Windows 8 DLL File Information - lsasrv.dll |
The following DLL report was generated by automatic DLL script that scanned and loaded all DLL files in the system32 directory of Windows 8, extracted the information from them, and then saved it into HTML reports. If you want to view a report of another DLL, go to the main page of this Web site.
General Information
File Description: | LSA Server DLL |
File Version: | 6.2.9200.16384 (win8_rtm.120725-1247) |
Company: | Microsoft Corporation |
Product Name: | Microsoft® Windows® Operating System |
DLL popularity | Very Low - 2 other DLL files in system32 directory are statically linked to this file. |
File Size: | 998 KB |
Total Number of Exported Functions: | 253 |
Total Number of Exported Functions With Names: | 253 |
Section Headers
Name | Virtual Address | Raw Data Size | % of File | Characteristics | Section Contains... |
---|---|---|---|---|---|
.text | 0x00001000 | 916,480 Bytes | 89.6% | Read, Execute | Code |
.data | 0x000e1000 | 23,040 Bytes | 2.3% | Write, Read | Initialized Data |
.idata | 0x000e7000 | 17,920 Bytes | 1.8% | Read | Initialized Data |
.rsrc | 0x000ec000 | 21,504 Bytes | 2.1% | Read | Initialized Data |
.reloc | 0x000f2000 | 42,496 Bytes | 4.2% | Read, Discardable | Initialized Data |
Static Linking
lsasrv.dll is statically linked to the following files:ntdll.dll
msvcrt.dll
api-ms-win-core-errorhandling-l1-1-1.dll
api-ms-win-core-string-l1-1-0.dll
api-ms-win-core-libraryloader-l1-1-1.dll
api-ms-win-core-handle-l1-1-0.dll
api-ms-win-core-processthreads-l1-1-1.dll
api-ms-win-core-interlocked-l1-2-0.dll
api-ms-win-security-base-l1-2-0.dll
api-ms-win-core-memory-l1-1-1.dll
RPCRT4.dll
api-ms-win-core-localization-l1-2-0.dll
api-ms-win-core-sysinfo-l1-2-0.dll
api-ms-win-core-file-l1-2-0.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-registry-l1-1-0.dll
SspiCli.dll
api-ms-win-core-processenvironment-l1-2-0.dll
api-ms-win-core-console-l1-1-0.dll
api-ms-win-core-debug-l1-1-1.dll
api-ms-win-service-winsvc-l1-2-0.dll
api-ms-win-service-core-l1-1-1.dll
api-ms-win-core-psapi-l1-1-0.dll
api-ms-win-core-file-l2-1-0.dll
api-ms-win-core-timezone-l1-1-0.dll
api-ms-win-core-datetime-l1-1-1.dll
api-ms-win-core-profile-l1-1-0.dll
api-ms-win-core-kernel32-legacy-l1-1-0.dll
api-ms-win-core-threadpool-legacy-l1-1-0.dll
api-ms-win-core-string-obsolete-l1-1-0.dll
api-ms-win-core-heap-obsolete-l1-1-0.dll
api-ms-win-core-kernel32-private-l1-1-0.dll
api-ms-win-core-threadpool-private-l1-1-0.dll
api-ms-win-service-private-l1-1-0.dll
api-ms-win-security-grouppolicy-l1-1-0.dll
MSASN1.dll
api-ms-win-core-heap-l1-2-0.dll
api-ms-win-core-privateprofile-l1-1-0.dll
api-ms-win-core-apiquery-l1-1-0.dll
api-ms-win-core-delayload-l1-1-1.dll
This means that when lsasrv.dll is loaded, the above files are automatically loaded too. If one of these files is corrupted or missing, lsasrv.dll won't be loaded.
