SecurityHealthAgent.dll
Description: Windows Security Health Agent
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.29510.1001
Architecture: 64-bit
Operating System: Windows NT
SHA256: 933a266eb16bc28536e08c61824a05c4
File Size: 1.4 MB
Uploaded At: Feb. 17, 2026, 10:28 p.m.
Views: 11
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x56dc0)
- DllGetClassObject (Ordinal: 2, Address: 0x56e00)
- DllMain (Ordinal: 3, Address: 0x56ee0)
- DllRegisterServer (Ordinal: 4, Address: 0x57070)
Imported DLLs & Functions
api-ms-win-core-processthreads-l1-1-0.dll
- OpenProcessToken (Address: 0x1800c9c28)
- OpenThreadToken (Address: 0x1800c9c20)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800c9c50)
- RegCreateKeyExW (Address: 0x1800c9c60)
- RegOpenCurrentUser (Address: 0x1800c9c40)
- RegOpenKeyExW (Address: 0x1800c9c38)
- RegQueryValueExW (Address: 0x1800c9c48)
- RegSetValueExW (Address: 0x1800c9c58)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x1800c9c70)
- RoGetActivationFactory (Address: 0x1800c9c78)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateStringReference (Address: 0x1800c9ca0)
- WindowsDeleteString (Address: 0x1800c9c90)
- WindowsGetStringRawBuffer (Address: 0x1800c9c98)
- WindowsStringHasEmbeddedNull (Address: 0x1800c9c88)
api-ms-win-crt-convert-l1-1-0.dll
- _i64toa_s (Address: 0x1800c9ce8)
- _i64tow_s (Address: 0x1800c9cf0)
- _ui64toa_s (Address: 0x1800c9ce0)
- _ui64tow_s (Address: 0x1800c9cd0)
- _wcstod_l (Address: 0x1800c9cd8)
- _wtoi (Address: 0x1800c9cc0)
- strtod (Address: 0x1800c9cb8)
- strtof (Address: 0x1800c9cc8)
- wcstol (Address: 0x1800c9cb0)
api-ms-win-crt-heap-l1-1-0.dll
- _callnewh (Address: 0x1800c9d00)
- _calloc_base (Address: 0x1800c9d10)
- calloc (Address: 0x1800c9d20)
- free (Address: 0x1800c9d18)
- malloc (Address: 0x1800c9d08)
api-ms-win-crt-locale-l1-1-0.dll
- ___lc_codepage_func (Address: 0x1800c9d40)
- ___lc_locale_name_func (Address: 0x1800c9d38)
- ___mb_cur_max_func (Address: 0x1800c9d30)
- __pctype_func (Address: 0x1800c9d78)
- _create_locale (Address: 0x1800c9d70)
- _free_locale (Address: 0x1800c9d68)
- _lock_locales (Address: 0x1800c9d50)
- _unlock_locales (Address: 0x1800c9d60)
- localeconv (Address: 0x1800c9d58)
- setlocale (Address: 0x1800c9d48)
api-ms-win-crt-math-l1-1-0.dll
- frexp (Address: 0x1800c9d88)
api-ms-win-crt-private-l1-1-0.dll
- __AdjustPointer (Address: 0x1800c9df0)
- __C_specific_handler (Address: 0x1800c9db0)
- __current_exception (Address: 0x1800c9da0)
- __current_exception_context (Address: 0x1800c9e18)
- __CxxFrameHandler3 (Address: 0x1800c9db8)
- __CxxFrameHandler4 (Address: 0x1800c9dd0)
- __std_exception_copy (Address: 0x1800c9de0)
- __std_exception_destroy (Address: 0x1800c9e20)
- __std_terminate (Address: 0x1800c9e10)
- __std_type_info_destroy_list (Address: 0x1800c9dc0)
- __uncaught_exception (Address: 0x1800c9d98)
- _CxxThrowException (Address: 0x1800c9dc8)
- _purecall (Address: 0x1800c9de8)
- memchr (Address: 0x1800c9dd8)
- memcmp (Address: 0x1800c9e08)
- memcpy (Address: 0x1800c9df8)
