Import table
advapi32.dll
RegCreateKeyExW, GetTokenInformation, CreateProcessAsUserW, DuplicateTokenEx, SetTokenInformation, GetLengthSid, RegOpenKeyExA, RegQueryValueExA, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegSetValueExA, CryptAcquireContextW, CryptImportKey, CryptSetKeyParam, CryptEncrypt, CryptDestroyKey, CryptReleaseContext, CryptDecrypt, RegSetValueExW, RegQueryValueExW, RegOpenKeyExW, RegCloseKey, OpenProcessToken
kernel32.dll
FormatMessageA, ResumeThread, TlsFree, GetThreadTimes, TlsAlloc, ResetEvent, TlsSetValue, GetCurrentThread, TlsGetValue, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, GetCurrentThreadId, lstrlenA, CreateEventW, GetPrivateProfileStringA, GetCurrentProcessId, GetModuleFileNameW, GetLastError, WaitForSingleObject, SetEvent, CloseHandle, lstrlenW, WideCharToMultiByte, MultiByteToWideChar, GetFileAttributesExW, FlushFileBuffers, CreateFileW, ReadFile, SetFilePointerEx, OpenEventA, GetProcessHeap, HeapFree, GetSystemTimeAsFileTime, GetTickCount, QueryPerformanceCounter, IsDebuggerPresent, SetUnhandledExceptionFilter, UnhandledExceptionFilter, InterlockedCompareExchange, Sleep, InterlockedExchange, DecodePointer, EncodePointer, ProcessIdToSessionId, TerminateProcess, OpenProcess, Process32NextW, Process32FirstW, CreateToolhelp32Snapshot, WTSGetActiveConsoleSessionId, CreateEventA, OutputDebugStringW, CreateProcessW, LocalFree, GetCurrentProcess, GetLocalTime, WriteFile, CreateMutexW, FindNextChangeNotification, FindFirstChangeNotificationW, SetFileAttributesW, GetFileAttributesW, CreateDirectoryW, CreateMutexA, ReleaseMutex, ExpandEnvironmentStringsW, InterlockedDecrement, IsProcessorFeaturePresent
msvcp100.dll
DllMain
msvcr100.dll
DllMain
ole32.dll
CoInitializeEx, CoUninitialize, CoCreateGuid, CLSIDFromProgID, CoCreateInstance, CoSetProxyBlanket
rpcrt4.dll
RpcStringFreeW, UuidToStringW
user32.dll
DispatchMessageW, wsprintfW, MsgWaitForMultipleObjects, PeekMessageW
userenv.dll
CreateEnvironmentBlock
winmm.dll
timeGetTime
wtsapi32.dll
WTSQueryUserToken
Export table
doCleanup
getAllTasksList