List of files that are statically linked to lsasrv.dll
samsrv.dll
vaultsvc.dll
This means that when one of the above files is loaded, lsasrv.dll will be loaded too. (The opposite of the previous 'Static Linking' section)
General Resources Information
Resource Type | Number of Items | Total Size | % of File |
---|---|---|---|
Icons | 0 | 0 Bytes | 0.0% |
Animated Icons | 0 | 0 Bytes | 0.0% |
Cursors | 0 | 0 Bytes | 0.0% |
Animated Cursors | 0 | 0 Bytes | 0.0% |
Bitmaps | 0 | 0 Bytes | 0.0% |
AVI Files | 0 | 0 Bytes | 0.0% |
Dialog-Boxes | 0 | 0 Bytes | 0.0% |
HTML Related Files | 0 | 0 Bytes | 0.0% |
Menus | 0 | 0 Bytes | 0.0% |
Strings | 0 | 0 Bytes | 0.0% |
Type Libraries | 0 | 0 Bytes | 0.0% |
Manifest | 0 | 0 Bytes | 0.0% |
All Others | 5 | 57,551 Bytes | 5.6% |
Total | 5 | 57,551 Bytes | 5.6% |
Icons in this file
No icons found in this file
Cursors in this file
No cursors found in this file
Dialog-boxes list (up to 200 dialogs)
No dialog resources in this file.
String resources in this dll (up to 200 strings)
No string resources in this file.
COM Classes/Interfaces
There is no type library in this file with COM classes/interfaces information
Exported Functions List
The following functions are exported by this dll:InitializeLsaExtension | LsaDbLookupSidChainRequest |
LsaIAddNamesToLogonSession | LsaIAdjustTokenObjectIntegrity |
LsaIAdtAuditingEnabledByCategory | LsaIAdtAuditingEnabledBySubCategory |
LsaIAllocateHeap | LsaIAllocateHeapZero |
LsaIAuditAccountLogon | LsaIAuditAccountLogonEx |
LsaIAuditInitializeParametersAndWriteEvent | LsaIAuditKdcEvent |
LsaIAuditKerberosLogon | LsaIAuditLogonEx |
LsaIAuditLogonUsingExplicitCreds | LsaIAuditNotifyPackageLoad |
LsaIAuditPasswordAccessEvent | LsaIAuditReplay |
LsaIAuditSamEvent | LsaICallPackage |
LsaICallPackageEx | LsaICallPackagePassthrough |
LsaICancelNotification | LsaIChangeSecretCipherKey |
LsaIClearOldSyskey | LsaICryptProtectData |
LsaICryptProtectDataEx | LsaICryptUnprotectData |
LsaICryptUnprotectDataEx | LsaIDereferenceCredHandle |
LsaIDsNotifiedObjectChange | LsaIEfsAcceptSmartcardCredentials |
LsaIEqualLogonProcessName | LsaIEqualSupplementalTokenInfo |
LsaIFilterNamespace | LsaIFilterSids |
LsaIForestTrustFindMatch | LsaIFreeForestTrustInfo |
LsaIFreeHeap | LsaIFreeReturnBuffer |
LsaIFreeSupplementalTokenInfo | LsaIFree_LSAI_PRIVATE_DATA |
LsaIFree_LSAI_SECRET_ENUM_BUFFER | LsaIFree_LSAPR_ACCOUNT_ENUM_BUFFER |
LsaIFree_LSAPR_CR_CIPHER_VALUE | LsaIFree_LSAPR_POLICY_DOMAIN_INFORMATION |
LsaIFree_LSAPR_POLICY_INFORMATION | LsaIFree_LSAPR_PRIVILEGE_ENUM_BUFFER |
LsaIFree_LSAPR_PRIVILEGE_SET | LsaIFree_LSAPR_REFERENCED_DOMAIN_LIST |
LsaIFree_LSAPR_SR_SECURITY_DESCRIPTOR | LsaIFree_LSAPR_TRANSLATED_NAMES |
LsaIFree_LSAPR_TRANSLATED_SIDS | LsaIFree_LSAPR_TRUSTED_DOMAIN_INFO |
LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER | LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER_EX |
LsaIFree_LSAPR_TRUST_INFORMATION | LsaIFree_LSAPR_UNICODE_STRING |
LsaIFree_LSAPR_UNICODE_STRING_BUFFER | LsaIFree_LSAP_SITENAME_INFO |
LsaIFree_LSAP_SITE_INFO | LsaIFree_LSAP_SUBNET_INFO |
