¿Para qué sirve la dll sysmain.dll?

Host de servicio SysMain

Dependencias de la dll sysmain.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\sysmain.dll

File Type: DLL

  Image has the following dependencies:

    msvcrt.dll
    ntdll.dll
    api-ms-win-core-synch-l1-1-0.dll
    api-ms-win-core-registry-l1-1-0.dll
    api-ms-win-eventing-provider-l1-1-0.dll
    api-ms-win-core-synch-l1-2-0.dll
    api-ms-win-core-errorhandling-l1-1-0.dll
    api-ms-win-core-libraryloader-l1-2-0.dll
    api-ms-win-core-handle-l1-1-0.dll
    api-ms-win-core-debug-l1-1-0.dll
    api-ms-win-core-sysinfo-l1-1-0.dll
    api-ms-win-core-libraryloader-l1-2-1.dll
    api-ms-win-core-processthreads-l1-1-0.dll
    api-ms-win-core-heap-l2-1-0.dll
    api-ms-win-core-memory-l1-1-0.dll
    api-ms-win-core-processthreads-l1-1-1.dll
    api-ms-win-security-base-l1-1-0.dll
    api-ms-win-core-file-l1-1-0.dll
    api-ms-win-core-heap-l1-1-0.dll
    api-ms-win-core-string-l1-1-0.dll
    api-ms-win-core-profile-l1-1-0.dll
    api-ms-win-core-timezone-l1-1-0.dll
    api-ms-win-core-synch-l1-2-1.dll
    api-ms-win-core-io-l1-1-0.dll
    api-ms-win-core-psapi-l1-1-0.dll
    api-ms-win-core-processenvironment-l1-1-0.dll
    api-ms-win-eventing-classicprovider-l1-1-0.dll
    api-ms-win-devices-config-l1-1-1.dll
    api-ms-win-core-threadpool-l1-2-0.dll
    api-ms-win-core-file-l1-2-0.dll
    api-ms-win-eventing-controller-l1-1-0.dll
    RPCRT4.dll
    api-ms-win-core-localization-l1-2-0.dll
    api-ms-win-core-io-l1-1-1.dll
    api-ms-win-eventing-consumer-l1-1-0.dll
    api-ms-win-core-datetime-l1-1-0.dll
    api-ms-win-core-file-l2-1-0.dll
    api-ms-win-core-kernel32-legacy-l1-1-0.dll
    api-ms-win-core-sidebyside-l1-1-0.dll
    UMPDC.dll
    POWRPROF.dll
    api-ms-win-core-psm-key-l1-1-0.dll
    api-ms-win-core-featurestaging-l1-1-0.dll
    api-ms-win-core-delayload-l1-1-1.dll
    api-ms-win-core-delayload-l1-1-0.dll
    api-ms-win-core-apiquery-l1-1-0.dll

  Image has the following delay load dependencies:

    api-ms-win-service-core-l1-1-0.dll
    OLEAUT32.dll
    api-ms-win-security-sddl-l1-1-0.dll
    api-ms-win-service-management-l1-1-0.dll
    api-ms-win-service-management-l2-1-0.dll
    api-ms-win-service-winsvc-l1-1-0.dll
    api-ms-win-power-setting-l1-1-0.dll
    api-ms-win-core-com-l1-1-0.dll
    api-ms-win-service-core-l1-1-1.dll
    api-ms-win-security-provider-l1-1-0.dll
    api-ms-win-core-registry-l2-1-0.dll
    api-ms-win-service-private-l1-1-0.dll
    DEVOBJ.dll
    api-ms-win-appmodel-runtime-l1-1-1.dll
    api-ms-win-appmodel-runtime-l1-1-0.dll
    ext-ms-win-session-wtsapi32-l1-1-0.dll
    ext-ms-win-advapi32-idletask-l1-1-0.dll
    ext-ms-win-session-usertoken-l1-1-0.dll
    ext-ms-win-setupapi-classinstallers-l1-1-0.dll
    ext-ms-win-setupapi-classinstallers-l1-1-2.dll
    ext-ms-win-ole32-bindctx-l1-1-0.dll
    ext-ms-win-resourcemanager-crm-l1-2-0.dll
    RMCLIENT.dll

  Summary

        3000 .data
        1000 .didat
        8000 .pdata
       1D000 .rdata
        1000 .reloc
        B000 .rsrc
       C5000 .text

