTraceGuids
• 0x2e001024 - ConvertSidToStringSidA
• 0x2e001028 - RegCloseKey
• 0x2e00102c - RegSetValueExW
• 0x2e001030 - RegCreateKeyExW
• 0x2e001034 - RegDeleteKeyW
• 0x2e001038 - RegEnumKeyExW
• 0x2e00103c - RegOpenKeyExW
• 0x2e001040 - RegQueryValueExA
• 0x2e001044 - RegQueryValueExW
• 0x2e001048 - GetTraceEnableFlags
• 0x2e00104c - GetTraceEnableLevel
• 0x2e001050 - GetTraceLoggerHandle
• 0x2e001054 - RegisterTraceGuidsA
• 0x2e001058 - TraceEvent
• 0x2e00105c - RegQueryInfoKeyW
• 0x2e001060 - RegEnumKeyW
• 0x2e001064 - RegEnumValueW
• 0x2e001068 - RegOpenKeyExA
• 0x2e00106c - GetLengthSid
• 0x2e001070 - AddAccessAllowedAce
• 0x2e001074 - AddAccessDeniedAce
• 0x2e001078 - InitializeAcl
• 0x2e00107c - AllocateAndInitializeSid
• 0x2e001080 - CopySid
• 0x2e001084 - OpenProcessToken
• 0x2e001088 - FreeSid
• 0x2e00108c - SetSecurityDescriptorDacl
• 0x2e001090 - InitializeSecurityDescriptor
• 0x2e001094 - GetSecurityDescriptorDacl
• 0x2e001098 - ConvertStringSecurityDescriptorToSecurityDescriptorW
• 0x2e00109c - CheckTokenMembership
• 0x2e0010a0 - IsValidSid
库 KERNEL32.dll:
• 0x2e0010c0 - GetSystemWindowsDirectoryW
• 0x2e0010c4 - lstrcmpiW
• 0x2e0010c8 - WriteConsoleW
• 0x2e0010cc - SetEvent
• 0x2e0010d0 - lstrlenW
• 0x2e0010d4 - CreateEventW
• 0x2e0010d8 - GetModuleFileNameW
• 0x2e0010dc - WaitForSingleObject
• 0x2e0010e0 - RaiseException
• 0x2e0010e4 - HeapFree
• 0x2e0010e8 - HeapAlloc
• 0x2e0010ec - GetProcessHeap
• 0x2e0010f0 - GetModuleHandleA
• 0x2e0010f4 - VirtualAlloc
• 0x2e0010f8 - HeapSetInformation
• 0x2e0010fc - HeapCreate
• 0x2e001100 - HeapDestroy
• 0x2e001104 - HeapReAlloc
• 0x2e001108 - HeapSize
• 0x2e00110c - HeapUnlock
• 0x2e001110 - HeapLock
• 0x2e001114 - TlsSetValue
• 0x2e001118 - SetLastError
• 0x2e00111c - GetLastError
• 0x2e001120 - VirtualFree
• 0x2e001124 - TlsGetValue
• 0x2e001128 - InitializeCriticalSectionAndSpinCount
• 0x2e00112c - TlsAlloc
• 0x2e001130 - GetSystemDefaultLCID
• 0x2e001134 - TlsFree
• 0x2e001138 - DeleteCriticalSection
• 0x2e00113c - EnterCriticalSection
• 0x2e001140 - LeaveCriticalSection
• 0x2e001144 - IsValidLocale
• 0x2e001148 - GetModuleHandleW
• 0x2e00114c - GetProcAddress
• 0x2e001150 - GetFileAttributesW
• 0x2e001154 - GetVersion
• 0x2e001158 - GetVersionExA
• 0x2e00115c - GetModuleHandleExW
• 0x2e001160 - RtlCaptureStackBackTrace
• 0x2e001164 - ReleaseMutex
• 0x2e001168 - CloseHandle
• 0x2e00116c - GetSystemTimeAsFileTime
• 0x2e001170 - GetTickCount
• 0x2e001174 - GetLocalTime