LsaIFree_LSAP_UPN_SUFFIXES | LsaIFree_LSA_FOREST_TRUST_COLLISION_INFORMATION |
LsaIFree_LSA_FOREST_TRUST_INFORMATION | LsaIGetCallInfo |
LsaIGetForestTrustInformation | LsaIGetLogonGuid |
LsaIGetNameFromLuid | LsaIGetNbAndDnsDomainNames |
LsaIGetNego2Package | LsaIGetSiteName |
LsaIGetSupplementalTokenInfo | LsaIHealthCheck |
LsaIImpersonateClient | LsaIInitializeNetlogonFuncPtrs |
LsaIIsDomainWithinForest | LsaIIsDsPaused |
LsaIIsLastInteractiveLogonInfoEnabled | LsaIIsLocalHost |
LsaIIsSuppressChannelBindingInfo | LsaIIsTrustedDomainsEnabled |
LsaIKerberosRegisterTrustNotification | LsaILookupWellKnownName |
LsaIModifyPerformanceCounter | LsaINoConnectedUserPolicy |
LsaINoMoreWin2KDomain | LsaINotifyChangeNotification |
LsaINotifyGCStatusChange | LsaINotifyNetlogonParametersChangeW |
LsaINotifyNewPassword | LsaINotifyPasswordChanged |
LsaIOpenPolicyTrusted | LsaIQueryForestTrustInfo |
LsaIQueryInformationPolicyTrusted | LsaIQueryPackageAttrInLogonSession |
LsaIQuerySiteInfo | LsaIQuerySubnetInfo |
LsaIQueryUpnSuffixes | LsaIReferenceCredHandle |
LsaIRegisterLogonSessionCallback | LsaIRegisterNotification |
LsaIRegisterPolicyChangeNotificationCallback | LsaIReplicateClientObject |
LsaIRetrieveCurrentUserSid | LsaISafeMode |
LsaISamIndicatedDsStarted | LsaISetClientDnsHostName |
LsaISetLogonGuidInLogonSession | LsaISetLogonInfo |
LsaISetNewSyskey | LsaISetPackageAttrInLogonSession |
LsaISetSupplementalTokenInfo | LsaISetTokenDacl |
LsaISetUserFlags | LsaISetupWasRun |
LsaITransformAuthorizationData | LsaIUnregisterAllPolicyChangeNotificationCallback |
LsaIUnregisterLogonSessionCallback | LsaIUnregisterPolicyChangeNotificationCallback |
LsaIUpdateForestTrustInformation | LsaIUpdateKerbMaxTokenSize |
LsaIUpdateLogonSession | LsaIValidateTargetInfo |
LsaIVerifyCachability | LsaIWriteAuditEvent |
LsapAdtAuditingEnabledByLogonId | LsapAdtAuditingEnabledBySubCategory |
LsapAdtAuditingEnabledHint | LsapAdtInitParametersArray |
LsapAdtWriteLog | LsapAllocateLsaHeap |
LsapAllocatePrivateHeap | LsapAuOpenSam |
LsapAuditFailed | LsapBuildPrivilegeAuditString |
LsapCheckBootMode | LsapCloseHandle |
LsapCompareDomainNames | LsapCrServerGetSessionKey |
LsapCrServerGetSessionKeySafe | LsapDbAcquireLockEx |
LsapDbApplyTransaction | LsapDbBuildObjectCaches |
LsapDbCloseHandle | LsapDbCloseObject |
LsapDbCopyUnicodeAttribute | LsapDbCopyUnicodeAttributeNoAlloc |
LsapDbCreateObject | LsapDbDeleteAttributesObject |
LsapDbDeleteObject | LsapDbDereferenceHandle |
LsapDbDereferenceObject | LsapDbEnumerateSids |
LsapDbEnumerateTrustedDomainsEx | LsapDbExpAcquireReadLockTrustedDomainList |
LsapDbExpAcquireWriteLockTrustedDomainList | LsapDbExpConvertReadLockTrustedDomainListToExclusive |
LsapDbExpConvertWriteLockTrustedDomainListToShared | LsapDbExpIsCacheBuilding |
LsapDbExpIsCacheValid | LsapDbExpIsLockedTrustedDomainList |
LsapDbExpMakeCacheBuilding | LsapDbExpMakeCacheInvalid |
LsapDbExpMakeCacheValid | LsapDbExpReleaseLockTrustedDomainList |
LsapDbFreeAttributes | LsapDbFreeTrustedDomainsEx |
