Import table
advapi32.dll
TraceEvent, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, SetServiceStatus, RegisterServiceCtrlHandlerW, StartServiceCtrlDispatcherW, AllocateAndInitializeSid, FreeSid, SetEntriesInAclW, RegOpenKeyW, QueryServiceStatus, OpenSCManagerW, OpenServiceW, StartServiceW, CloseServiceHandle, PrivilegeCheck, OpenThreadToken, RegOpenKeyExW, RegCloseKey, GetSecurityDescriptorDacl, GetExplicitEntriesFromAclW, GetSidSubAuthority, IsValidSid, GetSidIdentifierAuthority, OpenProcessToken, SetNamedSecurityInfoW, GetNamedSecurityInfoW, EqualSid, LookupPrivilegeValueW, AdjustTokenPrivileges, BuildTrusteeWithSidW, RegQueryValueExW, GetSidSubAuthorityCount, GetTokenInformation, CopySid, GetLengthSid, SetSecurityDescriptorDacl, AddAccessAllowedAceEx, AddAccessDeniedAceEx, InitializeAcl, InitializeSecurityDescriptor, SetServiceObjectSecurity, RegCreateKeyExW
crypt32.dll
CertCreateContext
kernel32.dll
GetFileAttributesExW, GetSystemWindowsDirectoryW, QueryDosDeviceW, GetLogicalDriveStringsW, GetVersion, OpenProcess, ReadFile, SetFilePointer, VirtualProtect, IsBadReadPtr, GetSystemDirectoryW, GetWindowsDirectoryW, GetEnvironmentVariableW, HeapAlloc, HeapFree, GetVersionExA, HeapReAlloc, RaiseException, VirtualFree, VirtualAlloc, HeapDestroy, HeapCreate, GetModuleHandleA, ExitProcess, GetModuleFileNameA, UnhandledExceptionFilter, SetUnhandledExceptionFilter, TlsFree, OutputDebugStringA, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, InitializeCriticalSectionAndSpinCount, SetHandleCount, GetFileType, GetStartupInfoA, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, HeapSize, GetCPInfo, GetACP, GetOEMCP, LCMapStringA, WideCharToMultiByte, LCMapStringW, RtlUnwind, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, GetSystemInfo, VirtualQuery, GetConsoleCP, GetConsoleMode, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, LocalFree, LocalAlloc, FreeLibrary, GetProcAddress, CreateFileW, ResetEvent, Sleep, LoadLibraryA, SetLastError, GetCurrentThread, DebugBreak, GetStdHandle, WriteFile, TerminateProcess, TlsGetValue, TlsSetValue, TlsAlloc, GetCurrentThreadId, DeleteCriticalSection, InterlockedDecrement, InterlockedIncrement, InterlockedCompareExchange, GetModuleHandleW, GetCurrentProcess, GetModuleFileNameW, GetVersionExW, InitializeCriticalSection, CreateThread, CloseHandle, SetEvent, CreateEventW, EnterCriticalSection, LeaveCriticalSection, WaitForSingleObject, DeviceIoControl, GetLastError, LoadLibraryW, GetCommandLineW, InterlockedExchange, FindFirstFileW, FindClose
ntdll.dll
_wcsnicmp
psapi.dll
GetMappedFileNameW, EnumProcessModules, GetModuleInformation
sfc.dll
SfcIsFileProtected