¿Para qué sirve la dll witnesswmiv2provider.dll?

Witness Service WMIv2 Provider

Dependencias de la dll witnesswmiv2provider.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\witnesswmiv2provider.dll

File Type: DLL

  Image has the following dependencies:

    msvcrt.dll
    api-ms-win-core-sysinfo-l1-1-0.dll
    api-ms-win-core-errorhandling-l1-1-0.dll
    api-ms-win-core-libraryloader-l1-2-0.dll
    api-ms-win-security-base-l1-1-0.dll
    RPCRT4.dll
    api-ms-win-security-lsalookup-l2-1-0.dll
    api-ms-win-core-processthreads-l1-1-0.dll
    api-ms-win-eventing-classicprovider-l1-1-0.dll
    api-ms-win-core-handle-l1-1-0.dll
    api-ms-win-eventing-provider-l1-1-0.dll
    api-ms-win-core-heap-l1-1-0.dll
    api-ms-win-core-localization-l1-2-0.dll
    api-ms-win-core-synch-l1-2-0.dll
    api-ms-win-core-rtlsupport-l1-1-0.dll
    api-ms-win-core-profile-l1-1-0.dll
    ext-ms-win-cluster-clusapi-l1-1-0.dll
    ext-ms-win-cluster-resutils-l1-1-0.dll

  Summary

        1000 .data
        1000 .pdata
        5000 .rdata
        1000 .reloc
        1000 .rsrc
        4000 .text

Funciones que tiene la dll witnesswmiv2provider.dll


1    0 00001490 DllCanUnloadNow
2    1 000014D0 DllGetClassObject
3    2 00001180 DllMain
4    3 000013F0 DllRegisterServer
5    4 00001440 DllUnregisterServer
6    5 000011E0 GetProviderClassID
7    6 00001120 MI_Main
8    7 00002460 WitnessWmiInitialize
9    8 00002600 WitnessWmiTerminate

Información avanzada sobre funciones que tiene la dll witnesswmiv2provider.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\witnesswmiv2provider.dll

File Type: DLL

  Section contains the following exports for WitnessWmiv2Provider.dll

    00000000 characteristics
    9E0B5E21 time date stamp
        0.00 version
           1 ordinal base
           9 number of functions
           9 number of names

    ordinal hint RVA      name

          1    0 00001490 DllCanUnloadNow
          2    1 000014D0 DllGetClassObject
          3    2 00001180 DllMain
          4    3 000013F0 DllRegisterServer
          5    4 00001440 DllUnregisterServer
          6    5 000011E0 GetProviderClassID
          7    6 00001120 MI_Main
          8    7 00002460 WitnessWmiInitialize
          9    8 00002600 WitnessWmiTerminate

  Summary

        1000 .data
        1000 .pdata
        5000 .rdata
        1000 .reloc
        1000 .rsrc
        4000 .text

Integridad de la dll witnesswmiv2provider.dll



Algorithm       Hash                                                                   Path                                                           
---------       ----                                                                   ----                                                           
SHA256          F76FDFA637ED749D4E2087BA93C6F5D5C6C3066B622B70EEF95F5056F26B5651       C:\Windows\System32\witnesswmiv2provider.dll                   


Detalles sobre el fichero dll witnesswmiv2provider.dll




PSPath            : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32\witnesswmiv2provider.dll
PSParentPath      : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32
PSChildName       : witnesswmiv2provider.dll
PSDrive           : C
PSProvider        : Microsoft.PowerShell.Core\FileSystem
PSIsContainer     : False
Mode              : -a----
VersionInfo       : File:             C:\Windows\System32\witnesswmiv2provider.dll
                    InternalName:     WitnessWmiv2Provider.dll
                    OriginalFilename: WitnessWmiv2Provider.dll.mui
                    FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
                    FileDescription:  Witness Service WMIv2 Provider
                    Product:          Microsoft® Windows® Operating System
                    ProductVersion:   10.0.19041.1
                    Debug:            False
                    Patched:          False
                    PreRelease:       False
                    PrivateBuild:     False
                    SpecialBuild:     False
                    Language:         Español (España, internacional)
                    
BaseName          : witnesswmiv2provider
Target            : {C:\Windows\WinSxS\amd64_microsoft-windows-smbwitnessservice-apis_31bf3856ad364e35_10.0.19041.1_none_5a0c8dfc89473d73\witnesswmiv2
                    provider.dll}
LinkType          : HardLink
Name              : witnesswmiv2provider.dll
Length            : 36864
DirectoryName     : C:\Windows\System32
Directory         : C:\Windows\System32
IsReadOnly        : False
Exists            : True
FullName          : C:\Windows\System32\witnesswmiv2provider.dll
Extension         : .dll
CreationTime      : 07/12/2019 10:08:58
CreationTimeUtc   : 07/12/2019 9:08:58
LastAccessTime    : 03/12/2020 17:38:48
LastAccessTimeUtc : 03/12/2020 16:38:48
LastWriteTime     : 07/12/2019 10:08:58
LastWriteTimeUtc  : 07/12/2019 9:08:58
Attributes        : Archive



Procesos que utilizan la dll witnesswmiv2provider.dll