Import table
advapi32.dll
RegNotifyChangeKeyValue, ConvertStringSidToSidW, LookupAccountSidW, ConvertSidToStringSidW, GetTokenInformation, EqualSid, CheckTokenMembership, FreeSid, AllocateAndInitializeSid, RegisterEventSourceW, SetThreadToken, OpenThreadToken, OpenProcessToken, SetServiceStatus, AdjustTokenPrivileges, LookupPrivilegeValueW, RegGetValueW, ConvertStringSecurityDescriptorToSecurityDescriptorW, RegCloseKey, SetNamedSecurityInfoW, GetSecurityDescriptorDacl, RegCreateKeyExW, RegisterServiceCtrlHandlerW, RegUnLoadKeyW, RegLoadKeyW, RegOpenKeyExW, RegQueryValueExW, RegDeleteTreeW, RegEnumKeyExW, RegSetKeyValueW, RegDeleteValueW, RegEnumValueW, RegSetValueExW, RegQueryInfoKeyW, DeregisterEventSource, ReportEventW, GetLengthSid, CryptReleaseContext, CryptGenRandom, CryptAcquireContextW
api-ms-win-core-com-l1-1-0.dll
StringFromGUID2, CoGetObjectContext, CoRegisterClassObject, FreePropVariantArray, CLSIDFromString, PropVariantClear, CoCancelCall, CoUninitialize, CoSetProxyBlanket, CoCreateInstance, CoEnableCallCancellation, CoUnmarshalInterface, CoMarshalInterface, CoInitializeEx, CoDisableCallCancellation, StringFromCLSID, CoDisconnectContext, CoTaskMemFree, IIDFromString, CoRevertToSelf, CoReleaseMarshalData, CoImpersonateClient, CoRevokeClassObject, CoTaskMemAlloc, CreateStreamOnHGlobal, CoGetClassObject, PropVariantCopy, CoCreateGuid, CoCopyProxy
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringW, IsDebuggerPresent, DebugBreak, OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, GetLastError, RaiseException, SetUnhandledExceptionFilter
api-ms-win-core-file-l1-1-0.dll
GetFileAttributesW
api-ms-win-core-file-l1-1-1.dll
FindClose, CreateDirectoryW, FindNextFileW, DeleteFileW, SetFileAttributesW, GetFileAttributesW, FindFirstFileW
api-ms-win-core-file-l1-2-0.dll
FindClose, CreateDirectoryW, SetFileAttributesW, FindNextFileW, FindFirstFileW, GetFileAttributesW, DeleteFileW
api-ms-win-core-file-l1-2-1.dll
DeleteFileW, GetFileAttributesW, CreateDirectoryW, SetFileAttributesW, FindClose, FindNextFileW, FindFirstFileW
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-obsolete-l1-1-0.dll
GlobalFree, GlobalUnlock, GlobalAlloc, GlobalLock, LocalFree, LocalAlloc
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedDecrement, InterlockedCompareExchange, InterlockedExchange, InterlockedIncrement
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedCompareExchange64, InterlockedExchangeAdd, InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, InterlockedExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedDecrement, InterlockedCompareExchange, InterlockedExchange, InterlockedExchangeAdd, InterlockedIncrement, InterlockedCompareExchange64
api-ms-win-core-io-l1-1-1.dll
CreateIoCompletionPort, GetQueuedCompletionStatus, PostQueuedCompletionStatus
api-ms-win-core-kernel32-legacy-l1-1-0.dll
GetComputerNameW
api-ms-win-core-kernel32-legacy-l1-1-1.dll
GetComputerNameW
api-ms-win-core-libraryloader-l1-1-0.dll
