Sens.dll
Description: System Event Notification Service (SENS)
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.1
Architecture: 64-bit
Operating System: Windows NT
SHA256: 56a94b1617815c1e8a79d832b0f0cba6
File Size: 76.0 KB
Uploaded At: Dec. 1, 2025, 7:38 a.m.
Views: 4
Exported Functions
- ServiceMain (Ordinal: 1, Address: 0x4b30)
- SvchostPushServiceGlobals (Ordinal: 2, Address: 0x5bb0)
- SensNotifyNetconEvent (Ordinal: 3, Address: 0xc430)
- SensNotifyRasEvent (Ordinal: 4, Address: 0xc5a0)
- SensNotifyWinlogonEvent (Ordinal: 5, Address: 0x11f0)
Imported DLLs & Functions
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x18000de80)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x18000de90)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18000dea0)
- SetUnhandledExceptionFilter (Address: 0x18000deb0)
- UnhandledExceptionFilter (Address: 0x18000dea8)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18000dec0)
- DuplicateHandle (Address: 0x18000dec8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18000ded8)
- HeapAlloc (Address: 0x18000dee0)
- HeapFree (Address: 0x18000dee8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- GetSystemPowerStatus (Address: 0x18000def8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x18000df10)
- FreeLibrary (Address: 0x18000df08)
- GetProcAddress (Address: 0x18000df20)
- LoadLibraryExW (Address: 0x18000df18)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x18000df40)
- MapViewOfFile (Address: 0x18000df38)
- UnmapViewOfFile (Address: 0x18000df30)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessAsUserW (Address: 0x18000df58)
- GetCurrentProcess (Address: 0x18000df70)
- GetCurrentProcessId (Address: 0x18000df50)
- GetCurrentThreadId (Address: 0x18000df60)
- TerminateProcess (Address: 0x18000df68)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18000df80)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18000dfa0)
- RegOpenKeyExW (Address: 0x18000df90)
- RegQueryValueExW (Address: 0x18000df98)
api-ms-win-core-synch-l1-1-0.dll
- CreateEventW (Address: 0x18000dfb0)
- DeleteCriticalSection (Address: 0x18000dfc0)
- EnterCriticalSection (Address: 0x18000dfd8)
- InitializeCriticalSection (Address: 0x18000dfe0)
- LeaveCriticalSection (Address: 0x18000dfd0)
- ResetEvent (Address: 0x18000dfe8)
- SetEvent (Address: 0x18000dfc8)
- WaitForSingleObject (Address: 0x18000dfb8)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x18000dff8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x18000e010)
- GetTickCount (Address: 0x18000e008)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueueTimer (Address: 0x18000e030)
- DeleteTimerQueueTimer (Address: 0x18000e038)
- QueueUserWorkItem (Address: 0x18000e020)
- UnregisterWaitEx (Address: 0x18000e028)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x18000e058)
- EventRegister (Address: 0x18000e050)
- EventSetInformation (Address: 0x18000e060)
- EventUnregister (Address: 0x18000e048)
- EventWriteTransfer (Address: 0x18000e068)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x18000e098)
- AllocateAndInitializeSid (Address: 0x18000e088)
- FreeSid (Address: 0x18000e078)
- GetLengthSid (Address: 0x18000e0a0)
- GetTokenInformation (Address: 0x18000e080)
- InitializeAcl (Address: 0x18000e0a8)
- InitializeSecurityDescriptor (Address: 0x18000e090)
- SetSecurityDescriptorDacl (Address: 0x18000e0b0)
api-ms-win-security-lsalookup-l1-1-0.dll
- LookupAccountSidLocalW (Address: 0x18000e0c0)
KERNELBASE.dll
- WTSIsServerContainer (Address: 0x18000ddf0)
msvcrt.dll
- __C_specific_handler (Address: 0x18000e0d8)
- _amsg_exit (Address: 0x18000e0f0)
- _initterm (Address: 0x18000e0d0)
- _XcptFilter (Address: 0x18000e0e8)
- free (Address: 0x18000e0e0)
- malloc (Address: 0x18000e0f8)
- memset (Address: 0x18000e100)
- wcscmp (Address: 0x18000e108)
ntdll.dll
- EtwGetTraceEnableFlags (Address: 0x18000e138)
- EtwGetTraceEnableLevel (Address: 0x18000e140)
- EtwGetTraceLoggerHandle (Address: 0x18000e148)
- EtwRegisterTraceGuidsW (Address: 0x18000e158)
- EtwTraceMessage (Address: 0x18000e150)
- EtwUnregisterTraceGuids (Address: 0x18000e128)
- RtlCaptureContext (Address: 0x18000e120)
- RtlLookupFunctionEntry (Address: 0x18000e118)
- RtlVirtualUnwind (Address: 0x18000e130)
RPCRT4.dll
- I_RpcBindingIsClientLocal (Address: 0x18000de20)
- NdrClientCall3 (Address: 0x18000de58)
- NdrServerCall2 (Address: 0x18000de48)
- NdrServerCallAll (Address: 0x18000de50)
- RpcBindingFree (Address: 0x18000de38)
- RpcBindingFromStringBindingW (Address: 0x18000de28)
- RpcBindingSetAuthInfoExW (Address: 0x18000de30)
- RpcMgmtSetServerStackSize (Address: 0x18000de40)
- RpcServerRegisterIf3 (Address: 0x18000de08)
- RpcServerRegisterIfEx (Address: 0x18000de00)
- RpcServerUnregisterIf (Address: 0x18000de18)
- RpcServerUseProtseqEpW (Address: 0x18000de10)
SYSNTFY.dll
- SysNotifyStartServer (Address: 0x18000de70)
- SysNotifyStopServer (Address: 0x18000de68)