Windows 10 DLL File Information - scesrv.dll |
The following DLL report was generated by automatic DLL script that scanned and loaded all DLL files in the system32 directory of Windows 10, extracted the information from them, and then saved it into HTML reports. If you want to view a report of another DLL, go to the main page of this Web site.
General Information
File Description: | Windows Security Configuration Editor Engine |
File Version: | 10.0.10130.0 (fbl_impressive.150522-2224) |
Company: | Microsoft Corporation |
Product Name: | Microsoft® Windows® Operating System |
DLL popularity | Very Low - There is no any other DLL in system32 directory that is statically linked to this file. |
File Size: | 408 KB |
Total Number of Exported Functions: | 2 |
Total Number of Exported Functions With Names: | 2 |
Section Headers
Name | Virtual Address | Raw Data Size | % of File | Characteristics | Section Contains... |
---|---|---|---|---|---|
.text | 0x00001000 | 382,464 Bytes | 91.5% | Read, Execute | Code |
.data | 0x0005f000 | 1,536 Bytes | 0.4% | Write, Read | Initialized Data |
.idata | 0x00060000 | 8,192 Bytes | 2.0% | Read | Initialized Data |
.didat | 0x00062000 | 1,024 Bytes | 0.2% | Write, Read | Initialized Data |
.tls | 0x00063000 | 3,072 Bytes | 0.7% | Write, Read | Initialized Data |
.rsrc | 0x00064000 | 1,536 Bytes | 0.4% | Read | Initialized Data |
.reloc | 0x00065000 | 18,944 Bytes | 4.5% | Read, Discardable | Initialized Data |
Static Linking
scesrv.dll is statically linked to the following files:msvcrt.dll
RPCRT4.dll
api-ms-win-core-datetime-l1-1-1.dll
api-ms-win-core-processthreads-l1-1-2.dll
api-ms-win-core-file-l1-2-1.dll
api-ms-win-eventing-classicprovider-l1-1-0.dll
api-ms-win-core-libraryloader-l1-2-1.dll
api-ms-win-core-libraryloader-l1-2-0.dll
api-ms-win-core-sysinfo-l1-2-1.dll
api-ms-win-core-registry-l1-1-0.dll
api-ms-win-security-base-l1-2-0.dll
api-ms-win-core-timezone-l1-1-0.dll
api-ms-win-core-string-l1-1-0.dll
api-ms-win-core-errorhandling-l1-1-1.dll
api-ms-win-core-heap-l2-1-0.dll
api-ms-win-core-handle-l1-1-0.dll
api-ms-win-core-processenvironment-l1-2-0.dll
api-ms-win-core-synch-l1-2-0.dll
api-ms-win-core-localization-l1-2-1.dll
api-ms-win-core-file-l2-1-2.dll
api-ms-win-core-console-l1-1-0.dll
api-ms-win-core-profile-l1-1-0.dll
api-ms-win-core-kernel32-legacy-l1-1-1.dll
api-ms-win-core-threadpool-legacy-l1-1-0.dll
api-ms-win-core-string-obsolete-l1-1-0.dll
api-ms-win-core-privateprofile-l1-1-1.dll
ntdll.dll
api-ms-win-core-memory-l1-1-2.dll
api-ms-win-core-delayload-l1-1-1.dll
This means that when scesrv.dll is loaded, the above files are automatically loaded too. If one of these files is corrupted or missing, scesrv.dll won't be loaded.
General Resources Information
Resource Type | Number of Items | Total Size | % of File |
---|---|---|---|
Icons | 0 | 0 Bytes | 0.0% |
Animated Icons | 0 | 0 Bytes | 0.0% |
Cursors | 0 | 0 Bytes | 0.0% |
Animated Cursors | 0 | 0 Bytes | 0.0% |
Bitmaps | 0 | 0 Bytes | 0.0% |
AVI Files | 0 | 0 Bytes | 0.0% |
Dialog-Boxes | 0 | 0 Bytes | 0.0% |
HTML Related Files | 0 | 0 Bytes | 0.0% |
Menus | 0 | 0 Bytes | 0.0% |
Strings | 378 | 36,652 Bytes | 8.8% |
Type Libraries | 0 | 0 Bytes | 0.0% |
Manifest | 0 | 0 Bytes | 0.0% |
All Others | 3 | 7,532 Bytes | 1.8% |
Total | 381 | 44,184 Bytes | 10.6% |
Icons in this file
No icons found in this file
Cursors in this file
No cursors found in this file
Dialog-boxes list (up to 1000 dialogs)
No dialog resources in this file.
