-
-
Save enigma0x3/2e549345e7f0ac88fad130e2444bb702 to your computer and use it in GitHub Desktop.
RPC interfaces RS5
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
-------------------------------------------------------------------------------- | |
<WinProcess "smss.exe" pid 368 at 0x5306908L> | |
64 | |
[!!] Invalid rpcrt4 base: 0x0 vs 0x7ffec24f0000 | |
-------------------------------------------------------------------------------- | |
<WinProcess "csrss.exe" pid 472 at 0x5306e48L> | |
64 | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "wininit.exe" pid 548 at 0x5306780L> | |
64 | |
Interfaces : | |
RPC 76f226c3-ec14-4325-8a99-6a46348418ae (1.0) -- C:\windows\system32\wininit.exe | |
0 -> I_WMsgkSendMessage | |
1 -> I_WMsgkSendPSPMessage | |
RPC 894de0c0-0d55-11d3-a322-00c04fa321a1 (1.0) -- C:\windows\system32\wininit.exe | |
0 -> s_BaseInitiateShutdown | |
1 -> s_BaseAbortShutdown | |
2 -> s_BaseInitiateShutdownEx | |
RPC d95afe70-a6d5-4259-822e-2c84da1ddb0d (1.0) -- C:\windows\system32\wininit.exe | |
0 -> s_WsdrInitiateShutdown | |
1 -> s_WsdrAbortShutdown | |
2 -> s_WsdrCheckForHiberboot | |
RPC 76f226c3-ec14-4325-8a99-6a46348418af (1.0) -- C:\windows\system32\wininit.exe | |
0 -> I_WMsgSendMessage | |
1 -> I_WMsgSendPSPMessage | |
2 -> I_WMsgSendNotifyMessage | |
3 -> I_WMsgSendReconnectionUpdateMessage | |
Endpoints : | |
ncalrpc : WMsgKRpc0551A0 | |
ncacn_np : \PIPE\InitShutdown | |
ncalrpc : WindowsShutdown | |
ncacn_ip_tcp : 49664 | |
-------------------------------------------------------------------------------- | |
<WinProcess "csrss.exe" pid 564 at 0x53069e8L> | |
64 | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "winlogon.exe" pid 644 at 0x5306860L> | |
64 | |
Interfaces : | |
RPC 76f226c3-ec14-4325-8a99-6a46348418ae (1.0) -- C:\windows\system32\winlogon.exe | |
0 -> I_WMsgkSendMessage | |
1 -> I_WMsgkSendPSPMessage | |
RPC 76f226c3-ec14-4325-8a99-6a46348418af (1.0) -- C:\windows\system32\winlogon.exe | |
0 -> I_WMsgSendMessage | |
1 -> I_WMsgSendPSPMessage | |
2 -> I_WMsgSendNotifyMessage | |
3 -> I_WMsgSendReconnectionUpdateMessage | |
Endpoints : | |
ncalrpc : WMsgKRpc058201 | |
-------------------------------------------------------------------------------- | |
<WinProcess "services.exe" pid 684 at 0x5306320L> | |
64 | |
Interfaces : | |
RPC 367abb81-9844-35f1-ad32-98f038001003 (2.0) -- C:\windows\system32\services.exe | |
0 -> RCloseServiceHandle | |
1 -> RControlService | |
2 -> RDeleteService | |
3 -> RLockServiceDatabase | |
4 -> RQueryServiceObjectSecurity | |
5 -> RSetServiceObjectSecurity | |
6 -> RQueryServiceStatus | |
7 -> RSetServiceStatus | |
8 -> RUnlockServiceDatabase | |
9 -> RNotifyBootConfigStatus | |
10 -> RI_ScSetServiceBitsW | |
11 -> RChangeServiceConfigW | |
12 -> RCreateServiceW | |
13 -> REnumDependentServicesW | |
14 -> REnumServicesStatusW | |
15 -> ROpenSCManagerW | |
16 -> ROpenServiceW | |
17 -> RQueryServiceConfigW | |
18 -> RQueryServiceLockStatusW | |
19 -> RStartServiceW | |
20 -> RGetServiceDisplayNameW | |
21 -> RGetServiceKeyNameW | |
22 -> CServiceRecord::GetStatusInternal | |
23 -> RChangeServiceConfigA | |
24 -> RCreateServiceA | |
25 -> REnumDependentServicesA | |
26 -> REnumServicesStatusA | |
27 -> ROpenSCManagerA | |
28 -> ROpenServiceA | |
29 -> RQueryServiceConfigA | |
30 -> RQueryServiceLockStatusA | |
31 -> RStartServiceA | |
32 -> RGetServiceDisplayNameA | |
33 -> RGetServiceKeyNameA | |
34 -> CServiceRecord::GetStatusInternal | |
35 -> REnumServiceGroupW | |
36 -> RChangeServiceConfig2A | |
37 -> RChangeServiceConfig2W | |
38 -> RQueryServiceConfig2A | |
39 -> RQueryServiceConfig2W | |
40 -> RQueryServiceStatusEx | |
41 -> REnumServicesStatusExA | |
42 -> REnumServicesStatusExW | |
43 -> RI_ScBroadcastServiceControlMessage | |
44 -> RCreateServiceWOW64A | |
45 -> RCreateServiceWOW64W | |
46 -> RI_ScQueryServiceTagInfo | |
47 -> RNotifyServiceStatusChange | |
48 -> RGetNotifyResults | |
49 -> RCloseNotifyHandle | |
50 -> RControlServiceExA | |
51 -> RControlServiceExW | |
52 -> RI_ScSendPnPMessage | |
53 -> RI_ScValidatePnPService | |
54 -> RI_ScOpenServiceStatusHandle | |
55 -> RI_ScQueryServiceConfig | |
56 -> RQueryServiceConfigEx | |
57 -> RI_ScRegisterPreshutdownRestart | |
58 -> RI_ScReparseServiceDatabase | |
59 -> RQueryUserServiceName | |
60 -> RCreateWowService | |
61 -> RGetServiceRegistryStateKey | |
62 -> RGetServiceDirectory | |
63 -> RGetServiceProcessToken | |
RPC a2c45f7c-7d32-46ad-96f5-adafb486be74 (1.0) -- C:\windows\system32\services.exe | |
0 -> RI_ScOpenServiceChannelHandle | |
1 -> RI_ScSendResponseReceiveControls | |
2 -> RI_ScCloseServiceChannelHandle | |
RPC 93149ca2-973b-11d1-8c39-00c04fb984f9 (0.0) -- C:\windows\SYSTEM32\scesrv.dll | |
0 -> SceSvcRpcQueryInfo | |
1 -> SceSvcRpcSetInfo | |
2 -> SceRpcSetupUpdateObject | |
3 -> SceRpcSetupMoveFile | |
4 -> SceRpcGenerateTemplate | |
5 -> SceRpcConfigureSystem | |
6 -> SceRpcGetDatabaseInfo | |
7 -> SceRpcGetObjectChildren | |
8 -> SceRpcOpenDatabase | |
9 -> SceRpcCloseDatabase | |
10 -> SceRpcGetDatabaseDescription | |
11 -> SceRpcGetDBTimeStamp | |
12 -> SceRpcGetObjectSecurity | |
13 -> SceRpcGetAnalysisSummary | |
14 -> SceRpcAnalyzeSystem | |
15 -> SceRpcUpdateDatabaseInfo | |
16 -> SceRpcUpdateObjectInfo | |
17 -> SceRpcStartTransaction | |
18 -> SceRpcCommitTransaction | |
19 -> SceRpcRollbackTransaction | |
20 -> SceRpcGetServerProductType | |
21 -> SceSvcRpcUpdateInfo | |
22 -> SceRpcCopyObjects | |
23 -> SceRpcSetupResetLocalPolicy | |
24 -> SceRpcNotifySaveChangesInGP | |
25 -> SceRpcControlNotificationQProcess | |
26 -> SceRpcBrowseDatabaseTable | |
27 -> SceRpcGetSystemSecurity | |
28 -> SceRpcGetSystemSecurity | |
29 -> SceRpcSetSystemSecurity | |
30 -> SceRpcSetSystemSecurity | |
31 -> SceRpcSetDatabaseSetting | |
32 -> SceRpcGetDatabaseSetting | |
33 -> SceRpcConfigureConvertedFileSecurityImmediately | |
Endpoints : | |
ncalrpc : ntsvcs | |
ncacn_np : \pipe\ntsvcs | |
ncacn_np : \PIPE\scerpc | |
ncacn_ip_tcp : 49677 | |
-------------------------------------------------------------------------------- | |
<WinProcess "lsass.exe" pid 692 at 0x53062b0L> | |
64 | |
['KeyIso', 'SamSs', 'VaultSvc'] | |
Interfaces : | |
RPC 12345778-1234-abcd-ef00-0123456789ab (0.0) -- C:\windows\system32\lsasrv.dll | |
0 -> LsarClose | |
1 -> CredrRename | |
2 -> LsarEnumeratePrivileges | |
3 -> LsarQuerySecurityObject | |
4 -> LsarSetSecurityObject | |
5 -> LsaITestCall | |
6 -> LsarOpenPolicyRPC | |
7 -> LsarQueryInformationPolicy | |
8 -> LsarSetInformationPolicy | |
9 -> LsaITestCall | |
10 -> LsarCreateAccount | |
11 -> LsarEnumerateAccounts | |
12 -> LsarCreateTrustedDomain | |
13 -> LsarEnumerateTrustedDomains | |
14 -> LsarLookupNames | |
15 -> LsarLookupSids | |
16 -> LsarCreateSecret | |
17 -> LsarOpenAccount | |
18 -> LsarEnumeratePrivilegesAccount | |
19 -> LsarAddPrivilegesToAccount | |
20 -> LsarRemovePrivilegesFromAccount | |
21 -> LsarGetQuotasForAccount | |
22 -> LsarSetQuotasForAccount | |
23 -> LsarGetSystemAccessAccount | |
24 -> LsarSetSystemAccessAccount | |
25 -> LsarOpenTrustedDomain | |
26 -> LsarQueryInfoTrustedDomain | |
27 -> LsarSetInformationTrustedDomain | |
28 -> LsarOpenSecret | |
29 -> LsarSetSecret | |
30 -> LsarQuerySecret | |
31 -> LsarLookupPrivilegeValue | |
32 -> LsarLookupPrivilegeName | |
33 -> LsarLookupPrivilegeDisplayName | |
34 -> LsarDeleteObject | |
35 -> LsarEnumerateAccountsWithUserRight | |
36 -> LsarEnumerateAccountRights | |
37 -> LsarAddAccountRights | |
38 -> LsarRemoveAccountRights | |
39 -> LsarQueryTrustedDomainInfo | |
40 -> LsarSetTrustedDomainInfo | |
41 -> LsarDeleteTrustedDomain | |
42 -> LsarStorePrivateData | |
43 -> LsarRetrievePrivateData | |
44 -> LsarOpenPolicy2 | |
45 -> LsarGetUserName | |
46 -> LsarQueryInformationPolicy2 | |
47 -> LsarSetInformationPolicy2 | |
48 -> LsarQueryTrustedDomainInfoByName | |
49 -> LsarSetTrustedDomainInfoByName | |
50 -> LsarEnumerateTrustedDomainsEx | |
51 -> LsarCreateTrustedDomainEx | |
52 -> LsaITestCall | |
53 -> LsarQueryDomainInformationPolicy | |
54 -> LsarSetDomainInformationPolicy | |
55 -> LsarOpenTrustedDomainByName | |
56 -> LsaITestCall | |
57 -> LsarLookupSids2 | |
58 -> LsarLookupNames2 | |
59 -> LsarCreateTrustedDomainEx2 | |
60 -> CredrWrite | |
61 -> CredrRead | |
62 -> CredrEnumerate | |
63 -> CredrWriteDomainCredentials | |
64 -> CredrReadDomainCredentials | |
65 -> CredrDelete | |
66 -> CredrGetTargetInfo | |
67 -> CredrProfileLoaded | |
68 -> LsarLookupNames3 | |
69 -> CredrGetSessionTypes | |
70 -> LsarRegisterAuditEvent | |
71 -> LsarGenAuditEvent | |
72 -> LsarUnregisterAuditEvent | |
73 -> LsarQueryForestTrustInformation | |
74 -> LsarSetForestTrustInformation | |
75 -> CredrRename | |
76 -> LsarLookupSids3 | |
77 -> LsarLookupNames4 | |
78 -> LsarOpenPolicySce | |
79 -> LsarAdtRegisterSecurityEventSource | |
80 -> LsarAdtUnregisterSecurityEventSource | |
81 -> LsarAdtReportSecurityEvent | |
82 -> CredrFindBestCredential | |
83 -> LsarSetAuditPolicy | |
84 -> LsarQueryAuditPolicy | |
85 -> LsarEnumerateAuditPolicy | |
86 -> LsarEnumerateAuditCategories | |
87 -> LsarEnumerateAuditSubCategories | |
88 -> LsarLookupAuditCategoryName | |
89 -> LsarLookupAuditSubCategoryName | |
90 -> LsarSetAuditSecurity | |
91 -> LsarQueryAuditSecurity | |
92 -> CredrReadByTokenHandle | |
93 -> CredrRestoreCredentials | |
94 -> CredrBackupCredentials | |
95 -> LsarManageSidNameMapping | |
96 -> CredrProfileUnloaded | |
97 -> CredrRename | |
98 -> CredrRename | |
99 -> CredrRename | |
100 -> CredrRename | |
101 -> CredrRename | |
102 -> LsarEfsGetSmartcardCredentials | |
103 -> LsarAuditSetGlobalSacl | |
104 -> LsarAuditQueryGlobalSacl | |
105 -> CredrProfileLoadedEx | |
106 -> LsarInteractiveSessionIsLoggedOff | |
107 -> LsarConfigureAutoLogonCredentials | |
108 -> LsarGetDeviceRegistrationInfo | |
109 -> LsaITestCall | |
110 -> LsarProfileDeleted | |
111 -> LsaITestCall | |
112 -> CredrRename | |
113 -> LsarValidateProcUniqueLuid | |
114 -> LsarIsArsoAllowedByPolicy | |
115 -> LsarIsArsoAllowedByConsent | |
116 -> LsarEnableArsoConsent | |
117 -> LsarDisableArsoConsent | |
118 -> LsarIsArsoAllowedByPolicy | |
119 -> LsarIsUserArsoEnabled | |
120 -> LsarEnableUserArso | |
121 -> LsarDisableUserArso | |
122 -> LsarConfigureUserArso | |
123 -> LsarGetInprocDispatchTable | |
124 -> LsarSetSharedUserSession | |
125 -> LsarClearSharedUserSession | |
126 -> LsarEnablePasswordLessCurrentUser | |
127 -> LsarDisablePasswordLessCurrentUser | |
RPC ace1c026-8b3f-4711-8918-f345d17f5bff (1.0) -- C:\windows\system32\lsasrv.dll | |
0 -> S_RPC_LspUpdatePrivateData | |
1 -> S_RPC_LspReadPrivateData | |
RPC afc07e2e-311c-4435-808c-c483ffeec7c9 (1.0) -- C:\windows\system32\lsasrv.dll | |
0 -> LsarGetAvailableCAPIDs | |
1 -> LsarSetCAPs | |
2 -> LsarQueryCAPs | |
RPC c0d930f0-b787-4124-99bc-21f0ecb642ce (0.0) -- C:\windows\system32\lsasrv.dll | |
0 -> LsarConnectLocalUser | |
1 -> LsarDisconnectLocalUser | |
2 -> LsarCreateConnectedUser | |
3 -> LsarIsCurrentUserConnected | |
4 -> LsarRenewCertificate | |
5 -> LsarGetSSOAccountType | |
6 -> LsarIsUserMSA | |
RPC d25576e4-00d2-43f7-98f9-b4c0724158f9 (0.0) -- C:\windows\system32\lsasrv.dll | |
0 -> LsarEasMarkUserControlled | |
1 -> LsarEasGetCallerPasswordComplexity | |
2 -> LsarEasGetControlledUsersInfo | |
RPC c681d488-d850-11d0-8c52-00c04fd90f7e (1.0) -- C:\windows\system32\efslsaext.dll | |
