Import table
advapi32.dll
InitializeAcl, SetSecurityDescriptorSacl, SetSecurityDescriptorDacl, SetSecurityDescriptorGroup, SetSecurityDescriptorOwner, InitializeSecurityDescriptor, AddAuditAccessAceEx, AddAccessDeniedAceEx, CreateProcessAsUserW, RegSetValueExW, SetSecurityInfo, GetAce, GetLengthSid, GetSecurityDescriptorDacl, GetSecurityDescriptorControl, RegGetKeySecurity, RegQueryInfoKeyW, EventWrite, ConvertSidToStringSidW, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, SetServiceStatus, RegisterServiceCtrlHandlerExW, TraceMessage, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, RegisterTraceGuidsW, UnregisterTraceGuids, EventRegister, EventUnregister, IsValidAcl, AddAccessAllowedAceEx, AddAce, EqualSid
kernel32.dll
GetLastError, CreateEventW, EnterCriticalSection, LeaveCriticalSection, VerifyVersionInfoW, VerSetConditionMask, SetEvent, UnregisterWait, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, lstrlenW, GetSystemDirectoryW, CreateThreadpool, CreateThreadpoolCleanupGroup, CloseThreadpoolCleanupGroup, CloseThreadpool, LocalFree, TrySubmitThreadpoolCallback, CallbackMayRunLong, WaitForSingleObject, CloseThreadpoolCleanupGroupMembers, ExpandEnvironmentStringsW, CreateFileW, DeviceIoControl, SearchPathW, CompareFileTime, CreateThread, WaitForMultipleObjects, CreateWaitableTimerW, RegisterWaitForSingleObject, RtlCaptureContext, CancelWaitableTimer, SetWaitableTimer, FileTimeToSystemTime, GetDateFormatW, GetTickCount64, ResumeThread, GetExitCodeProcess, TerminateProcess, GetCurrentProcess, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetTickCount, GetSystemTimeAsFileTime, GetCurrentThreadId, GetCurrentProcessId, QueryPerformanceCounter, InterlockedCompareExchange, InterlockedExchange, Sleep, CloseHandle, UnregisterWaitEx
msvcrt.dll
DllMain
ntdll.dll
RtlInitUnicodeString, DbgPrint, RtlNtStatusToDosError, NtQuerySystemInformation
rpcrt4.dll
UuidFromStringW, UuidToStringW, UuidCreate, RpcStringFreeW
setupapi.dll
SetupDiDeleteDeviceInfo, CM_Get_DevNode_Status, SetupDiGetDeviceInstanceIdW, SetupDiOpenDevRegKey, SetupDiGetDeviceInfoListDetailW, SetupDiGetDevicePropertyW, SetupDiGetClassDevsW, CM_Query_And_Remove_SubTreeW, CM_Setup_DevNode, SetupDiDestroyDeviceInfoList, SetupDiCreateDeviceInfoList, SetupDiGetDeviceRegistryPropertyW, SetupDiOpenDeviceInfoW, SetupDiEnumDeviceInfo, CM_Get_DevNode_Status_Ex
wudfplatform.dll
WdfGetLpcInterface, GetAndInitializePlatformObject, ShutdownPlatformLibrary, InitializePlatformLibrary
Export table
ServiceMain
SvchostPushServiceGlobals