LoadLibraryExW, GetProcAddress, LoadLibraryExA, DisableThreadLibraryCalls, FreeLibrary
api-ms-win-core-libraryloader-l1-1-1.dll
FindResourceExW, LoadResource, LoadStringW, LockResource, FreeLibraryAndExitThread, GetProcAddress, GetModuleFileNameW, GetModuleHandleExW, GetModuleHandleW, FreeLibrary, LoadLibraryExW, DisableThreadLibraryCalls
api-ms-win-core-libraryloader-l1-2-0.dll
FindResourceExW, LoadLibraryExW, LoadStringW, GetModuleFileNameW, LoadResource, GetModuleHandleExW, LockResource, DisableThreadLibraryCalls, FreeLibrary, FreeLibraryAndExitThread, GetProcAddress, GetModuleHandleW
api-ms-win-core-localization-l1-1-0.dll
GetUserDefaultLCID
api-ms-win-core-localization-l1-1-1.dll
FormatMessageW, GetUserDefaultLCID
api-ms-win-core-localization-l1-2-0.dll
FormatMessageW, GetUserDefaultLCID
api-ms-win-core-localization-l1-2-1.dll
GetUserDefaultLCID, FormatMessageW
api-ms-win-core-localregistry-l1-1-0.dll
RegCloseKey, RegOpenKeyExW, RegLoadKeyW, RegUnLoadKeyW, RegCreateKeyExW, RegGetValueW, RegQueryValueExW
api-ms-win-core-memory-l1-1-1.dll
VirtualQuery, VirtualAlloc, VirtualProtect
api-ms-win-core-memory-l1-1-2.dll
VirtualQuery, VirtualAlloc, VirtualProtect
api-ms-win-core-misc-l1-1-0.dll
FormatMessageW, Sleep, LocalFree, lstrlenW
api-ms-win-core-processenvironment-l1-1-0.dll
SearchPathW
api-ms-win-core-processenvironment-l1-1-1.dll
SearchPathW, ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW, SearchPathW
api-ms-win-core-processthreads-l1-1-0.dll
GetCurrentProcess, TerminateProcess, GetCurrentProcessId, OpenProcessToken, SetThreadToken, GetCurrentThread, OpenThreadToken, GetCurrentThreadId, CreateThread
api-ms-win-core-processthreads-l1-1-1.dll
SetThreadToken, OpenThreadToken, GetCurrentThreadId, SetThreadStackGuarantee, GetThreadContext, GetCurrentThread, GetCurrentProcess, GetCurrentProcessId, OpenProcessToken, SetThreadPriority, CreateThread, TerminateProcess, GetExitCodeProcess, CreateProcessW, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
SetThreadPriority, GetCurrentProcess, OpenProcessToken, GetCurrentThreadId, GetCurrentThread, SetThreadStackGuarantee, SetThreadToken, OpenThreadToken, GetThreadContext, GetExitCodeProcess, CreateThread, TerminateProcess, GetCurrentProcessId, CreateProcessW
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter, QueryPerformanceFrequency
api-ms-win-core-registry-l1-1-0.dll
RegNotifyChangeKeyValue, RegCreateKeyExW, RegQueryInfoKeyW, RegQueryValueExW, RegEnumValueW, RegSetValueExW, RegCloseKey, RegEnumKeyExW, RegDeleteValueW, RegUnLoadKeyW, RegLoadKeyW, RegOpenKeyExW, RegGetValueW, RegDeleteTreeW
api-ms-win-core-string-l1-1-0.dll
CompareStringW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrlenW
api-ms-win-core-synch-l1-1-0.dll
DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, WaitForSingleObject, ResetEvent, CreateEventW, SetEvent, InitializeCriticalSectionAndSpinCount
api-ms-win-core-synch-l1-1-1.dll
