Generated by JEB on 2019/08/01

PE: C:\Windows\System32\csrsrv.dll Base=0x180000000 SHA-256=4F315302DBA388E4C4643F09F12333C7DAEB9BCE64DCFCBABF4D57E2643D90E1
PDB: csrsrv.pdb GUID={85B5FB15-1EEE-3B22-698271F717C597C1} Age=1

383 located named symbols:
0x1800018C0: CsrDestroyProcessByPtr
0x180008400: CsrReplyToMessage
0x180005300: CsrSbApiRequestThread
0x180003280: CsrUpdateShutdownFlagsForLuid
0x18000A1E0: "__cdecl _imp_RtlFreeUnicodeString" __imp_RtlFreeUnicodeString
0x18000C7F0: "__cdecl _IMPORT_DESCRIPTOR_ntdll" __IMPORT_DESCRIPTOR_ntdll
0x180008A60: CsrDestroyThread
0x180008AD0: CsrIsClientSandboxed
0x1800081CC: CsrReportToWerSvc
0x18000AE98: "\DosDevices" ??_C@_1BI@DDHLANDD@?$AA?2?$AAD?$AAo?$AAs?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AAs?$AA?$AA@
0x180005640: CsrSbApiHandleConnectionRequest
0x18000AD40: "CSRSS: CsrSrvCreateProcess: Read" ??_C@_0FG@IJGKNNOB@CSRSS?3?5CsrSrvCreateProcess?3?5Read@
0x18000A7DC: "CSRSS" ??_C@_05CGCKMKNC@CSRSS?$AA@
0x180001450: CsrImpersonateClient
0x18000E018: "__cdecl _security_cookie_complement" __security_cookie_complement
0x1800126F0: CsrSbApiPortName
0x18000A250: "__cdecl _imp__stricmp" __imp__stricmp
0x18000A2F0: "__cdecl _imp_RtlSetUnhandledExceptionFilter" __imp_RtlSetUnhandledExceptionFilter
0x18000A858: "CSRSHR!" ??_C@_1BA@GOELFJMD@?$AAC?$AAS?$AAR?$AAS?$AAH?$AAR?$AA?$CB?$AA?$AA@
0x1800126D8: DosDevicesDirectory
0x18000A460: "__cdecl _imp_NtReadVirtualMemory" __imp_NtReadVirtualMemory
0x180001920: CsrUnlockThread
0x18000A400: "__cdecl _imp_AlpcGetMessageAttribute" __imp_AlpcGetMessageAttribute
0x18000A1F0: "__cdecl _imp_RtlInitUnicodeString" __imp_RtlInitUnicodeString
0x18000ACE0: "CSRSS: CsrSrvCreateProcess: Read" ??_C@_0FD@PPHGLIDP@CSRSS?3?5CsrSrvCreateProcess?3?5Read@
0x180012670: SessionObjectDirectory
0x1800070B0: "__cdecl guard_dispatch_icall_nop" _guard_dispatch_icall_nop
0x180001330: CsrRevertToSelf
0x180003400: CsrGetProcessLuid
0x18000A868: "`string'" ??_C@_1BM@CGIOIMBB@?$AA?$CB?$AAC?$AAS?$AAR?$AAS?$AAH?$AAR?$AA?$AA?$AAI?$AAN?$AAI?$AAT?$AA?$AA?$AA?$AA@
0x180012720: CsrDirectoryName
0x18000A888: "SharedSection" ??_C@_1BM@MFJNAPBB@?$AAS?$AAh?$AAa?$AAr?$AAe?$AAd?$AAS?$AAe?$AAc?$AAt?$AAi?$AAo?$AAn?$AA?$AA@
0x180006C60: CsrQueryApiPort
0x180008588: QueueHardError
0x180003940: CsrCreateSessionObjectDirectory
0x18000B0B0: "CSRSS: ReadUnicodeString: NtRead" ??_C@_0EM@POKGAPFO@CSRSS?3?5ReadUnicodeString?3?5NtRead@
0x18000A290: "__cdecl _imp_RtlCreateSecurityDescriptor" __imp_RtlCreateSecurityDescriptor
0x180012740: CsrNtSysInfo
0x18000A448: "__cdecl _imp_NtSetInformationThread" __imp_NtSetInformationThread
