Import table
api-ms-win-security-base-l1-1-0.dll
GetTokenInformation, CreatePrivateObjectSecurityEx, MapGenericMask, ImpersonateLoggedOnUser, DuplicateToken, GetLengthSid, CopySid, ImpersonateAnonymousToken, EqualSid, DestroyPrivateObjectSecurity, SetPrivateObjectSecurityEx, GetPrivateObjectSecurity, RevertToSelf
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenServiceW, OpenSCManagerW
api-ms-win-service-management-l2-1-0.dll
QueryServiceConfigW, ChangeServiceConfigW
authz.dll
AuthzInitializeResourceManager, AuthziInitializeAuditEventType, AuthzAccessCheck, AuthzFreeResourceManager, AuthziFreeAuditEventType, AuthzFreeAuditEvent, AuthziLogAuditEvent, AuthziInitializeAuditEvent, AuthziInitializeAuditParamsFromArray
fwpuclnt.dll
FwpsClassifyUser0, IPsecKeyModuleUpdateAcquire0, IPsecSaContextExpire0, FwpsQueryIPsecOffloadDone0, FwpsQueryIPsecDosFWUsed0, FwpmFilterDestroyEnumHandle0, FwpmFilterEnum0, FwpmFilterCreateEnumHandle0, FwpmFreeMemory0, FwpsLayerReleaseInProcReplica0, FwpsOpenToken0, IPsecSaContextCreate1, FwpmProviderContextGetByKey1, FwpsAleExplicitCredentialsQuery0, FwpmEventProviderFireNetEvent0, FwpmEventProviderIsNetEventTypeEnabled0, IPsecSaContextGetSpi1, IPsecSaContextAddInbound1, IPsecSaContextAddOutbound1, IPsecSaContextUpdate0, FwpsLayerCreateInProcReplica0, IkeextGetConfigParameters0, FwpmEventProviderDestroy0, FwpmEngineClose0, IPsecKeyModuleDelete0, FwpmFilterUnsubscribeChanges0, FwpmProviderContextUnsubscribeChanges0, FwpmEngineOpen0, FwpmEventProviderCreate0, FwpmFilterSubscribeChanges0, FwpmProviderContextSubscribeChanges0, IPsecKeyModuleAdd0, FwpmFilterAdd0
kernel32.dll
GetCurrentProcess, GetThreadPriority, SetThreadPriority, OpenEventW, SetEvent, LocalFree, WaitForThreadpoolWaitCallbacks, SetThreadpoolWait, TrySubmitThreadpoolCallback, FormatMessageW, GetSystemTime, SystemTimeToFileTime, CreateEventW, RegisterWaitForSingleObject, UnregisterWaitEx, InterlockedCompareExchange64, InterlockedExchange, InterlockedIncrement, InterlockedDecrement, GetTickCount, OutputDebugStringA, TlsSetValue, TlsGetValue, EncodePointer, TlsAlloc, GetCurrentThread, CreateThreadpoolWait, CreateThreadpool, SetThreadpoolThreadMaximum, SetThreadpoolThreadMinimum, GetSystemInfo, LoadLibraryW, CloseHandle, TlsFree, CloseThreadpool, CloseThreadpoolWait, Sleep, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, GetLastError, GetProcAddress, GetComputerNameExW, DuplicateHandle, DecodePointer, UnregisterWait, HeapCreate, HeapDestroy, HeapReAlloc, HeapAlloc, HeapFree, MultiByteToWideChar, WideCharToMultiByte, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EnterCriticalSection, TryEnterCriticalSection, LeaveCriticalSection, InterlockedExchangeAdd, CreateEventA, WaitForSingleObject, ReleaseSemaphore, CreateSemaphoreW, CreateTimerQueue, DeleteTimerQueueEx, DeleteTimerQueueTimer, CreateTimerQueueTimer, DelayLoadFailureHook, DisableThreadLibraryCalls, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, QueryPerformanceCounter, CompareStringW, GetProcessHeap
msasn1.dll
ASN1_Decode, ASN1_FreeDecoded, ASN1_CloseDecoder, ASN1_CloseModule, ASN1_CreateModule, ASN1Free, ASN1DecRealloc, ASN1_CreateDecoder, ASN1BERDecEndOfContents, ASN1BERDecOpenType2, ASN1BERDecPeekTag, ASN1DecSetError, ASN1BERDecExplicitTag, ASN1BERDecNotEndOfContents
msvcrt.dll
DllMain
nsi.dll
NsiGetParameter, NsiSetParameter
ntdll.dll
RtlTimeToTimeFields, RtlConvertSidToUnicodeString, RtlFreeUnicodeString, RtlIntegerToUnicodeString, RtlIpv6AddressToStringW, RtlIpv4AddressToStringW, RtlExpandHashTable, RtlContractHashTable, RtlDeleteHashTable, RtlEndEnumerationHashTable, RtlEnumerateEntryHashTable, RtlInitEnumerationHashTable, RtlGetNextEntryHashTable, RtlLookupEntryHashTable, RtlRemoveEntryHashTable, RtlInsertEntryHashTable, RtlCreateHashTable, EtwEventActivityIdControl, EtwEventUnregister, EtwEventRegister, RtlAllocateHeap, RtlValidRelativeSecurityDescriptor, RtlCompareMemory, NtQueryInformationToken, EtwEventWrite, WinSqmEndSession, WinSqmStartSession, WinSqmSetDWORD, EtwEventEnabled, RtlInitString, RtlNtStatusToDosError, RtlExtendedLargeIntegerDivide, RtlLengthSecurityDescriptor, EtwTraceMessage, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, RtlAdjustPrivilege, RtlInterlockedPopEntrySList, RtlInterlockedPushEntrySList, RtlInitializeSListHead
pcwum.dll
PerfSetCounterSetInfo, PerfSetCounterRefValue, PerfSetULongCounterValue, PerfStartProvider, PerfCreateInstance, PerfStopProvider
rpcrt4.dll
RpcRaiseException, RpcEpRegisterW, RpcServerInqBindings, RpcServerRegisterIfEx, RpcServerUseProtseqW, RpcGetAuthorizationContextForClient, RpcFreeAuthorizationContext, RpcRevertToSelf, RpcImpersonateClient, UuidCreate, RpcServerInqCallAttributesW, I_RpcExceptionFilter, MesEncodeDynBufferHandleCreate, MesDecodeBufferHandleCreate, RpcServerUnregisterIfEx, NdrMesTypeDecode2, NdrMesTypeFree2, RpcStringFreeW, UuidToStringW, RpcEpUnregister, MesHandleFree, NdrMesTypeEncode2, RpcBindingVectorFree, NdrAsyncServerCall, NdrServerCall2, RpcAsyncCompleteCall
sspicli.dll
QueryCredentialsAttributesW, FreeCredentialsHandle, DeleteSecurityContext, QuerySecurityPackageInfoW, LsaFreeReturnBuffer, LsaLogonUser, InitializeSecurityContextW, AcceptSecurityContext, AcquireCredentialsHandleW, EncryptMessage, DecryptMessage, LsaUnregisterPolicyChangeNotification, LsaRegisterPolicyChangeNotification, QuerySecurityContextToken, QueryContextAttributesW, FreeContextBuffer, LsaRegisterLogonProcess, LsaDeregisterLogonProcess, LsaCallAuthenticationPackage, LsaLookupAuthenticationPackage
ws2_32.dll
WSASocketA, WSCEnumProtocols, WSASocketW, WSAEventSelect, WSAIoctl
Export table
IkeServiceMain
SvchostPushServiceGlobals