Import table
advapi32.dll
RegQueryValueExW, RegSetValueExA, RegCreateKeyW, RegOpenKeyW, RegQueryInfoKeyW, RegDeleteKeyA, RegDeleteKeyW, RegEnumKeyExA, RegCreateKeyA, RegOpenKeyExA, RegQueryInfoKeyA, RegDeleteValueW, RegDeleteValueA, CryptHashData, CryptDestroyHash, CryptCreateHash, CryptReleaseContext, CryptAcquireContextW, CryptGetHashParam, CreateWellKnownSid, ConvertSidToStringSidW, OpenProcessToken, SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, RegCloseKey, DuplicateTokenEx, RegOpenUserClassesRoot, QueryServiceConfigW, ControlService, StartServiceW, OpenServiceW, OpenSCManagerW, DeleteService, CloseServiceHandle, CreateServiceW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AdjustTokenPrivileges, RevertToSelf, ImpersonateSelf, LookupPrivilegeValueW, GetTokenInformation, RegEnumValueA, RegEnumValueW, RegOpenKeyExW, RegOpenKeyA, RegEnumKeyExW, RegSetValueExW, RegQueryValueExA, RegCreateKeyExA, RegCreateKeyExW, GetSecurityDescriptorSacl, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegEnumKeyW, GetUserNameW, SetSecurityDescriptorSacl, ImpersonateLoggedOnUser, QueryServiceStatus
kernel32.dll
DuplicateHandle, WideCharToMultiByte, MultiByteToWideChar, FreeLibrary, GetModuleHandleExW, LoadLibraryW, GetProcAddress, GetVolumeInformationA, GetTempFileNameW, CreateFileA, MoveFileExA, MoveFileExW, CopyFileW, ReplaceFileW, ReplaceFileA, GetTempPathW, MoveFileW, CopyFileA, MoveFileA, DeleteFileW, DeleteFileA, CreatePipe, WriteFile, GetNamedPipeInfo, ReadFile, GetFileType, GetNativeSystemInfo, GetVersionExW, GetExitCodeThread, GetExitCodeProcess, TerminateThread, SetHandleInformation, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, GetSystemTime, GetCurrentProcessId, GetCurrentThreadId, CreateDirectoryW, SetEnvironmentVariableW, GetModuleFileNameW, GetCurrentProcess, RegisterWaitForSingleObject, UnregisterWait, CreateProcessW, WTSGetActiveConsoleSessionId, GetUserDefaultLCID, InterlockedDecrement, InterlockedIncrement, CancelIo, DeviceIoControl, GetOverlappedResult, CreateFileW, CreateThread, WaitForMultipleObjects, ResetEvent, SetEvent, WaitForSingleObject, LocalFree, LocalSize, LocalAlloc, lstrlenW, FormatMessageW, ResumeThread, SuspendThread, WriteProcessMemory, CloseHandle, CreateEventW, OpenThread, VirtualAllocEx, QueueUserAPC, OpenProcess, CreateRemoteThread, Sleep, InterlockedCompareExchange, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, HeapFree, GetProcessHeap, SetLastError, GetLastError, GetCommandLineW, InterlockedExchange, LockResource, SizeofResource, LoadResource, FindResourceExW, CreateToolhelp32Snapshot, Process32NextW, Process32FirstW, GetTempPathA, FlushFileBuffers, SetEndOfFile, ReleaseMutex, CreateMutexW, MapViewOfFile, UnmapViewOfFile, CreateFileMappingW, OpenFileMappingW, WaitForMultipleObjectsEx, SetThreadPriority, ReadFileEx, GetLocalTime, FileTimeToSystemTime, ConnectNamedPipe, CreateNamedPipeW, DisconnectNamedPipe, CreateSemaphoreW, GetFullPathNameW, GetFullPathNameA, GetFileSize, SetFilePointer, UnlockFile, LockFile, UnlockFileEx, FormatMessageA, GetFileAttributesA, GetFileAttributesW, LockFileEx, GetDiskFreeSpaceW, LoadLibraryA, GetDiskFreeSpaceA, GetFileAttributesExW, AreFileApisANSI, OpenFile, GetFileAttributesExA
msvcp90.dll
DllMain
msvcr90.dll
DllMain
ole32.dll
CoInitializeEx, CoUninitialize, CoCreateInstance, CoInitializeSecurity, CoSetProxyBlanket, OleRun, CoInitialize, CoCreateGuid
secur32.dll
GetUserNameExW
shell32.dll
SHGetFolderPathW, SHCreateDirectoryExW
shlwapi.dll
PathFileExistsW
user32.dll
PostThreadMessageW, PeekMessageW, GetMessageW, PostQuitMessage, wsprintfW
userenv.dll
UnloadUserProfile, LoadUserProfileW
wtsapi32.dll
WTSQueryUserToken