Import table
advapi32.dll
PerfSetCounterRefValue, RegOpenKeyExW, RegCloseKey, RegNotifyChangeKeyValue, ImpersonateAnonymousToken, OpenThreadToken, RevertToSelf, CryptReleaseContext, CryptAcquireContextW, StartTraceW, EnableTrace, CryptDestroyHash, CryptGetHashParam, CryptHashData, CryptCreateHash, CryptAcquireContextA, GetLengthSid, CopySid, AuditComputeEffectivePolicyBySid, AuditQuerySystemPolicy, AuditFree, ConvertSecurityDescriptorToStringSecurityDescriptorW, RegSetValueExW, RegQueryValueExW, RegCreateKeyExW, RegisterServiceCtrlHandlerExW, SetServiceStatus, SetPrivateObjectSecurityEx, GetPrivateObjectSecurity, DestroyPrivateObjectSecurity, CreatePrivateObjectSecurityEx, MapGenericMask, ConvertStringSecurityDescriptorToSecurityDescriptorW, DuplicateToken, OpenProcessToken, LookupAccountSidW, ImpersonateLoggedOnUser, GetTokenInformation, CryptGenRandom, EqualSid, PerfStartProvider, PerfSetULongCounterValue, ControlTraceW, PerfSetCounterSetInfo, PerfCreateInstance, TraceMessage, UnregisterTraceGuids, RegisterTraceGuidsA, GetTraceLoggerHandle, GetTraceEnableLevel, GetTraceEnableFlags, PerfStopProvider, RegEnumValueW, RegQueryInfoKeyW
api-ms-win-core-apiquery-l1-1-0.dll
ApiSetQueryApiSetPresence
api-ms-win-core-debug-l1-1-1.dll
DebugBreak, OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
ResolveDelayLoadedAPI, DelayLoadFailureHook
api-ms-win-core-errorhandling-l1-1-1.dll
SetUnhandledExceptionFilter, GetLastError, UnhandledExceptionFilter
api-ms-win-core-file-l1-2-0.dll
CompareFileTime
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-2-0.dll
GetProcessHeap, HeapFree, HeapSize, HeapCreate, HeapDestroy, HeapReAlloc, HeapAlloc
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree
api-ms-win-core-interlocked-l1-2-0.dll
InterlockedExchange, InterlockedCompareExchange, InterlockedIncrement, InterlockedExchangeAdd, InterlockedDecrement, InterlockedCompareExchange64
api-ms-win-core-kernel32-legacy-l1-1-0.dll
LoadLibraryW
api-ms-win-core-libraryloader-l1-1-1.dll
LoadLibraryExW, FreeLibrary, DisableThreadLibraryCalls, GetProcAddress
api-ms-win-core-localization-l1-2-0.dll
FormatMessageW
api-ms-win-core-processthreads-l1-1-1.dll
GetThreadPriority, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, OpenThreadToken, GetCurrentThread, GetCurrentThreadId, GetCurrentProcess, GetCurrentProcessId, OpenProcessToken, SetThreadPriority, TerminateProcess
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegNotifyChangeKeyValue, RegSetValueExW, RegCloseKey, RegCreateKeyExW, RegOpenKeyExW, RegQueryValueExW
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar, CompareStringW, CompareStringEx, WideCharToMultiByte
api-ms-win-core-synch-l1-2-0.dll
Sleep, CreateEventW, WaitForSingleObject, LeaveCriticalSection, TryEnterCriticalSection, EnterCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, CreateEventA, ReleaseSemaphore, CreateSemaphoreExW, SetEvent
api-ms-win-core-sysinfo-l1-2-0.dll
GetComputerNameExW, GetSystemInfo, GetTickCount, GetSystemTime, GetSystemTimeAsFileTime
api-ms-win-core-threadpool-l1-2-0.dll
SetThreadpoolThreadMaximum, CreateThreadpool, SetThreadpoolWait, WaitForThreadpoolWaitCallbacks, SetThreadpoolThreadMinimum, CloseThreadpoolWait, TrySubmitThreadpoolCallback, CloseThreadpoolTimer, CreateThreadpoolTimer, SetThreadpoolTimer, WaitForThreadpoolTimerCallbacks, CreateThreadpoolWait, CloseThreadpool
api-ms-win-core-threadpool-legacy-l1-1-0.dll
UnregisterWaitEx
api-ms-win-core-threadpool-private-l1-1-0.dll
RegisterWaitForSingleObjectEx
api-ms-win-core-timezone-l1-1-0.dll
SystemTimeToFileTime
api-ms-win-core-util-l1-1-0.dll
DecodePointer, EncodePointer
api-ms-win-eventing-controller-l1-1-0.dll
StartTraceW, ControlTraceW
api-ms-win-eventing-provider-l1-1-0.dll
