Import table
advapi32.dll
GetSidSubAuthority, SetTokenInformation, CreatePrivateObjectSecurity, DestroyPrivateObjectSecurity, ImpersonateAnonymousToken, CryptCreateHash, CryptDeriveKey, CryptSetProvParam, CryptHashData, CryptDestroyHash, CryptEncrypt, MapGenericMask, GetSecurityDescriptorDacl, IsValidAcl, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, IsValidSecurityDescriptor, LookupAccountSidW, ConvertStringSidToSidW, LookupAccountNameW, ConvertSidToStringSidW, GetUserNameW, CryptImportKey, CryptGetUserKey, CryptDecrypt, CryptDuplicateKey, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerExW, ControlService, DeleteService, CreateServiceW, ChangeServiceConfig2W, RegEnumKeyW, SetServiceStatus, SetSecurityInfo, ReportEventW, GetSidLengthRequired, InitializeSid, RegQueryInfoKeyW, RegDeleteValueW, OpenThreadToken, OpenProcessToken, SetSecurityDescriptorDacl, RegEnumKeyExW, CryptGetProvParam, CryptGenKey, CryptAcquireContextW, CryptReleaseContext, CryptDestroyKey, AddAccessAllowedAceEx, ImpersonateSelf, RevertToSelf, SetThreadToken, EqualSid, CloseEventLog, DeregisterEventSource, OpenEventLogW, RegOpenKeyExA, RegQueryValueExA, RegEnumKeyA, RegEnumValueW, InitializeAcl, AddAccessAllowedAce, GetAclInformation, GetAce, AddAce, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, IsValidSid, GetLengthSid, CopySid, RegSetValueExW, RegDeleteKeyW, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, QueryServiceStatus, CloseServiceHandle, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey
crypt32.dll
CryptEncodeObject, CryptVerifyCertificateSignature, CryptExportPublicKeyInfo, CryptSignCertificate, CryptDecodeObject
dnsapi.dll
DnsQueryConfig
kernel32.dll
TlsAlloc, TlsGetValue, GetStartupInfoA, GetProcessHeap, GetCommandLineA, HeapReAlloc, VirtualQuery, GetSystemInfo, GetSystemDirectoryW, GetSystemTimeAsFileTime, GetCommandLineW, ExitProcess, ReadFile, WideCharToMultiByte, IsDebuggerPresent, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, SetLastError, CreateFileW, GetFileSize, GetComputerNameA, FormatMessageW, lstrlenA, GetModuleFileNameA, InterlockedExchange, CreateDirectoryW, FindFirstFileW, FindClose, lstrcmpiW, GetCurrentThread, SetFilePointer, GetCurrentThreadId, GetCurrentProcess, GetModuleFileNameW, GetModuleHandleW, TlsSetValue, CreateMutexW, GetLocalTime, WriteFile, ProcessIdToSessionId, GetVersionExA, GetCurrentProcessId, RaiseException, lstrlenW, MultiByteToWideChar, QueueUserWorkItem, ResetEvent, ChangeTimerQueueTimer, InterlockedDecrement, InterlockedIncrement, GetModuleHandleA, CreateEventW, CreateTimerQueueTimer, GetTickCount, Sleep, GetComputerNameExW, GetCPInfo, DeleteTimerQueueTimer, SetEvent, CloseHandle, FreeLibrary, GetVersionExW, LoadLibraryW, GetProcAddress, LocalAlloc, GetLastError, LocalFree, DeleteCriticalSection, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, VirtualProtect, HeapFree, ReleaseMutex, TlsFree, LoadLibraryA, VirtualFree, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, GetStringTypeW, GetStringTypeA, QueryPerformanceCounter, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, HeapSize, GetStdHandle, HeapCreate, HeapDestroy, HeapAlloc, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, RtlUnwind, GetThreadLocale, GetLocaleInfoA, GetACP, GetOEMCP, LCMapStringA, LCMapStringW, WaitForSingleObject
netapi32.dll
NetUserGetInfo, NetApiBufferFree
ole32.dll
CoSetProxyBlanket, CoCreateInstance, CoRevokeClassObject, StringFromCLSID, CoTaskMemFree, CoRegisterClassObject, StringFromGUID2, CoTaskMemAlloc, CoTaskMemRealloc, CoCreateGuid, CoDisconnectObject, CoUninitialize, CoFreeUnusedLibraries, CoInitializeSecurity, CoInitializeEx, CoRevertToSelf, CoImpersonateClient, CLSIDFromString, OleRun
rpcrt4.dll
RpcImpersonateClient, RpcRevertToSelf
shlwapi.dll
PathAppendW
user32.dll
UnregisterClassA, CharNextW, CloseWindowStation, CloseDesktop, OpenWindowStationW, GetProcessWindowStation, SetProcessWindowStation, GetThreadDesktop, SetThreadDesktop, GetMessageW, DispatchMessageW, PostThreadMessageW, wsprintfW, LoadStringW, MessageBoxW, OpenDesktopW