¿Para qué sirve la dll sechost.dll?

Host for SCM/SDDL/LSA Lookup APIs

Dependencias de la dll sechost.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\sechost.dll

File Type: DLL

  Image has the following dependencies:

    api-ms-win-core-crt-l1-1-0.dll
    api-ms-win-core-crt-l2-1-0.dll
    ntdll.dll
    api-ms-win-core-libraryloader-l1-2-0.dll
    api-ms-win-core-debug-l1-1-0.dll
    api-ms-win-core-errorhandling-l1-1-0.dll
    api-ms-win-core-handle-l1-1-0.dll
    api-ms-win-core-heap-l1-1-0.dll
    api-ms-win-core-processthreads-l1-1-0.dll
    api-ms-win-core-synch-l1-1-0.dll
    api-ms-win-core-util-l1-1-0.dll
    RPCRT4.dll
    api-ms-win-core-localization-l1-2-0.dll
    api-ms-win-core-registry-l1-1-0.dll
    api-ms-win-core-heap-l2-1-0.dll
    api-ms-win-security-base-l1-1-0.dll
    api-ms-win-core-string-l1-1-0.dll
    api-ms-win-core-wow64-l1-1-1.dll
    api-ms-win-core-synch-l1-2-0.dll
    api-ms-win-core-threadpool-l1-2-0.dll
    api-ms-win-core-sysinfo-l1-1-0.dll
    api-ms-win-core-file-l1-1-0.dll
    api-ms-win-core-memory-l1-1-0.dll
    api-ms-win-core-io-l1-1-0.dll
    api-ms-win-core-rtlsupport-l1-1-0.dll
    api-ms-win-core-processthreads-l1-1-1.dll
    api-ms-win-eventing-provider-l1-1-0.dll
    api-ms-win-core-delayload-l1-1-1.dll
    api-ms-win-core-delayload-l1-1-0.dll
    api-ms-win-core-apiquery-l1-1-0.dll

  Image has the following delay load dependencies:

    CRYPTBASE.dll
    USERENV.dll
    api-ms-win-core-winrt-string-l1-1-0.dll
    api-ms-win-core-com-l1-1-0.dll
    api-ms-win-core-winrt-error-l1-1-0.dll
    api-ms-win-core-winrt-l1-1-0.dll
    api-ms-win-security-base-private-l1-1-1.dll
    api-ms-win-appmodel-identity-l1-2-0.dll
    ext-ms-win-eventing-rundown-l1-1-0.dll
    ext-ms-win-security-chambers-l1-1-0.dll

  Summary

        4000 .data
        1000 .didat
        5000 .pdata
       27000 .rdata
        2000 .reloc
        2000 .rsrc
       65000 .text