Funciones que tiene la dll sysmain.dll


2    0 00069810 AgGlLoad
3    1 0006A540 AgPdLoad
4    2 00071630 AgTwLoad
5    3 0004D4E0 CloseReadyBoostPerfData
6    4 00067920 CollectReadyBoostPerfData
7    5 000687F0 DllCanUnloadNow
8    6 00068830 DllGetClassObject
9    7 000689C0 DllRegisterServer
10    8 00068A00 DllUnregisterServer
11    9 00068A40 GetProviderClassID
12    A 00068200 MI_Main
13    B 00067A50 OpenReadyBoostPerfData
14    C 0007A5F0 PfSvSysprepCleanup
15    D 0007ABC0 PfSvUnattendCallback
1    E 00068420 PfSvWsSwapAssessmentTask
16    F 00067EF0 SysMtServiceMain

Información avanzada sobre funciones que tiene la dll sysmain.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\sysmain.dll

File Type: DLL

  Section contains the following exports for sysmain.dll

    00000000 characteristics
    93137B7D time date stamp
        0.00 version
           1 ordinal base
          16 number of functions
          16 number of names

    ordinal hint RVA      name

          2    0 00069810 AgGlLoad
          3    1 0006A540 AgPdLoad
          4    2 00071630 AgTwLoad
          5    3 0004D4E0 CloseReadyBoostPerfData
          6    4 00067920 CollectReadyBoostPerfData
          7    5 000687F0 DllCanUnloadNow
          8    6 00068830 DllGetClassObject
          9    7 000689C0 DllRegisterServer
         10    8 00068A00 DllUnregisterServer
         11    9 00068A40 GetProviderClassID
         12    A 00068200 MI_Main
         13    B 00067A50 OpenReadyBoostPerfData
         14    C 0007A5F0 PfSvSysprepCleanup
         15    D 0007ABC0 PfSvUnattendCallback
          1    E 00068420 PfSvWsSwapAssessmentTask
         16    F 00067EF0 SysMtServiceMain

  Summary

        3000 .data
        1000 .didat
        8000 .pdata
       1D000 .rdata
        1000 .reloc
        B000 .rsrc
       C5000 .text

Integridad de la dll sysmain.dll



Algorithm       Hash                                                                   Path                                         
---------       ----                                                                   ----                                         
SHA256          DD606D82397D7C15DF560075B083A4EFBDEECD8975E7FD44283BF95BEBEAF581       C:\Windows\System32\sysmain.dll              


Detalles sobre el fichero dll sysmain.dll




PSPath            : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32\sysmain.dll
PSParentPath      : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32
PSChildName       : sysmain.dll
PSDrive           : C
PSProvider        : Microsoft.PowerShell.Core\FileSystem
PSIsContainer     : False
Mode              : -a----
VersionInfo       : File:             C:\Windows\System32\sysmain.dll
                    InternalName:     SysMain
                    OriginalFilename: sysmain.dll.mui
                    FileVersion:      10.0.19041.561 (WinBuild.160101.0800)
                    FileDescription:  Host de servicio SysMain
                    Product:          Sistema operativo Microsoft® Windows®
                    ProductVersion:   10.0.19041.561
                    Debug:            False
                    Patched:          False
                    PreRelease:       False
                    PrivateBuild:     False
                    SpecialBuild:     False
                    Language:         Español (España, internacional)
                    
BaseName          : sysmain
Target            : {C:\Windows\WinSxS\amd64_microsoft-windows-s..tenanceservice-core_31bf3856ad364e35_10.0.19041.546_none_ae0134ca7
                    406e2a4\sysmain.dll}
LinkType          : HardLink
Name              : sysmain.dll
Length            : 1006592
DirectoryName     : C:\Windows\System32
Directory         : C:\Windows\System32
IsReadOnly        : False
Exists            : True
FullName          : C:\Windows\System32\sysmain.dll
Extension         : .dll
CreationTime      : 21/11/2020 8:47:47
CreationTimeUtc   : 21/11/2020 7:47:47
LastAccessTime    : 03/12/2020 15:39:21
LastAccessTimeUtc : 03/12/2020 14:39:21
LastWriteTime     : 21/11/2020 8:47:47
LastWriteTimeUtc  : 21/11/2020 7:47:47
Attributes        : Archive



Procesos que utilizan la dll sysmain.dll