Advapi32, AdjustTokenPrivileges Advapi32, CryptAcquireContextW Advapi32, CryptDecrypt Advapi32, CryptDestroyKey Advapi32, CryptEncrypt Advapi32, CryptImportKey Advapi32, CryptReleaseContext Advapi32, CryptSetKeyParam advapi32, GetSidSubAuthority advapi32, GetSidSubAuthorityCount Advapi32, GetTokenInformation Advapi32, GetUserNameW Advapi32, ImpersonateSelf advapi32, LookupAccountSidW Advapi32, LookupPrivilegeValueW advapi32, OpenProcessToken advapi32, OpenThreadToken Advapi32, RegCloseKey Advapi32, RegEnumKeyExW Advapi32, RegEnumValueW Advapi32, RegisterServiceCtrlHandlerW Advapi32, RegOpenKeyExW Advapi32, SetServiceStatus cabinet, CloseDecompressor cabinet, CreateDecompressor cabinet, Decompress kernel32, CreateEventW kernel32, CreateFileA kernel32, CreateFileMappingA kernel32, CreateFileMappingW kernel32, CreateFileW kernel32, CreatePipe kernel32, CreatePipe kernel32, CreateProcessW kernel32, CreateRemoteThread kernel32, CreateThread kernel32, CreateToolhelp32Snapshot kernel32, DeviceIoControl kernel32, ExpandEnvironmentStringsW kernel32, FindFirstFileW kernel32, FindNextFileW kernel32, GetComputerNameExW kernel32, GetComputerNameW kernel32, GetFileSizeEx kernel32, GetNativeSystemInfo kernel32, GetPhysicallyInstalledSystemMemory kernel32, GetSystemInfo kernel32, GetThreadContext kernel32, GetThreadPriority kernel32, GetThreadTimes kernel32, GlobalAddAtomA kernel32, GlobalGetAtomNameA kernel32, GlobalMemoryStatusEx kernel32, InitializeProcThreadAttributeList kernel32, IsNativeVhdBoot kernel32, IsWow64Process kernel32, MapViewOfFile kernel32, MapViewOfFile kernel32, MessageBoxA kernel32, Module32FirstW kernel32, Module32NextW kernel32, OpenProcess kernel32, OpenProcessToken kernel32, OpenThread kernel32, PeekNamedPipe kernel32, Process32FirstW kernel32, Process32NextW kernel32, QueryFullProcessImageNameW kernel32, QueryPerformanceCounter kernel32, QueryPerformanceFrequency kernel32, QueueUserAPC kernel32, QueueUserAPC kernel32, ReadFile kernel32, ReadProcessMemory kernel32, SetEvent kernel32, SetProcessMitigationPolicy kernel32, SetThreadContext kernel32, SetThreadPriority kernel32, SetThreadPriorityBoost kernel32, Sleep kernel32, SleepEx kernel32, TerminateProcess kernel32, Thread32First kernel32, Thread32Next kernel32, UpdateProcThreadAttribute kernel32, VirtualAlloc kernel32, VirtualAllocEx kernel32, VirtualAllocExNuma kernel32, VirtualFreeEx kernel32, VirtualProtect kernel32, VirtualProtectEx kernel32, VirtualQueryEx kernel32, WriteProcessMemory Netapi32, DsRoleFreeMemory Netapi32, DsRoleGetPrimaryDomainInformation netapi32, NetGetJoinInformation ntdll, NtAllocateVirtualMemory ntdll, NtCreateFile ntdll, NtGetContextThread ntdll, NtMapViewOfSection ntdll, NtOpenProcess ntdll, NtOpenThread ntdll, NtProtectVirtualMemory ntdll, NtQueryInformationProcess ntdll, NtQuerySystemInformation ntdll, NtQueueApcThreadEx ntdll, NtReadVirtualMemory ntdll, NtResumeThread ntdll, NtSetContextThread ntdll, NtSuspendThread ntdll, NtTestAlert ntdll, NtWriteVirtualMemory ntdll, RtlCreateUserThread ntdll, RtlDecompressBuffer ntdll, RtlDecompressBufferEx ntdll, RtlGetCompressionWorkSpaceSize