SessEnv.dll
Description: Remote Desktop Configuration service
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6456
Architecture: 32-bit
Operating System: Windows NT
SHA256: 620b2c84869fb1f1497133a63c19c4ea
File Size: 435.0 KB
Uploaded At: Dec. 1, 2025, 8:04 a.m.
Views: 27
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- ServiceMain (Ordinal: 1, Address: 0x1caf0)
- SvchostPushServiceGlobals (Ordinal: 2, Address: 0x22f80)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x10068090)
api-ms-win-core-com-l1-1-0.dll
- CoCreateGuid (Address: 0x100680b0)
- CoCreateInstance (Address: 0x1006809c)
- CoCreateInstanceEx (Address: 0x100680b4)
- CoInitializeEx (Address: 0x10068098)
- CoSetProxyBlanket (Address: 0x100680a0)
- CoTaskMemAlloc (Address: 0x100680b8)
- CoTaskMemFree (Address: 0x100680bc)
- CoUninitialize (Address: 0x100680a4)
- CoWaitForMultipleHandles (Address: 0x100680ac)
- StringFromCLSID (Address: 0x100680a8)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x100680c8)
- IsDebuggerPresent (Address: 0x100680d0)
- OutputDebugStringA (Address: 0x100680c4)
- OutputDebugStringW (Address: 0x100680cc)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x100680d8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x100680e0)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x100680f4)
- SetLastError (Address: 0x100680f0)
- SetUnhandledExceptionFilter (Address: 0x100680ec)
- UnhandledExceptionFilter (Address: 0x100680e8)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x10068140)
- CreateDirectoryW (Address: 0x10068104)
- CreateFileW (Address: 0x10068138)
- DeleteFileW (Address: 0x10068108)
- DeleteVolumeMountPointW (Address: 0x10068124)
- FileTimeToLocalFileTime (Address: 0x1006813c)
- FindClose (Address: 0x100680fc)
- FindFirstFileW (Address: 0x1006810c)
- FindFirstVolumeW (Address: 0x10068114)
- FindNextFileW (Address: 0x10068100)
- FindNextVolumeW (Address: 0x10068118)
- FindVolumeClose (Address: 0x1006811c)
- GetFileAttributesW (Address: 0x10068134)
- GetFileSizeEx (Address: 0x10068130)
- GetFileTime (Address: 0x10068148)
- ReadFile (Address: 0x1006812c)
- RemoveDirectoryW (Address: 0x10068120)
- SetFileAttributesW (Address: 0x10068144)
- SetFilePointer (Address: 0x10068110)
- WriteFile (Address: 0x10068128)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x10068150)
- GetVolumeNameForVolumeMountPointW (Address: 0x10068154)
- GetVolumePathNamesForVolumeNameW (Address: 0x10068158)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x1006816c)
- CreateSymbolicLinkW (Address: 0x10068168)
- GetFileInformationByHandleEx (Address: 0x10068160)
- MoveFileWithProgressW (Address: 0x10068164)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10068174)
- DuplicateHandle (Address: 0x10068178)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x10068184)
- HeapAlloc (Address: 0x10068188)
- HeapFree (Address: 0x10068180)
- HeapReAlloc (Address: 0x1006818c)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x10068194)
- LocalFree (Address: 0x10068198)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalSize (Address: 0x100681a0)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x100681a8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- GetComputerNameW (Address: 0x100681b8)
- MoveFileW (Address: 0x100681b0)
- WTSGetActiveConsoleSessionId (Address: 0x100681b4)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
- SetVolumeMountPointW (Address: 0x100681c4)
- VerifyVersionInfoW (Address: 0x100681c0)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x100681cc)
- FreeLibrary (Address: 0x100681d8)
- GetModuleFileNameA (Address: 0x100681e0)
- GetModuleFileNameW (Address: 0x100681d4)
- GetModuleHandleExW (Address: 0x100681d0)
- GetModuleHandleW (Address: 0x100681e8)
- GetProcAddress (Address: 0x100681e4)
- LoadLibraryExW (Address: 0x100681dc)
