Windows 7 DLL File Information - lsasrv.dll |
The following DLL report was generated by automatic DLL script that scanned and loaded all DLL files in the system32 directory of Windows 7, extracted the information from them, and then saved it into HTML reports. If you want to view a report of another DLL, go to the main page of this Web site.
General Information
File Description: | LSA Server DLL |
File Version: | 6.1.7100.0 (winmain_win7rc.090421-1700) |
Company: | Microsoft Corporation |
Product Name: | Microsoft Windows Operating System |
DLL popularity | Very Low - 3 other DLL files in system32 directory are statically linked to this file. |
File Size: | 1,014 KB |
Total Number of Exported Functions: | 139 |
Total Number of Exported Functions With Names: | 139 |
Section Headers
Name | Virtual Address | Raw Data Size | % of File | Characteristics | Section Contains... |
---|---|---|---|---|---|
.text | 0x00001000 | 953,344 Bytes | 91.8% | Read, Execute | Code |
.data | 0x000ea000 | 25,600 Bytes | 2.5% | Write, Read | Initialized Data |
.rsrc | 0x000f1000 | 20,480 Bytes | 2.0% | Read | Initialized Data |
.reloc | 0x000f6000 | 37,376 Bytes | 3.6% | Read, Discardable | Initialized Data |
Static Linking
lsasrv.dll is statically linked to the following files:ntdll.dll
msvcrt.dll
RPCRT4.dll
API-MS-Win-Security-SDDL-L1-1-0.dll
SspiCli.dll
API-MS-WIN-Service-Core-L1-1-0.dll
API-MS-WIN-Service-winsvc-L1-1-0.dll
ADVAPI32.dll
USER32.dll
SAMSRV.dll
MSASN1.dll
wevtapi.dll
lsass.exe
KERNEL32.dll
API-MS-WIN-Service-Management-L1-1-0.dll
API-MS-WIN-Service-Management-L2-1-0.dll
This means that when lsasrv.dll is loaded, the above files are automatically loaded too. If one of these files is corrupted or missing, lsasrv.dll won't be loaded.
List of files that are statically linked to lsasrv.dll
netlogon.dll
samsrv.dll
vaultsvc.dll
This means that when one of the above files is loaded, lsasrv.dll will be loaded too. (The opposite of the previous 'Static Linking' section)
General Resources Information
Resource Type | Number of Items | Total Size | % of File |
---|---|---|---|
Icons | 0 | 0 Bytes | 0.0% |
Animated Icons | 0 | 0 Bytes | 0.0% |
Cursors | 0 | 0 Bytes | 0.0% |
Animated Cursors | 0 | 0 Bytes | 0.0% |
Bitmaps | 0 | 0 Bytes | 0.0% |
AVI Files | 0 | 0 Bytes | 0.0% |
Dialog-Boxes | 0 | 0 Bytes | 0.0% |
HTML Related Files | 0 | 0 Bytes | 0.0% |
Menus | 0 | 0 Bytes | 0.0% |
Strings | 0 | 0 Bytes | 0.0% |
Type Libraries | 0 | 0 Bytes | 0.0% |
Manifest | 0 | 0 Bytes | 0.0% |
All Others | 5 | 61,657 Bytes | 5.9% |
Total | 5 | 61,657 Bytes | 5.9% |
Icons in this file
No icons found in this file
Cursors in this file
No cursors found in this file
Dialog-boxes list (up to 200 dialogs)
No dialog resources in this file.
String resources in this dll (up to 200 strings)
No string resources in this file.