0 -> EfsRpcOpenFileRaw_Downlevel | |
1 -> EfsRpcReadFileRaw_Downlevel | |
2 -> EfsRpcWriteFileRaw_Downlevel | |
3 -> EfsRpcCloseRaw_Downlevel | |
4 -> EfsRpcEncryptFileSrv_Downlevel | |
5 -> EfsRpcDecryptFileSrv_Downlevel | |
6 -> EfsRpcQueryUsersOnFile_Downlevel | |
7 -> EfsRpcQueryRecoveryAgents_Downlevel | |
8 -> EfsRpcRemoveUsersFromFile_Downlevel | |
9 -> EfsRpcAddUsersToFile_Downlevel | |
10 -> EfsRpcFileKeyInfoEx_Downlevel | |
11 -> EfsRpcFileKeyInfoEx_Downlevel | |
12 -> EfsRpcFileKeyInfo_Downlevel | |
13 -> EfsRpcDuplicateEncryptionInfoFile_Downlevel | |
14 -> EfsRpcFileKeyInfoEx_Downlevel | |
15 -> EfsRpcAddUsersToFileEx_Downlevel | |
16 -> EfsRpcFileKeyInfoEx_Downlevel | |
17 -> EfsRpcFileKeyInfoEx_Downlevel | |
18 -> EfsRpcFileKeyInfoEx_Downlevel | |
19 -> EfsRpcFileKeyInfoEx_Downlevel | |
20 -> EfsRpcFlushEfsCache_Downlevel | |
RPC fb8a0729-2d04-4658-be93-27b4ad553fac (1.0) -- C:\windows\system32\lsass.exe | |
0 -> LsaLookuprOpenPolicy2 | |
1 -> LsaLookuprClose | |
2 -> LsaLookuprTranslateSids2 | |
3 -> LsaLookuprTranslateNames3 | |
4 -> LsaLookuprManageCache | |
5 -> LsaLookuprGetDomainInfo | |
6 -> LsaLookuprUserAccountType | |
RPC 4f32adc8-6052-4a04-8701-293ccf2096f0 (1.0) -- C:\windows\SYSTEM32\SspiSrv.dll | |
0 -> SspirConnectRpc | |
1 -> SspirDisconnectRpc | |
2 -> SspirDisconnectRpc | |
3 -> SspirCallRpc | |
4 -> SspirAcquireCredentialsHandle | |
5 -> SspirFreeCredentialsHandle | |
6 -> SspirProcessSecurityContext | |
7 -> SspirDeleteSecurityContext | |
8 -> SspirSslQueryCredentialsAttributes | |
9 -> SspirNegQueryContextAttributes | |
10 -> SspirSslSetCredentialsAttributes | |
11 -> SspirApplyControlToken | |
12 -> SspirLogonUser | |
13 -> SspirLookupAccountSid | |
14 -> SspirGetUserName | |
15 -> SspirGetInprocDispatchTable | |
RPC 11220835-5b26-4d94-ae86-c3e475a809de (1.0) -- C:\windows\system32\dpapisrv.dll | |
0 -> s_SSCryptProtectData | |
1 -> s_SSCryptUnprotectData | |
2 -> s_SSCryptUpdateProtectedState | |
RPC 5cbe92cb-f4be-45c9-9fc9-33e73e557b20 (1.0) -- C:\windows\system32\dpapisrv.dll | |
0 -> s_SSRecoverQueryStatus | |
1 -> s_SSRecoverImportRecoveryKey | |
2 -> s_SSRecoverPassword | |
RPC 7f1317a8-4dea-4fa2-a551-df5516ff8879 (1.0) -- C:\windows\system32\dpapisrv.dll | |
0 -> s_LRpcSIDKeyProtect | |
1 -> s_LRpcSIDKeyUnprotect | |
RPC 3919286a-b10c-11d0-9ba8-00c04fd92ef5 (0.0) -- C:\windows\system32\lsasrv.dll | |
0 -> DsRolerGetPrimaryDomainInformation | |
RPC 12345778-1234-abcd-ef00-0123456789ac (1.0) -- C:\windows\SYSTEM32\samsrv.dll | |
0 -> SamrConnect | |
1 -> SamrCloseHandle | |
2 -> SamrSetSecurityObject | |
3 -> SamrQuerySecurityObject | |
4 -> SamrShutdownSamServer | |
5 -> SamrLookupDomainInSamServer | |
6 -> SamrEnumerateDomainsInSamServer | |
7 -> SamrOpenDomain | |
8 -> SamrQueryInformationDomain | |
9 -> SamrSetInformationDomain | |
10 -> SamrCreateGroupInDomain | |
11 -> SamrEnumerateGroupsInDomain | |
12 -> SamrCreateUserInDomain | |
13 -> SamrEnumerateUsersInDomain | |
14 -> SamrCreateAliasInDomain | |
15 -> SamrEnumerateAliasesInDomain | |
16 -> SamrGetAliasMembership | |
17 -> SamrLookupNamesInDomain | |
18 -> SamrLookupIdsInDomain | |
19 -> SamrOpenGroup | |
20 -> SamrQueryInformationGroup | |
21 -> SamrSetInformationGroup | |
22 -> SamrAddMemberToGroup | |
23 -> SamrDeleteGroup | |
24 -> SamrRemoveMemberFromGroup | |
25 -> SamrGetMembersInGroup | |
26 -> SamrSetMemberAttributesOfGroup | |
27 -> SamrOpenAlias | |
28 -> SamrQueryInformationAlias | |
29 -> SamrSetInformationAlias | |
30 -> SamrDeleteAlias | |
31 -> SamrAddMemberToAlias | |
32 -> SamrRemoveMemberFromAlias | |
33 -> SamrGetMembersInAlias | |
34 -> SamrOpenUser | |
35 -> SamrDeleteUser | |
36 -> SamrQueryInformationUser | |
37 -> SamrSetInformationUser | |
38 -> SamrChangePasswordUser | |
39 -> SamrGetGroupsForUser | |
40 -> SamrQueryDisplayInformation | |
41 -> SamrGetDisplayEnumerationIndex | |
42 -> SamrTestPrivateFunctionsDomain | |
43 -> SamrTestPrivateFunctionsUser | |
44 -> SamrGetUserDomainPasswordInformation | |
45 -> SamrRemoveMemberFromForeignDomain | |
46 -> SamrQueryInformationDomain2 | |
47 -> SamrQueryInformationUser2 | |
48 -> SamrQueryDisplayInformation2 | |
49 -> SamrGetDisplayEnumerationIndex2 | |
50 -> SamrCreateUser2InDomain | |
51 -> SamrQueryDisplayInformation3 | |
52 -> SamrAddMultipleMembersToAlias | |
53 -> SamrRemoveMultipleMembersFromAlias | |
54 -> SamrOemChangePasswordUser2 | |
55 -> SamrUnicodeChangePasswordUser2 | |
56 -> SamrGetDomainPasswordInformation | |
57 -> SamrConnect2 | |
58 -> SamrSetInformationUser2 | |
59 -> SamrSetBootKeyInformation | |
60 -> SamrGetBootKeyInformation | |
61 -> SamrConnect3 | |
62 -> SamrConnect4 | |
63 -> SamrUnicodeChangePasswordUser3 | |
64 -> SamrConnect5 | |
65 -> SamrRidToSid | |
66 -> SamrSetDSRMPassword | |
67 -> SamrValidatePassword | |
68 -> SamrQueryLocalizableAccountsInDomain | |
69 -> SamrPerformGenericOperation | |
70 -> SamrSyncDSRMPasswordFromAccount | |
71 -> SamrLookupNamesInDomain2 | |
72 -> SamrEnumerateUsersInDomain2 | |
RPC b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86 (2.0) -- C:\windows\system32\keyiso.dll | |
0 -> s_SrvRpcCreateContext | |
1 -> s_SrvRpcReleaseContext | |
2 -> s_SrvRpcCryptOpenStorageProvider | |
3 -> s_SrvRpcCryptIsAlgSupported | |
4 -> s_SrvRpcCryptEnumAlgorithms | |
5 -> s_SrvRpcCryptEnumKeys | |
6 -> s_SrvRpcCryptFreeBuffer | |
7 -> s_SrvRpcCryptFreeProvider | |
8 -> s_SrvRpcCryptFreeKey | |
9 -> s_SrvRpcCryptOpenKey | |
10 -> s_SrvRpcCryptCreatePersistedKey | |
11 -> s_SrvRpcCryptGetProviderProperty | |
12 -> s_SrvRpcCryptSetProviderProperty | |
13 -> s_SrvRpcCryptGetKeyProperty | |
14 -> s_SrvRpcCryptSetKeyProperty | |
15 -> s_SrvRpcCryptFinalizeKey | |
16 -> s_SrvRpcCryptEncrypt | |
17 -> s_SrvRpcCryptDecrypt | |
18 -> s_SrvRpcCryptImportKey | |
19 -> s_SrvRpcCryptExportKey | |
20 -> s_SrvRpcCryptSignHash | |
21 -> s_SrvRpcCryptVerifySignature | |
22 -> s_SrvRpcCryptDeleteKey | |
23 -> s_SrvRpcCryptNotifyChangeKey | |
24 -> s_SrvRpcCryptSecretAgreement | |
25 -> s_SrvRpcCryptDeriveKey | |
26 -> s_SrvRpcCryptFreeSecret | |
27 -> s_SrvRpcCryptCipherEncrypt | |
28 -> s_SrvRpcCryptCipherDecrypt | |
29 -> s_SrvRpcCryptKeyDerivation | |
30 -> s_SrvRpcCryptCreateClaim | |
31 -> s_SrvRpcCryptVerifyClaim | |
RPC 8fb74744-b2ff-4c00-be0d-9ef9a191fe1b (1.0) -- C:\windows\system32\keyiso.dll | |
0 -> s_GetSymmetricPopKeyTransportKey | |
1 -> s_GetSymmetricPopKeyTransportKeyName | |
2 -> s_DeleteSymmetricPopKeyTransportKey | |
3 -> s_ImportSymmetricPopKey | |
4 -> s_SignWithSymmetricPopKey | |
5 -> s_VerifyWithSymmetricPopKey | |
6 -> s_DecryptWithSymmetricPopKey | |
7 -> s_EncryptWithSymmetricPopKey | |
8 -> s_GetKeyAttestationForContainerService | |
9 -> s_RenewKeyAttestation | |
10 -> s_GetPregenUserKey | |
11 -> s_GetPregenKeyState | |
RPC 51a227ae-825b-41f2-b4a9-1ac9557a1018 (1.0) -- C:\windows\system32\keyiso.dll | |
0 -> s_TokenBindingGenerateTpmKeyFromSoftware | |
RPC bb8b98e8-84dd-45e7-9f34-c3fb6155eeed (1.0) -- C:\Windows\System32\vaultsvc.dll | |
0 -> VltCreateItemType | |
1 -> VltDeleteItemType | |
2 -> VltEnumerateItemTypes | |
3 -> VltAddItem | |
4 -> VltFindItems | |
5 -> VltEnumerateItems | |
6 -> VltGetItem | |
7 -> VltRemoveItem | |
8 -> VltGetItemType | |
9 -> VltOpenVault | |
10 -> VltCloseVault | |
11 -> VltGetInformation | |
12 -> VltEnumerateVaults | |
13 -> VltEnumerateSettingUnits | |
14 -> VltGetSettingUnit | |
15 -> VltApplySettingUnit | |
16 -> VltRemoveSettingUnit | |
17 -> VltTriggerSync | |
18 -> VltGetSettingUnitInfo | |
Endpoints : | |
ncacn_np : \pipe\lsass | |
ncalrpc : audit | |
ncalrpc : securityevent | |
ncalrpc : LSARPC_ENDPOINT | |
ncalrpc : lsacap | |
ncalrpc : LSA_IDPEXT_ENDPOINT | |
ncalrpc : LSA_EAS_ENDPOINT | |
ncalrpc : lsapolicylookup | |
ncalrpc : lsasspirpc | |
ncalrpc : protected_storage | |
ncalrpc : SidKey Local End Point | |
ncalrpc : samss lpc | |
ncacn_ip_tcp : 49678 | |
ncalrpc : Vault | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 808 at 0x5306e10L> | |
64 | |
['PlugPlay'] | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "fontdrvhost.exe" pid 832 at 0x5306ba8L> | |
64 | |
[!!] Invalid rpcrt4 base: 0x0 vs 0x7ffec24f0000 | |
-------------------------------------------------------------------------------- | |
<WinProcess "fontdrvhost.exe" pid 828 at 0x5306898L> | |
64 | |
[!!] Invalid rpcrt4 base: 0x0 vs 0x7ffec24f0000 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 844 at 0x53064a8L> | |
64 | |
['BrokerInfrastructure', 'DcomLaunch', 'Power', 'SystemEventsBroker'] | |
Interfaces : | |
RPC 6c9b7b96-45a8-4cca-9eb3-e21ccf8b5a89 (1.1) -- c:\windows\system32\umpo.dll | |
0 -> UmpoRpcGetPowerConfiguration | |
1 -> UmpoRpcReadFromSystemPowerKey | |
2 -> UmpoRpcReadFromUserPowerKey | |
3 -> UmpoRpcReadACValue | |
4 -> UmpoRpcReadDCValue | |
5 -> UmpoRpcWriteToSystemPowerKey | |
6 -> UmpoRpcWriteToUserPowerKey | |
7 -> UmpoRpcApplyPowerRequestOverride | |
8 -> UmpoRpcApplyPowerSetting | |
9 -> UmpoRpcSetActiveScheme | |
10 -> UmpoRpcGetActiveScheme | |
11 -> UmpoRpcSetActiveOverlayScheme | |
12 -> UmpoRpcGetActualOverlayScheme | |
13 -> UmpoRpcGetEffectiveOverlayScheme | |
14 -> UmpoRpcGetOverlaySchemes | |
15 -> UmpoRpcRestoreDefaultScheme | |
16 -> UmpoRpcRestoreDefaultSchemesAll | |
17 -> UmpoRpcDuplicateScheme | |
18 -> UmpoRpcDeleteScheme | |
19 -> UmpoRpcImportScheme | |
20 -> UmpoRpcReplaceDefaultPowerSchemes | |
21 -> UmpoRpcLegacyEventRegisterNotification | |
22 -> UmpoRpcEnumerate | |
23 -> UmpoRpcReadSecurityDescriptor | |
24 -> UmpoRpcWriteSecurityDescriptor | |
25 -> UmpoRpcSettingAccessCheck | |
26 -> UmpoRpcCreateSetting | |
27 -> UmpoRpcCreatePossibleSetting | |
28 -> UmpoRpcRemoveSetting | |
29 -> UmpoSetExpectedUserAwayIntervals | |
30 -> UmpoClearExpectedUserAwayIntervals | |
31 -> UmpoGetMinUserAwayPredictionInterval | |
32 -> UmpoRpcGetAdaptiveStandbyDiagnostics | |
RPC 9b8699ae-0e44-47b1-8e7f-86a461d7ecdc (0.0) -- c:\windows\system32\rpcss.dll | |
0 -> _LaunchActivatorServer | |
1 -> _LaunchRunAsServer | |
2 -> _LaunchService | |
3 -> _LaunchWinRTActivatorServer | |
4 -> _LaunchWinRTRunAsServer | |
5 -> _LaunchWinRTService | |
6 -> _CertifyServerIdentity | |
7 -> _QueryNTService | |
8 -> _QueryNTServiceType | |
9 -> ControlNTService | |
10 -> PrivTranslateShareName | |
11 -> GenericStreamBase<IMarshalingStream,AllocationWrapper>::Commit | |
12 -> IsPortOpen | |
13 -> TickleActivationSettings | |
14 -> QueryProcessArchitecture | |
15 -> PrivilegedNotifyWinRTActivationStoreChanged | |
16 -> _QueryUserSidForSession | |
17 -> PrivActivatePsmServer | |
18 -> _PrivGetUserTokenForSession | |
19 -> PrivGetBrokerToken | |
20 -> PrivGetDesktopWinRTBrokerToken | |
21 -> PrivGetPsmToken | |
22 -> GetSessionUserTokenCacheDetails | |
23 -> PrivilegedNotifyComClassChangesFromDeployment | |
24 -> PrivGetPsmTokenWithDynamicId | |
25 -> PrivGetInteractiveUserToken | |
26 -> PrivReportUnhealthyProcess | |
27 -> PrivNormalizePsmTokenHostId | |
RPC 4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9 (1.0) -- c:\windows\system32\psmsrv.dll | |
0 -> PsmSrvActivateApplication | |
1 -> PsmSrvCloseActivationChannel | |
2 -> PsmSrvOpenActivationChannel | |
3 -> PsmSrvRegisterProcess | |
RPC 085b0334-e454-4d91-9b8c-4134f9e793f3 (1.0) -- c:\windows\system32\psmsrv.dll | |
0 -> PsmSrvOpenManagementChannel | |
1 -> PsmSrvSetApplicationState | |
