das.dll

Description: Device Association Service

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 1860d1b7ae7ccd3e5dcc0c3bdd34af3b

File Size: 478.0 KB

Uploaded At: Dec. 1, 2025, 7:25 a.m.

Views: 8

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ServiceMain (Ordinal: 1, Address: 0x1650)

Imported DLLs & Functions

api-ms-win-appmodel-runtime-l1-1-1.dll
  • GetApplicationUserModelIdFromToken (Address: 0x180062e58)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180062e68)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x180062e90)
  • CoGetApartmentType (Address: 0x180062e98)
  • CoTaskMemAlloc (Address: 0x180062e88)
  • PropVariantClear (Address: 0x180062e80)
  • StringFromGUID2 (Address: 0x180062e78)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180062ea8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180062eb8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180062ee0)
  • RaiseException (Address: 0x180062ec8)
  • SetLastError (Address: 0x180062ed8)
  • SetUnhandledExceptionFilter (Address: 0x180062ee8)
  • UnhandledExceptionFilter (Address: 0x180062ed0)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x180062ef8)
  • GetFileAttributesW (Address: 0x180062f00)
  • GetFullPathNameW (Address: 0x180062f08)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180062f20)
  • DuplicateHandle (Address: 0x180062f18)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180062f38)
  • HeapAlloc (Address: 0x180062f30)
  • HeapFree (Address: 0x180062f40)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x180062f50)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180062f70)
  • InterlockedPopEntrySList (Address: 0x180062f68)
  • InterlockedPushEntrySList (Address: 0x180062f60)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180062f88)
  • FreeLibrary (Address: 0x180062f90)
  • GetModuleHandleExW (Address: 0x180062fa0)
  • GetProcAddress (Address: 0x180062f80)
  • LoadLibraryExW (Address: 0x180062f98)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x180062fb0)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessAsUserW (Address: 0x180062ff8)
  • GetCurrentProcess (Address: 0x180062fc0)
  • GetCurrentProcessId (Address: 0x180062fd8)
  • GetCurrentThread (Address: 0x180062fe0)
  • GetCurrentThreadId (Address: 0x180062fd0)
  • GetExitCodeProcess (Address: 0x180063008)
  • OpenProcessToken (Address: 0x180062ff0)
  • OpenThreadToken (Address: 0x180063000)
  • SetThreadToken (Address: 0x180062fc8)
  • TerminateProcess (Address: 0x180062fe8)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x180063018)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180063028)
api-ms-win-core-psapi-l1-1-0.dll
  • K32GetModuleFileNameExW (Address: 0x180063038)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180063058)
  • RegEnumKeyExW (Address: 0x180063048)
  • RegGetValueW (Address: 0x180063060)
  • RegOpenKeyExW (Address: 0x180063050)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x180063070)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x180063080)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180063100)
  • AcquireSRWLockShared (Address: 0x1800630d8)
  • CreateEventW (Address: 0x1800630b8)
  • DeleteCriticalSection (Address: 0x180063090)
  • EnterCriticalSection (Address: 0x1800630e0)
  • InitializeCriticalSection (Address: 0x1800630e8)
  • InitializeSRWLock (Address: 0x1800630d0)
  • LeaveCriticalSection (Address: 0x1800630f0)
  • OpenEventW (Address: 0x1800630f8)
  • ReleaseSRWLockExclusive (Address: 0x1800630b0)
  • ReleaseSRWLockShared (Address: 0x1800630a8)
  • ResetEvent (Address: 0x1800630c0)
  • SetEvent (Address: 0x180063098)