InitOnceExecuteOnce, LeaveCriticalSection, EnterCriticalSection, ResetEvent, InitializeCriticalSection, SetEvent, InitializeCriticalSectionAndSpinCount, WaitForSingleObject, DeleteCriticalSection, WaitForSingleObjectEx, Sleep, ReleaseSemaphore, CreateSemaphoreExW, CreateEventW
api-ms-win-core-synch-l1-2-0.dll
EnterCriticalSection, InitializeCriticalSectionAndSpinCount, ResetEvent, WaitForSingleObjectEx, LeaveCriticalSection, InitializeCriticalSection, CreateEventW, InitOnceExecuteOnce, SetEvent, WaitForSingleObject, DeleteCriticalSection, ReleaseSemaphore, CreateSemaphoreExW, Sleep
api-ms-win-core-sysinfo-l1-1-0.dll
GetTickCount, GetSystemTimeAsFileTime, GetTickCount64
api-ms-win-core-sysinfo-l1-1-1.dll
GetTickCount64, GetTickCount, GetLocalTime, GetSystemTimeAsFileTime, GetSystemInfo
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetSystemInfo, GetTickCount, GetTickCount64, GetLocalTime
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTimeAsFileTime, GetSystemInfo, GetLocalTime, GetTickCount64, GetTickCount
api-ms-win-core-threadpool-l1-1-0.dll
CreateTimerQueueTimer, DeleteTimerQueueTimer
api-ms-win-core-threadpool-l1-1-1.dll
WaitForThreadpoolWaitCallbacks, SetThreadpoolWait, CreateTimerQueueTimer, CreateThreadpoolWait, DeleteTimerQueueTimer, CloseThreadpoolWait
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolWait, WaitForThreadpoolWaitCallbacks, CreateThreadpoolWait, CloseThreadpoolWait
api-ms-win-core-threadpool-legacy-l1-1-0.dll
DeleteTimerQueueTimer, UnregisterWaitEx, CreateTimerQueueTimer, ChangeTimerQueueTimer
api-ms-win-core-threadpool-private-l1-1-0.dll
RegisterWaitForSingleObjectEx
api-ms-win-core-version-l1-1-0.dll
VerQueryValueW
api-ms-win-obsolete-kernelbase-l1-1-0.dll
lstrlenW, LocalFree
api-ms-win-security-base-l1-1-0.dll
AdjustTokenPrivileges, GetSecurityDescriptorDacl, FreeSid, AllocateAndInitializeSid, CheckTokenMembership, GetTokenInformation, EqualSid, GetLengthSid
api-ms-win-security-base-l1-2-0.dll
EqualSid, AllocateAndInitializeSid, FreeSid, CheckTokenMembership, AdjustTokenPrivileges, GetSecurityDescriptorDacl, GetTokenInformation, GetLengthSid
kernel32.dll
OutputDebugStringW, RegNotifyChangeKeyValue, RegisterWaitForSingleObject, GetModuleHandleExW, InitializeCriticalSection, VirtualProtect, VirtualAlloc, VirtualQuery, GetVersion, IsDebuggerPresent, GetThreadContext, GetLocalTime, CreateDirectoryW, CreateProcessW, GetExitCodeProcess, FindFirstFileW, FindNextFileW, SetFileAttributesW, DeleteFileW, FindClose, GetModuleHandleW, FindResourceW, LoadResource, LockResource, OutputDebugStringA, SetThreadPriority, GetQueuedCompletionStatus, FreeLibraryAndExitThread, CreateIoCompletionPort, QueryPerformanceFrequency, InterlockedExchangeAdd, PostQueuedCompletionStatus, ChangeTimerQueueTimer, LoadLibraryW, InterlockedCompareExchange64, LocalAlloc, ReleaseSemaphore, CreateSemaphoreW, GetSystemInfo, GetModuleFileNameW, RaiseException, DelayLoadFailureHook, UnregisterWait, RegDeleteTreeW, RegEnumKeyExW, RegDeleteValueW, GetComputerNameW, RegEnumValueW, RegSetValueExW, ExpandEnvironmentStringsW, RegQueryInfoKeyW, DebugBreak, InitOnceExecuteOnce, GlobalMemoryStatusEx, GetTickCount, CreateThread, DuplicateHandle, SearchPathW, InterlockedExchange, QueryPerformanceCounter, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, VirtualFree, DeleteTimerQueueTimer, CreateTimerQueueTimer, InitializeCriticalSectionAndSpinCount, LocalFree, Sleep, LoadLibraryA, GetProcAddress, FormatMessageW, FreeLibrary, LoadLibraryExW, GetFileAttributesW, InterlockedCompareExchange, GetCurrentProcess, DisableThreadLibraryCalls, CreateEventW, ResetEvent, WaitForSingleObject, GetCurrentThreadId, GetCurrentThread, GetLastError, SetEvent, CloseHandle, GetUserDefaultLCID, InterlockedDecrement, CompareStringW, InterlockedIncrement, lstrlenW, LeaveCriticalSection, EnterCriticalSection, DeleteCriticalSection, SetThreadStackGuarantee, UnregisterWaitEx, RegisterWaitForSingleObjectEx, GlobalLock, GlobalAlloc, GlobalUnlock, GlobalFree
msvcrt.dll
DllMain
ntdll.dll
NtOpenEvent, RtlInitUnicodeString, NtQueryEvent, RtlImageNtHeader, RtlAllocateHeap, RtlFreeHeap, RtlDelete, RtlSplay, RtlDllShutdownInProgress, RtlInitializeCriticalSectionAndSpinCount, RtlDeleteCriticalSection, RtlCreateServiceSid, RtlNtStatusToDosError, RtlInitAnsiString, RtlOemStringToUnicodeString, RtlApplicationVerifierStop
ole32.dll
CoUnmarshalInterface, CoCreateGuid, CoDisconnectContext, CoUninitialize, PropVariantClear, FreePropVariantArray, CoRegisterClassObject, CoGetObjectContext, StringFromCLSID, CoGetMalloc, CoRevokeClassObject, IIDFromString, CoGetInterceptorFromTypeInfo, CLSIDFromString, CoGetObject, StringFromGUID2, CoCreateInstance, CoEnableCallCancellation, CoDisableCallCancellation, CoSetProxyBlanket, CoCancelCall, CoTaskMemFree, CoTaskMemAlloc, CoRevertToSelf, CoImpersonateClient, CoMarshalInterface, CreateStreamOnHGlobal, PropVariantCopy, CoCopyProxy, CoGetClassObject, CoInitializeEx
propsys.dll
PropVariantToVariant, VariantToPropVariant
rpcrt4.dll
CStdStubBuffer_Connect, CStdStubBuffer_AddRef, CStdStubBuffer_QueryInterface, NdrStubCall2, NdrStubForwardingFunction, IUnknown_Release_Proxy, IUnknown_AddRef_Proxy, IUnknown_QueryInterface_Proxy, NdrOleFree, NdrOleAllocate, CStdStubBuffer_Invoke, CStdStubBuffer_IsIIDSupported, CStdStubBuffer_CountRefs, CStdStubBuffer_DebugServerQueryInterface, CStdStubBuffer_DebugServerRelease, NdrCStdStubBuffer2_Release, NdrCStdStubBuffer_Release, NdrDllCanUnloadNow, NdrDllGetClassObject, CStdStubBuffer_Disconnect, I_RpcOpenClientProcess, I_RpcBindingInqLocalClientPID, I_RpcBindingInqTransportType
user32.dll
OpenWindowStationW, GetThreadDesktop, GetProcessWindowStation, CloseDesktop, CloseWindowStation, SetDlgItemTextW, EndDialog, DialogBoxParamW, SetProcessWindowStation, OpenDesktopW, SetThreadDesktop, GetDesktopWindow, GetWindowRect, GetClientRect, MapWindowPoints, SetWindowPos, LoadStringW, PeekMessageW, MsgWaitForMultipleObjectsEx, PostThreadMessageW
Export table
DllCanUnloadNow
DllGetClassObject
LCEControlServer
NotifyLogoffUser
NotifyLogonUser
ServiceMain
SvchostPushServiceGlobals