Import table
advapi32.dll
RegCreateKeyA, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorSacl, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, ImpersonateNamedPipeClient, OpenThreadToken, RegOpenCurrentUser, LookupAccountNameA, ImpersonateLoggedOnUser, GetUserNameA, RevertToSelf, DuplicateTokenEx, SetTokenInformation, CreateProcessAsUserA, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, RegDeleteValueA, OpenSCManagerA, OpenServiceA, ControlService, QueryServiceStatus, StartServiceA, CloseServiceHandle, RegQueryValueExA, RegOpenKeyExA, OpenProcessToken, RegSetValueExA, RegCloseKey, LookupPrivilegeValueA, AdjustTokenPrivileges
kernel32.dll
GetCurrentThreadId, LocalAlloc, GlobalFree, WriteFile, GlobalAlloc, MultiByteToWideChar, SetProcessWorkingSetSize, LoadLibraryA, lstrlenA, SetLastError, TerminateProcess, SetThreadPriority, GetCurrentThread, FreeLibrary, CreateFileW, MulDiv, WTSGetActiveConsoleSessionId, GetTickCount, lstrcmpA, WriteProfileStringA, GetProfileStringA, LocalFree, CopyFileA, CreateProcessA, lstrcatA, GetComputerNameA, GetPrivateProfileSectionNamesA, GetSystemTime, GetFileSize, ExitThread, DisconnectNamedPipe, CreateThread, ConnectNamedPipe, CreateNamedPipeA, QueryPerformanceCounter, VirtualProtect, GetProcessHeap, GetPrivateProfileStringA, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSection, CreateFileA, ReadFile, GetPrivateProfileIntA, GetCurrentProcessId, ProcessIdToSessionId, Sleep, OpenProcess, Process32First, Process32Next, CreateToolhelp32Snapshot, OutputDebugStringA, VirtualAllocEx, WriteProcessMemory, GetModuleHandleA, CreateEventW, GetCurrentProcess, DuplicateHandle, GetProcAddress, CreateRemoteThread, GetLastError, SetEvent, CloseHandle, VirtualFreeEx, FlushFileBuffers, WriteConsoleW, SetEndOfFile, Beep, RtlUnwind, HeapFree, HeapAlloc, GetSystemTimeAsFileTime, RaiseException, DecodePointer, EncodePointer, ResumeThread, GetModuleHandleW, ExitProcess, GetCommandLineA, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, IsProcessorFeaturePresent, HeapCreate, HeapDestroy, GetStdHandle, GetModuleFileNameW, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, WideCharToMultiByte, LCMapStringW, HeapSize, HeapReAlloc, InitializeCriticalSectionAndSpinCount, InterlockedExchange, LoadLibraryW, SetHandleCount, GetFileType, GetStartupInfoW, GetModuleFileNameA, FreeEnvironmentStringsW, GetEnvironmentStringsW, SetFilePointer, GetConsoleCP, GetConsoleMode, GetStringTypeW, SetStdHandle
Export table
LockDesk
LogOut
PCBoot
StopProcessAtWinLogoff
SwitchMe
SwitchWB
Sys
UnLockDesk