Funciones que tiene la dll sechost.dll


3    0 0001BC00 AuditComputeEffectivePolicyBySid
4    1 0004FDA0 AuditEnumerateCategories
5    2 0004FEF0 AuditEnumeratePerUserPolicy
6    3 0004FF80 AuditEnumerateSubCategories
7    4 0000E850 AuditFree
8    5 000500F0 AuditLookupCategoryNameW
9    6 00050270 AuditLookupSubCategoryNameW
10    7 000503F0 AuditQueryGlobalSaclW
11    8 0001A0E0 AuditQueryPerUserPolicy
12    9 00050460 AuditQuerySecurity
13    A 0001A230 AuditQuerySystemPolicy
14    B 00050530 AuditSetGlobalSaclW
15    C 000505A0 AuditSetPerUserPolicy
16    D 00050650 AuditSetSecurity
17    E 000507B0 AuditSetSystemPolicy
18    F 000194C0 BuildSecurityDescriptorForSharingAccess
19   10 00018E30 BuildSecurityDescriptorForSharingAccessEx
20   11 0000D550 CapabilityCheck
21   12 00045270 CapabilityCheckForSingleSessionSku
22   13 00045B40 ChangeServiceConfig2A
23   14 0001C5D0 ChangeServiceConfig2W
24   15 00045CF0 ChangeServiceConfigA
25   16 0000E470 ChangeServiceConfigW
26   17 00008460 CloseServiceHandle
27   18 0000B900 CloseTrace
28   19 0000E780 ControlService
29   1A 00045FD0 ControlServiceExA
30   1B 0000E1B0 ControlServiceExW
31   1C 0004B610 ControlTraceA
32   1D 00009280 ControlTraceW
33   1E 0002C9E0 ConvertSDToStringSDRootDomainW
34   1F 00010DA0 ConvertSecurityDescriptorToStringSecurityDescriptorW
35   20 0000EB80 ConvertSidToStringSidW
36   21 0002CA60 ConvertStringSDToSDDomainA
37   22 0002CBA0 ConvertStringSDToSDDomainW
38   23 0002CC70 ConvertStringSDToSDRootDomainW
39   24 00010E40 ConvertStringSecurityDescriptorToSecurityDescriptorW
40   25 00011870 ConvertStringSidToSidW
41   26 000611E0 CreateIsolatedProcess
42   27 00061270 CreateIsolationContainer
43   28 00046130 CreateServiceA
44   29 00046890 CreateServiceEx
45   2A 00046D90 CreateServiceW
46   2B 00050AB0 CredBackupCredentials
47   2C 00050C50 CredDeleteA
48   2D 00050D40 CredDeleteW
49   2E 000520F0 CredEncryptAndMarshalBinaryBlob
50   2F 00050E30 CredEnumerateA
51   30 0000ECC0 CredEnumerateW
52   31 00050F90 CredFindBestCredentialA
53   32 000510D0 CredFindBestCredentialW
54   33 0000E850 CredFree
55   34 00051210 CredGetSessionTypes
56   35 000512A0 CredGetTargetInfoA
57   36 000513E0 CredGetTargetInfoW
58   37 00052120 CredIsMarshaledCredentialW
59   38 00052160 CredIsProtectedA
60   39 000196F0 CredIsProtectedW
61   3A 00052200 CredMarshalCredentialA
62   3B 0001ACC0 CredMarshalCredentialW
63   3C 000195E0 CredParseUserNameWithType
64   3D 00051520 CredProfileLoaded
65   3E 0000EB20 CredProfileLoadedEx
66   3F 00019F10 CredProfileUnloaded
67   40 00052270 CredProtectA
68   41 0001AA30 CredProtectEx
69   42 0001AA10 CredProtectW
70   43 000515A0 CredReadA
71   44 000516E0 CredReadByTokenHandle
72   45 00051830 CredReadDomainCredentialsA
73   46 00051990 CredReadDomainCredentialsW
74   47 00051B00 CredReadW
75   48 00051C40 CredRestoreCredentials
76   49 000523F0 CredUnmarshalCredentialA
