库 KERNEL32.dll:
• 0x10013090 - FindNextFileA
• 0x10013094 - LocalReAlloc
• 0x10013098 - FindFirstFileA
• 0x1001309c - LocalAlloc
• 0x100130a0 - RemoveDirectoryA
• 0x100130a4 - GetFileSize
• 0x100130a8 - CreateFileA
• 0x100130ac - ReadFile
• 0x100130b0 - SetFilePointer
• 0x100130b4 - WriteFile
• 0x100130b8 - MoveFileA
• 0x100130bc - lstrcatA
• 0x100130c0 - GetSystemDirectoryA
• 0x100130c4 - CreateProcessA
• 0x100130c8 - ExitProcess
• 0x100130cc - Process32Next
• 0x100130d0 - lstrcmpiA
• 0x100130d4 - Process32First
• 0x100130d8 - CreateToolhelp32Snapshot
• 0x100130dc - HeapFree
• 0x100130e0 - MapViewOfFile
• 0x100130e4 - CreateFileMappingA
• 0x100130e8 - UnmapViewOfFile
• 0x100130ec - GetLogicalDriveStringsA
• 0x100130f0 - GlobalFree
• 0x100130f4 - GlobalUnlock
• 0x100130f8 - GlobalLock
• 0x100130fc - GlobalAlloc
• 0x10013100 - GlobalSize
• 0x10013104 - GetStartupInfoA
• 0x10013108 - WaitForMultipleObjects
• 0x1001310c - LocalSize
• 0x10013110 - TerminateProcess
• 0x10013114 - OpenProcess
• 0x10013118 - GetCurrentThreadId
• 0x1001311c - GlobalMemoryStatus
• 0x10013120 - GetSystemInfo
• 0x10013124 - GetComputerNameA
• 0x10013128 - LocalFree
• 0x1001312c - OpenEventA
• 0x10013130 - SetErrorMode
• 0x10013134 - GetCurrentProcess
• 0x10013138 - GetWindowsDirectoryA
• 0x1001313c - SetFileAttributesA
• 0x10013140 - CopyFileA
• 0x10013144 - ExpandEnvironmentStringsA
• 0x10013148 - GetModuleFileNameA
• 0x1001314c - GetVolumeInformationA
• 0x10013150 - GetDiskFreeSpaceExA
• 0x10013154 - GetDriveTypeA
• 0x10013158 - lstrlenA
• 0x1001315c - lstrcpyA
• 0x10013160 - GetFileAttributesA
• 0x10013164 - CreateDirectoryA
• 0x10013168 - DeleteFileA
• 0x1001316c - GetProcessHeap
• 0x10013170 - HeapAlloc
• 0x10013174 - GetCurrentProcessId
• 0x10013178 - GetLocalTime
• 0x1001317c - GetTickCount
• 0x10013180 - CancelIo
• 0x10013184 - InterlockedExchange
• 0x10013188 - ResetEvent
• 0x1001318c - GetLastError
• 0x10013190 - VirtualAlloc
• 0x10013194 - EnterCriticalSection
• 0x10013198 - LeaveCriticalSection
• 0x1001319c - VirtualFree
• 0x100131a0 - DeleteCriticalSection
• 0x100131a4 - CreateThread
• 0x100131a8 - ResumeThread
• 0x100131ac - SetEvent
• 0x100131b0 - WaitForSingleObject
• 0x100131b4 - GetProcAddress
• 0x100131b8 - Sleep
• 0x100131bc - TerminateThread
• 0x100131c0 - GetVersionExA
• 0x100131c4 - FindClose
• 0x100131c8 - CloseHandle
• 0x100131cc - FreeLibrary
• 0x100131d0 - LoadLibraryA
• 0x100131d4 - GetModuleHandleA
• 0x100131d8 - CreateEventA
库 USER32.dll:
• 0x10013288 - LoadMenuA
• 0x1001328c - RegisterClassA
• 0x10013290 - LoadIconA
• 0x10013294 - CreateWindowExA
• 0x10013298 - CloseWindow
• 0x1001329c - IsWindow
• 0x100132a0 - PostMessageA
• 0x100132a4 - OpenDesktopA
• 0x100132a8 - GetThreadDesktop
• 0x100132ac - GetUserObjectInformationA
• 0x100132b0 - OpenInputDesktop
• 0x100132b4 - SetThreadDesktop
• 0x100132b8 - CloseDesktop
• 0x100132bc - IsWindowVisible
• 0x100132c0 - ExitWindowsEx
• 0x100132c4 - GetCursorPos
• 0x100132c8 - GetCursorInfo
• 0x100132cc - DestroyCursor
• 0x100132d0 - ReleaseDC
• 0x100132d4 - GetDesktopWindow
• 0x100132d8 - GetDC
• 0x100132dc - SetRect
• 0x100132e0 - GetSystemMetrics
• 0x100132e4 - GetClipboardData
• 0x100132e8 - OpenClipboard
• 0x100132ec - EmptyClipboard
• 0x100132f0 - SetClipboardData
• 0x100132f4 - CloseClipboard
• 0x100132f8 - mouse_event
• 0x100132fc - SetCursorPos
• 0x10013300 - WindowFromPoint
• 0x10013304 - SetCapture
• 0x10013308 - DispatchMessageA