  • SleepEx (Address: 0x1800630a0)
  • WaitForSingleObject (Address: 0x1800630c8)
  • WaitForSingleObjectEx (Address: 0x180063108)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180063118)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180063138)
  • GetSystemWindowsDirectoryW (Address: 0x180063130)
  • GetTickCount (Address: 0x180063128)
api-ms-win-core-threadpool-l1-2-0.dll
  • CallbackMayRunLong (Address: 0x180063170)
  • CloseThreadpoolCleanupGroup (Address: 0x1800631a8)
  • CloseThreadpoolCleanupGroupMembers (Address: 0x1800631b0)
  • CloseThreadpoolTimer (Address: 0x180063150)
  • CloseThreadpoolWait (Address: 0x1800631c0)
  • CloseThreadpoolWork (Address: 0x180063158)
  • CreateThreadpoolCleanupGroup (Address: 0x1800631c8)
  • CreateThreadpoolTimer (Address: 0x180063178)
  • CreateThreadpoolWait (Address: 0x180063160)
  • CreateThreadpoolWork (Address: 0x180063190)
  • FreeLibraryWhenCallbackReturns (Address: 0x1800631b8)
  • SetThreadpoolTimer (Address: 0x1800631a0)
  • SetThreadpoolWait (Address: 0x1800631d0)
  • SubmitThreadpoolWork (Address: 0x180063188)
  • TrySubmitThreadpoolCallback (Address: 0x180063198)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180063180)
  • WaitForThreadpoolWaitCallbacks (Address: 0x180063148)
  • WaitForThreadpoolWorkCallbacks (Address: 0x180063168)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x1800631e0)
  • RoTransformError (Address: 0x1800631e8)
api-ms-win-core-winrt-l1-1-0.dll
  • RoGetActivationFactory (Address: 0x180063200)
  • RoInitialize (Address: 0x1800631f8)
  • RoUninitialize (Address: 0x180063208)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x180063220)
  • WindowsCreateStringReference (Address: 0x180063230)
  • WindowsDeleteString (Address: 0x180063218)
  • WindowsDuplicateString (Address: 0x180063238)
  • WindowsGetStringRawBuffer (Address: 0x180063228)
api-ms-win-core-wow64-l1-1-0.dll
  • IsWow64Process (Address: 0x180063248)
api-ms-win-devices-query-l1-1-0.dll
  • DevFreeObjectProperties (Address: 0x180063258)
api-ms-win-devices-query-l1-1-1.dll
  • DevGetObjectPropertiesEx (Address: 0x180063268)
api-ms-win-devices-swdevice-l1-1-0.dll
  • SwDeviceClose (Address: 0x180063288)
  • SwDeviceCreate (Address: 0x1800632a0)
  • SwDeviceInterfacePropertySet (Address: 0x180063278)
  • SwDeviceInterfaceRegister (Address: 0x180063290)
  • SwDeviceInterfaceSetState (Address: 0x1800632a8)
  • SwDevicePropertySet (Address: 0x180063280)
  • SwMemFree (Address: 0x180063298)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x1800632d0)
  • GetTraceEnableLevel (Address: 0x1800632d8)
  • GetTraceLoggerHandle (Address: 0x1800632c0)
  • RegisterTraceGuidsW (Address: 0x1800632e0)
  • TraceMessage (Address: 0x1800632c8)
  • UnregisterTraceGuids (Address: 0x1800632b8)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x1800632f0)
  • EventRegister (Address: 0x180063308)
  • EventUnregister (Address: 0x180063300)
  • EventWriteTransfer (Address: 0x1800632f8)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x180063350)
  • AllocateAndInitializeSid (Address: 0x180063370)
  • CreateWellKnownSid (Address: 0x180063330)
  • DuplicateToken (Address: 0x180063318)
  • DuplicateTokenEx (Address: 0x180063360)
  • FreeSid (Address: 0x180063340)
  • GetKernelObjectSecurity (Address: 0x180063358)
  • GetTokenInformation (Address: 0x180063320)
  • ImpersonateLoggedOnUser (Address: 0x180063378)
  • InitializeSecurityDescriptor (Address: 0x180063368)
  • RevertToSelf (Address: 0x180063338)
  • SetSecurityDescriptorDacl (Address: 0x180063328)
  • SetSecurityDescriptorOwner (Address: 0x180063348)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x1800633a0)
