Import table
advapi32.dll
RegCreateKeyExW, LookupAccountNameW, IsValidSid, ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegSetValueExA, RegCloseKey, RegQueryValueExA, RegQueryValueExW, RegOpenKeyExW
dbghelp.dll
ImageNtHeader
kernel32.dll
GetCommandLineW, CreateEventW, CreateSemaphoreA, GetSystemTimeAsFileTime, ReleaseSemaphore, OpenMutexW, PulseEvent, GetCurrentProcessId, WaitForMultipleObjects, GetProcessHeap, HeapFree, LocalFree, HeapAlloc, LoadLibraryA, DuplicateHandle, GetCurrentProcess, CopyFileW, DeleteFileW, FindClose, SetLastError, GetFullPathNameW, FindFirstFileW, lstrcpyW, lstrcatW, FindNextFileW, FreeLibrary, VirtualQuery, GetModuleHandleA, VirtualAlloc, InterlockedCompareExchange, ResumeThread, FlushInstructionCache, GetThreadContext, SetThreadContext, SuspendThread, WideCharToMultiByte, MultiByteToWideChar, lstrlenA, GetModuleFileNameW, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, GetVersionExW, AreFileApisANSI, lstrlenW, SetEndOfFile, FlushFileBuffers, UnlockFile, LockFile, GetFileAttributesA, DeleteFileA, GetFileAttributesW, LoadLibraryW, QueryPerformanceCounter, GetTickCount, GetSystemTime, LockFileEx, GetTempPathA, GetTempPathW, FormatMessageA, FormatMessageW, GetFullPathNameA, GetDiskFreeSpaceA, GetDiskFreeSpaceW, CreateFileA, TerminateProcess, GetLocaleInfoW, GetDateFormatA, GetConsoleMode, GetConsoleCP, GetCurrentThread, OpenEventW, WriteFile, GetLastError, CreateFileW, RemoveVectoredExceptionHandler, InterlockedExchange, VirtualProtect, AddVectoredExceptionHandler, TlsAlloc, WaitForSingleObject, GetCurrentThreadId, SetEvent, CreateEventA, TlsSetValue, TlsGetValue, IsBadReadPtr, IsBadWritePtr, GetModuleHandleW, GetProcAddress, CloseHandle, ReadFile, GetFileSize, SetStdHandle, WriteConsoleW, CompareStringW, SetEnvironmentVariableA, DeviceIoControl, GetTimeFormatA, SetFilePointer, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetTimeZoneInformation, GetEnvironmentStringsW, LocalAlloc, RaiseException, InterlockedIncrement, InterlockedDecrement, GetStringTypeW, EncodePointer, DecodePointer, HeapDestroy, HeapReAlloc, HeapSize, TlsFree, OpenEventA, ResetEvent, SystemTimeToFileTime, SetWaitableTimer, CreateWaitableTimerA, GetUserDefaultLCID, GetStringTypeExA, LCMapStringA, LCMapStringW, GetCommandLineA, RtlUnwind, GetCPInfo, ExitThread, CreateThread, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetACP, GetOEMCP, IsValidCodePage, IsProcessorFeaturePresent, GetStdHandle, ExitProcess, HeapCreate, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, GetStartupInfoW, GetModuleFileNameA, FreeEnvironmentStringsW
ntdll.dll
NtQueryInformationProcess, RtlCreateUserThread, NtAllocateVirtualMemory, NtFreeVirtualMemory, ZwClose
user32.dll
LoadStringA, FindWindowExW, GetWindowThreadProcessId
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory