Import table
advapi32.dll
RegQueryValueExW, RegCloseKey, StartServiceW, QueryServiceStatus, RegDeleteKeyW, RegQueryInfoKeyW, RegEnumValueW, RegOpenKeyExW, RegSetValueExW, SetServiceStatus, EventWrite, EventRegister, EventUnregister, InitializeSecurityDescriptor, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, ChangeServiceConfig2W, RegEnumKeyW, RegFlushKey, DuplicateTokenEx, SetThreadToken, AccessCheck, IsWellKnownSid, GetFileSecurityW, LogonUserW, ImpersonateLoggedOnUser, RevertToSelf, LookupAccountSidW, ConvertStringSidToSidW, MakeAbsoluteSD, GetLengthSid, InitializeAcl, GetAclInformation, GetAce, EqualSid, AddAce, AddAccessAllowedAceEx, SetSecurityDescriptorDacl, GetSecurityDescriptorOwner, GetSecurityDescriptorGroup, RegDeleteValueW, RegCreateKeyExW, QueryAllTracesW, StartTraceW, UpdateTraceW, EnableTraceEx, FlushTraceW, StopTraceW, QueryTraceW, EnumerateTraceGuidsEx, ControlTraceW, RegConnectRegistryW, AdjustTokenPrivileges, EventAccessQuery, ConvertSecurityDescriptorToStringSecurityDescriptorW, EventAccessRemove, ConvertStringSecurityDescriptorToSecurityDescriptorW, GetSecurityDescriptorDacl, GetSecurityDescriptorSacl, RegEnumKeyExW, ControlService, ChangeServiceConfigW, OpenSCManagerW, OpenServiceW, QueryServiceConfigW, CloseServiceHandle, RegisterServiceCtrlHandlerExW, CheckTokenMembership, CreateWellKnownSid, ConvertSidToStringSidW, GetTokenInformation, OpenProcessToken, OpenThreadToken, SetNamedSecurityInfoW
api-ms-win-service-core-l1-1-0.dll
SetServiceStatus, RegisterServiceCtrlHandlerExW
api-ms-win-service-management-l1-1-0.dll
StartServiceW, CloseServiceHandle, OpenServiceW, OpenSCManagerW
api-ms-win-service-management-l2-1-0.dll
ChangeServiceConfig2W, ChangeServiceConfigW, QueryServiceConfigW
api-ms-win-service-winsvc-l1-1-0.dll
QueryServiceStatus, ControlService
crypt32.dll
CryptUnprotectData
iphlpapi.dll
GetCurrentThreadCompartmentId, GetAdaptersAddresses
kernel32.dll
HeapFree, HeapValidate, ExpandEnvironmentStringsW, GetLocaleInfoW, GetTimeZoneInformation, GetLocalTime, GetComputerNameW, LocalFree, FormatMessageW, InitializeCriticalSection, WideCharToMultiByte, GlobalFree, GlobalUnlock, UnregisterWait, GlobalLock, GlobalAlloc, SizeofResource, LockResource, LoadResource, FindResourceW, GetCurrentProcess, GetCurrentThread, Wow64RevertWow64FsRedirection, GetCurrentThreadId, Wow64DisableWow64FsRedirection, IsWow64Process, ResetEvent, CreateDirectoryW, FreeLibrary, LoadLibraryW, OpenProcess, WriteFile, CreateFileW, WaitForSingleObject, GetCurrentProcessId, QueryPerformanceCounter, FindClose, FindNextFileW, FindFirstFileW, DuplicateHandle, GetSystemTimeAsFileTime, SystemTimeToFileTime, FileTimeToSystemTime, CompareStringW, HeapReAlloc, HeapSize, GetUserDefaultUILanguage, WaitForMultipleObjects, GetExitCodeThread, CreateThread, GetProcessHeap, CreateWaitableTimerW, GetCommandLineW, InterlockedExchange, OpenEventW, CopyFileExW, GetFullPathNameW, GetTimeFormatW, GetDateFormatW, FileTimeToLocalFileTime, GetBinaryTypeW, GetProcAddress