Import table
advapi32.dll
StartServiceW, GetAce, AddAce, GetAclInformation, InitializeAcl, AddAccessAllowedAce, GetTokenInformation, OpenThreadToken, OpenProcessToken, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, IsValidSid, GetLengthSid, CopySid, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, StartServiceCtrlDispatcherW, OpenSCManagerW, QueryServiceConfigW, OpenServiceW, ChangeServiceConfig2W, CreateServiceW, DeleteService, LockServiceDatabase, ControlService, QueryServiceStatus, ChangeServiceConfigW, CloseServiceHandle, UnlockServiceDatabase, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, CreateProcessAsUserW, DuplicateTokenEx, RegEnumValueW, ConvertSidToStringSidW, RegisterServiceCtrlHandlerExW, RegEnumKeyExW, RegQueryInfoKeyW, RegDeleteKeyW, RegOpenKeyW, RegCreateKeyW, GetSecurityDescriptorLength, RegSetValueExA, ConvertStringSecurityDescriptorToSecurityDescriptorW, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource, LookupAccountNameW
crypt32.dll
CryptMsgClose, CertFreeCertificateChain, CertGetSubjectCertificateFromStore, CryptMsgGetParam, CryptQueryObject, CertGetNameStringW, CertVerifyCertificateChainPolicy, CertGetCertificateChain, CertGetCertificateContextProperty, CryptDecodeObject, CertCloseStore, CertFreeCertificateContext
kernel32.dll
GetCurrentThread, GetCurrentProcess, FreeLibrary, LoadLibraryW, GetProcAddress, CloseHandle, GetTickCount, CreateDirectoryW, lstrlenW, Sleep, GetFileAttributesExW, GetLastError, GetModuleFileNameW, CreateFileA, ReadFile, GetProcessHeap, SetEndOfFile, GetStringTypeW, GetStringTypeA, LCMapStringW, HeapAlloc, HeapFree, GetStartupInfoW, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualFree, VirtualAlloc, HeapReAlloc, HeapCreate, GetModuleHandleW, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, RtlUnwind, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, SetLastError, GetCurrentThreadId, InterlockedDecrement, HeapSize, RaiseException, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, InitializeCriticalSectionAndSpinCount, LoadLibraryA, SetStdHandle, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, FlushFileBuffers, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, MultiByteToWideChar, CreateFileW, GetLocaleInfoA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, SetFilePointer, LCMapStringA, IsBadCodePtr, IsBadReadPtr, WaitForMultipleObjects, CreateProcessW, OpenProcess, lstrcmpW, GetUserDefaultLangID, GetUserDefaultLCID, GetSystemDefaultLangID, GetCommandLineA, GetEnvironmentStrings, FreeEnvironmentStringsA, lstrlenA, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, SetEvent, CreateEventW, CreateThread, InitializeCriticalSection, WaitForSingleObject, GetModuleHandleA, GetThreadLocale, InterlockedExchange, HeapDestroy, SetCurrentDirectoryW, LocalFree, LoadLibraryExW, OutputDebugStringW, lstrcmpiW, GetVersionExW, GetVersionExA, GetSystemDefaultLCID, OpenEventW, GetExitCodeProcess, ReadConsoleW, SetFilePointerEx, EncodePointer, DecodePointer, GetModuleHandleExW, IsProcessorFeaturePresent
ole32.dll
CoInitializeEx, CoInitializeSecurity, CoUninitialize, CoCreateInstance, CoResumeClassObjects, CoRegisterClassObject, CoSuspendClassObjects, CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, StringFromGUID2, CoImpersonateClient, CoRevertToSelf, CoRevokeClassObject
shell32.dll
SHGetSpecialFolderPathW
shlwapi.dll
StrCatW, StrStrIW, StrRChrW, StrSpnW, StrCmpW
urlmon.dll
CoInternetParseUrl
user32.dll
CharUpperW, CharNextW, UnregisterClassA, MessageBoxW, CharLowerBuffW, LoadStringW, PostThreadMessageW, GetMessageW, DispatchMessageW, TranslateMessage, MsgWaitForMultipleObjects, PeekMessageW
userenv.dll
CreateEnvironmentBlock
wintrust.dll
WinVerifyTrust
wtsapi32.dll
WTSEnumerateProcessesW, WTSFreeMemory