Import table
advapi32.dll
RegCloseKey, RegOpenKeyExW, OpenProcessToken, InitializeAcl, RegDeleteKeyW, RegDeleteValueW, RegCreateKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegEnumKeyExW, InitializeSecurityDescriptor, RegQueryValueExW, AdjustTokenPrivileges, LookupPrivilegeValueW, RegLoadKeyW, RegUnLoadKeyW, SetSecurityDescriptorOwner, IsValidSid, GetLengthSid, CopySid, GetTokenInformation, AddAce, GetAce, GetAclInformation, AddAccessAllowedAce, SetServiceStatus, StartServiceCtrlDispatcherW, SetSecurityDescriptorDacl, OpenThreadToken, LookupAccountNameW, RegNotifyChangeKeyValue, RegisterServiceCtrlHandlerExW, RegEnumValueW, GetSidSubAuthority, InitializeSid, GetSidLengthRequired, LookupAccountSidW, CreateWellKnownSid, ReportEventW, AddAccessDeniedAce, SetTokenInformation, IsValidAcl, DeregisterEventSource, RegisterEventSourceW, SetSecurityDescriptorGroup, RegisterTraceGuidsW, UnregisterTraceGuids, TraceEvent, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, ImpersonateLoggedOnUser, GetSecurityDescriptorLength, RevertToSelf, ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorA, CheckTokenMembership
kernel32.dll
UnmapViewOfFile, LCMapStringW, lstrcmpW, CompareFileTime, RemoveDirectoryW, LoadLibraryW, FindNextFileW, GetCommandLineW, MapViewOfFile, GetDriveTypeW, GetVersionExW, CreateEventW, DuplicateHandle, CreateFileW, GetLocalTime, SetEvent, GetCurrentThread, WaitForSingleObject, GetSystemDefaultLCID, VerSetConditionMask, VerifyVersionInfoW, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetModuleHandleA, SetUnhandledExceptionFilter, RtlUnwind, OutputDebugStringA, GetStartupInfoA, InterlockedCompareExchange, GetEnvironmentVariableW, CreateFileMappingW, GetLocaleInfoW, GetSystemDefaultUILanguage, GetUserDefaultUILanguage, SearchPathW, CopyFileW, ExpandEnvironmentStringsW, GetFileAttributesW, DeleteFileW, FindFirstFileW, lstrlenA, FindClose, FindResourceExW, LockResource, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, MultiByteToWideChar, FreeLibrary, HeapSetInformation, SetPriorityClass, SetEnvironmentVariableW, CreateMutexW, InterlockedExchange, GetVersionExA, HeapSize, HeapReAlloc, HeapAlloc, Sleep, GetModuleFileNameW, lstrcmpiW, LeaveCriticalSection, EnterCriticalSection, SetLastError, GetProcessHeap, HeapFree, InterlockedDecrement, InterlockedIncrement, DeleteCriticalSection, InitializeCriticalSection, RaiseException, GetVolumeInformationW, GetCurrentProcess, GetSystemDirectoryW, GetUserDefaultLCID, GetModuleHandleW, GetModuleHandleExW, GetProcAddress, GetLastError, CloseHandle, WideCharToMultiByte, CompareStringW, lstrlenW, HeapDestroy, FormatMessageW, ReleaseMutex, OpenMutexW, FileTimeToSystemTime, SystemTimeToTzSpecificLocalTime, GetTimeFormatW, LocalFree, GetStringTypeExW, OutputDebugStringW, CreateFileA, FlushViewOfFile, DeleteFileA, CopyFileA, CreateThread, WaitForMultipleObjects
mpr.dll
WNetGetConnectionW
msvcrt.dll
DllMain
netapi32.dll
NetShareEnum, NetApiBufferFree
ole32.dll
CoCreateInstance, CoInitializeEx, CoUninitialize, CoTaskMemAlloc, CoTaskMemRealloc, CoRevokeClassObject, CoRegisterClassObject, CoInitializeSecurity, CLSIDFromProgID, CoTaskMemFree, CoInitialize, CoImpersonateClient, CoRevertToSelf
shell32.dll
SHFileOperationW, SHGetFolderPathW
shlwapi.dll
PathSkipRootW, PathStripToRootW, PathIsUNCServerShareW, PathIsUNCServerW, PathIsUNCW, SHGetValueW, PathAddBackslashW, SHSetValueW, PathRemoveBackslashW, PathAppendW, SHDeleteKeyW, PathFileExistsW, SHStrDupW, SHCopyKeyW, SHEnumKeyExW, SHEnumValueW, SHRegGetValueW, SHDeleteValueW
user32.dll
GetKeyboardLayout, CharNextW, PeekMessageW, DispatchMessageW, MsgWaitForMultipleObjects, LoadStringW, UnregisterClassA
userenv.dll
GetUserProfileDirectoryW, GetDefaultUserProfileDirectoryW, GetProfilesDirectoryW, GetAllUsersProfileDirectoryW
wtsapi32.dll
WTSQueryUserToken, WTSFreeMemory, WTSEnumerateSessionsW