77   4A 000197D0 CredUnmarshalCredentialW
78   4B 000524A0 CredUnprotectA
79   4C 0001B380 CredUnprotectEx
80   4D 00052640 CredUnprotectW
81   4E 00051DC0 CredWriteA
82   4F 00051EA0 CredWriteDomainCredentialsA
83   50 00051FD0 CredWriteDomainCredentialsW
84   51 0000E870 CredWriteW
85   52 0000E920 CredpConvertCredential
86   53 00010810 CredpConvertOneCredentialSize
87   54 00052660 CredpConvertTargetInfo
88   55 000528C0 CredpDecodeCredential
89   56 00052910 CredpEncodeCredential
90   57 00052990 CredpEncodeSecret
91   58 000612D0 DeleteIsolationContainer
92   59 00047250 DeleteService
93   5A 000097D0 EnableTraceEx2
94   5B 00019FB0 EnumDependentServicesW
95   5C 00007E10 EnumServicesStatusExW
96   5D 0000C910 EnumerateIdentityProviders
97   5E 0000E660 EnumerateTraceGuidsEx
98   5F 0004AD60 EtwQueryRealtimeConsumer
99   60 0004BC80 EventAccessControl
100   61 0004BCD0 EventAccessQuery
101   62 0004BF20 EventAccessRemove
102   63 000534C0 FreeContainer
103   64 000180F0 FreeTransientObjectSecurityDescriptor
104   65 0001BA80 GetDefaultIdentityProvider
105   66 00053510 GetEmbeddedContainerIsolationPolicy
106   67 0000D6D0 GetEmbeddedImageMitigationPolicy
107   68 0001B8F0 GetIdentityProviderInfoByGUID
108   69 0002A010 GetIdentityProviderInfoByName
109   6A 0000E070 GetServiceDirectory
110   6B 00019AD0 GetServiceDisplayNameW
111   6C 00019B90 GetServiceKeyNameW
112   6D 000472D0 GetServiceProcessToken
113   6E 0000E5F0 GetServiceRegistryStateKey
114   6F 000074A0 I_QueryTagInformation
115   70 0000E760 I_RegisterSvchostNotificationCallback
116   71 0001B9C0 I_ScBroadcastServiceControlMessage
117   72 0001C720 I_ScIsSecurityProcess
118   73 0000AA40 I_ScPnPGetServiceName
119   74 00007380 I_ScQueryServiceConfig
120   75 0000B920 I_ScRegisterDeviceNotification
121   76 00047360 I_ScRegisterPreshutdownRestart
122   77 00047430 I_ScReparseServiceDatabase
123   78 00048F30 I_ScRpcBindA
124   79 0001BB90 I_ScRpcBindW
125   7A 00007710 I_ScSendPnPMessage
126   7B 0001B9C0 I_ScSendTSMessage
1   7C 00045990 I_ScSetServiceBitsA
2   7D 0001C660 I_ScSetServiceBitsW
127   7E 0000E3C0 I_ScUnregisterDeviceNotification
128   7F 0000AA90 I_ScValidatePnPService
129   80 000100F0 LocalGetConditionForString
130   81 0002E510 LocalGetReferencedTokenTypesForCondition
131   82 0002F390 LocalGetStringForCondition
132   83 00045480 LocalRpcBindingCreateWithSecurity
133   84 00045630 LocalRpcBindingSetAuthInfoEx
134   85 0002A110 LookupAccountNameLocalA
135   86 00014CA0 LookupAccountNameLocalW
136   87 0002A290 LookupAccountSidLocalA
137   88 00015130 LookupAccountSidLocalW
138   89 0004E370 LsaAddAccountRights
139   8A 0000F720 LsaClose
140   8B 0004EEF0 LsaCreateSecret
141   8C 0004E5A0 LsaDelete
142   8D 0001A170 LsaEnumerateAccountRights
143   8E 0004E410 LsaEnumerateAccountsWithUserRight
144   8F 0000D6B0 LsaFreeMemory
145   90 0000EE70 LsaICLookupNames
146   91 0004E640 LsaICLookupNamesWithCreds
147   92 0000F4E0 LsaICLookupSids
148   93 0004E850 LsaICLookupSidsWithCreds
149   94 00015630 LsaLookupClose
150   95 0000D6B0 LsaLookupFreeMemory
151   96 00014C00 LsaLookupGetDomainInfo
152   97 0000DF60 LsaLookupManageSidNameMapping
153   98 0000EE00 LsaLookupNames2
154   99 000156A0 LsaLookupOpenLocalPolicy
155   9A 0000F330 LsaLookupSids
156   9B 0004EAA0 LsaLookupSids2
157   9C 0001BDC0 LsaLookupTranslateNames
158   9D 0000D780 LsaLookupTranslateSids
159   9E 0000D8E0 LsaLookupUserAccountType
160   9F 0000F7B0 LsaOpenPolicy
161   A0 0004F000 LsaOpenSecret
162   A1 0000F1F0 LsaQueryInformationPolicy
163   A2 0004F110 LsaQuerySecret
164   A3 0004E4F0 LsaRemoveAccountRights
165   A4 0001A2B0 LsaRetrievePrivateData
166   A5 0004EAB0 LsaSetInformationPolicy
167   A6 0004F5B0 LsaSetSecret
168   A7 0004F800 LsaStorePrivateData
169   A8 00006A70 NotifyServiceStatusChange
170   A9 00019EF0 NotifyServiceStatusChangeA
171   AA 00006A70 NotifyServiceStatusChangeW
172   AB 000081B0 OpenSCManagerA
173   AC 00008360 OpenSCManagerW
174   AD 00019E20 OpenServiceA
175   AE 000082E0 OpenServiceW
176   AF 0000AED0 OpenTraceW
177   B0 0000B5A0 ProcessTrace
178   B1 0004C140 QueryAllTracesA
179   B2 000013F0 QueryAllTracesW
180   B3 000474F0 QueryLocalUserServiceName
181   B4 00047870 QueryServiceConfig2A
182   B5 00007850 QueryServiceConfig2W
183   B6 00047CE0 QueryServiceConfigA
184   B7 00008090 QueryServiceConfigW
185   B8 00048310 QueryServiceDynamicInformation
186   B9 00047E70 QueryServiceObjectSecurity
187   BA 00007B30 QueryServiceStatus
188   BB 00008240 QueryServiceStatusEx
189   BC 0004ADE0 QueryTraceProcessingHandle
190   BD 00017F50 QueryTransientObjectSecurityDescriptor
191   BE 00007C90 QueryUserServiceName
192   BF 00047F50 QueryUserServiceNameForContext
193   C0 000483B0 RegisterServiceCtrlHandlerA
194   C1 00019CE0 RegisterServiceCtrlHandlerExA
195   C2 000054F0 RegisterServiceCtrlHandlerExW
196   C3 0000E830 RegisterServiceCtrlHandlerW
197   C4          RegisterTraceGuidsA (forwarded to NTDLL.EtwRegisterTraceGuidsA)
198   C5 0000D310 ReleaseIdentityProviderEnumContext
199   C6 0004B000 RemoveTraceCallback
200   C7 0000D470 RpcClientCapabilityCheck
201   C8 00045740 SetLocalRpcServerInterfaceSecurity
202   C9 00045820 SetLocalRpcServerProtseqSecurity
203   CA 0001C4C0 SetServiceObjectSecurity
204   CB 00007B90 SetServiceStatus
205   CC 0004B0F0 SetTraceCallback
206   CD 00019E90 StartServiceA
207   CE 00048420 StartServiceCtrlDispatcherA
208   CF 00005A60 StartServiceCtrlDispatcherW
209   D0 00005480 StartServiceW
210   D1 0004C150 StartTraceA
211   D2 0000A270 StartTraceW
212   D3 0001BB70 StopTraceW
213   D4 0000DE60 SubscribeServiceChangeNotifications
214   D5 0004C680 TraceQueryInformation
215   D6 0004CA30 TraceSetInformation
216   D7 0000E7F0 UnsubscribeServiceChangeNotifications
217   D8 0000DAF0 WaitServiceState