- memmove (Address: 0x1800c9e00)
- wcsrchr (Address: 0x1800c9da8)
api-ms-win-crt-runtime-l1-1-0.dll
- _cexit (Address: 0x1800c9e78)
- _configure_narrow_argv (Address: 0x1800c9e48)
- _crt_atexit (Address: 0x1800c9e70)
- _errno (Address: 0x1800c9e98)
- _execute_onexit_table (Address: 0x1800c9e68)
- _initialize_narrow_environment (Address: 0x1800c9e50)
- _initialize_onexit_table (Address: 0x1800c9e58)
- _initterm (Address: 0x1800c9e88)
- _initterm_e (Address: 0x1800c9e30)
- _invalid_parameter_noinfo (Address: 0x1800c9ea0)
- _invoke_watson (Address: 0x1800c9e90)
- _register_onexit_function (Address: 0x1800c9e60)
- _seh_filter_dll (Address: 0x1800c9e38)
- abort (Address: 0x1800c9e40)
- terminate (Address: 0x1800c9e80)
api-ms-win-crt-stdio-l1-1-0.dll
- __stdio_common_vsnwprintf_s (Address: 0x1800c9ec0)
- __stdio_common_vsprintf (Address: 0x1800c9ec8)
- __stdio_common_vsprintf_s (Address: 0x1800c9eb8)
- __stdio_common_vswprintf (Address: 0x1800c9eb0)
- __stdio_common_vswprintf_s (Address: 0x1800c9ed0)
api-ms-win-crt-string-l1-1-0.dll
- _wcsdup (Address: 0x1800c9f08)
- _wcsicmp (Address: 0x1800c9f18)
- _wcsnicmp (Address: 0x1800c9f40)
- isalpha (Address: 0x1800c9f50)
- isdigit (Address: 0x1800c9f58)
- isspace (Address: 0x1800c9ef0)
- iswspace (Address: 0x1800c9f20)
- memset (Address: 0x1800c9ee0)
- strcspn (Address: 0x1800c9f00)
- strlen (Address: 0x1800c9f28)
- strnlen (Address: 0x1800c9f48)
- tolower (Address: 0x1800c9ee8)
- towlower (Address: 0x1800c9f38)
- wcscmp (Address: 0x1800c9f10)
- wcslen (Address: 0x1800c9f30)
- wcsnlen (Address: 0x1800c9ef8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x1800c9f90)
- GetTraceEnableLevel (Address: 0x1800c9f80)
- GetTraceLoggerHandle (Address: 0x1800c9f70)
- RegisterTraceGuidsW (Address: 0x1800c9f88)
- TraceMessage (Address: 0x1800c9f68)
- UnregisterTraceGuids (Address: 0x1800c9f78)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x1800c9fa0)
- EventSetInformation (Address: 0x1800c9fb0)
- EventUnregister (Address: 0x1800c9fa8)
- EventWriteTransfer (Address: 0x1800c9fb8)
api-ms-win-security-base-l1-1-0.dll
- AccessCheck (Address: 0x1800c9fd8)
- AdjustTokenPrivileges (Address: 0x1800c9ff8)
- AllocateAndInitializeSid (Address: 0x1800ca008)
- CheckTokenMembership (Address: 0x1800c9fe8)
- CopySid (Address: 0x1800ca030)
- CreateWellKnownSid (Address: 0x1800c9fd0)
- DuplicateToken (Address: 0x1800ca000)
- FreeSid (Address: 0x1800ca028)
- GetLengthSid (Address: 0x1800c9ff0)
- GetSecurityDescriptorDacl (Address: 0x1800c9fe0)
- GetSecurityDescriptorOwner (Address: 0x1800c9fc8)
- GetTokenInformation (Address: 0x1800ca018)
- ImpersonateLoggedOnUser (Address: 0x1800ca010)
- InitializeAcl (Address: 0x1800ca038)
- RevertToSelf (Address: 0x1800ca020)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x1800ca048)
api-ms-win-security-provider-l1-1-0.dll
- GetNamedSecurityInfoW (Address: 0x1800ca058)
- SetEntriesInAclW (Address: 0x1800ca068)