LsapDbGetDbObjectTypeName | LsapDbGetDbPolicyHandle |
LsapDbGetSecretType | LsapDbInitializeAttribute |
LsapDbIsStatusConnectionFailure | LsapDbLookupAddListReferencedDomains |
LsapDbLookupCreateListReferencedDomains | LsapDbLookupGetDomainInfo |
LsapDbLookupListReferencedDomains | LsapDbLookupMergeDisjointReferencedDomains |
LsapDbLookupNameChainRequest | LsapDbLookupNamesInPrimaryDomain |
LsapDbLookupSidsInPrimaryDomain | LsapDbMakeGuidAttribute |
LsapDbMakeSidAttribute | LsapDbMakeUnicodeAttribute |
LsapDbOpenObject | LsapDbQueryInformationPolicy |
LsapDbReadAttribute | LsapDbReadAttributesObject |
LsapDbReferenceObject | LsapDbReleaseLockEx |
LsapDbSecretIsMachineAcc | LsapDbSidToLogicalNameObject |
LsapDbSlowEnumerateTrustedDomains | LsapDbUpdateCountCompUnmappedNames |
LsapDbVerifyHandle | LsapDbVerifyInfoQueryTrustedDomain |
LsapDbVerifyInfoSetTrustedDomain | LsapDbWriteAttributesObject |
LsapDomainRenameHandlerForLogonSessions | LsapDsInitializeDsStateInfo |
LsapDsUnitializeDsStateInfo | LsapDssetupInitializeGetPrimaryDomainInformationOpState |
LsapDuplicateSid | LsapDuplicateString |
LsapFreeLsaHeap | LsapFreePrivateHeap |
LsapFreeString | LsapGetAccountDomainHandle |
LsapGetCapeNamesForCap | LsapGetGlobalRestrictAnonymous |
LsapGetHourlyLogLevel | LsapGetLogonSessionAccountInfoEx |
LsapGetLookupRestrictIsolatedNameLevel | LsapGetPolicyHandle |
LsapGetWellKnownSid | LsapInitLsa |
LsapInitializeLsaDb | LsapIsBuiltinDomain |
LsapIsSamOpened | LsapOpenSam |
LsapQueryClientInfo | LsapRemoveTrailingDot |
LsapRpcCopySid | LsapRpcCopyUnicodeString |
LsapRtlValidateControllerTrustedDomain | LsapRtlValidateControllerTrustedDomainByHandle |
LsapSetErrorInfo | LsapSidListSize |
LsapTraceEvent | LsapTraceEventWithData |
LsapTruncateUnicodeString | LsarClose |
LsarCreateSecret | LsarDeleteObject |
LsarEnumerateTrustedDomainsEx | LsarLookupSids |
LsarOpenPolicy | LsarOpenSecret |
LsarQueryDomainInformationPolicy | LsarQueryInformationPolicy |
LsarQuerySecret | LsarQueryTrustedDomainInfoByName |
LsarRetrievePrivateData | LsarSetInformationPolicy |
LsarSetSecret | LsarSetTrustedDomainInfoByName |
LsarStorePrivateData | QueryLsaInterface |
ServiceInit | _fgs__LSAPR_TRUSTED_ENUM_BUFFER |
_fgs__LSAPR_TRUSTED_ENUM_BUFFER_EX | _fgs__LSAPR_TRUST_INFORMATION |
_fgu__LSAPR_TRUSTED_DOMAIN_INFO |
Imported Functions List
The following functions are imported by this dll:- ntdll.dll:
DbgPrint EtwEventEnabled EtwEventRegister EtwEventUnregister EtwEventWrite EtwGetTraceLoggerHandle EtwLogTraceEvent EtwRegisterSecurityProvider EtwRegisterTraceGuidsW EtwTraceMessage EtwWriteUMSecurityEvent EvtIntReportAuthzEventAndSourceAsync LdrLoadDll NtAccessCheck NtAccessCheckAndAuditAlarm NtAccessCheckByTypeAndAuditAlarm NtAdjustPrivilegesToken NtAllocateLocallyUniqueId NtAllocateVirtualMemory NtClose NtCloseObjectAuditAlarm NtCommitTransaction NtConnectPort NtCreateEvent NtCreateKey NtCreateKeyTransacted NtCreateSection NtCreateToken NtCreateTokenEx NtCreateTransaction NtDeleteKey NtDeleteObjectAuditAlarm NtDeleteValueKey NtDuplicateObject NtDuplicateToken NtEnumerateKey