Import table
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalAlloc
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-libraryloader-l1-1-1.dll
DisableThreadLibraryCalls, GetProcAddress, GetModuleFileNameW, GetModuleHandleExW, FreeLibrary
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentProcess, OpenThreadToken, SetThreadToken, OpenProcessToken, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess
api-ms-win-core-processthreads-l1-1-2.dll
GetCurrentThreadId, GetCurrentProcessId, OpenProcessToken, SetThreadToken, TerminateProcess, GetCurrentProcess, OpenThreadToken
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegCloseKey, RegSetValueExW, RegEnumValueW, RegDeleteKeyExW, RegCreateKeyExW, RegQueryInfoKeyW, RegNotifyChangeKeyValue, RegQueryValueExW
api-ms-win-core-synch-l1-1-1.dll
Sleep
api-ms-win-core-synch-l1-2-0.dll
Sleep
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-security-base-l1-1-0.dll
GetTokenInformation, CheckTokenMembership, GetWindowsAccountDomainSid, CreateWellKnownSid, RevertToSelf, EqualSid, CopySid
api-ms-win-security-base-l1-2-0.dll
GetTokenInformation, CopySid, GetWindowsAccountDomainSid, CheckTokenMembership, CreateWellKnownSid, RevertToSelf, EqualSid
api-ms-win-security-grouppolicy-l1-1-0.dll
RegisterGPNotificationInternal, UnregisterGPNotificationInternal
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, StartServiceW, OpenServiceW, OpenSCManagerW
api-ms-win-service-winsvc-l1-1-0.dll
QueryServiceStatus
api-ms-win-service-winsvc-l1-2-0.dll
QueryServiceStatus
kernel32.dll
LoadLibraryExA, InterlockedExchange, Sleep, QueryPerformanceCounter, GetTickCount, InterlockedCompareExchange, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetProcessHeap, HeapSetInformation, HeapCreate, HeapDestroy, HeapAlloc, HeapReAlloc, HeapFree, RegOpenKeyExW, RegCloseKey, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, InterlockedDecrement, InterlockedIncrement, FreeLibrary, GetLastError, GetProcAddress, DelayLoadFailureHook, DisableThreadLibraryCalls, SwitchToThread, LoadLibraryW, GetCurrentThreadId, CreateDirectoryW, RegCreateKeyExW, RegDeleteKeyExW, RegQueryInfoKeyW, RegSetValueExW, RegEnumValueW, DuplicateHandle, ResetEvent, CreateTimerQueueTimer, DeleteTimerQueueTimer, DeviceIoControl, RegNotifyChangeKeyValue, CreateThread, WaitForMultipleObjects, WaitForSingleObject, FileTimeToSystemTime, SystemTimeToFileTime, ExitProcess, GetVersionExW, SetLastError, CopyFileW, DeleteFileW, RegQueryValueExW, DebugBreak, MultiByteToWideChar, WideCharToMultiByte, CloseHandle, WriteFile, CreateFileW, ReadFile, GetFileSize, CompareFileTime, CompareStringA, lstrlenA, lstrlenW, UnregisterWaitEx, SetEvent, RegisterWaitForSingleObject, CreateEventW, GetCurrentThread, LoadLibraryExW, GetFileAttributesW, WaitForMultipleObjectsEx, CopyFileExW, RegisterWaitForSingleObjectEx, LocalFree
msvcrt.dll
DllMain
ntdll.dll
EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, EtwTraceMessage, RtlIpv4AddressToStringExW, RtlIpv6AddressToStringExW, EtwGetTraceEnableFlags, RtlFreeUnicodeString, RtlStringFromGUID
rpcrt4.dll
RpcSsContextLockExclusive, RpcRaiseException, NdrClientCall2, I_RpcExceptionFilter, UuidToStringW, RpcServerUseProtseqW, RpcServerUseProtseqEpW, RpcServerRegisterAuthInfoW, RpcServerRegisterIfEx, RpcEpRegisterW, RpcErrorStartEnumeration, RpcErrorGetNextRecord, RpcErrorEndEnumeration, RpcStringBindingComposeW, RpcBindingFromStringBindingW, RpcBindingSetAuthInfoExW, RpcBindingFree, RpcServerUnregisterIfEx, RpcServerInqBindings, RpcStringFreeW, RpcBindingToStringBindingW, RpcStringBindingParseW, RpcBindingVectorFree, I_RpcBindingInqTransportType, RpcBindingInqAuthClientW, UuidCreate, RpcRevertToSelf, RpcImpersonateClient, NdrServerCall2
Export table
IMServiceMain
SvchostPushServiceGlobals
SVCServiceMain