Import table
advapi32.dll
RegisterServiceCtrlHandlerExW, GetTokenInformation, LookupPrivilegeNameW, CreateRestrictedToken, CreateProcessAsUserW, SetTokenInformation, RegDeleteValueW, RegGetValueW, ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, SetServiceStatus, OpenProcessToken, DuplicateTokenEx, LookupPrivilegeValueW, AdjustTokenPrivileges, RegCreateKeyExW, RegQueryValueExW, RegSetValueExW, RegCloseKey, UnregisterTraceGuids, RegisterTraceGuidsW, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage, TraceEvent, RegOpenKeyExW, RegDeleteKeyW
api-ms-win-core-localregistry-l1-1-0.dll
RegOpenKeyExW, RegQueryValueExW, RegDeleteKeyExW, RegCreateKeyExW, RegSetValueExW, RegCloseKey
api-ms-win-core-processthreads-l1-1-0.dll
GetExitCodeProcess, GetCurrentProcess, CreateProcessAsUserW, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, OpenProcessToken
api-ms-win-security-base-l1-1-0.dll
SetTokenInformation, GetSidSubAuthority, DuplicateTokenEx, AdjustTokenPrivileges, InitializeSid, GetSidLengthRequired, GetTokenInformation
api-ms-win-security-sddl-l1-1-0.dll
ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenSCManagerW, OpenServiceW
api-ms-win-service-management-l2-1-0.dll
ChangeServiceConfigW, QueryServiceConfigW, ChangeServiceConfig2W
hid.dll
HidD_GetHidGuid, HidP_GetCaps, HidD_GetAttributes, HidD_GetProductString, HidD_FreePreparsedData, HidD_GetPreparsedData
kernel32.dll
ResetEvent, WTSGetActiveConsoleSessionId, GetCurrentProcess, GetLastError, WaitForMultipleObjectsEx, GetCurrentThreadId, CloseHandle, InterlockedIncrement, GetExitCodeProcess, InterlockedDecrement, SetEvent, GetWindowsDirectoryW, ExpandEnvironmentStringsW, InterlockedExchange, InterlockedCompareExchange, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, CreateMutexW, CreateEventW, WaitForSingleObject, LocalFree, Sleep, CreateFileW, LocalAlloc, CreateThread, ReleaseMutex, InterlockedFlushSList, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, RegDeleteValueW, RegGetValueW, LoadLibraryExA, FreeLibrary, GetProcAddress, DelayLoadFailureHook, UnregisterWaitEx, InterlockedPushEntrySList, InitializeSListHead, LeaveCriticalSection
msvcrt.dll
DllMain
ntdll.dll
NtOpenEvent, NtCreateEvent, NtOpenMutant, NtOpenDirectoryObject, RtlInitUnicodeString, NtClose, EtwLogTraceEvent, EtwTraceMessage, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, RtlRemovePrivileges
ole32.dll
CoUninitialize, CoInitializeSecurity, CoCreateInstance, CoInitializeEx
setupapi.dll
SetupDiGetClassDevsExW, SetupDiEnumDeviceInterfaces, SetupDiDestroyDeviceInfoList, SetupDiGetDeviceInterfaceDetailW
slc.dll
SLGetWindowsInformationDWORD
user32.dll
RegisterDeviceNotificationW, PostThreadMessageW, UnregisterDeviceNotification, GetMessageW, DispatchMessageW, GetSystemMetrics
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
wtsapi32.dll
WTSQueryUserToken, WTSQuerySessionInformationW, WTSFreeMemory, WTSEnumerateSessionsW
Export table
ServiceMain
SvchostPushServiceGlobals