sdiagschd.dll

Description: Scripted Diagnostics Scheduled Task

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 64-bit

Operating System: Windows NT

SHA256: 8303232cebe2bacd16c3887f083a5ec0

File Size: 66.5 KB

Uploaded At: Dec. 1, 2025, 7:38 a.m.

Views: 6

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x59f0)
  • DllGetClassObject (Ordinal: 2, Address: 0x5a10)
  • EnableScheduledDiagnostics (Ordinal: 3, Address: 0x6160)
  • GetScheduledDiagnosticsExecutionLevel (Ordinal: 4, Address: 0x6290)

Imported DLLs & Functions

ADVAPI32.dll
  • EventRegister (Address: 0x18000c1d0)
  • EventUnregister (Address: 0x18000c1c8)
  • EventWrite (Address: 0x18000c1c0)
  • EventWriteTransfer (Address: 0x18000c1b8)
  • RegCloseKey (Address: 0x18000c1e0)
  • RegOpenKeyExW (Address: 0x18000c1f0)
  • RegQueryValueExW (Address: 0x18000c1d8)
  • RegSetValueExW (Address: 0x18000c1e8)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x18000c3a8)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18000c2c0)
  • CloseHandle (Address: 0x18000c2a0)
  • CreateMutexExW (Address: 0x18000c260)
  • CreateSemaphoreExW (Address: 0x18000c308)
  • CreateThread (Address: 0x18000c2b8)
  • DebugBreak (Address: 0x18000c248)
  • DisableThreadLibraryCalls (Address: 0x18000c290)
  • ExpandEnvironmentStringsW (Address: 0x18000c2a8)
  • FindClose (Address: 0x18000c2f0)
  • FindFirstFileW (Address: 0x18000c2e0)
  • FindNextFileW (Address: 0x18000c2e8)
  • FormatMessageW (Address: 0x18000c338)
  • FreeLibraryAndExitThread (Address: 0x18000c2f8)
  • GetCurrentProcess (Address: 0x18000c318)
  • GetCurrentProcessId (Address: 0x18000c258)
  • GetCurrentThreadId (Address: 0x18000c200)
  • GetLastError (Address: 0x18000c2b0)
  • GetModuleFileNameA (Address: 0x18000c300)
  • GetModuleHandleExW (Address: 0x18000c2d8)
  • GetModuleHandleW (Address: 0x18000c250)
  • GetProcAddress (Address: 0x18000c268)
  • GetProcessHeap (Address: 0x18000c280)
  • GetSystemTimeAsFileTime (Address: 0x18000c210)
  • GetTickCount (Address: 0x18000c208)
  • HeapAlloc (Address: 0x18000c288)
  • HeapFree (Address: 0x18000c278)
  • InitializeSRWLock (Address: 0x18000c298)
  • IsDebuggerPresent (Address: 0x18000c240)
  • OpenSemaphoreW (Address: 0x18000c270)
  • OutputDebugStringW (Address: 0x18000c340)
  • QueryPerformanceCounter (Address: 0x18000c218)
  • ReleaseMutex (Address: 0x18000c330)
  • ReleaseSemaphore (Address: 0x18000c320)
  • ReleaseSRWLockExclusive (Address: 0x18000c2c8)
  • SetLastError (Address: 0x18000c310)
  • SetUnhandledExceptionFilter (Address: 0x18000c228)
  • Sleep (Address: 0x18000c238)
  • TerminateProcess (Address: 0x18000c220)
  • UnhandledExceptionFilter (Address: 0x18000c230)
  • WaitForSingleObject (Address: 0x18000c2d0)
  • WaitForSingleObjectEx (Address: 0x18000c328)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000c470)
  • __CxxFrameHandler3 (Address: 0x18000c458)
  • __dllonexit (Address: 0x18000c3c0)
  • _amsg_exit (Address: 0x18000c3e0)
  • _callnewh (Address: 0x18000c400)
  • _CxxThrowException (Address: 0x18000c3f8)
  • _initterm (Address: 0x18000c3d8)
  • _lock (Address: 0x18000c3d0)
  • _onexit (Address: 0x18000c3b8)
  • _unlock (Address: 0x18000c3f0)
  • _vsnprintf (Address: 0x18000c448)
  • _vsnprintf_s (Address: 0x18000c428)
  • _vsnwprintf (Address: 0x18000c460)
  • _wcsicmp (Address: 0x18000c468)
  • _wtoi (Address: 0x18000c478)
  • _XcptFilter (Address: 0x18000c3e8)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18000c410)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18000c430)
  • ??0exception@@QEAA@XZ (Address: 0x18000c438)
  • ??1exception@@UEAA@XZ (Address: 0x18000c440)
  • ??1type_info@@UEAA@XZ (Address: 0x18000c3c8)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18000c408)
  • free (Address: 0x18000c420)
  • malloc (Address: 0x18000c418)
  • memcpy_s (Address: 0x18000c450)
  • memset (Address: 0x18000c480)
ntdll.dll
  • DbgPrintEx (Address: 0x18000c4a0)
  • RtlCaptureContext (Address: 0x18000c498)
  • RtlCreateEnvironment (Address: 0x18000c4e8)
  • RtlDestroyEnvironment (Address: 0x18000c4c8)
  • RtlExpandEnvironmentStrings (Address: 0x18000c4c0)
  • RtlInitUnicodeStringEx (Address: 0x18000c4d8)
  • RtlLookupFunctionEntry (Address: 0x18000c490)
  • RtlNtStatusToDosError (Address: 0x18000c4e0)
  • RtlSetEnvironmentVariable (Address: 0x18000c4d0)
  • RtlVirtualUnwind (Address: 0x18000c4b8)
  • WinSqmAddToStream (Address: 0x18000c4f0)
  • WinSqmEndSession (Address: 0x18000c4b0)
  • WinSqmStartSession (Address: 0x18000c4a8)
OLEAUT32.dll
  • SafeArrayCopy (Address: 0x18000c370)
  • SafeArrayCreate (Address: 0x18000c360)
  • SafeArrayCreateVector (Address: 0x18000c390)
  • SafeArrayDestroy (Address: 0x18000c398)
  • SafeArrayGetElement (Address: 0x18000c368)
  • SafeArrayPutElement (Address: 0x18000c358)
  • SysAllocString (Address: 0x18000c380)
  • SysFreeString (Address: 0x18000c350)
  • SysStringByteLen (Address: 0x18000c388)
  • SysStringLen (Address: 0x18000c378)