2 -> PsmSrvSetApplicationPriority | |
3 -> PsmSrvReleaseCacheEntry | |
4 -> PsmSrvAcquireCachedEntries | |
5 -> PsmSrvQueryApplicationSwapState | |
6 -> PsmSrvCloseActivationChannel | |
7 -> PsmSrvSetApplicationProperties | |
8 -> PsmSrvQueryApplicationProperties | |
9 -> PsmSrvQueryApplicationResourceUsage | |
10 -> PsmSrvQueryMemoryUsage | |
11 -> PsmSrvResetMaxMemoryUsage | |
12 -> PsmSrvQuerySharedCommit | |
RPC 8782d3b9-ebbd-4644-a3d8-e8725381919b (1.0) -- c:\windows\system32\psmsrv.dll | |
0 -> PsmSrvRegisterQuiesceResumeApp | |
1 -> PsmSrvQuiesceCallbacksComplete | |
2 -> PsmSrvCloseActivationChannel | |
RPC 3b338d89-6cfa-44b8-847e-531531bc9992 (1.0) -- c:\windows\system32\psmsrv.dll | |
0 -> PsmSrvQueryApplicationPerformanceInformation | |
1 -> PsmSrvQueryQuotaInformation | |
RPC bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760 (1.0) -- c:\windows\system32\psmsrv.dll | |
0 -> PsmSrvOpenTcChannel | |
1 -> PsmSrvApplyTaskCompletion | |
2 -> PsmSrvRegisterDynamicProcess | |
3 -> PsmSrvCloseActivationChannel | |
4 -> PsmSrvGetSessionInfo | |
RPC 5824833b-3c1a-4ad2-bdfd-c31d19e23ed2 (1.0) -- c:\windows\system32\psmsrv.dll | |
0 -> PsmSrvRegisterAppPriorityNotification | |
1 -> PsmSrvQueryApplicationResourceUsageForTimer | |
2 -> PsmSrvTimerStart | |
3 -> PsmSrvTimerCleanup | |
4 -> PsmSrvTimerRemainingResourceTimeGet | |
5 -> PsmSrvTimerElapsedResourceTimeGet | |
RPC 0361ae94-0316-4c6c-8ad8-c594375800e2 (1.0) -- c:\windows\system32\psmsrv.dll | |
0 -> PsmSrvQueryCurrentApplications | |
1 -> PsmSrvQueryApplicationHosts | |
2 -> PsmSrvQueryApplicationHostExecutionState | |
3 -> PsmSrvQueryApplicationHostJob | |
4 -> PsmSrvConnect | |
5 -> PsmSrvDisconnect | |
6 -> PsmSrvSubscribeToNotifications | |
7 -> PsmSrvUnsubscribeFromNotifications | |
RPC 2d98a740-581d-41b9-aa0d-a88b9d5ce938 (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> RBiSrvActivateDeferredWorkItem | |
1 -> RBiSrvActivateInBackground | |
2 -> RBiSrvActivateWorkItem | |
3 -> RBiSrvAssociateActivationProxy | |
4 -> RBiSrvAssociateApplicationExtensionClass | |
5 -> RBiSrvCancelWorkItem | |
6 -> RBiSrvCreateEvent | |
7 -> RBiSrvCreateEventForPackageName | |
8 -> RBiSrvDeleteEvent | |
9 -> RBiSrvDisassociateWorkItem | |
10 -> RBiSrvDiscardPendingActivations | |
11 -> RBiSrvEnumerateBrokeredEvents | |
12 -> RBiSrvEnumerateUserContexts | |
13 -> RBiSrvEnumerateUserSessions | |
14 -> RBiSrvEnumerateWorkItemsForPackageName | |
15 -> RBiPtSrvGetStatusStateNameFromBrokerEventId | |
16 -> RBiSrvQueryBrokeredEvent | |
17 -> RBiSrvQuerySystemStateBroadcastChannels | |
18 -> RBiSrvQueryUserContext | |
19 -> RBiSrvQueryUserSession | |
20 -> RBiSrvQueryWorkItem | |
21 -> RBiPtSrvQueryWorkItemStatusStateName | |
22 -> RBiSrvSignalEvent | |
23 -> RBiSrvSignalMultipleEvents | |
24 -> RBiSrvSignalTriggerEvent | |
25 -> RBiSrvUpdateEventParameters | |
26 -> RBiSrvUpdateEventFlags | |
27 -> RBiSrvUpdateEventInformation | |
RPC 8bfc3be1-6def-4e2d-af74-7c47cd0ade4a (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> RBiSrvActivateWorkItemForUser | |
1 -> RBiSrvChangeApplicationStateForPackageNameForUser | |
2 -> RBiSrvChangeApplicationStateForPsmKeyForUser | |
3 -> RBiSrvChangeUserState | |
4 -> RBiSrvEnumerateWorkItemsForPackageNameAndUser | |
5 -> RBiSrvGetActiveBackgroundTasksEventForUser | |
6 -> RBiSrvGetCancellationTimeoutInMs | |
7 -> RBiSrvIsApplicationTerminateSensitiveForUser | |
8 -> RBiSrvNotifyEndSession | |
9 -> RBiSrvNotifyNewSession | |
10 -> RBiSrvNotifyNewSessionComplete | |
11 -> RBiSrvNotifyNewUser | |
12 -> RBiSrvQueryWorkItemForUser | |
13 -> RBiSrvResetActiveUserForPackage | |
14 -> RBiSrvSetActiveUserForPackage | |
15 -> RBiSrvTerminateApplicationHostForUser | |
16 -> RBiSrvUpdateBackgroundAccessApplicationsForUser | |
RPC 1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0 (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> RBiRtSrvAddWaitableEvent | |
1 -> RBiRtSrvAssociateWorkItem | |
2 -> RBiRtSrvCreateEvent | |
3 -> RBiRtSrvCreateEventForApp | |
4 -> RBiRtSrvCreateStatusStateName | |
5 -> RBiRtSrvDeleteEvent | |
6 -> RBiRtSrvDisassociateWorkItem | |
7 -> RBiRtSrvEnumerateBrokeredEvents | |
8 -> RBiRtSrvEnumerateWorkItems | |
9 -> RBiRtSrvGetWorkItemProperties | |
10 -> RBiRtSrvInitiatePause | |
11 -> RBiRtSrvQueryBrokerEventId | |
12 -> RBiRtSrvQueryBrokerEventIdFromWorkItem | |
13 -> RBiRtSrvRegisterWorkItem | |
14 -> RBiRtSrvSignalEvent | |
15 -> RBiRtSrvUpdateEventParameters | |
RPC c605f9fb-f0a3-4e2a-a073-73560f8d9e3e (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> RBiSrvSignalEvent | |
RPC 0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> RBiPtSrvActivateDeferredWorkItem | |
1 -> RBiPtSrvActivateInBackground | |
2 -> RBiPtSrvActivateWorkItem | |
3 -> RBiPtSrvAssociateActivationProxy | |
4 -> RBiPtSrvAssociateApplicationEntryPoint | |
5 -> RBiPtSrvCancelWorkItem | |
6 -> RBiPtSrvCreateEvent | |
7 -> RBiPtSrvCreateEventForApp | |
8 -> RBiPtSrvCreateEventForPackageName | |
9 -> RBiPtSrvDeleteEvent | |
10 -> RBiPtSrvDisableWorkItem | |
11 -> RBiPtSrvDisassociateWorkItem | |
12 -> RBiPtSrvEnableWorkItem | |
13 -> RBiPtSrvEnumerateBrokeredEvents | |
14 -> RBiPtSrvEnumerateWorkItemsForPackageName | |
15 -> RBiPtSrvGetStatusStateNameFromBrokerEventId | |
16 -> RBiPtSrvQueryBrokeredEvent | |
17 -> RBiPtSrvQueryBrokerEventId | |
18 -> RBiPtSrvQuerySystemStateBroadcastChannels | |
19 -> RBiPtSrvQueryWorkItem | |
20 -> RBiPtSrvQueryWorkItemStatusStateName | |
21 -> RBiPtSrvSignalEvent | |
22 -> RBiPtSrvSignalMultipleEvents | |
23 -> RBiPtSrvSignalTriggerEvent | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
RPC 2513bcbe-6cd4-4348-855e-7efb3c336dd3 (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> SrvOdbCreateSession | |
1 -> SrvOdbCompleteSession | |
2 -> SrvOdbLaunchBackgroundTask | |
3 -> SrvOdbCancelBackgroundTask | |
4 -> SrvOdbCancelBackgroundTasksForPackage | |
RPC 20c40295-8dba-48e6-aebf-3e78ef3bb144 (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> SrvOdbPtCreateSession | |
1 -> SrvOdbPtCompleteSession | |
2 -> SrvOdbPtLaunchBackgroundTask | |
3 -> SrvOdbPtCancelBackgroundTask | |
4 -> SrvOdbPtCancelBackgroundTasksForPackage | |
RPC b8cadbaf-e84b-46b9-84f2-6f71c03f9e55 (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> SrvOdbLbPublishLegacyExitCode | |
RPC 857fb1be-084f-4fb5-b59c-4b2c4be5f0cf (1.0) -- C:\windows\SYSTEM32\bisrv.dll | |
0 -> SrvOdbPrivGetLaunchInfo | |
RPC 55e6b932-1979-45d6-90c5-7f6270724112 (1.0) -- C:\windows\SYSTEM32\resourcepolicyserver.dll | |
0 -> Srv_GetResourcePolicyKey | |
1 -> Srv_GetResourcePolicyInformation | |
2 -> Srv_CreateResourcePolicy | |
3 -> Srv_GetResourcePolicyName | |
4 -> Srv_CreatePolicyEngineClientContext | |
5 -> Srv_ClosePolicyEngineClientContext | |
6 -> Srv_RegisterForPackageEnergyStateChangeNotifications | |
7 -> Srv_IsPackageInGoodEnergyState | |
8 -> Srv_InterruptiveUIStateChanged_Subscribe | |
9 -> Srv_InterruptiveUIStateChanged_Unsubscribe | |
RPC 76c217bc-c8b4-4201-a745-373ad9032b1a (1.0) -- C:\windows\SYSTEM32\resourcepolicyserver.dll | |
0 -> Srv_QueryApplicationEnergyUsage | |
1 -> Srv_GetDeviceSpecificConversionFactor | |
2 -> Srv_ResetTotalEnergyUsage | |
RPC 88abcbc3-34ea-76ae-8215-767520655a23 (0.0) -- C:\windows\SYSTEM32\resourcepolicyserver.dll | |
0 -> GcsSrv_GetGameConfigSize | |
1 -> GcsSrv_GetGameConfig | |
2 -> GcsSrv_GetGameConfigSizeForClientProcess | |
3 -> GcsSrv_GetGameConfigForClientProcess | |
4 -> GcsSrv_ModifyGameConfig | |
5 -> GcsSrv_AddGameConfig | |
6 -> GcsSrv_RemoveGameConfig | |
7 -> GcsSrv_GetGameIdByAUMID | |
8 -> GcsSrv_GetGameIdByPID | |
9 -> GcsSrv_GetGameIdCount | |
10 -> GcsSrv_GetAllGameIds | |
11 -> GcsSrv_GetGameIdsByExeNameCount | |
12 -> GcsSrv_GetGameIdsByExeName | |
13 -> GcsSrv_GetGameProperty | |
14 -> GcsSrv_GetGamePropertySize | |
15 -> GcsSrv_SetGameProperty | |
16 -> GcsSrv_GetGlobalProperty | |
17 -> GcsSrv_GetGlobalPropertySize | |
18 -> GcsSrv_SetGlobalProperty | |
19 -> GcsSrv_SetGamePropertyUserOverride | |
20 -> GcsSrv_GetGamePropertyIsUserOverride | |
RPC 2c7fd9ce-e706-4b40-b412-953107ef9bb0 (0.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> RmgrSrv_RegisterWithServer | |
1 -> RmgrSrv_RmSetMemoryUsageLimit | |
2 -> RmgrSrv_RmRegisterResource | |
3 -> RmgrSrv_RmAccessCheck | |
4 -> RmgrSrv_RmAccessCheckOnCaller | |
5 -> RmgrSrv_RmAvailabilityCheck | |
6 -> RmgrSrv_RmAcquireResources | |
7 -> RmgrSrv_RmGetNotification | |
8 -> RmgrSrv_RmReleaseResources | |
RPC c521facf-09a9-42c5-b155-72388595cbf0 (0.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> RmtSrv_RM_ConnectToServer | |
1 -> RmtSrv_RM_DisconnectFromServer | |
2 -> RmtSrv_RM_AcquireResourceSet | |
3 -> RmtSrv_RS_Apply | |
4 -> RmtSrv_RS_ReleaseResources | |
5 -> ExecutionModel::BaseResourceSet::OnAccessLost | |
6 -> RmtSrv_RS_SetExternalResourcePriorities | |
7 -> ExecutionModel::BaseResourceSet::OnAccessLost | |
RPC 1832bcf6-cab8-41d4-85d2-c9410764f75a (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> RmCoreRpcSrvConnectToRmServer | |
1 -> RmCoreRpcSrvDisconnectFromRmServer | |
2 -> RmCoreRpcSrvRegisterActivityHostCallbacks | |
3 -> RmCoreRpcSrvUnregisterActivityHostCallbacks | |
4 -> RmCoreRpcSrvAcquireResourceSet | |
5 -> RmCoreRpcSrvApplyResourceSet | |
6 -> RmCoreRpcSrvReleaseResourceSet | |
7 -> CrmRpcSrvActivityRenew | |
8 -> RmCoreRpcSrvQueryHostMemoryLimitValues | |
RPC 4dace966-a243-4450-ae3f-9b7bcb5315b8 (2.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> RmGameModeSrvRegisterProcess | |
1 -> RmGameModeSrvUnregisterProcess | |
2 -> RmGameModeSrvDisableForRegisteredProcess | |
3 -> RmGameModeSrvReenableForRegisteredProcess | |
4 -> RmGameModeSrvGetLargestValidResourceRequest | |
5 -> RmGameModeSrvRegisterPairedAuxiliaryProcess | |
RPC 178d84be-9291-4994-82c6-3f909aca5a03 (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> RmGameModeRSrvRegisterProcess | |
1 -> RmGameModeRSrvUnregisterProcess | |
2 -> RmGameModeRSrvDisableForRegisteredProcess | |
3 -> RmGameModeRSrvReenableForRegisteredProcess | |
4 -> RmGameModeRSrvRegisterPairedAuxiliaryProcess | |
RPC e53d94ca-7464-4839-b044-09a2fb8b3ae5 (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvConnect | |
1 -> HamRpcSrvDisconnect | |
2 -> HamRpcSrvCreateActivity | |
3 -> HamRpcSrvCreateActivityForProcess | |
4 -> HamRpcSrvCreateAutoRestartActivity | |
5 -> HamRpcSrvStartActivityAsync | |
6 -> HamRpcSrvStopActivity | |
7 -> HamRpcSrvUpdateActivityProperties | |
8 -> HamRpcSrvTerminateActivityHost | |
9 -> HamRpcSrvSetExternalResourcePriority | |
10 -> HamRpcSrvResetExternalResourcePriority | |
11 -> HamRpcSrvCloseActivity | |
12 -> HamRpcSrvIsHostBeingDebugged | |
13 -> HamRpcSrvTerminateHostOnProcessExit | |
14 -> HamRpcSrvGetApplicationInterruptiveUIState | |
15 -> HamRpcSrvGetPackageInterruptiveUIState | |
16 -> HamRpcSrvGetInterruptiveUIStateForAumid | |
RPC fae436b0-b864-4a87-9eda-298547cd82f2 (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvConnectDebugging | |
1 -> HamRpcSrvDisconnect | |
2 -> HamRpcSrvDebugOpenPackageHandle | |
3 -> HamRpcSrvDebugClosePackageHandle | |
4 -> HamRpcSrvDebugModeEnable | |
5 -> HamRpcSrvDebugTerminatePackage | |
6 -> HamRpcSrvDebugQueryPackageState | |
7 -> HamRpcSrvDebugSuspendPackage | |
RPC 082a3471-31b6-422a-b931-a54401960c62 (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvConnectExtendedExecution | |
1 -> HamRpcSrvDisconnect | |
