Import table
advapi32.dll
TraceMessage, RegCloseKey, RegOpenKeyExW, RegCreateKeyExW, ConvertSecurityDescriptorToStringSecurityDescriptorW, IsTextUnicode, InitializeAcl, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, OpenThreadToken, GetSecurityDescriptorLength, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, CloseServiceHandle, GetLengthSid, AuditComputeEffectivePolicyBySid, AuditQuerySystemPolicy, AuditFree, OpenTraceW, ProcessTrace, CloseTrace, StartTraceW, EnableTraceEx, ControlTraceW, RegQueryValueExW, RegDeleteValueW, RegSetValueExW, RegEnumValueW, CopySid, LookupAccountSidW, PerfStartProvider, PerfSetULongCounterValue, PerfSetCounterSetInfo, PerfCreateInstance, PerfStopProvider, GetSecurityDescriptorControl, SetSecurityDescriptorControl, SetPrivateObjectSecurityEx, GetPrivateObjectSecurity, PrivilegeCheck, MapGenericMask, DestroyPrivateObjectSecurity, CreatePrivateObjectSecurityEx, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegisterServiceCtrlHandlerExW, SetServiceStatus, UnregisterTraceGuids, RegisterTraceGuidsA, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegQueryInfoKeyW, RegOpenKeyTransactedW, RegCreateKeyTransactedW, EqualSid
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, SetLastError, GetLastError
api-ms-win-core-file-l1-1-1.dll
CreateFileW, FileTimeToSystemTime
api-ms-win-core-file-l1-2-0.dll
CreateFileW
api-ms-win-core-file-l1-2-1.dll
CreateFileW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-1-0.dll
HeapReAlloc, HeapDestroy, HeapSize, HeapCreate, HeapFree, HeapAlloc, GetProcessHeap
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, GetProcessHeap, HeapFree, HeapSize, HeapReAlloc, HeapDestroy, HeapCreate
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc, LocalFree
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange64, InterlockedExchangeAdd, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, InterlockedExchange
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedIncrement, InterlockedCompareExchange64, InterlockedExchange, InterlockedExchangeAdd, InterlockedDecrement, InterlockedCompareExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedExchange, InterlockedCompareExchange64, InterlockedExchangeAdd, InterlockedCompareExchange, InterlockedDecrement
api-ms-win-core-kernel32-legacy-l1-1-0.dll
CreateFileMappingA, QueryFullProcessImageNameW
api-ms-win-core-libraryloader-l1-1-0.dll
DisableThreadLibraryCalls, FreeLibrary, LoadLibraryExA, LoadStringW, GetModuleHandleExW, GetProcAddress
api-ms-win-core-libraryloader-l1-1-1.dll
LoadStringW, DisableThreadLibraryCalls, GetModuleHandleExW, GetProcAddress
api-ms-win-core-libraryloader-l1-2-0.dll
LoadStringW, GetModuleHandleExW, DisableThreadLibraryCalls, GetProcAddress
api-ms-win-core-localization-l1-1-1.dll
LoadStringByReference
api-ms-win-core-memory-l1-1-1.dll
UnmapViewOfFile, MapViewOfFile, CreateFileMappingW
api-ms-win-core-memory-l1-1-2.dll
MapViewOfFile, CreateFileMappingW, UnmapViewOfFile
api-ms-win-core-processenvironment-l1-1-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-1-1.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll
TlsSetValue, TlsAlloc, GetProcessId, OpenProcess, GetCurrentProcessId, TlsFree, TlsGetValue, CreateThread, TerminateProcess, GetCurrentThreadId, GetCurrentThread, OpenThreadToken, GetCurrentProcess, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
TlsAlloc, TlsFree, GetProcessId, CreateThread, GetCurrentProcessId, TlsSetValue, TlsGetValue, OpenThreadToken, GetCurrentThreadId, GetCurrentThread, TerminateProcess, OpenProcess, GetCurrentProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
