Import table
advapi32.dll
RegSetValueExW, RegEnumKeyExW, CryptDestroyKey, CryptDecrypt, CryptSetKeyParam, CryptImportKey, RegOpenKeyW, RegDeleteKeyW, DuplicateTokenEx, ImpersonateLoggedOnUser, RevertToSelf, GetTokenInformation, RegEnumValueW, OpenThreadToken, RegisterServiceCtrlHandlerExW, SetServiceStatus, CryptAcquireContextW, CryptGenRandom, CryptReleaseContext, RegCreateKeyExW, RegQueryInfoKeyW, RegDeleteValueW, RegOpenKeyExW, RegCloseKey, RegEnumKeyW, RegQueryValueExW
crypt32.dll
CryptUnprotectData, CryptProtectData
dhcpcsvc.dll
DhcpStaticRefreshParams, DhcpReleaseParameters, DhcpNotifyMediaReconnected
esent.dll
JetCreateDatabase, JetOpenDatabase, JetBeginSession, JetEndSession, JetSetSystemParameter, JetCreateInstance, JetBeginTransaction, JetRollback, JetTerm2, JetInit, JetAttachDatabase, JetCommitTransaction, JetPrepareUpdate, JetSeek, JetSetCurrentIndex, JetUpdate, JetSetColumn, JetMove, JetCreateIndex, JetAddColumn, JetMakeKey, JetDeleteTable, JetCloseTable, JetRetrieveColumn, JetOpenTable, JetGetTableColumnInfo, JetCreateTable
kernel32.dll
CloseHandle, DeviceIoControl, GetLastError, CreateFileA, OutputDebugStringW, lstrlenA, DeleteTimerQueue, WriteFile, LoadLibraryW, ResetEvent, GetStringTypeExW, GetThreadLocale, lstrcmpW, lstrlenW, InterlockedExchange, DebugBreak, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, QueryPerformanceCounter, CreateEventW, UnregisterWait, GetProcAddress, FreeLibrary, WaitForSingleObject, Sleep, SetEvent, GetSystemTimeAsFileTime, LocalAlloc, SetLastError, FormatMessageW, ExpandEnvironmentStringsW, LoadLibraryExW, WideCharToMultiByte, MultiByteToWideChar, LocalFree, ChangeTimerQueueTimer, CreateTimerQueueTimer, DeleteTimerQueueTimer, DeleteTimerQueueEx, CreateTimerQueue, BindIoCompletionCallback, HeapAlloc, InterlockedCompareExchange, GetCurrentThread, CreateFileW, ReadFile, GetUserDefaultLCID, GetProcessHeap, HeapFree, InterlockedIncrement, QueueUserWorkItem, InterlockedDecrement, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, GetUserDefaultUILanguage, CompareFileTime, SystemTimeToFileTime, GetLocalTime, VerifyVersionInfoW, CreateThread, WaitForMultipleObjects, InitializeCriticalSection
msvcrt.dll
DllMain
netapi32.dll
DsGetDcNameW, NetApiBufferFree
ntdll.dll
RtlInitUnicodeString, RtlNtStatusToDosError, VerSetConditionMask, NtDuplicateToken, NtOpenFile, RtlInitializeSid, RtlLengthRequiredSid, RtlSubAuthoritySid, RtlCopySid, RtlSubAuthorityCountSid, RtlDeleteSecurityObject, RtlLengthSid, RtlSetSaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAddAce, RtlCreateAcl, NtClose, RtlNewSecurityObject, NtOpenProcessToken, NtAccessCheckAndAuditAlarm, RtlAdjustPrivilege, RtlConvertSidToUnicodeString, NtConnectPort, NtCreateSection, NtRequestWaitReplyPort, RtlCompareMemory
ole32.dll
CoInitializeEx, StringFromGUID2, CLSIDFromString, CoCreateInstance, CoUninitialize, CoTaskMemFree
rpcrt4.dll
RpcBindingSetAuthInfoExW, RpcBindingFromStringBindingW, NdrClientCall2, RpcRevertToSelf, RpcImpersonateClient, RpcRevertToSelfEx, RpcServerUseProtseqEpW, RpcBindingFree, NdrServerCall2, RpcStringFreeW, RpcStringBindingParseW, RpcBindingToStringBindingW, UuidToStringW, RpcServerRegisterIfEx, RpcServerRegisterAuthInfoW, RpcServerListen, RpcServerUnregisterIfEx
rtutils.dll
RouterLogRegisterW, TraceVprintfExA, TraceDeregisterW, TraceRegisterExW, TracePrintfExA, RouterLogDeregisterW, TraceDumpExW, TraceDeregisterA, TraceDumpExA, RouterLogEventW
secur32.dll
GetUserNameExW
shlwapi.dll
SHDeleteKeyW
user32.dll
UnregisterDeviceNotification, wsprintfW, CharNextW, RegisterDeviceNotificationA, GetSystemMetrics, OemToCharBuffA, CharLowerW, wvsprintfW, LoadStringW
winsta.dll
WinStationQueryInformationW
wmi.dll
WmiNotificationRegistrationW
wtsapi32.dll
WTSQueryUserToken, WTSFreeMemory, WTSEnumerateSessionsW
Export table
SvchostPushServiceGlobals
WZCQueryGUIDNCSState
WZCSvcMain
WZCTrayIconReady