Import table
advapi32.dll
StartServiceCtrlDispatcherW, ChangeServiceConfigW, QueryServiceConfigW, RegOpenKeyW, ConvertStringSecurityDescriptorToSecurityDescriptorW, CryptAcquireContextW, CryptCreateHash, CryptHashData, CryptGetHashParam, CryptDestroyHash, CryptReleaseContext, RegEnumKeyW, RegisterServiceCtrlHandlerExW, ChangeServiceConfig2W, RegEnumKeyExW, SetServiceStatus, QueryServiceStatusEx, StartServiceW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegQueryInfoKeyW, RegSetValueExW, RegCreateKeyExW, RegDeleteValueW, RegDeleteKeyW, OpenSCManagerW, DeleteService, OpenServiceW, ControlService, CreateServiceW, CloseServiceHandle, RegQueryValueExW, RegOpenKeyExW, RegEnumValueW, RegCloseKey, DuplicateTokenEx, CreateProcessAsUserW, GetTokenInformation, IsValidSid, EqualSid, FreeSid, AllocateAndInitializeSid
kernel32.dll
DllMain
ole32.dll
CoInitialize, CoUninitialize, CoCreateInstance, CoTaskMemAlloc, CoTaskMemRealloc, CoRevokeClassObject, CoRegisterClassObject, StringFromGUID2, CoInitializeSecurity, CoInitializeEx, CoSuspendClassObjects, CoResumeClassObjects, StringFromCLSID, CLSIDFromString, CoTaskMemFree
psapi.dll
GetProcessImageFileNameW, GetModuleFileNameExW, GetModuleBaseNameW, EnumProcesses
shell32.dll
SHGetFolderPathW
shlwapi.dll
PathRemoveExtensionW, PathGetArgsW, PathRemoveArgsW, PathIsRelativeW, PathFindOnPathW, PathSearchAndQualifyW, PathFileExistsW, PathFindExtensionW, PathRemoveFileSpecW, PathAddBackslashW, PathAppendW, PathStripPathW, PathRemoveBlanksW, PathCanonicalizeW, PathIsRootW, PathFindFileNameW
user32.dll
CharUpperW, CharNextW, wsprintfW, DispatchMessageW, GetMessageW, PostThreadMessageW, LoadStringW, TranslateMessage
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, GetFileVersionInfoW, VerQueryValueW
wtsapi32.dll
WTSFreeMemory, WTSOpenServerW, WTSCloseServer, WTSQueryUserToken, WTSQuerySessionInformationW, WTSEnumerateSessionsW