2 -> HamRpcSrvIsHostHamManaged | |
3 -> HamRpcSrvQueryTaskCompletionsForTerminateGraph | |
4 -> HamRpcSrvCreateExtendedExecution | |
5 -> HamRpcSrvStartExtendedExecutionAsync | |
6 -> HamRpcSrvCloseActivity | |
7 -> HamRpcSrvAddDependency | |
8 -> HamRpcSrvRemoveDependency | |
9 -> HamRpcSrvAddHostDependency | |
10 -> HamRpcSrvRemoveHostDependency | |
11 -> HamRpcSrvTerminateSelf | |
12 -> HamRpcSrvTerminateSelfOnRequiredProcessExit | |
13 -> HamRpcSrvTryEstimateRemainingQuiesceTime | |
RPC 6982a06e-5fe2-46b1-b39c-a2c545bfa069 (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvConnectFullTrust | |
1 -> HamRpcSrvDisconnect | |
2 -> HamRpcSrvFullTrustOpenPackageHandle | |
3 -> HamRpcSrvDebugClosePackageHandle | |
4 -> HamRpcSrvDebugTerminatePackage | |
RPC 0ff1f646-13bb-400a-ab50-9a78f2b7a85a (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvFindOrCreateHostId | |
1 -> HamRpcSrvCreateSingleUseHostId | |
2 -> HamRpcSrvRetrieveDynamicIdForHostId | |
RPC 4ed8abcc-f1e2-438b-981f-bb0e8abc010c (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvConnectStateChangeNotifications | |
1 -> HamRpcSrvDisconnect | |
2 -> HamRpcSrvGetApplicationStateForPsmKey | |
3 -> HamRpcSrvTerminateIfSuspendedByProcess | |
RPC 95406f0b-b239-4318-91bb-cea3a46ff0dc (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvConnectServicing | |
1 -> HamRpcSrvDisconnect | |
2 -> HamRpcSrvFullTrustOpenPackageHandle | |
3 -> HamRpcSrvDebugClosePackageHandle | |
4 -> HamRpcSrvServicingQueryActiveAppsInPackage | |
5 -> HamRpcSrvServicingEnableServicing | |
6 -> HamRpcSrvDebugTerminatePackage | |
RPC 0d47017b-b33b-46ad-9e18-fe96456c5078 (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> HamRpcSrvConnectSessionState | |
1 -> HamRpcSrvDisconnect | |
2 -> HamRpcSrvSessionStateLogoffUser | |
3 -> HamRpcSrvSessionStateLogoffSession | |
RPC dd59071b-3215-4c59-8481-972edadc0f6a (1.0) -- C:\windows\SYSTEM32\psmserviceexthost.dll | |
0 -> CrmRpcSrvRegister | |
1 -> CrmRpcSrvUnregister | |
2 -> CrmRpcSrvActivityAllocate | |
3 -> CrmRpcSrvActivityQueryWindowClosedReasons | |
4 -> CrmRpcSrvActivityFree | |
5 -> CrmRpcSrvActivityStart | |
6 -> CrmRpcSrvActivityRenew | |
7 -> CrmRpcSrvActivityStop | |
8 -> CrmRpcSrvActivityWindowClosedReasonSubscribe | |
9 -> CrmRpcSrvActivityWindowClosedReasonUnsubscribe | |
RPC d09bdeb5-6171-4a34-bfe2-06fa82652568 (1.0) -- c:\windows\system32\BrokerLib.dll | |
0 -> _BriCreateEvent | |
1 -> _BriDeleteEvent | |
2 -> BriDisableEvent | |
3 -> BriEnableEvent | |
4 -> BriSignalEvent | |
RPC 9b008953-f195-4bf9-bde0-4471971e58ed (1.0) -- c:\windows\system32\systemeventsbrokerserver.dll | |
0 -> SebiEnumerateEvents | |
1 -> _SebiEnumerateEventsByType | |
2 -> _SebiQueryEventData | |
3 -> SebiQueryEventPackage | |
4 -> _SebiSignalSyncEventEx | |
5 -> SebiGetUserPresenceHistory | |
RPC 697dcda9-3ba9-4eb2-9247-e11f1901b0d2 (1.0) -- c:\windows\system32\systemeventsbrokerserver.dll | |
0 -> CSebiCreateWellKnownEvent | |
1 -> _CSebiCreatePrivateEvent | |
2 -> _CSebiDeleteEvent | |
3 -> CSebiEnumerateEvents | |
4 -> CSebiQueryEventData | |
5 -> CSebiCreateCustomEvent | |
RPC 1377d115-98fd-4034-b574-111156ca239c (1.0) -- c:\windows\system32\systemeventsbrokerserver.dll | |
0 -> _CSebiRegisterPublisher | |
1 -> CSebiPublisherUpdateLevelEvent | |
2 -> CSebiUnregisterPublisher | |
RPC 7419cf08-91a7-4afd-8f5e-1dd76de094fd (1.0) -- c:\windows\system32\DAB.dll | |
0 -> s_DabRpcRegisterTriggerConsumer | |
1 -> s_DabRpcUnregisterTriggerConsumer | |
2 -> s_DabRpcGetLastScheduledRunTime | |
RPC fc48cd89-98d6-4628-9839-86f7a3e4161a (1.0) -- C:\Windows\System32\ACPBackgroundManagerPolicy.dll | |
0 -> MVoipSrvNotifyVoipActiveCall | |
1 -> MVoipSrvNotifyVoipActivityCompleted | |
2 -> MVoipSrvHoldActiveCall | |
3 -> MVoipSrvUnholdActiveCall | |
4 -> MVoipSrvNotifyIncomingCallDialogDisplayed | |
5 -> MVoipSrvNotifyIncomingCallDialogDismissed | |
6 -> MVoipSrvLaunchVoipRtcTask | |
7 -> MVoipSrvLaunchVoipActivity | |
8 -> MVoipSrvCancelVoipCall | |
OLE 7656cfa4-b63a-4542-a8de-ef402bac895d (0.0) -- IUserApplicationStateChangeHandler | |
OLE 43c6b434-c1be-4ad2-af03-c0deaccebd1f (0.0) -- IBackgroundAccessStateChangeHandler | |
OLE 0166231b-fd21-4e33-a713-75eb3207a138 (0.0) -- IBackgroundWorkItemInstanceRemote | |
Endpoints : | |
ncalrpc : umpo | |
ncalrpc : actkernel | |
ncalrpc : LRPC-52052fd65c5c272467 | |
ncalrpc : OLE0B4A1FCA316D75160A1E9D74EAA9 | |
ncalrpc : LRPC-4ab018e2789c955e4e | |
ncalrpc : LRPC-10ae42bf2b12c862e5 | |
ncalrpc : LRPC-72ebfc69859a71292b | |
ncalrpc : LRPC-841d50e1fe23b6a7d7 | |
ncalrpc : LRPC-b950717adfd86cb405 | |
ncalrpc : csebpub | |
ncalrpc : dabrpc | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 940 at 0x5306550L> | |
64 | |
['RpcEptMapper', 'RpcSs'] | |
Interfaces : | |
RPC e1af8308-5d1f-11c9-91a4-08002b14a0fa (3.0) -- c:\windows\system32\rpcepmap.dll | |
0 -> ept_delete | |
1 -> ept_delete | |
2 -> ept_lookup | |
3 -> ept_map | |
4 -> ept_lookup_handle_free | |
5 -> ept_delete | |
6 -> ept_delete | |
7 -> ept_map_auth | |
8 -> ept_map_auth_async | |
RPC 0b0a6584-9e0f-11cf-a3cf-00805f68cb1b (1.1) -- c:\windows\system32\rpcepmap.dll | |
0 -> OpenEndpointMapper | |
1 -> AllocateReservedIPPort | |
2 -> ept_insert_ex | |
3 -> ept_delete_ex | |
4 -> SetRestrictRemoteClients | |
5 -> ResetWithNoAuthException | |
RPC 1d55b526-c137-46c5-ab79-638f2a68e869 (1.0) -- c:\windows\system32\rpcepmap.dll | |
0 -> RemoteGetCellByDebugCellID | |
1 -> RemoteOpenRPCDebugCallInfoEnumeration | |
2 -> RemoteGetNextRPCDebugCallInfo | |
3 -> RemoteFinishRPCDebugCallInfoEnumeration | |
4 -> RemoteOpenRPCDebugEndpointInfoEnumeration | |
5 -> RemoteGetNextRPCDebugEndpointInfo | |
6 -> RemoteFinishRPCDebugEndpointInfoEnumeration | |
7 -> RemoteOpenRPCDebugThreadInfoEnumeration | |
8 -> RemoteGetNextRPCDebugThreadInfo | |
9 -> RemoteFinishRPCDebugThreadInfoEnumeration | |
10 -> RemoteOpenRPCDebugClientCallInfoEnumeration | |
11 -> RemoteGetNextRPCDebugClientCallInfo | |
12 -> RemoteFinishRPCDebugClientCallInfoEnumeration | |
RPC 64fe0b7f-9ef5-4553-a7db-9a1975777554 (1.0) -- C:\windows\system32\RpcRtRemote.dll | |
0 -> FwConnectToManager | |
1 -> FwSubscribeForNewRulesNotification | |
2 -> FwInterfaceRegistered | |
RPC e60c73e6-88f9-11cf-9af1-0020af6e72f4 (2.0) -- c:\windows\system32\rpcss.dll | |
0 -> _Connect | |
1 -> _SetAppID | |
2 -> GetDefaultSecurityPermissions | |
3 -> _AllocateReservedIds | |
4 -> _BulkUpdateOIDs | |
5 -> _ClientResolveOXID | |
6 -> _ServerAllocateOXIDAndOIDs | |
7 -> _ServerAllocateOIDs | |
8 -> _ServerFreeOXIDAndOIDs | |
9 -> _SetServerOIDFlags | |
10 -> _Disconnect | |
11 -> GetUpdatedResolverBindings | |
RPC 99fcfec4-5260-101b-bbcb-00aa0021347a (0.0) -- c:\windows\system32\rpcss.dll | |
0 -> ResolveOxid | |
1 -> SimplePing | |
2 -> ComplexPing | |
3 -> ServerAlive | |
4 -> ResolveOxid2 | |
5 -> ServerAlive2 | |
RPC b9e79e60-3d52-11ce-aaa1-00006901293f (0.2) -- c:\windows\system32\rpcss.dll | |
0 -> IrotRegister | |
1 -> IrotRevoke | |
2 -> IrotIsRunning | |
3 -> IrotGetObject | |
4 -> IrotNoteChangeTime | |
5 -> IrotGetTimeOfLastChange | |
6 -> IrotEnumRunning | |
7 -> IMgotRegister | |
8 -> IMgotRevoke | |
9 -> IMgotGetObject | |
10 -> IMgotEnumRunning | |
RPC 412f241e-c12a-11ce-abff-0020af6e7a17 (0.2) -- c:\windows\system32\rpcss.dll | |
0 -> ServerRegisterClsid | |
1 -> ServerRevokeClsid | |
2 -> ServerRegisterActivatableClasses | |
3 -> ServerRevokeActivatableClasses | |
4 -> GetThreadID | |
5 -> UpdateActivationSettings | |
6 -> RegisterWindowPropInterface | |
7 -> GetWindowPropInterface | |
8 -> EnableDisableDynamicIPTracking | |
9 -> GetCurrentAddrExclusionList | |
10 -> SetAddrExclusionList | |
11 -> FlushSCMBindings | |
12 -> RetireServer | |
13 -> NotifyDDStartOrStop | |
14 -> QueryDragDropActive | |
15 -> SetOrRevokeForcedDropTarget | |
16 -> IsObjectCreationAllowed | |
17 -> ControlTracingForProcess | |
18 -> QueryPIDForActivation | |
19 -> NotifyWinRTActivationStoreChanged | |
20 -> DecodeProxy | |
21 -> NotifyPsmResume | |
22 -> QueryServerProcessHandleHeld | |
23 -> RegisterRacActivationToken | |
24 -> RevokeRacActivationToken | |
25 -> RegisterConsoleHandles | |
26 -> RevokeConsoleHandles | |
27 -> NotifyComClassChangesFromDeployment | |
DCOM 00000136-0000-0000-c000-000000000046 (0.0) -- ISCMLocalActivator | |
RPC c6f3ee72-ce7e-11d1-b71e-00c04fc3111a (1.0) -- c:\windows\system32\rpcss.dll | |
0 -> ProcessActivatorStarted | |
1 -> ProcessActivatorInitializing | |
2 -> ProcessActivatorReady | |
3 -> ProcessActivatorStopped | |
4 -> ProcessActivatorPaused | |
5 -> ProcessActivatorResumed | |
6 -> ProcessActivatorUserInitializing | |
RPC 4d9f4ab8-7d1c-11cf-861e-0020af6e7c57 (0.0) -- c:\windows\system32\rpcss.dll | |
0 -> RemoteActivation | |
DCOM 000001a0-0000-0000-c000-000000000046 (0.0) -- ISystemActivator | |
RPC cb40a179-20e1-43f0-97fb-3c5c6ff37ec3 (0.0) -- c:\windows\system32\rpcss.dll | |
0 -> CrossContainerActivation | |
Endpoints : | |
ncalrpc : epmapper | |
ncacn_ip_tcp : 135 | |
ncacn_np : \pipe\epmapper | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 980 at 0x5306cc0L> | |
64 | |
['LSM'] | |
Interfaces : | |
RPC c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 (1.0) -- c:\windows\system32\SYSNTFY.dll | |
0 -> s_OnInitialConnection | |
1 -> s_OnCreateSession | |
2 -> s_OnStartScreenSaverAsDefaultUser | |
3 -> s_OnStopScreenSaverAsDefaultUser | |
4 -> s_OnLogon | |
5 -> s_OnLock | |
6 -> s_OnUnlock | |
7 -> s_OnStartScreenSaverAsUser | |
8 -> s_OnStopScreenSaverAsUser | |
9 -> s_OnDisconnect | |
10 -> s_OnReconnect | |
11 -> s_OnLogoff | |
12 -> s_OnTerminateSession | |
13 -> s_OnStartShell | |
14 -> s_OnEndShell | |
RPC 11f25515-c879-400a-989e-b074d5f092fe (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcGetUserToken | |
1 -> RpcConnectTerminal | |
2 -> RpcSystemShutdownStarted | |
3 -> RpcConsumeCacheSession | |
4 -> RpcGetRequestForWinlogon | |
5 -> RpcReportWinlogonReply | |
6 -> RpcGetReconnectId | |
7 -> RpcCreateWorkerSession | |
8 -> RpcGetWorkerSessionGpuLuid | |
RPC 1e665584-40fe-4450-8f6e-802362399694 (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcBroadcastSystemMessage | |
1 -> RpcSendWindowMessage | |
2 -> RpcCreateSession | |
3 -> RpcTerminateSession | |
RPC 484809d6-4239-471b-b5bc-61df8c23ac48 (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcOpenSession | |
1 -> RpcCloseSession | |
2 -> RpcConnect | |
3 -> RpcDisconnect | |
4 -> RpcLogoff | |
5 -> RpcGetUserName | |
6 -> RpcGetTerminalName | |
7 -> RpcGetState | |
8 -> RpcIsSessionDesktopLocked | |
9 -> RpcShowMessageBox | |
10 -> RpcGetTimes | |
11 -> RpcGetSessionCounters | |
12 -> RpcGetSessionInformation | |
13 -> RpcSwitchToServicesSession | |
14 -> RpcRevertFromServicesSession | |
15 -> RpcGetLoggedOnCount | |
16 -> RpcGetSessionType | |
17 -> RpcGetSessionInformationEx | |
18 -> RpcIsTerminalRemote | |
19 -> RpcIsBoundToCacheTerminal | |
20 -> RpcConnectAndLockTargetDesktop | |
RPC e3907f22-c899-44e7-9d11-9d8b3d924832 (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcEnableChildSessions | |
1 -> RpcIsChildSessionsEnabled | |
2 -> RpcGetChildSessionId | |
3 -> RpcGetParentSessionId | |
4 -> RpcGetAllUserSessions | |
RPC 53825514-1183-4934-a0f4-cfdc51c3389b (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcIsCurrentSessionTerminalRemote | |
1 -> RpcGetCurrentSessionTerminalName | |
2 -> RpcGetCurrentSessionInformation | |
