Import table
advapi32.dll
ConvertSidToStringSidW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, DuplicateTokenEx, ConvertStringSidToSidW, SetTokenInformation, GetSidSubAuthorityCount, GetSidSubAuthority, RegGetValueW, RegOpenKeyExW, RegDeleteValueW, RegCloseKey, RegisterServiceCtrlHandlerExW, GetLengthSid, GetTokenInformation, CreateProcessAsUserW, TraceMessage, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegisterTraceGuidsW, UnregisterTraceGuids, RevertToSelf, ImpersonateLoggedOnUser, OpenProcessToken, OpenThreadToken, SetServiceStatus, ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-appmodel-runtime-l1-1-0.dll
GetApplicationUserModelId, GetPackageFullName
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetLastError
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll
HeapFree, GetProcessHeap, HeapAlloc
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange, InterlockedDecrement, InterlockedIncrement
api-ms-win-core-kernel32-legacy-l1-1-0.dll
LoadLibraryW, WTSGetActiveConsoleSessionId
api-ms-win-core-libraryloader-l1-1-1.dll
LoadLibraryExW, DisableThreadLibraryCalls, FreeLibrary, GetProcAddress
api-ms-win-core-memory-l1-1-1.dll
MapViewOfFile, CreateFileMappingW, ReadProcessMemory, UnmapViewOfFile
api-ms-win-core-namespace-l1-1-0.dll
OpenPrivateNamespaceW, ClosePrivateNamespace, CreatePrivateNamespaceW
api-ms-win-core-processthreads-l1-1-1.dll
GetProcessTimes, OpenThreadToken, OpenProcessToken, CreateProcessAsUserW, ResumeThread, TerminateProcess, GetCurrentProcessId, InitializeProcThreadAttributeList, UpdateProcThreadAttribute, DeleteProcThreadAttributeList, GetExitCodeProcess, GetProcessId, ProcessIdToSessionId, GetCurrentThreadId, GetCurrentProcess, CreateProcessW, OpenThread, CreateThread, GetThreadId, OpenProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll
QueryFullProcessImageNameW
api-ms-win-core-psapi-obsolete-l1-1-0.dll
K32GetModuleFileNameExW
api-ms-win-core-registry-l1-1-0.dll
RegGetValueW, RegSetValueExW, RegCreateKeyExW, RegCloseKey, RegOpenKeyExW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrlenW
api-ms-win-core-synch-l1-2-0.dll
Sleep, ResetEvent, SetEvent, CreateMutexW, InitializeCriticalSection, WaitForSingleObject, DeleteCriticalSection, LeaveCriticalSection, EnterCriticalSection, WaitForMultipleObjectsEx, CreateEventW, OpenEventW
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemDirectoryW, GetSystemTime, GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-threadpool-l1-2-0.dll
WaitForThreadpoolWaitCallbacks, TrySubmitThreadpoolCallback, CloseThreadpoolWait, SetThreadpoolWait, CloseThreadpoolCleanupGroup, LeaveCriticalSectionWhenCallbackReturns, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroupMembers, CreateThreadpoolWait
api-ms-win-core-threadpool-legacy-l1-1-0.dll
UnregisterWaitEx
api-ms-win-core-timezone-l1-1-0.dll
SystemTimeToFileTime
api-ms-win-core-util-l1-1-0.dll
DecodePointer, EncodePointer
api-ms-win-core-version-l1-1-0.dll
VerQueryValueW, GetFileVersionInfoExW, GetFileVersionInfoSizeExW
api-ms-win-eventing-classicprovider-l1-1-0.dll
TraceMessage
api-ms-win-security-base-l1-2-0.dll
AllocateAndInitializeSid, GetTokenInformation, FreeSid, SetTokenInformation, ImpersonateLoggedOnUser, GetSidSubAuthority, GetSidSubAuthorityCount, SetSecurityDescriptorDacl, CheckTokenMembership, RevertToSelf, InitializeSecurityDescriptor, DuplicateToken, CreateWellKnownSid, DuplicateTokenEx
