Import table
advapi32.dll
ControlService, InitializeSecurityDescriptor, RegCloseKey, SetSecurityDescriptorDacl, RegOpenKeyExA, RegNotifyChangeKeyValue, ConvertStringSecurityDescriptorToSecurityDescriptorA, InitializeAcl, AddAccessAllowedAce, AddAce, GetTokenInformation, GetLengthSid, GetAclInformation, CopySid, GetSecurityDescriptorDacl, GetAce, OpenProcessToken, SetServiceStatus, CreateServiceA, DeleteService, QueryServiceStatus, OpenServiceA, OpenSCManagerA, CreateProcessAsUserW, RegisterServiceCtrlHandlerExA, StartServiceCtrlDispatcherA, DuplicateTokenEx, CloseServiceHandle, IsValidSid, EqualSid, LookupAccountSidA, GetSidIdentifierAuthority, GetSidSubAuthorityCount, AdjustTokenPrivileges, GetSidSubAuthority, LookupPrivilegeValueA, AllocateAndInitializeSid, RegSetValueExA, RegQueryValueExA, RegCreateKeyExA, IsValidSecurityDescriptor, GetSecurityDescriptorLength, CryptDestroyHash, CryptAcquireContextA, CryptCreateHash, CryptGetHashParam, CryptHashData, CryptReleaseContext
iphlpapi.dll
GetNetworkParams, GetAdaptersInfo
kernel32.dll
GetSystemTimeAsFileTime, GetACP, GetLocaleInfoA, GetTickCount, GetCurrentProcessId, GetSystemWow64DirectoryA, GetDriveTypeA, GetSystemDirectoryA, GetCurrentDirectoryW, CreateFileW, GetCurrentThreadId, InterlockedDecrement, LoadLibraryA, InterlockedIncrement, GetProcAddress, GetWindowsDirectoryA, WideCharToMultiByte, InterlockedExchange, GetVersionExA, CreateDirectoryA, SetFileAttributesA, GetFileAttributesA, SetLastError, GetCurrentProcess, WTSGetActiveConsoleSessionId, FormatMessageA, CopyFileA, SetConsoleCtrlHandler, SetUnhandledExceptionFilter, GetProcessHeap, HeapFree, HeapAlloc, GetFileSize, CreateFileA, SetEndOfFile, SetFilePointer, OutputDebugStringA, InitializeCriticalSection, DeleteCriticalSection, FlushFileBuffers, ReadFile, EnterCriticalSection, LeaveCriticalSection, WriteFile, OpenMutexA, FreeLibrary, GetModuleFileNameA, SetEvent, Process32First, WaitForMultipleObjects, QueryPerformanceCounter, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, GetLastError, CreateToolhelp32Snapshot, ResetEvent, Sleep, CloseHandle, GetModuleHandleA, SetThreadPriority, CreateMutexA, WaitForSingleObject, OpenProcess, Process32Next, CreateEventA, InterlockedCompareExchange, GetThreadLocale, GetLogicalDriveStringsA
msvcp80.dll
DllMain
msvcr80.dll
DllMain
netapi32.dll
NetShareEnum, NetApiBufferFree
oemlibr.dll
OemLibLoadResourceDLL
ole32.dll
CoUninitialize, CoInitialize
persistr.dll
CreateCrypto, CreatePersist
psapi.dll
EnumProcesses
user32.dll
CloseDesktop, CloseWindowStation, OpenDesktopA, SetProcessWindowStation, GetUserObjectSecurity, SetUserObjectSecurity, OpenWindowStationA, wsprintfA, MessageBoxA, GetSystemMetrics
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
version.dll
GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA
wtsapi32.dll
WTSEnumerateProcessesA, WTSQuerySessionInformationA, WTSFreeMemory, WTSEnumerateSessionsA, WTSQueryUserToken