Import table
advapi32.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus, ConvertStringSecurityDescriptorToSecurityDescriptorW, CreateProcessAsUserW, RegOpenKeyExW, RegQueryValueExW, RegCloseKey
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
kernel32.dll
CreateThread, GetSystemTimeAsFileTime, GetTickCount, QueryPerformanceCounter, InterlockedExchange, SetEvent, CreateEventW, SetUnhandledExceptionFilter, UnhandledExceptionFilter, DebugBreak, IsWow64Process, Sleep, GetSystemDirectoryW, GetCurrentThread, TerminateThread, DisableThreadLibraryCalls, InterlockedIncrement, InterlockedDecrement, SetLastError, GetLastError, UnregisterWait, LocalFree, ProcessIdToSessionId, GetCurrentProcessId, InitializeCriticalSection, DeleteCriticalSection, OpenProcess, CloseHandle, GetModuleHandleExW, CreateThreadpoolWait, SetThreadpoolWait, FreeLibrary, TerminateProcess, ResumeThread, GetExitCodeProcess, GetProcessTimes, FreeLibraryWhenCallbackReturns, CloseThreadpoolWait, WaitForSingleObject, DuplicateHandle, GetCurrentProcess, EnterCriticalSection, LeaveCriticalSection, GetProcessHeap, DelayLoadFailureHook, GetProcAddress, InterlockedCompareExchange, LoadLibraryExA, GetModuleHandleW, GetCurrentThreadId, ExitProcess, IsDebuggerPresent, HeapFree, HeapAlloc, HeapReAlloc, RegisterWaitForSingleObject, UnregisterWaitEx
msvcrt.dll
DllMain
ntdll.dll
NtAcceptConnectPort, NtCompleteConnectPort, NtReplyWaitReceivePort, NtRequestPort, NtConnectPort, NtRequestWaitReplyPort, DbgPrintEx, DbgPrompt, NtQuerySystemInformation, RtlCaptureStackBackTrace, RtlInsertElementGenericTable, RtlLookupElementGenericTable, RtlInitializeGenericTable, NtQueryInformationProcess, NtReplyPort, NtCreatePort, RtlInitUnicodeString, RtlDeleteElementGenericTable, RtlEnumerateGenericTableWithoutSplaying, DbgBreakPoint
userenv.dll
DestroyEnvironmentBlock, CreateEnvironmentBlock
wtsapi32.dll
WTSEnumerateSessionsW, WTSFreeMemory, WTSQueryUserToken
Export table
ServiceMain
SvchostPushServiceGlobals