Import table
advapi32.dll
UnregisterTraceGuids, SetSecurityDescriptorDacl, RegisterServiceCtrlHandlerExW, RegQueryInfoKeyW, RegEnumKeyExW, RegDeleteKeyW, ConvertStringSidToSidW, GetLengthSid, InitializeAcl, AddAccessAllowedAce, NotifyServiceStatusChangeW, QueryServiceStatus, OpenSCManagerW, OpenServiceW, CloseServiceHandle, WmiNotificationRegistrationW, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, SetServiceStatus, TraceMessage, FreeSid, AllocateAndInitializeSid, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, RegSetValueExW, RegCreateKeyExW, InitializeSecurityDescriptor
api-ms-win-core-com-l1-1-0.dll
CoCreateInstance, CoTaskMemFree, StringFromIID
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, SetLastError, GetLastError
api-ms-win-core-errorhandling-l1-1-1.dll
SetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetLastError
api-ms-win-core-file-l1-1-1.dll
FileTimeToSystemTime, CreateFileW, FileTimeToLocalFileTime
api-ms-win-core-file-l1-2-0.dll
CreateFileW, FileTimeToLocalFileTime
api-ms-win-core-file-l1-2-1.dll
FileTimeToLocalFileTime, CreateFileW
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-1-0.dll
HeapAlloc, HeapFree, HeapCreate, GetProcessHeap, HeapDestroy
api-ms-win-core-heap-l1-2-0.dll
HeapCreate, HeapAlloc, HeapDestroy, GetProcessHeap, HeapFree
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc, LocalFree
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedExchange, InterlockedDecrement, InterlockedCompareExchange, InterlockedIncrement
api-ms-win-core-interlocked-l1-1-1.dll
InterlockedCompareExchange, InterlockedIncrement, InterlockedDecrement, InterlockedExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedIncrement, InterlockedDecrement, InterlockedCompareExchange, InterlockedExchange
api-ms-win-core-io-l1-1-1.dll
DeviceIoControl
api-ms-win-core-kernel32-legacy-l1-1-0.dll
LoadLibraryW, UnregisterWait, RegisterWaitForSingleObject
api-ms-win-core-kernel32-legacy-l1-1-1.dll
UnregisterWait, RegisterWaitForSingleObject, LoadLibraryW
api-ms-win-core-libraryloader-l1-1-1.dll
FreeLibrary, GetProcAddress, DisableThreadLibraryCalls, GetModuleHandleExW
api-ms-win-core-libraryloader-l1-2-0.dll
GetProcAddress, DisableThreadLibraryCalls, FreeLibrary, GetModuleHandleExW
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentProcessId, TerminateProcess, CreateThread, GetCurrentThread, GetCurrentProcess, GetCurrentThreadId, OpenThreadToken, IsProcessorFeaturePresent
api-ms-win-core-processthreads-l1-1-2.dll
GetCurrentProcessId, GetCurrentThreadId, OpenThreadToken, CreateThread, GetCurrentProcess, TerminateProcess, GetCurrentThread
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegQueryValueExW, RegCloseKey, RegCreateKeyExW, RegGetValueW, RegDeleteKeyExW, RegQueryInfoKeyW, RegEnumKeyExW, RegSetValueExW
api-ms-win-core-rtlsupport-l1-1-0.dll
RtlCompareMemory
api-ms-win-core-rtlsupport-l1-1-1.dll
RtlCompareMemory
api-ms-win-core-rtlsupport-l1-2-0.dll
RtlCompareMemory
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar, WideCharToMultiByte
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrlenW, lstrlenA
api-ms-win-core-synch-l1-1-1.dll