- SetNamedSecurityInfoW (Address: 0x1800ca060)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1800ca088)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800ca078)
- ConvertStringSidToSidW (Address: 0x1800ca080)
api-ms-win-shcore-path-l1-1-0.dll
- (Address: 0x1800ca098)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1800ca0d0)
- BCryptCreateHash (Address: 0x1800ca0b8)
- BCryptDestroyHash (Address: 0x1800ca0d8)
- BCryptFinishHash (Address: 0x1800ca0b0)
- BCryptGetProperty (Address: 0x1800ca0c8)
- BCryptHashData (Address: 0x1800ca0a8)
- BCryptOpenAlgorithmProvider (Address: 0x1800ca0c0)
CRYPT32.dll
- CertFreeCertificateChain (Address: 0x1800c9760)
- CertFreeCertificateContext (Address: 0x1800c9748)
- CertGetCertificateChain (Address: 0x1800c9740)
- CertVerifyCertificateChainPolicy (Address: 0x1800c9758)
- CryptUnprotectMemory (Address: 0x1800c9750)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x1800c98c0)
- AcquireSRWLockShared (Address: 0x1800c9910)
- CloseHandle (Address: 0x1800c98d8)
- CloseThreadpoolTimer (Address: 0x1800c98b8)
- CloseThreadpoolWork (Address: 0x1800c9798)
- CreateEventExW (Address: 0x1800c9990)
- CreateEventW (Address: 0x1800c97d0)
- CreateFileW (Address: 0x1800c97e8)
- CreateMutexExW (Address: 0x1800c9908)
- CreateSemaphoreExW (Address: 0x1800c9838)
- CreateSemaphoreW (Address: 0x1800c97c0)
- CreateThreadpoolTimer (Address: 0x1800c98f0)
- CreateThreadpoolWork (Address: 0x1800c97a8)
- DebugBreak (Address: 0x1800c9940)
- DecodePointer (Address: 0x1800c99d0)
- DeleteCriticalSection (Address: 0x1800c9918)
- DisableThreadLibraryCalls (Address: 0x1800c9950)
- EncodePointer (Address: 0x1800c99c8)
- EnterCriticalSection (Address: 0x1800c9850)
- FindResourceW (Address: 0x1800c9808)
- FormatMessageA (Address: 0x1800c99a0)
- FormatMessageW (Address: 0x1800c9898)
- FreeLibrary (Address: 0x1800c97f0)
- GetCurrentProcess (Address: 0x1800c9a08)
- GetCurrentProcessId (Address: 0x1800c9920)
- GetCurrentThread (Address: 0x1800c9770)
- GetCurrentThreadId (Address: 0x1800c9888)
- GetFileAttributesW (Address: 0x1800c97e0)
- GetFinalPathNameByHandleW (Address: 0x1800c9978)
- GetLastError (Address: 0x1800c98a0)
- GetLocaleInfoEx (Address: 0x1800c99c0)
- GetModuleFileNameA (Address: 0x1800c9830)
- GetModuleFileNameW (Address: 0x1800c97f8)
- GetModuleHandleA (Address: 0x1800c9790)
- GetModuleHandleExW (Address: 0x1800c9860)
- GetModuleHandleW (Address: 0x1800c9930)
- GetPackagesByPackageFamily (Address: 0x1800c9980)
- GetProcAddress (Address: 0x1800c9900)
- GetProcessHeap (Address: 0x1800c9928)
- GetStringTypeW (Address: 0x1800c99b0)
- GetSystemDirectoryW (Address: 0x1800c97d8)
- GetSystemTimeAsFileTime (Address: 0x1800c9960)
- GlobalFree (Address: 0x1800c9788)
- HeapAlloc (Address: 0x1800c98f8)
- HeapFree (Address: 0x1800c9840)
- InitializeCriticalSection (Address: 0x1800c9820)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800c97b8)
- InitializeCriticalSectionEx (Address: 0x1800c9870)
- InitializeSListHead (Address: 0x1800c9a28)
- InitOnceBeginInitialize (Address: 0x1800c9780)
- InitOnceComplete (Address: 0x1800c9778)