ntdll, RtlInitUnicodeString ntdll, ZwClose ntdll, ZwCreateSection ntdll, ZwCreateThreadEx ntdll, ZwSetInformationThread ntdll, ZwUnmapViewOfSection ntdll, KiUserApcDispatcher ntdll, KiUserExceptionDispatcher ntdll, LdrFindEntryForAddress ntdll, LdrLoadDll ntdll, LdrOpenImageFileOptionsKey ntdll, LdrResolveDelayLoadedAPI ntdll, NtAddBootEntry ntdll, NtAdjustPrivilegesToken ntdll, NtAlertResumeThread ntdll, NtAllocateVirtualMemory ntdll, NtAllocateVirtualMemoryEx ntdll, NtAlpcConnectPort ntdll, NtAreMappedFilesTheSame ntdll, NtClose ntdll, NtCreateFile ntdll, NtCreateKey ntdll, NtCreateMutant ntdll, NtCreateProcess ntdll, NtCreateProcessEx ntdll, NtCreateSection ntdll, NtCreateThread ntdll, NtCreateThreadEx ntdll, NtCreateUserProcess ntdll, NtDelayExecution ntdll, NtDeleteBootEntry ntdll, NtDeleteFile ntdll, NtDeleteKey ntdll, NtDeleteValueKey ntdll, NtDeviceIoControlFile ntdll, NtDuplicateObject ntdll, NtFreeVirtualMemory ntdll, NtGdiBitBlt ntdll, NtGetContextThread ntdll, NtLoadDriver ntdll, NtMapUserPhysicalPages ntdll, NtMapViewOfSection ntdll, NtMapViewOfSectionEx ntdll, NtModifyBootEntry ntdll, NtOpenCreateFile ntdll, NtOpenFile ntdll, NtOpenKey ntdll, NtOpenKeyEx ntdll, NtOpenProcess ntdll, NtOpenProcessToken ntdll, NtOpenProcessTokenEx ntdll, NtOpenThreadToken ntdll, NtOpenThreadTokenEx ntdll, NtProtectVirtualMemory ntdll, NtQueryAttributesFile ntdll, NtQueryFullAttributesFile ntdll, NtQueryInformationProcess ntdll, NtQueryInformationThread ntdll, NtQueryInformationTokenTokenUser ntdll, NtQuerySystemInformation ntdll, NtQuerySystemInformationEx ntdll, NtQueryVirtualMemory ntdll, NtQueueApcThread ntdll, NtQueueApcThreadEx ntdll, NtQueueApcThreadEx2 ntdll, NtReadVirtualMemory ntdll, NtRenameKey ntdll, NtResumeThread ntdll, NtSetContextThread ntdll, NtSetInformationFile ntdll, NtSetInformationProcess ntdll, NtSetInformationProcessCriticalProcess ntdll, NtSetInformationThread ntdll, NtSetInformationThreadCriticalThread ntdll, NtSetInformationThreadHideFromDebugger ntdll, NtSetInformationThreadImpersonationToken ntdll, NtSetInformationThreadWow64Context ntdll, NtSetInformationVirtualMemory ntdll, NtSetValueKey ntdll, NtSuspendThread ntdll, NtSystemDebugControl ntdll, NtTerminateProcess ntdll, NtTerminateThread ntdll, NtUnmapViewOfSection ntdll, NtUnmapViewOfSectionEx ntdll, NtUserGetAsyncKeyState ntdll, NtUserGetClipboardData ntdll, NtUserSetWindowsHookEx ntdll, NtWriteFile ntdll, NtWriteVirtualMemory ntdll, RegNtCallbackObjectContextCleanup ntdll, RegNtPostCreateKey ntdll, RegNtPostCreateKeyEx ntdll, RegNtPostDeleteKey ntdll, RegNtPostDeleteValueKey ntdll, RegNtPostEnumerateKey ntdll, RegNtPostEnumerateValueKey ntdll, RegNtPostFlushKey ntdll, RegNtPostKeyHandleClose ntdll, RegNtPostLoadKey ntdll, RegNtPostOpenKey ntdll, RegNtPostOpenKeyEx ntdll, RegNtPostQueryKey ntdll, RegNtPostQueryKeyName ntdll, RegNtPostQueryKeySecurity ntdll, RegNtPostQueryMultipleValueKey ntdll, RegNtPostQueryValueKey ntdll, RegNtPostRenameKey ntdll, RegNtPostReplaceKey ntdll, RegNtPostRestoreKey ntdll, RegNtPostSaveKey ntdll, RegNtPostSetInformationKey