Import table
advapi32.dll
OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges
kernel32.dll
GetVersionExW, GetShortPathNameW, lstrlenW, InterlockedDecrement, InterlockedIncrement, GetLastError, HeapFree, HeapAlloc, GetCurrentThreadId, GetCommandLineA, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, RaiseException, GetCPInfo, GetACP, GetOEMCP, IsValidCodePage, GetModuleHandleW, GetProcAddress, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, HeapCreate, HeapDestroy, VirtualFree, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, VirtualAlloc, HeapReAlloc, Sleep, ExitProcess, WriteFile, GetStdHandle, GetModuleFileNameA, SetHandleCount, GetFileType, GetStartupInfoA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, HeapSize, SetFilePointer, GetConsoleCP, GetConsoleMode, MultiByteToWideChar, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, GetModuleHandleA, InitializeCriticalSectionAndSpinCount, RtlUnwind, LoadLibraryA, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, CloseHandle, FlushFileBuffers, DeleteFileW, SetFileAttributesW, GetModuleFileNameW, lstrlenA, GetFileSize, CreateFileW, GetLocalTime, SetCurrentDirectoryW, GetCurrentDirectoryW, SetErrorMode, GetExitCodeProcess, WaitForSingleObject, FindClose, FindFirstFileW, OpenProcess, QueryDosDeviceW
psapi.dll
GetModuleFileNameExW, GetProcessImageFileNameW, EnumProcesses
shell32.dll
ShellExecuteExW, ShellExecuteW
user32.dll
FindWindowW, GetTopWindow, GetParent, GetWindowThreadProcessId, GetWindow, GetForegroundWindow, PostMessageW, WaitForInputIdle, SetFocus, GetWindowLongW, AttachThreadInput, SetForegroundWindow, SetWindowPos, BringWindowToTop, IsIconic, IsHungAppWindow, ShowWindow, mouse_event, GetSystemMetrics, GetCursorPos, IsWindow, GetWindowTextW, GetClassNameW, SendInput
Export table
CreateInstance
DeleteInstance