String resources in this dll (up to 1000 strings)
String ID | String Text |
---|---|
7101 | ----Configuration engine was initialized with one or more errors.---- |
7102 | ----Configuration engine was initialized successfully.---- |
7103 | ----Reading Configuration Template info... |
7104 | ----Configure Security Policy... |
7105 | System Access configuration was completed with one or more errors. |
7106 | System Access configuration was completed successfully. |
7107 | Audit/Log configuration was completed with one or more errors. |
7108 | Audit/Log configuration was completed successfully. |
7109 | ----Configure User Rights... |
7110 | User Rights configuration was completed with one or more errors. |
7111 | User Rights configuration was completed successfully. |
7112 | ----Configure User Security Settings... |
7113 | User Security configuration was completed with one or more errors. |
7114 | User Security configuration was completed successfully. |
7115 | ----Configure Group Membership... |
7116 | Group Membership configuration was completed with one or more errors. |
7117 | Group Membership configuration was completed successfully. |
7118 | ----Configure Registry Keys... |
7119 | Configuration of Registry Keys was completed with one or more errors. |
7120 | Configuration of Registry Keys was completed successfully. |
7121 | ----Configure File Security... |
7122 | File Security configuration was completed with one or more errors. |
7123 | File Security configuration was completed successfully. |
7124 | ----Configure Active Directory Security... |
7125 | Active Directory Security configuration was completed with one or more errors. |
7126 | Active Directory Security configuration was completed successfully. |
7127 | ----Configure General Service Settings... |
7128 | General Service configuration was completed with one or more errors. |
7129 | General Service configuration was completed successfully. |
7130 | ----Configure available attachment engines... |
7131 | An error may have occurred during configuration of attachment engines. |
7132 | Configuration of attachment engines was completed successfully. |
7133 | Kerberos Policy configuration was completed with one or more errors. |
7134 | Kerberos Policy configuration was completed successfully. |
7135 | Configuration of Registry Values was completed with one or more errors. |
7136 | Configuration of Registry Values was completed successfully. |
7137 | ----Un-initialize configuration engine... |
7138 | Administrator account is not allowed to be disabled. |
7139 | Guest account is not allowed to be disabled. |
7140 | add %s. |
7141 | add to %s. |
7142 | Cannot remove special account %s. |
7143 | Configure %s. |
7144 | error adding %s. |
7145 | error adding object to %s. |
7146 | Error renaming administrator account. |
7147 | Error configuring %s. |
7148 | Error configuring event audit settings. |
7149 | Error renaming guest account. |
7150 | Error configuring log settings. |
7151 | Error configuring kerberos policy. |
7152 | Error configuring account lockout information. |
7153 | Error configuring account force logoff information. |
7154 | Error configuring password information. |
7155 | error removing %s. |
7156 | Error configuring password OWF (UAS) information. |
7157 | Error configuring user settings. |
7158 | Configure event audit settings. |
7159 | Configure kerberos policy. |
7160 | Configure account lockout information. |
7161 | Configure account force logoff information. |
7162 | Configure log settings. |
7163 | Attachment does not support configuration interface. |
7164 | Configure other policy settings. |
7165 | Configure password information. |
7166 | remove %s. |
7167 | Rename the Administrator account to %s. |
7168 | Rename the Guest account to %s. |
7169 | Take ownership of object %s. |
7170 | Configure password OWF (UAS) information. |
7171 | Configure user settings. |
7172 | Error configuring registry values. |
