Import table
advapi32.dll
SetTokenInformation, CreateProcessAsUserW, ImpersonateLoggedOnUser, DuplicateTokenEx, FreeSid, RegNotifyChangeKeyValue, RegSetValueExW, RegCreateKeyExW, RegOpenKeyExW, StartServiceCtrlDispatcherW, OpenSCManagerW, OpenServiceW, QueryServiceStatus, ControlService, CloseServiceHandle, RegisterServiceCtrlHandlerExW, RegQueryValueExW, RegCloseKey, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, SetServiceStatus, AllocateAndInitializeSid, SetEntriesInAclW, SetNamedSecurityInfoW, RevertToSelf, RegQueryValueExA, CreateProcessAsUserA, RegSetValueExA, RegCreateKeyExA, RegOpenKeyExA, StartServiceCtrlDispatcherA, OpenSCManagerA, OpenServiceA, RegisterServiceCtrlHandlerExA, LookupPrivilegeValueA, SetEntriesInAclA, SetNamedSecurityInfoA
crypt32.dll
CertFindCertificateInStore, CryptQueryObject, CertFreeCertificateContext, CertCloseStore
kernel32.dll
lstrlenW, LocalAlloc, LocalReAlloc, LocalSize, ReadFile, WriteFile, GetCurrentProcessId, WaitNamedPipeW, CreateFileW, GetSystemDirectoryW, DeviceIoControl, lstrcmpiW, CreateEventW, CreateThread, GetExitCodeThread, SetEvent, WaitForMultipleObjects, ExitThread, FindFirstFileW, FindClose, SetThreadPriority, GetModuleHandleW, GetCommandLineW, GlobalFree, OpenFileMappingW, CreateFileMappingW, GetShortPathNameW, GetCurrentProcess, WTSGetActiveConsoleSessionId, SetLastError, GetModuleFileNameW, LoadLibraryW, GetProcAddress, FreeLibrary, OpenEventW, WaitForSingleObject, MapViewOfFile, UnmapViewOfFile, CompareStringW, CompareStringA, GetTimeZoneInformation, FlushFileBuffers, CreateFileA, GetLocaleInfoW, HeapSize, IsValidLocale, EnumSystemLocalesA, GetLocaleInfoA, GetUserDefaultLCID, GetDateFormatA, GetTimeFormatA, SetEnvironmentVariableA, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, LocalFree, GetVersionExW, GetLastError, Sleep, CloseHandle, WriteConsoleW, GetConsoleOutputCP, GetCommandLineA, GetStartupInfoA, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, ExitProcess, GetStdHandle, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, GetFileType, DeleteCriticalSection, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, GetCurrentThreadId, InterlockedDecrement, GetCurrentThread, HeapCreate, HeapDestroy, VirtualFree, HeapFree, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, SetFilePointer, GetConsoleCP, GetConsoleMode, EnterCriticalSection, LeaveCriticalSection, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, MultiByteToWideChar, FatalAppExitA, SetConsoleCtrlHandler, InterlockedExchange, LoadLibraryA, InitializeCriticalSectionAndSpinCount, HeapAlloc, VirtualAlloc, HeapReAlloc, RtlUnwind, SetStdHandle, WriteConsoleA, lstrcatW, lstrcpyW, IsBadWritePtr, GetModuleHandleA, GetVersion, GetEnvironmentVariableA, GetVersionExA, CreateEventA, FindFirstFileA, OutputDebugStringA, OpenFileMappingA, CreateFileMappingA, GetShortPathNameA, SetEndOfFile
setupapi.dll
SetupDiDestroyDeviceInfoList, SetupDiGetDeviceRegistryPropertyW, SetupDiGetClassDevsW, SetupDiEnumDeviceInfo, SetupDiGetClassDevsA, SetupDiGetDeviceRegistryPropertyA, SetupDiDeleteDeviceInfo
shell32.dll
CommandLineToArgvW
shlwapi.dll
StrRChrW
user32.dll
wsprintfA
userenv.dll
LoadUserProfileW, DestroyEnvironmentBlock, UnloadUserProfile, CreateEnvironmentBlock
wintrust.dll
WinVerifyTrust
wtsapi32.dll
WTSQueryUserToken, WTSFreeMemory, WTSQuerySessionInformationW, WTSQuerySessionInformationA