Import table
advapi32.dll
StartServiceCtrlDispatcherA, RegQueryValueExA, RegisterEventSourceA, ReportEventA, InitializeSecurityDescriptor, OpenProcessToken, CreateProcessAsUserA, CloseServiceHandle, CreateServiceA, OpenSCManagerA, DeleteService, OpenServiceA, SetServiceStatus, RegisterServiceCtrlHandlerExA, RegCloseKey, RegSetValueExA, RegCreateKeyExA, RegDeleteValueA, RegGetValueA, RegOpenKeyExA, RegDeleteKeyA, RegOpenCurrentUser, SetSecurityDescriptorDacl, RevertToSelf, ImpersonateLoggedOnUser, RegSetValueExW, RegGetValueW
kernel32.dll
CompareStringA, CompareStringW, SetEnvironmentVariableA, GetCommandLineA, GetLocaleInfoW, GetProcessHeap, SetEndOfFile, GetTimeZoneInformation, VirtualQuery, GetSystemInfo, VirtualProtect, RaiseException, LoadLibraryA, InterlockedExchange, FreeLibrary, SetConsoleCtrlHandler, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetModuleHandleW, InitializeCriticalSection, IsValidCodePage, IsValidLocale, EnumSystemLocalesA, lstrcmpiA, WaitForSingleObject, MapViewOfFile, CreateFileMappingA, OpenProcess, GetLastError, GetModuleFileNameA, WTSGetActiveConsoleSessionId, OutputDebugStringA, GetLocalTime, CloseHandle, Sleep, GetVersionExA, GetSystemDirectoryA, CreateProcessA, CreateMutexA, OpenMutexA, ReleaseMutex, CreateEventA, OpenEventA, WaitForMultipleObjects, SetEvent, ResetEvent, CreateThread, SetThreadPriority, CreateNamedPipeA, ConnectNamedPipe, DisconnectNamedPipe, ReadFile, WriteFile, FlushFileBuffers, CreateFileA, LocalFree, HeapAlloc, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, HeapFree, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, GetProcAddress, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, GetCurrentThread, EnterCriticalSection, LeaveCriticalSection, RtlUnwind, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, DeleteCriticalSection, FatalAppExitA, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, ExitProcess, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, VirtualAlloc, HeapReAlloc, SetFilePointer, LCMapStringA, MultiByteToWideChar, LCMapStringW, GetStringTypeA, GetStringTypeW, GetTimeFormatA, GetDateFormatA, GetUserDefaultLCID, GetLocaleInfoA, ReadConsoleW, HeapSize, LoadLibraryExA, InitializeCriticalSectionAndSpinCount, IsProcessorFeaturePresent, LoadLibraryExW
powrprof.dll
PowerGetActiveScheme, PowerSetActiveScheme, PowerWriteACValueIndex, PowerWriteDCValueIndex, PowerEnumerate, PowerSettingAccessCheck, PowerReadACValueIndex, PowerReadDCValueIndex
psapi.dll
GetModuleBaseNameA, EnumProcessModules
user32.dll
UnregisterDeviceNotification, PostMessageA, RegisterDeviceNotificationA, PostThreadMessageA, RegisterPowerSettingNotification, UnregisterPowerSettingNotification, SystemParametersInfoA
userenv.dll
LoadUserProfileA, UnloadUserProfile
wtsapi32.dll
WTSEnumerateProcessesA, WTSQueryUserToken, WTSQuerySessionInformationA, WTSFreeMemory