Import table
advapi32.dll
GetSidSubAuthority, GetLengthSid, DeregisterEventSource, RegisterEventSourceW, ReportEventW, SetServiceStatus, RegisterServiceCtrlHandlerExW, ControlService, EnumDependentServicesW, StartServiceW, QueryServiceStatusEx, ChangeServiceConfigW, QueryServiceConfigW, DeleteService, RegCreateKeyW, ChangeServiceConfig2W, CreateServiceW, SetServiceObjectSecurity, SetEntriesInAclW, BuildExplicitAccessWithNameW, GetExplicitEntriesFromAclW, GetSecurityDescriptorDacl, QueryServiceObjectSecurity, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegDeleteValueW, RegOpenKeyExW, GetSidSubAuthorityCount, CopySid, OpenProcessToken, CreateProcessAsUserW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, DuplicateTokenEx, RegCloseKey, RegSetValueExW, RegQueryValueExW, RegCreateKeyExW, LookupAccountSidW, GetTokenInformation
crypt32.dll
CertGetNameStringW
kernel32.dll
OutputDebugStringW, ExitProcess, CopyFileW, DeleteFileW, RegisterWaitForSingleObject, UnregisterWait, lstrlenA, Sleep, GetCurrentProcess, GetModuleFileNameW, HeapFree, GetProcessHeap, HeapAlloc, GetEnvironmentVariableW, GetPrivateProfileStringW, DeleteCriticalSection, InitializeCriticalSection, MultiByteToWideChar, GetTickCount, SetEvent, CreateEventW, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, GetCurrentThreadId, WaitNamedPipeW, CreateFileW, WriteFile, TerminateThread, WaitForSingleObject, CreateThread, ConnectNamedPipe, CreateNamedPipeW, FlushFileBuffers, DisconnectNamedPipe, ReadFile, lstrlenW, LocalFree, LocalAlloc, CreateFileA, SetEnvironmentVariableW, SetEndOfFile, CompareStringW, GetDateFormatA, GetTimeFormatA, GetDateFormatW, GetTimeFormatW, GetTimeZoneInformation, SetNamedPipeHandleState, WideCharToMultiByte, ExitThread, SetEnvironmentVariableA, MoveFileW, CloseHandle, WTSGetActiveConsoleSessionId, GetLastError, LeaveCriticalSection, EnterCriticalSection, AllocConsole, ResetEvent, SetStdHandle, WriteConsoleW, LoadLibraryW, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, SetFilePointer, GetLocaleInfoW, GetConsoleMode, HeapDestroy, HeapReAlloc, HeapSize, RaiseException, InitializeCriticalSectionAndSpinCount, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, InterlockedExchange, GetStringTypeW, EncodePointer, DecodePointer, GetCommandLineA, RtlUnwind, GetCPInfo, LCMapStringW, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, IsProcessorFeaturePresent, HeapCreate, GetProcAddress, GetModuleHandleW, GetStdHandle, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, SetLastError, SetHandleCount, GetFileType, GetStartupInfoW, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, GetConsoleCP
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathAppendW, PathFileExistsW
userenv.dll
LoadUserProfileW, CreateEnvironmentBlock, DestroyEnvironmentBlock, UnloadUserProfile
wintrust.dll
WinVerifyTrust, WTHelperGetProvSignerFromChain, WTHelperGetProvCertFromChain, WTHelperProvDataFromStateData
wtsapi32.dll
WTSQueryUserToken
Export table
PPTVLogOutA
PPTVLogOutW
ReloadConfig
RundllCmd
SendMsgToSvc
ServiceMain