Import table
advapi32.dll
LsaOpenPolicy, LsaFreeMemory, LsaClose, LsaQueryInformationPolicy, OpenThreadToken, GetTokenInformation, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, AccessCheck, AreAllAccessesGranted, MakeAbsoluteSD, RegisterServiceCtrlHandlerExW, SetServiceStatus, RegCreateKeyW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, InitializeSecurityDescriptor, SetSecurityDescriptorControl, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, RegQueryValueExW, RegSetValueExW, RegDeleteValueW, RegOpenKeyW, ImpersonateSelf, RevertToSelf, FreeSid, AllocateAndInitializeSid, CheckTokenMembership, RegCloseKey
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
RaiseException, GetLastError, SetLastError, UnhandledExceptionFilter, SetUnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
SetLastError, GetLastError, RaiseException, SetUnhandledExceptionFilter, UnhandledExceptionFilter
api-ms-win-core-file-l1-1-0.dll
FlushFileBuffers, GetFileSize, SetEndOfFile, SetFilePointer, DeleteFileW, CreateFileW, FindVolumeClose, FindFirstVolumeW, GetVolumeInformationW, GetDriveTypeW, FindNextVolumeW
api-ms-win-core-file-l1-2-0.dll
FlushFileBuffers, SetEndOfFile, FindVolumeClose, FindNextVolumeW, GetFileSize, GetDriveTypeW, DeleteFileW, CreateFileW, GetVolumeInformationW, FindFirstVolumeW, SetFilePointer
api-ms-win-core-file-l2-1-0.dll
ReadDirectoryChangesW, MoveFileExW
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedDecrement, InterlockedExchange, InterlockedCompareExchange, InterlockedIncrement
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedCompareExchange, InterlockedIncrement, InterlockedDecrement, InterlockedExchange
api-ms-win-core-io-l1-1-0.dll
CancelIoEx, GetOverlappedResult, DeviceIoControl
api-ms-win-core-io-l1-1-1.dll
GetOverlappedResult, DeviceIoControl, CancelIoEx
api-ms-win-core-localization-l1-1-0.dll
LCMapStringW
api-ms-win-core-localization-l1-2-0.dll
LCMapStringW
api-ms-win-core-localregistry-l1-1-0.dll
RegCloseKey, RegOpenKeyExW, RegDeleteValueW, RegSetValueExW, RegQueryValueExW, RegCreateKeyExW
api-ms-win-core-misc-l1-1-0.dll
LocalAlloc, Sleep, LocalFree
api-ms-win-core-processthreads-l1-1-0.dll
GetCurrentThreadId, CreateThread, GetCurrentProcessId, TerminateProcess, GetCurrentThread, OpenThreadToken, OpenThread, OpenProcessToken, GetCurrentProcess
api-ms-win-core-processthreads-l1-1-1.dll
CreateThread, GetCurrentProcess, GetCurrentThreadId, GetCurrentProcessId, OpenThreadToken, GetCurrentThread, OpenProcessToken, OpenThread, TerminateProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegOpenKeyExW, RegDeleteValueW, RegSetValueExW, RegCloseKey, RegCreateKeyExW, RegQueryValueExW
api-ms-win-core-string-l1-1-0.dll
WideCharToMultiByte
api-ms-win-core-synch-l1-1-0.dll
ResetEvent, CreateEventW, InitializeCriticalSection, DeleteCriticalSection, SetEvent, LeaveCriticalSection, EnterCriticalSection
api-ms-win-core-synch-l1-2-0.dll
SetEvent, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, ResetEvent, CreateEventW, Sleep, DeleteCriticalSection
api-ms-win-core-sysinfo-l1-1-0.dll
GetSystemTime, GetTickCount, GetSystemTimeAsFileTime, SystemTimeToFileTime
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount, GetSystemTime
api-ms-win-core-timezone-l1-1-0.dll
SystemTimeToFileTime
api-ms-win-security-base-l1-1-0.dll