NtEnumerateValueKey NtFilterToken NtFlushKey NtFreeVirtualMemory NtImpersonateAnonymousToken NtMapViewOfSection NtOpenEvent NtOpenKey NtOpenKeyTransacted NtOpenProcess NtOpenProcessToken NtOpenSymbolicLinkObject NtOpenThreadToken NtPrivilegeCheck NtPrivilegeObjectAuditAlarm NtPrivilegedServiceAuditAlarm NtQueryInformationProcess NtQueryInformationToken NtQueryKey NtQueryLicenseValue NtQueryObject NtQuerySymbolicLinkObject NtQuerySystemInformation NtQueryValueKey NtRaiseHardError NtReadVirtualMemory NtReplyPort NtRequestWaitReplyPort NtRollbackTransaction NtSetEvent NtSetInformationThread NtSetInformationToken NtSetSecurityObject NtShutdownSystem NtWaitForSingleObject NtWriteVirtualMemory RtlAbortRXact RtlAcquireResourceExclusive RtlAcquireResourceShared RtlAddAccessAllowedAce RtlAddAce RtlAddActionToRXact RtlAddMandatoryAce RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHeap RtlAnsiStringToUnicodeString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlApplyRXact RtlAreAllAccessesGranted RtlAvlInsertNodeEx RtlAvlRemoveNode RtlCheckTokenCapability RtlCompareUnicodeString RtlConvertExclusiveToShared RtlConvertSharedToExclusive RtlConvertSidToUnicodeString RtlCopyLuid RtlCopySid RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateHeap RtlCreateSecurityDescriptor RtlCreateServiceSid RtlCreateUnicodeStringFromAsciiz RtlDeleteAce RtlDeleteCriticalSection RtlDeleteElementGenericTableAvl RtlDeleteResource RtlEnterCriticalSection RtlEnumerateGenericTableAvl RtlEqualDomainName RtlEqualPrefixSid RtlEqualSid RtlEqualString RtlEqualUnicodeString RtlEthernetAddressToStringW RtlFindAceByType RtlFindCharInUnicodeString RtlFindMessage RtlFreeAnsiString RtlFreeAnsiString RtlFreeHeap RtlFreeSid RtlGetAce RtlGetControlSecurityDescriptor RtlGetDaclSecurityDescriptor RtlGetLastNtStatus RtlGetLastWin32Error RtlGetNtProductType RtlGetSaclSecurityDescriptor RtlGetSetBootStatusData RtlGetThreadPreferredUILanguages RtlIdentifierAuthoritySid RtlImageNtHeader RtlImpersonateSelf RtlImpersonateSelfEx RtlInitAnsiString RtlInitString RtlInitUnicodeString RtlInitUnicodeStringEx RtlInitializeCriticalSection RtlInitializeCriticalSectionAndSpinCount RtlInitializeGenericTableAvl RtlInitializeRXact RtlInitializeResource RtlInitializeSid RtlInsertElementGenericTableAvl RtlIntegerToChar RtlIntegerToUnicodeString RtlIpv4AddressToStringW RtlIpv6AddressToStringW RtlLeaveCriticalSection RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlLengthSidAsUnicodeString RtlLockBootStatusData RtlLookupElementGenericTableAvl RtlMakeSelfRelativeSD RtlMapGenericMask RtlNewSecurityObject RtlNtStatusToDosError RtlOwnerAcesPresent RtlPrefixUnicodeString RtlPublishWnfStateData RtlQueryInformationAcl RtlQueryTimeZoneInformation RtlReleaseResource RtlRunDecodeUnicodeString RtlSetDaclSecurityDescriptor RtlSetLastWin32ErrorAndNtStatusFromNtStatus RtlSetOwnerSecurityDescriptor RtlSetSaclSecurityDescriptor RtlSetSecurityObject RtlSetThreadPreferredUILanguages RtlSidDominates RtlSidHashInitialize RtlSidHashLookup RtlStartRXact RtlStringFromGUID RtlSubAuthorityCountSid