ntdll, RegNtPostSetKeySecurity ntdll, RegNtPostSetValueKey ntdll, RegNtPostUnLoadKey ntdll, RegNtPreCreateKey ntdll, RegNtPreCreateKeyEx ntdll, RegNtPreDeleteKey ntdll, RegNtPreDeleteValueKey ntdll, RegNtPreEnumerateKey ntdll, RegNtPreEnumerateValueKey ntdll, RegNtPreFlushKey ntdll, RegNtPreKeyHandleClose ntdll, RegNtPreLoadKey ntdll, RegNtPreOpenKey ntdll, RegNtPreOpenKeyEx ntdll, RegNtPreQueryKey ntdll, RegNtPreQueryKeyName ntdll, RegNtPreQueryKeySecurity ntdll, RegNtPreQueryMultipleValueKey ntdll, RegNtPreQueryValueKey ntdll, RegNtPreRenameKey ntdll, RegNtPreReplaceKey ntdll, RegNtPreRestoreKey ntdll, RegNtPreSaveKey ntdll, RegNtPreSetInformationKey ntdll, RegNtPreSetKeySecurity ntdll, RegNtPreSetValueKey ntdll, RegNtPreUnLoadKey ntdll, RtlAddVectoredExceptionHandler ntdll, RtlCreateUserThread ntdll, RtlDosApplyFileIsolationRedirection_Ustr ntdll, RtlGetNativeSystemInformation ntdll, RtlInstallFunctionTableCallback ntdll, ZwAlertResumeThread ntdll, ZwAllocateVirtualMemory ntdll, ZwAllocateVirtualMemoryEx ntdll, ZwAlpcConnectPort ntdll, ZwAreMappedFilesTheSame ntdll, ZwClose ntdll, ZwCreateFile ntdll, ZwCreateKey ntdll, ZwCreateProcess ntdll, ZwCreateProcessEx ntdll, ZwCreateSection ntdll, ZwCreateThread ntdll, ZwCreateThreadEx ntdll, ZwCreateUserProcess ntdll, ZwDeleteFile ntdll, ZwDeleteKey ntdll, ZwDeleteValueKey ntdll, ZwDeviceIoControlFile ntdll, ZwDuplicateObject ntdll, ZwFreeVirtualMemory ntdll, ZwGetContextThread ntdll, ZwLoadDriver ntdll, ZwMapUserPhysicalPages ntdll, ZwMapViewOfSection ntdll, ZwMapViewOfSectionEx ntdll, ZwOpenFile ntdll, ZwOpenKey ntdll, ZwOpenKeyEx ntdll, ZwOpenProcess ntdll, ZwProtectVirtualMemory ntdll, ZwQueryAttributesFile ntdll, ZwQueryFullAttributesFile ntdll, ZwQueryInformationProcess ntdll, ZwQueryInformationThread ntdll, ZwQuerySystemInformation ntdll, ZwQuerySystemInformationEx ntdll, ZwQueryVirtualMemory ntdll, ZwQueueApcThread ntdll, ZwQueueApcThreadEx ntdll, ZwReadVirtualMemory ntdll, ZwRenameKey ntdll, ZwResumeThread ntdll, ZwSetContextThread ntdll, ZwSetInformationFile ntdll, ZwSetInformationProcess ntdll, ZwSetInformationThread ntdll, ZwSetValueKey ntdll, ZwSuspendThread ntdll, ZwTerminateProcess ntdll, ZwTerminateThread ntdll, ZwUnmapViewOfSection ntdll, ZwUnmapViewOfSectionEx ntdll, ZwWriteFile ntdll, ZwWriteVirtualMemory ole32, CLSIDFromString ole32, CoCreateInstance ole32, CoInitializeEx ole32, CoInitializeSecurity ole32, CoSetProxyBlanket ole32, CoUninitialize oleaut32, SysAllocString oleaut32, SysFreeString setupapi, SetupDiEnumDeviceInfo setupapi, SetupDiGetClassDevsW setupapi, SetupDiGetDeviceRegistryPropertyW shell32, CommandLineToArgvW urlmon, ObtainUserAgentString user32, EnumChildWindows user32, EnumPropsExW user32, EnumWindows user32, GetClassNameW user32, GetCursorPos user32, GetParent user32, GetPropW user32, GetWindowThreadProcessId user32, PostMessageW user32, SetPropW wininet, HttpOpenRequestW wininet, HttpQueryInfoW wininet, HttpSendRequestW wininet, InternetCloseHandle wininet, InternetConnectW wininet, InternetCrackUrlW wininet, InternetGetLastResponseInfoW wininet, InternetOpenW wininet, InternetReadFile