Import table
advapi32.dll
LookupAccountNameW, RegCloseKey, RegQueryValueExW, SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, InitializeSecurityDescriptor, InitializeAcl, GetAce, AdjustTokenPrivileges, OpenProcessToken, MakeAbsoluteSD, OpenThreadToken, RegCreateKeyExW, RegOpenKeyExW, SetSecurityDescriptorOwner, SetKernelObjectSecurity, SetSecurityDescriptorGroup, GetSecurityInfo, AddAce, AllocateAndInitializeSid, LookupPrivilegeValueW, CreateProcessAsUserW, EqualSid, ConvertStringSidToSidW, SetThreadToken, DuplicateTokenEx, CreateRestrictedToken, SetSecurityInfo, GetSecurityDescriptorSacl, SetTokenInformation, GetTokenInformation, SetSecurityDescriptorSacl, SetSecurityDescriptorDacl, AddAuditAccessAce, AddAccessAllowedAce, RegDeleteValueW, RegEnumValueW, RegOpenKeyW, RegCreateKeyW, ImpersonateNamedPipeClient, RevertToSelf, ImpersonateLoggedOnUser, ConvertSidToStringSidW, RegSetValueExW
crypt32.dll
CertGetIssuerCertificateFromStore, CertFindCertificateInStore, CertCreateCertificateChainEngine, CertGetCertificateChain, CryptQueryObject, CryptHashPublicKeyInfo, CertGetNameStringW, CertNameToStrW, CertGetCertificateContextProperty, CryptDecodeObject, CryptMsgClose, CertFreeCertificateChainEngine, CertFreeCertificateChain, CertCloseStore, CertOpenSystemStoreW, CryptMsgGetParam, CertFreeCertificateContext, CertEnumCertificatesInStore
kernel32.dll
SetLastError, WaitForSingleObject, GetTickCount, GetThreadPriority, FreeLibrary, GetCurrentThread, SetThreadPriority, CreateEventW, CloseHandle, CreateToolhelp32Snapshot, Process32FirstW, SetUnhandledExceptionFilter, SetEvent, InterlockedCompareExchange, Process32NextW, QueueUserAPC, DeviceIoControl, SleepEx, GetVersion, TerminateProcess, OpenThread, DuplicateHandle, GetModuleHandleW, InterlockedExchange, CreateProcessW, GetExitCodeProcess, LocalFree, ResumeThread, GetStartupInfoA, UnhandledExceptionFilter, OpenProcess, QueryPerformanceCounter, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, GetCurrentProcess, SetProcessWorkingSetSize, Sleep, GetProcAddress, LoadLibraryW, GetLastError, WaitForMultipleObjects, ResetEvent, GetComputerNameW, QueueUserWorkItem, CreateFileMappingW, MapViewOfFile, UnmapViewOfFile, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, GetEnvironmentStringsW, SetEnvironmentVariableW, GetWindowsDirectoryW, GetTempPathW, CreateDirectoryW, GetEnvironmentVariableW, GetFileAttributesW, MultiByteToWideChar, FindFirstFileW, GetModuleFileNameW, FindClose, SearchPathW, WriteFile, FlushFileBuffers, DisconnectNamedPipe, ReadFile, ConnectNamedPipe, CreateNamedPipeW, TlsAlloc, GetCurrentDirectoryW, TlsFree, OpenFileMappingW, VirtualQuery, lstrcmpA, IsBadReadPtr, IsBadWritePtr, lstrcpynW, VerLanguageNameW, FormatMessageW, HeapDestroy, HeapCreate, GetFileSizeEx, MoveFileExW, SetFilePointerEx, CompareFileTime, HeapFree, GetCommandLineW, ExitThread, GetLocalTime, ReleaseMutex, CreateMutexW, WaitForSingleObjectEx, SetEndOfFile, HeapAlloc, GetSystemTime, CompareStringA, CompareStringW, GetShortPathNameW, WaitNamedPipeW, GetPrivateProfileIntW, GetPrivateProfileStringW, GetVersionExW, WideCharToMultiByte, RemoveDirectoryW, SetFileAttributesW, FindNextFileW, DeleteFileW, OutputDebugStringW, ReadProcessMemory, GetExitCodeThread, CreateThread, GetFileSize, CreateFileW, CopyFileW, TlsGetValue, TlsSetValue, GetProcessAffinityMask, InterlockedIncrement, InterlockedDecrement, VirtualAlloc, VirtualFree, QueryPerformanceFrequency, IsDebuggerPresent, GetSystemDirectoryW, GetLongPathNameW, SystemTimeToFileTime
msvcp80.dll
DllMain
msvcr80.dll
DllMain
ntdll.dll
ZwDelayExecution, ZwSetInformationFile, ZwQueryFullAttributesFile, ZwWaitForMultipleObjects, ZwOpenKey, RtlFreeUnicodeString, ZwCreateFile, ZwQueryInformationFile, ZwOpenThread, RtlGetVersion, ZwFlushBuffersFile, ZwWriteFile, ZwReadFile, ZwReleaseMutant, RtlFormatCurrentUserKeyPath, ZwCreateKey, RtlInitUnicodeString, ZwAllocateVirtualMemory, ZwWriteVirtualMemory, ZwFlushInstructionCache, ZwQueryInformationProcess, ZwQueryKey, ZwYieldExecution, ZwCreateEvent, ZwWaitForSingleObject, ZwResetEvent, ZwSetValueKey, ZwQueryInformationThread, ZwOpenDirectoryObject, ZwOpenSymbolicLinkObject, ZwQuerySymbolicLinkObject, ZwOpenSection, ZwMapViewOfSection, ZwReadVirtualMemory, ZwQueryVirtualMemory, ZwQueryValueKey, ZwProtectVirtualMemory, ZwSetEvent, ZwAreMappedFilesTheSame, ZwUnmapViewOfSection, RtlNtStatusToDosError, ZwOpenMutant, ZwClose, ZwCreateMutant, ZwOpenFile, ZwOpenEvent
ole32.dll
CoInitialize, CoUninitialize
psapi.dll
EnumProcesses
shell32.dll
CommandLineToArgvW, SHGetSpecialFolderPathW
shlwapi.dll
SHDeleteKeyW
user32.dll
CharLowerW, wsprintfW, CharUpperW, OpenInputDesktop, SetThreadDesktop, GetThreadDesktop, OpenDesktopW, CloseDesktop, GetDesktopWindow, FindWindowExW, GetUserObjectInformationW, CharUpperBuffW, CharUpperBuffA, CharLowerBuffA, RegisterWindowMessageW, MessageBoxW, PeekMessageW, MsgWaitForMultipleObjects, DispatchMessageW, TranslateMessage, CharLowerBuffW
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
version.dll
VerQueryValueW, GetFileVersionInfoSizeW, GetFileVersionInfoW
wintrust.dll
WinVerifyTrust, WTHelperGetProvSignerFromChain, CryptCATAdminReleaseContext, CryptCATAdminReleaseCatalogContext, CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext, CryptCATAdminAcquireContext, WTHelperProvDataFromStateData, CryptCATAdminCalcHashFromFileHandle