Import table
advapi32.dll
GetSecurityDescriptorLength, ImpersonateLoggedOnUser, RevertToSelf, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, MakeSelfRelativeSD, GetTokenInformation, AllocateAndInitializeSid, SetEntriesInAclW, InitiateShutdownW, OpenProcessToken, LookupPrivilegeValueW, AdjustTokenPrivileges, GetTraceEnableFlags, GetTraceEnableLevel, GetTraceLoggerHandle, RegCreateKeyExW, ConvertSecurityDescriptorToStringSecurityDescriptorW, SetSecurityInfo, RegisterServiceCtrlHandlerExW, SetServiceStatus, RegSetValueExW, RegCloseKey, ControlTraceW, EnableTrace, RegOpenKeyExW, RegQueryValueExW, UnregisterTraceGuids, RegisterTraceGuidsW, TraceMessage, RegEnumValueW, RegOpenCurrentUser, RegDeleteValueW, AuditQuerySystemPolicy, AuditQueryPerUserPolicy, AuditFree, RegDeleteKeyW
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, RaiseException, UnhandledExceptionFilter, GetLastError
api-ms-win-core-file-l1-2-0.dll
CreateFileW
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapDestroy, GetProcessHeap, HeapReAlloc, HeapFree, HeapSize
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedCompareExchange64, InterlockedDecrement, InterlockedIncrement, InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-io-l1-1-1.dll
DeviceIoControl
api-ms-win-core-libraryloader-l1-1-1.dll
LoadResource, FindResourceExW, FreeLibrary, LoadLibraryExW, SizeofResource, LockResource, LoadStringW
api-ms-win-core-processthreads-l1-1-1.dll
GetCurrentThread, CreateThread, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, OpenProcessToken, GetCurrentProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter, QueryPerformanceFrequency
api-ms-win-core-registry-l1-1-0.dll
RegQueryValueExW, RegOpenKeyExW, RegSetValueExW, RegCloseKey, RegCreateKeyExW, RegEnumKeyExW, RegGetValueW, RegDeleteTreeW
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar
api-ms-win-core-synch-l1-2-0.dll
ReleaseMutex, WaitForSingleObject, CreateEventW, DeleteCriticalSection, InitializeCriticalSection, EnterCriticalSection, ResetEvent, LeaveCriticalSection, Sleep, SetEvent, CreateMutexW
api-ms-win-core-sysinfo-l1-2-0.dll
GetSystemTimeAsFileTime, GetTickCount, GetVersionExW
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolTimer, CreateThreadpoolTimer, CloseThreadpoolTimer, WaitForThreadpoolTimerCallbacks
api-ms-win-eventing-classicprovider-l1-1-0.dll
RegisterTraceGuidsW, GetTraceEnableLevel, GetTraceEnableFlags, TraceMessage, UnregisterTraceGuids, GetTraceLoggerHandle
api-ms-win-eventing-controller-l1-1-0.dll
ControlTraceW
api-ms-win-security-base-l1-2-0.dll
ImpersonateLoggedOnUser, GetSecurityDescriptorLength, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AdjustTokenPrivileges, AllocateAndInitializeSid, GetTokenInformation, SetSecurityDescriptorSacl, MakeSelfRelativeSD, RevertToSelf
api-ms-win-security-lsalookup-l2-1-0.dll
LookupPrivilegeValueW
api-ms-win-security-sddl-l1-1-0.dll
ConvertSecurityDescriptorToStringSecurityDescriptorW, ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
kernel32.dll
RegEnumValueW, RegOpenCurrentUser, RegDeleteValueW, InterlockedDecrement, InterlockedIncrement, GetLastError, MultiByteToWideChar, SetEvent, CloseHandle, WaitForSingleObject, CreateThread, CreateEventW, TerminateThread, DeviceIoControl, CreateFileW, SizeofResource, LockResource, LoadResource, FindResourceW, FindResourceExW, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, DeleteCriticalSection, CreateMutexW, ReleaseMutex, SetThreadpoolTimer, InterlockedCompareExchange64, UnregisterWait, CloseThreadpoolTimer, WaitForThreadpoolTimerCallbacks, CreateThreadpoolTimer, QueryPerformanceCounter, QueryPerformanceFrequency, LocalFree, UnregisterWaitEx, LocalAlloc, lstrcmpW, RegisterWaitForSingleObject, GetVersionExW, InterlockedExchange, DuplicateHandle, GetCurrentThread, GetCurrentProcess, GetSystemPowerStatus, WTSGetActiveConsoleSessionId, ResetEvent, DelayLoadFailureHook, GetProcAddress, FreeLibrary, InterlockedCompareExchange, LoadLibraryExA, HeapDestroy, HeapAlloc, HeapFree, HeapReAlloc, HeapSize, GetProcessHeap, RaiseException, GetVersionExA, Sleep, GetTickCount, GetCurrentThreadId, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, QueueUserWorkItem, LoadLibraryA, ResolveDelayLoadedAPI
msvcrt.dll
DllMain
ntdll.dll
RtlCompareMemory, NtQueryVolumeInformationFile
ole32.dll
StringFromGUID2, CoFreeUnusedLibraries, CoCreateInstance, PropVariantClear, CoTaskMemFree, CoTaskMemAlloc, CoUninitialize, CoInitializeEx, PropVariantCopy
setupapi.dll
SetupDiGetDeviceInterfaceDetailW, SetupDiOpenDeviceInterfaceW, SetupDiCreateDeviceInfoList, SetupDiSetClassInstallParamsW, SetupDiCallClassInstaller, SetupDiSetDeviceRegistryPropertyW, SetupDiDestroyDeviceInfoList, SetupDiGetDevicePropertyW, SetupDiGetDeviceInstanceIdW, SetupDiEnumDeviceInfo, SetupDiGetClassDevsW, SetupDiEnumDeviceInterfaces, SetupDiGetDeviceRegistryPropertyW, SetupDiGetDeviceInstallParamsW, SetupDiSetDeviceInstallParamsW, CM_Get_DevNode_Status_Ex
user32.dll
DispatchMessageW, GetMessageW, PeekMessageW, UnregisterDeviceNotification, PostThreadMessageW, RegisterDeviceNotificationW, LoadStringW, MsgWaitForMultipleObjectsEx, UnregisterClassA
userenv.dll
RegisterGPNotification, UnregisterGPNotification
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateSessionsW, WTSFreeMemory
Export table
ServiceMain
SvchostPushServiceGlobals