• 0x1001330c - TranslateMessage
• 0x10013310 - GetMessageA
• 0x10013314 - CharNextA
• 0x10013318 - wsprintfA
• 0x1001331c - GetWindowTextA
• 0x10013320 - MessageBoxA
• 0x10013324 - LoadCursorA
• 0x10013328 - BlockInput
• 0x1001332c - SendMessageA
• 0x10013330 - keybd_event
• 0x10013334 - MapVirtualKeyA
• 0x10013338 - GetWindowThreadProcessId
库 GDI32.dll:
• 0x10013088 - GetStockObject
库 ADVAPI32.dll:
• 0x10013000 - OpenProcessToken
• 0x10013004 - RegDeleteKeyA
• 0x10013008 - RegRestoreKeyA
• 0x1001300c - RegSaveKeyA
• 0x10013010 - RegCloseKey
• 0x10013014 - RegQueryValueExA
• 0x10013018 - RegOpenKeyExA
• 0x1001301c - CloseEventLog
• 0x10013020 - ClearEventLogA
• 0x10013024 - OpenEventLogA
• 0x10013028 - RegSetValueExA
• 0x1001302c - RegCreateKeyExA
• 0x10013030 - CloseServiceHandle
• 0x10013034 - DeleteService
• 0x10013038 - OpenServiceA
• 0x1001303c - OpenSCManagerA
• 0x10013040 - FreeSid
• 0x10013044 - SetSecurityDescriptorDacl
• 0x10013048 - AddAccessAllowedAce
• 0x1001304c - InitializeAcl
• 0x10013050 - GetLengthSid
• 0x10013054 - AllocateAndInitializeSid
• 0x10013058 - InitializeSecurityDescriptor
• 0x1001305c - RegOpenKeyA
• 0x10013060 - SetServiceStatus
• 0x10013064 - RegisterServiceCtrlHandlerA
• 0x10013068 - UnlockServiceDatabase
• 0x1001306c - ChangeServiceConfig2A
• 0x10013070 - LockServiceDatabase
• 0x10013074 - CreateServiceA
• 0x10013078 - StartServiceA
• 0x1001307c - AdjustTokenPrivileges
• 0x10013080 - LookupPrivilegeValueA
库 SHELL32.dll:
• 0x10013280 - SHGetSpecialFolderPathA
库 MSVCRT.dll:
• 0x1001320c - sprintf
• 0x10013210 - strncpy
• 0x10013214 - free
• 0x10013218 - malloc
• 0x1001321c - _except_handler3
• 0x10013220 - strrchr
• 0x10013224 - _beginthreadex
• 0x10013228 - atoi
• 0x1001322c - _stricmp
• 0x10013230 - _access
• 0x10013234 - srand
• 0x10013238 - calloc
• 0x1001323c - ??1type_info@@UAE@XZ
• 0x10013240 - _initterm
• 0x10013244 - _adjust_fdiv
• 0x10013248 - rand
• 0x1001324c - _CxxThrowException
• 0x10013250 - strstr
• 0x10013254 - _ftol
• 0x10013258 - ??2@YAPAXI@Z
• 0x1001325c - ??3@YAXPAX@Z
• 0x10013260 - puts
• 0x10013264 - __CxxFrameHandler
• 0x10013268 - memmove
• 0x1001326c - putchar
• 0x10013270 - wcstombs
• 0x10013274 - _strrev
• 0x10013278 - ceil
库 WS2_32.dll:
• 0x10013340 - sendto
• 0x10013344 - WSASocketA
• 0x10013348 - htonl
• 0x1001334c - getsockname
• 0x10013350 - inet_addr
• 0x10013354 - send
• 0x10013358 - closesocket
• 0x1001335c - select
• 0x10013360 - recv
• 0x10013364 - socket
• 0x10013368 - gethostbyname
• 0x1001336c - htons
• 0x10013370 - setsockopt
• 0x10013374 - WSAIoctl
• 0x10013378 - WSACleanup
• 0x1001337c - WSAStartup
• 0x10013380 - connect
库 MSVCP60.dll:
• 0x100131e0 - ?npos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@2IB
• 0x100131e4 - ?_Xran@std@@YAXXZ
• 0x100131e8 - ?_Split@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEXXZ
• 0x100131ec - ?_Eos@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEXI@Z
• 0x100131f0 - ?_Refcnt@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEAAEPBD@Z
• 0x100131f4 - ?_Grow@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAE_NI_N@Z
• 0x100131f8 - ?assign@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAEAAV12@PBDI@Z
• 0x100131fc - ??1?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@QAE@XZ
• 0x10013200 - ?_C@?1??_Nullstr@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@CAPBDXZ@4DB
• 0x10013204 - ?_Tidy@?$basic_string@DU?$char_traits@D@std@@V?$allocator@D@2@@std@@AAEX_N@Z