0x180002AD0: CsrShutdownProcesses
0x18000A280: "__cdecl _imp_RtlCreateTagHeap" __imp_RtlCreateTagHeap
0x18000A378: "__cdecl _imp_RtlEnterCriticalSection" __imp_RtlEnterCriticalSection
0x18000A500: "__cdecl _guard_dispatch_icall_fptr" __guard_dispatch_icall_fptr
0x18000A710: "ServerDllInitialization" ??_C@_0BI@FHMNPOJI@ServerDllInitialization?$AA@
0x180012600: CsrSharedBaseTag
0x18000A350: "__cdecl _imp_NtCreatePort" __imp_NtCreatePort
0x180001E30: CsrLockProcessByClientId
0x180012710: CsrSrvSharedSectionSize
0x18000A268: "__cdecl _imp_RtlInitString" __imp_RtlInitString
0x180012708: CsrSrvSharedSectionHeap
0x1800125F0: CsrNtSessionList
0x18000AA68: "DosDevices" ??_C@_1BG@NKCPFBJK@?$AAD?$AAo?$AAs?$AAD?$AAe?$AAv?$AAi?$AAc?$AAe?$AAs?$AA?$AA@
0x180012700: BNOLinksDirectory
0x18000AC38: "Windows SubSystem" ??_C@_1CE@EDHIFDEJ@?$AAW?$AAi?$AAn?$AAd?$AAo?$AAw?$AAs?$AA?5?$AAS?$AAu?$AAb?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?$AA@
0x1800081C0: CsrSrvUnusedFunction
0x18000A360: "__cdecl _imp_NtCompleteConnectPort" __imp_NtCompleteConnectPort
0x18000A4B0: "__cdecl _imp_LdrDisableThreadCalloutsForDll" __imp_LdrDisableThreadCalloutsForDll
0x18000A2C8: "__cdecl _imp_RtlAppendUnicodeStringToString" __imp_RtlAppendUnicodeStringToString
0x18000A840: "SbApiPort" ??_C@_1BE@KFEIKMLB@?$AAS?$AAb?$AAA?$AAp?$AAi?$AAP?$AAo?$AAr?$AAt?$AA?$AA@
0x180001F20: CsrRegisterThread
0x180012658: CsrSrvSharedSection
0x18000708B: memcpy
0x1800127F0: CsrIsReportingtoWerSvc
0x180012660: CsrObjectDirectory
0x180002240: CsrpCreateProcess
0x180006E7C: "__cdecl _security_init_cookie_ex" __security_init_cookie_ex
0x180004F20: CsrpGenerateWorldAccessSD
0x18000A4E8: "__cdecl _imp_memset" __imp_memset
0x18000A2A0: "__cdecl _imp_NtWaitForSingleObject" __imp_NtWaitForSingleObject
0x180001010: CsrCaptureArguments
0x18000A3B0: "__cdecl _imp_RtlSubAuthoritySid" __imp_RtlSubAuthoritySid
0x18000A3E8: "__cdecl _imp_NtAlpcDeleteSectionView" __imp_NtAlpcDeleteSectionView
0x18000A190: "__cdecl _imp_NtOpenProcessToken" __imp_NtOpenProcessToken
0x180006F1A: RtlUnhandledExceptionFilter
0x18000AC00: "CSRSS: GetDosDevicesProtection f" ??_C@_0DG@HEOKNALA@CSRSS?3?5GetDosDevicesProtection?5f@
0x180006F0E: "__cdecl _C_specific_handler" __C_specific_handler
0x180012620: CsrLoadedServerDll
0x180008810: CsrCreateRemoteThread
0x18000A358: "__cdecl _imp_NtTerminateThread" __imp_NtTerminateThread
0x18000A010: CsrServerApiDispatchTable
0x180006F32: RtlCaptureContext
0x18000A8A8: "%ws\BNOLINKS" ??_C@_1BK@CBBOOJPP@?$AA?$CF?$AAw?$AAs?$AA?2?$AAB?$AAN?$AAO?$AAL?$AAI?$AAN?$AAK?$AAS?$AA?$AA@
