Windows 10 DLL File Information - offlinelsa.dll |
The following DLL report was generated by automatic DLL script that scanned and loaded all DLL files in the system32 directory of Windows 10, extracted the information from them, and then saved it into HTML reports. If you want to view a report of another DLL, go to the main page of this Web site.
General Information
File Description: | Windows |
File Version: | 10.0.10130.0 (fbl_impressive.150522-2224) |
Company: | Microsoft Corporation |
Product Name: | Microsoft® Windows® Operating System |
DLL popularity | Very Low - 1 other DLL files in system32 directory are statically linked to this file. |
File Size: | 98 KB |
Total Number of Exported Functions: | 19 |
Total Number of Exported Functions With Names: | 19 |
Section Headers
Name | Virtual Address | Raw Data Size | % of File | Characteristics | Section Contains... |
---|---|---|---|---|---|
.text | 0x00001000 | 88,064 Bytes | 87.3% | Read, Execute | Code |
.data | 0x00017000 | 1,024 Bytes | 1.0% | Write, Read | Initialized Data |
.idata | 0x00018000 | 5,120 Bytes | 5.1% | Read | Initialized Data |
.rsrc | 0x0001a000 | 1,024 Bytes | 1.0% | Read | Initialized Data |
.reloc | 0x0001b000 | 4,608 Bytes | 4.6% | Read, Discardable | Initialized Data |
Static Linking
offlinelsa.dll is statically linked to the following files:msvcrt.dll
api-ms-win-core-libraryloader-l1-1-0.dll
api-ms-win-core-heap-obsolete-l1-1-0.dll
api-ms-win-eventing-classicprovider-l1-1-0.dll
api-ms-win-security-lsalookup-l2-1-0.dll
api-ms-win-core-errorhandling-l1-1-0.dll
api-ms-win-core-file-l1-1-0.dll
api-ms-win-security-sddl-l1-1-0.dll
api-ms-win-core-handle-l1-1-0.dll
api-ms-win-security-base-l1-1-0.dll
api-ms-win-core-synch-l1-1-0.dll
api-ms-win-core-processthreads-l1-1-0.dll
api-ms-win-core-kernel32-legacy-l1-1-0.dll
api-ms-win-core-processthreads-l1-1-1.dll
api-ms-win-security-cryptoapi-l1-1-0.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-profile-l1-1-0.dll
api-ms-win-core-sysinfo-l1-1-0.dll
ntdll.dll
bcrypt.dll
RPCRT4.dll
api-ms-win-core-memory-l1-1-0.dll
This means that when offlinelsa.dll is loaded, the above files are automatically loaded too. If one of these files is corrupted or missing, offlinelsa.dll won't be loaded.
List of files that are statically linked to offlinelsa.dll
offlinesam.dll
This means that when one of the above files is loaded, offlinelsa.dll will be loaded too. (The opposite of the previous 'Static Linking' section)
General Resources Information
Resource Type | Number of Items | Total Size | % of File |
---|---|---|---|
Icons | 0 | 0 Bytes | 0.0% |
Animated Icons | 0 | 0 Bytes | 0.0% |
Cursors | 0 | 0 Bytes | 0.0% |
Animated Cursors | 0 | 0 Bytes | 0.0% |
Bitmaps | 0 | 0 Bytes | 0.0% |
AVI Files | 0 | 0 Bytes | 0.0% |
Dialog-Boxes | 0 | 0 Bytes | 0.0% |
HTML Related Files | 0 | 0 Bytes | 0.0% |
Menus | 0 | 0 Bytes | 0.0% |
Strings | 0 | 0 Bytes | 0.0% |
Type Libraries | 0 | 0 Bytes | 0.0% |
Manifest | 0 | 0 Bytes | 0.0% |
All Others | 1 | 904 Bytes | 0.9% |
Total | 1 | 904 Bytes | 0.9% |
Icons in this file
No icons found in this file
Cursors in this file
No cursors found in this file
Dialog-boxes list (up to 1000 dialogs)
No dialog resources in this file.
String resources in this dll (up to 1000 strings)
No string resources in this file.