- LoadStringW (Address: 0x100681ec)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryW (Address: 0x100681f4)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x100681fc)
api-ms-win-core-path-l1-1-0.dll
- PathCchCombine (Address: 0x10068204)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x1006820c)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessAsUserW (Address: 0x10068230)
- CreateProcessW (Address: 0x10068240)
- CreateThread (Address: 0x10068234)
- GetCurrentProcess (Address: 0x10068244)
- GetCurrentProcessId (Address: 0x10068220)
- GetCurrentThread (Address: 0x10068218)
- GetCurrentThreadId (Address: 0x1006823c)
- GetThreadId (Address: 0x10068228)
- OpenProcessToken (Address: 0x10068238)
- OpenThreadToken (Address: 0x1006821c)
- ProcessIdToSessionId (Address: 0x10068214)
- TerminateProcess (Address: 0x10068224)
- TerminateThread (Address: 0x1006822c)
api-ms-win-core-processthreads-l1-1-1.dll
- GetProcessMitigationPolicy (Address: 0x1006824c)
- OpenProcess (Address: 0x10068250)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1006825c)
- QueryPerformanceFrequency (Address: 0x10068258)
api-ms-win-core-psapi-l1-1-0.dll
- QueryFullProcessImageNameW (Address: 0x10068264)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x10068288)
- RegCreateKeyExW (Address: 0x100682a4)
- RegDeleteTreeW (Address: 0x1006827c)
- RegDeleteValueW (Address: 0x1006828c)
- RegEnumKeyExW (Address: 0x1006829c)
- RegEnumValueW (Address: 0x10068280)
- RegGetValueW (Address: 0x10068290)
- RegLoadKeyW (Address: 0x1006826c)
- RegNotifyChangeKeyValue (Address: 0x10068270)
- RegOpenCurrentUser (Address: 0x100682a0)
- RegOpenKeyExW (Address: 0x10068274)
- RegQueryInfoKeyW (Address: 0x10068284)
- RegQueryValueExW (Address: 0x10068298)
- RegSetValueExW (Address: 0x10068294)
- RegUnLoadKeyW (Address: 0x10068278)
api-ms-win-core-registry-l2-1-0.dll
- RegDeleteKeyW (Address: 0x100682ac)
- RegEnumKeyW (Address: 0x100682b0)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- StrToIntExW (Address: 0x100682b8)
api-ms-win-core-shutdown-l1-1-0.dll
- InitiateSystemShutdownExW (Address: 0x100682c0)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x100682c8)
- WideCharToMultiByte (Address: 0x100682cc)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x100682d4)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x100682fc)
- AcquireSRWLockShared (Address: 0x10068310)
- CreateEventW (Address: 0x1006830c)
- CreateMutexExW (Address: 0x10068314)
- CreateSemaphoreExW (Address: 0x100682f4)
- DeleteCriticalSection (Address: 0x10068308)
- EnterCriticalSection (Address: 0x100682f0)
- InitializeCriticalSection (Address: 0x10068300)
- InitializeCriticalSectionAndSpinCount (Address: 0x100682e8)
- InitializeCriticalSectionEx (Address: 0x1006832c)
- LeaveCriticalSection (Address: 0x100682e0)
- OpenSemaphoreW (Address: 0x10068318)
- ReleaseMutex (Address: 0x100682dc)
- ReleaseSemaphore (Address: 0x100682e4)
- ReleaseSRWLockExclusive (Address: 0x100682ec)
- ReleaseSRWLockShared (Address: 0x10068324)
- ResetEvent (Address: 0x10068328)
- SetEvent (Address: 0x100682f8)
- WaitForMultipleObjectsEx (Address: 0x10068320)
- WaitForSingleObject (Address: 0x1006831c)
- WaitForSingleObjectEx (Address: 0x10068304)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x10068338)
- Sleep (Address: 0x10068334)
api-ms-win-core-synch-l1-2-1.dll
- WaitForMultipleObjects (Address: 0x10068340)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x1006834c)
- GetLocalTime (Address: 0x10068354)
- GetSystemDirectoryW (Address: 0x10068358)
- GetSystemTime (Address: 0x10068350)
- GetSystemTimeAsFileTime (Address: 0x1006835c)
- GetTickCount (Address: 0x10068348)
- GetVersionExW (Address: 0x10068360)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x10068370)
- CreateThreadpoolTimer (Address: 0x10068374)
- SetThreadpoolTimer (Address: 0x10068368)
- WaitForThreadpoolTimerCallbacks (Address: 0x1006836c)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueue (Address: 0x1006837c)