7173 | Stopping service %s failed. |
7174 | Starting service %s failed. |
7175 | Opening service %s for stop access failed. |
7176 | Opening service %s for start access failed. |
7177 | Administrator account is disabled. |
7178 | Administrator account is enabled. |
7179 | Guest account is disabled. |
7180 | Guest account is enabled. |
7181 | ----Analysis engine was initialized with one or more errors.---- |
7182 | ----Analysis engine was initialized successfully.---- |
7183 | ----Reading Configuration Info... |
7184 | ----Analyze Security Policy... |
7185 | System Access analysis was completed with one or more errors. |
7186 | System Access analysis completed successfully. |
7187 | Audit/Log analysis was completed with one or more errors. |
7188 | Audit/Log analysis completed successfully. |
7189 | Security Policy analysis was completed with one or more errors. |
7190 | ----Analyze User Rights... |
7191 | User Rights analysis was completed with one or more errors. |
7192 | User Rights analysis completed successfully. |
7193 | ----Analyze user security setting... |
7194 | User security analysis was completed with one or more errors. |
7195 | User security analysis completed successfully. |
7196 | ----Analyze Group Membership... |
7197 | Group Membership analysis was completed with one or more errors. |
7198 | Group Membership analysis completed successfully. |
7199 | ----Analyze Registry Keys... |
7200 | Registry keys analysis was completed with one or more errors. |
7201 | Registry keys analysis completed successfully. |
7202 | ----Analyze File Security... |
7203 | File Security analysis was completed with one or more errors. |
7204 | File Security analysis completed successfully. |
7205 | ----Analyze Active Directory Security... |
7206 | Active Directory Security analysis was completed with one or more errors. |
7207 | Active Directory Security analysis completed successfully. |
7208 | ----Analyze General Service Settings... |
7209 | General Service analysis was completed with one or more errors. |
7210 | General Service analysis completed successfully. |
7211 | ----Analyze available attachment engines... |
7212 | Error may occur in attachment engines analysis. |
7213 | Attachment engines analysis completed successfully. |
7214 | Kerberos policy analysis was completed with one or more errors. |
7215 | Kerberos policy analysis completed successfully. |
7216 | Registry values analysis was completed with one or more errors. |
7217 | Registry values analysis completed successfully. |
7218 | ----Un-initialize analysis engine... |
7220 | Analyze %s. |
7221 | Error comparing ACL of %s. |
7222 | Error adding object %s. |
7223 | Error analyzing administrator account. |
7224 | Error analyzing %s. |
7225 | Error enumerating info for %s. |
7226 | Error analyzing event audit settings. |
7227 | Error analyzing guest account. |
7228 | Error analyzing kerberos policy. |
7229 | Error analyzing account lockout information. |
7230 | Error analyzing account force logoff information. |
7231 | Errors occurred. |
7232 | Error analyzing password information. |
7233 | Error saving analysis result for %s. |
7234 | Error analyzing security of %s. |
7235 | Error analyzing password OWF (UAS) information. |
7236 | Analyze event audit settings. |
7237 | Template is ignored because the system was configured with another template. |
7238 | Analyze kerberos policy. |
7239 | Analyze account lockout information. |
7240 | Analyze account force logoff information. |
7241 | Analyze log settings. |
7242 | Attachment does not support analysis interface. |
7243 | Analyze other policy settings. |
7244 | Analyze password information. |
7245 | Error starting a new section %s. |
7246 | Analyze password OWF (UAS) information. |
7247 | Error analyzing LSA lookup names setting. |
7249 | %s is ignored to be defined in default policy because it may break W2K clients. |
7250 | Error opening SAM account domain. |
7251 | Administrative privileged user logged on. |