, DeleteFileW, RemoveDirectoryW, GetDiskFreeSpaceExW, GetFileSizeEx, SetPriorityClass, CopyFileW, GetExitCodeProcess, TerminateProcess, CreateProcessW, GetTempFileNameW, GetSystemTime, MultiByteToWideChar, FileTimeToDosDateTime, GetFileInformationByHandle, GetTempFileNameA, GetTempPathA, SetFileAttributesW, SetFileTime, LocalFileTimeToFileTime, DosDateTimeToFileTime, GetFileMUIPath, GetTickCount, UnhandledExceptionFilter, SetUnhandledExceptionFilter, SetEvent, IsDebuggerPresent, DebugBreak, InterlockedCompareExchange, CreateEventW, CloseHandle, GetModuleFileNameW, Sleep, DisableThreadLibraryCalls, GetSystemDirectoryW, GetLastError, GetWindowsDirectoryW, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, HeapAlloc, GetFileAttributesW, EnterCriticalSection, SetWaitableTimer, LeaveCriticalSection, FreeResource, LoadLibraryExW, K32GetModuleFileNameExW, GetTickCount64, GetTempPathW, DelayLoadFailureHook, LoadLibraryExA
msvcrt.dll
DllMain
nsi.dll
NsiAllocateAndGetTable, NsiFreeTable
ntdll.dll
RtlNtStatusToDosError, NtQuerySystemTime, RtlStringFromGUID, RtlFreeUnicodeString, EtwNotificationUnregister, EtwNotificationRegister, NtQuerySystemInformation, EtwEventUnregister, EtwEventRegister, EtwEventWrite
ole32.dll
StringFromGUID2, CoGetClassObject, StgOpenStorageEx, FreePropVariantArray, CreateStreamOnHGlobal, CoCreateInstance, CLSIDFromString, CoCreateInstanceEx, CoSetProxyBlanket, CoUninitialize, CoInitializeEx, CoInitializeSecurity, CoRegisterClassObject, CoRevokeClassObject
pdh.dll
PdhTranslate009CounterW, PdhTranslateLocaleCounterW, PdhOpenLogW, PdhCloseLog, PdhUpdateLogW, PdhAddCounterW, PdhExpandWildCardPathW, PdhOpenQueryW, PdhGetFormattedCounterValue, PdhCollectQueryData, PdhCloseQuery
psapi.dll
GetModuleFileNameExW
rpcrt4.dll
RpcBindingFromStringBindingW, RpcStringBindingComposeW, RpcStringBindingParseW, RpcBindingToStringBindingW, RpcBindingInqAuthClientW, RpcImpersonateClient, RpcRevertToSelf, RpcServerRegisterIfEx, RpcServerUseProtseqEpW, RpcServerUnregisterIfEx, RpcServerInqCallAttributesW, NdrServerCall2, NdrClientCall2, RpcBindingSetAuthInfoW, RpcBindingFree, RpcStringFreeW, UuidCreate
secur32.dll
GetUserNameExW
shell32.dll
CommandLineToArgvW
shlwapi.dll
PathIsNetworkPathW, PathIsFileSpecW
tdh.dll
TdhEnumerateProviders, TdhEnumerateProviderFieldInformation, TdhEnumerateRemoteWBEMProviderFieldInformation, TdhEnumerateRemoteWBEMProviders
user32.dll
MsgWaitForMultipleObjects, LoadStringW, PeekMessageW, CreateWindowExW, DestroyWindow, DispatchMessageW
wevtapi.dll
EvtClose, EvtCreateRenderContext, EvtRender, EvtNext, EvtSubscribe, EvtGetChannelConfigProperty, EvtOpenChannelConfig, EvtCreateBookmark, EvtUpdateBookmark
ws2_32.dll
WSAAddressToStringW
Export table
DllCanUnloadNow
DllGetClassObject
PlaConvertLogEntries
PlaDeleteReport
PlaExpandTaskArguments
PlaExtractCabinet
PlaGetLegacyAlertActionsFlagsFromString
PlaGetLegacyAlertActionsStringFromFlags
PlaGetServerCapabilities
PlaHost
PlaServer
PlaUpgrade
ServiceMain
SvchostPushServiceGlobals