0x1800053B0: CsrSbCreateSession
0x1800033F0: CsrReferenceThread
0x18000A308: "__cdecl _imp_NtDelayExecution" __imp_NtDelayExecution
0x18000A2C0: "__cdecl _imp_LdrGetProcedureAddress" __imp_LdrGetProcedureAddress
0x18000A3B8: "__cdecl _imp_RtlLengthRequiredSid" __imp_RtlLengthRequiredSid
0x180001A50: CsrRemoveThread
0x18000B010: "CSRSS: CsrSrvCreateProcess: NtDu" ??_C@_0FA@OFBBPHFJ@CSRSS?3?5CsrSrvCreateProcess?3?5NtDu@
0x18000A270: "__cdecl _imp_RtlCreateAcl" __imp_RtlCreateAcl
0x18000A740: "\Registry\Machine\System\Current" ??_C@_1IG@FLEJHJI@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAy?$AAs?$AAt?$AAe?$AAm?$AA?2?$AAC?$AAu?$AAr?$AAr?$AAe?$AAn?$AAt@
0x18000A4E0: "__cdecl _imp_RtlSendMsgToSm" __imp_RtlSendMsgToSm
0x18000A690: CsrEventProvider
0x180008B10: CsrLockedReferenceProcess
0x18000A388: "__cdecl _imp_NtQueryInformationThread" __imp_NtQueryInformationThread
0x180009110: ReadUnicodeString
0x18000A200: "__cdecl _imp_NtQueryInformationToken" __imp_NtQueryInformationToken
0x180006F9C: "__cdecl _GSHandlerCheckCommon" __GSHandlerCheckCommon
0x18000A240: "__cdecl _imp_NtCreateEvent" __imp_NtCreateEvent
0x1800127C8: CsrMaxApiRequestThreads
0x1800057F0: CsrInsertThread
0x180012678: CsrApiPort
0x180001390: CsrpHandleInlineUserConnect
0x180009030: CsrSetForegroundPriority
0x1800034C0: CsrRemoveUnneededPrivileges
0x18000A1B0: "__cdecl _imp_RtlAllocateHeap" __imp_RtlAllocateHeap
0x18000A3F8: "__cdecl _imp_AlpcInitializeMessageAttribute" __imp_AlpcInitializeMessageAttribute
0x1800127D0: CsrHeap
0x18000AE50: "CSRSS: CsrSrvCreateProcess: RtlC" ??_C@_0EI@ONJFINIA@CSRSS?3?5CsrSrvCreateProcess?3?5RtlC@
0x18000A3D8: "__cdecl _imp_NtAlpcOpenSenderProcess" __imp_NtAlpcOpenSenderProcess
0x18000A6C0: "ObjectDirectory" ??_C@_0BA@BNPMLFML@ObjectDirectory?$AA@
0x180005720: CsrSetBackgroundPriority
0x180002A20: CsrRemoveProcess
0x18000A348: "__cdecl _imp_NtTerminateProcess" __imp_NtTerminateProcess
0x18000ABC0: "CSRSS: CsrCreateSessionObjectDir" ??_C@_0DM@DACKGJB@CSRSS?3?5CsrCreateSessionObjectDir@
0x180002940: CsrLockedDereferenceProcess
0x1800032F0: CsrLocateThreadByClientId
0x1800065E0: CsrConnectToUser
0x1800019F0: CsrDereferenceProcess
0x180005690: CsrInsertProcess
0x1800030F0: FindProcessesForShutdown
0x18000A418: "__cdecl _imp_RtlInitializeCriticalSection" __imp_RtlInitializeCriticalSection
0x18000A180: "__cdecl _imp_NtAdjustPrivilegesToken" __imp_NtAdjustPrivilegesToken
0x180001990: CsrThreadRefcountZero
0x18000A150: CsrServerSbApiDispatch
0x18000A610: "CSRSS!" ??_C@_1O@KMKFMMLM@?$AAC?$AAS?$AAR?$AAS?$AAS?$AA?$CB?$AA?$AA@