Información avanzada sobre funciones que tiene la dll sechost.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\sechost.dll

File Type: DLL

  Section contains the following exports for SECHOST.dll

    00000000 characteristics
    18CB116B time date stamp
        0.00 version
           1 ordinal base
         217 number of functions
         217 number of names

    ordinal hint RVA      name

          3    0 0001BC00 AuditComputeEffectivePolicyBySid
          4    1 0004FDA0 AuditEnumerateCategories
          5    2 0004FEF0 AuditEnumeratePerUserPolicy
          6    3 0004FF80 AuditEnumerateSubCategories
          7    4 0000E850 AuditFree
          8    5 000500F0 AuditLookupCategoryNameW
          9    6 00050270 AuditLookupSubCategoryNameW
         10    7 000503F0 AuditQueryGlobalSaclW
         11    8 0001A0E0 AuditQueryPerUserPolicy
         12    9 00050460 AuditQuerySecurity
         13    A 0001A230 AuditQuerySystemPolicy
         14    B 00050530 AuditSetGlobalSaclW
         15    C 000505A0 AuditSetPerUserPolicy
         16    D 00050650 AuditSetSecurity
         17    E 000507B0 AuditSetSystemPolicy
         18    F 000194C0 BuildSecurityDescriptorForSharingAccess
         19   10 00018E30 BuildSecurityDescriptorForSharingAccessEx
         20   11 0000D550 CapabilityCheck
         21   12 00045270 CapabilityCheckForSingleSessionSku
         22   13 00045B40 ChangeServiceConfig2A
         23   14 0001C5D0 ChangeServiceConfig2W
         24   15 00045CF0 ChangeServiceConfigA
         25   16 0000E470 ChangeServiceConfigW
         26   17 00008460 CloseServiceHandle
         27   18 0000B900 CloseTrace
         28   19 0000E780 ControlService
         29   1A 00045FD0 ControlServiceExA
         30   1B 0000E1B0 ControlServiceExW
         31   1C 0004B610 ControlTraceA
         32   1D 00009280 ControlTraceW
         33   1E 0002C9E0 ConvertSDToStringSDRootDomainW
         34   1F 00010DA0 ConvertSecurityDescriptorToStringSecurityDescriptorW
         35   20 0000EB80 ConvertSidToStringSidW
         36   21 0002CA60 ConvertStringSDToSDDomainA
         37   22 0002CBA0 ConvertStringSDToSDDomainW
         38   23 0002CC70 ConvertStringSDToSDRootDomainW
         39   24 00010E40 ConvertStringSecurityDescriptorToSecurityDescriptorW
         40   25 00011870 ConvertStringSidToSidW
         41   26 000611E0 CreateIsolatedProcess
         42   27 00061270 CreateIsolationContainer
         43   28 00046130 CreateServiceA
         44   29 00046890 CreateServiceEx
         45   2A 00046D90 CreateServiceW
         46   2B 00050AB0 CredBackupCredentials
         47   2C 00050C50 CredDeleteA
         48   2D 00050D40 CredDeleteW
         49   2E 000520F0 CredEncryptAndMarshalBinaryBlob
         50   2F 00050E30 CredEnumerateA
         51   30 0000ECC0 CredEnumerateW
         52   31 00050F90 CredFindBestCredentialA
         53   32 000510D0 CredFindBestCredentialW
         54   33 0000E850 CredFree
         55   34 00051210 CredGetSessionTypes
         56   35 000512A0 CredGetTargetInfoA
         57   36 000513E0 CredGetTargetInfoW
         58   37 00052120 CredIsMarshaledCredentialW
         59   38 00052160 CredIsProtectedA
         60   39 000196F0 CredIsProtectedW
         61   3A 00052200 CredMarshalCredentialA
         62   3B 0001ACC0 CredMarshalCredentialW
         63   3C 000195E0 CredParseUserNameWithType
         64   3D 00051520 CredProfileLoaded
         65   3E 0000EB20 CredProfileLoadedEx
         66   3F 00019F10 CredProfileUnloaded
         67   40 00052270 CredProtectA
         68   41 0001AA30 CredProtectEx
         69   42 0001AA10 CredProtectW