COM Classes/Interfaces
There is no type library in this file with COM classes/interfaces information
Exported Functions List
The following functions are exported by this dll:InitializeLsaExtension | LsaIAddNamesToLogonSession |
LsaIAdjustTokenObjectIntegrity | LsaIAdtAuditingEnabledByCategory |
LsaIAdtAuditingEnabledBySubCategory | LsaIAllocateHeap |
LsaIAllocateHeapZero | LsaIAuditAccountLogon |
LsaIAuditAccountLogonEx | LsaIAuditInitializeParametersAndWriteEvent |
LsaIAuditKdcEvent | LsaIAuditKerberosLogon |
LsaIAuditLogonEx | LsaIAuditLogonUsingExplicitCreds |
LsaIAuditNotifyPackageLoad | LsaIAuditPasswordAccessEvent |
LsaIAuditReplay | LsaIAuditSamEvent |
LsaICallPackage | LsaICallPackageEx |
LsaICallPackagePassthrough | LsaICancelNotification |
LsaIChangeSecretCipherKey | LsaIClearOldSyskey |
LsaICryptProtectData | LsaICryptProtectDataEx |
LsaICryptUnprotectData | LsaICryptUnprotectDataEx |
LsaIDereferenceCredHandle | LsaIDsNotifiedObjectChange |
LsaIEfsAcceptSmartcardCredentials | LsaIEqualLogonProcessName |
LsaIEqualSupplementalTokenInfo | LsaIFilterNamespace |
LsaIFilterSids | LsaIForestTrustFindMatch |
LsaIFreeForestTrustInfo | LsaIFreeHeap |
LsaIFreeReturnBuffer | LsaIFreeSupplementalTokenInfo |
LsaIFree_LSAI_PRIVATE_DATA | LsaIFree_LSAI_SECRET_ENUM_BUFFER |
LsaIFree_LSAPR_ACCOUNT_ENUM_BUFFER | LsaIFree_LSAPR_CR_CIPHER_VALUE |
LsaIFree_LSAPR_POLICY_DOMAIN_INFORMATION | LsaIFree_LSAPR_POLICY_INFORMATION |
LsaIFree_LSAPR_PRIVILEGE_ENUM_BUFFER | LsaIFree_LSAPR_PRIVILEGE_SET |
LsaIFree_LSAPR_REFERENCED_DOMAIN_LIST | LsaIFree_LSAPR_SR_SECURITY_DESCRIPTOR |
LsaIFree_LSAPR_TRANSLATED_NAMES | LsaIFree_LSAPR_TRANSLATED_SIDS |
LsaIFree_LSAPR_TRUSTED_DOMAIN_INFO | LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER |
LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER_EX | LsaIFree_LSAPR_TRUST_INFORMATION |
LsaIFree_LSAPR_UNICODE_STRING | LsaIFree_LSAPR_UNICODE_STRING_BUFFER |
LsaIFree_LSAP_SITENAME_INFO | LsaIFree_LSAP_SITE_INFO |
LsaIFree_LSAP_SUBNET_INFO | LsaIFree_LSAP_UPN_SUFFIXES |
LsaIFree_LSA_FOREST_TRUST_COLLISION_INFORMATION | LsaIFree_LSA_FOREST_TRUST_INFORMATION |
LsaIGetCallInfo | LsaIGetForestTrustInformation |
LsaIGetLogonGuid | LsaIGetNameFromLuid |
LsaIGetNbAndDnsDomainNames | LsaIGetNego2Package |
LsaIGetSiteName | LsaIGetSupplementalTokenInfo |
LsaIHealthCheck | LsaIImpersonateClient |
LsaIIsDomainWithinForest | LsaIIsDsPaused |
LsaIIsLastInteractiveLogonInfoEnabled | LsaIIsLocalHost |
LsaIIsSuppressChannelBindingInfo | LsaIKerberosRegisterTrustNotification |
LsaILookupWellKnownName | LsaIModifyPerformanceCounter |
LsaINoMoreWin2KDomain | LsaINotifyChangeNotification |
LsaINotifyGCStatusChange | LsaINotifyNetlogonParametersChangeW |
LsaINotifyPasswordChanged | LsaIOpenPolicyTrusted |
LsaIQueryForestTrustInfo | LsaIQueryInformationPolicyTrusted |
LsaIQueryPackageAttrInLogonSession | LsaIQuerySiteInfo |
