SecurityHealthAgent.dll

Description: Windows Security Health Agent

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.18.1907.16384

Architecture: 64-bit

Operating System: Windows NT

SHA256: 5fe0462e198cdbcbe184fd5d9ad5af68

File Size: 433.4 KB

Uploaded At: Dec. 1, 2025, 7:38 a.m.

Views: 5

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x90a0)
  • DllGetClassObject (Ordinal: 2, Address: 0x8fb0)
  • DllMain (Ordinal: 3, Address: 0xa420)
  • DllRegisterServer (Ordinal: 4, Address: 0x9f60)
  • DllUnregisterServer (Ordinal: 5, Address: 0xa160)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180045e70)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x180045e98)
  • CoImpersonateClient (Address: 0x180045ea0)
  • CoRevertToSelf (Address: 0x180045e90)
  • CoSetProxyBlanket (Address: 0x180045e88)
  • CoTaskMemFree (Address: 0x180045e80)
  • StringFromCLSID (Address: 0x180045eb0)
  • StringFromGUID2 (Address: 0x180045ea8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180045ec8)
  • IsDebuggerPresent (Address: 0x180045ec0)
  • OutputDebugStringW (Address: 0x180045ed0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180045ee0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180045ef0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180045f08)
  • RaiseException (Address: 0x180045f10)
  • SetLastError (Address: 0x180045f20)
  • SetUnhandledExceptionFilter (Address: 0x180045f18)
  • UnhandledExceptionFilter (Address: 0x180045f00)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x180045f38)
  • GetFileAttributesW (Address: 0x180045f30)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180045f48)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180045f58)
  • HeapAlloc (Address: 0x180045f60)
  • HeapFree (Address: 0x180045f68)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x180045f78)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180045f88)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180045fb8)
  • FreeLibrary (Address: 0x180045fa0)
  • GetModuleFileNameA (Address: 0x180045fc8)
  • GetModuleFileNameW (Address: 0x180045fd8)
  • GetModuleHandleExW (Address: 0x180045fd0)
  • GetModuleHandleW (Address: 0x180045fa8)
  • GetProcAddress (Address: 0x180045fe0)
  • LoadLibraryExW (Address: 0x180045fe8)
  • LoadResource (Address: 0x180045fb0)
  • LockResource (Address: 0x180045f98)
  • SizeofResource (Address: 0x180045fc0)
api-ms-win-core-libraryloader-l1-2-1.dll
  • FindResourceW (Address: 0x180045ff8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180046008)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180046038)
  • GetCurrentProcessId (Address: 0x180046018)
  • GetCurrentThread (Address: 0x180046020)
  • GetCurrentThreadId (Address: 0x180046050)
  • OpenProcessToken (Address: 0x180046048)
  • OpenThreadToken (Address: 0x180046028)
  • ProcessIdToSessionId (Address: 0x180046030)
  • TerminateProcess (Address: 0x180046040)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180046060)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180046070)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800460a0)
  • RegCreateKeyExW (Address: 0x180046080)
  • RegOpenCurrentUser (Address: 0x180046088)
  • RegOpenKeyExW (Address: 0x180046098)
  • RegQueryValueExW (Address: 0x1800460a8)
  • RegSetValueExW (Address: 0x180046090)
api-ms-win-core-registry-l2-1-0.dll
  • RegDeleteKeyW (Address: 0x1800460b8)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800460d8)
  • RtlLookupFunctionEntry (Address: 0x1800460d0)
  • RtlVirtualUnwind (Address: 0x1800460c8)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpW (Address: 0x1800460e8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180046100)
