Import table
advapi32.dll
RegLoadKeyW, GetTokenInformation, DuplicateTokenEx, ImpersonateLoggedOnUser, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, RegisterServiceCtrlHandlerExW, CreateServiceW, DeleteService, ControlService, StartServiceW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, SetServiceStatus, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetFileSecurityW, FreeSid, InitializeAcl, AddAccessAllowedAce, GetAce, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, RegFlushKey, RegCreateKeyW, RegOpenKeyW, RegQueryValueExW, AllocateAndInitializeSid, SetNamedSecurityInfoW, OpenSCManagerW, OpenServiceW, CloseServiceHandle, QueryServiceStatusEx, RegEnumKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, RegCreateKeyExW, RegOpenKeyExW, RegUnLoadKeyW, OpenThreadToken, ImpersonateSelf, IsTextUnicode, CreateProcessAsUserW
kernel32.dll
DllMain
ole32.dll
CoTaskMemAlloc, CoTaskMemRealloc, CoTaskMemFree, CoInitialize, CoUninitialize, CoRevokeClassObject, CoRegisterClassObject, CoInitializeSecurity, StringFromGUID2, CoCreateInstance, CoAddRefServerProcess, CoReleaseServerProcess, CoInitializeEx, CoSetProxyBlanket
psapi.dll
GetProcessImageFileNameW
shell32.dll
ShellExecuteExW, SHGetFolderPathW
shlwapi.dll
PathFileExistsW, PathAddBackslashW, PathRemoveFileSpecW, PathIsDirectoryW
user32.dll
CharNextW, CharUpperW, PostThreadMessageW, UnregisterDeviceNotification, KillTimer, LoadStringW, DispatchMessageW, TranslateMessage, GetMessageW, SetTimer, RegisterDeviceNotificationW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, VerQueryValueW, GetFileVersionInfoSizeW
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory, WTSQueryUserToken