QueryFullProcessImageNameW
api-ms-win-core-registry-l1-1-0.dll
RegEnumValueW, RegQueryInfoKeyW, RegDeleteValueW, RegCloseKey, RegOpenKeyExW, RegCreateKeyExW, RegQueryValueExW, RegSetValueExW
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
SHLoadIndirectString
api-ms-win-core-string-l1-1-0.dll
CompareStringW, MultiByteToWideChar, WideCharToMultiByte
api-ms-win-core-synch-l1-1-1.dll
Sleep, DeleteCriticalSection, WaitForSingleObject, CreateSemaphoreExW, CreateEventW, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, SetEvent, EnterCriticalSection, InitializeSRWLock, AcquireSRWLockExclusive, ReleaseSRWLockExclusive, AcquireSRWLockShared, ReleaseSRWLockShared, ReleaseSemaphore
api-ms-win-core-synch-l1-2-0.dll
ReleaseSemaphore, DeleteCriticalSection, CreateSemaphoreExW, CreateEventW, ReleaseSRWLockShared, SetEvent, EnterCriticalSection, AcquireSRWLockShared, LeaveCriticalSection, InitializeCriticalSectionAndSpinCount, ReleaseSRWLockExclusive, Sleep, AcquireSRWLockExclusive, InitializeSRWLock, WaitForSingleObject
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTime, GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTime, GetTickCount64, GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTime, GetTickCount, GetSystemTimeAsFileTime, GetTickCount64
api-ms-win-core-threadpool-l1-1-1.dll
SetThreadpoolTimer, RegisterWaitForSingleObjectEx, WaitForThreadpoolTimerCallbacks, UnregisterWaitEx, CreateThreadpoolTimer, CloseThreadpoolTimer, DeleteTimerQueueTimer, CreateTimerQueueTimer, DeleteTimerQueueEx, CreateTimerQueue
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolTimer, WaitForThreadpoolTimerCallbacks, CloseThreadpoolTimer, CreateThreadpoolTimer
api-ms-win-core-threadpool-legacy-l1-1-0.dll
DeleteTimerQueueEx, CreateTimerQueue, UnregisterWaitEx, DeleteTimerQueueTimer, CreateTimerQueueTimer
api-ms-win-core-threadpool-private-l1-1-0.dll
RegisterWaitForSingleObjectEx
api-ms-win-core-timezone-l1-1-0.dll
FileTimeToSystemTime
api-ms-win-core-util-l1-1-0.dll
EncodePointer, DecodePointer
api-ms-win-eventing-consumer-l1-1-0.dll
CloseTrace, OpenTraceW, ProcessTrace
api-ms-win-eventing-controller-l1-1-0.dll
StartTraceW, EnableTraceEx2, ControlTraceW
api-ms-win-eventing-provider-l1-1-0.dll
EventWriteTransfer
api-ms-win-legacy-kernel32-l1-1-0.dll
CreateFileMappingA, QueryFullProcessImageNameW
api-ms-win-obsolete-kernelbase-l1-1-0.dll
LocalFree, LocalAlloc
api-ms-win-obsolete-shlwapi-l1-1-0.dll
SHLoadIndirectString, StrDupW, StrStrIW, StrChrW
api-ms-win-security-base-l1-1-0.dll
CreatePrivateObjectSecurityEx, DestroyPrivateObjectSecurity, PrivilegeCheck, GetSecurityDescriptorControl, SetSecurityDescriptorControl, SetPrivateObjectSecurityEx, GetLengthSid, CopySid, EqualSid, GetPrivateObjectSecurity, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, MapGenericMask, GetSecurityDescriptorLength, InitializeAcl, AddAccessAllowedAce, CreateWellKnownSid, AllocateAndInitializeSid, FreeSid
api-ms-win-security-base-l1-2-0.dll
EqualSid, GetLengthSid, CopySid, AllocateAndInitializeSid, FreeSid, InitializeAcl, PrivilegeCheck, AddAccessAllowedAce, MapGenericMask, SetPrivateObjectSecurityEx, SetSecurityDescriptorControl, GetSecurityDescriptorControl, GetPrivateObjectSecurity, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, GetSecurityDescriptorLength, CreatePrivateObjectSecurityEx, DestroyPrivateObjectSecurity, CreateWellKnownSid
authz.dll