0x18000AFB0: "CSRSS: CsrSrvCreateProcess: NtDu" ??_C@_0FB@NLOIHMKK@CSRSS?3?5CsrSrvCreateProcess?3?5NtDu@
0x180007000: "__cdecl _GSHandlerCheck_SEH" __GSHandlerCheck_SEH
0x18000A178: "__cdecl _imp___C_specific_handler" __imp___C_specific_handler
0x18000A4B8: "__cdecl _imp_RtlCaptureContext" __imp_RtlCaptureContext
0x18000A808: "%ws\%ld%s" ??_C@_09GCBKCEBC@?$CFws?2?$CFld?$CFs?$AA@
0x18000A4A0: "__cdecl _imp_RtlCreateUserProcess" __imp_RtlCreateUserProcess
0x1800058B0: CsrExecServerThread
0x18000A830: "ApiPort" ??_C@_1BA@NOKOJJED@?$AAA?$AAp?$AAi?$AAP?$AAo?$AAr?$AAt?$AA?$AA@
0x180006F78: "__cdecl _GSHandlerCheck" __GSHandlerCheck
0x1800125E0: CsrpStaticThreadCount
0x18000A218: "__cdecl _imp_RtlAddAccessAllowedAce" __imp_RtlAddAccessAllowedAce
0x18000AA00: "%ws\%ld" ??_C@_1BA@HLJIPNMB@?$AA?$CF?$AAw?$AAs?$AA?2?$AA?$CF?$AAl?$AAd?$AA?$AA@
0x18000A318: "__cdecl _imp_RtlAdjustPrivilege" __imp_RtlAdjustPrivilege
0x18000A340: "__cdecl _imp_NtMapViewOfSection" __imp_NtMapViewOfSection
0x180003C40: GetDosDevicesProtection
0x18000A478: "__cdecl _imp_RtlCheckSandboxedToken" __imp_RtlCheckSandboxedToken
0x18000A230: "__cdecl _imp_swprintf_s" __imp_swprintf_s
0x18000E054: SessionFirstProcessImageType
0x18000A9A0: "CSRSS: NtCreateSymbolicLinkObjec" ??_C@_0FM@OANPLKNP@CSRSS?3?5NtCreateSymbolicLinkObjec@
0x1800127E4: ServiceSessionId
0x1800021E0: CsrLocateProcessByClientId
0x18000A1D8: "__cdecl _imp_RtlGetAce" __imp_RtlGetAce
0x18000A260: "__cdecl _imp_RtlFreeHeap" __imp_RtlFreeHeap
0x1800126C8: CsrTotalPerProcessDataLength
0x18000A7C8: "SubSystemType" ??_C@_0O@OGJDCOBK@SubSystemType?$AA@
0x18000AEB0: "%ws\%ld%ws" ??_C@_1BG@JEHLEJDO@?$AA?$CF?$AAw?$AAs?$AA?2?$AA?$CF?$AAl?$AAd?$AA?$CF?$AAw?$AAs?$AA?$AA@
0x18000A368: "__cdecl _imp_NtReplyWaitReceivePort" __imp_NtReplyWaitReceivePort
0x180012730: CsrSrvSharedStaticServerData
0x18000A8A4: "\" ??_C@_13FPGAJAPJ@?$AA?2?$AA?$AA@
0x18000A3C8: "__cdecl _imp_NtAlpcCreatePort" __imp_NtAlpcCreatePort
0x18000A6A0: "ProtectionMode" ??_C@_1BO@JFJHGLBJ@?$AAP?$AAr?$AAo?$AAt?$AAe?$AAc?$AAt?$AAi?$AAo?$AAn?$AAM?$AAo?$AAd?$AAe?$AA?$AA@
0x18000A2E0: "__cdecl _imp_strncpy_s" __imp_strncpy_s
0x180006780: CsrAllocateProcess
0x18000A600: CsrEvt_ShutdownProcess_Start
0x1800069A0: CsrSetDirectorySecurity
0x180001210: CsrValidateMessageBuffer
0x1800029E0: CsrLocateServerThread
0x18000A5F0: CsrEvt_ShutdownProcess_Stop
0x1800127E0: CsrInitFailReason
0x18000A3E0: "__cdecl _imp_RtlWaitOnAddress" __imp_RtlWaitOnAddress
0x180004BE0: CsrSrvCreateSharedSection
0x18000A338: "__cdecl _imp_RtlCreateHeap" __imp_RtlCreateHeap
