SecurityHealthAgent.dll

Description: Windows Security Health Agent

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.29510.1001

Architecture: 64-bit

Operating System: Windows NT

SHA256: 933a266eb16bc28536e08c61824a05c4

File Size: 1.4 MB

Uploaded At: Feb. 17, 2026, 10:28 p.m.

Views: 11

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x56dc0)
  • DllGetClassObject (Ordinal: 2, Address: 0x56e00)
  • DllMain (Ordinal: 3, Address: 0x56ee0)
  • DllRegisterServer (Ordinal: 4, Address: 0x57070)

Imported DLLs & Functions

api-ms-win-core-processthreads-l1-1-0.dll
  • OpenProcessToken (Address: 0x1800c9c28)
  • OpenThreadToken (Address: 0x1800c9c20)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800c9c50)
  • RegCreateKeyExW (Address: 0x1800c9c60)
  • RegOpenCurrentUser (Address: 0x1800c9c40)
  • RegOpenKeyExW (Address: 0x1800c9c38)
  • RegQueryValueExW (Address: 0x1800c9c48)
  • RegSetValueExW (Address: 0x1800c9c58)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1800c9c70)
  • RoGetActivationFactory (Address: 0x1800c9c78)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x1800c9ca0)
  • WindowsDeleteString (Address: 0x1800c9c90)
  • WindowsGetStringRawBuffer (Address: 0x1800c9c98)
  • WindowsStringHasEmbeddedNull (Address: 0x1800c9c88)
api-ms-win-crt-convert-l1-1-0.dll
  • _i64toa_s (Address: 0x1800c9ce8)
  • _i64tow_s (Address: 0x1800c9cf0)
  • _ui64toa_s (Address: 0x1800c9ce0)
  • _ui64tow_s (Address: 0x1800c9cd0)
  • _wcstod_l (Address: 0x1800c9cd8)
  • _wtoi (Address: 0x1800c9cc0)
  • strtod (Address: 0x1800c9cb8)
  • strtof (Address: 0x1800c9cc8)
  • wcstol (Address: 0x1800c9cb0)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x1800c9d00)
  • _calloc_base (Address: 0x1800c9d10)
  • calloc (Address: 0x1800c9d20)
  • free (Address: 0x1800c9d18)
  • malloc (Address: 0x1800c9d08)
api-ms-win-crt-locale-l1-1-0.dll
  • ___lc_codepage_func (Address: 0x1800c9d40)
  • ___lc_locale_name_func (Address: 0x1800c9d38)
  • ___mb_cur_max_func (Address: 0x1800c9d30)
  • __pctype_func (Address: 0x1800c9d78)
  • _create_locale (Address: 0x1800c9d70)
  • _free_locale (Address: 0x1800c9d68)
  • _lock_locales (Address: 0x1800c9d50)
  • _unlock_locales (Address: 0x1800c9d60)
  • localeconv (Address: 0x1800c9d58)
  • setlocale (Address: 0x1800c9d48)
api-ms-win-crt-math-l1-1-0.dll
  • frexp (Address: 0x1800c9d88)
api-ms-win-crt-private-l1-1-0.dll
  • __AdjustPointer (Address: 0x1800c9df0)
  • __C_specific_handler (Address: 0x1800c9db0)
  • __current_exception (Address: 0x1800c9da0)
  • __current_exception_context (Address: 0x1800c9e18)
  • __CxxFrameHandler3 (Address: 0x1800c9db8)
  • __CxxFrameHandler4 (Address: 0x1800c9dd0)
  • __std_exception_copy (Address: 0x1800c9de0)
  • __std_exception_destroy (Address: 0x1800c9e20)
  • __std_terminate (Address: 0x1800c9e10)
  • __std_type_info_destroy_list (Address: 0x1800c9dc0)
  • __uncaught_exception (Address: 0x1800c9d98)
  • _CxxThrowException (Address: 0x1800c9dc8)
  • _purecall (Address: 0x1800c9de8)
  • memchr (Address: 0x1800c9dd8)
  • memcmp (Address: 0x1800c9e08)
  • memcpy (Address: 0x1800c9df8)
