Import table
advapi32.dll
RegCreateKeyExA, ImpersonateLoggedOnUser, CreateProcessAsUserW, CreateProcessAsUserA, DuplicateTokenEx, SetTokenInformation, RegOpenKeyExW, RegQueryValueExW, RevertToSelf, RegOpenKeyA, ConvertSidToStringSidA, LookupPrivilegeValueA, AdjustTokenPrivileges, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerExA, ControlService, DeleteService, CreateServiceA, OpenThreadToken, OpenProcessToken, SetServiceStatus, RegisterEventSourceA, ReportEventA, DeregisterEventSource, OpenSCManagerA, OpenServiceA, CloseServiceHandle, ChangeServiceConfigA, GetTokenInformation, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, IsValidSid, GetLengthSid, CopySid, RegQueryValueExA, RegEnumKeyExA, InitializeSecurityDescriptor, GetSidLengthRequired, InitializeAcl, InitializeSid, GetSidSubAuthority, AddAccessAllowedAce, SetSecurityDescriptorDacl, IsValidSecurityDescriptor, RegQueryInfoKeyA, RegSetValueExA, RegOpenKeyExA, RegCloseKey, RegDeleteValueA, RegDeleteKeyA
kernel32.dll
LocalFree, GetCurrentProcessId, TerminateProcess, OpenProcess, CreateFileA, CreateProcessA, SetLastError, CreateProcessW, GetExitCodeProcess, FlushFileBuffers, SetStdHandle, IsBadCodePtr, IsBadReadPtr, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, UnhandledExceptionFilter, LCMapStringW, LCMapStringA, GetFileType, GetStdHandle, SetHandleCount, SetFilePointer, ReadFile, WriteFile, GetCPInfo, GetOEMCP, GetStringTypeW, GetStringTypeA, TlsGetValue, TlsSetValue, TlsFree, TlsAlloc, SetUnhandledExceptionFilter, QueryPerformanceCounter, IsBadWritePtr, FormatMessageA, ReleaseMutex, CreateMutexA, InterlockedCompareExchange, LoadLibraryA, GetCommandLineA, GetCurrentThreadId, GetTickCount, WTSGetActiveConsoleSessionId, lstrcatA, lstrcpyA, GetCurrentThread, GetCurrentProcess, FindResourceA, LoadResource, SizeofResource, GetModuleFileNameA, IsDBCSLeadByte, InterlockedDecrement, InterlockedIncrement, CreateThread, lstrcpynA, CreateEventA, WaitForSingleObject, TerminateThread, GetModuleHandleA, LoadLibraryExA, GetProcAddress, FreeLibrary, EnterCriticalSection, SetEvent, Sleep, ResetEvent, LeaveCriticalSection, CloseHandle, lstrcmpiA, lstrlenA, GetLastError, DeleteCriticalSection, InitializeCriticalSection, RaiseException, lstrlenW, WideCharToMultiByte, MultiByteToWideChar, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, SetEndOfFile, VirtualFree, HeapCreate, GetStartupInfoA, GetSystemTimeAsFileTime, ExitProcess, RtlUnwind, VirtualQuery, GetSystemInfo, VirtualAlloc, VirtualProtect, GetProcessHeap, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy
ole32.dll
CoCreateInstance, CoInitializeSecurity, StringFromGUID2, CoRevertToSelf, CoUninitialize, CoInitialize, CoRegisterClassObject, CoRevokeClassObject, CoImpersonateClient, CoTaskMemRealloc, CoTaskMemFree, CoInitializeEx, CoTaskMemAlloc
shlwapi.dll
PathFindExtensionA
user32.dll
LoadStringA, CharUpperA, MessageBoxA, DispatchMessageA, GetMessageA, PostThreadMessageA, CharNextA, TranslateMessage, GetSystemMetrics
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock, UnloadUserProfile