  • ConvertSidToStringSidW (Address: 0x180063388)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180063398)
  • ConvertStringSidToSidW (Address: 0x180063390)
api-ms-win-service-core-l1-1-0.dll
  • RegisterServiceCtrlHandlerExW (Address: 0x1800633b8)
  • SetServiceStatus (Address: 0x1800633b0)
api-ms-win-service-core-l1-1-3.dll
  • GetServiceRegistryStateKey (Address: 0x1800633c8)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x1800633d8)
  • OpenSCManagerW (Address: 0x1800633e0)
  • OpenServiceW (Address: 0x1800633e8)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfigW (Address: 0x1800633f8)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800634c0)
  • __CxxFrameHandler3 (Address: 0x180063460)
  • _amsg_exit (Address: 0x180063470)
  • _callnewh (Address: 0x180063480)
  • _initterm (Address: 0x180063468)
  • _purecall (Address: 0x180063498)
  • _resetstkoflw (Address: 0x180063438)
  • _ultow_s (Address: 0x1800634d0)
  • _vsnwprintf (Address: 0x1800634b8)
  • _wcsicmp (Address: 0x180063418)
  • _wcsnicmp (Address: 0x180063428)
  • _XcptFilter (Address: 0x180063478)
  • free (Address: 0x1800634b0)
  • malloc (Address: 0x180063488)
  • memcmp (Address: 0x180063440)
  • memcpy (Address: 0x180063448)
  • memmove (Address: 0x180063450)
  • memmove_s (Address: 0x180063490)
  • memset (Address: 0x180063458)
  • realloc (Address: 0x1800634a0)
  • swprintf_s (Address: 0x180063408)
  • wcschr (Address: 0x1800634c8)
  • wcscmp (Address: 0x1800634d8)
  • wcsrchr (Address: 0x180063420)
  • wcsstr (Address: 0x180063430)
  • wcstoul (Address: 0x180063410)
  • wprintf (Address: 0x1800634a8)
ntdll.dll
  • LdrGetDllHandle (Address: 0x180063500)
  • LdrGetProcedureAddress (Address: 0x1800634f0)
  • NtAdjustPrivilegesToken (Address: 0x1800636d8)
  • NtClose (Address: 0x180063658)
  • NtCreateKey (Address: 0x180063560)
  • NtDeleteKey (Address: 0x180063558)
  • NtDeleteValueKey (Address: 0x180063530)
  • NtDuplicateToken (Address: 0x180063598)
  • NtEnumerateKey (Address: 0x180063540)
  • NtEnumerateValueKey (Address: 0x180063538)
  • NtOpenKey (Address: 0x180063568)
  • NtOpenProcessToken (Address: 0x1800635a8)
  • NtOpenProcessTokenEx (Address: 0x180063648)
  • NtOpenThreadToken (Address: 0x1800635b0)
  • NtOpenThreadTokenEx (Address: 0x180063650)
  • NtQueryInformationToken (Address: 0x180063640)
  • NtQueryKey (Address: 0x180063550)
  • NtQuerySecurityObject (Address: 0x1800635a0)
  • NtQueryValueKey (Address: 0x180063520)
  • NtSetInformationThread (Address: 0x180063590)
  • NtSetSecurityObject (Address: 0x180063548)
  • NtSetValueKey (Address: 0x180063528)
  • RtlAbsoluteToSelfRelativeSD (Address: 0x1800635d0)
  • RtlAcquireSRWLockExclusive (Address: 0x1800636b0)
  • RtlAddAccessAllowedAce (Address: 0x180063700)
  • RtlAddAccessAllowedAceEx (Address: 0x180063600)
  • RtlAddAce (Address: 0x180063578)
  • RtlAllocateHeap (Address: 0x1800636c8)
  • RtlAppendUnicodeStringToString (Address: 0x180063618)
  • RtlCaptureContext (Address: 0x1800636f0)
  • RtlCompareMemory (Address: 0x1800635c8)
  • RtlConvertSidToUnicodeString (Address: 0x180063620)
  • RtlCopySid (Address: 0x180063580)
  • RtlCreateAcl (Address: 0x1800636f8)
  • RtlCreateSecurityDescriptor (Address: 0x1800635f8)
  • RtlCreateUnicodeString (Address: 0x1800636a0)
  • RtlDeleteElementGenericTableAvl (Address: 0x180063728)
  • RtlEnumerateGenericTableAvl (Address: 0x180063710)
  • RtlEqualSid (Address: 0x180063628)
  • RtlEqualUnicodeString (Address: 0x180063688)
  • RtlFormatCurrentUserKeyPath (Address: 0x180063570)
  • RtlFreeHeap (Address: 0x1800636b8)
  • RtlFreeUnicodeString (Address: 0x180063698)