LsaIQuerySubnetInfo | LsaIQueryUpnSuffixes |
LsaIReferenceCredHandle | LsaIRegisterLogonSessionCallback |
LsaIRegisterNotification | LsaIRegisterPolicyChangeNotificationCallback |
LsaIReplicateClientObject | LsaISafeMode |
LsaISamIndicatedDsStarted | LsaISetClientDnsHostName |
LsaISetLogonGuidInLogonSession | LsaISetLogonInfo |
LsaISetNewSyskey | LsaISetPackageAttrInLogonSession |
LsaISetSupplementalTokenInfo | LsaISetTokenDacl |
LsaISetUserFlags | LsaISetupWasRun |
LsaIUnregisterAllPolicyChangeNotificationCallback | LsaIUnregisterLogonSessionCallback |
LsaIUnregisterPolicyChangeNotificationCallback | LsaIUpdateForestTrustInformation |
LsaIUpdateKerbMaxTokenSize | LsaIUpdateLogonSession |
LsaIValidateTargetInfo | LsaIVerifyCachability |
LsaIWriteAuditEvent | LsapAuOpenSam |
LsapCheckBootMode | LsapDsDebugInitialize |
LsapDsInitializeDsStateInfo | LsapInitLsa |
LsarClose | LsarCreateSecret |
LsarDeleteObject | LsarEnumerateTrustedDomainsEx |
LsarLookupSids | LsarOpenPolicy |
LsarOpenSecret | LsarQueryDomainInformationPolicy |
LsarQueryInformationPolicy | LsarQuerySecret |
LsarQueryTrustedDomainInfoByName | LsarSetInformationPolicy |
LsarSetSecret | LsarSetTrustedDomainInfoByName |
ServiceInit |
Imported Functions List
The following functions are imported by this dll:- ntdll.dll:
DbgPrint DbgUserBreakPoint EtwEventRegister EtwEventUnregister EtwEventWrite EtwGetTraceLoggerHandle EtwLogTraceEvent EtwRegisterSecurityProvider EtwRegisterTraceGuidsW EtwWriteUMSecurityEvent EvtIntReportAuthzEventAndSourceAsync LdrLoadDll NtAccessCheckAndAuditAlarm NtAccessCheckByTypeAndAuditAlarm NtAccessCheckByTypeResultListAndAuditAlarm NtAdjustPrivilegesToken NtAllocateLocallyUniqueId NtAllocateVirtualMemory NtClose NtCloseObjectAuditAlarm NtConnectPort NtCreateEvent NtCreateFile NtCreateSection NtCreateToken NtDeleteObjectAuditAlarm NtDuplicateObject NtDuplicateToken NtEnumerateKey NtEnumerateValueKey NtFilterToken NtFlushKey NtFreeVirtualMemory NtFsControlFile NtImpersonateAnonymousToken NtMapViewOfSection NtOpenEvent NtOpenFile NtOpenKey NtOpenProcess NtOpenProcessToken NtOpenSymbolicLinkObject NtOpenThreadToken NtPrivilegeCheck NtPrivilegeObjectAuditAlarm NtPrivilegedServiceAuditAlarm NtQueryInformationProcess NtQueryInformationToken NtQueryLicenseValue NtQueryObject NtQuerySymbolicLinkObject NtQuerySystemInformation NtQuerySystemTime NtQueryValueKey NtRaiseHardError NtReadVirtualMemory NtReplyPort NtRequestWaitReplyPort NtResetEvent NtSetEvent NtSetInformationFile NtSetInformationThread NtSetInformationToken NtSetSecurityObject NtSetSystemTime NtSetValueKey NtShutdownSystem NtWaitForSingleObject NtWriteVirtualMemory RtlAbortRXact RtlAcquireResourceExclusive RtlAcquireResourceShared RtlAddAccessAllowedAce RtlAddAce RtlAddActionToRXact RtlAddMandatoryAce RtlAdjustPrivilege RtlAllocateAndInitializeSid RtlAllocateHeap RtlAnsiStringToUnicodeString RtlAppendUnicodeStringToString