0x1800045A0: CsrLoadServerDll
0x180001580: CsrUnlockProcess
0x180008270: CsrUnhandledExceptionFilter
0x180006C70: "__cdecl DllMainCRTStartupForGS" _DllMainCRTStartupForGS
0x1800127D8: CsrBaseTag
0x18000922C: StringCchPrintfW
0x18000A1A8: "__cdecl _imp_RtlWakeAddressAll" __imp_RtlWakeAddressAll
0x180001B60: CsrProcessLazyRegister
0x180012650: SessionId
0x18000A4F8: "__cdecl _guard_check_icall_fptr" __guard_check_icall_fptr
0x180006F3E: RtlLookupFunctionEntry
0x18000AA98: CsrEvt_ShutdownProcesses_Start
0x1800125E4: CsrpDynamicThreadTotal
0x18000A7D8: "Off" ??_C@_03GCDBBDDL@Off?$AA@
0x18000A2D8: "__cdecl _imp_RtlAppendUnicodeToString" __imp_RtlAppendUnicodeToString
0x180001730: CsrLockThreadByClientId
0x180004850: CsrApiPortInitialize
0x18000A220: "__cdecl _imp__snprintf_s" __imp__snprintf_s
0x1800083D0: CsrpReportToWerSvcThread
0x18000A288: "__cdecl _imp_EtwEventRegister" __imp_EtwEventRegister
0x18000AF70: "CSRSS: CsrSrvCreateProcess - NtR" ??_C@_0DP@NDDMPIEG@CSRSS?3?5CsrSrvCreateProcess?5?9?5NtR@
0x180006F26: NtTerminateProcess
0x18000A440: "__cdecl _imp_NtImpersonateThread" __imp_NtImpersonateThread
0x18000A428: "__cdecl _imp_NtOpenThread" __imp_NtOpenThread
0x18000E020: ProcessSequenceCount
0x18000A278: "__cdecl _imp_RtlCharToInteger" __imp_RtlCharToInteger
0x18000A198: "__cdecl _imp_RtlGetCurrentServiceSessionId" __imp_RtlGetCurrentServiceSessionId
0x18000E028: CsrSecurityQos
0x18000A488: "__cdecl _imp_NtOpenThreadToken" __imp_NtOpenThreadToken
0x18000A1E8: "__cdecl _imp_NtSetInformationObject" __imp_NtSetInformationObject
0x18000A3C0: "__cdecl _imp_NtSetDefaultHardErrorPort" __imp_NtSetDefaultHardErrorPort
0x18000A7E8: "\CsrSbSyncEvent" ??_C@_1CA@CEPFPKAF@?$AA?2?$AAC?$AAs?$AAr?$AAS?$AAb?$AAS?$AAy?$AAn?$AAc?$AAE?$AAv?$AAe?$AAn?$AAt?$AA?$AA@
0x18000A410: "__cdecl _imp_NtAlpcSendWaitReceivePort" __imp_NtAlpcSendWaitReceivePort
0x18000A2F8: "__cdecl _imp_LdrLoadDll" __imp_LdrLoadDll
0x180006660: CsrAddStaticServerThread
0x18000A238: "__cdecl _imp_RtlFreeSid" __imp_RtlFreeSid
0x18000A8D0: "CSRSS: NtCreateDirectoryObject f" ??_C@_0FJ@FFGIKGPI@CSRSS?3?5NtCreateDirectoryObject?5f@
0x18000A2B0: "__cdecl _imp_NtResumeThread" __imp_NtResumeThread
0x18000A2B8: "__cdecl _imp_NtQueryValueKey" __imp_NtQueryValueKey
0x180006CB0: "__cdecl _security_check_cookie" __security_check_cookie
0x180001FC0: CsrCreateThread
0x1800127A0: CsrNtSessionLock
0x180001AE0: CsrProcessRefcountZero
0x1800012A0: CsrReleaseCapturedArguments
0x180012780: CsrApiPortName
0x18000AE00: "CSRSS: CsrSrvCreateProcess: RtlC" ??_C@_0EO@HLHHBHLG@CSRSS?3?5CsrSrvCreateProcess?3?5RtlC@
