Import table
advapi32.dll
SetServiceStatus, StartServiceCtrlDispatcherW, ControlService, ChangeServiceConfigW, ChangeServiceConfig2W, StartServiceA, OpenServiceW, OpenSCManagerW, DeleteService, CloseServiceHandle, CreateServiceW, RegSetValueExW, RegCloseKey, RegOpenKeyExW, RegDeleteValueW, RegQueryValueExW, RegCreateKeyExW, RegisterServiceCtrlHandlerW, CreateProcessAsUserW, GetTokenInformation, DuplicateTokenEx, QueryServiceConfigW, UnlockServiceDatabase, LockServiceDatabase, QueryServiceStatusEx, StartServiceW
kernel32.dll
CloseHandle, DeleteFileW, GetSystemTimeAsFileTime, GetModuleHandleW, CreateProcessW, FindFirstFileW, SystemTimeToFileTime, WideCharToMultiByte, GetFileAttributesW, MultiByteToWideChar, GetFileSizeEx, FindClose, FindNextFileW, GetSystemTime, GetVersionExA, GetFullPathNameW, SetEvent, RemoveDirectoryW, InterlockedDecrement, FreeLibrary, GetCurrentProcess, LoadLibraryW, GetProcAddress, SetStdHandle, WriteConsoleW, GetTempPathW, CreateFileW, ReadFile, WriteFile, CreateDirectoryW, GetFileSize, GetTempFileNameW, GetLastError, CreateFileA, SetEndOfFile, GetTickCount, GetCurrentProcessId, GetStringTypeA, CreateEventW, WriteConsoleA, GetConsoleOutputCP, GetLocaleInfoW, InitializeCriticalSectionAndSpinCount, GetModuleHandleA, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, QueryPerformanceCounter, GetCommandLineW, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetModuleFileNameW, InterlockedIncrement, InterlockedCompareExchange, InterlockedExchange, Sleep, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, HeapFree, GetProcessHeap, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, LoadLibraryA, RaiseException, RtlUnwind, GetCPInfo, LCMapStringA, LCMapStringW, GetStringTypeW, HeapAlloc, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, HeapSize, ExitProcess, GetACP, GetOEMCP, IsValidCodePage, GetStdHandle, GetModuleFileNameA, SetHandleCount, GetFileType, GetStartupInfoA, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, ResetEvent, TerminateThread, GlobalFree, WTSGetActiveConsoleSessionId, lstrlenA, LocalAlloc, LocalFree, WaitForSingleObject, CopyFileW, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, IsProcessorFeaturePresent, GetVolumeInformationW, HeapDestroy, EncodePointer, DecodePointer, ExitThread, CreateThread, HeapSetInformation, GetStartupInfoW
ole32.dll
CoCreateGuid, CoCreateInstance, CoUninitialize, CoInitializeSecurity, CoInitialize, CoInitializeEx, StringFromGUID2
shell32.dll
SHFileOperationW, SHGetFolderPathW, SHGetSpecialFolderPathW, CommandLineToArgvW
shlwapi.dll
PathFileExistsW, PathAppendW
user32.dll
LoadStringW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
winhttp.dll
WinHttpQueryDataAvailable, WinHttpReadData, WinHttpCloseHandle, WinHttpConnect, WinHttpSendRequest, WinHttpReceiveResponse, WinHttpOpenRequest, WinHttpOpen, WinHttpSetOption, WinHttpAddRequestHeaders, WinHttpSetStatusCallback, WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpQueryHeaders
wtsapi32.dll
WTSQueryUserToken