7252 | Error creating administrators SID. |
7253 | Initializing engine, please wait... |
7254 | Recovering database, please wait... |
7255 | Cannot find %s. |
7256 | Create internal table--%s. |
7257 | Delete internal table--%s. |
7258 | Engine error status was reset. |
7259 | Error adjusting privilege %s. |
7260 | Aliases cannot be members of other groups. |
7261 | Member Of list contains invalid alias %s |
7262 | Error analyzing MemberOf list of group %s. |
7263 | Error analyzing group members of %s. |
7264 | Error building security descriptor for %s. |
7265 | Error computing inherited security for tree %s. |
7266 | Error converting %s. |
7267 | Error getting LDAP name of domain root. |
7268 | Error converting section %s. |
7269 | Error creating %s. |
7270 | Error deleting %s. |
7271 | Error generating template %s. |
7272 | Error loading attachment %s. |
7273 | Error occurred during lookup of all accounts. |
7274 | Error opening %s. |
7275 | Error converting Unicode string for %s. |
7276 | Error querying event audit settings. |
7277 | Error querying info of %s. |
7278 | Error querying account lockout information. |
7279 | Error querying account force logoff information. |
7280 | Error querying log settings. |
7281 | Error querying password information. |
7282 | Error querying security of %s. |
7283 | Error querying password OWF (UAS) information. |
7284 | Error querying volume information on %s. |
7285 | Error saving default settings--%s. |
7286 | Error configuring %s. |
7287 | Error setting security on %s. |
7288 | Cannot start file translation. |
7289 | Error taking ownership of %s. |
7290 | User objects cannot have members. |
7291 | Error writing info for %s. |
7292 | Event audit settings are turned off. |
7293 | Event audit settings are restored. |
7294 | Find database %s. |
7295 | ----Generate Template %s. |
7296 | Invalid group name %s. |
7297 | Invalid template path %s. |
7298 | Invalid security to set to %s. |
7299 | Invalid user name. |
7300 | Load attachment %s. |
7301 | Log file %s cannot be opened for write. Logging to screen. |
7302 | Error opening LSA policy. |
7303 | No acl support on volume %s. |
7304 | No detail info for %s. |
7305 | No system mapping was found for %s. |
7306 | %s is not a group. |
7307 | Parsing template %s. |
7308 | ------------------------------------------- |
7309 | ---------------------------------------- |
7310 | Error process time stamp for %s. |
7311 | Error getting total ticks. |
7312 | Error searching default database location. |
7313 | Error detecting current logged on user. |
7314 | Error opening the user object. |
7315 | Some user rights are not defined in SecEdit. |
7316 | Processing %s. |
7317 | Copy undo values to the merged policy. |
7318 | Error copying local policy to start policy propagation. |
7319 | Can't delete the existing internal database. |
7320 | JetInit() cannot recover some database(s). Run esentutl /g to check the integrity of the security database %%windir%%\security\Database\secedit.sdb. If it is corrupt, attempt a soft recovery first by running esentutl /r in the %%windir%%\security directory. If soft recovery fails, attempt a repair with esentutl /p on %%windir%%\security\Database\secedit.sdb. Then delete the log files in %%windir%%\security. |
7321 | Not Available - %s. |
7322 | Match - %s. |
7323 | Mismatch - %s. |
7324 | Not Configured - %s. |
7325 | New - %s. |
7326 | No Acl Support - %s. |
7327 | Configuring some user rights for this account is not supported. Re-attempting configuration by ignoring unsupported operation errors. |
7328 | Configuring %s for this account is not supported. |
7370 | Server Operators |
7371 | Account Operators |
7372 | Print Operators |
7373 | Create account RID %x |
7374 | UnsupportEd aCcount %s in SCE. |
7380 | Default policy from %s was copied in policy propagation. |
7381 | Error copying default policy from section %s. |
7385 | Warning |
7386 | Error |
