Import table
advapi32.dll
RegQueryValueExW, RegOpenKeyExW, RegCloseKey, DuplicateTokenEx, ConvertSidToStringSidW, CreateProcessAsUserW, GetLengthSid, SetTokenInformation, GetTokenInformation
crypt32.dll
CertGetNameStringW, CertFindCertificateInStore, CryptMsgGetParam, CryptQueryObject
kernel32.dll
GetCurrentProcessId, HeapFree, GetProcessHeap, HeapAlloc, WTSGetActiveConsoleSessionId, GetModuleFileNameW, GetLastError, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, CloseHandle, GetCurrentProcess, TerminateProcess, InterlockedCompareExchange, Sleep, InterlockedExchange, DecodePointer, EncodePointer, LocalAlloc, FormatMessageA, ResumeThread, TlsFree, GetThreadTimes, TlsAlloc, GetCurrentThreadId, CreateEventW, ResetEvent, TlsSetValue, GetCurrentThread, SetEvent, WaitForSingleObject, TlsGetValue, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, lstrlenW, WideCharToMultiByte, GetSystemTimeAsFileTime, LocalFree, GetTickCount, UnhandledExceptionFilter
msvcp100.dll
DllMain
msvcr100.dll
DllMain
userenv.dll
CreateEnvironmentBlock
wtsapi32.dll
WTSQueryUserToken
Export table
doCleanup
getAllTasksList