Import table
advapi32.dll
SetServiceStatus, DeregisterEventSource, ReportEventW, RegisterEventSourceW, RegisterServiceCtrlHandlerExW
api-ms-win-core-debug-l1-1-0.dll
OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
SetUnhandledExceptionFilter, GetLastError, UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
GetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter
api-ms-win-core-file-l1-1-0.dll
CreateFileW, GetFileAttributesW, GetDriveTypeW, GetFinalPathNameByHandleW
api-ms-win-core-file-l1-1-1.dll
CreateFileW, GetDriveTypeW, GetFinalPathNameByHandleW, GetFileAttributesW
api-ms-win-core-file-l1-2-0.dll
GetDriveTypeW, GetFileAttributesW, GetFinalPathNameByHandleW, CreateFileW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedIncrement, InterlockedCompareExchange64, InterlockedDecrement, InterlockedCompareExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedDecrement, InterlockedIncrement, InterlockedCompareExchange64
api-ms-win-core-processthreads-l1-1-0.dll
GetCurrentProcess, GetCurrentProcessId, GetProcessId, GetCurrentThreadId, TerminateProcess
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentThreadId, TerminateProcess, GetCurrentProcess, GetProcessId, GetCurrentProcessId
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegGetValueW
api-ms-win-core-sysinfo-l1-1-0.dll
GetSystemTimeAsFileTime, GetSystemInfo, GetTickCount
api-ms-win-core-sysinfo-l1-1-1.dll
GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-threadpool-l1-1-0.dll
CloseThreadpool, CreateThreadpool, UnregisterWaitEx, CloseThreadpoolWork, SubmitThreadpoolWork, CreateThreadpoolWork, SetThreadpoolThreadMinimum, CloseThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, SetThreadpoolThreadMaximum, CreateThreadpoolCleanupGroup
api-ms-win-core-threadpool-l1-1-1.dll
CloseThreadpoolWork, SetThreadpoolThreadMaximum, CreateThreadpoolCleanupGroup, SetThreadpoolThreadMinimum, CreateThreadpoolWork, CloseThreadpool, CloseThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, SubmitThreadpoolWork, UnregisterWaitEx, CreateThreadpool
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolThreadMaximum, SetThreadpoolThreadMinimum, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, CloseThreadpoolCleanupGroup, CloseThreadpool, SubmitThreadpoolWork, CreateThreadpoolWork, CloseThreadpoolWork, CreateThreadpool
api-ms-win-security-sddl-l1-1-0.dll
ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
apphelp.dll
ApphelpCheckRunApp, ApphelpCheckRunAppEx, ApphelpDebugPrintf
kernel32.dll
DelayLoadFailureHook, FreeLibrary, LoadLibraryExA, SetEndOfFile, SetFilePointer, WriteFile, ExpandEnvironmentStringsW, HeapAlloc, LocalFree, GetProcessHeap, HeapFree, CompareStringW, Sleep, lstrcmpiW, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, GetFileSize, GetProcAddress, GetSystemTimeAsFileTime, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetProcessId, TerminateProcess, CreateFileW, InterlockedCompareExchange64, GetSystemInfo, UnregisterWait, OutputDebugStringA, GetLastError, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCurrentProcessId, GetVolumePathNameW, DisableThreadLibraryCalls, GetModuleHandleW, CreateActCtxW, QueryActCtxW, ReleaseActCtx, FindFirstFileW, SetErrorMode, SetFilePointerEx, ReadFile, GetFileTime, VirtualQuery, GetFileSizeEx, GetFileInformationByHandle, GetVolumeNameForVolumeMountPointW, GetVolumeInformationW, CompareStringA, LocalAlloc, SetLastError, IsDBCSLeadByte, LoadLibraryExW, lstrlenA, VirtualProtect, VirtualAlloc, GetLongPathNameW, VirtualFree, OutputDebugStringW, GetEnvironmentVariableW, FindNextFileW, FindClose, UnregisterWaitEx, GetSystemWindowsDirectoryW, GetBinaryTypeW, CreateMutexW, WaitForSingleObject, ReleaseMutex, GetFileAttributesExW, PackageIdFromFullName, CompareFileTime, GetModuleFileNameW, InterlockedCompareExchange
kernelbase.dll
ResolveDelayLoadedAPI
msvcrt.dll
DllMain
ntdll.dll
ZwClose, NtCreateEvent, RtlCreateUserThread, AlpcGetMessageAttribute, NtAlpcCancelMessage, RtlExitUserThread, NtAlpcOpenSenderProcess, RtlDosPathNameToRelativeNtPathName_U, RtlReleaseRelativeName, RtlFreeUnicodeString, RtlCreateHeap, NtWaitForSingleObject, AlpcInitializeMessageAttribute, NtAlpcAcceptConnectPort, NtAlpcCreatePort, RtlAllocateAndInitializeSid, RtlLengthSid, RtlCreateSecurityDescriptor, RtlCreateAcl, RtlAddAccessAllowedAce, RtlSetDaclSecurityDescriptor, RtlFreeSid, NtOpenKey, RtlDestroyHeap, NtResumeThread, NtSetInformationFile, NtQueryInformationFile, EtwTraceMessage, NtAlpcSendWaitReceivePort, RtlInitUnicodeString, NtApphelpCacheControl, AlpcMaxAllowedMessageLength, NtQueryValueKey, RtlFreeHeap, RtlAllocateHeap, RtlInitializeCriticalSectionAndSpinCount, RtlDeleteCriticalSection, NtSetEvent, RtlEnterCriticalSection, RtlLeaveCriticalSection, NtClose, NtQuerySystemInformation, NtDelayExecution, NtResetEvent, NtWaitForMultipleObjects, NtTerminateThread, RtlUnwind, _vsnprintf, memset, memcpy, RtlValidateHeap, RtlSizeHeap, RtlAdjustPrivilege, RtlNtStatusToDosError, RtlCheckTokenMembership, NtOpenFile, EtwEventUnregister, EtwEventRegister, EtwEventWrite, RtlGetVersion, RtlImageRvaToVa, RtlImageDirectoryEntryToData, RtlAppendUnicodeToString, RtlAppendUnicodeStringToString, DbgPrintEx, RtlFormatCurrentUserKeyPath, RtlDowncaseUnicodeString, NlsMbCodePageTag, NtQueryKey, NtEnumerateValueKey, RtlExpandEnvironmentStrings_U, RtlAnsiStringToUnicodeString, NtMapViewOfSection, RtlInitAnsiString, RtlInitString, LdrGetDllHandle, NtQueryInformationProcess, NtQueryDirectoryFile, NtUnmapViewOfSection, RtlQueryEnvironmentVariable_U, RtlxAnsiStringToUnicodeSize, NtCreateFile, RtlGetNativeSystemInformation, RtlUnicodeStringToInteger, RtlDoesFileExists_U, RtlGetFullPathName_U, NtCreateSection, LdrGetProcedureAddressEx, RtlDosPathNameToNtPathName_U, RtlUnicodeStringToAnsiString, RtlFreeAnsiString, LdrResSearchResource, LdrResFindResource, RtlUpcaseUnicodeString, RtlCopyUnicodeString, RtlUpcaseUnicodeChar, RtlUpcaseUnicodeToMultiByteN, RtlGUIDFromString, RtlInitializeCriticalSection, EtwEventWriteNoRegistration, RtlCreateUnicodeString, RtlInitUnicodeStringEx, NtFreeVirtualMemory, NtAllocateVirtualMemory, NtProtectVirtualMemory, NtQueryVirtualMemory
Export table
ServiceMain
SvchostPushServiceGlobals