Import table
advapi32.dll
RegConnectRegistryW, CheckTokenMembership, CreateWellKnownSid, MakeSelfRelativeSD, MakeAbsoluteSD, BuildTrusteeWithSidW, SetNamedSecurityInfoW, SetThreadToken, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, InitiateSystemShutdownExW, ConvertSidToStringSidW, ImpersonateLoggedOnUser, CreateProcessAsUserW, RevertToSelf, RegEnumKeyExW, AllocateAndInitializeSid, SetEntriesInAclW, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, RegQueryInfoKeyW, RegSetValueExW, RegCreateKeyExW, RegCloseKey, RegDeleteValueW, RegDeleteKeyW, EventWriteEndScenario, GetSecurityDescriptorDacl, GetFileSecurityW, GetAclInformation, GetAce, RegisterEventSourceW, DeregisterEventSource, ReportEventW, IsValidSecurityDescriptor, OpenProcessToken, LsaGetUserName, LsaFreeMemory, LookupAccountSidW, DuplicateToken, DuplicateTokenEx, ControlService, OpenSCManagerW, OpenServiceW, QueryServiceStatus, StartServiceW, QueryServiceConfigW, NotifyServiceStatusChangeW, CloseServiceHandle, GetTokenInformation, EventUnregister, EventRegister, EventWrite, TraceMessage, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, SetServiceStatus, RegisterServiceCtrlHandlerW, RegQueryValueExW, RegOpenKeyExW, AccessCheckAndAuditAlarmW, OpenThreadToken, EventWriteStartScenario, EventActivityIdControl, EqualSid, QueryTraceW, EnableTrace, StartTraceW, ControlTraceW, GetSecurityDescriptorLength, SetServiceBits
icaapi.dll
IcaChannelClose, IcaStackOpen, IcaStackConnectionRequest, IcaStackConnectionClose, IcaStackConnectionWait, IcaStackConnectionAccept, IcaStackLock, IcaChannelIoControl, IcaStackTerminate, _IcaStackIoControl, IcaPushConsoleStack, IcaStackClose, IcaStackDisconnect, IcaOpen, IcaIoControl, IcaStackIoControl, IcaClose, IcaStackUnlock, IcaChannelOpen
kernel32.dll
CreateThread, VerifyVersionInfoW, VerSetConditionMask, GetModuleHandleExW, ExpandEnvironmentStringsW, ProcessIdToSessionId, GetModuleFileNameW, GetModuleHandleW, LoadLibraryExW, FindResourceW, LoadResource, SizeofResource, lstrcmpiW, lstrlenW, ResetEvent, GetCurrentThread, GetSystemTime, MultiByteToWideChar, DeviceIoControl, GetCurrentProcessId, FormatMessageW, IsDebuggerPresent, CreateProcessW, SleepEx, LocalSize, SetLastError, QueryDosDeviceW, CreateFileW, OpenProcess, RegisterWaitForSingleObject, HeapFree, GetProcessHeap, HeapAlloc, OutputDebugStringA, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetVersionExA, LoadLibraryA, DelayLoadFailureHook, InterlockedExchange, CompareFileTime, InterlockedCompareExchange, LocalAlloc, GetCurrentProcess, CreateDirectoryW, GetVersionExW, GetComputerNameW, ExitThread, WaitForSingleObject, SetEvent, GetLastError, GetExitCodeThread, WaitForMultipleObjects, InterlockedIncrement, InterlockedDecrement, RaiseException, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, DisableThreadLibraryCalls, UnregisterWait, CloseHandle, Sleep, DebugBreak, DuplicateHandle, CreateEventW, LocalFree, GetProcAddress, LoadLibraryW, FreeLibrary, GetSystemTimeAsFileTime, SystemTimeToFileTime, GetSystemDirectoryW, RtlCaptureStackBackTrace, lstrcmpW
msvcrt.dll
DllMain
ntdll.dll
NtDuplicateToken, RtlLengthSid, RtlRaiseException, RtlAcquireResourceExclusive, RtlAcquireResourceShared, RtlReleaseResource, RtlMapGenericMask, RtlGetAce, RtlQueryInformationAcl, RtlGetDaclSecurityDescriptor, RtlCreateUserSecurityObject, RtlGetOwnerSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlCopySecurityDescriptor, RtlGetGroupSecurityDescriptor, NtQueryInformationProcess, RtlCopySid, NtQueryInformationToken, NtOpenProcessToken, NtOpenProcess, DbgPrint, RtlEqualSid, RtlNtStatusToDosError, NtQueryVirtualMemory, RtlFreeSid, RtlCompareMemory, RtlExtendedLargeIntegerDivide, RtlInitString, NtDuplicateObject, NtClose, NtQueryLicenseValue, RtlAdjustPrivilege, RtlClearBits, RtlAreBitsSet, RtlFindClearBitsAndSet, RtlLookupElementGenericTable, RtlInitializeGenericTable, RtlDeleteElementGenericTable, RtlEnumerateGenericTable, RtlInsertElementGenericTable, RtlInitializeBitMap, RtlDeleteResource, RtlInitializeResource, NtQuerySystemTime, NtQuerySystemInformation, RtlInitAnsiString, RtlAnsiStringToUnicodeString, RtlInitUnicodeString, NtCreateFile, RtlCaptureStackBackTrace, RtlAllocateAndInitializeSid, RtlGetControlSecurityDescriptor, RtlNumberGenericTableElements
psapi.dll
EnumProcessModules
rpcrt4.dll
UuidFromStringW, UuidToStringW, RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, I_RpcBindingIsClientLocal, I_RpcBindingInqLocalClientPID, RpcServerUseProtseqEpW, RpcServerRegisterIfEx, RpcServerListen, RpcBindingToStringBindingW, RpcStringBindingParseW, RpcStringFreeW, RpcServerInqCallAttributesW, RpcImpersonateClient, RpcRevertToSelf, RpcServerUnregisterIfEx, NdrServerCall2
shell32.dll
SHEvaluateSystemCommandTemplate, FindExecutableW
wintrust.dll
WinVerifyTrust, CryptCATAdminAcquireContext, CryptCATAdminCalcHashFromFileHandle, CryptCATCatalogInfoFromContext, CryptCATAdminEnumCatalogFromHash, CryptCATAdminReleaseCatalogContext, CryptCATAdminReleaseContext, WTHelperProvDataFromStateData, WTHelperGetProvSignerFromChain
ws2_32.dll
GetNameInfoW
Export table
ServiceMain
SvchostPushServiceGlobals