Import table
advapi32.dll
OpenProcessToken, GetTokenInformation, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, OpenSCManagerW, OpenServiceW, CreateServiceW, QueryServiceConfigW, StartServiceW, QueryServiceStatusEx, ControlService, DeleteService, OpenThreadToken, RegOpenKeyA, GetSecurityDescriptorDacl, InitializeAcl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertSecurityDescriptorToStringSecurityDescriptorA, AddAce, GetAce, ConvertStringSecurityDescriptorToSecurityDescriptorA, RegSetKeySecurity, RegGetKeySecurity, RegDeleteValueA, RegDeleteKeyA, RegCreateKeyExA, RegSetValueExA, RegQueryMultipleValuesA, LookupPrivilegeValueW, AdjustTokenPrivileges, RegEnumKeyExA, CloseServiceHandle, CryptDestroyKey, CryptExportKey, CryptImportKey, CryptReleaseContext, CryptGenKey, CryptAcquireContextW, CryptEncrypt, FreeSid, EqualSid, AllocateAndInitializeSid, ConvertSidToStringSidA, RegEnumValueA
crypt32.dll
CryptDecodeObject, CertFindCertificateInStore, CryptMsgGetParam, CryptQueryObject, CertGetNameStringW
kernel32.dll
GetFileType, GetStartupInfoA, DeleteCriticalSection, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, WriteFile, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, HeapReAlloc, CloseHandle, MultiByteToWideChar, ReadFile, HeapSize, FreeLibrary, InterlockedExchange, LoadLibraryA, InitializeCriticalSection, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetLocaleInfoA, GetLocaleInfoW, SetFilePointer, GetConsoleCP, GetConsoleMode, SetStdHandle, FlushFileBuffers, CreateFileA, GetUserDefaultLCID, EnumSystemLocalesA, IsValidLocale, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, TlsSetValue, GetConsoleOutputCP, WriteConsoleW, SetEndOfFile, GetTimeZoneInformation, CompareStringA, CompareStringW, SetEnvironmentVariableA, VirtualQuery, GetFileAttributesW, GetSystemTime, OutputDebugStringA, InterlockedExchangeAdd, GetModuleFileNameW, DeleteFileW, MoveFileW, CreateDirectoryW, FindClose, FindNextFileW, FindFirstFileW, FindNextFileA, FindFirstFileA, CompareFileTime, OpenProcess, GetStdHandle, ReadProcessMemory, GetExitCodeProcess, WaitForSingleObject, CreateProcessA, DeleteFileA, RtlCaptureContext, GetSystemInfo, GetModuleHandleW, LocalFree, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, LoadLibraryExA, lstrcmpA, CreateFileW, GetVolumeInformationA, ExpandEnvironmentStringsA, SetFileAttributesA, MoveFileExA, GetFileAttributesExA, ReleaseMutex, CreateMutexA, OpenMutexA, GetVolumeNameForVolumeMountPointA, MoveFileA, QueryPerformanceFrequency, DuplicateHandle, TerminateThread, CreateThread, LocalAlloc, LoadLibraryW, lstrcpynW, FlushInstructionCache, QueryDosDeviceW, DeviceIoControl, TlsAlloc, TlsGetValue, ExitProcess, GetModuleHandleA, RaiseException, GetProcessHeap, HeapAlloc, GetVersionExA, HeapFree, GetCommandLineA, GetCurrentThreadId, GetLastError, InterlockedDecrement, InterlockedIncrement, InterlockedCompareExchange, GetModuleFileNameA, GetProcAddress, GetFullPathNameW, GetCurrentDirectoryA, SetHandleCount, Sleep, GetCurrentThread, SetLastError, TlsFree, GetDriveTypeA, WriteConsoleA, ProcessIdToSessionId, WaitNamedPipeA, MapViewOfFileEx, RtlUnwind, lstrlenA
ntdll.dll
RtlNtStatusToDosError, NtQueryInformationProcess, ZwQuerySystemInformation, RtlUnwind, NtDeviceIoControlFile, RtlDosPathNameToNtPathName_U, RtlFreeUnicodeString
ole32.dll
CoUninitialize, OleRun, CoCreateInstance, CoSetProxyBlanket, CoInitializeEx
psapi.dll
GetModuleFileNameExA, GetModuleFileNameExW, GetModuleInformation, GetDeviceDriverBaseNameA, EnumDeviceDrivers
shell32.dll
SHGetFolderPathA, SHGetFolderPathW
shlwapi.dll
PathAppendA
user32.dll
GetDesktopWindow, MessageBoxA, wsprintfW
version.dll
VerQueryValueW, GetFileVersionInfoW, GetFileVersionInfoSizeW
wintrust.dll
CryptCATAdminCalcHashFromFileHandle, CryptCATAdminAcquireContext, CryptCATAdminEnumCatalogFromHash, CryptCATCatalogInfoFromContext, CryptCATAdminReleaseContext, CryptCATAdminReleaseCatalogContext, CryptCATClose, CryptCATEnumerateAttr, CryptCATGetMemberInfo, CryptCATOpen, WinVerifyTrust
wtsapi32.dll
WTSFreeMemory, WTSSendMessageA, WTSEnumerateSessionsW
Export table
execute2
prepare_for_update
register_components