3 -> RpcGetCurrentSessionCapabilities | |
4 -> RpcGetCurrentSessionType | |
RPC 11899a43-2b68-4a76-92e3-a3d6ad8c26ce (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcWaitForSessionState | |
1 -> RpcRegisterAsyncNotification | |
2 -> RpcWaitAsyncNotification | |
3 -> RpcUnRegisterAsyncNotification | |
RPC c2d15ccf-a416-46dc-ba58-4624ac7a9123 (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcRegisterCurrentSessionAsyncNotification | |
1 -> RpcWaitAsyncNotificationEx | |
2 -> RpcUnRegisterAsyncNotificationEx | |
RPC 88143fd0-c28d-4b2b-8fef-8d882f6a9390 (1.0) -- c:\windows\system32\lsm.dll | |
0 -> RpcOpenEnum | |
1 -> RpcCloseEnum | |
2 -> RpcFilterByState | |
3 -> RpcFilterByCallersName | |
4 -> RpcEnumAddFilter | |
5 -> RpcGetEnumResult | |
6 -> RpcFilterBySessionType | |
7 -> RpcFilterByLicenseType | |
8 -> RpcGetSessionIds | |
9 -> RpcGetEnumResultEx | |
10 -> RpcGetAllSessions | |
11 -> RpcGetAllSessionsEx | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 517f87fe-597a-4672-8555-6daf1c8c788d (0.0) -- ISessionManager | |
OLE 75a446c5-40b7-41d3-8d53-292652c04121 (0.0) -- ITSEventDispatcher | |
OLE 959c5a99-177c-478e-8c3b-77e07e9bf3aa (0.0) -- ISessionList | |
OLE a8105b4f-7d5a-402b-aac0-fd85daecf94c (0.0) -- ISessionEnum | |
OLE a1b7de7a-4e77-43db-ae78-96fc182fed4a (0.0) -- ITSSession | |
OLE 1a8a5d71-d95b-4dcd-915e-f9f6d31879ad (0.0) -- ITerminal | |
OLE 6344a5b7-ef1c-47ba-98b7-28c664427793 (0.0) -- IGlassTerminal | |
OLE c2d3e131-c587-49b4-8bae-f0ee269eeb31 (0.0) -- ITSSessionAttribute | |
OLE 35481b58-f46c-4254-b52c-fdc3001484c3 (0.0) -- IRestrictedCalls | |
OLE 4d10b48b-c531-4731-9bde-b03c28e9c61c (0.0) -- IUserName | |
Endpoints : | |
ncalrpc : LRPC-6b49de762b15890702 | |
ncalrpc : LSMApi | |
ncacn_np : \pipe\LSM_API_service | |
ncalrpc : OLE3F9B241B15C1D6F0A2B264568291 | |
-------------------------------------------------------------------------------- | |
<WinProcess "LogonUI.exe" pid 420 at 0x5306278L> | |
64 | |
Interfaces : | |
RPC f3f09ffd-fbcf-4291-944d-70ad6e0e73bb (1.0) -- C:\windows\System32\logoncontroller.dll | |
0 -> WluirAbort | |
1 -> WluirSecureDisplayLocked | |
2 -> WluirDisplayLocked | |
3 -> WluirWaitForLockScreenDismiss | |
4 -> WluirDisplayMessage | |
5 -> WluirDisplayRequestCredentialsError | |
6 -> WluirDisplaySecurityOptions | |
7 -> WluirDisplayStatus | |
8 -> WluirDisplayTSDisconnectOptions | |
9 -> WluirDisplayWelcome | |
10 -> WluirNotifyIsReadyForDesktopSwitch | |
11 -> WluirPromptForCredentials | |
12 -> WluirReleaseContext | |
13 -> WluirClearUIState | |
14 -> WluirReportResult | |
15 -> WluirRequestCredentials | |
16 -> WluirDisplayTSDisconnectUI | |
17 -> WluirDisplayTSReconnectUI | |
18 -> WluirNotifyUserIsLoggedOn | |
19 -> WluirFinishOperation | |
20 -> WluirInformLogonUI | |
21 -> WluirDelayLocked | |
22 -> WluirSecureDelayLocked | |
23 -> WluirGetShutdownResolverInfo | |
24 -> WluirSignalShutdown | |
25 -> WluirPrepareWebDialog | |
26 -> WluirWaitForWebDialogComplete | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 0000000c-0000-0000-c000-000000000046 (0.0) -- IStream | |
OLE 06386a7a-e009-5b0b-ab68-a8e48b516647 (0.0) -- __FIAsyncOperationWithProgressCompletedHandler_2_Windows__CStorage__CStreams__CIBuffer_UINT32 | |
OLE 30d5a829-7fa4-4026-83bb-d75bae4ea99e (0.0) -- IClosable | |
OLE af86e2e0-b12d-4c6a-9c5a-d7aa65101e90 (0.0) -- IInspectable | |
OLE ce17c10a-90f9-42e5-a43b-4ffee2f937a0 (0.0) -- IObjectWithRWLock | |
OLE 00000141-0000-0000-c000-000000000046 (0.0) -- IDLLHost | |
OLE 000001a0-0000-0000-c000-000000000046 (0.0) -- ISystemActivator | |
OLE 947aab5f-0a5c-4c13-b4d6-4bf7836fc9f8 (0.0) -- IFileOperation | |
Endpoints : | |
ncalrpc : LRPC-7ad18c0181b776e795 | |
ncalrpc : OLE273901A57D58B270B18B090D94E5 | |
-------------------------------------------------------------------------------- | |
<WinProcess "dwm.exe" pid 416 at 0x53068d0L> | |
64 | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00621c22-42e8-529f-9270-836b32931d72 (0.0) -- __FIEventHandler_1_Windows__CGaming__CInput__CRawGameController | |
Endpoints : | |
ncalrpc : OLE23E3E1AC7EE9CC6F1F25CDFF90CC | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 496 at 0x5306160L> | |
64 | |
['TermService'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE be5a9fee-1c29-4aae-a6b7-feb0e4c96d5e (0.0) -- IConnectionManager | |
OLE 6e796d86-376c-46fe-8381-43982edd00fe (0.0) -- ITSNotifySink | |
RPC 2f59a331-bf7d-48cb-9e5c-7c090d76e8b8 (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcLicensingOpenServer | |
1 -> RpcLicensingCloseServer | |
2 -> RpcLicensingLoadPolicy | |
3 -> RpcLicensingLoadPolicy | |
4 -> RpcLicensingSetPolicy | |
5 -> RpcLicensingGetAvailablePolicyIds | |
6 -> RpcLicensingGetPolicy | |
7 -> RpcLicensingGetPolicyInformation | |
8 -> RpcLicensingDeactivateCurrentPolicy | |
9 -> RpcLicensingServerPing | |
10 -> RpcGetSessionUnderArbitration | |
RPC 1f260487-ba29-4f13-928a-bbd29761b083 (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcIsSessionPermitted | |
1 -> RpcGetUserCredentials | |
2 -> RpcGetUserProfile | |
3 -> RpcWinStationRedirectErrorMessage | |
4 -> RpcRedirectLogonBeginPainting | |
5 -> RpcRedirectLogonStatus | |
6 -> RpcRedirectLogonMessage | |
7 -> RpcRedirectLogonError | |
8 -> RpcGetRedirectAuthInfo | |
9 -> RpcGetRestrictedLogonInfo | |
RPC ecd85155-cc3a-4f10-aad5-9a9a2bf2ef0c (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcSetAutologonPassword | |
RPC bde95fdf-eee0-45de-9e12-e5a61cd0d4fe (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcGetClientData | |
1 -> RpcGetConfigData | |
2 -> RpcGetProtocolStatus | |
3 -> RpcGetLastInputTime | |
4 -> RpcGetRemoteAddress | |
5 -> RpcShadow | |
6 -> RpcShadowTarget | |
7 -> RpcShadowStop | |
8 -> RpcGetAllListeners | |
9 -> RpcGetSessionProtocolLastInputTime | |
10 -> RpcGetUserCertificates | |
11 -> RpcQuerySessionData | |
RPC 497d95a6-2d27-4bf5-9bbd-a6046957133c (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcOpenListener | |
1 -> RpcCloseListener | |
2 -> RpcStopListener | |
3 -> RpcStartListener | |
4 -> RpcIsListening | |
RPC 5267aaba-4f49-4653-8e26-d1e11f3f2ad9 (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcCreateVirtualChannel | |
1 -> CConnectionEx::Connect | |
2 -> RpcPopSecurityDialog | |
3 -> RpcGetInitialApplication | |
4 -> RpcGetConnectionProperty | |
5 -> CConnectionEx::Connect | |
6 -> RpcVerify | |
7 -> RpcCreateChildSessionTransport | |
8 -> RpcRcmShadow2 | |
9 -> RpcShadowAccessCheck | |
10 -> RpcShadowStop2 | |
RPC 28098650-fe3c-4af4-8a41-8bcd284941c5 (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcGetCurrentSessionConnectionProperty | |
1 -> RpcGetCurrentSessionClientData | |
2 -> RpcGetCurrentSessionConfigData | |
3 -> RpcGetCurrentSessionProtocolLastInputTime | |
RPC 5ca4a760-ebb1-11cf-8611-00a0245420ed (1.0) -- c:\windows\system32\termsrv.dll | |
0 -> RpcWinStationOpenServer | |
1 -> RpcWinStationCloseServer | |
2 -> RpcIcaServerPing | |
3 -> RpcWinStationEnumerate | |
4 -> RpcWinStationRename | |
5 -> RpcWinStationQueryInformation | |
6 -> RpcWinStationSetInformation | |
7 -> RpcWinStationSendMessage | |
8 -> RpcLogonIdFromWinStationName | |
9 -> RpcWinStationNameFromLogonId | |
10 -> RpcWinStationConnect | |
11 -> RpcWinStationVirtualOpen | |
12 -> RpcWinStationBeepOpen | |
13 -> RpcWinStationDisconnect | |
14 -> RpcWinStationReset | |
15 -> RpcWinStationShutdownSystem | |
16 -> RpcWinStationWaitSystemEvent | |
17 -> RpcWinStationShadow | |
18 -> RpcWinStationShadowTargetSetup | |
19 -> RpcWinStationShadowTarget | |
20 -> RpcWinStationGenerateLicense | |
21 -> RpcWinStationInstallLicense | |
22 -> RpcWinStationEnumerateLicenses | |
23 -> RpcWinStationActivateLicense | |
24 -> RpcWinStationRemoveLicense | |
25 -> RpcWinStationQueryLicense | |
26 -> RpcWinStationSetPoolCount | |
27 -> RpcWinStationQueryUpdateRequired | |
28 -> RpcWinStationCallback | |
29 -> RpcWinStationBreakPoint | |
30 -> RpcWinStationReadRegistry | |
31 -> RpcWinStationWaitForConnect | |
32 -> RpcWinStationNotifyLogon | |
33 -> RpcWinStationNotifyLogoff | |
34 -> OldRpcWinStationEnumerateProcesses | |
35 -> RpcWinStationAnnoyancePopup | |
36 -> RpcWinStationEnumerateProcesses | |
37 -> RpcWinStationTerminateProcess | |
38 -> RpcServerNWLogonSetAdmin | |
39 -> RpcServerNWLogonQueryAdmin | |
40 -> RpcWinStationCheckForApplicationName | |
41 -> RpcWinStationGetApplicationInfo | |
42 -> RpcWinStationNtsdDebug | |
43 -> RpcWinStationGetAllProcesses | |
44 -> RpcWinStationGetProcessSid | |
45 -> RpcWinStationGetTermSrvCountersValue | |
46 -> RpcWinStationReInitializeSecurity | |
47 -> RpcWinStationBroadcastSystemMessage | |
48 -> RpcWinStationSendWindowMessage | |
49 -> RpcWinStationNotifyNewSession | |
50 -> RpcServerGetInternetConnectorStatus | |
51 -> RpcServerSetInternetConnectorStatus | |
52 -> RpcServerQueryInetConnectorInformation | |
53 -> RpcWinStationGetLanAdapterName | |
54 -> RpcWinStationUpdateUserConfig | |
55 -> RpcWinStationQueryLogonCredentials | |
56 -> RpcWinStationRegisterConsoleNotification | |
57 -> RpcWinStationUnRegisterConsoleNotification | |
58 -> RpcWinStationUpdateSettings | |
59 -> RpcWinStationShadowStop | |
60 -> RpcWinStationCloseServerEx | |
61 -> RpcWinStationIsHelpAssistantSession | |
62 -> RpcWinStationGetMachinePolicy | |
63 -> RpcWinStationUpdateClientCachedCredentials | |
64 -> RpcWinStationFUSCanRemoteUserDisconnect | |
65 -> RpcWinStationCheckLoopBack | |
66 -> RpcConnectCallback | |
67 -> RpcWinStationNotifyDisconnectPipe | |
68 -> RpcWinStationSessionInitialized | |
69 -> RpcRemoteAssistancePrepareSystemRestore | |
70 -> RpcWinStationGetAllProcesses_NT6 | |
71 -> RpcWinStationRegisterNotificationEvent | |
72 -> RpcWinStationUnRegisterNotificationEvent | |
73 -> RpcWinStationAutoReconnect | |
74 -> RpcWinStationCheckAccess | |
75 -> RpcWinStationOpenSessionDirectory | |
OLE 4d10b48b-c531-4731-9bde-b03c28e9c61c (0.0) -- IUserName | |
OLE 02e6ec4c-96e4-42e8-b533-336916a0087d (0.0) -- ISessionEnumFilter | |
OLE 1a8a5d71-d95b-4dcd-915e-f9f6d31879ad (0.0) -- ITerminal | |
OLE a9052eea-734f-41d8-978b-e32cad12381a (0.0) -- ISessionArbitration | |
Endpoints : | |
ncalrpc : OLE5AE2BB39E98F6C6862D43D1741FE | |
ncalrpc : LcRpc | |
ncalrpc : TermSrvApi | |
ncacn_np : \pipe\TermSrv_API_service | |
ncacn_np : \pipe\Ctx_WinStation_API_service | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1064 at 0x5306b38L> | |
64 | |
['CoreMessagingRegistrar'] | |
Interfaces : | |
RPC df4df73a-c52d-4e3a-8003-8437fdf8302a (0.0) -- c:\windows\system32\coremessaging.dll | |
0 -> ServerValidateWindowId | |
1 -> ServerValidateWindowIdAndOwner | |
Endpoints : | |
ncalrpc : LRPC-0004450a441212400f | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1104 at 0x53067f0L> | |
64 | |
['NcbService'] | |
Interfaces : | |
RPC d09bdeb5-6171-4a34-bfe2-06fa82652568 (1.0) -- c:\windows\system32\BrokerLib.dll | |
0 -> _BriCreateEvent | |
1 -> _BriDeleteEvent | |
2 -> BriDisableEvent | |
3 -> BriEnableEvent | |
4 -> BriSignalEvent | |
RPC 5222821f-d5e2-4885-84f1-5f6185a0ec41 (1.0) -- c:\windows\system32\ncbservice.dll | |
0 -> RpcSrvRegisterControlChannelReset | |
1 -> RpcSrvUnregisterControlChannelReset | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\Windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 1299cf18-c4f5-4b6a-bb0f-2299f0398e27 (0.0) -- INotifyNetworkListManagerEvents | |
