库 KERNEL32.dll:
• 0x1002309c - OpenProcess
• 0x100230a0 - VirtualAllocEx
• 0x100230a4 - WriteProcessMemory
• 0x100230a8 - FreeLibrary
• 0x100230ac - VirtualFree
• 0x100230b0 - Thread32First
• 0x100230b4 - Thread32Next
• 0x100230b8 - SetLastError
• 0x100230bc - VirtualAlloc
• 0x100230c0 - LoadLibraryA
• 0x100230c4 - OpenThread
• 0x100230c8 - CreateToolhelp32Snapshot
• 0x100230cc - SuspendThread
• 0x100230d0 - ResumeThread
• 0x100230d4 - PeekNamedPipe
• 0x100230d8 - WaitNamedPipeA
• 0x100230dc - SetNamedPipeHandleState
• 0x100230e0 - LocalAlloc
• 0x100230e4 - LocalFree
• 0x100230e8 - GetComputerNameA
• 0x100230ec - Process32First
• 0x100230f0 - TerminateProcess
• 0x100230f4 - Process32Next
• 0x100230f8 - ProcessIdToSessionId
• 0x100230fc - GetFileAttributesA
• 0x10023100 - GetLogicalDrives
• 0x10023104 - SystemTimeToTzSpecificLocalTime
• 0x10023108 - GetFullPathNameA
• 0x1002310c - CreateThread
• 0x10023110 - GetVersionExA
• 0x10023114 - GetModuleHandleA
• 0x10023118 - CreateNamedPipeA
• 0x1002311c - GetProcAddress
• 0x10023120 - ReadFile
• 0x10023124 - GetCurrentThread
• 0x10023128 - ConnectNamedPipe
• 0x1002312c - GetCurrentProcess
• 0x10023130 - CloseHandle
• 0x10023134 - GetFileTime
• 0x10023138 - GetCurrentDirectoryA
• 0x1002313c - CreatePipe
• 0x10023140 - GetCurrentDirectoryW
• 0x10023144 - GetLastError
• 0x10023148 - GetWindowsDirectoryA
• 0x1002314c - SetCurrentDirectoryA
• 0x10023150 - FlushFileBuffers
• 0x10023154 - DisconnectNamedPipe
• 0x10023158 - GetEnvironmentVariableA
• 0x1002315c - CreateProcessA
• 0x10023160 - WriteFile
• 0x10023164 - SetFileTime
• 0x10023168 - WaitForSingleObject
• 0x1002316c - CreateFileA
• 0x10023170 - GetCurrentProcessId
• 0x10023174 - GetLocalTime
• 0x10023178 - Sleep
• 0x1002317c - SetEndOfFile
• 0x10023180 - VirtualQuery
• 0x10023184 - GetModuleFileNameW
• 0x10023188 - GetProcessHeap
• 0x1002318c - SetStdHandle
• 0x10023190 - WriteConsoleW
• 0x10023194 - GetConsoleOutputCP
• 0x10023198 - WriteConsoleA
• 0x1002319c - GetTickCount
• 0x100231a0 - GetStringTypeW
• 0x100231a4 - GetStringTypeA
• 0x100231a8 - LCMapStringW
• 0x100231ac - LCMapStringA
• 0x100231b0 - GetLocaleInfoA
• 0x100231b4 - HeapSize
• 0x100231b8 - DebugBreak
• 0x100231bc - RaiseException
• 0x100231c0 - QueryPerformanceCounter
• 0x100231c4 - GetEnvironmentStringsW
• 0x100231c8 - FreeEnvironmentStringsW
• 0x100231cc - GetEnvironmentStrings
• 0x100231d0 - FreeEnvironmentStringsA
• 0x100231d4 - CreateRemoteThread
• 0x100231d8 - FindNextFileA
• 0x100231dc - FindClose
• 0x100231e0 - FindFirstFileA
• 0x100231e4 - GetStartupInfoA
• 0x100231e8 - FileTimeToSystemTime
• 0x100231ec - SetFilePointer
• 0x100231f0 - GetFileType
• 0x100231f4 - SetHandleCount
• 0x100231f8 - GetConsoleMode
• 0x100231fc - HeapFree
• 0x10023200 - HeapAlloc
• 0x10023204 - GetModuleHandleW
• 0x10023208 - ExitProcess
• 0x1002320c - MultiByteToWideChar
• 0x10023210 - DeleteFileA
• 0x10023214 - CreateDirectoryA
• 0x10023218 - RemoveDirectoryA
• 0x1002321c - GetCurrentThreadId
• 0x10023220 - GetCommandLineA
• 0x10023224 - GetSystemTimeAsFileTime
• 0x10023228 - UnhandledExceptionFilter
• 0x1002322c - SetUnhandledExceptionFilter
• 0x10023230 - IsDebuggerPresent
• 0x10023234 - HeapCreate
• 0x10023238 - HeapDestroy
• 0x1002323c - DeleteCriticalSection
• 0x10023240 - LeaveCriticalSection
• 0x10023244 - EnterCriticalSection
• 0x10023248 - HeapReAlloc
• 0x1002324c - GetStdHandle
• 0x10023250 - GetModuleFileNameA
• 0x10023254 - TlsGetValue
• 0x10023258 - TlsAlloc
• 0x1002325c - TlsSetValue
• 0x10023260 - TlsFree
• 0x10023264 - InterlockedIncrement
• 0x10023268 - InterlockedDecrement
• 0x1002326c - InitializeCriticalSectionAndSpinCount
• 0x10023270 - GetCPInfo
• 0x10023274 - GetACP
• 0x10023278 - GetOEMCP
• 0x1002327c - IsValidCodePage
• 0x10023280 - RtlUnwind
• 0x10023284 - WideCharToMultiByte
• 0x10023288 - GetConsoleCP
库 ADVAPI32.dll:
• 0x10023000 - CryptGenRandom
• 0x10023004 - CryptReleaseContext
• 0x10023008 - CryptAcquireContextA
• 0x1002300c - LogonUserA
• 0x10023010 - CheckTokenMembership
• 0x10023014 - FreeSid
• 0x10023018 - RevertToSelf
• 0x1002301c - AllocateAndInitializeSid
• 0x10023020 - DuplicateTokenEx
• 0x10023024 - LookupAccountSidA
• 0x10023028 - GetTokenInformation
• 0x1002302c - SetSecurityDescriptorDacl
• 0x10023030 - InitializeSecurityDescriptor
• 0x10023034 - GetUserNameA
• 0x10023038 - AdjustTokenPrivileges
• 0x1002303c - ControlService
• 0x10023040 - QueryServiceStatusEx
• 0x10023044 - ImpersonateNamedPipeClient
• 0x10023048 - ImpersonateLoggedOnUser
• 0x1002304c - LookupPrivilegeValueA
• 0x10023050 - OpenThreadToken
• 0x10023054 - OpenProcessToken
• 0x10023058 - OpenServiceA
• 0x1002305c - OpenSCManagerA
• 0x10023060 - QueryServiceStatus
• 0x10023064 - CreateProcessWithTokenW
• 0x10023068 - StartServiceA
• 0x1002306c - CreateServiceA
• 0x10023070 - DeleteService
• 0x10023074 - CreateProcessWithLogonW
• 0x10023078 - CloseServiceHandle
• 0x1002307c - CreateProcessAsUserA