Import table
advapi32.dll
IsValidSid, RegSetValueExA, RegQueryValueExA, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, DuplicateTokenEx, CreateProcessAsUserW, ChangeServiceConfigW, ChangeServiceConfig2W, StartServiceW, OpenThreadToken, OpenProcessToken, RegEnumKeyExW, ControlService, DeleteService, CreateServiceW, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, GetLengthSid, CopySid, RegQueryInfoKeyW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, OpenSCManagerW, OpenServiceW, CloseServiceHandle, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegCreateKeyExA, RegOpenKeyExA
kernel32.dll
SetFileAttributesW, GetPrivateProfileIntW, WritePrivateProfileStringW, VirtualQuery, GetModuleFileNameA, EnterCriticalSection, LeaveCriticalSection, GetVersionExW, CreateFileW, DeleteFileW, GetTimeZoneInformation, lstrlenA, TerminateProcess, GetTickCount, GetCommandLineW, CreateWaitableTimerW, SetEnvironmentVariableA, SetEndOfFile, CreateFileA, SetStdHandle, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetLocaleInfoW, IsValidLocale, EnumSystemLocalesA, SetWaitableTimer, WTSGetActiveConsoleSessionId, OpenProcess, ProcessIdToSessionId, CancelWaitableTimer, ExitProcess, LoadLibraryExW, FreeLibrary, SetEvent, InterlockedDecrement, InterlockedIncrement, GetCurrentThreadId, CreateEventW, CreateThread, Sleep, GetCurrentThread, GetCurrentProcess, SetThreadPriority, GetModuleFileNameW, MultiByteToWideChar, lstrcmpiW, GetModuleHandleW, GetProcAddress, WaitForSingleObject, CloseHandle, GetLastError, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, DeleteCriticalSection, InitializeCriticalSection, RaiseException, lstrlenW, WideCharToMultiByte, SleepEx, CreateDirectoryW, GetLocaleInfoA, GetUserDefaultLCID, FlushFileBuffers, ReadFile, SetFilePointer, GetConsoleMode, GetConsoleCP, GetStringTypeA, InitializeCriticalSectionAndSpinCount, QueryPerformanceCounter, GetStartupInfoA, GetFileType, SetHandleCount, GetEnvironmentStringsW, ResumeThread, GetExitCodeThread, DebugBreak, GetModuleHandleA, InterlockedExchange, InterlockedCompareExchange, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, ResetEvent, GetTempPathW, FreeEnvironmentStringsW, IsValidCodePage, GetOEMCP, GetACP, GetStdHandle, WriteFile, HeapCreate, VirtualAlloc, VirtualFree, SetLastError, TlsFree, TlsSetValue, TlsAlloc, TlsGetValue, ExitThread, GetStringTypeW, CompareStringW, CompareStringA, LCMapStringW, LCMapStringA, GetCPInfo, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStartupInfoW, GetSystemTimeAsFileTime, RtlUnwind, LoadLibraryA, IsBadWritePtr, TerminateThread, CreateEventA, GetCurrentProcessId
ole32.dll
CoTaskMemAlloc, CoTaskMemRealloc, CoUninitialize, CoInitialize, CoRevokeClassObject, CoRegisterClassObject, StringFromGUID2, CoCreateInstance, CoInitializeSecurity, CoCreateGuid, StringFromCLSID, CoInitializeEx, CoTaskMemFree
psapi.dll
GetModuleBaseNameW, GetModuleInformation, EnumProcessModules, EnumProcesses, GetProcessImageFileNameW, GetModuleFileNameExA
shell32.dll
SHGetSpecialFolderPathW, ShellExecuteW
shlwapi.dll
PathStripPathW, PathFileExistsW, PathRemoveExtensionW, PathRemoveFileSpecW
urlmon.dll
UrlMkGetSessionOption, ObtainUserAgentString
user32.dll
MessageBoxW, MsgWaitForMultipleObjects, MessageBoxA, IsWindowUnicode, PostThreadMessageA, PeekMessageA, GetMessageA, DispatchMessageA, CharUpperW, PostThreadMessageW, CharNextW, LoadStringW, PeekMessageW, GetMessageW, TranslateMessage, DispatchMessageW
wininet.dll
InternetCheckConnectionA
ws2_32.dll
WSAEnumNetworkEvents, WSAEventSelect