- IsDebuggerPresent (Address: 0x1800c9948)
- IsProcessorFeaturePresent (Address: 0x1800c9a18)
- LCMapStringEx (Address: 0x1800c99d8)
- LeaveCriticalSection (Address: 0x1800c9868)
- LoadLibraryExW (Address: 0x1800c9800)
- LoadResource (Address: 0x1800c9810)
- LocalFree (Address: 0x1800c9958)
- LockResource (Address: 0x1800c9818)
- lstrcmpW (Address: 0x1800c9970)
- MultiByteToWideChar (Address: 0x1800c99a8)
- OpenSemaphoreW (Address: 0x1800c98d0)
- OutputDebugStringW (Address: 0x1800c98b0)
- PackageIdFromFullName (Address: 0x1800c9988)
- ProcessIdToSessionId (Address: 0x1800c9a38)
- QueryPerformanceCounter (Address: 0x1800c9a20)
- RaiseException (Address: 0x1800c9968)
- ReleaseMutex (Address: 0x1800c9890)
- ReleaseSemaphore (Address: 0x1800c9858)
- ReleaseSRWLockExclusive (Address: 0x1800c98a8)
- ReleaseSRWLockShared (Address: 0x1800c98e8)
- ResetEvent (Address: 0x1800c97c8)
- RtlCaptureContext (Address: 0x1800c99e0)
- RtlLookupFunctionEntry (Address: 0x1800c99e8)
- RtlPcToFileHeader (Address: 0x1800c99b8)
- RtlVirtualUnwind (Address: 0x1800c99f0)
- SetEvent (Address: 0x1800c9998)
- SetLastError (Address: 0x1800c9848)
- SetThreadpoolTimer (Address: 0x1800c98e0)
- SetUnhandledExceptionFilter (Address: 0x1800c9a00)
- SizeofResource (Address: 0x1800c9a30)
- Sleep (Address: 0x1800c97b0)
- SubmitThreadpoolWork (Address: 0x1800c97a0)
- TerminateProcess (Address: 0x1800c9a10)
- UnhandledExceptionFilter (Address: 0x1800c99f8)
- VerifyVersionInfoW (Address: 0x1800c9828)
- WaitForSingleObject (Address: 0x1800c9880)
- WaitForSingleObjectEx (Address: 0x1800c98c8)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800c9878)
- WideCharToMultiByte (Address: 0x1800c9938)
NETAPI32.dll
- NetGetAadJoinInformation (Address: 0x1800c9a48)
netutils.dll
- NetApiBufferFree (Address: 0x1800ca0e8)
ntdll.dll
- RtlGetDeviceFamilyInfoEnum (Address: 0x1800ca110)
- RtlGetPersistedStateLocation (Address: 0x1800ca100)
- RtlNtStatusToDosError (Address: 0x1800ca0f8)
- VerSetConditionMask (Address: 0x1800ca108)
ole32.dll
- CoCreateFreeThreadedMarshaler (Address: 0x1800ca168)
- CoCreateInstance (Address: 0x1800ca210)
- CoGetObject (Address: 0x1800ca1c8)
- CoImpersonateClient (Address: 0x1800ca200)
- CoRevertToSelf (Address: 0x1800ca208)
- CoSetProxyBlanket (Address: 0x1800ca1b0)
- CoTaskMemAlloc (Address: 0x1800ca1b8)
- CoTaskMemFree (Address: 0x1800ca170)
- CoWaitForMultipleHandles (Address: 0x1800ca1a8)
- HWND_UserFree (Address: 0x1800ca180)
- HWND_UserFree64 (Address: 0x1800ca160)
- HWND_UserMarshal (Address: 0x1800ca130)
- HWND_UserMarshal64 (Address: 0x1800ca138)
- HWND_UserSize (Address: 0x1800ca190)
- HWND_UserSize64 (Address: 0x1800ca148)
- HWND_UserUnmarshal (Address: 0x1800ca188)
- HWND_UserUnmarshal64 (Address: 0x1800ca1f0)
- ObjectStublessClient10 (Address: 0x1800ca1e8)
- ObjectStublessClient11 (Address: 0x1800ca1d0)
- ObjectStublessClient12 (Address: 0x1800ca1a0)
- ObjectStublessClient13 (Address: 0x1800ca120)
- ObjectStublessClient14 (Address: 0x1800ca198)
