Import table
advapi32.dll
RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegSetValueExW, RegQueryInfoKeyW, OpenProcessToken, GetTokenInformation, LookupAccountSidW, RegDeleteKeyW, RegCreateKeyExW, AllocateAndInitializeSid, InitializeAcl, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, GetLengthSid, FreeSid, AddAccessAllowedAce, ConvertSidToStringSidW, RegEnumValueW, RegEnumKeyExW, RegDeleteValueW
kernel32.dll
CompareStringW, OpenProcess, GetWindowsDirectoryW, SetEvent, MapViewOfFile, UnmapViewOfFile, LoadLibraryW, LocalFree, Process32NextW, CreateThread, FreeLibrary, Process32FirstW, GetPrivateProfileStringW, CreateToolhelp32Snapshot, CreateFileMappingW, WaitForSingleObject, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, DeleteFileW, InterlockedDecrement, CloseHandle, CreateEventW, HeapFree, lstrlenW, GetOverlappedResult, SystemTimeToFileTime, GetFileAttributesExW, CreateFileW, HeapAlloc, ResetEvent, FileTimeToSystemTime, GetFileAttributesW, lstrcmpiW, GetProcessHeap, lstrcpynW, ReadDirectoryChangesW, GetProcAddress, GetLastError, Sleep, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, InterlockedCompareExchange, InterlockedExchange, CreateDirectoryW, GetModuleFileNameW
msvcp80.dll
DllMain
msvcr80.dll
DllMain
shell32.dll
SHGetFolderPathW
wtsapi32.dll
WTSFreeMemory, WTSEnumerateSessionsW
Export table
NServiceModule_Load
NServiceModule_Run
NServiceModule_Unload