  • AcquireSRWLockShared (Address: 0x180046128)
  • CreateEventW (Address: 0x180046150)
  • CreateMutexExW (Address: 0x180046178)
  • CreateSemaphoreExW (Address: 0x180046108)
  • DeleteCriticalSection (Address: 0x180046148)
  • EnterCriticalSection (Address: 0x180046110)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180046130)
  • InitializeCriticalSectionEx (Address: 0x180046188)
  • LeaveCriticalSection (Address: 0x180046120)
  • OpenSemaphoreW (Address: 0x180046168)
  • ReleaseMutex (Address: 0x180046138)
  • ReleaseSemaphore (Address: 0x180046118)
  • ReleaseSRWLockExclusive (Address: 0x1800460f8)
  • ReleaseSRWLockShared (Address: 0x180046160)
  • ResetEvent (Address: 0x180046180)
  • SetEvent (Address: 0x180046158)
  • WaitForSingleObject (Address: 0x180046170)
  • WaitForSingleObjectEx (Address: 0x180046140)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180046198)
api-ms-win-core-synch-l1-2-1.dll
  • CreateSemaphoreW (Address: 0x1800461a8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x1800461b8)
  • GetSystemTimeAsFileTime (Address: 0x1800461c0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x1800461d8)
  • CreateThreadpoolTimer (Address: 0x1800461e8)
  • SetThreadpoolTimer (Address: 0x1800461e0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800461d0)
api-ms-win-core-util-l1-1-0.dll
  • EncodePointer (Address: 0x1800461f8)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180046208)
  • RoGetActivationFactory (Address: 0x180046210)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x180046220)
  • WindowsDeleteString (Address: 0x180046230)
  • WindowsGetStringRawBuffer (Address: 0x180046228)
api-ms-win-crt-convert-l1-1-0.dll
  • _i64toa_s (Address: 0x180046250)
  • _i64tow_s (Address: 0x180046260)
  • _ui64toa_s (Address: 0x180046268)
  • _ui64tow_s (Address: 0x180046258)
  • _wcstod_l (Address: 0x180046240)
  • _wtoi (Address: 0x180046248)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x180046288)
  • free (Address: 0x180046278)
  • malloc (Address: 0x180046280)
api-ms-win-crt-locale-l1-1-0.dll
  • __pctype_func (Address: 0x1800462a8)
  • _create_locale (Address: 0x180046298)
  • _free_locale (Address: 0x1800462a0)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x1800462f8)
  • __CxxFrameHandler3 (Address: 0x1800462f0)
  • __CxxFrameHandler4 (Address: 0x1800462e0)
  • __std_exception_copy (Address: 0x1800462d0)
  • __std_exception_destroy (Address: 0x1800462c0)
  • __std_terminate (Address: 0x180046300)
  • __std_type_info_destroy_list (Address: 0x1800462e8)
  • _CxxThrowException (Address: 0x1800462d8)
  • _purecall (Address: 0x180046308)
  • memcmp (Address: 0x1800462b8)
  • memcpy (Address: 0x1800462c8)
  • memmove (Address: 0x180046310)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x180046388)
  • _configure_narrow_argv (Address: 0x180046358)
  • _crt_atexit (Address: 0x180046378)
  • _errno (Address: 0x180046328)
  • _execute_onexit_table (Address: 0x180046370)
  • _initialize_narrow_environment (Address: 0x180046360)
  • _initialize_onexit_table (Address: 0x180046368)
  • _initterm (Address: 0x180046340)
  • _initterm_e (Address: 0x180046348)
  • _invalid_parameter_noinfo (Address: 0x180046330)
  • _invalid_parameter_noinfo_noreturn (Address: 0x180046338)
  • _register_onexit_function (Address: 0x180046320)
  • _seh_filter_dll (Address: 0x180046350)
  • terminate (Address: 0x180046380)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vsnprintf_s (Address: 0x1800463c0)
  • __stdio_common_vsnwprintf_s (Address: 0x180046398)