EventWriteTransfer
api-ms-win-security-activedirectoryclient-l1-1-0.dll
DsBindWithSpnExW, DsUnBindW, DsFreeNameResultW, DsCrackNamesW
api-ms-win-security-base-l1-1-0.dll
GetTokenInformation, CreatePrivateObjectSecurityEx, MapGenericMask, ImpersonateLoggedOnUser, DuplicateToken, GetLengthSid, CopySid, ImpersonateAnonymousToken, EqualSid, DestroyPrivateObjectSecurity, SetPrivateObjectSecurityEx, GetPrivateObjectSecurity, RevertToSelf
api-ms-win-security-base-l1-2-0.dll
SetPrivateObjectSecurityEx, RevertToSelf, EqualSid, ImpersonateAnonymousToken, ImpersonateLoggedOnUser, DuplicateToken, GetPrivateObjectSecurity, DestroyPrivateObjectSecurity, MapGenericMask, GetTokenInformation, CreatePrivateObjectSecurityEx, CopySid, GetLengthSid
api-ms-win-service-core-l1-1-0.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
api-ms-win-service-management-l1-1-0.dll
CloseServiceHandle, OpenServiceW, OpenSCManagerW
api-ms-win-service-management-l2-1-0.dll
QueryServiceConfigW, ChangeServiceConfigW
authz.dll
AuthzInitializeResourceManager, AuthziInitializeAuditEventType, AuthzAccessCheck, AuthzFreeResourceManager, AuthziFreeAuditEventType, AuthzFreeAuditEvent, AuthziLogAuditEvent, AuthziInitializeAuditEvent, AuthziInitializeAuditParamsFromArray
fwpuclnt.dll
FwpsClassifyUser0, IPsecKeyModuleUpdateAcquire0, IPsecSaContextExpire0, FwpsQueryIPsecOffloadDone0, FwpsQueryIPsecDosFWUsed0, FwpmFilterDestroyEnumHandle0, FwpmFilterEnum0, FwpmFilterCreateEnumHandle0, FwpmFreeMemory0, FwpsLayerReleaseInProcReplica0, FwpsOpenToken0, IPsecSaContextCreate1, FwpmProviderContextGetByKey1, FwpsAleExplicitCredentialsQuery0, FwpmEventProviderFireNetEvent0, FwpmEventProviderIsNetEventTypeEnabled0, IPsecSaContextGetSpi1, IPsecSaContextAddInbound1, IPsecSaContextAddOutbound1, IPsecSaContextUpdate0, FwpsLayerCreateInProcReplica0, IkeextGetConfigParameters0, FwpmEventProviderDestroy0, FwpmEngineClose0, IPsecKeyModuleDelete0, FwpmFilterUnsubscribeChanges0, FwpmProviderContextUnsubscribeChanges0, FwpmEngineOpen0, FwpmEventProviderCreate0, FwpmFilterSubscribeChanges0, FwpmProviderContextSubscribeChanges0, IPsecKeyModuleAdd0, FwpmFilterAdd0, IPsecSaContextAddOutbound0, IPsecSaContextAddInbound0, IPsecSaContextGetSpi0, FwpmProviderContextGetByKey0, IPsecSaContextCreate0, IPsecKeyModuleCompleteAcquire0, FwpmProviderContextGetByKey2, IPsecSaContextAddInboundAndTrackConnection, IPsecSaContextAddOutboundAndTrackConnection, IPsecKeyDictationCheck0, IPsecGetKeyFromDictator0, IPsecKeyNotification0, FwpmFilterGetById0
kernel32.dll
GetCurrentProcess, GetThreadPriority, SetThreadPriority, OpenEventW, SetEvent, LocalFree, WaitForThreadpoolWaitCallbacks, SetThreadpoolWait, TrySubmitThreadpoolCallback, FormatMessageW, GetSystemTime, SystemTimeToFileTime, CreateEventW, RegisterWaitForSingleObject, UnregisterWaitEx, InterlockedCompareExchange64, InterlockedExchange, InterlockedIncrement, InterlockedDecrement, GetTickCount, OutputDebugStringA, TlsSetValue, TlsGetValue, EncodePointer, TlsAlloc, GetCurrentThread, CreateThreadpoolWait, CreateThreadpool, SetThreadpoolThreadMaximum, SetThreadpoolThreadMinimum, GetSystemInfo, LoadLibraryW, CloseHandle, TlsFree, CloseThreadpool, CloseThreadpoolWait, Sleep, LoadLibraryExA, InterlockedCompareExchange, FreeLibrary, GetLastError, GetProcAddress, GetComputerNameExW, DuplicateHandle, DecodePointer, UnregisterWait, HeapCreate, HeapDestroy, HeapReAlloc, HeapAlloc, HeapFree, MultiByteToWideChar, WideCharToMultiByte, InitializeCriticalSectionAndSpinCount, DeleteCriticalSection, EnterCriticalSection, TryEnterCriticalSection, LeaveCriticalSection, InterlockedExchangeAdd, CreateEventA, WaitForSingleObject, ReleaseSemaphore, CreateSemaphoreW, CreateTimerQueue, DeleteTimerQueueEx, DeleteTimerQueueTimer, CreateTimerQueueTimer, DelayLoadFailureHook, DisableThreadLibraryCalls, SetUnhandledExceptionFilter, UnhandledExceptionFilter, TerminateProcess, GetSystemTimeAsFileTime, GetCurrentProcessId, GetCurrentThreadId, QueryPerformanceCounter, CompareStringW, GetProcessHeap, WaitForMultipleObjectsEx, CreateThread, LoadLibraryA, CompareFileTime, CompareStringEx
