Import table
advapi32.dll
SetSecurityDescriptorDacl, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptDeriveKey, CryptEncrypt, CryptDecrypt, CryptDestroyHash, CryptDestroyKey, CryptReleaseContext, ReportEventW, DeregisterEventSource, RegisterEventSourceW, ConvertStringSecurityDescriptorToSecurityDescriptorW, ConvertSidToStringSidW, RegGetKeySecurity, GetFileSecurityW, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorSacl, SetSecurityDescriptorSacl, LsaOpenPolicy, LsaAddAccountRights, LsaNtStatusToWinError, CryptVerifySignatureW, CryptImportKey, LogonUserW, CreateProcessAsUserW, DuplicateTokenEx, CreateServiceW, ChangeServiceConfig2W, ControlService, DeleteService, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, SetServiceStatus, OpenSCManagerW, OpenServiceW, CloseServiceHandle, RevertToSelf, LsaClose, RegSetKeySecurity, SetFileSecurityW, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, InitializeAcl, InitializeSecurityDescriptor, MakeAbsoluteSD, RegQueryValueExW, IsValidSecurityDescriptor, MakeSelfRelativeSD, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, AddAccessDeniedAce, GetAce, AddAccessAllowedAce, GetLengthSid, GetAclInformation, IsValidAcl, GetSecurityDescriptorDacl, DeleteAce, EqualSid, LookupAccountNameW, FreeSid, AllocateAndInitializeSid, RegConnectRegistryW, RegEnumKeyW, AdjustTokenPrivileges, LookupPrivilegeValueW, OpenProcessToken, AddAce, ConvertSecurityDescriptorToStringSecurityDescriptorW, GetSecurityDescriptorControl, SetSecurityDescriptorControl, SetThreadToken, AccessCheck, MapGenericMask, CopySid, GetTokenInformation, OpenThreadToken, ConvertStringSidToSidW, LookupAccountSidW, AddAccessAllowedAceEx, AddAccessDeniedAceEx, AddAuditAccessAceEx, AddAccessAllowedObjectAce, AddAccessDeniedObjectAce, AddAuditAccessObjectAce
kernel32.dll
CreateFileMappingW, OpenFileMappingW, MapViewOfFile, lstrcpyW, lstrcatW, GetProcAddress, CreateThread, FindCloseChangeNotification, FindFirstChangeNotificationW, FindNextChangeNotification, GetLocaleInfoW, IsDBCSLeadByte, CompareStringA, SetThreadPriority, FormatMessageW, GetWindowsDirectoryW, LocalAlloc, LoadLibraryA, RaiseException, ResetEvent, MoveFileW, ReleaseMutex, FlushViewOfFile, UnmapViewOfFile, OpenMutexW, SetLastError, lstrcmpiA, MultiByteToWideChar, lstrlenW, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, lstrcmpiW, lstrcpynW, HeapDestroy, InterlockedIncrement, InterlockedDecrement, FreeLibrary, lstrlenA, SizeofResource, LoadResource, FindResourceW, GetLastError, LoadLibraryExW, GetShortPathNameW, GetModuleFileNameW, GetVersionExW, GetCommandLineW, GetPrivateProfileStringW, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, InterlockedExchange, Sleep, LoadLibraryW, WaitForMultipleObjects, SetEvent, CloseHandle, CreateEventW, WaitForSingleObject, GetCurrentThread, SetEnvironmentVariableW, GetTempPathW, GetEnvironmentVariableW, CopyFileW, SetFileAttributesW, DeleteFileW, MoveFileExW, GetFileAttributesExW, CreateDirectoryW, FindClose, FindNextFileW, FindFirstFileW, RemoveDirectoryW, CreateFileW, CompareFileTime, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, GetSystemTime, GetLocalTime, OpenProcess, GlobalMemoryStatusEx, GetSystemDirectoryW, GlobalUnlock, GlobalLock, GlobalSize, GlobalAlloc, FileTimeToSystemTime, GetUserDefaultLCID, GetTimeZoneInformation, GetCurrentDirectoryW, GetFullPathNameW, ExpandEnvironmentStringsW, GetDiskFreeSpaceW, GetTempFileNameW, WideCharToMultiByte, LocalFree, DuplicateHandle, WriteFile, SetFilePointer, ReadFile, GetFileInformationByHandle, GlobalFree, GetModuleHandleA, GetStartupInfoW, GetFileAttributesA, FileTimeToDosDateTime, FileTimeToLocalFileTime, CreateFileA, HeapAlloc, HeapReAlloc, GetThreadPriority, IsDBCSLeadByteEx, GetSystemDefaultLangID, GetLocaleInfoA, GetACP, HeapFree, GetProcessHeap, CreateMutexW
msvcrt.dll
DllMain
ntdll.dll
wcsncmp, sprintf, strrchr, tolower, strchr, _wtol, _itow, _ltow, wcsstr, _snwprintf, towlower, strtoul, wcstoul, NtQueryInformationProcess, strncpy
ole32.dll
CLSIDFromString, CoSuspendClassObjects, CoRegisterClassObject, StringFromCLSID, CoSetProxyBlanket, GetHGlobalFromStream, StgOpenStorageEx, StgCreateStorageEx, CoGetCallContext, CreateStreamOnHGlobal, CoCreateGuid, StringFromGUID2, CoCreateInstanceEx, CoInitializeEx, CoInitializeSecurity, CoUninitialize, CoTaskMemRealloc, CoTaskMemAlloc, CoTaskMemFree, CoCreateInstance, CoRevokeClassObject
rpcrt4.dll
I_RpcBindingInqLocalClientPID
user32.dll
CharUpperBuffW, CharUpperW, CharNextA, GetSystemMetrics, GetMessageW, DispatchMessageW, MsgWaitForMultipleObjects, LoadStringW, CharNextW, PostThreadMessageW, TranslateMessage, PeekMessageW