Import table
advapi32.dll
GetTokenInformation, OpenProcessToken, CreateProcessAsUserW, RegEnumKeyExW, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCreateKeyExW, RegCloseKey, RegDeleteKeyW
crypt32.dll
CryptMsgClose, CertFreeCertificateContext, CertGetNameStringW, CertFindCertificateInStore, CryptMsgGetParam, CryptQueryObject, CertCloseStore
kernel32.dll
GetModuleFileNameW, WaitForSingleObject, ReleaseMutex, FindResourceExW, FindResourceW, LoadResource, LockResource, SizeofResource, DisableThreadLibraryCalls, GetProcAddress, OpenMutexW, SetLastError, GetCurrentProcess, GetLastError, FlushFileBuffers, CloseHandle, lstrcmpW, lstrlenW, GetVersionExW, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, GetVersionExA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, ExitProcess, RaiseException, RtlUnwind, GetCurrentThreadId, TlsSetValue, GetCommandLineA, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, GetModuleFileNameA, SetUnhandledExceptionFilter, TlsFree, TlsGetValue, TlsAlloc, GetModuleHandleA, TerminateProcess, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, HeapCreate, VirtualFree, WriteFile, VirtualAlloc, IsBadWritePtr, LoadLibraryA, IsBadReadPtr, IsBadCodePtr, MultiByteToWideChar, LCMapStringA, LCMapStringW, GetCPInfo, GetStringTypeA, GetStringTypeW, GetOEMCP, SetFilePointer, VirtualProtect, GetSystemInfo, VirtualQuery, SetStdHandle
shlwapi.dll
PathFileExistsW
wintrust.dll
WinVerifyTrust
Export table
DllRegisterServer
DllUnregisterServer
EventLock
EventLogoff
EventLogon
EventShutdown
EventStartScreenSaver
EventStartShell
EventStartup
EventStopScreenSaver
EventUnlock