0x18000A320: "__cdecl _imp_RtlInitAnsiString" __imp_RtlInitAnsiString
0x180006710: CsrAllocateThread
0x18000AA90: CsrServerApiServerValidTable
0x18000A438: "__cdecl _imp_EtwEventEnabled" __imp_EtwEventEnabled
0x1800127E8: ClientThreadSetupRoutine
0x1800126E0: CsrSrvSharedSectionBase
0x1800047F0: CsrServerCreateApiPort
0x18000A508: "__cdecl _guard_fids_table" __guard_fids_table
0x18000A040: "__cdecl load_config_used" _load_config_used
0x18000AB30: "SerializeAppShutdown" ??_C@_1CK@BGMJKHAJ@?$AAS?$AAe?$AAr?$AAi?$AAa?$AAl?$AAi?$AAz?$AAe?$AAA?$AAp?$AAp?$AAS?$AAh?$AAu?$AAt?$AAd?$AAo?$AAw?$AAn?$AA?$AA@
0x18000A818: "\Sessions" ??_C@_1BE@GBAFMKEO@?$AA?2?$AAS?$AAe?$AAs?$AAs?$AAi?$AAo?$AAn?$AAs?$AA?$AA@
0x1800059A0: CsrApiRequestThread
0x18000E5E0: CsrThreadHashTable
0x180006C50: CsrRegisterClientThreadSetup
0x18000A960: "%ws\%ld\BaseNamedObjects" ??_C@_1DC@BGGFLPH@?$AA?$CF?$AAw?$AAs?$AA?2?$AA?$CF?$AAl?$AAd?$AA?2?$AAB?$AAa?$AAs?$AAe?$AAN?$AAa?$AAm?$AAe?$AAd?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?$AA@
0x180004ED0: CsrpFreeSecurityContext
0x1800015C0: CsrCallServerFromServer
0x180002AC0: CsrSbForeignSessionComplete
0x180002980: CsrDereferenceNtSession
0x18000A380: "__cdecl _imp_NtSetInformationProcess" __imp_NtSetInformationProcess
0x180009060: FindProcessForShutdown
0x180004A20: CsrSbApiPortInitialize
0x18000A458: "__cdecl _imp_qsort" __imp_qsort
0x180006810: CsrCreateLocalSystemSD
0x18000A208: "__cdecl _imp_NtSetSecurityObject" __imp_NtSetSecurityObject
0x18000A328: "__cdecl _imp_RtlCreateUserThread" __imp_RtlCreateUserThread
0x1800089E0: CsrDestroyProcess
0x18000AAB0: "\Registry\Machine\Software\Polic" ??_C@_1HK@BDCJFGLI@?$AA?2?$AAR?$AAe?$AAg?$AAi?$AAs?$AAt?$AAr?$AAy?$AA?2?$AAM?$AAa?$AAc?$AAh?$AAi?$AAn?$AAe?$AA?2?$AAS?$AAo?$AAf?$AAt?$AAw?$AAa?$AAr?$AAe?$AA?2?$AAP?$AAo?$AAl?$AAi?$AAc@
0x18000A3D0: "__cdecl _imp_NtQueryInformationProcess" __imp_NtQueryInformationProcess
0x18000A228: "__cdecl _imp_NtClose" __imp_NtClose
0x18000AA10: "CSRSS: NtSetInformationObject fa" ??_C@_0FI@GCCFCLP@CSRSS?3?5NtSetInformationObject?5fa@
0x18000A938: "\BaseNamedObjects" ??_C@_1CE@NPBNEBGN@?$AA?2?$AAB?$AAa?$AAs?$AAe?$AAN?$AAa?$AAm?$AAe?$AAd?$AAO?$AAb?$AAj?$AAe?$AAc?$AAt?$AAs?$AA?$AA@
0x18000A930: "%ld" ??_C@_17OADJODNB@?$AA?$CF?$AAl?$AAd?$AA?$AA@
0x18000A4C0: "__cdecl _imp_RtlLookupFunctionEntry" __imp_RtlLookupFunctionEntry
0x180003030: CsrEventWriteULONG3
0x180002F90: CsrEventWriteULONG2
0x1800089B0: CsrDeferredCreateProcess
0x18000A450: "__cdecl _imp_RtlDestroyProcessParameters" __imp_RtlDestroyProcessParameters