OLE 22d2e146-1a68-40b8-949c-8fd848b415e6 (0.0) -- INotifyNetworkEvents | |
OLE 2abc0864-9677-42e5-882a-d415c556c284 (0.0) -- INotifyNetworkInterfaceEvents | |
OLE 733b7764-5c0c-4ad6-bb4b-d0585e993e0e (0.0) -- INotifyNetworkGlobalCostEvents | |
RPC 880fd55e-43b9-11e0-b1a8-cf4edfd72085 (1.0) -- c:\windows\system32\ncbservice.dll | |
0 -> KapiRegisterProvider | |
1 -> KapiDeregisterProvider | |
2 -> KapiUpdateKaSample | |
3 -> KapiReceiveKaUpdateRequest | |
RPC e40f7b57-7a25-4cd3-a135-7f7d3df9d16b (1.0) -- c:\windows\system32\ncbservice.dll | |
0 -> RpcSrvCreateSession | |
1 -> RpcSrvDestroySession | |
2 -> RpcSrvStartBrokeredActivation | |
3 -> RpcSrvSetServerKeepAliveInterval | |
4 -> RpcSrvGetCurrentKeepAliveInterval | |
5 -> RpcSrvDecreaseKeepAliveInterval | |
6 -> RpcSrvUsingTransport | |
7 -> RpcSrvIndicateSlotAllocation | |
8 -> RpcSrvSBCreatePushEnabledContext | |
9 -> RpcSrvSBTransferOwnership | |
10 -> RpcSrvSBRetrieveSocket | |
11 -> RpcSrvSBCompleteRetrieveSocket | |
12 -> RpcSrvSBRetrieveContext | |
13 -> RpcSrvSBEnumSockets | |
14 -> RpcSrvHotspotRegisterHotspotApp | |
15 -> RpcSrvHotspotFindEventForPackage | |
16 -> RpcSrvHotspotTriggerBackgroundEvent | |
17 -> RpcSrvHotspotIsAppInstalled | |
18 -> RpcSrvFirewallWcmSetFirewallRule | |
19 -> RpcSrvFirewallWcmSetFirewallRuleFlags | |
20 -> RpcSrvFirewallWcmDeleteFirewallRule | |
Endpoints : | |
ncalrpc : LRPC-c671927dd9659a0385 | |
ncalrpc : LRPC-b104ee7e9393d8bf7f | |
ncalrpc : OLE9C9313BE9E1E2574A19C7FAC69FC | |
ncalrpc : LRPC-0c5aafc72066fcc0c4 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1176 at 0x5306978L> | |
64 | |
['TimeBrokerSvc'] | |
Interfaces : | |
RPC d09bdeb5-6171-4a34-bfe2-06fa82652568 (1.0) -- c:\windows\system32\BrokerLib.dll | |
0 -> _BriCreateEvent | |
1 -> _BriDeleteEvent | |
2 -> BriDisableEvent | |
3 -> BriEnableEvent | |
4 -> BriSignalEvent | |
RPC a500d4c6-0dd1-4543-bc0c-d5f93486eaf8 (1.0) -- c:\windows\system32\timebrokerserver.dll | |
0 -> _TbiEnumerateEvents | |
1 -> _TbiQueryEventData | |
2 -> _TbiUpdateEvent | |
3 -> _TbiQueryCEventData | |
4 -> _TbiQueryCEventTriggerTime | |
5 -> _TbiUpdateCEvent | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\Windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
Endpoints : | |
ncalrpc : LRPC-0f32fccfe501ad8fa4 | |
ncalrpc : LRPC-c73bd8309b02b2a015 | |
ncalrpc : OLEC1455F967D34F83BDA59E71D52F7 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1260 at 0x5306f98L> | |
64 | |
['vmicheartbeat'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE f7c4122f-6e32-4075-99d4-3d2b080b204e (0.0) -- IVmApplicationHealthQuery | |
Endpoints : | |
ncalrpc : OLEBCE0F0E17E902814B1FB5192AA95 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1268 at 0x53060f0L> | |
64 | |
['EventLog'] | |
Interfaces : | |
RPC 82273fdc-e32a-18c3-3f78-827929dc23ea (0.0) -- c:\windows\system32\wevtsvc.dll | |
0 -> ElfrClearELFW | |
1 -> ElfrBackupELFW | |
2 -> ElfrCloseEL | |
3 -> ElfrDeregisterEventSource | |
4 -> ElfrNumberOfRecords | |
5 -> ElfrOldestRecord | |
6 -> ElfrChangeNotify | |
7 -> ElfrOpenELW | |
8 -> ElfrRegisterEventSourceW | |
9 -> ElfrOpenBELW | |
10 -> ElfrReadELW | |
11 -> ElfrReportEventW | |
12 -> ElfrClearELFA | |
13 -> ElfrBackupELFA | |
14 -> ElfrOpenELA | |
15 -> ElfrRegisterEventSourceA | |
16 -> ElfrOpenBELA | |
17 -> ElfrReadELA | |
18 -> ElfrReportEventA | |
19 -> ElfrRegisterClusterSvc | |
20 -> ElfrDeregisterClusterSvc | |
21 -> ElfrWriteClusterEvents | |
22 -> ElfrGetLogInformation | |
23 -> ElfrFlushEL | |
24 -> ElfrReportEventAndSourceW | |
25 -> ElfrReportEventExW | |
26 -> ElfrReportEventExA | |
RPC f6beaff7-1e19-4fbb-9f8f-b89e2018337c (1.0) -- c:\windows\system32\wevtsvc.dll | |
0 -> _EvtRpcRegisterRemoteSubscription | |
1 -> _EvtRpcRemoteSubscriptionNextAsync | |
2 -> _EvtRpcRemoteSubscriptionNext | |
3 -> EvtRpcRemoteSubscriptionWaitAsync | |
4 -> EvtRpcRegisterControllableOperation | |
5 -> _EvtRpcRegisterLogQuery | |
6 -> EvtRpcClearLog | |
7 -> EvtRpcExportLog | |
8 -> EvtRpcLocalizeExportLog | |
9 -> _EvtRpcMessageRender | |
10 -> EvtRpcMessageRenderDefault | |
11 -> _EvtRpcQueryNext | |
12 -> _EvtRpcQuerySeek | |
13 -> EvtRpcClose | |
14 -> EvtRpcCancel | |
15 -> _EvtRpcAssertConfig | |
16 -> EvtRpcRetractConfig | |
17 -> _EvtRpcOpenLogHandle | |
18 -> _EvtRpcGetLogFileInfo | |
19 -> _EvtRpcGetChannelList | |
20 -> _EvtRpcGetChannelConfig | |
21 -> EvtRpcPutChannelConfig | |
22 -> _EvtRpcGetPublisherList | |
23 -> EvtRpcGetPublisherListForChannel | |
24 -> _EvtRpcGetPublisherMetadata | |
25 -> _EvtRpcGetPublisherResourceMetadata | |
26 -> EvtRpcGetEventMetadataEnum | |
27 -> EvtRpcGetNextEventMetadata | |
28 -> _EvtRpcGetClassicLogDisplayName | |
Endpoints : | |
ncalrpc : eventlog | |
ncacn_np : \pipe\eventlog | |
ncacn_ip_tcp : 49665 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1288 at 0x5306400L> | |
64 | |
['vmickvpexchange'] | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1308 at 0x53060b8L> | |
64 | |
['vmicrdv'] | |
Interfaces : | |
RPC f763c91c-2ab1-47fa-868f-7de7efd42194 (1.0) -- C:\windows\system32\vmrdvcore.dll | |
0 -> VmGetAppAllowListEntryByAlias | |
1 -> VmVerifyAppAllowed | |
Endpoints : | |
ncalrpc : RdvVmAllowListRpc | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1348 at 0x53062e8L> | |
64 | |
['vmicshutdown'] | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1372 at 0x53069b0L> | |
64 | |
['vmictimesync'] | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1392 at 0x5306ac8L> | |
64 | |
['UmRdpService'] | |
Interfaces : | |
RPC 7212a04b-b463-402e-9649-2ba477394676 (1.0) -- c:\windows\system32\umrdp.dll | |
0 -> CTSEventFilterBlockAllEvents::AllowTSEvent | |
1 -> RpcOpenDevice | |
2 -> RpcCloseDevice | |
3 -> RpcGetSessionId | |
4 -> RpcGetInterfaceGuids | |
5 -> RpcGetClientDeviceId | |
6 -> RpcGetDeviceCaps | |
RPC c80066a8-7579-44fc-b9b2-8466930791b0 (1.0) -- c:\windows\system32\umrdp.dll | |
0 -> RpcPrintDrvGetInfo | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
Endpoints : | |
ncalrpc : RemoteDevicesLPC_API | |
ncalrpc : TSUMRPD_PRINT_DRV_LPC_API | |
ncalrpc : OLEF239C965B5F7A486BA655D8FB6B3 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1408 at 0x5306b00L> | |
64 | |
['vmicvss'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
Endpoints : | |
ncalrpc : OLE0AC93FC754D4BF276C3945B96D2C | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1576 at 0x5306d30L> | |
64 | |
['ProfSvc'] | |
Interfaces : | |
RPC 326731e3-c1c0-4a69-ae20-7d9044a4ea5c (1.0) -- c:\windows\system32\profsvc.dll | |
0 -> DropClientContext | |
1 -> ReleaseClientContext | |
2 -> LoadUserProfileServer | |
3 -> UnloadUserProfileServer | |
4 -> DeleteProfileServer | |
5 -> RemapProfileServer | |
6 -> CreateProfileServer | |
7 -> ProcessWmiSettingsServer | |
RPC c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 (1.0) -- c:\windows\system32\SYSNTFY.dll | |
0 -> s_OnInitialConnection | |
1 -> s_OnCreateSession | |
2 -> s_OnStartScreenSaverAsDefaultUser | |
3 -> s_OnStopScreenSaverAsDefaultUser | |
4 -> s_OnLogon | |
5 -> s_OnLock | |
6 -> s_OnUnlock | |
7 -> s_OnStartScreenSaverAsUser | |
8 -> s_OnStopScreenSaverAsUser | |
9 -> s_OnDisconnect | |
10 -> s_OnReconnect | |
11 -> s_OnLogoff | |
12 -> s_OnTerminateSession | |
13 -> s_OnStartShell | |
14 -> s_OnEndShell | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
Endpoints : | |
ncalrpc : IUserProfile2 | |
ncalrpc : OLE578C3DF3149721A3389842CC648C | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1604 at 0x5306be0L> | |
64 | |
['nsi'] | |
Interfaces : | |
RPC 7ea70bcf-48af-4f6a-8968-6a440754d5fa (1.0) -- c:\windows\system32\nsisvc.dll | |
0 -> RpcNsiGetParameter | |
1 -> RpcNsiGetAllParameters | |
2 -> RpcNsiEnumerateObjectsAllParameters | |
3 -> RpcNsiSetParameter | |
4 -> RpcNsiSetAllParameters | |
5 -> RpcNsiRegisterChangeNotification | |
6 -> RpcNsiDeregisterChangeNotification | |
7 -> RpcNsiRequestChangeNotification | |
8 -> RpcNsiParameterChange | |
Endpoints : | |
ncalrpc : LRPC-743e6bda820abcb648 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1652 at 0x53063c8L> | |
64 | |
['EventSystem'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE 64b8f404-a4ae-11d1-b7b6-00c04fb926af (0.0) -- IEventSystemTier2Factory | |
OLE 00000001-0000-0000-c000-000000000046 (0.0) -- IClassFactory | |
OLE 609b954b-4fb6-11d1-9971-00c04fbbb345 (0.0) -- IEventSystemTier2 | |
OLE 609b9555-4fb6-11d1-9971-00c04fbbb345 (0.0) -- IEventClassTier2 | |
OLE 00000100-0000-0000-c000-000000000046 (0.0) -- IEnumUnknown | |
OLE 609b9557-4fb6-11d1-9971-00c04fbbb345 (0.0) -- IEventSubscriptionTier2 | |
Endpoints : | |
ncalrpc : OLE5B2510DDA8851BF9D25D05E69921 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1660 at 0x5306d68L> | |
64 | |
['SysMain'] | |
Interfaces : | |
RPC b58aa02e-2884-4e97-8176-4ee06d794184 (1.0) -- c:\windows\system32\sysmain.dll | |
0 -> PfRpcServerExecuteCommand | |
Endpoints : | |
ncalrpc : LRPC-7489ddaf2de31ec276 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1684 at 0x5306080L> | |
64 | |
['Themes'] | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "Memory Compression" pid 1932 at 0x5306da0L> | |
64 | |
[!!] Invalid rpcrt4 base: 0x0 vs 0x7ffec24f0000 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1980 at 0x5306518L> | |
64 | |
['Dhcp'] | |
Interfaces : | |
RPC 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6 (1.0) -- C:\windows\system32\dhcpcore6.dll | |
0 -> RpcSrvRequestPrefixEx | |
1 -> RpcSrvRenewPrefixEx | |
2 -> RpcSrvReleasePrefixEx | |
3 -> RpcSrvCancelOperation | |
4 -> RpcSrvEnablev6Tracing | |
5 -> RpcSrvRequestParams | |
6 -> RpcSrvAcquireParametersv6 | |
7 -> RpcSrvReleaseParametersv6 | |
8 -> RpcSrvQueryLeaseInfov6 | |
9 -> RpcSrvGetTraceArray | |
10 -> RpcSrvSetUserClass | |
11 -> RpcSrvQueryLeaseInfov6Array | |
12 -> RpcSrvEnableDhcpv6 | |
RPC 3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5 (1.0) -- c:\windows\system32\dhcpcore.dll | |
0 -> RpcSrvEnableDhcp | |
1 -> RpcSrvRenewLease | |
2 -> RpcSrvDeleteStaticAddressAndDefaultGateways | |
3 -> RpcSrvCheckServerAvailability | |
4 -> RpcSrvRenewLeaseByBroadcast | |
5 -> RpcSrvReleaseLease | |
6 -> RpcSrvSetFallbackParams | |
7 -> RpcSrvGetFallbackParams | |
8 -> RpcSrvFallbackRefreshParams | |
9 -> RpcSrvStaticRefreshParams | |
10 -> RpcSrvRemoveDnsRegistrations | |
11 -> RpcSrvRequestParams | |
12 -> RpcSrvPersistentRequestParams | |
13 -> RpcSrvRegisterParams | |
14 -> RpcSrvDeRegisterParams | |
15 -> RpcSrvEnumInterfaces | |
16 -> RpcSrvQueryLeaseInfo | |
17 -> RpcSrvQueryLeaseInfoArray | |
18 -> RpcSrvSetClassId | |
19 -> RpcSrvGetClassId | |
20 -> RpcSrvSetClientId | |
21 -> RpcSrvGetClientId | |
22 -> RpcSrvNotifyMediaReconnected | |
23 -> RpcSrvGetOriginalSubnetMask | |
24 -> RpcSrvSetMSFTVendorSpecificOptions | |
25 -> RpcSrvRequestCachedParams | |
26 -> RpcSrvRegisterConnectionStateNotification | |
27 -> RpcSrvDeRegisterConnectionStateNotification | |
28 -> RpcSrvGetNotificationStatus | |
29 -> RpcSrvGetDhcpServicedConnections | |
30 -> RpcSrvGetTraceArray | |
31 -> RpcSrvEnableTracing | |
32 -> RpcSrvLeaseIpAddressEx | |
33 -> RpcSrvRenewIpAddressLeaseEx | |
34 -> RpcSrvReleaseIpAddressLeaseEx | |
35 -> RpcSrvMadcapApiStartup | |
36 -> RpcSrvMadcapApiCleanup | |
37 -> RpcSrvMadcapEnumerateScopes | |
38 -> RpcSrvMadcapGenUID | |
39 -> RpcSrvMadcapRequestAddress | |
40 -> RpcSrvMadcapRenewAddress | |
41 -> RpcSrvMadcapReleaseAddress | |
