Import table
advapi32.dll
AllocateAndInitializeSid, ChangeServiceConfigA, CloseServiceHandle, CreateProcessAsUserA, CreateServiceA, DeleteService, DuplicateTokenEx, FreeSid, GetSecurityDescriptorDacl, GetTokenInformation, ImpersonateLoggedOnUser, InitializeSecurityDescriptor, LockServiceDatabase, OpenSCManagerA, OpenServiceA, QueryServiceConfigA, QueryServiceObjectSecurity, RegCloseKey, RegCreateKeyExA, RegDeleteValueA, RegEnumKeyA, RegOpenKeyExA, RegQueryInfoKeyA, RegQueryValueExA, RegSetKeySecurity, RegSetValueExA, RegisterServiceCtrlHandlerA, RevertToSelf, SetEntriesInAclA, SetSecurityDescriptorControl, SetSecurityDescriptorDacl, SetServiceObjectSecurity, SetServiceStatus, StartServiceA, StartServiceCtrlDispatcherA, UnlockServiceDatabase
gdi32.dll
GetStockObject
kernel32.dll
CloseHandle, CreateDirectoryA, CreateEventA, CreateFileA, CreateMutexA, CreateProcessA, CreateThread, DeleteCriticalSection, DeleteFileA, DosDateTimeToFileTime, EnterCriticalSection, ExitProcess, ExitThread, FileTimeToDosDateTime, FileTimeToLocalFileTime, FileTimeToSystemTime, FindClose, FindFirstFileA, FindNextFileA, FlushFileBuffers, FormatMessageA, FreeEnvironmentStringsA, FreeLibrary, GetACP, GetCPInfo, GetCommandLineA, GetCommandLineW, GetConsoleMode, GetCurrentDirectoryA, GetCurrentProcessId, GetCurrentProcess, GetCurrentThread, GetCurrentThreadId, GetDiskFreeSpaceA, GetEnvironmentStrings, GetExitCodeProcess, GetFileAttributesA, GetFileInformationByHandle, GetFileSize, GetFileTime, GetFileType, GetFullPathNameA, GetLastError, GetLocalTime, GetLocaleInfoA, GetModuleFileNameA, GetModuleFileNameW, GetModuleHandleA, GetOEMCP, GetPrivateProfileSectionA, GetPrivateProfileSectionNamesA, GetPrivateProfileStringA, GetProcAddress, GetProcessHeap, GetShortPathNameA, GetStdHandle, GetSystemDirectoryA, GetSystemTime, GetTimeZoneInformation, GetVersionExA, GetVersion, GetWindowsDirectoryA, HeapAlloc, HeapFree, InitializeCriticalSection, LeaveCriticalSection, LoadLibraryA, LocalFileTimeToFileTime, LocalFree, MoveFileA, MoveFileExA, MultiByteToWideChar, OpenEventA, OpenProcess, ReadConsoleInputA, ReadFile, ReleaseMutex, ResetEvent, RtlUnwind, SetConsoleCtrlHandler, SetConsoleMode, SetCurrentDirectoryA, SetEnvironmentVariableA, SetEnvironmentVariableW, SetEvent, SetFileAttributesA, SetFilePointer, SetFileTime, SetLastError, SetStdHandle, SetUnhandledExceptionFilter, Sleep, SleepEx, SystemTimeToFileTime, TerminateThread, TlsAlloc, TlsFree, TlsGetValue, TlsSetValue, UnhandledExceptionFilter, VirtualAlloc, VirtualFree, VirtualQuery, WaitForMultipleObjects, WaitForSingleObject, WideCharToMultiByte, WriteConsoleA, WriteFile, WritePrivateProfileSectionA, WritePrivateProfileStringA, lstrcmpA, lstrcmpiA, lstrlenA
psapi.dll
EnumProcessModules, EnumProcesses, GetModuleBaseNameA
rasapi32.dll
RasEnumConnectionsA
rpcrt4.dll
I_RpcGetBuffer, NdrClientInitializeNew, NdrConvert, NdrFreeBuffer, NdrGetBuffer, NdrSendReceive, NdrServerInitializeNew, NdrSimpleStructBufferSize, NdrSimpleStructMarshall, NdrSimpleStructUnmarshall, RpcBindingFree, RpcBindingFromStringBindingA, RpcBindingInqAuthClientA, RpcBindingSetAuthInfoA, RpcBindingToStringBindingA, RpcEpRegisterA, RpcMgmtStopServerListening, RpcRaiseException, RpcServerInqBindings, RpcServerListen, RpcServerRegisterAuthInfoA, RpcServerRegisterIfEx, RpcServerUseProtseqEpA, RpcStringBindingComposeA, RpcStringBindingParseA, RpcStringFreeA
shell32.dll
ShellExecuteExA
user32.dll
CharLowerA, CharUpperA, CloseWindowStation, CreateWindowExA, DefWindowProcA, DispatchMessageA, FindWindowA, GetClassNameA, GetMessageA, GetWindowTextA, GetWindowThreadProcessId, KillTimer, LoadCursorA, LoadIconA, OpenWindowStationA, PostMessageA, PostQuitMessage, RegisterClassExA, SendMessageA, SetTimer, TranslateMessage, wsprintfA
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoA, GetFileVersionInfoSizeA, VerQueryValueA