Import table
advapi32.dll
DuplicateTokenEx, CreateProcessAsUserW, GetTokenInformation, OpenProcessToken, SetServiceStatus, RegisterServiceCtrlHandlerExW, RegCloseKey, RegOpenKeyExW, RegQueryValueExW, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, StartServiceCtrlDispatcherW, ConvertSidToStringSidW
kernel32.dll
MapViewOfFile, UnmapViewOfFile, Sleep, GetExitCodeProcess, FileTimeToSystemTime, CreateFileMappingW, FindNextChangeNotification, WTSGetActiveConsoleSessionId, GetFileTime, DeleteFileW, GetSystemTime, CreateThread, CreateProcessW, GetCurrentProcess, WriteFile, FindFirstChangeNotificationW, LocalFree, SetEndOfFile, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA, GetLocaleInfoA, GetPrivateProfileStringW, LocalAlloc, DisconnectNamedPipe, GetOverlappedResult, ReadFile, CreateNamedPipeW, ConnectNamedPipe, SetNamedPipeHandleState, CreateFileW, WaitNamedPipeW, CloseHandle, ReleaseMutex, WaitForMultipleObjects, CreateEventW, GetLocalTime, ResetEvent, SetLastError, GetLastError, GetTempPathW, WritePrivateProfileStringW, TerminateThread, SetEvent, WaitForSingleObject, CreateMutexW, GetTempFileNameW, GetStringTypeW, GetStringTypeA, LCMapStringW, LCMapStringA, FlushFileBuffers, ExitThread, GetCurrentThreadId, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsDebuggerPresent, HeapFree, HeapAlloc, GetVersionExA, GetProcessHeap, GetStartupInfoW, RaiseException, RtlUnwind, EnterCriticalSection, LeaveCriticalSection, GetProcAddress, GetModuleHandleA, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, InterlockedIncrement, InterlockedDecrement, ExitProcess, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, DeleteCriticalSection, HeapDestroy, HeapCreate, VirtualFree, VirtualAlloc, HeapReAlloc, GetModuleFileNameA, GetCPInfo, GetACP, GetOEMCP, HeapSize, GetModuleFileNameW, FreeEnvironmentStringsA, MultiByteToWideChar, GetEnvironmentStrings, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCommandLineA, GetCommandLineW, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, SetFilePointer, WideCharToMultiByte, GetConsoleCP, GetConsoleMode, LoadLibraryA, InitializeCriticalSection, CreateFileA, SetStdHandle
user32.dll
WaitForInputIdle
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
winspool.drv
FindFirstPrinterChangeNotification, ClosePrinter, EnumJobsW, GetJobW, OpenPrinterW, FindClosePrinterChangeNotification, FreePrinterNotifyInfo, FindNextPrinterChangeNotification, SetJobW
wtsapi32.dll
WTSQuerySessionInformationW, WTSEnumerateSessionsW, WTSFreeMemory, WTSQueryUserToken