Import table
advapi32.dll
CryptDestroyHash, CryptDestroyKey, RegDeleteKeyW, RegDeleteValueW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW, RegSetValueExW, RegQueryInfoKeyW, MakeAbsoluteSD, ConvertStringSecurityDescriptorToSecurityDescriptorW, DeregisterEventSource, ReportEventW, RegisterEventSourceW, SetServiceStatus, CloseServiceHandle, OpenServiceW, OpenSCManagerW, RegEnumKeyExW, CreateServiceW, DeleteService, ControlService, RegisterServiceCtrlHandlerExW, StartServiceCtrlDispatcherW, SetThreadToken, GetTokenInformation, OpenThreadToken, CheckTokenMembership, CryptGetUserKey, LookupAccountNameW, AllocateAndInitializeSid, GetLengthSid, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, CryptGetKeyParam, CryptDeriveKey, CryptVerifySignatureW, CryptSignHashW, FreeSid, CredWriteDomainCredentialsW, CreateProcessAsUserW, CredReadW, CryptImportKey, CryptExportKey, RegQueryValueExA, RegEnumValueA, OpenProcessToken, EqualSid, GetSidSubAuthorityCount, GetSidLengthRequired, GetSidIdentifierAuthority, InitializeSid, GetSidSubAuthority, CryptCreateHash, CryptDuplicateKey, CryptSetHashParam, CryptGetHashParam, CryptHashData, IsValidSid, ConvertStringSidToSidW, IsWellKnownSid, CryptAcquireContextA, CryptGenKey, RegEnumValueW, CredEnumerateW, CredWriteW, CredDeleteW, CredFree, ConvertSidToStringSidW, CryptDecrypt, CryptEncrypt, RegOpenCurrentUser, DuplicateToken, ImpersonateLoggedOnUser, SetTokenInformation, RevertToSelf, CryptGetProvParam, CryptContextAddRef, CryptGenRandom, CryptReleaseContext, CryptAcquireContextW, GetAce, GetAclInformation, AddAccessAllowedAce, AddAce, SetNamedSecurityInfoW, InitializeAcl, GetSecurityDescriptorDacl, GetFileSecurityW, InitializeSecurityDescriptor, AccessCheck, IsValidSecurityDescriptor, CryptSetProvParam
crypt32.dll
CertFreeCertificateChain, CryptSignMessage, CertGetNameStringA, CryptUnprotectData, CryptProtectData, CryptExportPublicKeyInfo, CryptEncodeObjectEx, CryptSignAndEncodeCertificate, CertSetCertificateContextProperty, CertGetIssuerCertificateFromStore, CertEnumCertificatesInStore, CertCompareCertificate, CertDuplicateCertificateContext, CertGetCertificateContextProperty, CertAddCertificateContextToStore, CertOpenStore, CertFindCertificateInStore, CertDeleteCertificateFromStore, CertCloseStore, CertGetNameStringW, CryptAcquireCertificatePrivateKey, CertCreateCertificateContext, CertVerifySubjectCertificateContext, CertFreeCertificateContext, CryptVerifyMessageSignature, CertVerifyCertificateChainPolicy, CryptImportPublicKeyInfo, CertGetCertificateChain
iphlpapi.dll
CancelIPChangeNotify, NotifyAddrChange
kernel32.dll
GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, FlushFileBuffers, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, GetTimeZoneInformation, CreateFileA, CompareStringA, CompareStringW, SetEnvironmentVariableA, GetSystemInfo, lstrcmpA, CreateFileW, WaitForMultipleObjects, LoadLibraryW, DeleteFileW, GetFileSize, ReadFile, CreateMutexW, ExpandEnvironmentStringsW, ReleaseMutex, ResetEvent, GetComputerNameW, lstrlenW, CreateProcessW, lstrlenA, SetEndOfFile, GetLocalTime, FileTimeToLocalFileTime, FileTimeToSystemTime, GetUserDefaultLCID, GetDateFormatA, GetTimeFormatA, OutputDebugStringW, GlobalAlloc, GlobalFree, EnumResourceNamesW, CreateDirectoryExW, GetSystemDefaultLangID, SetThreadLocale, GetFileAttributesExW, FindFirstFileW, TryEnterCriticalSection, LockResource, LoadResource, FindResourceW, FindResourceExW, GetLastError, GetSystemTimeAsFileTime, GetConsoleMode, GetConsoleCP, SetFilePointer, IsValidCodePage, GetOEMCP, GetCPInfo, LoadLibraryA, VirtualAlloc, IsDebuggerPresent, UnhandledExceptionFilter, TerminateProcess, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, VirtualFree, HeapCreate, SetLastError, TlsFree, TlsSetValue, FindNextFileW, FindClose, InterlockedIncrement, InterlockedDecrement, TlsAlloc, RaiseException, TlsGetValue, GetStartupInfoA, GetFileType, SetHandleCount, GetCommandLineA, GetEnvironmentStringsW, FreeEnvironmentStringsW, GetEnvironmentStrings, FreeEnvironmentStringsA, GetModuleFileNameA, GetStdHandle, WriteFile, CloseHandle, lstrcmpiW, LocalFree, SetCurrentDirectoryW, GetCurrentDirectoryW, EnterCriticalSection, LocalAlloc, WaitForSingleObject, GetModuleFileNameW, Sleep, GetModuleHandleW, GetCurrentThreadId, CreateThread, CreateEventW, SetEvent, FreeLibrary, MultiByteToWideChar, LoadLibraryExW, GetProcessHandleCount, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, SizeofResource, ExitProcess, GetModuleHandleA, CopyFileW, GetProcAddress, SetUnhandledExceptionFilter, RtlUnwind, GetStartupInfoW, HeapSize, HeapReAlloc, HeapFree, HeapAlloc, HeapDestroy, GetVersionExA, GetThreadLocale, GetLocaleInfoA, GetACP, InterlockedExchange, CreateTimerQueueTimer, DeleteTimerQueueEx, GetCurrentThread, WideCharToMultiByte, GetProcessHeap, HeapSetInformation, GetCommandLineW, CreateTimerQueue, GetCurrentProcess, GetVersionExW
netapi32.dll
NetUserModalsGet, NetApiBufferFree
ntdsapi.dll
DsUnBindW, DsCrackNamesW, DsFreeNameResultW, DsBindW
ole32.dll
IIDFromString, CreateStreamOnHGlobal, CoTaskMemRealloc, CoUninitialize, CoInitializeEx, CoRevokeClassObject, CoRegisterClassObject, CoTaskMemFree, CoTaskMemAlloc, CoInitializeSecurity, CLSIDFromProgID, CoSuspendClassObjects, StringFromGUID2, CoCreateInstance, CoResumeClassObjects, PropVariantClear, CoImpersonateClient, CoRevertToSelf, CoSetProxyBlanket
psapi.dll
GetProcessMemoryInfo
rpcrt4.dll
RpcServerUnregisterIf, RpcRevertToSelf, NdrServerCall2, RpcServerUseProtseqEpW, RpcStringFreeW, RpcServerRegisterIf, RpcImpersonateClient, I_RpcBindingInqLocalClientPID, UuidCreate, UuidToStringA, RpcStringFreeA, UuidToStringW, RpcServerListen, RpcMgmtStopServerListening
secur32.dll
GetUserNameExW
sensapi.dll
IsNetworkAlive
shell32.dll
SHGetFolderPathW, SHFileOperationW, SHGetSpecialFolderPathW, SHCreateDirectoryExW
shlwapi.dll
PathIsDirectoryW, PathFileExistsW, SHStrDupW, PathCombineW
sqmapi.dll
SqmAddToStreamDWord, SqmSet, SqmEndSession, SqmStartSession, SqmStartUpload, SqmSetAppVersion, SqmSetMachineId, SqmWriteSharedMachineId, SqmCreateNewId, SqmReadSharedMachineId, SqmGetSession, SqmSetAppId, SqmAddToStreamString
user32.dll
LoadStringA, LoadStringW, TranslateMessage, UnregisterClassA, PostThreadMessageW, GetMessageW, CharUpperW, MessageBoxW, DispatchMessageW, CharNextW
userenv.dll
UnloadUserProfile, CreateEnvironmentBlock, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
winhttp.dll
WinHttpGetIEProxyConfigForCurrentUser, WinHttpGetProxyForUrl, WinHttpCreateUrl, WinHttpConnect, WinHttpOpenRequest, WinHttpSetOption, WinHttpSendRequest, WinHttpOpen, WinHttpSetTimeouts, WinHttpQueryHeaders, WinHttpQueryAuthSchemes, WinHttpQueryDataAvailable, WinHttpReadData, WinHttpAddRequestHeaders, WinHttpCloseHandle, WinHttpCrackUrl, WinHttpReceiveResponse
wininet.dll
InternetSetCookieW
wintrust.dll
WinVerifyTrustEx, WTHelperGetProvSignerFromChain, WTHelperProvDataFromStateData
ws2_32.dll
WSACloseEvent, WSACreateEvent
wtsapi32.dll
WTSFreeMemory, WTSEnumerateSessionsW, WTSQueryUserToken