Import table
advapi32.dll
CryptDecrypt, OpenProcessToken, GetTokenInformation, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, RegSetValueExW, RegSetValueExA, RegCreateKeyExW, CryptAcquireContextW, CryptReleaseContext, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, RegQueryValueExA, RegOpenKeyExA, CryptDestroyKey, CryptEncrypt, CryptSetKeyParam, CryptImportKey, GetLengthSid, SetTokenInformation, DuplicateTokenEx, CreateProcessAsUserW
crypt32.dll
CryptQueryObject, CryptMsgGetParam, CertFindCertificateInStore, CertGetNameStringW
kernel32.dll
GetPrivateProfileStringA, InterlockedDecrement, SetFilePointerEx, FlushFileBuffers, GetCurrentProcessId, GetModuleFileNameW, OutputDebugStringA, GetLocalTime, OpenEventA, GetProcessHeap, HeapFree, GetSystemTimeAsFileTime, lstrlenA, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, InterlockedCompareExchange, Sleep, InterlockedExchange, DecodePointer, EncodePointer, ProcessIdToSessionId, TerminateProcess, OpenProcess, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, WTSGetActiveConsoleSessionId, CreateEventA, LocalFree, GetCurrentProcess, WriteFile, CreateMutexW, FindNextChangeNotification, FindFirstChangeNotificationW, CreateDirectoryW, CreateMutexA, ReleaseMutex, ExpandEnvironmentStringsW, LocalAlloc, ReadFile, CreateFileW, GetFileAttributesExW, SetFileAttributesW, GetExitCodeThread, GetFileAttributesW, GetExitCodeProcess, SystemTimeToFileTime, CreateProcessW, GetSystemTime, OutputDebugStringW, FormatMessageA, GetLastError, lstrlenW, WideCharToMultiByte, GetTickCount, MultiByteToWideChar, CreateThread, ResumeThread, TlsFree, GetThreadTimes, InitializeCriticalSection, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, TlsGetValue, WaitForSingleObject, SetEvent, GetCurrentThread, TlsSetValue, ResetEvent, CreateEventW, GetCurrentThreadId, TlsAlloc, CloseHandle, IsProcessorFeaturePresent
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
CLSIDFromProgID, CoCreateGuid, CoCreateInstance, CoInitializeEx, CoUninitialize
rpcrt4.dll
RpcStringFreeW, UuidToStringW
shell32.dll
SHChangeNotify, SHGetSpecialFolderLocation, SHGetPathFromIDListW, SHGetMalloc, SHGetFolderPathW
user32.dll
wsprintfW
userenv.dll
CreateEnvironmentBlock
wininet.dll
InternetCheckConnectionW
winmm.dll
timeGetTime
wtsapi32.dll
WTSQueryUserToken
Export table
doCleanup
getAllTasksList