Import table
advapi32.dll
RegEnumKeyW, RegOpenKeyExW, RegCloseKey, RegSetValueExW, RegQueryValueExW, RegQueryInfoKeyW, RegEnumValueW, RegEnumKeyExW, GetUserNameW, RegCreateKeyExW, RegDeleteKeyW, RegSaveKeyExW, OpenProcessToken, RegDeleteValueW, LookupPrivilegeValueW, SetFileSecurityA, QueryServiceConfigW, CloseServiceHandle, OpenSCManagerW, OpenServiceW, LookupAccountNameW, QueryServiceStatusEx, ControlService, ConvertSidToStringSidW, IsTextUnicode, GetTokenInformation, SetFileSecurityW, AdjustTokenPrivileges, StartServiceW, ChangeServiceConfigW
crypt32.dll
CryptQueryObject, CryptMsgClose, CertFreeCertificateContext, CertFindCertificateInStore, CertCloseStore, CryptMsgGetParam, CertGetNameStringW, CryptDecodeObject
kernel32.dll
DllMain
ole32.dll
CoTaskMemFree, CoCreateInstance, CoInitialize, CoUninitialize
psapi.dll
EnumProcessModules, GetModuleFileNameExW, GetModuleInformation, GetProcessImageFileNameW
shell32.dll
ShellExecuteExW, SHGetFileInfoW
shlwapi.dll
SHDeleteKeyW, StrToIntW, StrStrIW, PathUnExpandEnvStringsW
user32.dll
wsprintfW, SetFocus, FindWindowW, WaitForInputIdle, SendMessageW, GetWindowTextW, EnumWindows, GetClassNameW, SendMessageTimeoutW, FindWindowExW, SetForegroundWindow, EnumDisplaySettingsW, GetWindowThreadProcessId, DestroyIcon, PostMessageW, wsprintfA, GetSystemMetrics, ShowWindow, CharUpperW, OemToCharBuffA, OemToCharA, CharUpperA, CharLowerA, CharToOemBuffW, CharToOemA, IsCharAlphaW, IsCharAlphaNumericW
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wintrust.dll
CryptCATCatalogInfoFromContext, CryptCATAdminReleaseContext, WinVerifyTrustEx, CryptCATAdminCalcHashFromFileHandle, CryptCATAdminAcquireContext, CryptCATAdminEnumCatalogFromHash