Import table
advapi32.dll
DeleteService, RegDeleteKeyW, RegDeleteValueW, RegEnumKeyExW, RegQueryInfoKeyW, RevertToSelf, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, SetNamedSecurityInfoW, DeleteAce, GetAce, GetNamedSecurityInfoW, SetEntriesInAclW, CloseServiceHandle, StartServiceW, QueryServiceStatus, ControlService, CreateProcessAsUserW, FreeSid, EqualSid, LookupAccountSidW, RegCloseKey, RegCreateKeyExW, DeregisterEventSource, ReportEventW, RegisterEventSourceW, SetServiceStatus, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, RegOpenKeyExW, RegSetValueExW, RegQueryValueExW, CryptGenRandom, CryptReleaseContext, CryptAcquireContextA, LsaLookupNames, LsaFreeMemory, LsaClose, ConvertSidToStringSidW, LsaOpenPolicy, GetUserNameW, RegFlushKey, ImpersonateLoggedOnUser, AllocateAndInitializeSid, GetSecurityInfo, SetSecurityInfo, RegCreateKeyW, InitiateSystemShutdownW, LogonUserW, RegOpenCurrentUser, OpenThreadToken, RegSetValueExA, LookupAccountNameW, ConvertStringSecurityDescriptorToSecurityDescriptorW
crypt32.dll
CertGetNameStringA, CertGetNameStringW, CryptVerifyMessageSignature, CertFreeCertificateContext, CryptHashCertificate
imagehlp.dll
ImageGetCertificateHeader, ImageGetCertificateData, ImageEnumerateCertificates
iphlpapi.dll
DeleteIPAddress, GetAdapterIndex, GetAdaptersInfo, SendARP, IpRenewAddress, FlushIpNetTable, GetBestInterface, GetIfEntry, GetIpAddrTable
kernel32.dll
DllMain, GetDriveTypeA, FindFirstFileA, LoadLibraryA, GetSystemDirectoryA, GetWindowsDirectoryA, GetModuleFileNameA, GetModuleHandleA, CompareStringA, FreeLibrary, InterlockedExchange, InterlockedIncrement, InterlockedExchangeAdd, InterlockedDecrement, SetLastError, SetConsoleCtrlHandler, Sleep, TlsFree, TlsAlloc, ExpandEnvironmentStringsA, GetThreadTimes, lstrlenA, SetEnvironmentVariableA, SetStdHandle, GetConsoleOutputCP, WriteConsoleA, CreateFileA, IsValidLocale, EnumSystemLocalesA, FlushFileBuffers, GetConsoleMode, GetConsoleCP, GetTimeZoneInformation, GetOEMCP, GetStartupInfoA, GetFileType, SetHandleCount, GetCommandLineW, GetCommandLineA, GetEnvironmentStrings, FreeEnvironmentStringsA, VirtualAlloc, VirtualFree, HeapCreate, HeapDestroy, HeapSize, GetStdHandle, ExitProcess, GetCurrentThreadId, GetLastError, GetFullPathNameA, GetCurrentDirectoryA, CreateSemaphoreA, GetStringTypeA, LCMapStringA, RtlUnwind, HeapReAlloc, GetDateFormatA, GetTimeFormatA, ExitThread, IsDebuggerPresent, UnhandledExceptionFilter, CreateWaitableTimerA, AreFileApisANSI, SetEndOfFile, FormatMessageA, GetThreadLocale, GetACP, GetVersionExA, FileTimeToLocalFileTime, SetUnhandledExceptionFilter, FileTimeToSystemTime, DeleteCriticalSection, CloseHandle, WaitForMultipleObjects, InitializeCriticalSectionAndSpinCount, GetCurrentProcessId, GetCurrentProcess, SetFilePointer, GetSystemTimeAsFileTime, WriteFile, GetTickCount, ReleaseMutex, SetWaitableTimer, GetFileSize, PostQueuedCompletionStatus, LeaveCriticalSection, WaitForSingleObject, SleepEx, SetEvent, EnterCriticalSection, CreateEventA, QueueUserAPC, InitializeCriticalSection, GetQueuedCompletionStatus, TerminateThread, LocalFree, OpenProcess, QueryPerformanceFrequency, FindClose, GetSystemDefaultLCID, GetUserDefaultLCID, GetLocaleInfoA, GetLocalTime, GetCurrentThread, QueryPerformanceCounter, DuplicateHandle, ReleaseSemaphore, InterlockedCompareExchange, TlsSetValue, TlsGetValue, OpenEventA, ResetEvent, HeapAlloc, GetProcessHeap, HeapFree, CreateIoCompletionPort, ReadFile, TerminateProcess, SizeofResource, LoadResource, RaiseException, CreateThread, ResumeThread, DeviceIoControl, SetThreadPriority, GetOverlappedResult, SystemTimeToFileTime, GetExitCodeThread, SetThreadAffinityMask, GetExitCodeProcess
mpr.dll
WNetCloseEnum, WNetEnumResourceW, WNetOpenEnumW
mswsock.dll
AcceptEx, GetAcceptExSockaddrs
netapi32.dll
NetApiBufferFree, NetWkstaGetInfo
ole32.dll
CoInitializeSecurity, CoTaskMemAlloc, StringFromGUID2, OleInitialize, OleUninitialize, CoTaskMemRealloc, CoCreateInstance, CoCreateGuid, CoTaskMemFree, CoRegisterClassObject, CoRevokeClassObject, ProgIDFromCLSID, CoUninitialize, CoInitializeEx, CoRevertToSelf, CoImpersonateClient
secur32.dll
GetUserNameExW
sensapi.dll
IsNetworkAlive
setupapi.dll
SetupDiDestroyDeviceInfoList, SetupDiEnumDeviceInfo, SetupDiGetClassDevsW, SetupDiGetDeviceRegistryPropertyW, SetupDiOpenDevRegKey
shell32.dll
SHGetPathFromIDListW, SHGetSpecialFolderLocation, ShellExecuteExW, SHGetMalloc, ShellExecuteW
user32.dll
MessageBoxW, GetMessageW, TranslateMessage, DispatchMessageW, MessageBoxA, PostThreadMessageW, CharNextW, DestroyWindow, SendMessageW, FindWindowW, PeekMessageW, MsgWaitForMultipleObjectsEx, ExitWindowsEx, UnregisterClassA, LoadStringA
userenv.dll
UnloadUserProfile, CreateEnvironmentBlock, LoadUserProfileW, DestroyEnvironmentBlock
wininet.dll
HttpSendRequestA, InternetErrorDlg, InternetQueryOptionW, InternetGoOnlineA, HttpOpenRequestA, HttpAddRequestHeadersA, HttpSendRequestExA, InternetWriteFile, HttpEndRequestA, InternetQueryDataAvailable, InternetReadFile, HttpQueryInfoW, InternetOpenW, InternetSetOptionW, InternetCloseHandle, InternetConnectW
winspool.drv
DeletePrinter, SetPrinterW, OpenPrinterW, GetPrinterW, ClosePrinter, AddPrinterW, SetJobW, EnumPrintersW
wintrust.dll
WinVerifyTrust, CryptCATCatalogInfoFromContext, CryptCATAdminEnumCatalogFromHash, CryptCATAdminCalcHashFromFileHandle, CryptCATAdminAcquireContext, CryptCATAdminReleaseCatalogContext, CryptCATAdminReleaseContext, WTHelperProvDataFromStateData, WTHelperGetProvSignerFromChain
ws2_32.dll
WSAResetEvent, WSADuplicateSocketW, WSACreateEvent, WSACloseEvent, WSAWaitForMultipleEvents, WSAEventSelect, WSASetEvent, WSARecv, WSARecvFrom, WSASocketW, WSASend, WSAAddressToStringA
wtsapi32.dll
WTSQuerySessionInformationW, WTSCloseServer, WTSEnumerateProcessesW, WTSFreeMemory, WTSEnumerateSessionsW