Import table
advapi32.dll
OpenThreadToken, RevertToSelf, RegCreateKeyExA, RegSetValueExA, RegCloseKey, OpenServiceA, ControlService, DeleteService, OpenSCManagerA, CreateServiceA, StartServiceA, QueryServiceStatus, CloseServiceHandle, RegisterEventSourceA, ReportEventA, DeregisterEventSource, SetServiceStatus, RegisterServiceCtrlHandlerA, StartServiceCtrlDispatcherA, ImpersonateNamedPipeClient, InitializeSecurityDescriptor, DuplicateTokenEx
kernel32.dll
LocalAlloc, Sleep, GetModuleFileNameA, FormatMessageA, CreateDirectoryA, CopyFileA, DeleteFileA, MoveFileA, _lclose, _lwrite, _llseek, _lcreat, _lopen, GetLocalTime, GetCurrentThread, GetCurrentThreadId, WaitForMultipleObjects, lstrcpyA, DisconnectNamedPipe, WriteFile, GetOverlappedResult, ReadFile, ConnectNamedPipe, SetLastError, ResetEvent, CreateNamedPipeA, CreateEventA, SetEvent, FreeResource, ExpandEnvironmentStringsA, LockResource, LoadResource, FindResourceA, GetVersionExA, lstrcmpiA, LocalFree, CreateProcessA, GetLastError, WaitForSingleObject, CloseHandle, EnterCriticalSection, LeaveCriticalSection, CreateThread, lstrlenA, HeapFree, HeapReAlloc, GetProcessHeap, HeapAlloc, DebugBreak, DeleteCriticalSection, InitializeCriticalSection, GetModuleHandleA, GetCommandLineA, ExitProcess, GetStartupInfoA, GetProcAddress, lstrcpynA
shlwapi.dll
SHDeleteValueA, SHDeleteKeyA
user32.dll
CharNextA, wsprintfA