DeleteCriticalSection, WaitForMultipleObjectsEx, EnterCriticalSection, ResetEvent, InitializeSRWLock, SetEvent, CreateEventW, InitializeCriticalSectionAndSpinCount, AcquireSRWLockShared, AcquireSRWLockExclusive, WaitForSingleObject, LeaveCriticalSection, ReleaseSRWLockShared, Sleep, ReleaseSRWLockExclusive
api-ms-win-core-synch-l1-2-0.dll
ReleaseSRWLockExclusive, LeaveCriticalSection, EnterCriticalSection, ReleaseSRWLockShared, CreateEventW, InitializeCriticalSectionAndSpinCount, WaitForMultipleObjectsEx, AcquireSRWLockExclusive, WaitForSingleObject, AcquireSRWLockShared, SetEvent, ResetEvent, Sleep, InitializeSRWLock, DeleteCriticalSection
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemDirectoryW, GetTickCount64, GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount64, GetTickCount, GetSystemDirectoryW, GetSystemTimeAsFileTime
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTimeAsFileTime, GetSystemDirectoryW, GetTickCount, GetTickCount64
api-ms-win-core-threadpool-l1-1-1.dll
QueueUserWorkItem, WaitForThreadpoolTimerCallbacks, SetThreadpoolTimer, UnregisterWaitEx, CreateThreadpoolTimer, CloseThreadpoolTimer
api-ms-win-core-threadpool-l1-2-0.dll
CreateThreadpoolTimer, SetThreadpoolTimer, WaitForThreadpoolTimerCallbacks, CloseThreadpoolTimer
api-ms-win-core-threadpool-legacy-l1-1-0.dll
QueueUserWorkItem, UnregisterWaitEx
api-ms-win-core-timezone-l1-1-0.dll
FileTimeToSystemTime
api-ms-win-legacy-kernel32-l1-1-0.dll
RegisterWaitForSingleObject, LoadLibraryW, UnregisterWait
api-ms-win-obsolete-kernelbase-l1-1-0.dll
lstrlenW, LocalFree, LocalAlloc, lstrlenA
api-ms-win-power-setting-l1-1-0.dll
PowerSettingRegisterNotification, PowerSettingUnregisterNotification
api-ms-win-security-base-l1-1-0.dll
FreeSid, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, InitializeAcl, GetLengthSid, AddAccessAllowedAce, AllocateAndInitializeSid, GetTokenInformation
api-ms-win-security-base-l1-2-0.dll
InitializeAcl, AddAccessAllowedAce, GetLengthSid, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, AllocateAndInitializeSid, FreeSid
api-ms-win-security-lsalookup-l1-1-0.dll
LookupAccountNameLocalW
api-ms-win-security-lsalookup-l1-1-1.dll
LookupAccountNameLocalW
api-ms-win-security-sddl-l1-1-0.dll
ConvertStringSecurityDescriptorToSecurityDescriptorW, ConvertStringSidToSidW
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenSCManagerW, OpenServiceW, StartServiceW
api-ms-win-service-management-l2-1-0.dll
NotifyServiceStatusChangeW
api-ms-win-service-private-l1-1-0.dll
SubscribeServiceChangeNotifications, UnsubscribeServiceChangeNotifications
api-ms-win-service-private-l1-1-1.dll
SubscribeServiceChangeNotifications, UnsubscribeServiceChangeNotifications
api-ms-win-service-winsvc-l1-1-0.dll
QueryServiceStatus, SubscribeServiceChangeNotifications, ControlService, UnsubscribeServiceChangeNotifications
api-ms-win-service-winsvc-l1-2-0.dll
QueryServiceStatus, ControlService
bcrypt.dll
BCryptDestroyHash, BCryptFinishHash, BCryptCreateHash, BCryptGetProperty, BCryptOpenAlgorithmProvider, BCryptHashData, BCryptCloseAlgorithmProvider
cfgmgr32.dll
CM_Open_Class_Key_ExW
dhcpcsvc.dll
DhcpFreeLeaseInfo, DhcpQueryLeaseInfoEx, DhcpIsEnabled
iphlpapi.dll
