Import table
advapi32.dll
CryptGenRandom, CryptReleaseContext, CryptAcquireContextW, RegOpenKeyExA, RegQueryValueExA, RegCloseKey, CreateWellKnownSid, CheckTokenMembership, CryptHashData, CryptGetHashParam, CryptDestroyHash, TraceMessage, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsA, UnregisterTraceGuids, SetServiceStatus, RegisterServiceCtrlHandlerExA, RegOpenKeyExW, RegQueryValueExW, CryptCreateHash
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentThreadId, GetCurrentProcess, TerminateProcess, GetCurrentProcessId
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar, WideCharToMultiByte
api-ms-win-core-synch-l1-2-0.dll
Sleep, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, SetEvent
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolThreadMaximum, CloseThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, CloseThreadpool, TrySubmitThreadpoolCallback, CreateThreadpoolCleanupGroup, CreateThreadpool
api-ms-win-security-base-l1-1-0.dll
CreateWellKnownSid, CheckTokenMembership
api-ms-win-security-base-l1-2-0.dll
CheckTokenMembership, CreateWellKnownSid
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus
api-ms-win-service-winsvc-l1-1-0.dll
RegisterServiceCtrlHandlerExA
api-ms-win-service-winsvc-l1-2-0.dll
RegisterServiceCtrlHandlerExA
firewallapi.dll
FWOpenPolicyStore, IsFirewallInCoExistanceMode, FWGetConfig, FWClosePolicyStore, FWGetGlobalConfig, FWQueryFirewallRules, FWFreeFirewallRules, FWEnumFirewallRules, FWIndicatePortInUse, FWIndicateTupleInUse, FWResetIndicatedTupleInUse
kernel32.dll
CloseThreadpoolCleanupGroupMembers, CreateThreadpool, CreateThreadpoolCleanupGroup, DeleteTimerQueueEx, DeleteTimerQueueTimer, CreateTimerQueueTimer, GetSystemInfo, DelayLoadFailureHook, DeleteCriticalSection, InitializeCriticalSection, SetEvent, LeaveCriticalSection, EnterCriticalSection, GetProcAddress, GetLastError, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, InterlockedExchange, Sleep, QueryPerformanceCounter, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, GetCurrentProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, SetThreadpoolTimer, CreateSemaphoreA, CloseHandle, WaitForMultipleObjects, InterlockedExchangeAdd, InterlockedDecrement, TrySubmitThreadpoolCallback, InterlockedIncrement, UnregisterWaitEx, UnregisterWait, CloseThreadpoolTimer, WaitForThreadpoolTimerCallbacks, lstrcmpA, CreateThreadpoolTimer, RegisterWaitForSingleObject, CreateEventA, LoadLibraryA, TryEnterCriticalSection, lstrlenW, lstrcmpW, lstrlenA, RegCloseKey, RegQueryValueExA, RegOpenKeyExA, CreateThread, GetExitCodeThread, WideCharToMultiByte, ResetEvent, SetLastError, CancelIo, GetOverlappedResult, CreateEventW, QueueUserWorkItem, HeapAlloc, GetProcessHeap, LoadLibraryW, SetThreadpoolThreadMaximum, CloseThreadpool, CloseThreadpoolCleanupGroup, RegQueryValueExW, MultiByteToWideChar, HeapFree, HeapReAlloc, RegOpenKeyExW, GetSystemWindowsDirectoryW, WaitForSingleObject, CreateTimerQueue, ReleaseSemaphore, CancelIoEx, ResolveDelayLoadedAPI, WaitForMultipleObjectsEx, LoadLibraryExW
msvcrt.dll
DllMain
nsi.dll
NsiGetParameter
ntdll.dll
EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwTraceMessage, EtwUnregisterTraceGuids
rpcrt4.dll
UuidFromStringW, NdrServerCall2, UuidFromStringA, RpcServerUseProtseqA, RpcServerRegisterAuthInfoA, RpcServerRegisterIfEx, RpcServerInqBindings, RpcEpRegisterA, RpcBindingVectorFree, RpcServerUnregisterIfEx, I_RpcBindingInqTransportType, RpcBindingInqAuthClientA, RpcImpersonateClient, RpcRevertToSelf, RpcAsyncCompleteCall, RpcServerUnsubscribeForNotification, NdrAsyncServerCall, RpcServerSubscribeForNotification
ws2_32.dll
getaddrinfo, WSAIoctl, freeaddrinfo, WSAEventSelect, WSAAddressToStringA, WSAEnumNetworkEvents, WSASocketW, WSAStringToAddressA, FreeAddrInfoW, GetAddrInfoW, WSAStringToAddressW
Export table
ServiceMain
SvchostPushServiceGlobals