efslsaext.dll

Description: LSA extension for EFS

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6328

Architecture: 64-bit

Operating System: Windows NT

SHA256: 0b4ae104fade167f02344ed0b6b20e65

File Size: 85.5 KB

Uploaded At: Dec. 1, 2025, 7:27 a.m.

Views: 6

Exported Functions

  • InitializeLsaExtension (Ordinal: 1, Address: 0x1cb0)

Imported DLLs & Functions

api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800102e0)
  • IsDebuggerPresent (Address: 0x1800102e8)
  • OutputDebugStringW (Address: 0x1800102d8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800102f8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180010308)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180010328)
  • SetLastError (Address: 0x180010330)
  • SetUnhandledExceptionFilter (Address: 0x180010320)
  • UnhandledExceptionFilter (Address: 0x180010318)
api-ms-win-core-featurestaging-l1-1-0.dll
  • RecordFeatureUsage (Address: 0x180010348)
  • SubscribeFeatureStateChangeNotification (Address: 0x180010350)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x180010340)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x180010390)
  • DeleteFileW (Address: 0x180010398)
  • GetDriveTypeW (Address: 0x180010370)
  • GetFileAttributesW (Address: 0x180010388)
  • GetFinalPathNameByHandleW (Address: 0x180010368)
  • GetVolumeInformationByHandleW (Address: 0x180010360)
  • GetVolumePathNameW (Address: 0x180010378)
  • RemoveDirectoryW (Address: 0x180010380)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800103a8)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1800103c0)
  • HeapAlloc (Address: 0x1800103c8)
  • HeapFree (Address: 0x1800103b8)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1800103e0)
  • LocalFree (Address: 0x1800103d8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x1800103f0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x180010418)
  • GetModuleHandleExW (Address: 0x180010400)
  • GetModuleHandleW (Address: 0x180010410)
  • GetProcAddress (Address: 0x180010408)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180010428)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x180010440)
  • VirtualFree (Address: 0x180010438)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180010458)
  • GetCurrentProcessId (Address: 0x180010480)
  • GetCurrentThread (Address: 0x180010460)
  • GetCurrentThreadId (Address: 0x180010470)
  • OpenThreadToken (Address: 0x180010450)
  • SetThreadToken (Address: 0x180010478)
  • TerminateProcess (Address: 0x180010468)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180010490)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800104a8)
  • RtlLookupFunctionEntry (Address: 0x1800104b0)
  • RtlVirtualUnwind (Address: 0x1800104a0)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringW (Address: 0x1800104c0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180010510)
  • CreateMutexExW (Address: 0x1800104d0)
  • CreateSemaphoreExW (Address: 0x180010518)
  • OpenSemaphoreW (Address: 0x1800104d8)
  • ReleaseMutex (Address: 0x1800104f8)
  • ReleaseSemaphore (Address: 0x180010508)
  • ReleaseSRWLockExclusive (Address: 0x1800104f0)
  • SleepEx (Address: 0x1800104e0)
  • WaitForSingleObject (Address: 0x180010500)
  • WaitForSingleObjectEx (Address: 0x1800104e8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180010528)
  • InitOnceComplete (Address: 0x180010538)
  • Sleep (Address: 0x180010530)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x180010550)
  • GetSystemTimeAsFileTime (Address: 0x180010548)
  • GetTickCount (Address: 0x180010558)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x180010568)
  • EventRegister (Address: 0x180010578)
  • EventSetInformation (Address: 0x180010588)
  • EventUnregister (Address: 0x180010580)
  • EventWriteTransfer (Address: 0x180010570)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x1800105a0)
  • RevertToSelf (Address: 0x180010598)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x1800105b8)
  • OpenSCManagerW (Address: 0x1800105c8)
  • OpenServiceW (Address: 0x1800105c0)
  • StartServiceW (Address: 0x1800105b0)
api-ms-win-service-management-l2-1-0.dll
  • NotifyServiceStatusChangeW (Address: 0x1800105e0)
  • QueryServiceStatusEx (Address: 0x1800105d8)
msvcrt.dll
  • __C_specific_handler (Address: 0x180010638)
  • __dllonexit (Address: 0x180010618)
  • _amsg_exit (Address: 0x180010660)
  • _initterm (Address: 0x180010640)
  • _lock (Address: 0x180010630)
  • _onexit (Address: 0x180010610)
  • _unlock (Address: 0x180010620)
  • _vsnwprintf (Address: 0x180010668)
  • _wcsicmp (Address: 0x1800105f0)
  • _wcsnicmp (Address: 0x180010680)
  • _XcptFilter (Address: 0x180010650)
  • ??3@YAXPEAX@Z (Address: 0x180010678)
  • free (Address: 0x180010658)
  • malloc (Address: 0x180010648)
  • memcmp (Address: 0x180010628)
  • memcpy (Address: 0x180010608)
  • memcpy_s (Address: 0x180010670)
  • memmove (Address: 0x180010600)
  • memset (Address: 0x180010688)
  • toupper (Address: 0x1800105f8)
netutils.dll
  • NetApiBufferFree (Address: 0x180010698)
ntdll.dll
  • EtwEventEnabled (Address: 0x180010720)
  • EtwEventRegister (Address: 0x180010700)
  • EtwEventUnregister (Address: 0x1800106f8)
  • EtwEventWrite (Address: 0x180010738)
  • NtClose (Address: 0x1800106d8)
  • NtCreateFile (Address: 0x1800106e8)
  • NtFsControlFile (Address: 0x1800106c0)
  • NtQueryInformationFile (Address: 0x1800106e0)
  • NtQueryVolumeInformationFile (Address: 0x180010718)
  • NtReadFile (Address: 0x1800106b8)
  • NtWriteFile (Address: 0x1800106b0)
  • RtlAllocateHeap (Address: 0x180010708)
  • RtlDosPathNameToNtPathName_U (Address: 0x1800106c8)
  • RtlFreeHeap (Address: 0x1800106f0)
  • RtlInitUnicodeString (Address: 0x1800106d0)
  • RtlLengthSid (Address: 0x180010728)
  • RtlNtStatusToDosError (Address: 0x180010710)
  • RtlQueryPackageClaims (Address: 0x1800106a8)
  • RtlValidSid (Address: 0x180010730)
RPCRT4.dll
  • I_RpcBindingIsClientLocal (Address: 0x1800102b8)
  • I_RpcExceptionFilter (Address: 0x180010270)
  • NdrClientCall3 (Address: 0x180010288)
  • NdrServerCall2 (Address: 0x1800102b0)
  • NdrServerCallAll (Address: 0x1800102c8)
  • RpcBindingFree (Address: 0x1800102a8)
  • RpcBindingFromStringBindingW (Address: 0x180010250)
  • RpcBindingInqAuthClientW (Address: 0x180010268)
  • RpcBindingSetAuthInfoW (Address: 0x180010248)
  • RpcBindingToStringBindingW (Address: 0x1800102c0)
  • RpcImpersonateClient (Address: 0x180010290)
  • RpcRaiseException (Address: 0x180010260)
  • RpcRevertToSelf (Address: 0x180010278)
  • RpcServerRegisterIfEx (Address: 0x180010280)
  • RpcStringBindingComposeW (Address: 0x180010258)
  • RpcStringBindingParseW (Address: 0x180010298)
  • RpcStringFreeW (Address: 0x1800102a0)