7387 | Invoke Registry Value Delay Filter. |
7388 | Error %x during lookup of %d sid(s). |
7389 | Error convert SID to string. |
7390 | Copy domain policy into default domain GPO. |
7391 | Copy local policy into default OU GPO. |
7392 | Copy user rights into OU GPO: upgraded. |
7393 | Copy user rights into OU GPO: clean install. |
7394 | Error 0x%x to get process address of %s. |
7395 | Copy user right %s. |
7396 | No analysis is needed because it's already done. |
7397 | Fresh install - analysis is not necessary. |
7398 | %d mismatches are found under %s. |
7399 | Cannot open log file %s, the default log is being used. |
7400 | Cannot bind to %s. |
7401 | %s failed. |
7405 | Error %d opening system policy and undoing tables for section [%s]. |
7406 | Undo value for the undefined group policy setting <%s> wasn't reset successfully (%d). Undo value was not removed. |
7407 | Undo value for group policy setting <%s> was saved. |
7408 | Error allocating buffer to store undo settings. |
7409 | Error %d querying/saving undo value for group policy setting <%s>. |
7410 | Error %d querying undo value for group policy setting <%s>. |
7411 | Undo value for undefined group policy setting <%s> was reset successfully and removed. |
7412 | There is already an undo value for group policy setting <%s>. |
7413 | There is no undo value for the undefined group policy setting <%s>. The previous group policy setting was tattooed. |
7414 | Undo value for group policy setting <%s> was queried successfully. |
7415 | Add setting <%s> to the tattoo array (index %d). |
7416 | Error %d removing undo value for undefined group policy setting <%s>. |
7417 | Start processing undo values for %d settings. |
7418 | ----Configure 64-bit Registry Keys... |
7419 | ----Configure 32-bit Registry Keys... |
7420 | %s cannot be assigned to Authenticated Users, Everyone, or Administrator(s) because it will block interactive logons. |
7421 | %s cannot be assigned to Authenticated Users account or Everyone account or Enterprise Controllers account because it will block policy propagations and replications. |
7422 | %s must be assigned to Enterprise Controllers account for policy propagation and replication to succeed. |
7423 | %s must be assigned to administrators. This setting is adjusted. |
7424 | Error assigning %s to Enterprise Controllers account. This setting may block domain controllers from replication and propagation. |
7425 | Error assigning %s to Administrators account. This setting may block administrators from logging on interactively. |
7426 | %s must be assigned to SERVICE. This setting is adjusted. |
7430 | There are pending account policy changes from downlevel APIs. Policy engine ignores account policies for this propagation. |
7431 | There are pending audit policy changes from downlevel APIs. Policy engine ignores audit policies for this propagation. |
7432 | There are pending user right changes from downlevel APIs. Some of the account rights are not removed by policy engine . |
7433 | Ignore %s because there are pending user right changes for this account from downlevel APIs. |
7434 | Error querying pending notifications from the queue. Policy propagation may overwrite changes made by down-level LSA/SAM APIs. |
7435 | Error opening private LSA handle. Policy propagation aborted due to this error. |
7436 | Error querying user rights for account %s. |
7437 | Error %d to save policy change for account %s in the default GPOs. For more debugging information, please look security\logs\scepol.log under Windows root. |
7438 | Error %d to save policy change in the default GPOs. For more debugging information, please look security\logs\scepol.log under Windows root. |
7439 | Error initializing splay sentinel. |
7450 | Attempt to set security on non-NTFS volume %s. |
7451 | Error %d getting information on volume %s. |
7452 | Attempt to set security on non fixed volume %s. |
7453 | Begin converting root volume %s. |