         70   43 000515A0 CredReadA
         71   44 000516E0 CredReadByTokenHandle
         72   45 00051830 CredReadDomainCredentialsA
         73   46 00051990 CredReadDomainCredentialsW
         74   47 00051B00 CredReadW
         75   48 00051C40 CredRestoreCredentials
         76   49 000523F0 CredUnmarshalCredentialA
         77   4A 000197D0 CredUnmarshalCredentialW
         78   4B 000524A0 CredUnprotectA
         79   4C 0001B380 CredUnprotectEx
         80   4D 00052640 CredUnprotectW
         81   4E 00051DC0 CredWriteA
         82   4F 00051EA0 CredWriteDomainCredentialsA
         83   50 00051FD0 CredWriteDomainCredentialsW
         84   51 0000E870 CredWriteW
         85   52 0000E920 CredpConvertCredential
         86   53 00010810 CredpConvertOneCredentialSize
         87   54 00052660 CredpConvertTargetInfo
         88   55 000528C0 CredpDecodeCredential
         89   56 00052910 CredpEncodeCredential
         90   57 00052990 CredpEncodeSecret
         91   58 000612D0 DeleteIsolationContainer
         92   59 00047250 DeleteService
         93   5A 000097D0 EnableTraceEx2
         94   5B 00019FB0 EnumDependentServicesW
         95   5C 00007E10 EnumServicesStatusExW
         96   5D 0000C910 EnumerateIdentityProviders
         97   5E 0000E660 EnumerateTraceGuidsEx
         98   5F 0004AD60 EtwQueryRealtimeConsumer
         99   60 0004BC80 EventAccessControl
        100   61 0004BCD0 EventAccessQuery
        101   62 0004BF20 EventAccessRemove
        102   63 000534C0 FreeContainer
        103   64 000180F0 FreeTransientObjectSecurityDescriptor
        104   65 0001BA80 GetDefaultIdentityProvider
        105   66 00053510 GetEmbeddedContainerIsolationPolicy
        106   67 0000D6D0 GetEmbeddedImageMitigationPolicy
        107   68 0001B8F0 GetIdentityProviderInfoByGUID
        108   69 0002A010 GetIdentityProviderInfoByName
        109   6A 0000E070 GetServiceDirectory
        110   6B 00019AD0 GetServiceDisplayNameW
        111   6C 00019B90 GetServiceKeyNameW
        112   6D 000472D0 GetServiceProcessToken
        113   6E 0000E5F0 GetServiceRegistryStateKey
        114   6F 000074A0 I_QueryTagInformation
        115   70 0000E760 I_RegisterSvchostNotificationCallback
        116   71 0001B9C0 I_ScBroadcastServiceControlMessage
        117   72 0001C720 I_ScIsSecurityProcess
        118   73 0000AA40 I_ScPnPGetServiceName
        119   74 00007380 I_ScQueryServiceConfig
        120   75 0000B920 I_ScRegisterDeviceNotification
        121   76 00047360 I_ScRegisterPreshutdownRestart
        122   77 00047430 I_ScReparseServiceDatabase
        123   78 00048F30 I_ScRpcBindA
        124   79 0001BB90 I_ScRpcBindW
        125   7A 00007710 I_ScSendPnPMessage
        126   7B 0001B9C0 I_ScSendTSMessage
          1   7C 00045990 I_ScSetServiceBitsA
          2   7D 0001C660 I_ScSetServiceBitsW
        127   7E 0000E3C0 I_ScUnregisterDeviceNotification
        128   7F 0000AA90 I_ScValidatePnPService
        129   80 000100F0 LocalGetConditionForString
        130   81 0002E510 LocalGetReferencedTokenTypesForCondition
        131   82 0002F390 LocalGetStringForCondition
        132   83 00045480 LocalRpcBindingCreateWithSecurity
        133   84 00045630 LocalRpcBindingSetAuthInfoEx
        134   85 0002A110 LookupAccountNameLocalA
        135   86 00014CA0 LookupAccountNameLocalW
        136   87 0002A290 LookupAccountSidLocalA
        137   88 00015130 LookupAccountSidLocalW
        138   89 0004E370 LsaAddAccountRights
        139   8A 0000F720 LsaClose
        140   8B 0004EEF0 LsaCreateSecret
        141   8C 0004E5A0 LsaDelete
        142   8D 0001A170 LsaEnumerateAccountRights
