Import table
advapi32.dll
CryptDecrypt, CryptDestroyKey, CryptEncrypt, CryptSetKeyParam, CryptImportKey, RegCloseKey, RegCreateKeyExW, OpenProcessToken, GetTokenInformation, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptReleaseContext, CryptAcquireContextW, RegSetValueExA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegQueryValueExA, RegOpenKeyExA, CreateProcessAsUserW, DuplicateTokenEx, SetTokenInformation, GetLengthSid
kernel32.dll
HeapFree, SetFilePointerEx, GetProcessHeap, FlushFileBuffers, GetFileAttributesExW, GetPrivateProfileStringA, OpenEventA, ReadFile, CreateFileW, WTSGetActiveConsoleSessionId, GetSystemTimeAsFileTime, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, InterlockedCompareExchange, Sleep, InterlockedExchange, DecodePointer, EncodePointer, ProcessIdToSessionId, TerminateProcess, OpenProcess, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, IsProcessorFeaturePresent, CreateEventA, OutputDebugStringW, LocalFree, GetCurrentProcess, GetLocalTime, MultiByteToWideChar, WideCharToMultiByte, lstrlenW, CloseHandle, SetEvent, WaitForSingleObject, GetModuleFileNameW, GetCurrentProcessId, lstrlenA, CreateEventW, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, TlsGetValue, GetCurrentThread, TlsSetValue, GetLastError, ResetEvent, GetCurrentThreadId, TlsAlloc, GetThreadTimes, TlsFree, ResumeThread, CreateThread, FormatMessageA, GetTickCount, InterlockedDecrement, ExpandEnvironmentStringsW, ReleaseMutex, CreateMutexA, CreateDirectoryW, GetFileAttributesW, SetFileAttributesW, FindFirstChangeNotificationW, FindNextChangeNotification, CreateMutexW, WriteFile
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
CoCreateInstance, CoInitializeEx, CoCreateGuid, CLSIDFromProgID, CoUninitialize, CoInitializeSecurity
rpcrt4.dll
UuidToStringW, RpcStringFreeW
user32.dll
MsgWaitForMultipleObjects, wsprintfW, DispatchMessageW, PeekMessageW
userenv.dll
CreateEnvironmentBlock
winmm.dll
timeGetTime
wtsapi32.dll
WTSQueryUserToken
Export table
doCleanup
getAllTasksList