Import table
advapi32.dll
OpenProcessToken, ImpersonateSelf, DuplicateTokenEx, GetUserNameW, SetSecurityDescriptorDacl, ImpersonateLoggedOnUser, CreateProcessAsUserW, RevertToSelf, RegNotifyChangeKeyValue, ChangeServiceConfigW, ChangeServiceConfig2W, OpenThreadToken, CreateServiceW, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, IsValidSid, GetLengthSid, CopySid, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, RegEnumKeyExW, ControlService, DeleteService, RegQueryInfoKeyW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, OpenSCManagerW, OpenServiceW, CloseServiceHandle, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource
kernel32.dll
OpenProcess, GetCurrentProcessId, MoveFileW, DeleteFileW, GetLocalTime, SuspendThread, ResumeThread, ResetEvent, CreateProcessW, WideCharToMultiByte, GetVersionExW, CreateMutexW, ReleaseMutex, lstrlenA, LocalFree, WriteFile, ExitProcess, HeapDestroy, HeapCreate, HeapReAlloc, VirtualFree, GetStartupInfoW, GetSystemTimeAsFileTime, WTSGetActiveConsoleSessionId, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, RtlUnwind, HeapFree, HeapAlloc, GetModuleFileNameA, TlsGetValue, TlsAlloc, IsProcessorFeaturePresent, InterlockedCompareExchange, SetEnvironmentVariableA, CompareStringW, CompareStringA, CreateFileA, GetProcessHeap, SetEndOfFile, ReadFile, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, CreateFileW, FlushFileBuffers, SetStdHandle, GetExitCodeThread, GetTickCount, GlobalAlloc, GlobalLock, GlobalHandle, GlobalFree, WaitForMultipleObjects, GetPrivateProfileSectionW, GetPrivateProfileStringW, FindResourceExW, lstrcpyW, SetEvent, InterlockedDecrement, InterlockedIncrement, SetLastError, GetCurrentThreadId, CreateEventW, CreateThread, Sleep, GetCurrentThread, GetCurrentProcess, FlushInstructionCache, WaitForSingleObject, CloseHandle, LockResource, DeleteCriticalSection, InitializeCriticalSection, lstrlenW, LeaveCriticalSection, EnterCriticalSection, GetCommandLineW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, FreeLibrary, GetModuleFileNameW, lstrcmpiW, GetModuleHandleW, GetProcAddress, GetLastError, RaiseException, GetFileAttributesW, TlsSetValue, TlsFree, HeapSize, GetLocaleInfoA, GetStringTypeW, GetCPInfo, GetStringTypeA, LCMapStringA, GetConsoleMode, GetConsoleCP, LoadLibraryA, InterlockedExchange, GetACP, GetOEMCP, IsValidCodePage, LCMapStringW, GetModuleHandleA, SetHandleCount, GetFileType, GetStartupInfoA, SetFilePointer, GetTimeZoneInformation, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, InitializeCriticalSectionAndSpinCount, GetStdHandle
ole32.dll
CoTaskMemAlloc, CoTaskMemRealloc, CoUninitialize, CoInitialize, CoTaskMemFree, StringFromGUID2, CoRevokeClassObject, CoRegisterClassObject, CoInitializeEx, OleRun, CoCreateGuid, CoInitializeSecurity, CoCreateInstance
psapi.dll
EnumProcessModules, GetModuleBaseNameW, EnumProcesses
rpcrt4.dll
NdrStubCall2, RpcStringFreeW, UuidToStringW, NdrClientCall2, NdrCStdStubBuffer2_Release, NdrOleAllocate, NdrOleFree, IUnknown_QueryInterface_Proxy, IUnknown_AddRef_Proxy, IUnknown_Release_Proxy, NdrStubForwardingFunction
shell32.dll
SHGetSpecialFolderPathW, ShellExecuteW
user32.dll
SetCursor, WaitForInputIdle, PeekMessageW, PostMessageW, GetWindowLongW, CallWindowProcW, DefWindowProcW, UnregisterClassA, RegisterClassExW, LoadCursorW, GetClassInfoExW, SetWindowLongW, DestroyWindow, MessageBoxW, CharUpperW, CharNextW, LoadStringW, PostThreadMessageW, GetMessageW, DispatchMessageW, TranslateMessage, CreateWindowExW
userenv.dll
LoadUserProfileW, UnloadUserProfile, CreateEnvironmentBlock, DestroyEnvironmentBlock
winspool.drv
FindFirstPrinterChangeNotification, OpenPrinterW, FindNextPrinterChangeNotification, FindClosePrinterChangeNotification, GetPrinterDataW, EnumPrintersW, DeletePrinterDataW, XcvDataW, GetPrinterW, DeviceCapabilitiesW, EnumJobsW, ClosePrinter
wtsapi32.dll
WTSQueryUserToken