  • memmove (Address: 0x1800c9e00)
  • wcsrchr (Address: 0x1800c9da8)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x1800c9e78)
  • _configure_narrow_argv (Address: 0x1800c9e48)
  • _crt_atexit (Address: 0x1800c9e70)
  • _errno (Address: 0x1800c9e98)
  • _execute_onexit_table (Address: 0x1800c9e68)
  • _initialize_narrow_environment (Address: 0x1800c9e50)
  • _initialize_onexit_table (Address: 0x1800c9e58)
  • _initterm (Address: 0x1800c9e88)
  • _initterm_e (Address: 0x1800c9e30)
  • _invalid_parameter_noinfo (Address: 0x1800c9ea0)
  • _invoke_watson (Address: 0x1800c9e90)
  • _register_onexit_function (Address: 0x1800c9e60)
  • _seh_filter_dll (Address: 0x1800c9e38)
  • abort (Address: 0x1800c9e40)
  • terminate (Address: 0x1800c9e80)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vsnwprintf_s (Address: 0x1800c9ec0)
  • __stdio_common_vsprintf (Address: 0x1800c9ec8)
  • __stdio_common_vsprintf_s (Address: 0x1800c9eb8)
  • __stdio_common_vswprintf (Address: 0x1800c9eb0)
  • __stdio_common_vswprintf_s (Address: 0x1800c9ed0)
api-ms-win-crt-string-l1-1-0.dll
  • _wcsdup (Address: 0x1800c9f08)
  • _wcsicmp (Address: 0x1800c9f18)
  • _wcsnicmp (Address: 0x1800c9f40)
  • isalpha (Address: 0x1800c9f50)
  • isdigit (Address: 0x1800c9f58)
  • isspace (Address: 0x1800c9ef0)
  • iswspace (Address: 0x1800c9f20)
  • memset (Address: 0x1800c9ee0)
  • strcspn (Address: 0x1800c9f00)
  • strlen (Address: 0x1800c9f28)
  • strnlen (Address: 0x1800c9f48)
  • tolower (Address: 0x1800c9ee8)
  • towlower (Address: 0x1800c9f38)
  • wcscmp (Address: 0x1800c9f10)
  • wcslen (Address: 0x1800c9f30)
  • wcsnlen (Address: 0x1800c9ef8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x1800c9f90)
  • GetTraceEnableLevel (Address: 0x1800c9f80)
  • GetTraceLoggerHandle (Address: 0x1800c9f70)
  • RegisterTraceGuidsW (Address: 0x1800c9f88)
  • TraceMessage (Address: 0x1800c9f68)
  • UnregisterTraceGuids (Address: 0x1800c9f78)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x1800c9fa0)
  • EventSetInformation (Address: 0x1800c9fb0)
  • EventUnregister (Address: 0x1800c9fa8)
  • EventWriteTransfer (Address: 0x1800c9fb8)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheck (Address: 0x1800c9fd8)
  • AdjustTokenPrivileges (Address: 0x1800c9ff8)
  • AllocateAndInitializeSid (Address: 0x1800ca008)
  • CheckTokenMembership (Address: 0x1800c9fe8)
  • CopySid (Address: 0x1800ca030)
  • CreateWellKnownSid (Address: 0x1800c9fd0)
  • DuplicateToken (Address: 0x1800ca000)
  • FreeSid (Address: 0x1800ca028)
  • GetLengthSid (Address: 0x1800c9ff0)
  • GetSecurityDescriptorDacl (Address: 0x1800c9fe0)
  • GetSecurityDescriptorOwner (Address: 0x1800c9fc8)
  • GetTokenInformation (Address: 0x1800ca018)
  • ImpersonateLoggedOnUser (Address: 0x1800ca010)
  • InitializeAcl (Address: 0x1800ca038)
  • RevertToSelf (Address: 0x1800ca020)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x1800ca048)
api-ms-win-security-provider-l1-1-0.dll
  • GetNamedSecurityInfoW (Address: 0x1800ca058)
  • SetEntriesInAclW (Address: 0x1800ca068)