        143   8E 0004E410 LsaEnumerateAccountsWithUserRight
        144   8F 0000D6B0 LsaFreeMemory
        145   90 0000EE70 LsaICLookupNames
        146   91 0004E640 LsaICLookupNamesWithCreds
        147   92 0000F4E0 LsaICLookupSids
        148   93 0004E850 LsaICLookupSidsWithCreds
        149   94 00015630 LsaLookupClose
        150   95 0000D6B0 LsaLookupFreeMemory
        151   96 00014C00 LsaLookupGetDomainInfo
        152   97 0000DF60 LsaLookupManageSidNameMapping
        153   98 0000EE00 LsaLookupNames2
        154   99 000156A0 LsaLookupOpenLocalPolicy
        155   9A 0000F330 LsaLookupSids
        156   9B 0004EAA0 LsaLookupSids2
        157   9C 0001BDC0 LsaLookupTranslateNames
        158   9D 0000D780 LsaLookupTranslateSids
        159   9E 0000D8E0 LsaLookupUserAccountType
        160   9F 0000F7B0 LsaOpenPolicy
        161   A0 0004F000 LsaOpenSecret
        162   A1 0000F1F0 LsaQueryInformationPolicy
        163   A2 0004F110 LsaQuerySecret
        164   A3 0004E4F0 LsaRemoveAccountRights
        165   A4 0001A2B0 LsaRetrievePrivateData
        166   A5 0004EAB0 LsaSetInformationPolicy
        167   A6 0004F5B0 LsaSetSecret
        168   A7 0004F800 LsaStorePrivateData
        169   A8 00006A70 NotifyServiceStatusChange
        170   A9 00019EF0 NotifyServiceStatusChangeA
        171   AA 00006A70 NotifyServiceStatusChangeW
        172   AB 000081B0 OpenSCManagerA
        173   AC 00008360 OpenSCManagerW
        174   AD 00019E20 OpenServiceA
        175   AE 000082E0 OpenServiceW
        176   AF 0000AED0 OpenTraceW
        177   B0 0000B5A0 ProcessTrace
        178   B1 0004C140 QueryAllTracesA
        179   B2 000013F0 QueryAllTracesW
        180   B3 000474F0 QueryLocalUserServiceName
        181   B4 00047870 QueryServiceConfig2A
        182   B5 00007850 QueryServiceConfig2W
        183   B6 00047CE0 QueryServiceConfigA
        184   B7 00008090 QueryServiceConfigW
        185   B8 00048310 QueryServiceDynamicInformation
        186   B9 00047E70 QueryServiceObjectSecurity
        187   BA 00007B30 QueryServiceStatus
        188   BB 00008240 QueryServiceStatusEx
        189   BC 0004ADE0 QueryTraceProcessingHandle
        190   BD 00017F50 QueryTransientObjectSecurityDescriptor
        191   BE 00007C90 QueryUserServiceName
        192   BF 00047F50 QueryUserServiceNameForContext
        193   C0 000483B0 RegisterServiceCtrlHandlerA
        194   C1 00019CE0 RegisterServiceCtrlHandlerExA
        195   C2 000054F0 RegisterServiceCtrlHandlerExW
        196   C3 0000E830 RegisterServiceCtrlHandlerW
        197   C4          RegisterTraceGuidsA (forwarded to NTDLL.EtwRegisterTraceGuidsA)
        198   C5 0000D310 ReleaseIdentityProviderEnumContext
        199   C6 0004B000 RemoveTraceCallback
        200   C7 0000D470 RpcClientCapabilityCheck
        201   C8 00045740 SetLocalRpcServerInterfaceSecurity
        202   C9 00045820 SetLocalRpcServerProtseqSecurity
        203   CA 0001C4C0 SetServiceObjectSecurity
        204   CB 00007B90 SetServiceStatus
        205   CC 0004B0F0 SetTraceCallback
        206   CD 00019E90 StartServiceA
        207   CE 00048420 StartServiceCtrlDispatcherA
        208   CF 00005A60 StartServiceCtrlDispatcherW
        209   D0 00005480 StartServiceW
        210   D1 0004C150 StartTraceA
        211   D2 0000A270 StartTraceW
        212   D3 0001BB70 StopTraceW
        213   D4 0000DE60 SubscribeServiceChangeNotifications
        214   D5 0004C680 TraceQueryInformation
        215   D6 0004CA30 TraceSetInformation
        216   D7 0000E7F0 UnsubscribeServiceChangeNotifications
        217   D8 0000DAF0 WaitServiceState

