Import table
advapi32.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetLastError, SetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetLastError, SetLastError
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedIncrement, InterlockedCompareExchange, InterlockedCompareExchange64, InterlockedExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedCompareExchange, InterlockedCompareExchange64, InterlockedExchange
api-ms-win-core-libraryloader-l1-1-0.dll
DisableThreadLibraryCalls
api-ms-win-core-libraryloader-l1-1-1.dll
DisableThreadLibraryCalls
api-ms-win-core-libraryloader-l1-2-0.dll
DisableThreadLibraryCalls
api-ms-win-core-misc-l1-1-0.dll
Sleep
api-ms-win-core-processthreads-l1-1-0.dll
GetCurrentProcessId, GetCurrentProcess, GetCurrentThreadId, TerminateProcess
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, GetCurrentProcess
api-ms-win-core-processthreads-l1-1-2.dll
GetCurrentThreadId, GetCurrentProcessId, GetCurrentProcess, TerminateProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-synch-l1-1-1.dll
Sleep
api-ms-win-core-synch-l1-2-0.dll
Sleep, AcquireSRWLockExclusive, InitializeSRWLock, ReleaseSRWLockExclusive, ReleaseSRWLockShared, AcquireSRWLockShared
api-ms-win-core-sysinfo-l1-1-0.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-eventing-classicprovider-l1-1-0.dll
GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage
api-ms-win-power-setting-l1-1-0.dll
PowerSettingRegisterNotification, PowerSettingUnregisterNotification
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
avrt.dll
AvRevertMmThreadCharacteristics, AvSetMmThreadCharacteristicsW
kernel32.dll
GetCurrentProcess, SetUnhandledExceptionFilter, TerminateProcess, InterlockedExchangeAdd, InterlockedCompareExchange64, InterlockedCompareExchange, GetLastError, SetLastError, InterlockedExchange, InterlockedIncrement, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, DisableThreadLibraryCalls, UnhandledExceptionFilter
ntdll.dll
NtCreateEvent, NtOpenEvent, NtCreatePrivateNamespace, NtOpenPrivateNamespace, RtlAddSIDToBoundaryDescriptor, RtlCreateBoundaryDescriptor, RtlInitUnicodeStringEx, NtAlpcCreatePort, NtCancelTimer, RtlInterlockedFlushSList, NtSetTimer, NtResetEvent, NtWaitForMultipleObjects, NtAlpcAcceptConnectPort, NtAlpcSendWaitReceivePort, AlpcGetMessageAttribute, AlpcInitializeMessageAttribute, RtlExitUserThread, RtlCreateUserThread, NtCreateTimer, NtQueryValueKey, memcpy, NtOpenKey, NtEnumerateKey, NtQueueApcThread, NtSetTimerResolution, NtWaitForSingleObject, NtSetSystemInformation, RtlInterlockedPushEntrySList, NtResumeThread, NtOpenThread, NtFreeVirtualMemory, NtAllocateVirtualMemory, RtlSetDaclSecurityDescriptor, NtDeletePrivateNamespace, RtlCreateAcl, RtlCreateSecurityDescriptor, RtlLengthSid, RtlSubAuthoritySid, RtlInitializeSid, RtlLengthRequiredSid, RtlCreateServiceSid, NtQueryPerformanceCounter, RtlCompareMemory, NtAlpcImpersonateClientOfPort, RtlGetCurrentProcessorNumber, _vsnwprintf, NtSetValueKey, RtlRandomEx, RtlUnwind, NtQueryTimerResolution, NtQuerySystemInformation, RtlAllocateHeap, RtlAcquirePrivilege, RtlFreeHeap, DbgPrompt, NtDeviceIoControlFile, NtOpenFile, NtQueryInformationProcess, NtReadVirtualMemory, NtOpenProcess, EtwLogTraceEvent, DbgPrintEx, EtwUnregisterTraceGuids, RtlDeleteBoundaryDescriptor, NtAlpcOpenSenderThread, NtQueryInformationThread, NtSetInformationThread, RtlInitializeSListHead, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, NtSetEvent, _wcsicmp, RtlAddAccessAllowedAce, RtlReleasePrivilege, NtClose, RtlNtStatusToDosError, NtDelayExecution, memset, DbgBreakPoint, NtTraceEvent, LdrGetDllFullName, RtlIntegerToUnicodeString, NtPowerInformation, TpAllocWait, TpSetWait, TpReleaseWait, TpWaitForWait, NtSetTimerEx, RtlAllocateAndInitializeSid, RtlFreeSid, NtAlertThread, ZwAlpcCancelMessage, ZwAlpcSendWaitReceivePort, ZwAlpcConnectPort, RtlWaitOnAddress, TpAllocAlpcCompletion, RtlInitUnicodeString, RtlWakeAddressAll, TpWaitForAlpcCompletion, ZwAlpcDisconnectPort, ZwClose, TpReleaseAlpcCompletion, ZwAlpcQueryInformation, vDbgPrintEx, RtlCaptureContext, memcmp
Export table
ServiceMain
ToServiceMain