Import table
advapi32.dll
RegSetValueExA, RegOpenKeyA, RegQueryValueExA, RegCloseKey, RegOpenKeyExA, StartServiceCtrlDispatcherA, CreateServiceA, DeleteService, RegisterServiceCtrlHandlerExA, SetServiceStatus, StartServiceA, OpenSCManagerA, OpenServiceA, CloseServiceHandle, ControlService, SetTokenInformation, GetSidSubAuthority, GetSidSubAuthorityCount, CreateProcessAsUserA, DuplicateTokenEx, OpenProcessToken, LookupPrivilegeValueA, AdjustTokenPrivileges, GetTokenInformation, GetSecurityDescriptorDacl, CopySid, GetLengthSid, SetSecurityDescriptorDacl, AddAce, GetAce, InitializeAcl, GetAclInformation, InitializeSecurityDescriptor, AddAccessAllowedAce
kernel32.dll
InitializeCriticalSection, DeleteCriticalSection, TerminateProcess, CreateProcessA, GetCurrentThreadId, GetPrivateProfileStringA, Sleep, WTSGetActiveConsoleSessionId, OpenProcess, GetModuleFileNameA, EnterCriticalSection, GetLocalTime, LeaveCriticalSection, FormatMessageA, GetCurrentProcess, GetPriorityClass, Process32Next, SetPriorityClass, CloseHandle, GetLastError, LocalAlloc, LocalFree, CreateToolhelp32Snapshot, Process32First, ProcessIdToSessionId, GetModuleHandleA, GetStartupInfoA, GetProcessHeap, HeapAlloc, HeapFree
msvcrt.dll
DllMain
user32.dll
GetProcessWindowStation, GetUserObjectInformationA, PostThreadMessageA, GetThreadDesktop, SetUserObjectSecurity, GetUserObjectSecurity, OpenWindowStationA, SetProcessWindowStation, OpenDesktopA, CloseWindowStation, CloseDesktop
userenv.dll
CreateEnvironmentBlock
wtsapi32.dll
WTSQueryUserToken