Import table
advapi32.dll
LsaNtStatusToWinError, ConvertStringSidToSidW, CheckTokenMembership, DuplicateTokenEx, CreateProcessAsUserA, LookupAccountSidA, EqualSid, IsValidSid, GetSidSubAuthorityCount, GetSidSubAuthority, GetTokenInformation, SetSecurityDescriptorDacl, GetSecurityDescriptorLength, MakeSelfRelativeSD, InitializeSecurityDescriptor, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, MakeAbsoluteSD, GetSecurityDescriptorControl, RegQueryValueExA, RegCreateKeyExA, RegOpenKeyExA, GetLengthSid, SetTokenInformation, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, ChangeServiceConfigW, ChangeServiceConfig2W, StartServiceW, ConvertSidToStringSidW, LookupAccountNameW, CopySid, ControlService, QueryServiceStatus, DeleteService, CreateServiceW, OpenSCManagerW, OpenServiceW, RegEnumKeyExW, CloseServiceHandle, RegQueryInfoKeyW, RegDeleteKeyW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, SetServiceStatus, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegEnumValueA, RegDeleteValueA, RegCloseKey
kernel32.dll
CreateMutexA, ReleaseMutex, PulseEvent, WaitForMultipleObjects, CreateEventA, SetEnvironmentVariableA, CompareStringW, CreateFileA, SetStdHandle, IsBadCodePtr, LocalAlloc, CreateDirectoryA, GetWindowsDirectoryA, GetTickCount, GetCurrentProcessId, OutputDebugStringA, CreateFileMappingA, LoadLibraryA, GetModuleHandleA, GetACP, SetLastError, GetCurrentThread, GetVersionExA, GetCommandLineW, GetPrivateProfileStringW, LocalFree, LoadLibraryExW, FreeLibrary, InterlockedDecrement, GetCurrentThreadId, Sleep, lstrcmpiW, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, EnterCriticalSection, RaiseException, GetModuleFileNameW, CreatePipe, SetHandleInformation, CreateProcessW, CreateEventW, GetCurrentProcess, DuplicateHandle, ResumeThread, WaitForSingleObject, GetExitCodeProcess, SetEvent, TerminateProcess, TerminateThread, ResetEvent, GetModuleFileNameA, PeekNamedPipe, OutputDebugStringW, lstrlenA, lstrlenW, UnmapViewOfFile, CreateFileMappingW, MapViewOfFileEx, SetEndOfFile, SetFilePointer, WriteFile, ReadFile, MultiByteToWideChar, CloseHandle, GetModuleHandleW, GetProcAddress, CreateFileW, WideCharToMultiByte, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, GetLastError, InterlockedExchange, InterlockedCompareExchange, SuspendThread, WriteConsoleW, LoadLibraryW, FlushFileBuffers, GetConsoleMode, GetConsoleCP, GetTimeZoneInformation, GetStringTypeW, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetLocaleInfoW, GetUserDefaultLCID, QueryPerformanceCounter, GetFileType, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetStdHandle, ExitProcess, IsProcessorFeaturePresent, HeapCreate, LCMapStringW, IsValidCodePage, GetOEMCP, GetCPInfo, TlsFree, TlsSetValue, TlsGetValue, TlsAlloc, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, InterlockedIncrement, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetStartupInfoW, HeapSetInformation, GetSystemTimeAsFileTime, DecodePointer, EncodePointer, CreateThread, ExitThread, RtlUnwind, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, InitializeCriticalSection
netapi32.dll
NetUserDel
ole32.dll
CoTaskMemFree, CoAddRefServerProcess, CoRevokeClassObject, CoCreateInstance, CoInitialize, CoUninitialize, CoInitializeEx, CoTaskMemRealloc, CoReleaseServerProcess, CoTaskMemAlloc
secur32.dll
LsaRegisterLogonProcess, LsaLogonUser, LsaDeregisterLogonProcess
shell32.dll
SHGetSpecialFolderLocation, SHGetPathFromIDListA, SHGetMalloc
shlwapi.dll
PathQuoteSpacesW, PathCanonicalizeW, PathIsDirectoryW, PathRemoveFileSpecW, PathAddExtensionW, PathUnquoteSpacesW, PathGetCharTypeW, PathAppendW, PathRemoveExtensionW, PathStripPathW, PathAddBackslashW, PathFileExistsA, PathIsDirectoryA, PathIsFileSpecA, PathIsFileSpecW, PathIsRelativeA, PathSkipRootW, PathSkipRootA, PathIsUNCW, PathIsUNCA, PathIsRelativeW, PathUnquoteSpacesA
user32.dll
GetFocus, LoadStringW, PostThreadMessageW, PeekMessageW, TranslateMessage, DispatchMessageW, CharUpperW, CharNextW
userenv.dll
CreateEnvironmentBlock, UnloadUserProfile, DeleteProfileW, LoadUserProfileA, DestroyEnvironmentBlock
wtsapi32.dll
WTSEnumerateSessionsW, WTSFreeMemory, WTSQuerySessionInformationW, WTSQueryUserToken