COM Classes/Interfaces
There is no type library in this file with COM classes/interfaces information
Exported Functions List
The following functions are exported by this dll:LsaOfflineAddAccountRights | LsaOfflineAddPrivilegesToAccount | LsaOfflineClose |
LsaOfflineCreateAccount | LsaOfflineDelete | LsaOfflineEnumerateAccountRights |
LsaOfflineEnumerateAccounts | LsaOfflineEnumeratePrivilegesOfAccount | LsaOfflineFreeMemory |
LsaOfflineGetSystemAccessAccount | LsaOfflineOpenAccount | LsaOfflineOpenPolicy |
LsaOfflineOpenPolicyExternal | LsaOfflineOpenPolicyForInstaller | LsaOfflineQueryInformationPolicy |
LsaOfflineRemoveAccountRights | LsaOfflineRemovePrivilegesFromAccount | LsaOfflineSetSystemAccessAccount |
LsaOfflineSyskeyRequest |
Imported Functions List
The following functions are imported by this dll:- msvcrt.dll:
_XcptFilter _amsg_exit _except_handler4_common _initterm _purecall _vsnwprintf free malloc memcmp memcpy memset - api-ms-win-core-libraryloader-l1-1-0.dll:
KernelBase!DisableThreadLibraryCalls - api-ms-win-core-heap-obsolete-l1-1-0.dll:
kernel32!LocalAlloc kernel32!LocalFree - api-ms-win-eventing-classicprovider-l1-1-0.dll:
ntdll!EtwGetTraceEnableFlags ntdll!EtwGetTraceEnableLevel ntdll!EtwGetTraceLoggerHandle ntdll!EtwRegisterTraceGuidsW ntdll!EtwTraceMessage ntdll!EtwUnregisterTraceGuids - api-ms-win-security-lsalookup-l2-1-0.dll:
advapi32!LookupPrivilegeNameW advapi32!LookupPrivilegeValueW - api-ms-win-core-errorhandling-l1-1-0.dll:
KernelBase!GetLastError KernelBase!SetUnhandledExceptionFilter KernelBase!UnhandledExceptionFilter - api-ms-win-core-file-l1-1-0.dll:
KernelBase!GetFileAttributesW - api-ms-win-security-sddl-l1-1-0.dll:
sechost!ConvertSidToStringSidW sechost!ConvertStringSidToSidW - api-ms-win-core-handle-l1-1-0.dll:
KernelBase!CloseHandle - api-ms-win-security-base-l1-1-0.dll:
KernelBase!DuplicateTokenEx KernelBase!GetLengthSid KernelBase!GetTokenInformation KernelBase!IsValidSid - api-ms-win-core-synch-l1-1-0.dll:
ntdll!RtlAcquireSRWLockExclusive ntdll!RtlInitializeConditionVariable ntdll!RtlReleaseSRWLockExclusive - api-ms-win-core-processthreads-l1-1-0.dll:
KernelBase!OpenProcessToken kernel32!GetCurrentProcess kernel32!GetCurrentProcessId kernel32!GetCurrentThreadId kernel32!SetThreadStackGuarantee kernel32!TerminateProcess - api-ms-win-core-kernel32-legacy-l1-1-0.dll:
kernel32!WTSGetActiveConsoleSessionId - api-ms-win-core-processthreads-l1-1-1.dll:
kernel32!OpenProcess - api-ms-win-security-cryptoapi-l1-1-0.dll:
cryptsp!CryptAcquireContextW cryptsp!CryptGenRandom cryptsp!CryptReleaseContext - api-ms-win-core-synch-l1-2-0.dll:
KernelBase!Sleep - api-ms-win-core-profile-l1-1-0.dll:
ntdll!RtlQueryPerformanceCounter - api-ms-win-core-sysinfo-l1-1-0.dll:
KernelBase!GetSystemInfo KernelBase!GetSystemTimeAsFileTime KernelBase!GetTickCount - ntdll.dll:
DbgPrintEx NtAdjustPrivilegesToken NtClose NtCreateKey NtDeleteKey NtDeleteValueKey NtDuplicateToken NtFlushKey NtLoadKey NtOpenKey NtOpenProcessToken NtOpenThreadToken NtQueryInformationToken NtQueryKey NtQuerySystemInformation NtQueryValueKey NtSetInformationThread NtSetSecurityObject NtSetValueKey NtUnloadKey2 RtlAddAccessAllowedAce RtlAllocateAndInitializeSid RtlAllocateHeap RtlAnsiStringToUnicodeString RtlCompareUnicodeString RtlCopySid RtlCreateAcl RtlCreateSecurityDescriptor RtlDosPathNameToRelativeNtPathName_U_WithStatus RtlEqualSid RtlEqualUnicodeString RtlFormatCurrentUserKeyPath RtlFreeAnsiString RtlFreeAnsiString RtlFreeHeap RtlFreeSid RtlGetAce RtlGetDaclSecurityDescriptor RtlGetGroupSecurityDescriptor RtlGetOwnerSecurityDescriptor RtlGetSaclSecurityDescriptor RtlImageNtHeader RtlInitAnsiString RtlInitUnicodeString RtlInitializeRXact RtlLengthSecurityDescriptor RtlLengthSid RtlNewSecurityObject RtlRaiseStatus RtlSetDaclSecurityDescriptor RtlSetOwnerSecurityDescriptor RtlSubAuthoritySid RtlUnicodeStringToAnsiString RtlUpcaseUnicodeChar RtlValidSid RtlpNtEnumerateSubKey - bcrypt.dll:
BCryptCloseAlgorithmProvider BCryptCreateHash BCryptDestroyHash BCryptDestroyKey BCryptEncrypt BCryptFinishHash BCryptGenerateSymmetricKey BCryptHashData BCryptOpenAlgorithmProvider - RPCRT4.dll:
RpcStringFreeW UuidCreate UuidToStringW - api-ms-win-core-memory-l1-1-0.dll:
KernelBase!VirtualAlloc KernelBase!VirtualProtect KernelBase!VirtualQuery