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenServiceW, OpenSCManagerW
api-ms-win-service-management-l2-1-0.dll
QueryServiceConfigW
kernel32.dll
LoadLibraryExW, CompareFileTime, GetFileInformationByHandle, CreateFileW, FindNextChangeNotification, FindFirstChangeNotificationW, FindResourceW, DisableThreadLibraryCalls, DecodePointer, InitializeCriticalSection, DeleteCriticalSection, FreeLibrary, LocalFree, CloseHandle, UnmapViewOfFile, LeaveCriticalSection, EnterCriticalSection, OpenEventW, GetLastError, GetCurrentProcessId, HeapFree, CreatePrivateNamespaceW, HeapAlloc, GetProcessHeap, ClosePrivateNamespace, WaitForSingleObject, EncodePointer, GetProcAddress, LoadLibraryW, CreateProcessW, GetSystemDirectoryW, DuplicateHandle, GetCurrentProcess, OpenProcess, GetThreadId, GetProcessId, WaitForMultipleObjects, ResumeThread, MapViewOfFile, CreateFileMappingW, ProcessIdToSessionId, CreateEventW, SetEvent, CloseThreadpoolCleanupGroupMembers, InterlockedDecrement, TerminateProcess, InterlockedIncrement, LeaveCriticalSectionWhenCallbackReturns, TrySubmitThreadpoolCallback, CreateThread, CreateThreadpoolCleanupGroup, DelayLoadFailureHook, InterlockedCompareExchange, LoadLibraryA, GetCommandLineA, GetVersionExA, GetModuleHandleA, ExitProcess, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, GetCurrentThreadId, SetHandleCount, GetStdHandle, GetFileType, GetStartupInfoA, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, FreeEnvironmentStringsW, WideCharToMultiByte, GetEnvironmentStringsW, HeapDestroy, HeapCreate, VirtualFree, QueryPerformanceCounter, GetTickCount, GetSystemTimeAsFileTime, OutputDebugStringA, UnhandledExceptionFilter, SetUnhandledExceptionFilter, HeapReAlloc, HeapSize, WriteFile, GetModuleHandleW, GetCPInfo, GetACP, GetOEMCP, Sleep, VirtualAlloc, SetFilePointer, GetConsoleCP, GetConsoleMode, MultiByteToWideChar, GetLocaleInfoA, GetStringTypeA, GetStringTypeW, LCMapStringA, LCMapStringW, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, VirtualProtect, GetSystemInfo, VirtualQuery, CreateFileA, FlushFileBuffers, OpenThread, SetThreadpoolWait, SystemTimeToFileTime, GetSystemTime, CloseThreadpoolWait, WaitForThreadpoolWaitCallbacks, GetProcessTimes, GetExitCodeProcess, lstrlenW, CreateThreadpoolWait, InterlockedCompareExchange64, DeleteTimerQueueEx, CreateTimerQueueTimer, CreateTimerQueue, SizeofResource, LockResource, LoadResource, GetSystemWow64DirectoryW, RegCreateKeyExW, RegSetValueExW, K32GetModuleFileNameExW, QueryFullProcessImageNameW, LoadLibraryExA, InterlockedExchange, OpenPrivateNamespaceW, ResetEvent, UnregisterWait, CloseThreadpoolCleanupGroup, ReadProcessMemory
msvcrt.dll
DllMain
ntdll.dll
RtlUnwind, NtAlpcCreatePort, AlpcInitializeMessageAttribute, AlpcGetMessageAttribute, NtSetSystemInformation, ShipAssert, WinSqmEventWrite, NtDuplicateToken, NtQueryInformationToken, RtlUpcaseUnicodeChar, WinSqmAddToStream, NtAlpcAcceptConnectPort, NtAlpcConnectPort, NtAlpcSendWaitReceivePort, RtlInitUnicodeString, RtlCreateBoundaryDescriptor, RtlCreateServiceSid, RtlAddSIDToBoundaryDescriptor, RtlDeleteBoundaryDescriptor, NtAlpcOpenSenderProcess, NtAlpcOpenSenderThread, NtClose, NtOpenEvent, NtTerminateProcess, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, EtwTraceMessage, NtQueryInformationProcess
Export table
ServiceMain
SvchostPushServiceGlobals