RtlAppendUnicodeToString RtlApplyRXact RtlAreAllAccessesGranted RtlCompareMemory RtlCompareUnicodeString RtlConvertExclusiveToShared RtlConvertSharedToExclusive RtlConvertSidToUnicodeString RtlCopyLuid RtlCopySid RtlCopyString RtlCopyUnicodeString RtlCreateAcl RtlCreateHeap RtlCreateSecurityDescriptor RtlCreateServiceSid RtlCreateUnicodeStringFromAsciiz RtlDeleteAce RtlDeleteCriticalSection RtlDeleteElementGenericTableAvl RtlDeleteResource RtlDeregisterWait RtlDosPathNameToNtPathName_U RtlDosPathNameToRelativeNtPathName_U RtlEnterCriticalSection RtlEnumerateGenericTableAvl RtlEqualDomainName RtlEqualPrefixSid RtlEqualSid RtlEqualString RtlEqualUnicodeString RtlEthernetAddressToStringW RtlFindCharInUnicodeString RtlFindMessage RtlFreeAnsiString RtlFreeAnsiString RtlFreeHeap RtlFreeSid RtlGetAce RtlGetControlSecurityDescriptor RtlGetDaclSecurityDescriptor RtlGetLastNtStatus RtlGetNtProductType RtlGetSetBootStatusData RtlGetThreadPreferredUILanguages RtlIdentifierAuthoritySid RtlImageNtHeader RtlImpersonateSelf RtlImpersonateSelfEx RtlInitAnsiString RtlInitString RtlInitUnicodeString RtlInitUnicodeStringEx RtlInitializeCriticalSection RtlInitializeCriticalSectionAndSpinCount RtlInitializeGenericTableAvl RtlInitializeRXact RtlInitializeResource RtlInitializeSid RtlInsertElementGenericTableAvl RtlIntegerToChar RtlIntegerToUnicodeString RtlIpv4AddressToStringW RtlIpv6AddressToStringW RtlLeaveCriticalSection RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlLockBootStatusData RtlLookupElementGenericTableAvl RtlMakeSelfRelativeSD RtlMapGenericMask RtlNewSecurityObject RtlNtStatusToDosError RtlPrefixUnicodeString RtlQueryInformationAcl RtlQueryTimeZoneInformation RtlRegisterWait RtlReleaseRelativeName RtlReleaseResource RtlRunDecodeUnicodeString RtlSetDaclSecurityDescriptor RtlSetOwnerSecurityDescriptor RtlSetSaclSecurityDescriptor RtlSetSecurityObject RtlSetThreadPreferredUILanguages RtlSidDominates RtlSidHashInitialize RtlSidHashLookup RtlStartRXact RtlSubAuthorityCountSid RtlSubAuthoritySid RtlTimeFieldsToTime RtlTimeToSecondsSince1980 RtlTryEnterCriticalSection RtlUnicodeStringToAnsiString RtlUnicodeStringToInteger RtlUnlockBootStatusData RtlUnwind RtlUpcaseUnicodeStringToOemString RtlValidRelativeSecurityDescriptor RtlValidSid RtlpNtEnumerateSubKey RtlpNtOpenKey RtlpNtQueryValueKey VerSetConditionMask WinSqmIncrementDWORD _allmul _alloca_probe _snprintf_s _snwprintf_s _strcmpi _strcmpi _strnicmp _vsnprintf_s _vsnwprintf _wcsicmp _wcsnicmp _wtoi mbstowcs memcpy memmove memset strcat_s strchr strcpy_s strrchr swprintf_s towupper wcscat_s wcschr wcscpy_s wcsncat_s wcsncpy_s wcsrchr wcsstr - msvcrt.dll:
_XcptFilter __CxxFrameHandler _amsg_exit _initterm _ultow _vsnprintf free malloc qsort realloc strtok wcsncmp - RPCRT4.dll:
I_RpcBindingInqLocalClientPID I_RpcBindingInqTransportType I_RpcBindingIsClientLocal I_RpcGetExtendedError I_RpcMapWin32Status I_RpcOpenClientProcess I_RpcOpenClientThread MesDecodeIncrementalHandleCreate MesEncodeIncrementalHandleCreate MesHandleFree MesIncrementalHandleReset NdrClientCall2 NdrMesTypeAlignSize2 NdrMesTypeDecode2 NdrMesTypeEncode2 NdrServerCall2 RpcBindingFree RpcBindingFromStringBindingW RpcBindingInqAuthClientW RpcBindingServerFromClient RpcBindingSetAuthInfoA RpcBindingSetAuthInfoExA RpcBindingSetAuthInfoExW RpcBindingSetAuthInfoW RpcBindingSetOption RpcBindingToStringBindingW RpcBindingVectorFree RpcEpRegisterW RpcEpResolveBinding RpcErrorEndEnumeration RpcErrorGetNextRecord RpcErrorStartEnumeration RpcImpersonateClient RpcMgmtEnableIdleCleanup RpcNetworkIsProtseqValidW RpcRevertToSelf RpcRevertToSelfEx RpcServerInqBindings RpcServerInqCallAttributesW RpcServerInqDefaultPrincNameW RpcServerRegisterAuthInfoW RpcServerRegisterIf RpcServerRegisterIf2 RpcServerRegisterIfEx RpcServerUnregisterIf RpcServerUseProtseqEpW RpcSsGetContextBinding RpcStringBindingComposeW RpcStringBindingParseW RpcStringFreeW RpcUserFree UuidCreate UuidFromStringW UuidToStringW - API-MS-Win-Security-SDDL-L1-1-0.dll:
sechost!ConvertSecurityDescriptorToStringSecurityDescriptorW sechost!ConvertSidToStringSidW sechost!ConvertStringSecurityDescriptorToSecurityDescriptorW sechost!ConvertStringSidToSidW - SspiCli.dll:
CredUnmarshalTargetInfo LsaCallAuthenticationPackage LsaConnectUntrusted LsaDeregisterLogonProcess LsaFreeReturnBuffer LsaLogonUser LsaLookupAuthenticationPackage LsaRegisterLogonProcess LsaRegisterPolicyChangeNotification SecCacheSspiPackages SeciAllocateAndSetCallFlags SeciFreeCallContext SspiEncodeStringsAsAuthIdentity SspiFreeAuthIdentity SspiLocalFree SspiPrepareForCredWrite SspiUnmarshalAuthIdentityInternal - API-MS-WIN-Service-Core-L1-1-0.dll:
sechost!SetServiceStatus sechost!StartServiceCtrlDispatcherW - API-MS-WIN-Service-winsvc-L1-1-0.dll:
sechost!ChangeServiceConfigA sechost!ControlService sechost!I_ScIsSecurityProcess sechost!OpenSCManagerA sechost!OpenServiceA sechost!QueryServiceConfigA sechost!QueryServiceStatus sechost!RegisterServiceCtrlHandlerW - ADVAPI32.dll:
AccessCheck AccessCheckAndAuditAlarmW AddAccessAllowedAce AddAuditAccessAce AdjustTokenPrivileges AllocateAndInitializeSid AllocateLocallyUniqueId AuditFree BuildTrusteeWithSidA CheckTokenMembership CopySid CreateWellKnownSid CredDeleteW CredIsProtectedW CredProtectW CredUnmarshalCredentialW CredUnprotectW CredWriteW CredpDecodeCredential CredpEncodeCredential DuplicateToken DuplicateTokenEx ElfDeregisterEventSource ElfFlushEventLog ElfRegisterEventSourceW ElfReportEventW EnumDependentServicesW EqualDomainSid EqualSid FreeSid GetAclInformation GetEventLogInformation GetFileSecurityW GetLengthSid GetNamedSecurityInfoW GetSecurityDescriptorDacl GetSecurityDescriptorLength GetSecurityDescriptorSacl GetSidIdentifierAuthority GetSidSubAuthority GetSidSubAuthorityCount