- ObjectStublessClient15 (Address: 0x1800ca178)
- ObjectStublessClient3 (Address: 0x1800ca1d8)
- ObjectStublessClient4 (Address: 0x1800ca1e0)
- ObjectStublessClient5 (Address: 0x1800ca128)
- ObjectStublessClient6 (Address: 0x1800ca140)
- ObjectStublessClient7 (Address: 0x1800ca158)
- ObjectStublessClient8 (Address: 0x1800ca150)
- ObjectStublessClient9 (Address: 0x1800ca218)
- StringFromCLSID (Address: 0x1800ca1f8)
- StringFromGUID2 (Address: 0x1800ca1c0)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x1800c9ad0)
- CStdStubBuffer_Connect (Address: 0x1800c9a88)
- CStdStubBuffer_CountRefs (Address: 0x1800c9a98)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800c9ad8)
- CStdStubBuffer_DebugServerRelease (Address: 0x1800c9a68)
- CStdStubBuffer_Disconnect (Address: 0x1800c9a70)
- CStdStubBuffer_Invoke (Address: 0x1800c9ac0)
- CStdStubBuffer_IsIIDSupported (Address: 0x1800c9ae8)
- CStdStubBuffer_QueryInterface (Address: 0x1800c9a58)
- IUnknown_AddRef_Proxy (Address: 0x1800c9ac8)
- IUnknown_QueryInterface_Proxy (Address: 0x1800c9a78)
- IUnknown_Release_Proxy (Address: 0x1800c9a80)
- NdrCStdStubBuffer_Release (Address: 0x1800c9ab8)
- NdrDllCanUnloadNow (Address: 0x1800c9aa0)
- NdrDllGetClassObject (Address: 0x1800c9a90)
- NdrDllRegisterProxy (Address: 0x1800c9ab0)
- NdrOleAllocate (Address: 0x1800c9a60)
- NdrOleFree (Address: 0x1800c9ae0)
- UuidCreate (Address: 0x1800c9aa8)
SHELL32.dll
- ShellExecuteW (Address: 0x1800c9af8)
USER32.dll
- GetDesktopWindow (Address: 0x1800c9b10)
- GetForegroundWindow (Address: 0x1800c9b18)
- GetWindow (Address: 0x1800c9b08)
WINHTTP.dll
- WinHttpAddRequestHeaders (Address: 0x1800c9bc0)
- WinHttpCloseHandle (Address: 0x1800c9b48)
- WinHttpConnect (Address: 0x1800c9b58)
- WinHttpGetDefaultProxyConfiguration (Address: 0x1800c9b38)
- WinHttpGetIEProxyConfigForCurrentUser (Address: 0x1800c9b68)
- WinHttpGetProxyForUrl (Address: 0x1800c9b78)
- WinHttpOpen (Address: 0x1800c9b40)
- WinHttpOpenRequest (Address: 0x1800c9b90)
- WinHttpQueryAuthSchemes (Address: 0x1800c9ba8)
- WinHttpQueryDataAvailable (Address: 0x1800c9b28)
- WinHttpQueryHeaders (Address: 0x1800c9b80)
- WinHttpQueryOption (Address: 0x1800c9b50)
- WinHttpReadData (Address: 0x1800c9b98)
- WinHttpReceiveResponse (Address: 0x1800c9ba0)
- WinHttpSendRequest (Address: 0x1800c9bb8)
- WinHttpSetCredentials (Address: 0x1800c9bb0)
- WinHttpSetOption (Address: 0x1800c9b70)
- WinHttpSetStatusCallback (Address: 0x1800c9b60)
- WinHttpSetTimeouts (Address: 0x1800c9b88)
- WinHttpWriteData (Address: 0x1800c9b30)
WINTRUST.dll
- CryptCATAdminAcquireContext (Address: 0x1800c9bd0)
- CryptCATAdminCalcHashFromFileHandle (Address: 0x1800c9bd8)
- CryptCATAdminEnumCatalogFromHash (Address: 0x1800c9bf8)
- CryptCATAdminReleaseCatalogContext (Address: 0x1800c9be8)
- CryptCATAdminReleaseContext (Address: 0x1800c9bf0)
- CryptCATCatalogInfoFromContext (Address: 0x1800c9c10)
- WinVerifyTrust (Address: 0x1800c9c00)
- WTHelperGetProvSignerFromChain (Address: 0x1800c9be0)
- WTHelperProvDataFromStateData (Address: 0x1800c9c08)