Import table
advapi32.dll
RegCloseKey, DeleteService, QueryServiceStatus, ControlService, OpenServiceA, CloseServiceHandle, StartServiceA, ChangeServiceConfig2A, CreateServiceA, OpenSCManagerA, SetServiceStatus, GetUserNameA, CreateProcessAsUserA, SetTokenInformation, DuplicateTokenEx, RegOpenKeyExA, RevertToSelf, ImpersonateLoggedOnUser, OpenProcessToken, AdjustTokenPrivileges, LookupPrivilegeValueA, RegisterServiceCtrlHandlerExA, StartServiceCtrlDispatcherA, RegQueryValueExA, RegCreateKeyExA, RegCreateKeyA, RegDeleteKeyA, RegSetValueExA, RegOpenKeyA, RegDeleteValueA
kernel32.dll
CreateEventA, SetPriorityClass, Sleep, FindClose, FindNextFileA, CopyFileA, WriteFile, WaitNamedPipeA, WaitForSingleObject, SetEvent, FindFirstFileA, FreeLibrary, CreateFileW, LoadLibraryA, SetProcessWorkingSetSize, GetCurrentProcess, GetLastError, GetModuleFileNameA, CloseHandle, CreateFileA, GetModuleHandleA, GetProcAddress, LocalFree, GetProcessHeap, LocalAlloc, WriteConsoleW, SetStdHandle, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, CreateDirectoryA, GetSystemTimeAsFileTime, GetCommandLineA, HeapSetInformation, EncodePointer, DecodePointer, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, GetCPInfo, InterlockedIncrement, InterlockedDecrement, GetACP, GetOEMCP, IsValidCodePage, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, GetModuleHandleW, SetLastError, GetCurrentThreadId, GetCurrentThread, EnterCriticalSection, LeaveCriticalSection, ExitProcess, GetStdHandle, GetModuleFileNameW, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, SetHandleCount, InitializeCriticalSectionAndSpinCount, GetFileType, GetStartupInfoW, DeleteCriticalSection, HeapCreate, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, RaiseException, LCMapStringW, MultiByteToWideChar, GetStringTypeW, FatalAppExitA, GetUserDefaultLCID, GetLocaleInfoW, GetLocaleInfoA, EnumSystemLocalesA, IsValidLocale, RtlUnwind, IsProcessorFeaturePresent, SetFilePointer, GetConsoleCP, GetConsoleMode, SetConsoleCtrlHandler, InterlockedExchange, LoadLibraryW, FlushFileBuffers
shlwapi.dll
PathFileExistsA, SHDeleteKeyA
wtsapi32.dll
WTSQueryUserToken