fhsettingsprovider.dll

Description: File History Backup & Restore Settings Provider

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5848

Architecture: 64-bit

Operating System: Windows NT

SHA256: d2c9a21ba5441b519f881ec0746e244f

File Size: 442.5 KB

Uploaded At: Dec. 1, 2025, 7:28 a.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x41e0)
  • DllGetActivationFactory (Ordinal: 2, Address: 0x3f10)
  • DllGetClassObject (Ordinal: 3, Address: 0x40f0)

Imported DLLs & Functions

api-ms-win-core-crt-l1-1-0.dll
  • _wcsnicmp (Address: 0x180055f50)
  • memmove_s (Address: 0x180055f48)
  • towupper (Address: 0x180055f58)
  • wcscspn (Address: 0x180055f38)
  • wcsncmp (Address: 0x180055f40)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180055f68)
  • IsDebuggerPresent (Address: 0x180055f78)
  • OutputDebugStringW (Address: 0x180055f70)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180055f88)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180055fa0)
  • RaiseException (Address: 0x180055f98)
  • SetLastError (Address: 0x180055fa8)
  • SetUnhandledExceptionFilter (Address: 0x180055fb0)
  • UnhandledExceptionFilter (Address: 0x180055fb8)
api-ms-win-core-file-l1-1-0.dll
  • GetDiskFreeSpaceExW (Address: 0x180055fd0)
  • GetDriveTypeW (Address: 0x180055fc8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180055fe0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180055ff0)
  • HeapAlloc (Address: 0x180055ff8)
  • HeapFree (Address: 0x180056000)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x180056010)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180056028)
  • FindResourceExW (Address: 0x180056030)
  • GetModuleFileNameA (Address: 0x180056038)
  • GetModuleHandleExW (Address: 0x180056058)
  • GetModuleHandleW (Address: 0x180056048)
  • GetProcAddress (Address: 0x180056040)
  • LoadResource (Address: 0x180056020)
  • LockResource (Address: 0x180056050)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180056068)
api-ms-win-core-path-l1-1-0.dll
  • PathCchRemoveBackslash (Address: 0x180056078)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180056098)
  • GetCurrentProcessId (Address: 0x1800560b0)
  • GetCurrentThreadId (Address: 0x1800560a0)
  • GetExitCodeProcess (Address: 0x180056088)
  • OpenProcessToken (Address: 0x1800560a8)
  • TerminateProcess (Address: 0x180056090)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x1800560c0)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800560d0)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800560f0)
  • RtlLookupFunctionEntry (Address: 0x1800560e8)
  • RtlVirtualUnwind (Address: 0x1800560e0)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFindFileNameW (Address: 0x180056110)
  • PathRemoveBackslashW (Address: 0x180056100)
  • PathRemoveFileSpecW (Address: 0x180056108)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x180056128)
  • CompareStringW (Address: 0x180056120)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180056180)
  • AcquireSRWLockShared (Address: 0x1800561a0)
  • CreateMutexExW (Address: 0x180056148)
  • CreateSemaphoreExW (Address: 0x180056168)
  • DeleteCriticalSection (Address: 0x180056198)
  • EnterCriticalSection (Address: 0x180056178)
  • InitializeCriticalSectionEx (Address: 0x180056190)
  • InitializeSRWLock (Address: 0x1800561a8)
  • LeaveCriticalSection (Address: 0x180056170)
  • OpenSemaphoreW (Address: 0x180056140)
  • ReleaseMutex (Address: 0x180056150)
  • ReleaseSemaphore (Address: 0x180056160)
  • ReleaseSRWLockExclusive (Address: 0x180056188)
  • ReleaseSRWLockShared (Address: 0x1800561b0)
  • WaitForSingleObject (Address: 0x180056158)
  • WaitForSingleObjectEx (Address: 0x180056138)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x1800561c8)
  • Sleep (Address: 0x1800561c0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1800561d8)
  • GetTickCount (Address: 0x1800561e0)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x1800561f8)
  • EncodePointer (Address: 0x1800561f0)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180056208)
fhsvcctl.dll
  • FhServiceBlockBackup (Address: 0x180056228)
  • FhServiceClosePipe (Address: 0x180056220)
  • FhServiceOpenPipe (Address: 0x180056230)
  • FhServiceStopBackup (Address: 0x180056218)
KERNELBASE.dll
  • ResolveDelayLoadedAPI (Address: 0x180055ee0)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800562b8)
  • __CxxFrameHandler3 (Address: 0x180056268)
  • __dllonexit (Address: 0x180056260)
  • _amsg_exit (Address: 0x180056240)
  • _callnewh (Address: 0x180056310)
  • _CxxThrowException (Address: 0x180056330)
  • _get_errno (Address: 0x1800562f8)
  • _initterm (Address: 0x1800562b0)
  • _lock (Address: 0x1800562a8)
  • _onexit (Address: 0x180056258)
  • _purecall (Address: 0x180056280)
  • _set_errno (Address: 0x1800562f0)
  • _unlock (Address: 0x180056270)
  • _vsnprintf_s (Address: 0x180056290)
  • _vsnwprintf (Address: 0x1800562e8)
  • _XcptFilter (Address: 0x1800562c0)
  • ??_V@YAXPEAX@Z (Address: 0x180056288)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180056318)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180056320)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180056298)
  • ??0exception@@QEAA@XZ (Address: 0x1800562a0)
  • ??1exception@@UEAA@XZ (Address: 0x1800562d0)
  • ??1type_info@@UEAA@XZ (Address: 0x180056248)
  • ??3@YAXPEAX@Z (Address: 0x1800562d8)
  • ?terminate@@YAXXZ (Address: 0x1800562c8)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180056328)
  • free (Address: 0x180056278)
  • iswalpha (Address: 0x180056308)
  • malloc (Address: 0x180056348)
  • memcmp (Address: 0x180056250)
  • memcpy (Address: 0x180056338)
  • memcpy_s (Address: 0x1800562e0)
  • memmove (Address: 0x180056340)
  • memset (Address: 0x180056350)
  • realloc (Address: 0x180056300)
ntdll.dll
  • NtQueryWnfStateData (Address: 0x180056368)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x180056370)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x180056360)
OLEAUT32.dll
  • SysAllocString (Address: 0x180055ef8)
  • SysAllocStringLen (Address: 0x180055f00)
  • SysFreeString (Address: 0x180055ef0)
  • SysStringLen (Address: 0x180055f08)
SHCORE.dll
  • SHRegGetValueW (Address: 0x180055f18)
  • SHTaskPoolAllowThreadReuse (Address: 0x180055f28)
  • SHTaskPoolQueueTask (Address: 0x180055f20)