  • __stdio_common_vsprintf (Address: 0x1800463a8)
  • __stdio_common_vsprintf_s (Address: 0x1800463b0)
  • __stdio_common_vswprintf (Address: 0x1800463b8)
  • __stdio_common_vswprintf_s (Address: 0x1800463a0)
api-ms-win-crt-string-l1-1-0.dll
  • _wcsicmp (Address: 0x1800463d8)
  • iswspace (Address: 0x1800463f8)
  • memset (Address: 0x1800463f0)
  • strnlen (Address: 0x1800463e0)
  • towlower (Address: 0x1800463d0)
  • wcscmp (Address: 0x180046400)
  • wcsnlen (Address: 0x1800463e8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180046428)
  • GetTraceEnableLevel (Address: 0x180046410)
  • GetTraceLoggerHandle (Address: 0x180046420)
  • RegisterTraceGuidsW (Address: 0x180046418)
  • TraceMessage (Address: 0x180046438)
  • UnregisterTraceGuids (Address: 0x180046430)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x180046450)
  • EventSetInformation (Address: 0x180046458)
  • EventUnregister (Address: 0x180046448)
  • EventWriteTransfer (Address: 0x180046460)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • GetForegroundWindow (Address: 0x180046470)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheck (Address: 0x1800464c0)
  • AdjustTokenPrivileges (Address: 0x1800464c8)
  • AllocateAndInitializeSid (Address: 0x1800464b8)
  • CheckTokenMembership (Address: 0x180046488)
  • CopySid (Address: 0x1800464a0)
  • FreeSid (Address: 0x180046480)
  • GetLengthSid (Address: 0x180046498)
  • GetSecurityDescriptorDacl (Address: 0x1800464d0)
  • GetSecurityDescriptorOwner (Address: 0x1800464b0)
  • GetTokenInformation (Address: 0x1800464a8)
  • InitializeAcl (Address: 0x180046490)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x1800464e0)
api-ms-win-security-provider-l1-1-0.dll
  • GetNamedSecurityInfoW (Address: 0x1800464f0)
  • SetEntriesInAclW (Address: 0x1800464f8)
  • SetNamedSecurityInfoW (Address: 0x180046500)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180046518)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180046510)
  • ConvertStringSidToSidW (Address: 0x180046520)
CRYPT32.dll
  • CertVerifyCertificateChainPolicy (Address: 0x180045d10)
msvcp_win.dll
  • ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z (Address: 0x180046570)
  • ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z (Address: 0x180046580)
  • ?__ExceptionPtrCreate@@YAXPEAX@Z (Address: 0x180046578)
  • ?__ExceptionPtrCurrentException@@YAXPEAX@Z (Address: 0x1800465a0)
  • ?__ExceptionPtrDestroy@@YAXPEAX@Z (Address: 0x180046598)
  • ?__ExceptionPtrRethrow@@YAXPEBX@Z (Address: 0x1800465a8)
  • ?__ExceptionPtrToBool@@YA_NPEBX@Z (Address: 0x180046590)
  • ?_Execute_once@std@@YAHAEAUonce_flag@1@P6AHPEAX1PEAPEAX@Z1@Z (Address: 0x180046548)
  • ?_Ipfx@?$basic_istream@GU?$char_traits@G@std@@@std@@QEAA_N_N@Z (Address: 0x180046560)
  • ?_Lock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x180046608)
  • ?_Pninc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ (Address: 0x180046630)
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x180046530)
  • ?_Unlock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x180046600)
  • ?_Winerror_map@std@@YAHH@Z (Address: 0x180046538)
  • ?_Winerror_message@std@@YAKKPEADK@Z (Address: 0x180046540)
  • ?_Xbad_alloc@std@@YAXXZ (Address: 0x1800465b0)
  • ?_XGetLastError@std@@YAXXZ (Address: 0x180046588)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x180046550)
  • ??0?$basic_ios@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x180046640)
  • ??0?$basic_iostream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@@Z (Address: 0x180046628)
  • ??0?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x180046648)
