Import table
advapi32.dll
DeregisterEventSource, RegOpenKeyExW, RegCloseKey, RegisterServiceCtrlHandlerExW, SetServiceStatus, RegCreateKeyExW, ImpersonateLoggedOnUser, AllocateAndInitializeSid, CheckTokenMembership, FreeSid, ReportEventW, RegisterEventSourceW, RegSetValueExW, RegQueryValueExW, CloseServiceHandle, QueryServiceConfigW, QueryServiceStatus, OpenServiceW, OpenSCManagerW, StartServiceW, ChangeServiceConfigW, ControlService, CreateProcessAsUserW, RevertToSelf, RegOpenCurrentUser, RegNotifyChangeKeyValue, ConvertSidToStringSidW, OpenThreadToken, GetTokenInformation, GetSidSubAuthorityCount, GetSidSubAuthority, OpenProcessToken, EventRegister, EventUnregister, RegDeleteValueW, ConvertStringSidToSidW, NotifyServiceStatusChangeW, EventWrite
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-0.dll
UnhandledExceptionFilter, GetLastError, SetUnhandledExceptionFilter
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetLastError
api-ms-win-core-handle-l1-1-0.dll
DuplicateHandle, CloseHandle
api-ms-win-core-heap-l1-1-0.dll
HeapFree, HeapAlloc, GetProcessHeap
api-ms-win-core-heap-l1-2-0.dll
HeapAlloc, HeapFree, GetProcessHeap
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedCompareExchange, InterlockedExchange
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange
api-ms-win-core-processenvironment-l1-1-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll
ExpandEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-1.dll
OpenThreadToken, GetCurrentThreadId, GetCurrentProcessId, CreateProcessW, TerminateProcess, CreateThread, OpenProcess, GetCurrentProcess
api-ms-win-core-processthreads-l1-1-2.dll
TerminateProcess, GetCurrentThreadId, CreateThread, GetCurrentProcessId, CreateProcessW, GetCurrentProcess, OpenThreadToken, GetExitCodeProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegQueryValueExW, RegDeleteValueW, RegCloseKey, RegSetValueExW, RegGetValueW, RegOpenKeyExW, RegNotifyChangeKeyValue, RegCreateKeyExW, RegDeleteKeyExW, RegEnumValueW
api-ms-win-core-synch-l1-1-1.dll
WaitForMultipleObjectsEx, CancelWaitableTimer, WaitForSingleObject, SetWaitableTimer, SetEvent, Sleep, CreateEventW
api-ms-win-core-synch-l1-2-0.dll
WaitForSingleObject, WaitForMultipleObjectsEx, SetWaitableTimer, SetEvent, Sleep, CancelWaitableTimer, CreateEventW, DeleteCriticalSection, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection
api-ms-win-core-sysinfo-l1-1-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-core-sysinfo-l1-2-0.dll
GetTickCount, GetSystemTimeAsFileTime
api-ms-win-core-sysinfo-l1-2-1.dll
GetSystemTimeAsFileTime, GetTickCount
api-ms-win-eventing-provider-l1-1-0.dll
EventWrite
api-ms-win-obsolete-kernelbase-l1-1-0.dll
LocalFree
api-ms-win-security-base-l1-1-0.dll
AllocateAndInitializeSid, GetSidSubAuthorityCount, CheckTokenMembership, GetTokenInformation, FreeSid, GetSidSubAuthority
api-ms-win-security-base-l1-2-0.dll
AllocateAndInitializeSid, GetSidSubAuthorityCount, FreeSid, CheckTokenMembership, GetSidSubAuthority, GetTokenInformation
api-ms-win-service-core-l1-1-1.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenSCManagerW, OpenServiceW
api-ms-win-service-management-l2-1-0.dll
NotifyServiceStatusChangeW
crypt32.dll
CryptHashPublicKeyInfo, CertFreeCertificateContext, CryptMsgClose, CryptMsgGetAndVerifySigner, CryptQueryObject, CertCloseStore
dbghelp.dll
ImageNtHeader
firewallapi.dll
FWChangeNotificationDestroy, FwAnalyzeFirewallPolicy, FwActivate, FWChangeNotificationCreate
hnetcfg.dll
IcfChangeNotificationDestroy, IcfDisconnect, IcfGetOperationalMode, IcfConnect, IcfFreeAdapters, IcfGetAdapters, IcfChangeNotificationCreate
kernel32.dll
WaitForSingleObject, HeapFree, HeapAlloc, ProcessIdToSessionId, OpenProcess, GetCurrentProcess, DuplicateHandle, GetProcessHeap, DeleteCriticalSection, WaitForMultipleObjects, LeaveCriticalSection, EnterCriticalSection, InitializeCriticalSection, GetLastError, CreateEventW, UnregisterWait, CloseHandle, SetEvent, CreateThread, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, GetFileSizeEx, CreateFileW, GetFileTime, LoadLibraryExW, FreeLibrary, GetSystemTimeAsFileTime, GetPrivateProfileStringW, Sleep, SystemTimeToFileTime, GetSystemTime, CancelWaitableTimer, SetWaitableTimer, CompareFileTime, WaitForMultipleObjectsEx, CreateWaitableTimerW, InterlockedIncrement, InterlockedDecrement, GetSystemDirectoryW, FindCloseChangeNotification, FindNextChangeNotification, FindFirstChangeNotificationW, InterlockedExchange, LocalFree, InterlockedCompareExchange, CreateFileMappingW, MapViewOfFile, UnmapViewOfFile, QueryFullProcessImageNameW, LoadLibraryW, SetLastError, GetCurrentThread, ResolveDelayLoadedAPI, DelayLoadFailureHook, LocalAlloc
msvcrt.dll
DllMain
netapi32.dll
NetApiBufferFree, NetGetJoinInformation
netshell.dll
NcFreeNetconProperties
netutils.dll
NetApiBufferFree
ntdll.dll
ShipAssertMsgA, WinSqmSetDWORD, EtwEventUnregister, EtwEventRegister, WinSqmIsOptedIn, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, EtwEventWrite, EtwTraceMessage, RtlPublishWnfStateData
ole32.dll
CoCreateInstance, CoTaskMemAlloc, CoUninitialize, CoInitializeEx, CoTaskMemFree, CLSIDFromString, CoDisconnectContext, StringFromCLSID
rpcrt4.dll
RpcStringFreeW, NdrServerCall2, RpcImpersonateClient, RpcRevertToSelf, RpcRaiseException, RpcServerUnregisterIfEx, RpcEpUnregister, RpcServerUseProtseqW, RpcServerRegisterIfEx, RpcServerInqDefaultPrincNameW, RpcServerRegisterAuthInfoW, RpcServerInqBindings, RpcEpRegisterW, RpcBindingVectorFree, RpcServerListen, RpcServerInqCallAttributesW
shlwapi.dll
PathFileExistsW, PathStripPathW, PathRemoveExtensionW, PathAddBackslashW
user32.dll
LoadStringW
userenv.dll
RegisterGPNotification, GetProfileType, CreateEnvironmentBlock, UnregisterGPNotification, DestroyEnvironmentBlock
version.dll
GetFileVersionInfoSizeW, VerQueryValueW, GetFileVersionInfoW
wtsapi32.dll
WTSQueryUserToken, WTSEnumerateProcessesW, WTSEnumerateSessionsW, WTSFreeMemory
Export table
ServiceMain
SvchostPushServiceGlobals