0x18000A2A8: "__cdecl _imp_RtlGetDaclSecurityDescriptor" __imp_RtlGetDaclSecurityDescriptor
0x18000A188: "__cdecl _imp_RtlAnsiStringToUnicodeString" __imp_RtlAnsiStringToUnicodeString
0x18000A480: "__cdecl _imp_RtlGetSuiteMask" __imp_RtlGetSuiteMask
0x18000A4D8: "__cdecl _imp_RtlConnectToSm" __imp_RtlConnectToSm
0x18000A390: "__cdecl _imp_RtlLeaveCriticalSection" __imp_RtlLeaveCriticalSection
0x18000A1D0: "__cdecl _imp_NtOpenEvent" __imp_NtOpenEvent
0x18000A4C8: "__cdecl _imp_RtlVirtualUnwind" __imp_RtlVirtualUnwind
0x18000AC60: "Default Load Path" ??_C@_1CE@CFPAGLOP@?$AAD?$AAe?$AAf?$AAa?$AAu?$AAl?$AAt?$AA?5?$AAL?$AAo?$AAa?$AAd?$AA?5?$AAP?$AAa?$AAt?$AAh?$AA?$AA@
0x180012608: CsrRootProcess
0x18000A310: "__cdecl _imp_NtRaiseHardError" __imp_NtRaiseHardError
0x180006F60: "__cdecl guard_check_icall_nop" _guard_check_icall_nop
0x18000A3F0: "__cdecl _imp_NtAlpcAcceptConnectPort" __imp_NtAlpcAcceptConnectPort
0x18000B060: "CSRSS: ReadUnicodeString: NtRead" ??_C@_0EF@LKANGOFD@CSRSS?3?5ReadUnicodeString?3?5NtRead@
0x18000A300: "__cdecl _imp_RtlReportException" __imp_RtlReportException
0x180004020: CsrParseServerCommandLine
0x18000AED0: "CSRSS: NtOpenDirectoryObject fai" ??_C@_0EK@MNHJOOAG@CSRSS?3?5NtOpenDirectoryObject?5fai@
0x180001950: CsrLockedDereferenceThread
0x18000A6F8: "ServerDLL" ??_C@_09NDHOILFE@ServerDLL?$AA@
0x18000A1A0: "__cdecl _imp_NtCreateDirectoryObject" __imp_NtCreateDirectoryObject
0x180001700: CsrServerDllInitialization
0x18000A330: "__cdecl _imp_RtlUnhandledExceptionFilter" __imp_RtlUnhandledExceptionFilter
0x18000A4F0: ntdll_NULL_THUNK_DATA
0x18000A4D0: "__cdecl _imp_memcpy" __imp_memcpy
0x180012680: CsrTraceHandle
0x18000A2E8: "__cdecl _imp_LdrUnloadDll" __imp_LdrUnloadDll
0x18000A468: "__cdecl _imp_NtOpenDirectoryObject" __imp_NtOpenDirectoryObject
0x1800016B0: FreeDosDevicesProtection
0x18000E010: "__cdecl _security_cookie" __security_cookie
0x1800126D0: CsrSbApiPort
0x180012668: CsrSmApiPort
0x18000A3A0: "__cdecl _imp_RtlAddProcessTrustLabelAce" __imp_RtlAddProcessTrustLabelAce
0x180003560: CsrSetProcessSecurity
0x18000A430: "__cdecl _imp_RtlCreateProcessParametersEx" __imp_RtlCreateProcessParametersEx
0x1800084BC: CsrpCheckRequestThreads
0x180002D00: ShutdownProcesses
0x18000A1F8: "__cdecl _imp_RtlAllocateAndInitializeSid" __imp_RtlAllocateAndInitializeSid
0x18000A420: "__cdecl _imp__vsnwprintf" __imp__vsnwprintf
0x180001E80: CsrThreadLazyRegister
0x18000A298: "__cdecl _imp_DbgPrint" __imp_DbgPrint
0x18000A728: "ProfileControl" ??_C@_0P@BKFLDAGP@ProfileControl?$AA@