  • SetNamedSecurityInfoW (Address: 0x1800ca060)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x1800ca088)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800ca078)
  • ConvertStringSidToSidW (Address: 0x1800ca080)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x1800ca0d0)
  • BCryptCreateHash (Address: 0x1800ca0b8)
  • BCryptDestroyHash (Address: 0x1800ca0d8)
  • BCryptFinishHash (Address: 0x1800ca0b0)
  • BCryptGetProperty (Address: 0x1800ca0c8)
  • BCryptHashData (Address: 0x1800ca0a8)
  • BCryptOpenAlgorithmProvider (Address: 0x1800ca0c0)
CRYPT32.dll
  • CertFreeCertificateChain (Address: 0x1800c9760)
  • CertFreeCertificateContext (Address: 0x1800c9748)
  • CertGetCertificateChain (Address: 0x1800c9740)
  • CertVerifyCertificateChainPolicy (Address: 0x1800c9758)
  • CryptUnprotectMemory (Address: 0x1800c9750)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1800c98c0)
  • AcquireSRWLockShared (Address: 0x1800c9910)
  • CloseHandle (Address: 0x1800c98d8)
  • CloseThreadpoolTimer (Address: 0x1800c98b8)
  • CloseThreadpoolWork (Address: 0x1800c9798)
  • CreateEventExW (Address: 0x1800c9990)
  • CreateEventW (Address: 0x1800c97d0)
  • CreateFileW (Address: 0x1800c97e8)
  • CreateMutexExW (Address: 0x1800c9908)
  • CreateSemaphoreExW (Address: 0x1800c9838)
  • CreateSemaphoreW (Address: 0x1800c97c0)
  • CreateThreadpoolTimer (Address: 0x1800c98f0)
  • CreateThreadpoolWork (Address: 0x1800c97a8)
  • DebugBreak (Address: 0x1800c9940)
  • DecodePointer (Address: 0x1800c99d0)
  • DeleteCriticalSection (Address: 0x1800c9918)
  • DisableThreadLibraryCalls (Address: 0x1800c9950)
  • EncodePointer (Address: 0x1800c99c8)
  • EnterCriticalSection (Address: 0x1800c9850)
  • FindResourceW (Address: 0x1800c9808)
  • FormatMessageA (Address: 0x1800c99a0)
  • FormatMessageW (Address: 0x1800c9898)
  • FreeLibrary (Address: 0x1800c97f0)
  • GetCurrentProcess (Address: 0x1800c9a08)
  • GetCurrentProcessId (Address: 0x1800c9920)
  • GetCurrentThread (Address: 0x1800c9770)
  • GetCurrentThreadId (Address: 0x1800c9888)
  • GetFileAttributesW (Address: 0x1800c97e0)
  • GetFinalPathNameByHandleW (Address: 0x1800c9978)
  • GetLastError (Address: 0x1800c98a0)
  • GetLocaleInfoEx (Address: 0x1800c99c0)
  • GetModuleFileNameA (Address: 0x1800c9830)
  • GetModuleFileNameW (Address: 0x1800c97f8)
  • GetModuleHandleA (Address: 0x1800c9790)
  • GetModuleHandleExW (Address: 0x1800c9860)
  • GetModuleHandleW (Address: 0x1800c9930)
  • GetPackagesByPackageFamily (Address: 0x1800c9980)
  • GetProcAddress (Address: 0x1800c9900)
  • GetProcessHeap (Address: 0x1800c9928)
  • GetStringTypeW (Address: 0x1800c99b0)
  • GetSystemDirectoryW (Address: 0x1800c97d8)
  • GetSystemTimeAsFileTime (Address: 0x1800c9960)
  • GlobalFree (Address: 0x1800c9788)
  • HeapAlloc (Address: 0x1800c98f8)
  • HeapFree (Address: 0x1800c9840)
  • InitializeCriticalSection (Address: 0x1800c9820)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800c97b8)
  • InitializeCriticalSectionEx (Address: 0x1800c9870)
  • InitializeSListHead (Address: 0x1800c9a28)
  • InitOnceBeginInitialize (Address: 0x1800c9780)
  • InitOnceComplete (Address: 0x1800c9778)
  • IsDebuggerPresent (Address: 0x1800c9948)
