Import table
advapi32.dll
GetLengthSid, AllocateAndInitializeSid, RegQueryValueExA, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AddAccessAllowedAce, AddAccessDeniedAce, InitializeAcl, FreeSid, RegSetValueExA, RegCreateKeyExA, RegCloseKey, RegOpenKeyExA
gdi32.dll
GetStockObject
kernel32.dll
CreateProcessA, lstrcmpiA, TerminateProcess, GetLastError, GetVersionExA, CreateFileA, Sleep, MultiByteToWideChar, DeviceIoControl, OpenEventA, GetExitCodeProcess, lstrcatA, lstrlenA, FindFirstFileA, FindClose, GetModuleHandleA, GetWindowsDirectoryA, lstrcpyA, FreeLibrary, LoadLibraryA, GetProcAddress, LocalSize, CreateEventA, lstrcmpA, LocalFree, LocalAlloc, WaitForSingleObject, TerminateThread, CloseHandle, ResetEvent, GetModuleFileNameA, WTSGetActiveConsoleSessionId, GetStartupInfoA, GetCommandLineA, HeapAlloc, GetLocaleInfoA, GetStringTypeW, IsBadCodePtr, IsBadReadPtr, GetStringTypeA, InitializeCriticalSection, GetFileType, SetUnhandledExceptionFilter, GetEnvironmentStringsW, FreeEnvironmentStringsW, SetHandleCount, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetEnvironmentStrings, WriteFile, SetEvent, CreateThread, GetStdHandle, HeapFree, WideCharToMultiByte, LCMapStringA, LCMapStringW, GetOEMCP, GetACP, GetCPInfo, TlsGetValue, TlsAlloc, GetCurrentThreadId, SetLastError, TlsSetValue, ExitProcess, VirtualFree, VirtualQuery, GetSystemInfo, VirtualProtect, TlsFree, DeleteCriticalSection, IsBadWritePtr, LeaveCriticalSection, RtlUnwind, HeapReAlloc, VirtualAlloc, HeapDestroy, EnterCriticalSection, HeapCreate
user32.dll
TranslateMessage, DispatchMessageA, RegisterClassA, GetMessageA, FindWindowA, CreateWindowExA, UpdateWindow, ShowWindow, PostQuitMessage, KillTimer, SendMessageA, wsprintfA, DefWindowProcA, SetTimer, EnumDisplaySettingsExA, MessageBoxA, LoadStringA, ChangeDisplaySettingsA, EnumDisplayDevicesA, ChangeDisplaySettingsExA, OpenInputDesktop, EnumDisplaySettingsA, GetUserObjectInformationA, CloseDesktop, RegisterWindowMessageA
wtsapi32.dll
WTSRegisterSessionNotification