dssvc.dll
Description: Data Sharing Service NT Service DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 64-bit
Operating System: Windows NT
SHA256: dc5eacc0f4406b07efd5bfeb66eb5ef0
File Size: 159.5 KB
Uploaded At: Dec. 1, 2025, 7:27 a.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- InitializeService (Ordinal: 1, Address: 0x65e0)
- ServiceMain (Ordinal: 2, Address: 0x6b30)
- SvchostPushServiceGlobals (Ordinal: 3, Address: 0x6890)
- DSSCreateSharedFileTokenEx (Ordinal: 4, Address: 0x9660)
- DSSFreeToken (Ordinal: 5, Address: 0x9c60)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-l1-1-1.dll
- GetPackageFullNameFromToken (Address: 0x18001ad58)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x18001ad68)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x18001ad88)
- CoCreateGuid (Address: 0x18001ad78)
- CoCreateInstance (Address: 0x18001ad98)
- CoTaskMemFree (Address: 0x18001ad90)
- StringFromGUID2 (Address: 0x18001ad80)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x18001ada8)
- IsDebuggerPresent (Address: 0x18001adb0)
- OutputDebugStringW (Address: 0x18001adb8)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x18001adc8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x18001add8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18001ae08)
- RaiseException (Address: 0x18001adf0)
- SetLastError (Address: 0x18001ae00)
- SetUnhandledExceptionFilter (Address: 0x18001ade8)
- UnhandledExceptionFilter (Address: 0x18001adf8)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x18001ae38)
- CreateDirectoryW (Address: 0x18001ae50)
- CreateFileW (Address: 0x18001ae40)
- DeleteFileW (Address: 0x18001ae68)
- FindClose (Address: 0x18001ae78)
- FindFirstFileW (Address: 0x18001ae58)
- FindNextFileW (Address: 0x18001ae70)
- GetFileAttributesW (Address: 0x18001ae30)
- GetFileInformationByHandle (Address: 0x18001ae60)
- GetFinalPathNameByHandleW (Address: 0x18001ae48)
- RemoveDirectoryW (Address: 0x18001ae18)
- SetFileAttributesW (Address: 0x18001ae20)
- SetFileInformationByHandle (Address: 0x18001ae28)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x18001ae88)
- GetFileInformationByHandleEx (Address: 0x18001ae90)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18001aea0)
- DuplicateHandle (Address: 0x18001aea8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18001aec8)
- HeapAlloc (Address: 0x18001aec0)
- HeapFree (Address: 0x18001aeb8)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x18001aee0)
- LocalFree (Address: 0x18001aed8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x18001af08)
- FreeLibrary (Address: 0x18001aef0)
- GetModuleFileNameA (Address: 0x18001aef8)
- GetModuleHandleExW (Address: 0x18001af10)
- GetModuleHandleW (Address: 0x18001af00)
- GetProcAddress (Address: 0x18001af18)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18001af28)
api-ms-win-core-path-l1-1-0.dll
- PathAllocCanonicalize (Address: 0x18001af60)
- PathAllocCombine (Address: 0x18001af48)
- PathCchRemoveBackslash (Address: 0x18001af38)
- PathCchRemoveFileSpec (Address: 0x18001af40)
- PathCchSkipRoot (Address: 0x18001af50)
- PathIsUNCEx (Address: 0x18001af58)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18001af78)
- GetCurrentProcessId (Address: 0x18001af80)
- GetCurrentThread (Address: 0x18001af88)