  • IsProcessorFeaturePresent (Address: 0x1800c9a18)
  • LCMapStringEx (Address: 0x1800c99d8)
  • LeaveCriticalSection (Address: 0x1800c9868)
  • LoadLibraryExW (Address: 0x1800c9800)
  • LoadResource (Address: 0x1800c9810)
  • LocalFree (Address: 0x1800c9958)
  • LockResource (Address: 0x1800c9818)
  • lstrcmpW (Address: 0x1800c9970)
  • MultiByteToWideChar (Address: 0x1800c99a8)
  • OpenSemaphoreW (Address: 0x1800c98d0)
  • OutputDebugStringW (Address: 0x1800c98b0)
  • PackageIdFromFullName (Address: 0x1800c9988)
  • ProcessIdToSessionId (Address: 0x1800c9a38)
  • QueryPerformanceCounter (Address: 0x1800c9a20)
  • RaiseException (Address: 0x1800c9968)
  • ReleaseMutex (Address: 0x1800c9890)
  • ReleaseSemaphore (Address: 0x1800c9858)
  • ReleaseSRWLockExclusive (Address: 0x1800c98a8)
  • ReleaseSRWLockShared (Address: 0x1800c98e8)
  • ResetEvent (Address: 0x1800c97c8)
  • RtlCaptureContext (Address: 0x1800c99e0)
  • RtlLookupFunctionEntry (Address: 0x1800c99e8)
  • RtlPcToFileHeader (Address: 0x1800c99b8)
  • RtlVirtualUnwind (Address: 0x1800c99f0)
  • SetEvent (Address: 0x1800c9998)
  • SetLastError (Address: 0x1800c9848)
  • SetThreadpoolTimer (Address: 0x1800c98e0)
  • SetUnhandledExceptionFilter (Address: 0x1800c9a00)
  • SizeofResource (Address: 0x1800c9a30)
  • Sleep (Address: 0x1800c97b0)
  • SubmitThreadpoolWork (Address: 0x1800c97a0)
  • TerminateProcess (Address: 0x1800c9a10)
  • UnhandledExceptionFilter (Address: 0x1800c99f8)
  • VerifyVersionInfoW (Address: 0x1800c9828)
  • WaitForSingleObject (Address: 0x1800c9880)
  • WaitForSingleObjectEx (Address: 0x1800c98c8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800c9878)
  • WideCharToMultiByte (Address: 0x1800c9938)
NETAPI32.dll
  • NetGetAadJoinInformation (Address: 0x1800c9a48)
netutils.dll
  • NetApiBufferFree (Address: 0x1800ca0e8)
ntdll.dll
  • RtlGetDeviceFamilyInfoEnum (Address: 0x1800ca110)
  • RtlGetPersistedStateLocation (Address: 0x1800ca100)
  • RtlNtStatusToDosError (Address: 0x1800ca0f8)
  • VerSetConditionMask (Address: 0x1800ca108)
ole32.dll
  • CoCreateFreeThreadedMarshaler (Address: 0x1800ca168)
  • CoCreateInstance (Address: 0x1800ca210)
  • CoGetObject (Address: 0x1800ca1c8)
  • CoImpersonateClient (Address: 0x1800ca200)
  • CoRevertToSelf (Address: 0x1800ca208)
  • CoSetProxyBlanket (Address: 0x1800ca1b0)
  • CoTaskMemAlloc (Address: 0x1800ca1b8)
  • CoTaskMemFree (Address: 0x1800ca170)
  • CoWaitForMultipleHandles (Address: 0x1800ca1a8)
  • HWND_UserFree (Address: 0x1800ca180)
  • HWND_UserFree64 (Address: 0x1800ca160)
  • HWND_UserMarshal (Address: 0x1800ca130)
  • HWND_UserMarshal64 (Address: 0x1800ca138)
  • HWND_UserSize (Address: 0x1800ca190)
  • HWND_UserSize64 (Address: 0x1800ca148)
  • HWND_UserUnmarshal (Address: 0x1800ca188)
  • HWND_UserUnmarshal64 (Address: 0x1800ca1f0)
  • ObjectStublessClient10 (Address: 0x1800ca1e8)
  • ObjectStublessClient11 (Address: 0x1800ca1d0)
  • ObjectStublessClient12 (Address: 0x1800ca1a0)
  • ObjectStublessClient13 (Address: 0x1800ca120)
  • ObjectStublessClient14 (Address: 0x1800ca198)
  • ObjectStublessClient15 (Address: 0x1800ca178)