RevertToSelf, GetTokenInformation, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, AccessCheck, AreAllAccessesGranted, MakeAbsoluteSD, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, InitializeSecurityDescriptor, SetSecurityDescriptorControl, InitializeAcl, AddAccessDeniedAce, AddAccessAllowedAce, AdjustTokenPrivileges, ImpersonateSelf, FreeSid, AllocateAndInitializeSid, CheckTokenMembership
api-ms-win-security-base-l1-2-0.dll
InitializeAcl, RevertToSelf, SetSecurityDescriptorOwner, AdjustTokenPrivileges, GetTokenInformation, AddAccessAllowedAce, InitializeSecurityDescriptor, FreeSid, AllocateAndInitializeSid, SetSecurityDescriptorGroup, SetSecurityDescriptorControl, SetSecurityDescriptorDacl, SetSecurityDescriptorSacl, CheckTokenMembership, MakeAbsoluteSD, AccessCheck, AreAllAccessesGranted, ImpersonateSelf
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
api-ms-win-service-private-l1-1-0.dll
I_ScRegisterDeviceNotification, I_ScUnregisterDeviceNotification
kernel32.dll
LoadLibraryExA, FreeLibrary, GetProcAddress, DelayLoadFailureHook, ReadDirectoryChangesW, UnregisterWait, MoveFileW, MoveFileExW, GetComputerNameW, GetCurrentThread, LCMapStringW, OpenThread, WideCharToMultiByte, DeviceIoControl, GetDriveTypeW, GetVolumeInformationW, LocalAlloc, LocalFree, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, InterlockedExchange, FindFirstVolumeW, FindNextVolumeW, FindVolumeClose, GetTickCount, CreateFileW, GetOverlappedResult, SetEvent, Sleep, CreateEventW, CloseHandle, DeleteFileW, ResetEvent, SetFilePointer, SetEndOfFile, GetFileSize, InterlockedDecrement, InterlockedIncrement, SetLastError, GetLastError, CancelIo, InterlockedCompareExchange, FlushFileBuffers, GetSystemTime, SystemTimeToFileTime, RaiseException, InitializeCriticalSection, DeleteCriticalSection, EnterCriticalSection, LeaveCriticalSection, QueryPerformanceCounter, UnregisterWaitEx
msvcrt.dll
DllMain
netapi32.dll
NetApiBufferFree, DsGetDcNameW, NetShareEnum, NetApiBufferAllocate
ntdll.dll
NtFsControlFile, RtlCreateSystemVolumeInformationFolder, RtlFreeUnicodeString, RtlDosPathNameToNtPathName_U, NtQueryVolumeInformationFile, RtlDeregisterWaitEx, RtlRegisterWait, RtlNtStatusToDosError, NtClose, NtWaitForSingleObject, NtReadFile, NtWriteFile, NtCompleteConnectPort, NtAcceptConnectPort, NtReplyPort, NtReplyWaitReceivePortEx, NtConnectPort, RtlInitUnicodeString, NtSetEvent, NtClearEvent, NtOpenEvent, NtCreateWaitablePort, RtlSetThreadErrorMode, NtCreateFile, RtlUnicodeStringToOemString, RtlDowncaseUnicodeString, RtlOemStringToUnicodeString, RtlInitString, NtSetVolumeInformationFile, NtOpenFile, NtQueryInformationFile, NtCancelTimer, NtCreateTimer, NtSetTimer, NtQueryDirectoryFile, RtlCompareMemoryUlong, RtlFreeHeap
rpcrt4.dll
RpcServerUseProtseqEpW, I_RpcBindingInqTransportType, RpcCancelThread, RpcServerUnregisterIf, RpcBindingVectorFree, RpcStringBindingComposeW, RpcEpUnregister, RpcBindingSetAuthInfoW, RpcBindingFree, RpcServerRegisterAuthInfoW, RpcBindingToStringBindingW, RpcStringBindingParseW, RpcEpRegisterW, RpcServerRegisterIfEx, RpcServerInqBindings, RpcStringFreeW, RpcAsyncCompleteCall, NdrAsyncServerCall, NdrServerCall2, RpcMgmtSetCancelTimeout, RpcRevertToSelf, RpcBindingFromStringBindingW, RpcImpersonateClient, NdrClientCall2, UuidCreate
user32.dll
UnregisterDeviceNotification, RegisterDeviceNotificationW
Export table
ServiceMain
SvchostPushServiceGlobals