GetTokenInformation GetWindowsAccountDomainSid ImpersonateLoggedOnUser ImpersonateSelf InitializeAcl InitializeSecurityDescriptor IsTokenRestricted IsValidSid IsWellKnownSid LogonUserExW LookupAccountNameW LookupPrivilegeValueW LsaClose LsaCreateTrustedDomainEx LsaDelete LsaFreeMemory LsaICLookupNames LsaICLookupNamesWithCreds LsaICLookupSids LsaICLookupSidsWithCreds LsaLookupNames2 LsaNtStatusToWinError LsaOpenPolicy LsaOpenSecret LsaOpenTrustedDomain LsaOpenTrustedDomainByName LsaQueryInfoTrustedDomain LsaQueryInformationPolicy LsaQueryTrustedDomainInfoByName LsaRetrievePrivateData LsaSetInformationPolicy LsaStorePrivateData MakeSelfRelativeSD MapGenericMask OpenProcessToken OpenThreadToken RegCloseKey RegCreateKeyExW RegDeleteKeyW RegDeleteValueW RegEnumKeyExW RegGetValueW RegLoadKeyW RegNotifyChangeKeyValue RegOpenKeyExW RegQueryInfoKeyW RegQueryValueExW RegQueryValueW RegSaveKeyW RegSetValueExW RegUnLoadKeyW RevertToSelf SetEntriesInAclW SetFileSecurityW SetNamedSecurityInfoW SetSecurityDescriptorDacl SetSecurityDescriptorGroup SetSecurityDescriptorOwner SetSecurityDescriptorSacl SetThreadToken SetTokenInformation SystemFunction007 ntdll!MD5Final ntdll!MD5Init ntdll!MD5Update - USER32.dll:
GetSystemMetrics - SAMSRV.dll:
SamIAccountRestrictions SamIAmIGC SamIChangePasswordForeignUser SamIConnect SamIDoFSMORoleChange SamIFreeSidAndAttributesList SamIFreeSidArray SamIFreeVoid SamIFree_SAMPR_RETURNED_USTRING_ARRAY SamIFree_SAMPR_ULONG_ARRAY SamIFree_SAMPR_USER_INFO_BUFFER SamIGCLookupNames SamIGCLookupSids SamIGetAliasMembership SamIGetDefaultAdministratorName SamIGetResourceGroupMembershipsTransitive SamIGetUserLogonInformation SamIGetUserLogonInformationEx SamIInitialize SamIIsExtendedSidMode SamIIsSetupInProgress SamIMixedDomain SamIMixedDomain2 SamIQueryCapabilities SamIQueryServerRole SamISetAuditingInformation SamIUpdateLogonStatistics SampDsIsRunning SampUsingDsData SamrCloseHandle SamrCreateUser2InDomain SamrDeleteUser SamrEnumerateUsersInDomain SamrLookupIdsInDomain SamrLookupNamesInDomain SamrOpenDomain SamrOpenUser SamrRidToSid SamrSetInformationUser - MSASN1.dll:
ASN1BERDecBitString ASN1BERDecEndOfContents ASN1BERDecExplicitTag ASN1BERDecNotEndOfContents ASN1BERDecObjectIdentifier ASN1BERDecOctetString ASN1BERDecPeekTag ASN1BERDecSkip ASN1BERDecU32Val ASN1BERDecZeroCharString ASN1BEREncEndOfContents ASN1BEREncExplicitTag ASN1BEREncObjectIdentifier ASN1BEREncRemoveZeroBits ASN1BEREncU32 ASN1BEREoid_free ASN1BEREoid_free ASN1DEREncBitString ASN1DEREncCharString ASN1DEREncCharString ASN1DecAlloc ASN1DecSetError ASN1EncSetError ASN1Free ASN1Free ASN1_CloseDecoder ASN1_CloseEncoder ASN1_CreateDecoder ASN1_CreateEncoder ASN1_CreateModule ASN1_Decode ASN1_Encode ASN1_FreeDecoded ASN1_FreeEncoded ASN1objectidentifier_free - wevtapi.dll:
EvtClose EvtCreateRenderContext EvtRender EvtSubscribe - lsass.exe:
LsaGetInterface LsaRegisterExtension - KERNEL32.dll:
CheckElevationEnabled CloseHandle CompareFileTime CompareStringOrdinal CompareStringW CopyFileW CreateDirectoryW CreateEventW CreateFileA CreateFileMappingW CreateFileW CreateThread CreateTimerQueueTimer DebugBreak DelayLoadFailureHook DeleteFileW DeleteTimerQueueTimer DnsHostnameToComputerNameW DuplicateHandle ExpandEnvironmentStringsW FileTimeToLocalFileTime FileTimeToSystemTime FindClose FindCloseChangeNotification FindFirstChangeNotificationW FindFirstFileW FindNextChangeNotification FindNextFileW FlushFileBuffers FlushViewOfFile FormatMessageW FreeLibrary GetComputerNameExA GetComputerNameExW GetComputerNameW GetCurrentProcess GetCurrentProcessId GetCurrentThread GetCurrentThreadId GetDateFormatW GetDriveTypeW GetEnvironmentVariableW GetFileAttributesW GetFileInformationByHandleEx GetFileSize GetFileSizeEx GetFileTime GetFileType GetLastError GetLocalTime GetLogicalDrives GetModuleFileNameA GetModuleFileNameW GetModuleHandleW GetProcAddress GetProcessHeap GetProductInfo GetProfileStringA GetStringTypeW GetSystemDirectoryW GetSystemInfo GetSystemTime GetSystemTimeAsFileTime GetTickCount GetTimeFormatW GetVersion GetVersionExW GetVolumeInformationW GetWindowsDirectoryW HeapFree HeapSetInformation InterlockedCompareExchange InterlockedDecrement InterlockedExchange InterlockedExchangeAdd InterlockedIncrement IsDebuggerPresent LoadLibraryA LoadLibraryExA LoadLibraryExW LoadLibraryW LocalAlloc LocalFree LocalReAlloc MapViewOfFile MapViewOfFileEx MoveFileW MultiByteToWideChar OpenEventW OpenFileMappingW OpenProcess OutputDebugStringA OutputDebugStringW QueryFullProcessImageNameW QueryPerformanceCounter QueueUserWorkItem RaiseException RaiseFailFastException ReadFile RegCreateKeyExA RegDeleteKeyExA RegOpenKeyExA RegQueryInfoKeyA RegSetValueExA RegisterWaitForSingleObjectEx RemoveDirectoryW ResetEvent SearchPathW SetComputerNameExW SetConsoleCtrlHandler SetEnvironmentVariableW SetEvent SetFileAttributesW SetFileInformationByHandle SetFilePointer SetLastError SetProcessShutdownParameters SetUnhandledExceptionFilter Sleep SystemTimeToFileTime TerminateProcess TlsAlloc TlsGetValue TlsSetValue UnhandledExceptionFilter UnmapViewOfFile UnregisterWait UnregisterWaitEx VerifyVersionInfoA VerifyVersionInfoW VirtualAlloc VirtualFree VirtualLock VirtualProtect VirtualQuery WTSGetActiveConsoleSessionId WaitForSingleObject WaitForSingleObjectEx WideCharToMultiByte WriteFile lstrcmpiW lstrlen lstrlenW ntdll!RtlAllocateHeap ntdll!RtlDeleteCriticalSection ntdll!RtlEnterCriticalSection ntdll!RtlExitUserThread ntdll!RtlInitializeCriticalSection ntdll!RtlInterlockedCompareExchange64 ntdll!RtlLeaveCriticalSection - API-MS-WIN-Service-Management-L1-1-0.dll:
sechost!CloseServiceHandle sechost!OpenSCManagerW sechost!OpenServiceW sechost!StartServiceW - API-MS-WIN-Service-Management-L2-1-0.dll:
sechost!ChangeServiceConfigW sechost!QueryServiceConfigW