- GetCurrentThreadId (Address: 0x18001af70)
- OpenThreadToken (Address: 0x18001af98)
- TerminateProcess (Address: 0x18001af90)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x18001afa8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18001afb8)
api-ms-win-core-psapi-l1-1-0.dll
- QueryFullProcessImageNameW (Address: 0x18001afc8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18001afd8)
- RegOpenKeyExW (Address: 0x18001afe0)
- RegQueryValueExW (Address: 0x18001afe8)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18001aff8)
- RtlLookupFunctionEntry (Address: 0x18001b008)
- RtlVirtualUnwind (Address: 0x18001b000)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18001b038)
- CreateEventW (Address: 0x18001b020)
- CreateMutexExW (Address: 0x18001b050)
- CreateMutexW (Address: 0x18001b058)
- CreateSemaphoreExW (Address: 0x18001b068)
- DeleteCriticalSection (Address: 0x18001b098)
- EnterCriticalSection (Address: 0x18001b040)
- InitializeCriticalSectionEx (Address: 0x18001b088)
- InitializeSRWLock (Address: 0x18001b048)
- LeaveCriticalSection (Address: 0x18001b078)
- OpenSemaphoreW (Address: 0x18001b060)
- ReleaseMutex (Address: 0x18001b030)
- ReleaseSemaphore (Address: 0x18001b080)
- ReleaseSRWLockExclusive (Address: 0x18001b018)
- SetEvent (Address: 0x18001b028)
- WaitForSingleObject (Address: 0x18001b090)
- WaitForSingleObjectEx (Address: 0x18001b070)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x18001b0b8)
- InitOnceComplete (Address: 0x18001b0b0)
- Sleep (Address: 0x18001b0a8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTime (Address: 0x18001b0d8)
- GetSystemTimeAsFileTime (Address: 0x18001b0c8)
- GetTickCount (Address: 0x18001b0d0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolWork (Address: 0x18001b0f0)
- CreateThreadpoolWork (Address: 0x18001b0e8)
- SubmitThreadpoolWork (Address: 0x18001b0f8)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- UnregisterWaitEx (Address: 0x18001b108)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x18001b118)
- SystemTimeToFileTime (Address: 0x18001b120)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x18001b158)
- EventProviderEnabled (Address: 0x18001b138)
- EventRegister (Address: 0x18001b140)
- EventSetInformation (Address: 0x18001b148)
- EventUnregister (Address: 0x18001b150)
- EventWriteTransfer (Address: 0x18001b130)
api-ms-win-security-accesshlpr-l1-1-0.dll
- FreeTransientObjectSecurityDescriptor (Address: 0x18001b168)
- QueryTransientObjectSecurityDescriptor (Address: 0x18001b170)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x18001b1b0)
- FreeSid (Address: 0x18001b180)
- GetLengthSid (Address: 0x18001b1a0)
- GetTokenInformation (Address: 0x18001b1a8)
- ImpersonateLoggedOnUser (Address: 0x18001b188)
- IsValidSid (Address: 0x18001b198)
- RevertToSelf (Address: 0x18001b190)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x18001b1c0)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x18001b1d0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18001b1e0)
- ConvertStringSidToSidW (Address: 0x18001b1d8)
api-ms-win-service-core-l1-1-0.dll
- RegisterServiceCtrlHandlerExW (Address: 0x18001b1f0)
- SetServiceStatus (Address: 0x18001b1f8)
ESENT.dll
- JetAddColumnW (Address: 0x18001ac48)
- JetAttachDatabaseW (Address: 0x18001acb8)
