Import table
advapi32.dll
RegEnumKeyExW, RegSetValueExW, RegCreateKeyExW, RegEnumValueW, ConvertSidToStringSidW, OpenProcessToken, GetTokenInformation, StartServiceCtrlDispatcherW, CreateServiceW, CloseServiceHandle, DeleteService, OpenSCManagerW, OpenServiceW, ChangeServiceConfig2W, StartServiceW, ControlService, RegQueryValueExW, RegDeleteKeyW, RegDeleteValueW, SetServiceStatus, RegOpenCurrentUser, RegOpenKeyExW, RegisterServiceCtrlHandlerW, RegCloseKey, RegOpenKeyW
kernel32.dll
lstrcmpiW, GetLastError, lstrlenW, ReleaseMutex, DeleteFileW, GetModuleFileNameW, Sleep, GetTickCount, GetLogicalDriveStringsW, GetDriveTypeW, CreateMutexW, InterlockedDecrement, HeapReAlloc, HeapAlloc, GetCurrentProcess, HeapFree, GetModuleHandleW, GetProcessHeap, GetFileAttributesW, CreateFileW, lstrcmpW, GetLongPathNameW, GetProcAddress, RemoveDirectoryW, CloseHandle, LocalFree, SetFileAttributesW, ExpandEnvironmentStringsW, GetLogicalDrives, QueryDosDeviceW, lstrcpyW, GetEnvironmentVariableW, FindFirstFileW, FindClose, FindNextFileW, WideCharToMultiByte, MultiByteToWideChar, SetLastError, TerminateProcess, GetCurrentProcessId, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCommandLineA, VirtualAlloc, GetSystemTimeAsFileTime, ExitProcess, RaiseException, RtlUnwind, EnterCriticalSection, LeaveCriticalSection, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, DeleteCriticalSection, WriteFile, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, HeapCreate, VirtualFree, QueryPerformanceCounter, HeapSize, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, LCMapStringA, LCMapStringW, ReadFile, SetFilePointer, GetConsoleCP, GetConsoleMode, GetStringTypeW, GetStringTypeA, LoadLibraryA, InitializeCriticalSectionAndSpinCount, CreateFileA, SetStdHandle, FlushFileBuffers, GetLocaleInfoA, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, GetModuleHandleA, SetEndOfFile, InterlockedExchange, InitializeCriticalSection
ole32.dll
CoTaskMemFree, CoCreateInstance
user32.dll
wsprintfW