Import table
advapi32.dll
LookupAccountNameW, ConvertSidToStringSidW, LsaNtStatusToWinError, GetTokenInformation, GetSidIdentifierAuthority, RegEnumValueW, GetSidSubAuthorityCount, RegisterServiceCtrlHandlerExW, SetNamedSecurityInfoW, ConvertStringSecurityDescriptorToSecurityDescriptorW, CreateServiceW, ChangeServiceConfig2W, ImpersonateLoggedOnUser, RegOpenCurrentUser, RevertToSelf, DuplicateTokenEx, CreateProcessAsUserW, StartServiceW, QueryServiceStatus, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, CopySid, IsValidSid, GetLengthSid, RegEnumKeyExW, InitializeSecurityDescriptor, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, MakeAbsoluteSD, GetSecurityDescriptorControl, GetAclInformation, InitializeAcl, AddAce, RegQueryInfoKeyW, RegSetValueExW, RegDeleteValueW, ControlService, DeleteService, OpenSCManagerW, OpenServiceW, CloseServiceHandle, RegDeleteKeyW, RegCreateKeyExW, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, StartServiceCtrlDispatcherW, RegQueryValueExW, RegCloseKey, RegOpenKeyExW, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource, CryptReleaseContext, CryptDestroyHash, CryptDestroyKey, CryptAcquireContextW, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptDeriveKey, CryptEncrypt, CryptDecrypt, GetUserNameW, SetTokenInformation, SaferCloseLevel, SaferComputeTokenFromLevel, SaferCreateLevel
kernel32.dll
DllMain
ole32.dll
StringFromGUID2, OleRun, CoCreateGuid, CoTaskMemFree, CoUninitialize, CoInitializeEx, CoCreateFreeThreadedMarshaler, CoCreateInstance, CoTaskMemRealloc, CoTaskMemAlloc, IIDFromString, StringFromIID, CoInitializeSecurity, CoAddRefServerProcess, CoReleaseServerProcess, CoResumeClassObjects, CoRegisterClassObject, CoRevokeClassObject, CoSuspendClassObjects
psapi.dll
EnumProcesses
secur32.dll
LsaGetLogonSessionData, LsaEnumerateLogonSessions, LsaFreeReturnBuffer
sensapi.dll
IsNetworkAlive
shell32.dll
ShellExecuteW, SHGetFolderPathA, SHGetFolderPathW, SHGetSpecialFolderPathW, SHFileOperationW, ShellExecuteExW
shlwapi.dll
PathRemoveFileSpecW, PathFileExistsW
user32.dll
PostThreadMessageW, LoadStringW, PostMessageW, GetWindowThreadProcessId, CharNextW, CharUpperW, MessageBoxW, EnumWindows, PeekMessageW, DispatchMessageW, TranslateMessage, GetMessageW, wsprintfW, UnregisterClassA, KillTimer, SetTimer, CallWindowProcW, GetWindowLongW, CreateWindowExW, RegisterClassExW, DefWindowProcW, DestroyWindow, LoadCursorW, GetClassInfoExW, SetWindowLongW, GetGUIThreadInfo
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
wininet.dll
InternetGetConnectedState
ws2_32.dll
getaddrinfo, WSAIoctl, freeaddrinfo
wtsapi32.dll
WTSFreeMemory, WTSEnumerateSessionsW, WTSQueryUserToken, WTSQuerySessionInformationW