Import table
advapi32.dll
AddAccessAllowedAce, InitializeSecurityDescriptor, InitializeAcl, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, IsValidSid, GetLengthSid, RegDeleteValueW, RegEnumValueW, RegQueryValueExW, RegQueryInfoKeyW, RegCloseKey, RegOpenKeyExW, RegCreateKeyExW, LookupAccountSidW, GetTokenInformation, AccessCheck, RegNotifyChangeKeyValue, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, SetSecurityDescriptorDacl, MakeSelfRelativeSD, IsValidSecurityDescriptor, GetSecurityDescriptorControl, GetSecurityDescriptorLength, FreeSid, QueryServiceStatus, OpenThreadToken, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, CheckTokenMembership, DuplicateTokenEx, CreateProcessAsUserW, OpenTraceW, ProcessTrace, CloseTrace, StartTraceW, EnableTrace, ControlTraceW, ConvertStringSecurityDescriptorToSecurityDescriptorW, SetFileSecurityW, RemoveTraceCallback, OpenSCManagerW, OpenServiceW, NotifyServiceStatusChangeW, CloseServiceHandle, RegisterServiceCtrlHandlerW, EventWrite, SetServiceStatus, TraceMessage, EventRegister, EventUnregister, UnregisterTraceGuids, RegisterTraceGuidsA, AllocateAndInitializeSid, BuildSecurityDescriptorW
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter, SetLastError, GetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, GetLastError, SetUnhandledExceptionFilter, SetLastError
api-ms-win-core-file-l1-1-1.dll
FileTimeToSystemTime, WriteFile, GetLongPathNameW, CreateFileW, CreateDirectoryW, GetFileAttributesW, FileTimeToLocalFileTime, SetFilePointerEx, GetFileType, SetEndOfFile, FindClose, GetFileSize, QueryDosDeviceW, GetLogicalDriveStringsW, FindNextFileW, FindFirstFileW
api-ms-win-core-file-l1-2-0.dll
CreateFileW, FindFirstFileW, FindNextFileW, GetFileType, WriteFile, GetLogicalDriveStringsW, QueryDosDeviceW, GetFileSize, CreateDirectoryW, SetEndOfFile, GetLongPathNameW, FileTimeToLocalFileTime, SetFilePointerEx, GetFileAttributesW, FindClose
api-ms-win-core-file-l1-2-1.dll
FindNextFileW, FindFirstFileW, FindClose, SetEndOfFile, QueryDosDeviceW, FileTimeToLocalFileTime, GetFileType, CreateFileW, GetFileAttributesW, GetLongPathNameW, GetFileSize, CreateDirectoryW, WriteFile, SetFilePointerEx, GetLogicalDriveStringsW
api-ms-win-core-file-l2-1-0.dll
CopyFileExW
api-ms-win-core-file-l2-1-1.dll
CopyFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-1-0.dll
HeapReAlloc, GetProcessHeap, HeapFree, HeapAlloc
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapReAlloc, GetProcessHeap, HeapFree
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree, LocalAlloc
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange, InterlockedExchange, InterlockedIncrement, InterlockedDecrement
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedCompareExchange, InterlockedDecrement, InterlockedExchange, InterlockedIncrement
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedDecrement, InterlockedExchange, InterlockedIncrement, InterlockedCompareExchange
api-ms-win-core-io-l1-1-1.dll
CancelIo, DeviceIoControl
api-ms-win-core-libraryloader-l1-1-1.dll
FreeLibrary, LoadStringW, GetModuleHandleW, GetProcAddress, LoadLibraryExW
api-ms-win-core-libraryloader-l1-2-0.dll
GetProcAddress, FreeLibrary, GetModuleHandleW, LoadStringW, LoadLibraryExW
api-ms-win-core-localization-l1-1-1.dll
LoadStringByReference, FormatMessageW
api-ms-win-core-localization-l1-2-0.dll