- CreateTimerQueueTimer (Address: 0x1006838c)
- DeleteTimerQueueEx (Address: 0x10068380)
- DeleteTimerQueueTimer (Address: 0x10068384)
- UnregisterWaitEx (Address: 0x10068388)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x10068398)
- SystemTimeToFileTime (Address: 0x10068394)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- TraceMessage (Address: 0x100683a0)
api-ms-win-eventing-controller-l1-1-0.dll
- ControlTraceW (Address: 0x100683b0)
- EnableTraceEx2 (Address: 0x100683ac)
- StartTraceW (Address: 0x100683a8)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x100683c0)
- EventProviderEnabled (Address: 0x100683b8)
- EventRegister (Address: 0x100683bc)
- EventSetInformation (Address: 0x100683c8)
- EventUnregister (Address: 0x100683cc)
- EventWriteTransfer (Address: 0x100683c4)
api-ms-win-eventlog-legacy-l1-1-0.dll
- DeregisterEventSource (Address: 0x100683d8)
- RegisterEventSourceW (Address: 0x100683dc)
- ReportEventW (Address: 0x100683d4)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x100683e8)
- AllocateAndInitializeSid (Address: 0x1006840c)
- CheckTokenMembership (Address: 0x100683fc)
- CopySid (Address: 0x100683f0)
- CreateWellKnownSid (Address: 0x100683ec)
- DeleteAce (Address: 0x10068434)
- DuplicateToken (Address: 0x100683f4)
- DuplicateTokenEx (Address: 0x10068404)
- EqualSid (Address: 0x10068424)
- FreeSid (Address: 0x10068410)
- GetAce (Address: 0x1006841c)
- GetAclInformation (Address: 0x1006843c)
- GetFileSecurityW (Address: 0x10068440)
- GetLengthSid (Address: 0x10068400)
- GetSecurityDescriptorControl (Address: 0x10068438)
- GetSecurityDescriptorDacl (Address: 0x10068420)
- GetSecurityDescriptorLength (Address: 0x100683e4)
- GetTokenInformation (Address: 0x10068418)
- ImpersonateLoggedOnUser (Address: 0x10068448)
- InitializeSecurityDescriptor (Address: 0x1006842c)
- IsValidSid (Address: 0x10068430)
- MakeAbsoluteSD (Address: 0x10068408)
- RevertToSelf (Address: 0x1006844c)
- SetFileSecurityW (Address: 0x10068444)
- SetSecurityDescriptorControl (Address: 0x10068428)
- SetSecurityDescriptorDacl (Address: 0x100683f8)
- SetTokenInformation (Address: 0x10068414)
api-ms-win-security-credentials-l1-1-0.dll
- CredUnprotectW (Address: 0x10068454)
api-ms-win-security-lsalookup-l1-1-0.dll
- LookupAccountSidLocalW (Address: 0x1006845c)
api-ms-win-security-lsapolicy-l1-1-0.dll
- LsaFreeMemory (Address: 0x10068464)
api-ms-win-security-provider-l1-1-0.dll
- SetEntriesInAclW (Address: 0x1006846c)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1006847c)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x10068478)
- ConvertStringSidToSidW (Address: 0x10068474)
api-ms-win-service-core-l1-1-0.dll
- RegisterServiceCtrlHandlerExW (Address: 0x10068488)
- SetServiceStatus (Address: 0x10068484)
DismApi.DLL
- DismDisableFeature (Address: 0x1006800c)
- DismEnableFeature (Address: 0x10068004)
- DismInitialize (Address: 0x10068000)
- DismOpenSession (Address: 0x10068008)
- DismShutdown (Address: 0x10068010)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x10068500)
- __dllonexit (Address: 0x100684a8)
- _amsg_exit (Address: 0x100684b4)
- _callnewh (Address: 0x100684c4)
- _CxxThrowException (Address: 0x100684f4)
- _except_handler4_common (Address: 0x100684c0)
- _initterm (Address: 0x100684cc)
- _lock (Address: 0x10068530)
- _onexit (Address: 0x100684d4)
- _purecall (Address: 0x10068518)
- _unlock (Address: 0x1006850c)
- _vsnprintf (Address: 0x100684ac)
- _vsnwprintf (Address: 0x100684d0)
- _wcsicmp (Address: 0x100684a4)
- _wcsnicmp (Address: 0x1006851c)
- _wtol (Address: 0x100684a0)
- _XcptFilter (Address: 0x10068514)
- ??_V@YAXPAX@Z (Address: 0x100684c8)
- ??0exception@@QAE@ABQBD@Z (Address: 0x100684e0)
- ??0exception@@QAE@ABQBDH@Z (Address: 0x100684e4)
- ??0exception@@QAE@ABV0@@Z (Address: 0x100684e8)
- ??1exception@@UAE@XZ (Address: 0x100684ec)