  • ??1?$basic_ios@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x180046620)
  • ??1?$basic_iostream@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x1800465b8)
  • ??1?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x180046610)
  • ?gbump@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXH@Z (Address: 0x180046638)
  • ?imbue@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAXAEBVlocale@2@@Z (Address: 0x1800465c0)
  • ?sbumpc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGXZ (Address: 0x1800465e8)
  • ?setbuf@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAPEAV12@PEAG_J@Z (Address: 0x1800465d0)
  • ?setstate@?$basic_ios@GU?$char_traits@G@std@@@std@@QEAAXH_N@Z (Address: 0x180046618)
  • ?sgetc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGXZ (Address: 0x180046650)
  • ?showmanyc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JXZ (Address: 0x1800465f8)
  • ?snextc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGXZ (Address: 0x180046558)
  • ?sync@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAHXZ (Address: 0x1800465c8)
  • ?uflow@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAGXZ (Address: 0x1800465f0)
  • ?widen@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAGD@Z (Address: 0x180046568)
  • ?xsgetn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEAG_J@Z (Address: 0x1800465e0)
  • ?xsputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEBG_J@Z (Address: 0x1800465d8)
ntdll.dll
  • RtlGetDeviceFamilyInfoEnum (Address: 0x180046668)
  • RtlGetPersistedStateLocation (Address: 0x180046670)
  • RtlNtStatusToDosError (Address: 0x180046660)
OLE32.dll
  • CoGetObject (Address: 0x180045d38)
  • ObjectStublessClient3 (Address: 0x180045d48)
  • ObjectStublessClient4 (Address: 0x180045d40)
  • ObjectStublessClient5 (Address: 0x180045d28)
  • ObjectStublessClient6 (Address: 0x180045d20)
  • ObjectStublessClient7 (Address: 0x180045d30)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x180045d90)
  • CStdStubBuffer_Connect (Address: 0x180045df0)
  • CStdStubBuffer_CountRefs (Address: 0x180045da0)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x180045d80)
  • CStdStubBuffer_DebugServerRelease (Address: 0x180045dc8)
  • CStdStubBuffer_Disconnect (Address: 0x180045dd0)
  • CStdStubBuffer_Invoke (Address: 0x180045dd8)
  • CStdStubBuffer_IsIIDSupported (Address: 0x180045de8)
  • CStdStubBuffer_QueryInterface (Address: 0x180045da8)
  • IUnknown_AddRef_Proxy (Address: 0x180045d78)
  • IUnknown_QueryInterface_Proxy (Address: 0x180045de0)
  • IUnknown_Release_Proxy (Address: 0x180045d98)
  • NdrCStdStubBuffer_Release (Address: 0x180045d70)
  • NdrDllCanUnloadNow (Address: 0x180045d58)
  • NdrDllGetClassObject (Address: 0x180045dc0)
  • NdrDllRegisterProxy (Address: 0x180045d60)
  • NdrDllUnregisterProxy (Address: 0x180045d68)
  • NdrOleAllocate (Address: 0x180045db8)
  • NdrOleFree (Address: 0x180045d88)
  • UuidCreate (Address: 0x180045db0)
SHELL32.dll
  • ShellExecuteW (Address: 0x180045e00)
WINTRUST.dll
  • CryptCATAdminAcquireContext (Address: 0x180045e30)
  • CryptCATAdminCalcHashFromFileHandle (Address: 0x180045e10)
  • CryptCATAdminEnumCatalogFromHash (Address: 0x180045e28)
  • CryptCATAdminReleaseCatalogContext (Address: 0x180045e38)
  • CryptCATAdminReleaseContext (Address: 0x180045e48)
  • CryptCATCatalogInfoFromContext (Address: 0x180045e50)
  • WinVerifyTrust (Address: 0x180045e40)
  • WTHelperGetProvSignerFromChain (Address: 0x180045e18)
  • WTHelperProvDataFromStateData (Address: 0x180045e20)
Wldp.dll
  • WldpQueryWindowsLockdownMode (Address: 0x180045e60)