FormatMessageW
api-ms-win-core-localization-l1-2-1.dll
FormatMessageW
api-ms-win-core-memory-l1-1-1.dll
CreateFileMappingW, MapViewOfFile, UnmapViewOfFile
api-ms-win-core-memory-l1-1-2.dll
UnmapViewOfFile, MapViewOfFile, CreateFileMappingW
api-ms-win-core-path-l1-1-0.dll
PathCchSkipRoot, PathCchCanonicalize
api-ms-win-core-processenvironment-l1-1-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-1-1.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll
OpenProcess, CreateThread, TerminateThread, OpenThreadToken, GetCurrentThread, OpenProcessToken, GetCurrentProcess, GetCurrentProcessId, GetCurrentThreadId, CreateProcessAsUserW, ResumeThread, TerminateProcess, QueueUserAPC, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
TerminateProcess, OpenProcess, GetCurrentThread, GetCurrentProcessId, GetCurrentThreadId, TerminateThread, OpenThreadToken, QueueUserAPC, ResumeThread, CreateThread, OpenProcessToken, CreateProcessAsUserW, GetCurrentProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegCloseKey, RegOpenCurrentUser, RegNotifyChangeKeyValue, RegOpenKeyExW, RegEnumValueW, RegQueryValueExW, RegSetValueExW, RegEnumKeyExW, RegQueryInfoKeyW, RegDeleteValueW, RegCreateKeyExW
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
PathFindNextComponentW, PathSkipRootW, PathCanonicalizeW, PathFindFileNameW, PathIsRelativeW, PathRemoveFileSpecW, PathFileExistsW
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
SHLoadIndirectString
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar, WideCharToMultiByte, CompareStringW, CompareStringOrdinal
api-ms-win-core-string-l2-1-0.dll
CharLowerBuffW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcmpiW
api-ms-win-core-synch-l1-1-1.dll
ResetEvent, CreateWaitableTimerExW, DeleteCriticalSection, CreateEventA, SetWaitableTimer, InitializeCriticalSectionAndSpinCount, LeaveCriticalSection, Sleep, WaitForSingleObjectEx, InitializeCriticalSection, WaitForMultipleObjectsEx, ReleaseMutex, WaitForSingleObject, SetEvent, CreateMutexW, EnterCriticalSection, CreateEventW
api-ms-win-core-synch-l1-2-0.dll
CreateEventA, ResetEvent, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, Sleep, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, WaitForSingleObjectEx, CreateWaitableTimerExW, SetWaitableTimer, WaitForMultipleObjectsEx, CreateEventW, CreateMutexW, SetEvent, WaitForSingleObject, ReleaseMutex
api-ms-win-core-sysinfo-l1-1-1.dll
GetTickCount, GetLocalTime, GetSystemTimeAsFileTime, GetVersionExW
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount, GetVersionExW, GetSystemTimeAsFileTime, GetLocalTime
api-ms-win-core-sysinfo-l1-2-1.dll
GetLocalTime, GetSystemTimeAsFileTime, GetTickCount, GetVersionExW
api-ms-win-core-threadpool-l1-1-1.dll
CloseThreadpoolIo, DeleteTimerQueueTimer, CreateThreadpoolTimer, CreateTimerQueueTimer, WaitForThreadpoolTimerCallbacks, CloseThreadpoolTimer, WaitForThreadpoolIoCallbacks, CreateThreadpoolIo, RegisterWaitForSingleObjectEx, QueueUserWorkItem, CancelThreadpoolIo, CreateTimerQueue, UnregisterWaitEx, SetThreadpoolTimer, DeleteTimerQueueEx, StartThreadpoolIo
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolTimer, StartThreadpoolIo, CancelThreadpoolIo, CloseThreadpoolTimer, CloseThreadpoolWait, SetThreadpoolWait, CreateThreadpoolWait, WaitForThreadpoolIoCallbacks, CloseThreadpoolIo, WaitForThreadpoolWaitCallbacks, CreateThreadpoolTimer, CreateThreadpoolIo, WaitForThreadpoolTimerCallbacks
