Import table
advapi32.dll
GetLengthSid, ConvertSidToStringSidW, QueryServiceConfigW, QueryServiceStatus, RegOpenKeyExW, RegCloseKey, RegQueryValueExW, ConvertStringSidToSidW, AllocateAndInitializeSid, FreeSid, CheckTokenMembership, IsValidSid, LookupAccountSidW, EqualSid, OpenThreadToken, OpenProcessToken, GetTokenInformation, LookupPrivilegeValueW, AdjustTokenPrivileges, StartServiceCtrlDispatcherW, RegisterServiceCtrlHandlerW, OpenSCManagerW, OpenServiceW, ChangeServiceConfigW, CloseServiceHandle, SetServiceStatus, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, TraceEvent
crypt32.dll
CertVerifyCertificateChainPolicy
kernel32.dll
WaitForSingleObject, SetThreadPriority, GetCurrentThread, CreateThread, lstrlenW, GetVersionExW, LeaveCriticalSection, EnterCriticalSection, ResetEvent, InterlockedIncrement, lstrcmpiW, GetFileAttributesW, CopyFileW, FindClose, FindNextFileW, FindFirstFileW, CreateDirectoryW, GetCurrentThreadId, InterlockedDecrement, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, GetThreadTimes, GetModuleHandleW, WaitForMultipleObjects, OpenThread, CreateMutexW, ReleaseMutex, UnregisterWaitEx, ReleaseSemaphore, CreateSemaphoreW, GetSystemTimeAsFileTime, FindCloseChangeNotification, FindNextChangeNotification, FindFirstChangeNotificationW, CreateFileW, GetTickCount, DeleteFileW, WriteFile, GetFileSize, GetFileAttributesExW, CompareFileTime, CreateEventW, GetTimeFormatW, GetDateFormatW, FileTimeToSystemTime, FileTimeToLocalFileTime, Sleep, QueryPerformanceCounter, GetCurrentProcessId, UnhandledExceptionFilter, SetUnhandledExceptionFilter, SetEvent, InterlockedCompareExchange, UnregisterWait, CloseHandle, DeleteTimerQueueTimer, CreateTimerQueueTimer, GetCurrentProcess, TerminateProcess, SetErrorMode, LoadLibraryW, GetProcAddress, FreeLibrary, LocalAlloc, LocalFree, GetLastError, InterlockedExchange, LoadLibraryExW, GetSystemDirectoryW, InitializeCriticalSection, FormatMessageW, DisableThreadLibraryCalls, RemoveDirectoryW, SetFileAttributesW, HeapFree, HeapAlloc, DeleteTimerQueueEx, TryEnterCriticalSection, GetModuleFileNameW, CreateTimerQueue, GetLocalTime, RegisterWaitForSingleObject
mpclient.dll
MpConfigIteratorEnum, MpConfigIteratorClose, MpConfigUnregisterNotifications, MpFeatureStatus, MpGetEngineVersion, MpOpen, MpFormatVErrorMessage, MpClose, MpConfigSetValue, MpConfigRegisterForNotifications, MpClientUtilExportFunctions, MpConfigUninitialize, MpConfigInitialize, MpConfigGetValue, MpConfigGetValueAlloc, MpConfigClose, MpConfigOpen, MpConfigIteratorOpen
msvcrt.dll
DllMain
ole32.dll
CoUninitialize, CoInitializeEx, StringFromGUID2, CoCreateInstance
rpcrt4.dll
RpcImpersonateClient, UuidFromStringW, NdrServerCall2, NdrAsyncServerCall, RpcStringFreeW, RpcBindingInqAuthClientW, RpcStringBindingParseW, RpcBindingToStringBindingW, RpcServerRegisterIfEx, UuidCreate, RpcRevertToSelf, RpcServerUseProtseqEpW, RpcServerRegisterAuthInfoW, RpcServerUnregisterIf, RpcAsyncCompleteCall
version.dll
GetFileVersionInfoW, GetFileVersionInfoSizeW, VerQueryValueW
wintrust.dll
WinVerifyTrust, CryptCATAdminReleaseContext, CryptCATAdminReleaseCatalogContext, WTHelperProvDataFromStateData, WTHelperGetProvSignerFromChain, CryptCATCatalogInfoFromContext, CryptCATAdminEnumCatalogFromHash, CryptCATAdminAcquireContext, CryptCATAdminCalcHashFromFileHandle
Export table
ServiceCrtMain
ServiceMain
SvchostPushServiceGlobals