• 0x2e001178 - WriteFile
• 0x2e00117c - SetFileAttributesW
• 0x2e001180 - DeleteFileW
• 0x2e001184 - CreateFileW
• 0x2e001188 - ExpandEnvironmentStringsW
• 0x2e00118c - GetProcessTimes
• 0x2e001190 - GetCurrentProcess
• 0x2e001194 - GlobalFree
• 0x2e001198 - LoadLibraryW
• 0x2e00119c - OutputDebugStringA
• 0x2e0011a0 - CreateMutexA
• 0x2e0011a4 - OpenMutexA
• 0x2e0011a8 - CreateSemaphoreA
• 0x2e0011ac - GetShortPathNameA
• 0x2e0011b0 - GetModuleFileNameA
• 0x2e0011b4 - GlobalAlloc
• 0x2e0011b8 - GetSystemDirectoryW
• 0x2e0011bc - GetTimeZoneInformation
• 0x2e0011c0 - GetDiskFreeSpaceExW
• 0x2e0011c4 - IsWow64Process
• 0x2e0011c8 - GetUserDefaultLCID
• 0x2e0011cc - FreeLibrary
• 0x2e0011d0 - GetSystemInfo
• 0x2e0011d4 - GetVersionExW
• 0x2e0011d8 - TerminateProcess
• 0x2e0011dc - GetCurrentProcessId
• 0x2e0011e0 - GetCurrentThreadId
• 0x2e0011e4 - CreateProcessW
• 0x2e0011e8 - LoadLibraryA
• 0x2e0011ec - GetConsoleOutputCP
• 0x2e0011f0 - LocalFree
• 0x2e0011f4 - LocalAlloc
• 0x2e0011f8 - Sleep
• 0x2e0011fc - GetTempPathW
• 0x2e001200 - GetShortPathNameW
• 0x2e001204 - GetLongPathNameW
• 0x2e001208 - CreateDirectoryW
• 0x2e00120c - GetFileType
• 0x2e001210 - CreateFileA
• 0x2e001214 - InitializeCriticalSection
• 0x2e001218 - LoadLibraryExW
• 0x2e00121c - IsDBCSLeadByte
• 0x2e001220 - GetStringTypeExW
• 0x2e001224 - GetACP
• 0x2e001228 - WideCharToMultiByte
• 0x2e00122c - IsValidCodePage
• 0x2e001230 - CompareStringW
• 0x2e001234 - MultiByteToWideChar
• 0x2e001238 - GetCurrentThread
• 0x2e00123c - FlushFileBuffers
• 0x2e001240 - GlobalMemoryStatus
• 0x2e001244 - ReleaseSemaphore
• 0x2e001248 - IsProcessorFeaturePresent
• 0x2e00124c - RtlUnwind
• 0x2e001250 - SetUnhandledExceptionFilter
• 0x2e001254 - ExitProcess
• 0x2e001258 - GetStdHandle
• 0x2e00125c - FreeEnvironmentStringsW
• 0x2e001260 - GetEnvironmentStringsW
• 0x2e001264 - GetCommandLineW
• 0x2e001268 - SetHandleCount
• 0x2e00126c - GetStartupInfoA
• 0x2e001270 - InterlockedIncrement
• 0x2e001274 - InterlockedDecrement
• 0x2e001278 - QueryPerformanceCounter
• 0x2e00127c - UnhandledExceptionFilter
• 0x2e001280 - IsDebuggerPresent
• 0x2e001284 - GetCPInfo
• 0x2e001288 - GetOEMCP
• 0x2e00128c - LCMapStringA
• 0x2e001290 - LCMapStringW
• 0x2e001294 - InterlockedExchange
• 0x2e001298 - SetFilePointer
• 0x2e00129c - GetConsoleCP
• 0x2e0012a0 - GetConsoleMode
• 0x2e0012a4 - GetLocaleInfoA
• 0x2e0012a8 - SetStdHandle
• 0x2e0012ac - GetStringTypeA
• 0x2e0012b0 - GetStringTypeW
• 0x2e0012b4 - WriteConsoleA