0x18000A258: "__cdecl _imp_NtCreateSymbolicLinkObject" __imp_NtCreateSymbolicLinkObject
0x180006E30: "__cdecl _security_init_cookie" __security_init_cookie
0x18000A1B8: "__cdecl _imp_NtQuerySystemInformation" __imp_NtQuerySystemInformation
0x18000AA80: CsrEvt_ShutdownProcesses_Stop
0x1800033C0: ShutdownProcessesSortRoutine
0x180002AC0: CsrSbTerminateSession
0x180002210: CsrCreateProcess
0x1800036D0: CsrServerInitialization
0x18000A2D0: "__cdecl _imp_NtCreateSection" __imp_NtCreateSection
0x18000A1C8: "__cdecl _imp_NtOpenKey" __imp_NtOpenKey
0x180005750: CsrAllocateNtSession
0x18000ADA0: "CSRSS: CsrSrvCreateProcess: Read" ??_C@_0FB@HJJOJEP@CSRSS?3?5CsrSrvCreateProcess?3?5Read@
0x180006F4A: RtlVirtualUnwind
0x1800126A0: CsrProcessStructureLock
0x18000A210: "__cdecl _imp_RtlLengthSid" __imp_RtlLengthSid
0x18000AF20: "CSRSS: NtSetInformationProcess f" ??_C@_0EM@JHBGDAKN@CSRSS?3?5NtSetInformationProcess?5f@
0x180006CE0: "__cdecl _report_gsfailure" __report_gsfailure
0x18000A498: "__cdecl _imp_EtwEventWrite" __imp_EtwEventWrite
0x18000A620: "`string'" ??_C@_1GO@OFEPLJLN@?$AAT?$AAM?$AAP?$AA?$AA?$AAI?$AAN?$AAI?$AAT?$AA?$AA?$AAC?$AAA?$AAP?$AAT?$AAU?$AAR?$AAE?$AA?$AA?$AAP?$AAR?$AAO?$AAC?$AAE?$AAS?$AAS?$AA?$AA?$AAT?$AAH?$AAR?$AAE?$AAA?$AAD?$AA?$AA@
0x18000A6D0: "MaxRequestThreads" ??_C@_0BC@FLPHDMPO@MaxRequestThreads?$AA@
0x18000A370: "__cdecl _imp_NtAcceptConnectPort" __imp_NtAcceptConnectPort
0x180008440: CsrValidateMessageString
0x18000A4A8: "__cdecl _imp_NtAlpcDisconnectPort" __imp_NtAlpcDisconnectPort
0x18000AC90: "CSRSS: CsrSrvCreateProcess: NtOp" ??_C@_0EB@KNCIDFEA@CSRSS?3?5CsrSrvCreateProcess?3?5NtOp@
0x18000A408: "__cdecl _imp_NtAlpcOpenSenderThread" __imp_NtAlpcOpenSenderThread
0x1800014B0: CsrSrvClientConnect
0x18000A398: "__cdecl _imp_RtlSetSaclSecurityDescriptor" __imp_RtlSetSaclSecurityDescriptor
0x18000A3A8: "__cdecl _imp_RtlInitializeSid" __imp_RtlInitializeSid
0x18000A708: "Windows" ??_C@_07LDLFNPGN@Windows?$AA@
0x180005270: CsrInitializeProcessStructure
0x18000A1C0: "__cdecl _imp_RtlSetDaclSecurityDescriptor" __imp_RtlSetDaclSecurityDescriptor
0x18000A470: "__cdecl _imp_NtDuplicateObject" __imp_NtDuplicateObject
0x180008B20: CsrSbCreateProcess
0x18000A248: "__cdecl _imp_NtSetEvent" __imp_NtSetEvent
0x18000A6E8: "SharedSection" ??_C@_0O@HMOIGLKF@SharedSection?$AA@
0x180007097: memset
0x18000C804: "__cdecl _NULL_IMPORT_DESCRIPTOR" __NULL_IMPORT_DESCRIPTOR
0x1800032A0: CsrEventWrite
0x18000A490: "__cdecl _imp_NtRegisterThreadTerminatePort" __imp_NtRegisterThreadTerminatePort
0x180003360: CsrDereferenceThread

[JEB Decompiler by PNF Software]