api-ms-win-core-threadpool-legacy-l1-1-0.dll
CreateTimerQueue, DeleteTimerQueueEx, CreateTimerQueueTimer, DeleteTimerQueueTimer, UnregisterWaitEx, QueueUserWorkItem
api-ms-win-core-threadpool-private-l1-1-0.dll
RegisterWaitForSingleObjectEx
api-ms-win-core-timezone-l1-1-0.dll
FileTimeToSystemTime
api-ms-win-devices-config-l1-1-0.dll
CM_Open_Class_KeyW
api-ms-win-devices-config-l1-1-1.dll
CM_Open_Class_KeyW
api-ms-win-eventing-consumer-l1-1-0.dll
CloseTrace, OpenTraceW, ProcessTrace
api-ms-win-eventing-controller-l1-1-0.dll
EnableTraceEx2, StartTraceW, ControlTraceW
api-ms-win-eventing-obsolete-l1-1-0.dll
RemoveTraceCallback
api-ms-win-legacy-kernel32-l1-1-0.dll
LoadLibraryW, RegisterWaitForSingleObject, UnregisterWait, CopyFileW
api-ms-win-legacy-shlwapi-l1-1-0.dll
PathRemoveFileSpecW, PathSkipRootW, PathFindNextComponentW, PathCanonicalizeW, PathFindFileNameW, PathIsRelativeW, PathFileExistsW
api-ms-win-obsolete-kernelbase-l1-1-0.dll
LocalAlloc, LocalFree, lstrcmpiW
api-ms-win-obsolete-shlwapi-l1-1-0.dll
SHLoadIndirectString
api-ms-win-security-base-l1-1-0.dll
CheckTokenCapability, CreateWellKnownSid, IsValidSid, AddAccessAllowedAce, SetSecurityDescriptorGroup, GetLengthSid, GetSecurityDescriptorControl, InitializeSecurityDescriptor, DuplicateTokenEx, SetSecurityDescriptorDacl, GetSecurityDescriptorLength, InitializeAcl, AllocateAndInitializeSid, SetSecurityDescriptorOwner, EqualSid, IsValidSecurityDescriptor, MakeSelfRelativeSD, FreeSid, GetTokenInformation, AccessCheck, AdjustTokenPrivileges, CheckTokenMembership, SetFileSecurityW
api-ms-win-security-base-l1-2-0.dll
MakeSelfRelativeSD, FreeSid, IsValidSid, AddAccessAllowedAce, SetSecurityDescriptorOwner, AllocateAndInitializeSid, IsValidSecurityDescriptor, GetSecurityDescriptorLength, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, GetSecurityDescriptorControl, SetSecurityDescriptorGroup, GetTokenInformation, InitializeAcl, CheckTokenCapability, AdjustTokenPrivileges, CheckTokenMembership, CreateWellKnownSid, GetLengthSid, DuplicateTokenEx, AccessCheck, SetFileSecurityW, EqualSid
api-ms-win-security-grouppolicy-l1-1-0.dll
RegisterGPNotificationInternal, UnregisterGPNotificationInternal
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus
api-ms-win-service-winsvc-l1-1-0.dll
RegisterServiceCtrlHandlerW
authz.dll
AuthzFreeAuditEvent, AuthziLogAuditEvent, AuthzInitializeResourceManager, AuthzFreeResourceManager
bcrypt.dll
BCryptGetFipsAlgorithmMode
cfgmgr32.dll
CM_Open_Class_Key_ExW
crypt32.dll
CertStrToNameW
firewallapi.dll
FwChangeSourceShutdown, FwChangeSourceInitialize, FwAlloc, FwFree, FwVerifyNoHeapLeaks, FwChangeSourceSignalStart, FwSddlStringVerify, FWVerifyMainModeRuleQuery, FwMMRuleVerify, FWVerifyCryptoSetQuery, FWVerifyCryptoSet, FWVerifyAuthenticationSetQuery, FwSetSet, FwDeleteSet, FWVerifyAuthenticationSet, FWVerifyConnectionSecurityRuleQuery, FwCSRuleVerify, FwSetRule, FwVerifyWFRuleSemantics, FwDeleteRule, FWVerifyFirewallRuleQuery, FwDeleteAllRules, FwDeleteAllSets, FwReduceObjectsToVersion, FWResolveGPONames, FwCreateLocalTempStore, FwGetGlobalConfigFromLocalTempStore, FwSetGlobalConfig, FwSetConfig, FwDestroyLocalTempStore, FwAddRule, FwAddSet, FwIPV4RangeContainsMulticast, FwIPV6RangeContainsMulticast, FwDoNothingOnObject, FwCopyWFAddressesContents, Isv4Orv6AddressesEmpty, FwEmptyWFAddresses, FwPortsToBstr, FwGetAddressesAsString, IsRuleOldGlobalOpenPort, IsRuleOldAuthApp, LoadGPExtensionDll, FWGPLock, FWGPUnlock, FwChangeSourceSignal, FwSetResolveFlags, FwCopyCSRule, FwCopyMMRule, FwCopyAuthSet, FwCopyCryptoSet, FwMigrateLegacyAuthenticatedBypassSddl, FwCopyRule, FwRuleResolveFlags, FwGetConfig, FwGetGlobalConfig, FwOpenPolicyStore, FwClosePolicyStore, FwEnumRules, FwEnumSets, FwFreeRules, FwFreeSets, FwAddrChangeSourceInitialize, FwAddrChangeSourceSignal, FwAllocCheckSize, FwAddrChangeSourceShutdown, IsAddressesEmpty, FwCopyLUID, FwSetMemLeakPolicy, FwCopyPortsContents, FwGetAppBlockList, FwImageListDestroy, FwCanonizeAuthorizedApps, FwImageListHasImage, FwStringToSids, FwSidAndAttributesFree, FwOpenAppCDbPolicyStore, FWFreeFirewallRules, FwGetRule, FwBinariesFree, FwSidsToString, FwAppContainerChangeFree, FwUniteWFAddressesContents, FwRemoveDuplicateAddresses, IsEqualAddresses, FwSubtractAddresses, FwAreAllContainedInAddresses, FwFreeAddresses, FwIsV6AddrLoopback, FwCopyAuthSetListToLowerVersion, FWFreeAuthenticationSet, FwCopyAuthsetToHigherVersion, FwMergeAddresses, FwStringToAddresses, FwPortsToString, IsUnicastExplicitAddressesEmpty, FwNegateAddresses, FwReduceSetsToVersion, FwSidAndAttributesCopy, FwCopyInterfaceLuids
fwpuclnt.dll
IkeextSaDeleteById0, IkeextSaDestroyEnumHandle0, FwpmEngineOpen0, IPsecSaContextCreateEnumHandle0, IPsecSaContextEnum0, IPsecSaContextDeleteById0, FwpmFreeMemory0, IPsecSaContextDestroyEnumHandle0, FwpmEngineClose0, IkeextSaEnum0, IkeextSaCreateEnumHandle0, FwpmNetEventDestroyEnumHandle0, FwpmNetEventEnum1, FwpmIPsecTunnelAddConditions0, FwpmIPsecTunnelDeleteByKey0, FwpmProviderContextDeleteByKey0, FwpmTransactionCommit0, FwpmIPsecTunnelAdd1, FwpmTransactionAbort0, FwpmNetEventCreateEnumHandle0, FwpmFilterDeleteByKey0, FwpmFilterDeleteById0, FwpmProviderContextDeleteById0, FwpmCalloutAdd0, FwpmTransactionBegin0, FwpmFilterAdd0, FwpmSubLayerAdd0, FwpmProviderAdd0, FwpmProviderContextAdd0, FwpmIPsecTunnelAdd0, FwpmNetEventEnum2, IkeextSaEnum2, FwpmProviderContextAdd2, FwpmIPsecTunnelAdd2, FwpmEventProviderCreate0, FwpmNetEventSubscribe1, FwpmEventProviderDestroy0, FwpmNetEventUnsubscribe0, FwpmEventProviderIsNetEventTypeEnabled0, FwpmEventProviderFireNetEvent0, FwpmEngineSetOption0, FwpiExpandCriteria0, FwpiFreeCriteria0, FwpmNetEventSubscribe0, FwpmFilterCreateEnumHandle0, FwpmFilterEnum0, FwpmFilterDestroyEnumHandle0
iphlpapi.dll
GetAdaptersAddresses
kernel32.dll
ExpandEnvironmentStringsW, SetLastError, LoadLibraryExW, GetLongPathNameW, CreateDirectoryW, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetSystemTimeAsFileTime, GetCurrentProcessId, GetTickCount, QueryPerformanceCounter, OutputDebugStringA, InterlockedExchange, CreateEventA, CreateWaitableTimerA, QueueUserAPC, SetWaitableTimer, WideCharToMultiByte, MultiByteToWideChar, QueueUserWorkItem, DelayLoadFailureHook, GetProcAddress, GetLastError, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, CloseHandle, CreateMutexW, CreateEventW, ReleaseMutex, WaitForSingleObject, SetEvent, WaitForMultipleObjects, GetCurrentThreadId, UnregisterWait, UnregisterWaitEx, CreateThread, RegisterWaitForSingleObject, EnterCriticalSection, LeaveCriticalSection, InterlockedIncrement, InterlockedDecrement, Sleep, ResetEvent, WaitForSingleObjectEx, CancelIo, DeviceIoControl, CreateFileW, LocalFree, lstrcmpiW, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, CreateTimerQueue, InitializeCriticalSection, CloseThreadpoolIo, WaitForThreadpoolIoCallbacks, FileTimeToSystemTime, FileTimeToLocalFileTime, CancelThreadpoolIo, WriteFile, StartThreadpoolIo, GetFileType, lstrlenA, HeapAlloc, GetProcessHeap, SetEndOfFile, SetFilePointerEx, CopyFileW, GetLocalTime, HeapFree, DeleteTimerQueueTimer, TerminateThread, DeleteTimerQueueEx, CreateThreadpoolIo, GetFileSize, CreateTimerQueueTimer, GetVersionExW, CompareStringOrdinal, QueryDosDeviceW, GetLogicalDriveStringsW, DuplicateHandle, GetCurrentProcess, TerminateProcess, LocalAlloc, ResumeThread, LoadLibraryW, lstrlenW, CompareStringW, GetCurrentThread, GetModuleHandleW, FormatMessageW, OpenProcess, BindIoCompletionCallback
kernelbase.dll
RemoveTraceCallback, lstrcmpiW, LocalFree, LocalAlloc
msvcrt.dll
DllMain
nlaapi.dll
NlaCreateTypeSet, NlaAddToTypeSet, NlaRegisterQuery, NlaGetIntranetCapability, NlaCloseQuery, NlaDeleteTypeSet
nsi.dll
NsiAllocateAndGetTable, NsiFreeTable, NsiGetParameter
ntdll.dll
NtOpenSymbolicLinkObject, NtQuerySymbolicLinkObject, NtClose, RtlNtStatusToDosError, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, EtwEventUnregister, EtwEventRegister, EtwTraceMessage, EtwEventWrite, RtlIpv6AddressToStringA, RtlIpv4AddressToStringA, DbgPrint, NtQueryInformationProcess, EtwEventEnabled, RtlCreateServiceSid, WinSqmSetDWORD, WinSqmAddToStream, RtlInitUnicodeString, WinSqmEventEnabled, WinSqmEventWrite, RtlContractHashTable, RtlExpandHashTable, RtlEndEnumerationHashTable, RtlEnumerateEntryHashTable, RtlInitEnumerationHashTable, RtlGetNextEntryHashTable, RtlLookupEntryHashTable, RtlRemoveEntryHashTable, RtlInsertEntryHashTable, RtlDeleteHashTable, RtlCreateHashTable, RtlEqualSid, RtlIsCapabilitySid, RtlLengthSid, RtlCopySid, RtlPublishWnfStateData, RtlIsPackageSid, RtlAllocateHeap, RtlFreeHeap, RtlNtStatusToDosErrorNoTeb, RtlGetAppContainerSidType, RtlIsParentOfChildAppContainer
ole32.dll
CoCreateInstance, StringFromGUID2, CoCreateGuid, CoReleaseMarshalData, CoUnmarshalInterface, CreateStreamOnHGlobal, CoMarshalInterface, CoSetProxyBlanket, CoInitializeEx, CoUninitialize, GetHGlobalFromStream
rpcrt4.dll
RpcServerRegisterIfEx, RpcServerUnregisterIfEx, RpcBindingVectorFree, RpcEpUnregister, RpcStringFreeW, RpcServerRegisterAuthInfoW, RpcServerInqDefaultPrincNameW, RpcEpRegisterW, RpcServerInqBindings, NdrServerCall2, RpcServerUseProtseqW, RpcBindingInqAuthClientW, RpcStringBindingParseW, RpcBindingToStringBindingW, I_RpcBindingIsClientLocal, I_RpcBindingInqLocalClientPID, RpcRevertToSelf, RpcImpersonateClient, UuidCreate, RpcServerRegisterIf3, RpcAsyncCancelCall, I_RpcExceptionFilter, NdrAsyncServerCall, RpcAsyncInitializeHandle, NdrAsyncClientCall, NdrClientCall2, RpcBindingFromStringBindingW, RpcStringBindingComposeW, RpcAsyncCompleteCall, RpcAsyncAbortCall, RpcBindingFree, RpcBindingSetAuthInfoW
shlwapi.dll
PathFindFileNameW, PathCanonicalizeW, PathFindNextComponentW, PathSkipRootW, PathFileExistsW, PathRemoveFileSpecW, PathIsRelativeW, AssocQueryStringW, PathIsDirectoryW
user32.dll
LoadStringW, CharLowerBuffW
userenv.dll
RegisterGPNotification, UnregisterGPNotification
ws2_32.dll
WSAAddressToStringW
wtsapi32.dll
WTSQuerySessionInformationW, WTSFreeMemory
Export table
ServiceMain
SvchostPushServiceGlobals