库 KERNEL32.dll:
• 0x72f41068 - GetProcAddress
• 0x72f4106c - LoadLibraryW
• 0x72f41070 - SetLastError
• 0x72f41074 - GetModuleFileNameW
• 0x72f41078 - GetSystemDirectoryW
• 0x72f4107c - DeleteCriticalSection
• 0x72f41080 - InitializeCriticalSectionAndSpinCount
• 0x72f41084 - DisableThreadLibraryCalls
• 0x72f41088 - LocalFree
• 0x72f4108c - WriteFile
• 0x72f41090 - LeaveCriticalSection
• 0x72f41094 - EnterCriticalSection
• 0x72f41098 - GetCurrentProcessId
• 0x72f4109c - CloseHandle
• 0x72f410a0 - DeactivateActCtx
• 0x72f410a4 - LoadLibraryExW
• 0x72f410a8 - ActivateActCtx
• 0x72f410ac - SetEvent
• 0x72f410b0 - CreateThread
• 0x72f410b4 - CreateEventW
• 0x72f410b8 - ReleaseActCtx
• 0x72f410bc - GetFileAttributesW
• 0x72f410c0 - GetFullPathNameW
• 0x72f410c4 - InterlockedIncrement
• 0x72f410c8 - InterlockedDecrement
• 0x72f410cc - LocalAlloc
• 0x72f410d0 - GetFileType
• 0x72f410d4 - GetLastError
• 0x72f410d8 - lstrcmpiW
• 0x72f410dc - VirtualFree
• 0x72f410e0 - VirtualAlloc
• 0x72f410e4 - GetNativeSystemInfo
• 0x72f410e8 - LoadLibraryA
• 0x72f410ec - GetVersionExW
• 0x72f410f0 - lstrcmpW
• 0x72f410f4 - GetTickCount
• 0x72f410f8 - CreateActCtxW
• 0x72f410fc - WaitForSingleObject
• 0x72f41100 - InterlockedCompareExchange
• 0x72f41104 - Sleep
• 0x72f41108 - ReleaseMutex
• 0x72f4110c - FreeLibrary
• 0x72f41110 - GetSystemWindowsDirectoryW
• 0x72f41114 - CreateMutexW
• 0x72f41118 - ProcessIdToSessionId
• 0x72f4111c - OpenEventW
• 0x72f41120 - lstrlenW
• 0x72f41124 - MultiByteToWideChar
• 0x72f41128 - WideCharToMultiByte
• 0x72f4112c - GetModuleHandleW
• 0x72f41130 - FormatMessageW
• 0x72f41134 - SearchPathW
• 0x72f41138 - GetCurrentDirectoryW
• 0x72f4113c - FindClose
• 0x72f41140 - FindFirstFileW
• 0x72f41144 - ResetEvent
• 0x72f41148 - GlobalFree
• 0x72f4114c - GlobalAlloc
• 0x72f41150 - DnsHostnameToComputerNameW
• 0x72f41154 - GetTempFileNameW
• 0x72f41158 - GetTempPathW
• 0x72f4115c - GetFileSize
• 0x72f41160 - SetEndOfFile
• 0x72f41164 - DelayLoadFailureHook
• 0x72f41168 - SetFilePointer
• 0x72f4116c - DeleteFileW
• 0x72f41170 - HeapDestroy
• 0x72f41174 - HeapAlloc
• 0x72f41178 - HeapCreate
• 0x72f4117c - HeapFree
• 0x72f41180 - QueryPerformanceCounter
• 0x72f41184 - GetCurrentThreadId
• 0x72f41188 - GetSystemTimeAsFileTime
• 0x72f4118c - TerminateProcess
• 0x72f41190 - GetCurrentProcess
• 0x72f41194 - UnhandledExceptionFilter
• 0x72f41198 - SetUnhandledExceptionFilter
• 0x72f4119c - HeapSetInformation
• 0x72f411a0 - MapViewOfFile
• 0x72f411a4 - UnmapViewOfFile
• 0x72f411a8 - CreateFileMappingW
• 0x72f411ac - CreateDirectoryW
• 0x72f411b0 - GetSystemInfo
• 0x72f411b4 - CopyFileW
• 0x72f411b8 - CreateProcessW
• 0x72f411bc - CreateFileW
• 0x72f411c0 - ReadFile
库 ADVAPI32.dll:
• 0x72f411f0 - RegCloseKey
• 0x72f411f4 - DeregisterEventSource
• 0x72f411f8 - ReportEventW
• 0x72f411fc - RegisterEventSourceW
• 0x72f41200 - OpenSCManagerW
• 0x72f41204 - OpenServiceW
• 0x72f41208 - QueryServiceConfigW
• 0x72f4120c - CloseServiceHandle
• 0x72f41210 - RegOpenCurrentUser
• 0x72f41214 - RegEnumValueW
• 0x72f41218 - RegEnumKeyExW
• 0x72f4121c - RegDeleteKeyW
• 0x72f41220 - RegOpenKeyExW
• 0x72f41224 - IsValidSecurityDescriptor
• 0x72f41228 - InitializeSecurityDescriptor
• 0x72f4122c - GetSecurityDescriptorOwner
• 0x72f41230 - SetSecurityDescriptorOwner
• 0x72f41234 - GetSecurityDescriptorGroup
• 0x72f41238 - SetSecurityDescriptorGroup
• 0x72f4123c - GetSecurityDescriptorDacl
• 0x72f41240 - SetSecurityDescriptorDacl
• 0x72f41244 - GetSecurityDescriptorSacl
• 0x72f41248 - SetSecurityDescriptorSacl
• 0x72f4124c - GetSecurityDescriptorLength
• 0x72f41250 - MakeSelfRelativeSD
• 0x72f41254 - RegQueryValueExW
• 0x72f41258 - RegDeleteValueW
• 0x72f4125c - RegCreateKeyExW
• 0x72f41260 - RegSetValueExW
库 USER32.dll:
• 0x72f41268 - GetDesktopWindow
• 0x72f4126c - GetWindowLongW
• 0x72f41270 - EndDialog
• 0x72f41274 - BringWindowToTop
• 0x72f41278 - SetWindowLongW
• 0x72f4127c - SendDlgItemMessageW
• 0x72f41280 - GetDlgItemTextW
• 0x72f41284 - MessageBoxW
• 0x72f41288 - GetForegroundWindow
• 0x72f4128c - SendNotifyMessageW
• 0x72f41290 - AllowSetForegroundWindow
• 0x72f41294 - IsWindow
• 0x72f41298 - GetFocus
• 0x72f4129c - GetMessageW
• 0x72f412a0 - LoadStringW
• 0x72f412a4 - GetProcessWindowStation
• 0x72f412a8 - GetUserObjectInformationW
• 0x72f412ac - FindWindowW
• 0x72f412b0 - DialogBoxParamW
• 0x72f412b4 - PostMessageW
• 0x72f412b8 - GetGUIThreadInfo
• 0x72f412bc - GetParent
• 0x72f412c0 - WinHelpW
• 0x72f412c4 - GetWindow
• 0x72f412c8 - GetLastActivePopup
• 0x72f412cc - EnableWindow
• 0x72f412d0 - SetFocus
• 0x72f412d4 - SetForegroundWindow
• 0x72f412d8 - PeekMessageW
• 0x72f412dc - DispatchMessageW
• 0x72f412e0 - TranslateMessage
• 0x72f412e4 - MsgWaitForMultipleObjects