RtlSubAuthoritySid RtlTimeFieldsToTime RtlTimeToSecondsSince1980 RtlTryEnterCriticalSection RtlUnicodeStringToAnsiString RtlUnicodeStringToInteger RtlUnlockBootStatusData RtlUpcaseUnicodeString RtlUpcaseUnicodeStringToOemString RtlValidRelativeSecurityDescriptor RtlValidSecurityDescriptor RtlValidSid RtlVerifyVersionInfo RtlpConvertAbsoluteToRelativeSecurityAttribute RtlpConvertRelativeToAbsoluteSecurityAttribute RtlpNtEnumerateSubKey RtlpNtOpenKey RtlpNtQueryValueKey TpAllocTimer TpReleaseTimer TpSetTimer VerSetConditionMask WinSqmIncrementDWORD WinSqmSetString _alldiv _allmul _alloca_probe _allshl _aulldiv _aullshr _snprintf_s _snwprintf_s _strcmpi _strnicmp _vsnprintf_s _vsnwprintf _wcsicmp _wcsnicmp _wtoi mbstowcs memcmp memcpy memmove memset strcat_s strchr strcpy_s strrchr swprintf_s swscanf_s toupper wcscat_s wcschr wcscpy_s wcsncat_s wcsncpy_s wcsnlen wcsrchr - msvcrt.dll:
_XcptFilter _amsg_exit _except_handler4_common _initterm _ultow free malloc qsort strtok void __cdecl operator delete(void *) wcsncmp - api-ms-win-core-errorhandling-l1-1-1.dll:
KernelBase!GetLastError KernelBase!RaiseException KernelBase!SetUnhandledExceptionFilter KernelBase!UnhandledExceptionFilter ntdll!RtlRestoreLastWin32Error - api-ms-win-core-string-l1-1-0.dll:
KernelBase!CompareStringW KernelBase!GetStringTypeW - api-ms-win-core-libraryloader-l1-1-1.dll:
KernelBase!FreeLibrary KernelBase!GetModuleFileNameA KernelBase!GetModuleFileNameW KernelBase!GetModuleHandleW KernelBase!GetProcAddress KernelBase!LoadLibraryExA KernelBase!LoadLibraryExW - api-ms-win-core-handle-l1-1-0.dll:
KernelBase!CloseHandle - api-ms-win-core-processthreads-l1-1-1.dll:
KernelBase!OpenProcessToken KernelBase!OpenThreadToken KernelBase!SetThreadToken kernel32!CreateThread kernel32!GetCurrentProcess kernel32!GetCurrentProcessId kernel32!GetCurrentThread kernel32!GetCurrentThreadId kernel32!OpenProcess kernel32!SetProcessShutdownParameters kernel32!SetThreadStackGuarantee kernel32!TerminateProcess kernel32!TlsAlloc kernel32!TlsGetValue kernel32!TlsSetValue - api-ms-win-core-interlocked-l1-2-0.dll:
KernelBase!InterlockedCompareExchange KernelBase!InterlockedDecrement KernelBase!InterlockedExchange KernelBase!InterlockedExchangeAdd KernelBase!InterlockedIncrement ntdll!RtlInterlockedCompareExchange64 - api-ms-win-security-base-l1-2-0.dll:
KernelBase!AccessCheck KernelBase!AdjustTokenPrivileges KernelBase!AllocateAndInitializeSid KernelBase!AllocateLocallyUniqueId KernelBase!CheckTokenMembership KernelBase!CheckTokenMembershipEx KernelBase!CopySid KernelBase!CreateWellKnownSid KernelBase!DuplicateTokenEx KernelBase!EqualDomainSid KernelBase!FreeSid KernelBase!GetAclInformation KernelBase!GetLengthSid KernelBase!GetSidSubAuthority KernelBase!GetSidSubAuthorityCount KernelBase!GetTokenInformation KernelBase!GetWindowsAccountDomainSid KernelBase!ImpersonateLoggedOnUser KernelBase!ImpersonateSelf KernelBase!InitializeSecurityDescriptor KernelBase!IsTokenRestricted KernelBase!IsWellKnownSid KernelBase!PrivilegeCheck KernelBase!RevertToSelf KernelBase!SetSecurityDescriptorSacl KernelBase!SetTokenInformation - api-ms-win-core-memory-l1-1-1.dll:
KernelBase!CreateFileMappingW KernelBase!MapViewOfFileEx KernelBase!OpenFileMappingW KernelBase!UnmapViewOfFile KernelBase!VirtualAlloc KernelBase!VirtualFree KernelBase!VirtualLock KernelBase!VirtualProtect KernelBase!VirtualQuery - RPCRT4.dll:
I_RpcBindingInqClientTokenAttributes I_RpcBindingInqLocalClientPID I_RpcBindingInqTransportType I_RpcBindingIsClientLocal I_RpcMapWin32Status I_RpcOpenClientProcess I_RpcOpenClientThread MesDecodeIncrementalHandleCreate MesEncodeIncrementalHandleCreate MesHandleFree MesIncrementalHandleReset NdrMesTypeAlignSize2 NdrMesTypeDecode2 NdrMesTypeEncode2 NdrServerCall2 RpcBindingFree RpcBindingInqAuthClientW RpcBindingServerFromClient RpcBindingSetAuthInfoW RpcBindingToStringBindingW RpcBindingVectorFree RpcEpRegisterW RpcImpersonateClient RpcMgmtEnableIdleCleanup RpcRevertToSelf RpcRevertToSelfEx RpcServerInqBindings RpcServerInqCallAttributesW RpcServerInqDefaultPrincNameW RpcServerRegisterAuthInfoW RpcServerRegisterIf RpcServerRegisterIf2 RpcServerRegisterIf3 RpcServerUseProtseqEpW RpcSsGetContextBinding RpcStringBindingParseW RpcStringFreeW RpcUserFree - api-ms-win-core-localization-l1-2-0.dll:
KernelBase!FormatMessageW - api-ms-win-core-sysinfo-l1-2-0.dll:
KernelBase!GetComputerNameExW KernelBase!GetLocalTime KernelBase!GetSystemInfo KernelBase!GetSystemTime KernelBase!GetSystemTimeAsFileTime KernelBase!GetTickCount KernelBase!GetWindowsDirectoryW - api-ms-win-core-file-l1-2-0.dll:
KernelBase!CompareFileTime KernelBase!CreateDirectoryW KernelBase!CreateFileA KernelBase!CreateFileW KernelBase!DeleteFileW KernelBase!FileTimeToLocalFileTime KernelBase!FindClose KernelBase!FindCloseChangeNotification KernelBase!FindFirstChangeNotificationW KernelBase!FindFirstFileW KernelBase!FindNextChangeNotification KernelBase!FindNextFileW KernelBase!GetFileSize KernelBase!GetFileSizeEx KernelBase!GetFileTime KernelBase!GetFileType KernelBase!ReadFile KernelBase!SetFileAttributesW KernelBase!SetFilePointer KernelBase!WriteFile - api-ms-win-core-synch-l1-2-0.dll:
KernelBase!CreateEventW KernelBase!OpenEventW KernelBase!ResetEvent KernelBase!SetEvent KernelBase!Sleep KernelBase!WaitForSingleObject ntdll!RtlEnterCriticalSection ntdll!RtlInitializeCriticalSection ntdll!RtlLeaveCriticalSection - api-ms-win-core-registry-l1-1-0.dll:
KernelBase!RegCloseKey KernelBase!RegCreateKeyExA KernelBase!RegCreateKeyExW KernelBase!RegDeleteKeyExA KernelBase!RegDeleteKeyExW KernelBase!RegDeleteValueW KernelBase!RegEnumKeyExW KernelBase!RegFlushKey KernelBase!RegGetValueW KernelBase!RegNotifyChangeKeyValue KernelBase!RegOpenKeyExW KernelBase!RegQueryInfoKeyW KernelBase!RegQueryValueExW KernelBase!RegSetValueExA KernelBase!RegSetValueExW - SspiCli.dll:
CredUnmarshalTargetInfo LogonUserExExW LsaCallAuthenticationPackage LsaConnectUntrusted LsaDeregisterLogonProcess LsaFreeReturnBuffer LsaLogonUser LsaLookupAuthenticationPackage LsaRegisterLogonProcess LsaRegisterPolicyChangeNotification SecCacheSspiPackages SeciAllocateAndSetCallFlags SeciFreeCallContext SspiCopyAuthIdentity SspiDecryptAuthIdentityEx SspiEncodeStringsAsAuthIdentity SspiEncryptAuthIdentityEx SspiFreeAuthIdentity SspiLocalFree SspiMarshalAuthIdentity SspiUnmarshalAuthIdentity SspiUnmarshalAuthIdentityInternal SspiValidateAuthIdentity - api-ms-win-core-processenvironment-l1-2-0.dll:
KernelBase!ExpandEnvironmentStringsW KernelBase!GetEnvironmentVariableW KernelBase!SearchPathW - api-ms-win-core-console-l1-1-0.dll:
KernelBase!SetConsoleCtrlHandler - api-ms-win-core-debug-l1-1-1.dll:
KernelBase!DebugBreak KernelBase!OutputDebugStringA KernelBase!OutputDebugStringW - api-ms-win-service-winsvc-l1-2-0.dll:
sechost!RegisterServiceCtrlHandlerW - api-ms-win-service-core-l1-1-1.dll:
sechost!SetServiceStatus sechost!StartServiceCtrlDispatcherW - api-ms-win-core-psapi-l1-1-0.dll:
KernelBase!QueryFullProcessImageNameW - api-ms-win-core-file-l2-1-0.dll:
KernelBase!MoveFileExW - api-ms-win-core-timezone-l1-1-0.dll:
KernelBase!FileTimeToSystemTime KernelBase!SystemTimeToFileTime - api-ms-win-core-datetime-l1-1-1.dll:
KernelBase!GetDateFormatW KernelBase!GetTimeFormatW - api-ms-win-core-profile-l1-1-0.dll:
ntdll!RtlQueryPerformanceCounter - api-ms-win-core-kernel32-legacy-l1-1-0.dll:
kernel32!DnsHostnameToComputerNameW kernel32!RaiseFailFastException kernel32!WTSGetActiveConsoleSessionId - api-ms-win-core-threadpool-legacy-l1-1-0.dll:
KernelBase!CreateTimerQueueTimer KernelBase!DeleteTimerQueueTimer KernelBase!QueueUserWorkItem KernelBase!UnregisterWaitEx - api-ms-win-core-string-obsolete-l1-1-0.dll:
kernel32!lstrcmpiW kernel32!lstrlen - api-ms-win-core-heap-obsolete-l1-1-0.dll:
kernel32!LocalAlloc kernel32!LocalFree - api-ms-win-core-kernel32-private-l1-1-0.dll:
kernel32!CheckElevationEnabled - api-ms-win-core-threadpool-private-l1-1-0.dll:
KernelBase!RegisterWaitForSingleObjectEx - api-ms-win-service-private-l1-1-0.dll:
sechost!I_ScIsSecurityProcess - api-ms-win-security-grouppolicy-l1-1-0.dll:
KernelBase!GetNextFgPolicyRefreshInfoInternal KernelBase!IsSyncForegroundPolicyRefresh - MSASN1.dll:
ASN1BERDecBitString ASN1BERDecEndOfContents ASN1BERDecExplicitTag ASN1BERDecNotEndOfContents ASN1BERDecObjectIdentifier ASN1BERDecOctetString ASN1BERDecPeekTag ASN1BERDecSkip ASN1BERDecU32Val ASN1BERDecZeroCharString ASN1BEREncEndOfContents ASN1BEREncExplicitTag ASN1BEREncObjectIdentifier ASN1BEREncRemoveZeroBits ASN1BEREncU32 ASN1BEREoid_free ASN1BEREoid_free ASN1DEREncBitString ASN1DEREncCharString ASN1DEREncCharString ASN1DecAlloc ASN1DecSetError ASN1EncSetError ASN1Free ASN1Free ASN1_CloseDecoder ASN1_CloseEncoder ASN1_CreateDecoder ASN1_CreateEncoder ASN1_CreateModule ASN1_Decode ASN1_Encode ASN1_FreeDecoded ASN1_FreeEncoded ASN1objectidentifier_free - api-ms-win-core-heap-l1-2-0.dll:
KernelBase!GetProcessHeap KernelBase!HeapSetInformation ntdll!RtlAllocateHeap ntdll!RtlFreeHeap - api-ms-win-core-privateprofile-l1-1-0.dll:
kernel32!GetProfileStringA - api-ms-win-core-apiquery-l1-1-0.dll:
ntdll!ApiSetQueryApiSetPresence - api-ms-win-core-delayload-l1-1-1.dll:
kernel32!DelayLoadFailureHook ntdll!LdrResolveDelayLoadedAPI