- JetBeginSessionW (Address: 0x18001acc0)
- JetBeginTransaction (Address: 0x18001ac58)
- JetCloseDatabase (Address: 0x18001aca0)
- JetCloseTable (Address: 0x18001ac78)
- JetCommitTransaction (Address: 0x18001ac80)
- JetCreateDatabaseW (Address: 0x18001acb0)
- JetCreateIndex2W (Address: 0x18001ac38)
- JetCreateInstanceW (Address: 0x18001acd0)
- JetCreateTableColumnIndexW (Address: 0x18001ac68)
- JetDelete (Address: 0x18001ac20)
- JetDetachDatabaseW (Address: 0x18001ac98)
- JetEndSession (Address: 0x18001ac90)
- JetGetErrorInfoW (Address: 0x18001ace0)
- JetGetTableColumnInfoW (Address: 0x18001ac50)
- JetInit (Address: 0x18001acc8)
- JetMakeKey (Address: 0x18001ac10)
- JetMove (Address: 0x18001ac00)
- JetOpenDatabaseW (Address: 0x18001aca8)
- JetOpenTableW (Address: 0x18001ac70)
- JetPrepareUpdate (Address: 0x18001ac30)
- JetRetrieveColumns (Address: 0x18001ac18)
- JetRollback (Address: 0x18001ac60)
- JetSeek (Address: 0x18001ac08)
- JetSetColumns (Address: 0x18001abf8)
- JetSetCurrentIndexW (Address: 0x18001ac40)
- JetSetSystemParameterW (Address: 0x18001acd8)
- JetTerm (Address: 0x18001ac88)
- JetUpdate (Address: 0x18001ac28)
msvcrt.dll
- __C_specific_handler (Address: 0x18001b2c0)
- __CxxFrameHandler3 (Address: 0x18001b228)
- __dllonexit (Address: 0x18001b218)
- _amsg_exit (Address: 0x18001b2b0)
- _CxxThrowException (Address: 0x18001b210)
- _errno (Address: 0x18001b250)
- _initterm (Address: 0x18001b240)
- _lock (Address: 0x18001b220)
- _onexit (Address: 0x18001b2f8)
- _purecall (Address: 0x18001b2d0)
- _unlock (Address: 0x18001b208)
- _vsnprintf_s (Address: 0x18001b288)
- _vsnwprintf (Address: 0x18001b2c8)
- _vsnwprintf_s (Address: 0x18001b248)
- _wcsdup (Address: 0x18001b2f0)
- _wcsicmp (Address: 0x18001b2d8)
- _XcptFilter (Address: 0x18001b2b8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x18001b280)
- ??0exception@@QEAA@XZ (Address: 0x18001b278)
- ??1exception@@UEAA@XZ (Address: 0x18001b270)
- ??1type_info@@UEAA@XZ (Address: 0x18001b2a0)
- ?terminate@@YAXXZ (Address: 0x18001b298)
- free (Address: 0x18001b2e0)
- malloc (Address: 0x18001b2e8)
- memcpy (Address: 0x18001b230)
- memcpy_s (Address: 0x18001b300)
- memmove (Address: 0x18001b238)
- memset (Address: 0x18001b308)
- swprintf_s (Address: 0x18001b258)
- toupper (Address: 0x18001b290)
- wcschr (Address: 0x18001b268)
- wcsncmp (Address: 0x18001b2a8)
- wcsstr (Address: 0x18001b260)
ntdll.dll
- NtOpenThreadToken (Address: 0x18001b320)
- RtlAllocateHeap (Address: 0x18001b348)
- RtlDeleteCriticalSection (Address: 0x18001b338)
- RtlFreeHeap (Address: 0x18001b340)
- RtlNtStatusToDosErrorNoTeb (Address: 0x18001b350)
- WinSqmAddToStreamEx (Address: 0x18001b330)
- WinSqmEndSession (Address: 0x18001b328)
- WinSqmStartSession (Address: 0x18001b318)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x18001ad30)
- NdrServerCall2 (Address: 0x18001ad40)
- NdrServerCallAll (Address: 0x18001ad38)
- RpcBindingVectorFree (Address: 0x18001ad48)
- RpcEpRegisterW (Address: 0x18001ad00)
- RpcEpUnregister (Address: 0x18001ad08)
- RpcImpersonateClient (Address: 0x18001ad18)
- RpcRevertToSelf (Address: 0x18001ad10)
- RpcServerInqBindings (Address: 0x18001acf8)
- RpcServerRegisterIf3 (Address: 0x18001ad28)
- RpcServerUnregisterIfEx (Address: 0x18001acf0)
- RpcServerUseProtseqW (Address: 0x18001ad20)