- ??1type_info@@UAE@XZ (Address: 0x10068508)
- ??3@YAXPAX@Z (Address: 0x1006852c)
- ?terminate@@YAXXZ (Address: 0x10068504)
- ?what@exception@@UBEPBDXZ (Address: 0x100684f0)
- free (Address: 0x100684b0)
- iswalpha (Address: 0x10068528)
- malloc (Address: 0x100684d8)
- memcmp (Address: 0x100684bc)
- memcpy (Address: 0x100684f8)
- memcpy_s (Address: 0x1006849c)
- memmove (Address: 0x100684fc)
- memmove_s (Address: 0x10068490)
- memset (Address: 0x10068534)
- swprintf_s (Address: 0x10068510)
- toupper (Address: 0x100684b8)
- wcscat_s (Address: 0x10068498)
- wcschr (Address: 0x100684dc)
- wcscpy_s (Address: 0x10068494)
- wcsncmp (Address: 0x10068520)
- wcsrchr (Address: 0x10068524)
ntdll.dll
- DbgPrint (Address: 0x100685ac)
- EtwEventRegister (Address: 0x1006856c)
- EtwEventUnregister (Address: 0x10068570)
- EtwEventWriteFull (Address: 0x10068568)
- NtDuplicateToken (Address: 0x1006853c)
- NtQueryInformationProcess (Address: 0x10068540)
- NtQuerySystemInformation (Address: 0x100685cc)
- NtQueryWnfStateData (Address: 0x1006857c)
- RtlAcquireResourceExclusive (Address: 0x100685a0)
- RtlAcquireResourceShared (Address: 0x100685a8)
- RtlAllocateAndInitializeSid (Address: 0x1006859c)
- RtlAllocateHeap (Address: 0x10068548)
- RtlCaptureStackBackTrace (Address: 0x100685c4)
- RtlDeleteElementGenericTable (Address: 0x10068594)
- RtlDeleteResource (Address: 0x100685c8)
- RtlEnumerateGenericTable (Address: 0x10068598)
- RtlEqualSid (Address: 0x100685b0)
- RtlFreeHeap (Address: 0x100685d0)
- RtlFreeSid (Address: 0x100685b8)
- RtlGetActiveConsoleId (Address: 0x10068564)
- RtlInitializeGenericTable (Address: 0x10068590)
- RtlInitializeResource (Address: 0x100685bc)
- RtlInitUnicodeStringEx (Address: 0x1006858c)
- RtlInsertElementGenericTable (Address: 0x10068580)
- RtlLengthSid (Address: 0x10068544)
- RtlLookupElementGenericTable (Address: 0x10068584)
- RtlNtStatusToDosError (Address: 0x1006854c)
- RtlQueryEnvironmentVariable_U (Address: 0x10068588)
- RtlReleaseResource (Address: 0x100685a4)
- RtlSubscribeWnfStateChangeNotification (Address: 0x10068578)
- RtlUnsubscribeWnfStateChangeNotification (Address: 0x10068574)
- RtlVerifyVersionInfo (Address: 0x100685c0)
- VerSetConditionMask (Address: 0x100685b4)
- WinSqmAddToStream (Address: 0x10068558)
- WinSqmEndSession (Address: 0x1006855c)
- WinSqmIsOptedIn (Address: 0x10068560)
- WinSqmSetDWORD (Address: 0x10068550)
- WinSqmStartSession (Address: 0x10068554)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x10068018)
- NdrServerCall2 (Address: 0x10068074)
- RpcBindingFree (Address: 0x10068030)
- RpcBindingInqAuthClientW (Address: 0x10068034)
- RpcBindingServerFromClient (Address: 0x1006803c)
- RpcBindingToStringBindingW (Address: 0x1006806c)
- RpcBindingVectorFree (Address: 0x10068020)
- RpcEpRegisterW (Address: 0x10068050)
- RpcFreeAuthorizationContext (Address: 0x10068040)
- RpcGetAuthorizationContextForClient (Address: 0x10068060)
- RpcImpersonateClient (Address: 0x10068058)
- RpcRevertToSelf (Address: 0x10068054)
- RpcServerInqBindings (Address: 0x10068028)
- RpcServerInqCallAttributesW (Address: 0x10068064)
- RpcServerInqDefaultPrincNameW (Address: 0x10068044)
- RpcServerRegisterAuthInfoW (Address: 0x10068024)
- RpcServerRegisterIfEx (Address: 0x1006805c)
- RpcServerUnregisterIfEx (Address: 0x10068070)
- RpcServerUseProtseqEpW (Address: 0x1006801c)
- RpcServerUseProtseqExW (Address: 0x1006802c)
- RpcStringBindingParseW (Address: 0x10068068)
- RpcStringFreeW (Address: 0x1006804c)
- UuidCreate (Address: 0x10068038)
- UuidToStringW (Address: 0x10068048)
samcli.dll
- NetLocalGroupAddMembers (Address: 0x100685dc)
- NetLocalGroupDelMembers (Address: 0x100685d8)
- NetUserGetInfo (Address: 0x100685e0)
SCECLI.dll
- SceSetupSystemByInfName (Address: 0x1006807c)
SYSNTFY.dll
- SysNotifyStartServer (Address: 0x10068084)
- SysNotifyStopServer (Address: 0x10068088)