7454 | Error converting user profiles folders under %s. |
7455 | Converted user profiles folders under %s. |
7456 | Error %d while configuring %s with setup template. |
7457 | Configured %s with setup template. |
7458 | Error %d while converting SDDL string %s. |
7459 | Error %d from MARTA while configuring %s. |
7460 | Error %d waiting for event %s. |
7461 | Successfully waited for event %s. |
7462 | Queried registry value %s with value %s. |
7463 | Error %d querying registry value %s. |
7465 | Registry value %s does not exist. |
7466 | Status code %d creating thread %s. |
7467 | Configured %s with MARTA. |
7468 | Error converting IIS folders under %s. |
7469 | Converted IIS folders under %s. |
7470 | Invalid parameter passed to FAT to NTFS security conversion routine. |
7471 | Error getting environment variable %s. |
7472 | Security was set on drive %s with success code %d |
7473 | Error %d getting product type. |
7474 | Error converting environment variable %s. |
7475 | Error %d in locating entry point %s in %s while processing %s. |
7476 | Error %d loading %s while processing %s. |
7477 | Error %d opening event %s. |
7478 | Error getting product type from GetVersionEx. |
7479 | Error %d querying LSA to get user rights for user %s. |
7480 | Existing members of the group are not removed, if any, because invalid accounts are found in the undo membership. |
7481 | The volume containing sysvol share has only %d bytes free for policy to use. Please free space (above 5MB) in order for policy notification to continue |
7490 | Error querying LSA anonymous lookup setting. |
7491 | Error setting LSA anonymous lookup setting. |
7492 | Error building LSA anonymous lookup setting security descriptor. |
7493 | Error initializing LSA anonymous lookup setting security descriptor. |
7494 | Error in Authz APIs while configuring LSA anonymous lookup setting. |
7495 | LSA anonymous lookup names setting : existing SD = %s. |
7496 | LSA anonymous lookup names setting : computed SD = %s. |
7497 | Configure LSA anonymous lookup setting. |
7498 | Analyze LSA anonymous lookup setting. |
7500 | Error configuring Administrator account to be disabled/enabled. |
7501 | Error configuring Guest account to be disabled/enabled. |
7502 | Error analyzing Administrator account status. |
7503 | Error analyzing Guest account status. |
7505 | Active Directory cannot resolve %s, which may be a foreign principal that is not allowed in membership. |
7506 | No existing member/memberof is found. |
7507 | One or more new members failed to be added so some existing members are not removed. |
7508 | Error %d querying existing value for the special LanMan setting <%s>. |
7509 | LanMan setting <%s> is ignored because system has a higher value already. |
7510 | Error %d to verify policy synchronization with PDC. |
7511 | Check your local domain controller status. |
7512 | Check your network configuration and/or the primary domain controller status. |
7513 | Check the domain controller group policy template on local DC and on PDC to make sure they are synchronized. |
7514 | There are new pending account policy changes from downlevel APIs. Policy engine ignores account policies for this propagation. |
7515 | Error re-querying pending notifications from the queue. Policy propagation may overwrite changes made by down-level SAM APIs. |
7516 | There are pending SAM domain policy changes from downlevel APIs. Policy engine ignores these policies for this propagation from the re-query. |
7517 | Error resetting E_ScepSamFilterAndPolicyPropExclusion. |
7518 | Error setting E_ScepSamFilterAndPolicyPropExclusion. |
7519 | error removing object from %s, retrying next time. |
7520 | successfully removed object from %s. |
7521 | successfully added object to %s. |
7522 | old memberof tattoo list: %s |
7523 | new memberof tattoo list: %s |
7524 | new memberof tattoo list is empty, deleting. |
7525 | object already member of %s. |
7526 | object is special account or already removed from %s. |
