Import table
advapi32.dll
DuplicateTokenEx, LookupPrivilegeValueW, SetTokenInformation, CreateProcessAsUserW, OpenProcessToken, ControlService, RegisterServiceCtrlHandlerW, QueryServiceStatusEx, SetServiceStatus, StartServiceW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, OpenServiceW, EnumDependentServicesW, StartServiceCtrlDispatcherW, OpenSCManagerW, DeleteService, CloseServiceHandle, CreateServiceW, AdjustTokenPrivileges
crypt32.dll
CryptVerifyMessageSignature, CertFreeCertificateContext, CertCompareIntegerBlob
imagehlp.dll
ImageGetCertificateData, ImageEnumerateCertificates
kernel32.dll
CreateFileMappingW, CreateEventW, OutputDebugStringW, OpenProcess, Process32FirstW, ProcessIdToSessionId, Process32NextW, CreateToolhelp32Snapshot, GetModuleFileNameW, SetEvent, WaitForSingleObject, HeapFree, HeapAlloc, UnmapViewOfFile, MapViewOfFile, CloseHandle, GetLastError, CreateFileW, Sleep, GetProcessHeap, GetTickCount, GetConsoleOutputCP, WriteConsoleW, SetStdHandle, CreateFileA, lstrcmpiW, GetACP, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, EnterCriticalSection, LeaveCriticalSection, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetOEMCP, IsValidCodePage, GetModuleHandleW, GetProcAddress, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, DeleteCriticalSection, HeapCreate, VirtualFree, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, WideCharToMultiByte, RtlUnwind, LCMapStringA, MultiByteToWideChar, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, LoadLibraryA, InitializeCriticalSectionAndSpinCount, VirtualAlloc, HeapReAlloc, GetConsoleCP, GetConsoleMode, FlushFileBuffers, SetFilePointer, HeapSize, WriteConsoleA
userenv.dll
CreateEnvironmentBlock
wintrust.dll
WinVerifyTrust