Import table
advapi32.dll
RegSetValueExW, LookupPrivilegeValueW, RegEnumKeyW, RegSetKeySecurity, RegQueryInfoKeyW, RegEnumValueW, SetFileSecurityW, LsaNtStatusToWinError, CopySid, LookupAccountNameW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey, SetServiceStatus, RegisterEventSourceW, ReportEventW, DeregisterEventSource, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, StartServiceW, OpenServiceW, ControlService, QueryServiceStatus, DeleteService, OpenSCManagerW, CreateServiceW, CloseServiceHandle, ChangeServiceConfig2W, OpenProcessToken, GetTokenInformation, AdjustTokenPrivileges, SetNamedSecurityInfoW, RegOpenKeyW, ConvertSidToStringSidW, RevertToSelf, CreateProcessAsUserW, ImpersonateLoggedOnUser, DuplicateTokenEx, RegCreateKeyExW
dbghelp.dll
MiniDumpWriteDump
faultrep.dll
ReportFault
kernel32.dll
TerminateThread, DeleteCriticalSection, InitializeCriticalSection, WaitForSingleObject, CreateThread, SetThreadPriority, ResumeThread, GetVersionExW, SetProcessWorkingSetSize, LoadLibraryW, GetProcAddress, SetEvent, WaitForMultipleObjects, GetTickCount, WTSGetActiveConsoleSessionId, SetLastError, GetModuleFileNameW, Sleep, GetLastError, SetConsoleCtrlHandler, EnterCriticalSection, LeaveCriticalSection, GetCurrentThreadId, GetCurrentProcessId, GetCurrentProcess, SetStdHandle, SetEnvironmentVariableW, SetEnvironmentVariableA, CompareStringW, CloseHandle, CompareStringA, GetStringTypeW, GetStringTypeA, GetConsoleCP, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetLocaleInfoA, LCMapStringW, WideCharToMultiByte, LCMapStringA, IsValidCodePage, GetOEMCP, GetACP, GetSystemTimes, GetSystemInfo, DeviceIoControl, QueryDosDeviceW, CreateFileW, GetShortPathNameW, MapViewOfFile, CreateFileMappingW, UnmapViewOfFile, FreeLibrary, GetSystemPowerStatus, OpenFileMappingW, InterlockedIncrement, InterlockedDecrement, ExpandEnvironmentStringsW, GetVolumeInformationW, LocalFree, FormatMessageW, GetLongPathNameW, GetLogicalDrives, DeleteFileW, FlushFileBuffers, RemoveDirectoryW, CreateDirectoryW, GetSystemDirectoryW, GetDriveTypeW, CreateMutexW, OpenMutexW, ReleaseMutex, CreateEventW, GetCPInfo, ResetEvent, GetProcessHeap, HeapAlloc, HeapFree, HeapReAlloc, VirtualAlloc, VirtualFree, HeapCompact, SystemTimeToFileTime, GetSystemTime, SystemTimeToTzSpecificLocalTime, GetTimeZoneInformation, FileTimeToSystemTime, TzSpecificLocalTimeToSystemTime, ReadFile, SetFilePointerEx, WriteFile, SetFilePointer, GetEnvironmentVariableW, InterlockedCompareExchange, GetTempPathW, SetUnhandledExceptionFilter, SetErrorMode, GetProcessId, VirtualProtect, GetModuleHandleA, TerminateProcess, GetStdHandle, LoadLibraryA, SuspendThread, GetModuleHandleW, GetTimeFormatW, GetDateFormatW, RtlUnwind, RaiseException, ReadConsoleInputA, SetConsoleMode, GetConsoleMode, UnhandledExceptionFilter, IsDebuggerPresent, GetVersionExA, MultiByteToWideChar, GetSystemTimeAsFileTime, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, GetModuleFileNameA, CreateFileA, HeapSize, ExitProcess, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetCommandLineW, SetHandleCount, GetFileType, GetStartupInfoA, HeapDestroy, HeapCreate, QueryPerformanceCounter, OpenEventW
ole32.dll
CoInitializeEx, CoUninitialize, StringFromGUID2, CoCreateGuid, CoTaskMemFree, CoTaskMemAlloc
psapi.dll
GetModuleBaseNameW
secur32.dll
GetUserNameExW, LsaGetLogonSessionData, LsaFreeReturnBuffer, LsaEnumerateLogonSessions
setupapi.dll
SetupDiDestroyDeviceInfoList, SetupDiGetDeviceInterfaceDetailW, SetupDiEnumDeviceInterfaces, SetupDiGetDeviceRegistryPropertyW, SetupDiEnumDeviceInfo, SetupDiGetClassDevsW
shell32.dll
SHGetFileInfoW, SHBindToParent, SHGetSpecialFolderPathW
shlwapi.dll
PathRemoveFileSpecW, PathAppendW, StrRetToBufW, PathStripToRootW, PathAddBackslashW
user32.dll
ExitWindowsEx, TranslateMessage, PeekMessageW, MsgWaitForMultipleObjects, UnregisterClassW, DestroyWindow, UnregisterDeviceNotification, RegisterDeviceNotificationW, CreateWindowExW, RegisterClassW, DefWindowProcW, KillTimer, SetTimer, GetWindowLongW, SetWindowLongW, DispatchMessageW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
wtsapi32.dll
WTSEnumerateProcessesW, WTSEnumerateSessionsW, WTSQueryUserToken, WTSQuerySessionInformationW, WTSFreeMemory