Endpoints : | |
ncalrpc : dhcpcsvc6 | |
ncalrpc : dhcpcsvc | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1132 at 0x5306ef0L> | |
64 | |
['CertPropSvc'] | |
Interfaces : | |
RPC 30b044a5-a225-43f0-b3a4-e060df91f9c1 (1.0) -- c:\windows\system32\certprop.dll | |
0 -> s_RPC_SmartCardRootCertsNotifyService | |
1 -> s_RPC_SmartCardCertsNotifyService | |
Endpoints : | |
ncalrpc : LRPC-0bf0ff1ef1a9db2596 | |
-------------------------------------------------------------------------------- | |
<WinProcess "VSSVC.exe" pid 404 at 0x5306a20L> | |
64 | |
['VSS'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE 77ed5996-2f63-11d3-8a39-00c04f72d8e3 (0.0) -- IVssAdmin | |
OLE fa7df749-66e7-4986-a27f-e2f04ae53772 (0.0) -- IVssSnapshotMgmt | |
Endpoints : | |
ncalrpc : OLE3C135C6FB627CF9DADFBB6BC8CEA | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 1472 at 0x5306048L> | |
64 | |
['Schedule'] | |
Interfaces : | |
RPC 0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53 (1.0) -- c:\windows\system32\schedsvc.dll | |
0 -> ItSrvRegisterIdleTask | |
1 -> ItSrvUnregisterIdleTask | |
2 -> ItSrvProcessIdleTasks | |
3 -> ItSrvSetDetectionParameters | |
4 -> ItSrvSetRuntimeOverrides | |
RPC 1ff70682-0a51-30e8-076d-740be8cee98b (1.0) -- C:\windows\system32\taskcomp.dll | |
0 -> NetrJobAdd | |
1 -> NetrJobDel | |
2 -> NetrJobEnum | |
3 -> NetrJobGetInfo | |
RPC 378e52b0-c0a9-11cf-822d-00aa0051e40f (1.0) -- C:\windows\system32\taskcomp.dll | |
0 -> SASetAccountInformation | |
1 -> SASetNSAccountInformation | |
2 -> SAGetNSAccountInformation | |
3 -> SAGetAccountInformation | |
RPC 2a82bb21-e44f-4791-9aa1-dfae788e2f43 (1.0) -- c:\windows\system32\UBPM.dll | |
0 -> s_UbpmRpcOpenTaskHostChannel | |
1 -> s_UbpmRpcCloseTaskHostChannel | |
2 -> s_UbpmRpcTaskHostSendResponseReceiveCommand | |
3 -> s_UbpmRpcTaskHostReportTaskStatus | |
RPC 33d84484-3626-47ee-8c6f-e7e98b113be1 (2.0) -- C:\windows\SYSTEM32\WPTaskScheduler.dll | |
0 -> s_TaskSchedulerCreateSchedule | |
1 -> s_TaskSchedulerDeleteSchedule | |
2 -> s_TaskSchedulerFindFirstSchedule | |
3 -> s_TaskSchedulerFindNextSchedule | |
4 -> s_TaskSchedulerFindScheduleClose | |
5 -> s_TaskSchedulerGetSchedule | |
6 -> s_TaskSchedulerEnableSchedule | |
7 -> s_TaskSchedulerExecuteSchedule | |
8 -> s_TaskSchedulerAdvanceSchedule | |
9 -> s_TaskSchedulerAdvanceScheduleIntervals | |
10 -> s_TaskSchedulerSnoozeSchedule | |
11 -> s_TaskSchedulerGetPublishStateName | |
12 -> s_TaskSchedulerServiceControl | |
RPC 86d35949-83c9-4044-b424-db363231fd0c (1.0) -- c:\windows\system32\schedsvc.dll | |
0 -> SchRpcHighestVersion | |
1 -> _SchRpcRegisterTask | |
2 -> SchRpcRetrieveTask | |
3 -> SchRpcCreateFolder | |
4 -> SchRpcSetSecurity | |
5 -> SchRpcGetSecurity | |
6 -> SchRpcEnumFolders | |
7 -> SchRpcEnumTasks | |
8 -> SchRpcEnumInstances | |
9 -> SchRpcGetInstanceInfo | |
10 -> SchRpcStopInstance | |
11 -> SchRpcStop | |
12 -> SchRpcRun | |
13 -> SchRpcDelete | |
14 -> SchRpcRename | |
15 -> SchRpcScheduledRuntimes | |
16 -> SchRpcGetLastRunInfo | |
17 -> _SchRpcGetTaskInfo | |
18 -> SchRpcGetNumberOfMissedRuns | |
19 -> SchRpcEnableTask | |
RPC 3a9ef155-691d-4449-8d05-09ad57031823 (1.0) -- c:\windows\system32\schedsvc.dll | |
0 -> I_pSchRpcRegisterTask | |
1 -> I_pSchRpcEnumTasks | |
2 -> I_pSchRpcGetTaskInfo | |
3 -> I_pSchRpcAquireTaskStateNotificationsName | |
4 -> I_pAcquireBackgroundExecutionMode | |
5 -> I_pReleaseBackgroundExecutionMode | |
6 -> I_pSetTaskDisabledForCurrentUser | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
Endpoints : | |
ncalrpc : LRPC-69ba40d97baa37e78b | |
ncacn_np : \PIPE\atsvc | |
ncalrpc : ubpmtaskhostchannel | |
ncalrpc : LRPC-1eae62186b2bb71d85 | |
ncacn_ip_tcp : 49666 | |
ncalrpc : OLEB9967DDCAAC08A0219EA8093CC24 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2056 at 0x5306828L> | |
64 | |
['SENS'] | |
Interfaces : | |
RPC 63fbe424-2029-11d1-8db8-00aa004abd5e (1.0) -- c:\windows\system32\sens.dll | |
0 -> RPC_IsNetworkAlive | |
1 -> RPC_IsDestinationReachableA | |
2 -> RPC_IsDestinationReachableA | |
RPC a0bc4698-b8d7-4330-a28f-7709e18b6108 (4.0) -- c:\windows\system32\sens.dll | |
0 -> RPC_SensNotifyWinlogonEvent | |
1 -> RPC_SensNotifyRasEvent | |
2 -> RPC_SensNotifyNetconEvent | |
RPC c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 (1.0) -- c:\windows\system32\SYSNTFY.dll | |
0 -> s_OnInitialConnection | |
1 -> s_OnCreateSession | |
2 -> s_OnStartScreenSaverAsDefaultUser | |
3 -> s_OnStopScreenSaverAsDefaultUser | |
4 -> s_OnLogon | |
5 -> s_OnLock | |
6 -> s_OnUnlock | |
7 -> s_OnStartScreenSaverAsUser | |
8 -> s_OnStopScreenSaverAsUser | |
9 -> s_OnDisconnect | |
10 -> s_OnReconnect | |
11 -> s_OnLogoff | |
12 -> s_OnTerminateSession | |
13 -> s_OnStartShell | |
14 -> s_OnEndShell | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 97312c82-d4c2-11d1-b682-00805fc79216 (0.0) -- ICollectionNotify | |
Endpoints : | |
ncalrpc : senssvc | |
ncalrpc : LRPC-cc6192df9611677bb5 | |
ncalrpc : OLE12DBE078CDEC19CDB2151EB60065 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2132 at 0x5306fd0L> | |
64 | |
['AudioEndpointBuilder'] | |
Interfaces : | |
Endpoints : | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2156 at 0x5319898L> | |
64 | |
['FontCache'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 97ea99c7-0186-4ad4-8df9-c5b4e0ed6b22 (0.0) -- IBackgroundCopyCallback | |
Endpoints : | |
ncalrpc : OLEB3F53AD0BE01D0AE74A209B34604 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2168 at 0x5319cf8L> | |
64 | |
['LanmanWorkstation'] | |
Interfaces : | |
RPC f2c9b409-c1c9-4100-8639-d8ab1486694a (1.0) -- c:\windows\system32\wkssvc.dll | |
0 -> ClusterConnectUpcall | |
1 -> ClusterDisConnectUpcall | |
RPC eb081a0d-10ee-478a-a1dd-50995283e7a8 (3.0) -- c:\windows\system32\wkssvc.dll | |
0 -> GetWitnessNodes | |
RPC 6bffd098-a112-3610-9833-46c3f87e345a (1.0) -- c:\windows\system32\wkssvc.dll | |
0 -> NetrWkstaGetInfo | |
1 -> NetrWkstaSetInfo | |
2 -> NetrWkstaUserEnum | |
3 -> NetrWkstaUserGetInfo | |
4 -> NetrWkstaUserSetInfo | |
5 -> NetrWkstaTransportEnum | |
6 -> NetrWkstaTransportAdd | |
7 -> NetrWkstaTransportDel | |
8 -> NetrUseAdd | |
9 -> NetrUseGetInfo | |
10 -> NetrUseDel | |
11 -> NetrUseEnum | |
12 -> I_NetrLogonDomainNameAdd | |
13 -> NetrWorkstationStatisticsGet | |
14 -> I_NetrLogonDomainNameAdd | |
15 -> I_NetrLogonDomainNameAdd | |
16 -> I_NetrLogonDomainNameAdd | |
17 -> I_NetrLogonDomainNameAdd | |
18 -> I_NetrLogonDomainNameAdd | |
19 -> I_NetrLogonDomainNameAdd | |
20 -> NetrGetJoinInformation | |
21 -> I_NetrLogonDomainNameAdd | |
22 -> NetrJoinDomain2 | |
23 -> NetrUnjoinDomain2 | |
24 -> NetrRenameMachineInDomain2 | |
25 -> NetrValidateName2 | |
26 -> NetrGetJoinableOUs2 | |
27 -> NetrAddAlternateComputerName | |
28 -> NetrRemoveAlternateComputerName | |
29 -> NetrSetPrimaryComputerName | |
30 -> NetrEnumerateComputerNames | |
RPC 7f1343fe-50a9-4927-a778-0c5859517bac (1.0) -- c:\windows\system32\wkssvc.dll | |
0 -> DfsDsGetDcName | |
1 -> DfsDsIsDomainController | |
2 -> DfsCredWrite | |
3 -> DfsCredDelete | |
Endpoints : | |
ncalrpc : LRPC-28f9e92a2d2927492b | |
ncacn_np : \PIPE\wkssvc | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2256 at 0x5319cc0L> | |
64 | |
['NlaSvc'] | |
Interfaces : | |
RPC aa411582-9bdf-48fb-b42b-faa1eee33949 (1.0) -- c:\windows\system32\nlasvc.dll | |
0 -> PMuxRpcPluginRegister | |
1 -> PMuxRpcPluginUnregister | |
2 -> PMuxRpcPluginDataIndicate | |
RPC c33b9f46-2088-4dbc-97e3-6125f127661c (1.0) -- c:\windows\system32\nlasvc.dll | |
0 -> AppSrv_NlaOpenQuery | |
1 -> AppSrv_NlaAsyncIndicate | |
2 -> AppSrv_NlaRefreshQuery | |
3 -> AppSrv_NlaCloseQuery | |
4 -> RpcNlaIndicateReprobe | |
5 -> RpcNlaGetCaptivePortalHosts | |
RPC 4c8d0bef-d7f1-49f0-9102-caa05f58d114 (1.0) -- c:\windows\system32\nlasvc.dll | |
0 -> RPCQueryLANIds | |
Endpoints : | |
ncalrpc : nlaplg | |
ncalrpc : nlaapi | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2308 at 0x5319f60L> | |
64 | |
['Dnscache'] | |
Interfaces : | |
RPC 45776b01-5956-4485-9f80-f428f7d60129 (2.0) -- c:\windows\system32\dnsrslvr.dll | |
0 -> CRrReadCache | |
1 -> R_ResolverGetConfig | |
2 -> R_ResolverFlushCache | |
3 -> R_ResolverFlushCacheEntry | |
4 -> R_ResolverQuery | |
5 -> R_DnsRegisterLocal | |
6 -> R_DnsDeRegisterLocal | |
7 -> R_DnsStartMulticastQuery | |
8 -> R_DnsGetMulticastData | |
9 -> R_DnsStopMulticastQuery | |
10 -> R_ResolverSimpleOp | |
11 -> R_DnsGetProxyInformation | |
12 -> R_DnsGetPolicyTableInfo | |
13 -> R_DnsSetConnectionPolicyInfo | |
14 -> R_DnsDeleteConnectionPolicyInfo | |
15 -> R_DnsGetSettings | |
16 -> R_DnsSetSettings | |
17 -> R_DnsGetInterfaceSettings | |
18 -> R_DnsSetInterfaceSettings | |
19 -> R_DnsGetAdaptersInfo | |
Endpoints : | |
ncalrpc : DNSResolver | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2360 at 0x5319da0L> | |
64 | |
['Audiosrv'] | |
Interfaces : | |
RPC 09704557-82c0-416b-b6e4-c85b8f789803 (2.8) -- c:\windows\system32\audiosrv.dll | |
0 -> AudioServerGetMixFormat | |
1 -> AudioServerIsFormatSupported | |
2 -> AudioServerGetDevicePeriod | |
3 -> AudioServerIsOffloadCapable | |
4 -> AudioServerInitialize | |
5 -> AudioServerDisconnect | |
6 -> AudioServerGetAudioSession | |
7 -> AudioServerCreateStream | |
8 -> AudioServerStartStream | |
9 -> AudioServerStopStream | |
10 -> AudioServerPreStartStream | |
11 -> AudioServerStartStreamAborted | |
12 -> AudioServerResetEndpoint | |
13 -> AudioServerDestroyStream | |
14 -> AudioServerGetEndpointBufferSize | |
15 -> AudioServerGetStreamLatency | |
16 -> AudioServerSetStreamSampleRate | |
17 -> AudioServerGetChannelCount | |
18 -> AudioServerSetChannelVolume | |
19 -> AudioServerGetChannelVolume | |
20 -> AudioServerSetAllVolumes | |
21 -> AudioServerGetAllVolumes | |
22 -> AudioServerSetAllInitialVolumesWithRamp | |
23 -> AudioSessionGetId | |
24 -> AudioSessionGetInstanceId | |
25 -> AudioSessionGetStreamSwitchId | |
26 -> AudioSessionGetProcessId | |
27 -> AudioSessionGetState | |
28 -> AudioSessionGetLastActivation | |
29 -> AudioSessionGetLastInactivation | |
30 -> AudioSessionIsSystemSoundsSession | |
31 -> AudioSessionGetDisplayOptions | |
32 -> AudioSessionGetDisplayName | |
33 -> AudioSessionSetDisplayName | |
34 -> AudioSessionGetIconPath | |
35 -> AudioSessionSetIconPath | |
36 -> AudioSessionGetGroupingParam | |
37 -> AudioSessionSetGroupingParam | |
38 -> AudioSessionGetVolume | |
39 -> AudioSessionSetVolume | |
40 -> AudioSessionGetMute | |
41 -> AudioSessionSetMute | |
42 -> AudioSessionGetChannelCount | |
43 -> AudioSessionSetChannelVolume | |
44 -> AudioSessionGetChannelVolume | |
45 -> AudioSessionSetAllVolumes | |
46 -> AudioSessionGetAllVolumes | |
47 -> AudioSessionPropertyStoreCommit | |
48 -> AudioSessionPropertyStoreGetAt | |
49 -> AudioSessionPropertyStoreGetCount | |
50 -> AudioSessionPropertyStoreGetValue | |
51 -> AudioSessionPropertyStoreSetValue | |
52 -> AudioSessionSetDuckingPreference | |
53 -> AudioSessionGetDuckingState | |
54 -> AudioSessionGetIsComms | |
55 -> AudioSessionDestroy | |
56 -> AudioSessionMeterGetPeakValue | |
57 -> AudioSessionMeterGetMeteringChannelCount | |
58 -> AudioSessionMeterGetChannelsPeakValues | |
59 -> AudioSessionSetWindowId | |
60 -> PolicyConfigGetMixFormat | |
61 -> PolicyConfigGetDeviceFormat | |
62 -> PolicyConfigSetDeviceFormat | |
63 -> PolicyConfigResetDeviceFormat | |