AuthzFreeResourceManager, AuthzInitializeContextFromSid, AuthzInitializeResourceManager, AuthziFreeAuditEventType, AuthzFreeAuditEvent, AuthziLogAuditEvent, AuthziInitializeAuditEvent, AuthziInitializeAuditParamsFromArray, AuthziInitializeAuditEventType, AuthzGetInformationFromContext, AuthzFreeContext, AuthzAccessCheck
dnsapi.dll
DnsValidateName_W
kernel32.dll
CompareStringW, InterlockedIncrement, InterlockedDecrement, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, InterlockedCompareExchange64, GetTickCount, QueryPerformanceCounter, CreateTimerQueueTimer, DeleteTimerQueueTimer, DeleteTimerQueueEx, CreateTimerQueue, CreateSemaphoreW, InterlockedExchange, ReleaseSemaphore, WaitForSingleObject, CreateFileW, Sleep, GetCurrentThread, TlsAlloc, TlsGetValue, TlsSetValue, GetCurrentProcessId, ExpandEnvironmentStringsW, CreateThread, RegCreateKeyExW, RegOpenKeyExW, RegCloseKey, RegQueryInfoKeyW, RegSetValueExW, RegDeleteValueW, RegQueryValueExW, RegEnumValueW, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, UnregisterWaitEx, RegisterWaitForSingleObject, InterlockedExchangeAdd, GetCurrentThreadId, HeapCreate, TlsFree, EncodePointer, LocalAlloc, LocalFree, GetCurrentProcess, GetProcessId, WideCharToMultiByte, MultiByteToWideChar, HeapFree, HeapAlloc, HeapReAlloc, HeapDestroy, CreateEventW, UnregisterWait, CloseHandle, DecodePointer, SetEvent, InterlockedCompareExchange, GetLastError, DelayLoadFailureHook, LoadLibraryA, FreeLibrary, GetProcAddress, DisableThreadLibraryCalls, GetModuleHandleExW
msvcrt.dll
DllMain
ntdll.dll
EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, EtwTraceMessage, RtlNtStatusToDosError, EtwEventRegister, EtwEventUnregister, EtwEventActivityIdControl, EtwEventWrite, RtlInsertEntryHashTable, RtlGetNextEntryHashTable, RtlLookupEntryHashTable, RtlRemoveEntryHashTable, RtlEndEnumerationHashTable, RtlEnumerateEntryHashTable, RtlInitEnumerationHashTable, RtlDeleteHashTable, RtlCreateHashTable, RtlIpv4AddressToStringA, RtlIpv6AddressToStringA, RtlEthernetAddressToStringA, RtlGetSaclSecurityDescriptor, RtlValidRelativeSecurityDescriptor, RtlValidSid, NtQueryObject, RtlSetThreadPreferredUILanguages, RtlContractHashTable, RtlExpandHashTable, RtlAdjustPrivilege, RtlIpv4AddressToStringW, RtlIpv6AddressToStringW, RtlIntegerToUnicodeString, EtwEventEnabled, RtlLengthSecurityDescriptor, RtlEqualSid, TpSetTimer, TpWaitForTimer, TpIsTimerSet, RtlCreateServiceSid, RtlInitUnicodeString, TpReleaseTimer, TpAllocTimer, RtlAbsoluteToSelfRelativeSD, RtlSetOwnerSecurityDescriptor, RtlSelfRelativeToAbsoluteSD2, RtlGetOwnerSecurityDescriptor, RtlAllocateHeap, NtDeviceIoControlFile, WinSqmAddToStream, WinSqmSetDWORD, WinSqmIsOptedIn, RtlLengthSid, RtlNumberOfSetBits, RtlInitializeBitMap, RtlGetCurrentTransaction, RtlSetCurrentTransaction, DbgBreakPoint, RtlFreeUnicodeString, RtlConvertSidToUnicodeString, RtlFreeHeap, RtlApplicationVerifierStop, RtlSubAuthorityCountSid, NtCreateTransaction
rpcrt4.dll
RpcBindingVectorFree, MesHandleFree, NdrMesTypeDecode2, NdrMesTypeEncode2, RpcRaiseException, RpcServerUseProtseqW, RpcServerRegisterIfEx, RpcServerInqBindings, RpcEpRegisterW, RpcFreeAuthorizationContext, RpcGetAuthorizationContextForClient, RpcImpersonateClient, RpcRevertToSelf, RpcEpUnregister, UuidFromStringW, RpcServerUnregisterIfEx, UuidCreate, RpcServerInqCallAttributesW, NdrServerCall2, I_RpcExceptionFilter, MesEncodeDynBufferHandleCreate, MesDecodeBufferHandleCreate, NdrMesTypeFree2, RpcServerRegisterIf3, I_RpcBindingInqLocalClientPID
secur32.dll
LsaRegisterPolicyChangeNotification, LsaUnregisterPolicyChangeNotification
slc.dll
SLGetWindowsInformationDWORD
Export table
BfeGetDirectDispatchTable
BfeOnServiceStartTypeChange
BfeServiceMain
SvchostPushServiceGlobals