  • ObjectStublessClient3 (Address: 0x1800ca1d8)
  • ObjectStublessClient4 (Address: 0x1800ca1e0)
  • ObjectStublessClient5 (Address: 0x1800ca128)
  • ObjectStublessClient6 (Address: 0x1800ca140)
  • ObjectStublessClient7 (Address: 0x1800ca158)
  • ObjectStublessClient8 (Address: 0x1800ca150)
  • ObjectStublessClient9 (Address: 0x1800ca218)
  • StringFromCLSID (Address: 0x1800ca1f8)
  • StringFromGUID2 (Address: 0x1800ca1c0)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x1800c9ad0)
  • CStdStubBuffer_Connect (Address: 0x1800c9a88)
  • CStdStubBuffer_CountRefs (Address: 0x1800c9a98)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800c9ad8)
  • CStdStubBuffer_DebugServerRelease (Address: 0x1800c9a68)
  • CStdStubBuffer_Disconnect (Address: 0x1800c9a70)
  • CStdStubBuffer_Invoke (Address: 0x1800c9ac0)
  • CStdStubBuffer_IsIIDSupported (Address: 0x1800c9ae8)
  • CStdStubBuffer_QueryInterface (Address: 0x1800c9a58)
  • IUnknown_AddRef_Proxy (Address: 0x1800c9ac8)
  • IUnknown_QueryInterface_Proxy (Address: 0x1800c9a78)
  • IUnknown_Release_Proxy (Address: 0x1800c9a80)
  • NdrCStdStubBuffer_Release (Address: 0x1800c9ab8)
  • NdrDllCanUnloadNow (Address: 0x1800c9aa0)
  • NdrDllGetClassObject (Address: 0x1800c9a90)
  • NdrDllRegisterProxy (Address: 0x1800c9ab0)
  • NdrOleAllocate (Address: 0x1800c9a60)
  • NdrOleFree (Address: 0x1800c9ae0)
  • UuidCreate (Address: 0x1800c9aa8)
SHELL32.dll
  • ShellExecuteW (Address: 0x1800c9af8)
USER32.dll
  • GetDesktopWindow (Address: 0x1800c9b10)
  • GetForegroundWindow (Address: 0x1800c9b18)
  • GetWindow (Address: 0x1800c9b08)
WINHTTP.dll
  • WinHttpAddRequestHeaders (Address: 0x1800c9bc0)
  • WinHttpCloseHandle (Address: 0x1800c9b48)
  • WinHttpConnect (Address: 0x1800c9b58)
  • WinHttpGetDefaultProxyConfiguration (Address: 0x1800c9b38)
  • WinHttpGetIEProxyConfigForCurrentUser (Address: 0x1800c9b68)
  • WinHttpGetProxyForUrl (Address: 0x1800c9b78)
  • WinHttpOpen (Address: 0x1800c9b40)
  • WinHttpOpenRequest (Address: 0x1800c9b90)
  • WinHttpQueryAuthSchemes (Address: 0x1800c9ba8)
  • WinHttpQueryDataAvailable (Address: 0x1800c9b28)
  • WinHttpQueryHeaders (Address: 0x1800c9b80)
  • WinHttpQueryOption (Address: 0x1800c9b50)
  • WinHttpReadData (Address: 0x1800c9b98)
  • WinHttpReceiveResponse (Address: 0x1800c9ba0)
  • WinHttpSendRequest (Address: 0x1800c9bb8)
  • WinHttpSetCredentials (Address: 0x1800c9bb0)
  • WinHttpSetOption (Address: 0x1800c9b70)
  • WinHttpSetStatusCallback (Address: 0x1800c9b60)
  • WinHttpSetTimeouts (Address: 0x1800c9b88)
  • WinHttpWriteData (Address: 0x1800c9b30)
WINTRUST.dll
  • CryptCATAdminAcquireContext (Address: 0x1800c9bd0)
  • CryptCATAdminCalcHashFromFileHandle (Address: 0x1800c9bd8)
  • CryptCATAdminEnumCatalogFromHash (Address: 0x1800c9bf8)
  • CryptCATAdminReleaseCatalogContext (Address: 0x1800c9be8)
  • CryptCATAdminReleaseContext (Address: 0x1800c9bf0)
  • CryptCATCatalogInfoFromContext (Address: 0x1800c9c10)
  • WinVerifyTrust (Address: 0x1800c9c00)
  • WTHelperGetProvSignerFromChain (Address: 0x1800c9be0)
  • WTHelperProvDataFromStateData (Address: 0x1800c9c08)