7527 | Legacy audit settings are disabled. Skipped configuration of legacy audit settings. |
7528 | The Administrator account cannot be disabled because it is the last account in the Administrators group. |
7529 | Setting for %s is configured to be ignored. |
17573 | Users |
17600 | Error adding %s. |
17601 | Error adding MemberOf list to group %s. |
17602 | Error adding Members list to group %s. |
17603 | Error adding %s to %s. |
17604 | Error build object. |
17605 | Error building security descriptor for object %s. |
17606 | Cannot find data type for %s. |
17607 | Cannot find keyword %s. |
17608 | Cannot find section by ID %d. |
17609 | Error getting LDAP name of %s. |
17610 | Error creating %s. |
17611 | Error creating %s. |
17612 | Invalid template path %s. |
17613 | %s is not a valid privilege. |
17614 | More objects than allocated (%d). |
17615 | Keyword %s not expected in section %s. |
17616 | Object %s must have 3 fields each line. |
17617 | Error opening %s. |
17618 | Error opening section by ID %d. |
17619 | Error process object %s. |
17620 | Error querying info of %s. |
17621 | Error querying privilege assignment for user %s. |
17622 | Error querying value of %s. |
17623 | Registry value %s must have 2 fields each line. |
17624 | Error setting security on %s. |
17625 | Error writing info for %s. |
COM Classes/Interfaces
There is no type library in this file with COM classes/interfaces information
Exported Functions List
The following functions are exported by this dll:ScesrvInitializeServer | ScesrvTerminateServer |
Imported Functions List
The following functions are imported by this dll:- msvcrt.dll:
_XcptFilter _amsg_exit _except_handler4_common _findclose _initterm _itow_s _snwprintf_s _ultow _vsnwprintf_s _wcsicmp _wcslwr _wcsnicmp _wcsupr _wfindfirst64 _wfindnext64 _wfopen _wsetlocale _wtol fclose free malloc memcmp memcpy memmove memset strcat_s swprintf_s towlower wcscat_s wcschr wcscpy_s wcsncat_s wcsncmp wcsncpy_s wcsnlen wcsrchr wcsstr - RPCRT4.dll:
I_RpcBindingIsClientLocal I_RpcExceptionFilter I_RpcMapWin32Status NdrClientCall4 NdrServerCall2 RpcBindingBind RpcBindingCreateW RpcBindingFree RpcBindingFromStringBindingW RpcImpersonateClient RpcRevertToSelf RpcServerRegisterAuthInfoW RpcServerRegisterIfEx RpcServerUnregisterIfEx RpcServerUseProtseqEpW RpcSsDestroyClientContext RpcStringBindingComposeW RpcStringFreeW - api-ms-win-core-datetime-l1-1-1.dll:
KernelBase!GetDateFormatW KernelBase!GetTimeFormatW - api-ms-win-core-processthreads-l1-1-2.dll:
KernelBase!OpenProcessToken KernelBase!OpenThreadToken kernel32!CreateThread kernel32!GetCurrentProcess kernel32!GetCurrentProcessId kernel32!GetCurrentThread kernel32!GetCurrentThreadId kernel32!SetThreadStackGuarantee kernel32!TerminateProcess ntdll!RtlExitUserThread - api-ms-win-core-file-l1-2-1.dll:
KernelBase!CreateDirectoryW KernelBase!CreateFileW KernelBase!DeleteFileA KernelBase!DeleteFileW KernelBase!FindClose KernelBase!FindFirstFileW KernelBase!FindNextFileW KernelBase!GetDiskFreeSpaceExW KernelBase!GetDriveTypeW KernelBase!GetFileAttributesW KernelBase!GetFileSize KernelBase!GetLogicalDriveStringsW KernelBase!GetVolumeInformationW KernelBase!SetFilePointer KernelBase!WriteFile - api-ms-win-eventing-classicprovider-l1-1-0.dll:
ntdll!EtwGetTraceEnableFlags ntdll!EtwGetTraceEnableLevel ntdll!EtwGetTraceLoggerHandle ntdll!EtwRegisterTraceGuidsW ntdll!EtwTraceMessage ntdll!EtwUnregisterTraceGuids - api-ms-win-core-libraryloader-l1-2-1.dll:
KernelBase!FindResourceW KernelBase!LoadLibraryW - api-ms-win-core-libraryloader-l1-2-0.dll:
KernelBase!FreeLibrary KernelBase!GetProcAddress KernelBase!LoadLibraryExW KernelBase!LoadResource KernelBase!LoadStringW KernelBase!LockResource - api-ms-win-core-sysinfo-l1-2-1.dll:
KernelBase!GetComputerNameExW KernelBase!GetSystemDirectoryW KernelBase!GetSystemInfo KernelBase!GetSystemTimeAsFileTime KernelBase!GetSystemWindowsDirectoryW KernelBase!GetTickCount KernelBase!GetVersionExW - api-ms-win-core-registry-l1-1-0.dll:
KernelBase!RegCloseKey KernelBase!RegCreateKeyExW KernelBase!RegDeleteValueW KernelBase!RegEnumKeyExW KernelBase!RegGetKeySecurity KernelBase!RegOpenCurrentUser KernelBase!RegOpenKeyExA KernelBase!RegOpenKeyExW KernelBase!RegQueryInfoKeyW KernelBase!RegQueryValueExA KernelBase!RegQueryValueExW KernelBase!RegSetKeySecurity KernelBase!RegSetValueExW - api-ms-win-security-base-l1-2-0.dll:
KernelBase!AccessCheck KernelBase!AddAccessAllowedAce KernelBase!AddAccessDeniedAce KernelBase!CheckTokenMembership KernelBase!DuplicateToken KernelBase!DuplicateTokenEx KernelBase!EqualSid KernelBase!GetSecurityDescriptorDacl KernelBase!GetSecurityDescriptorSacl KernelBase!GetSidSubAuthority KernelBase!ImpersonateSelf KernelBase!InitializeSecurityDescriptor KernelBase!IsValidSecurityDescriptor KernelBase!RevertToSelf KernelBase!SetFileSecurityW KernelBase!SetSecurityDescriptorDacl KernelBase!SetSecurityDescriptorSacl - api-ms-win-core-timezone-l1-1-0.dll:
KernelBase!FileTimeToSystemTime - api-ms-win-core-string-l1-1-0.dll:
KernelBase!MultiByteToWideChar - api-ms-win-core-errorhandling-l1-1-1.dll:
KernelBase!GetLastError KernelBase!SetUnhandledExceptionFilter KernelBase!UnhandledExceptionFilter ntdll!RtlRestoreLastWin32Error - api-ms-win-core-heap-l2-1-0.dll:
KernelBase!LocalAlloc KernelBase!LocalFree - api-ms-win-core-handle-l1-1-0.dll:
KernelBase!CloseHandle - api-ms-win-core-processenvironment-l1-2-0.dll:
KernelBase!ExpandEnvironmentStringsW KernelBase!GetEnvironmentVariableW - api-ms-win-core-synch-l1-2-0.dll:
KernelBase!CreateEventW KernelBase!OpenEventW KernelBase!ResetEvent KernelBase!SetEvent KernelBase!Sleep KernelBase!WaitForSingleObjectEx ntdll!RtlDeleteCriticalSection ntdll!RtlEnterCriticalSection ntdll!RtlInitializeCriticalSection ntdll!RtlLeaveCriticalSection ntdll!RtlTryEnterCriticalSection - api-ms-win-core-localization-l1-2-1.dll:
KernelBase!FormatMessageW - api-ms-win-core-file-l2-1-2.dll:
KernelBase!CopyFileW - api-ms-win-core-console-l1-1-0.dll:
KernelBase!GetConsoleOutputCP - api-ms-win-core-profile-l1-1-0.dll:
ntdll!RtlQueryPerformanceCounter - api-ms-win-core-kernel32-legacy-l1-1-1.dll:
kernel32!GetComputerNameW - api-ms-win-core-threadpool-legacy-l1-1-0.dll:
KernelBase!CreateTimerQueueTimer KernelBase!DeleteTimerQueueTimer - api-ms-win-core-string-obsolete-l1-1-0.dll:
kernel32!lstrcmpiW - api-ms-win-core-privateprofile-l1-1-1.dll:
kernel32!GetPrivateProfileIntW kernel32!GetPrivateProfileStringW kernel32!WritePrivateProfileSectionW kernel32!WritePrivateProfileStringW - ntdll.dll:
DbgPrint NtAdjustPrivilegesToken NtOpenFile NtQueryInformationToken NtQuerySecurityObject NtQuerySystemTime NtSetSecurityObject NtTerminateThread RtlAllocateAndInitializeSid RtlAllocateHeap RtlConvertSidToUnicodeString RtlCopySid RtlCreateSecurityDescriptor RtlCreateUnicodeString RtlDeleteSecurityObject RtlDosPathNameToNtPathName_U RtlDuplicateUnicodeString RtlEqualSid RtlFreeAnsiString RtlFreeHeap RtlFreeSid RtlGetAce RtlGetControlSecurityDescriptor RtlGetDaclSecurityDescriptor RtlGetGroupSecurityDescriptor RtlGetNtProductType RtlGetOwnerSecurityDescriptor RtlGetSaclSecurityDescriptor RtlIdentifierAuthoritySid RtlImageNtHeader RtlInitUnicodeString RtlInitializeSid RtlLengthRequiredSid RtlLengthSecurityDescriptor RtlLengthSid RtlMakeSelfRelativeSD RtlMapGenericMask RtlNewSecurityObjectEx RtlNtStatusToDosError RtlQueueWorkItem RtlSetControlSecurityDescriptor RtlSetDaclSecurityDescriptor RtlSetGroupSecurityDescriptor RtlSetOwnerSecurityDescriptor RtlSetSaclSecurityDescriptor RtlSubAuthorityCountSid RtlSubAuthoritySid RtlSystemTimeToLocalTime RtlTimeToSecondsSince1980 RtlTimeToTimeFields RtlUnicodeToMultiByteN RtlUnicodeToMultiByteSize RtlValidSid - api-ms-win-core-memory-l1-1-2.dll:
KernelBase!VirtualAlloc KernelBase!VirtualProtect KernelBase!VirtualQuery - api-ms-win-core-delayload-l1-1-1.dll:
KernelBase!DelayLoadFailureHook KernelBase!ResolveDelayLoadedAPI