msasn1.dll
ASN1_Decode, ASN1_FreeDecoded, ASN1_CloseDecoder, ASN1_CloseModule, ASN1_CreateModule, ASN1Free, ASN1DecRealloc, ASN1_CreateDecoder, ASN1BERDecEndOfContents, ASN1BERDecOpenType2, ASN1BERDecPeekTag, ASN1DecSetError, ASN1BERDecExplicitTag, ASN1BERDecNotEndOfContents
msvcrt.dll
DllMain
nsi.dll
NsiGetParameter, NsiSetParameter
ntdll.dll
RtlTimeToTimeFields, RtlConvertSidToUnicodeString, RtlFreeUnicodeString, RtlIntegerToUnicodeString, RtlIpv6AddressToStringW, RtlIpv4AddressToStringW, RtlExpandHashTable, RtlContractHashTable, RtlDeleteHashTable, RtlEndEnumerationHashTable, RtlEnumerateEntryHashTable, RtlInitEnumerationHashTable, RtlGetNextEntryHashTable, RtlLookupEntryHashTable, RtlRemoveEntryHashTable, RtlInsertEntryHashTable, RtlCreateHashTable, EtwEventActivityIdControl, EtwEventUnregister, EtwEventRegister, RtlAllocateHeap, RtlValidRelativeSecurityDescriptor, RtlCompareMemory, NtQueryInformationToken, EtwEventWrite, WinSqmEndSession, WinSqmStartSession, WinSqmSetDWORD, EtwEventEnabled, RtlInitString, RtlNtStatusToDosError, RtlExtendedLargeIntegerDivide, RtlLengthSecurityDescriptor, EtwTraceMessage, EtwUnregisterTraceGuids, EtwRegisterTraceGuidsW, EtwGetTraceLoggerHandle, EtwGetTraceEnableLevel, EtwGetTraceEnableFlags, RtlAdjustPrivilege, RtlInterlockedPopEntrySList, RtlInterlockedPushEntrySList, RtlInitializeSListHead, RtlFreeHeap, RtlApplicationVerifierStop, RtlIpv6StringToAddressW, RtlIpv4StringToAddressW
pcwum.dll
PerfSetCounterSetInfo, PerfSetCounterRefValue, PerfSetULongCounterValue, PerfStartProvider, PerfCreateInstance, PerfStopProvider
rpcrt4.dll
RpcRaiseException, RpcEpRegisterW, RpcServerInqBindings, RpcServerRegisterIfEx, RpcServerUseProtseqW, RpcGetAuthorizationContextForClient, RpcFreeAuthorizationContext, RpcRevertToSelf, RpcImpersonateClient, UuidCreate, RpcServerInqCallAttributesW, I_RpcExceptionFilter, MesEncodeDynBufferHandleCreate, MesDecodeBufferHandleCreate, RpcServerUnregisterIfEx, NdrMesTypeDecode2, NdrMesTypeFree2, RpcStringFreeW, UuidToStringW, RpcEpUnregister, MesHandleFree, NdrMesTypeEncode2, RpcBindingVectorFree, NdrAsyncServerCall, NdrServerCall2, RpcAsyncCompleteCall
secur32.dll
LsaLookupAuthenticationPackage, LsaRegisterLogonProcess, FreeContextBuffer, QueryContextAttributesW, InitializeSecurityContextW, AcceptSecurityContext, FreeCredentialsHandle, DeleteSecurityContext, QueryCredentialsAttributesW, LsaFreeReturnBuffer, LsaLogonUser, QuerySecurityContextToken, AcquireCredentialsHandleW, QuerySecurityPackageInfoW, EncryptMessage, DecryptMessage, LsaUnregisterPolicyChangeNotification, LsaRegisterPolicyChangeNotification, LsaCallAuthenticationPackage, LsaGetLogonSessionData
sspicli.dll
QueryCredentialsAttributesW, FreeCredentialsHandle, DeleteSecurityContext, QuerySecurityPackageInfoW, LsaFreeReturnBuffer, LsaLogonUser, InitializeSecurityContextW, AcceptSecurityContext, AcquireCredentialsHandleW, EncryptMessage, DecryptMessage, LsaUnregisterPolicyChangeNotification, LsaRegisterPolicyChangeNotification, QuerySecurityContextToken, QueryContextAttributesW, FreeContextBuffer, LsaRegisterLogonProcess, LsaDeregisterLogonProcess, LsaCallAuthenticationPackage, LsaLookupAuthenticationPackage
ws2_32.dll
WSASocketA, WSCEnumProtocols, WSASocketW, WSAEventSelect, WSAIoctl, getnameinfo, GetAddrInfoW, FreeAddrInfoW
Export table
IkeServiceMain
SvchostPushServiceGlobals