ConvertInterfaceIndexToLuid, CancelMibChangeNotify2, NotifyRouteChange2, NotifyUnicastIpAddressChange, ConvertInterfaceLuidToIndex, ResolveIpNetEntry2, GetAdaptersAddresses, ConvertInterfaceLuidToNameW, ConvertInterfaceLuidToGuid, ConvertInterfaceGuidToLuid, ConvertInterfaceLuidToAlias, GetAdaptersInfo, GetUnicastIpAddressEntry, GetIfTable2Ex, GetIpInterfaceTable, FreeMibTable, NotifyIpInterfaceChange
kernel32.dll
LoadLibraryExA, FreeLibrary, GetProcAddress, DelayLoadFailureHook, QueueUserWorkItem, GetTickCount64, WaitForMultipleObjects, CreateThread, ResetEvent, LocalAlloc, LocalFree, UnregisterWaitEx, InitializeCriticalSectionAndSpinCount, QueryPerformanceCounter, SetLastError, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, GetTickCount, GetLastError, CreateTimerQueueTimer, DeleteTimerQueueTimer, ChangeTimerQueueTimer, CreateTimerQueue, CreateEventW, WaitForSingleObject, Sleep, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, LoadLibraryW, MultiByteToWideChar, WideCharToMultiByte, lstrlenA, DeviceIoControl, lstrlenW, HeapFree, HeapDestroy, HeapCreate, GetProcessHeap, DisableThreadLibraryCalls, RegisterWaitForSingleObject, InterlockedDecrement, SetEvent, InterlockedCompareExchange, InterlockedIncrement, CloseHandle, UnregisterWait, DeleteTimerQueueEx, InterlockedExchange, HeapAlloc
msvcrt.dll
DllMain
ncsi.dll
NcsiUpdateClientPresence, NcsiNotifySessionChange, NcsiDeregisterConnectivityStatusChange, NcsiAllocateAndGetConnectivityStatusSet, NcsiFreeConnectivityStatusSet, NcsiRegisterConnectivityStatusChange, NcsiPerformRefresh
netapi32.dll
DsGetDcNameW, NetGetJoinInformation, NetApiBufferFree
nsi.dll
NsiAllocateAndGetTable, NsiSetAllParameters, NsiGetAllParameters, NsiGetParameter, NsiFreeTable
ntdll.dll
EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwEventUnregister, EtwEventRegister, RtlGUIDFromString, RtlInitUnicodeString, RtlUpcaseUnicodeChar, EtwEventEnabled, RtlCompareMemory, RtlAnsiStringToUnicodeString, RtlInitAnsiString, RtlNtStatusToDosError, NtOpenFile, EtwEventActivityIdControl, EtwEventWriteTransfer, RtlIpv6AddressToStringExW, RtlIpv4AddressToStringExW, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, RtlCopyUnicodeString, RtlCopySid, RtlDeleteSecurityObject, RtlLengthSid, RtlSetSaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAddAce, RtlCreateAcl, NtClose, RtlNewSecurityObject, NtOpenProcessToken, NtAccessCheckAndAuditAlarm, RtlAdjustPrivilege, EtwTraceMessage, RtlEqualUnicodeString, EtwEventWrite, RtlFreeUnicodeString, EtwGetTraceLoggerHandle, RtlStringFromGUID
rpcrt4.dll
RpcAsyncCompleteCall, RpcSsContextLockExclusive, RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, RpcServerUseProtseqEpW, RpcImpersonateClient, RpcServerRegisterIfEx, RpcServerListen, RpcBindingInqAuthClientW, RpcServerUnregisterIfEx, NdrServerCall2, NdrAsyncServerCall, RpcRevertToSelf, RpcStringFreeW, RpcServerUseProtseqW, I_RpcBindingInqTransportType, RpcServerInqBindings, RpcServerRegisterIf3, RpcEpRegisterW, RpcBindingVectorFree, RpcServerInqCallAttributesW
wevtapi.dll
EvtSubscribe, EvtClose, EvtOpenSession
winhttp.dll
WinHttpCrackUrl
winnsi.dll
NsiRpcRegisterChangeNotification, NsiRpcDeregisterChangeNotification, NsiConnectToServer, NsiDisconnectFromServer
ws2_32.dll
WSAAddressToStringW, getaddrinfo, getnameinfo, freeaddrinfo
Export table
ServiceMain
SvchostPushServiceGlobals