  Summary

        4000 .data
        1000 .didat
        5000 .pdata
       27000 .rdata
        2000 .reloc
        2000 .rsrc
       65000 .text

Integridad de la dll sechost.dll



Algorithm       Hash                                                                   Path                                         
---------       ----                                                                   ----                                         
SHA256          94329C71BAF91A6D31B55D7E1F0985288E7FDC408317E2764D1E9670B31C7ED8       C:\Windows\System32\sechost.dll              


Detalles sobre el fichero dll sechost.dll




PSPath            : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32\sechost.dll
PSParentPath      : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32
PSChildName       : sechost.dll
PSDrive           : C
PSProvider        : Microsoft.PowerShell.Core\FileSystem
PSIsContainer     : False
Mode              : -a----
VersionInfo       : File:             C:\Windows\System32\sechost.dll
                    InternalName:     sechost.dll
                    OriginalFilename: sechost.dll.mui
                    FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
                    FileDescription:  Host for SCM/SDDL/LSA Lookup APIs
                    Product:          Microsoft® Windows® Operating System
                    ProductVersion:   10.0.19041.1
                    Debug:            False
                    Patched:          False
                    PreRelease:       False
                    PrivateBuild:     False
                    SpecialBuild:     False
                    Language:         Inglés (Estados Unidos)
                    
BaseName          : sechost
Target            : {C:\Windows\WinSxS\amd64_microsoft-windows-sechost_31bf3856ad364e35_10.0.19041.546_none_65bc23de2bc58136\sechost
                    .dll}
LinkType          : HardLink
Name              : sechost.dll
Length            : 624480
DirectoryName     : C:\Windows\System32
Directory         : C:\Windows\System32
IsReadOnly        : False
Exists            : True
FullName          : C:\Windows\System32\sechost.dll
Extension         : .dll
CreationTime      : 21/11/2020 8:44:35
CreationTimeUtc   : 21/11/2020 7:44:35
LastAccessTime    : 03/12/2020 14:55:28
LastAccessTimeUtc : 03/12/2020 13:55:28
LastWriteTime     : 21/11/2020 8:44:35
LastWriteTimeUtc  : 21/11/2020 7:44:35
Attributes        : Archive



Procesos que utilizan la dll sechost.dll


ApplicationFrameHost
AsusTPCenter
AsusTPLoader
chrome
chrome
chrome
chrome
chrome
chrome
chrome
chrome
conhost
conhost
conhost
Cortana
dllhost
esif_assist_64
explorer
igfxEM
igfxHK
igfxTray
KinectService
Microsoft.Photos
powershell_ise
powershell_ise
powershell_ise
RAVBg64
RAVCpl64
RuntimeBroker
RuntimeBroker
RuntimeBroker
RuntimeBroker
RuntimeBroker
RuntimeBroker
RuntimeBroker
RuntimeBroker
SearchApp
ShellExperienceHost
sihost
SpeechRuntime
StartMenuExperienceHost
svchost
svchost
svchost
svchost
SystemSettings
taskhostw
TextInputHost
UserOOBEBroker
Video.UI
YourPhone