  • RtlGetDaclSecurityDescriptor (Address: 0x180063588)
  • RtlGetGroupSecurityDescriptor (Address: 0x180063508)
  • RtlGetOwnerSecurityDescriptor (Address: 0x180063518)
  • RtlGetSaclSecurityDescriptor (Address: 0x180063510)
  • RtlGetVersion (Address: 0x180063660)
  • RtlGUIDFromString (Address: 0x1800636d0)
  • RtlInitAnsiString (Address: 0x1800634f8)
  • RtlInitializeGenericTableAvl (Address: 0x180063730)
  • RtlInitializeSid (Address: 0x180063638)
  • RtlInitializeSRWLock (Address: 0x1800636c0)
  • RtlInitUnicodeString (Address: 0x180063690)
  • RtlInitUnicodeStringEx (Address: 0x180063670)
  • RtlInsertElementGenericTableAvl (Address: 0x180063718)
  • RtlLengthSecurityDescriptor (Address: 0x180063678)
  • RtlLengthSid (Address: 0x180063608)
  • RtlLookupElementGenericTableAvl (Address: 0x180063720)
  • RtlLookupFunctionEntry (Address: 0x1800636e8)
  • RtlNtStatusToDosError (Address: 0x1800634e8)
  • RtlPrefixUnicodeString (Address: 0x1800635c0)
  • RtlReleaseSRWLockExclusive (Address: 0x1800636a8)
  • RtlSetDaclSecurityDescriptor (Address: 0x1800635f0)
  • RtlSetGroupSecurityDescriptor (Address: 0x1800635e0)
  • RtlSetOwnerSecurityDescriptor (Address: 0x1800635e8)
  • RtlSubAuthoritySid (Address: 0x180063630)
  • RtlTimeToTimeFields (Address: 0x1800635b8)
  • RtlUnicodeStringToInteger (Address: 0x180063668)
  • RtlValidRelativeSecurityDescriptor (Address: 0x180063680)
  • RtlValidSecurityDescriptor (Address: 0x1800635d8)
  • RtlValidSid (Address: 0x180063610)
  • RtlVirtualUnwind (Address: 0x1800636e0)
  • WinSqmIsOptedIn (Address: 0x180063708)
RMCLIENT.dll
  • RmAcquireResources (Address: 0x180062d08)
  • RmGetNotification (Address: 0x180062d10)
  • RmRegisterResource (Address: 0x180062d18)
  • RmReleaseResources (Address: 0x180062d00)
RPCRT4.dll
  • I_RpcBindingInqLocalClientPID (Address: 0x180062e48)
  • I_RpcExceptionFilter (Address: 0x180062dd8)
  • MesDecodeBufferHandleCreate (Address: 0x180062d38)
  • MesDecodeIncrementalHandleCreate (Address: 0x180062d58)
  • MesEncodeDynBufferHandleCreate (Address: 0x180062d40)
  • MesEncodeIncrementalHandleCreate (Address: 0x180062d70)
  • MesHandleFree (Address: 0x180062d78)
  • MesIncrementalHandleReset (Address: 0x180062d68)
  • Ndr64AsyncClientCall (Address: 0x180062e40)
  • Ndr64AsyncServerCallAll (Address: 0x180062e10)
  • NdrAsyncServerCall (Address: 0x180062e00)
  • NdrClientCall3 (Address: 0x180062e20)
  • NdrMesTypeAlignSize3 (Address: 0x180062e38)
  • NdrMesTypeDecode3 (Address: 0x180062e28)
  • NdrMesTypeEncode3 (Address: 0x180062e30)
  • NdrServerCall2 (Address: 0x180062e18)
  • NdrServerCallAll (Address: 0x180062e08)
  • RpcAsyncAbortCall (Address: 0x180062de0)
  • RpcAsyncCompleteCall (Address: 0x180062dd0)
  • RpcAsyncInitializeHandle (Address: 0x180062de8)
  • RpcBindingFree (Address: 0x180062d88)
  • RpcBindingFromStringBindingW (Address: 0x180062da8)
  • RpcBindingSetOption (Address: 0x180062d30)
  • RpcExceptionFilter (Address: 0x180062d80)
  • RpcImpersonateClient (Address: 0x180062df8)
  • RpcRevertToSelf (Address: 0x180062df0)
  • RpcServerInterfaceGroupActivate (Address: 0x180062db0)
  • RpcServerInterfaceGroupClose (Address: 0x180062db8)
  • RpcServerInterfaceGroupCreateW (Address: 0x180062d98)
  • RpcServerInterfaceGroupDeactivate (Address: 0x180062d60)
  • RpcServerSubscribeForNotification (Address: 0x180062dc8)
  • RpcServerUnsubscribeForNotification (Address: 0x180062dc0)
  • RpcSsDestroyClientContext (Address: 0x180062d28)
  • RpcStringBindingComposeW (Address: 0x180062da0)
  • RpcStringFreeW (Address: 0x180062d90)
  • UuidCreate (Address: 0x180062d50)
  • UuidFromStringW (Address: 0x180062d48)