Import table
advapi32.dll
LookupAccountNameW, QueryServiceStatus, StartServiceCtrlDispatcherA, RegisterServiceCtrlHandlerA, SetServiceStatus, AllocateAndInitializeSid, RegEnumValueA, RegNotifyChangeKeyValue, RegEnumKeyA, RegQueryValueA, RegOpenKeyA, RegDeleteKeyA, RegDeleteValueA, RegOpenKeyExA, RegQueryValueExA, RegCreateKeyExA, RegSetValueExA, GetUserNameA, OpenProcessToken, RegOpenCurrentUser, AddAccessAllowedAce, GetSecurityDescriptorDacl, GetAclInformation, InitializeAcl, AddAce, GetAce, DuplicateTokenEx, CreateProcessAsUserA, LookupPrivilegeValueA, AdjustTokenPrivileges, FreeSid, IsValidSid, RevertToSelf, ImpersonateLoggedOnUser, GetTokenInformation, GetLengthSid, CopySid, RegCloseKey, ControlService, StartServiceA, DeleteService, OpenSCManagerA, OpenServiceA, ChangeServiceConfigA, CreateServiceA, CloseServiceHandle, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, ConvertStringSecurityDescriptorToSecurityDescriptorA, GetSecurityDescriptorSacl
kernel32.dll
InitializeCriticalSection, GetVersionExA, GetSystemDirectoryA, GetEnvironmentVariableA, OpenEventA, WaitForMultipleObjects, HeapFree, HeapAlloc, GetProcessHeap, Process32Next, OpenProcess, Process32First, CreateToolhelp32Snapshot, SetConsoleCtrlHandler, TerminateProcess, GetLocalTime, DeleteCriticalSection, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, SetStdHandle, GetConsoleMode, GetConsoleCP, GetStringTypeW, OutputDebugStringA, CreateDirectoryA, LocalFree, CreateFileA, GetFileType, FlushFileBuffers, SetFilePointer, LeaveCriticalSection, GetFileSize, WriteFile, LoadLibraryA, GetProcAddress, FreeLibrary, GetShortPathNameA, GetCurrentProcessId, GetModuleHandleA, GetModuleFileNameA, Sleep, GetTickCount, GetCurrentThreadId, InterlockedIncrement, InterlockedDecrement, TerminateThread, SetThreadPriority, GetCurrentProcess, DuplicateHandle, ResetEvent, CreateThread, CloseHandle, ExitThread, CreateEventA, SetEvent, GetLastError, WaitForSingleObject, InterlockedExchange, EnterCriticalSection, MoveFileExA, GetStringTypeA, HeapReAlloc, VirtualAlloc, GetLocaleInfoA, QueryPerformanceCounter, VirtualFree, HeapCreate, SetHandleCount, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, LCMapStringW, MultiByteToWideChar, RtlUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RaiseException, GetSystemTimeAsFileTime, GetModuleHandleW, ExitProcess, GetCommandLineA, GetStartupInfoA, GetStdHandle, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, HeapSize, InitializeCriticalSectionAndSpinCount, LCMapStringA, WideCharToMultiByte
psapi.dll
EnumProcesses, GetModuleBaseNameA, EnumProcessModules
shell32.dll
SHGetFolderPathA
user32.dll
GetMessageA, DispatchMessageA, MsgWaitForMultipleObjectsEx, CloseDesktop, CloseWindowStation, PeekMessageA, TranslateMessage, GetProcessWindowStation, OpenDesktopA, GetUserObjectSecurity, SetUserObjectSecurity, OpenWindowStationA, SetProcessWindowStation, OpenInputDesktop
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock, UnloadUserProfile, LoadUserProfileA
version.dll
GetFileVersionInfoA, VerQueryValueA, GetFileVersionInfoSizeA