64 -> PolicyConfigGetProcessingPeriod | |
65 -> PolicyConfigSetProcessingPeriod | |
66 -> PolicyConfigGetShareMode | |
67 -> PolicyConfigSetShareMode | |
68 -> PolicyConfigGetPropertyValue | |
69 -> PolicyConfigSetPropertyValue | |
70 -> PolicyConfigSetDefaultEndpoint | |
71 -> PolicyConfigSetEndpointVisibility | |
72 -> PolicyConfigSetEndpointAbilityToBeDefault | |
73 -> PolicyConfigSetAccessibilityAudioMonoMixState | |
74 -> PolicyConfigGetAccessibilityAudioMonoMixState | |
75 -> PolicyConfigValidateSpatialAudioSettings | |
76 -> PolicyConfigReportSpatialLicenseChanged | |
77 -> PolicyConfigSetMixedRealitySpatialAudioFormatPolicy | |
78 -> PolicyConfigGetDeviceFormatAndSpatialSettings | |
79 -> PolicyConfigSetDeviceSpatialSettings | |
80 -> PolicyConfigAddDynamicRoutingRule | |
81 -> PolicyConfigRemoveDynamicRoutingRule | |
82 -> PolicyConfigUpdateDynamicRoutingRule | |
83 -> PolicyConfigGetDynamicRoutingRule | |
84 -> GetAudioSessionManager | |
85 -> AudioSessionManagerDestroy | |
86 -> AudioSessionManagerGetAudioSessions | |
87 -> AudioSessionManagerGetCurrentSession | |
88 -> AudioSessionManagerGetExistingSession | |
89 -> AudioSessionManagerGetSessionForStreamSwitch | |
90 -> AudioSessionManagerAddAudioSessionClientNotification | |
91 -> AudioSessionManagerDeleteAudioSessionClientNotification | |
92 -> AudioSessionManagerAddVolumeDuckNotification | |
93 -> AudioSessionManagerDeleteVolumeDuckNotification | |
94 -> AudioVolumeConnect | |
95 -> AudioVolumeDisconnect | |
96 -> AudioVolumeQueryHardwareSupport | |
97 -> AudioVolumeGetVolumeRange | |
98 -> AudioVolumeGetChannelCount | |
99 -> AudioVolumeSetMasterVolumeLevel | |
100 -> AudioVolumeSetMasterVolumeLevelScalar | |
101 -> AudioVolumeGetMasterVolumeLevel | |
102 -> AudioVolumeGetMasterVolumeLevelScalar | |
103 -> AudioVolumeSetChannelVolumeLevel | |
104 -> AudioVolumeSetChannelVolumeLevelScalar | |
105 -> AudioVolumeGetChannelVolumeLevel | |
106 -> AudioVolumeGetChannelVolumeLevelScalar | |
107 -> AudioVolumeSetMute | |
108 -> AudioVolumeGetMute | |
109 -> AudioVolumeAddMasterVolumeNotification | |
110 -> AudioVolumeDeleteMasterVolumeNotification | |
111 -> AudioMeterGetPeakValue | |
112 -> AudioMeterGetMeteringChannelCount | |
113 -> AudioMeterGetChannelsPeakValues | |
114 -> AudioVolumeGetStepInfo | |
115 -> AudioVolumeStepUp | |
116 -> AudioVolumeStepDown | |
117 -> AudioServerGetBufferSizeLimits | |
118 -> AudioServerSetLastBufferInProgress | |
119 -> AudioServerIsRawStreamSupported | |
120 -> AudioServerDeriveStreamCategory | |
121 -> AudioServerGetStreamVpoContext | |
122 -> AudioServerGetEndpointVpoContext | |
123 -> AudioServerCloseVpoContext | |
124 -> AudioServerGetCurrentSharedModeEnginePeriod | |
125 -> AudioServerGetSharedModeEnginePeriod | |
126 -> AudioServerRequestSpatialDynamicObjects | |
127 -> AudioServerSetAmbMetadata | |
128 -> AudioServerSetAmbHeadTracking | |
129 -> AudioServerGetAmbHeadTracking | |
130 -> AudioServerSetAmbRotation | |
131 -> asm_GetApplicationSubmixContext | |
132 -> asm_GetApplicationSubmixContextFromPID | |
133 -> asm_GetApplicationSubmixContextForProcessTree | |
134 -> asm_ApplicationSubmixContextDestroy | |
135 -> asm_GetApplicationSubmixes | |
136 -> asm_ApplicationSubmixDestroy | |
137 -> asm_AudioServerGetApplicationSubmixFormat | |
138 -> asm_AudioServerGetApplicationSubmixPeriod | |
139 -> asm_AudioServerGetApplicationSubmixId | |
140 -> asm_GetApplicationSubmixFromId | |
141 -> asm_AudioServerInitializeStream | |
142 -> AudioServerTelephonyControlStartSession | |
143 -> AudioServerTelephonyControlIsSessionStarted | |
144 -> AudioServerTelephonyControlEndSession | |
145 -> AudioServerTelephonyControlSetRoutingPolicy | |
146 -> AudioServerTelephonyControlGetRoutingPolicy | |
147 -> AudioServerTelephonyControlSetCallState | |
148 -> AudioServerTelephonyControlGetCallState | |
149 -> AudioServerTelephonyControlProviderChange | |
150 -> AudioServerTelephonyControlSetMute | |
151 -> AudioServerTelephonyControlGetMute | |
152 -> AudioServerTelephonyControlSetVOIPMute | |
153 -> AudioServerTelephonyControlGetVOIPMute | |
154 -> AudioServerTelephonyControlSetVolume | |
155 -> AudioServerTelephonyControlGetMaxCallInstanceCount | |
156 -> AudioServerTelephonyControlGetValidTelephonyInstance | |
157 -> AudioServerGetAudioHistoryProducerHandle | |
158 -> AudioServerReleaseAudioHistoryProducerHandle | |
159 -> AudioServerGetAudioHistoryProducerInfo | |
160 -> AudioServerPopulateAudioHistoryForStream | |
161 -> PolicyConfigGetEndpointExtendedSpatialLicenseInfo | |
RPC 7c69ac10-fa12-4dbf-90d9-c7f1e40f5dc5 (1.6) -- c:\windows\system32\audiosrv.dll | |
0 -> s_winmmGetPnpInfo | |
1 -> s_mmeNotifyDeviceStateChanged | |
2 -> s_mmeNotifyDeviceAdded | |
3 -> s_mmeNotifyDeviceRemoved | |
4 -> s_mmeNotifyDefaultDeviceChanged | |
5 -> s_tsSessionGetAudioProtocol | |
6 -> s_tsRegisterAudioProtocolNotification | |
7 -> s_tsUnregisterAudioProtocolNotification | |
8 -> s_sndevtResolveSoundAlias | |
9 -> s_pbmRegisterPlaybackManagerNotifications | |
10 -> s_pbmUnregisterPlaybackManagerNotifications | |
11 -> s_pbmSetSmtcSubscriptionState | |
12 -> s_pbmGetSoundLevel | |
13 -> s_ccCreateHandsfreeHidFileFromAudioId | |
14 -> s_pbmRegisterAppClosureNotification | |
15 -> s_pbmUnregisterAppClosureNotification | |
16 -> s_pbmPlayToStreamStateChanged | |
17 -> s_pbmIsPlaying | |
18 -> s_pbmCastingAppStateChanged | |
19 -> s_pbmVoipCallStateChanged | |
20 -> s_pbmLaunchBackgroundTask | |
21 -> s_pbmRegisterAsBackgroundTask | |
22 -> s_afxOpenAudioEffectsWatcher | |
23 -> s_afxCloseAudioEffectsWatcher | |
24 -> s_midiOpenPort | |
25 -> s_rtgGetDefaultAudioEndpoint | |
26 -> s_apmRegisterProxyAudioProcess | |
27 -> s_apmSetDuckingGainForId | |
28 -> s_apmSetLayoutGainForId | |
29 -> s_apmSetVolumeGroupGainForId | |
30 -> s_apmSetVolumeGroupGainScalarForId | |
31 -> s_apmSetVolumeGroupMuteForId | |
32 -> s_setRingerVibrateState | |
33 -> s_getRingerVibrateState | |
34 -> s_getEmergencyCallbackMode | |
35 -> s_setEmergencyCallbackMode | |
36 -> s_apmSetPersistedDefaultAudioEndpoint | |
37 -> s_apmGetPersistedDefaultAudioEndpoint | |
38 -> s_apmClearAllPersistedApplicationDefaultEndpoints | |
39 -> s_apmRegisterAudioStateMonitor | |
40 -> s_apmUnregisterAudioStateMonitor | |
41 -> s_apmHandleEuVolumeNotificationResponse | |
42 -> AudioServerTelephonyControlGetCallStateSync | |
43 -> AudioServerTelephonyControlGetMuteSync | |
44 -> s_apmSetBalanceGroupBalanceForId | |
45 -> s_apmSetPreferredChatApplication | |
46 -> s_apmResetPreferredChatApplication | |
47 -> s_CreateHolographicDisplay | |
48 -> s_DestroyHolographicDisplay | |
49 -> s_GetHeadRotation | |
RPC 910562c3-ebd9-46b9-baba-1d45842a0ceb (1.0) -- c:\windows\system32\audiosrv.dll | |
0 -> s_pbmReportAppInteractivityChange | |
1 -> CHybridPropertyStore::Commit | |
2 -> s_pbmAllowMediaPlaybackForApp | |
3 -> s_CapabilityAccessManagerNotification | |
4 -> s_pbmRegisterAppManagerNotification | |
5 -> s_pbmUnregisterAppManagerNotification | |
6 -> s_pbmReportAppClosing | |
7 -> s_pbmReportHostedAppStateChange | |
8 -> s_SetScreenReaderState | |
9 -> s_pbmSwitchSoftNonInteractiveAppsToHardNonInteractive | |
10 -> s_pbmReportApplicationState | |
11 -> s_pbmSetApplicationViewPosition | |
RPC cba4c918-e55a-46ee-aa62-cade158e9165 (1.0) -- c:\windows\system32\audiosrv.dll | |
0 -> s_adGetDeviceGraphWnfStateName | |
RPC c7ce3826-891f-4376-b161-c63d2403142c (1.0) -- c:\windows\system32\audiosrv.dll | |
0 -> s_RequestHrtfData | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE a8a900c6-da0b-5bcc-a71a-be0b9265d87a (0.0) -- __FITypedEventHandler_2_Windows__CApplicationModel__CPackageCatalog_Windows__CApplicationModel__CPackageInstallingEventArgs | |
OLE bd636cf1-541f-53ea-8efc-e1604a395b1a (0.0) -- __FITypedEventHandler_2_Windows__CApplicationModel__CPackageCatalog_Windows__CApplicationModel__CPackageUninstallingEventArgs | |
OLE 2f732065-eff0-4c7c-8fc1-363851b1f1d7 (0.0) -- iaudiographcallback | |
Endpoints : | |
ncalrpc : AudioClientRpc | |
ncalrpc : Audiosrv | |
ncalrpc : PlaybackManagerRpc | |
ncalrpc : AudioSrvDiagnosticsRpc | |
ncalrpc : SpatialSoundDataManagerRpc | |
ncalrpc : OLEA1694B7BE165BE08A75BA4D67625 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2440 at 0x5319a58L> | |
64 | |
['SessionEnv'] | |
Interfaces : | |
RPC c9ac6db5-82b7-4e55-ae8a-e464ed7b4277 (1.0) -- c:\windows\system32\SYSNTFY.dll | |
0 -> s_OnInitialConnection | |
1 -> s_OnCreateSession | |
2 -> s_OnStartScreenSaverAsDefaultUser | |
3 -> s_OnStopScreenSaverAsDefaultUser | |
4 -> s_OnLogon | |
5 -> s_OnLock | |
6 -> s_OnUnlock | |
7 -> s_OnStartScreenSaverAsUser | |
8 -> s_OnStopScreenSaverAsUser | |
9 -> s_OnDisconnect | |
10 -> s_OnReconnect | |
11 -> s_OnLogoff | |
12 -> s_OnTerminateSession | |
13 -> s_OnStartShell | |
14 -> s_OnEndShell | |
RPC b12fd546-c875-4b41-97d8-950487662202 (1.0) -- c:\windows\system32\sessenv.dll | |
0 -> RpcCreateUserVhdTemplate | |
1 -> RpcGetCreateUserProfileVhd | |
2 -> RpcDestroyUserProfileVhd | |
3 -> RpcRepairUserProfileVhd | |
4 -> RpcReEncryptUserCredential | |
5 -> RpcDeleteFileFromVHD | |
6 -> RpcSetupVhdForRdv | |
7 -> RpcCopyRdvFolderFromVhdToHost | |
8 -> RpcQueryVhdOfflineInformation | |
RPC 1257b580-ce2f-4109-82d6-a9459d0bf6bc (1.0) -- c:\windows\system32\sessenv.dll | |
0 -> RpcShadow2 | |
RPC 29770a8f-829b-4158-90a2-78cd488501f7 (1.0) -- c:\windows\system32\sessenv.dll | |
0 -> TSSDFarmRpcGrantUserTSAccessRight | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
Endpoints : | |
ncalrpc : LRPC-b8b4b9a4b26ab9c3dd | |
ncalrpc : SessEnvPrivateRpc | |
ncacn_np : \pipe\SessEnvPublicRpc | |
ncacn_ip_tcp : 49667 | |
ncalrpc : OLEBE26F437DB1B1A053CE2B4E444BD | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2552 at 0x5319160L> | |
64 | |
['netprofm'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE d0074ffd-570f-4a9b-8d69-199fdba5723b (0.0) -- INetworkListManager | |
OLE b196b284-bab4-101a-b69c-00aa00341d07 (0.0) -- IConnectionPointContainer | |
OLE 26656eaa-54eb-4e6f-8f85-4f0ef901a406 (0.0) -- IEnumNetwork | |
OLE b196b286-bab4-101a-b69c-00aa00341d07 (0.0) -- IConnectionPoint | |
OLE bcd1de7e-2db1-418b-b047-4a74e101f8c1 (0.0) -- IEnumNetworkInterface | |
OLE 2a1c9eb2-df62-4154-b800-63278fcb8037 (0.0) -- INetworkInterface | |
OLE 8a40a45d-055c-4b62-abd7-6d613e2ceaec (0.0) -- INetwork | |
OLE 55272a00-42cb-11ce-8135-00aa004bb851 (0.0) -- IPropertyBag | |
Endpoints : | |
ncalrpc : OLE8BB424308424F763316FA2041545 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2704 at 0x5319940L> | |
64 | |
['UserManager'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE 00000035-0000-0000-c000-000000000046 (0.0) -- IActivationFactory | |
OLE af86e2e0-b12d-4c6a-9c5a-d7aa65101e90 (0.0) -- IInspectable | |
OLE 155eb23b-242a-45e0-a2e9-3171fc6a7fdd (0.0) -- Windows.System.IUserStatics | |
OLE 252e7f79-acfa-4ea2-9a7e-fa27a8a4d3d9 (0.0) -- Windows.System.Internal.IUserManagerStatics | |
RPC b18fbab6-56f8-4702-84e0-41053293a869 (1.0) -- c:\windows\system32\usermgr.dll | |
0 -> svcQueryUserToken | |
1 -> svcGetConstrainedUserToken | |
2 -> svcIsAllowedToActivateAsUser | |
3 -> svcQueryDefaultAccountToken | |
4 -> svcQuerySessionVirtualAccountToken | |
5 -> svcLaunchShell | |
6 -> svcLaunchShellInfrastructureHost | |
7 -> svcSetShellInformation | |
8 -> svcInformUserLogon | |
9 -> svcInformUserLogoff | |
10 -> svcQueryUserContext | |
11 -> svcUMLogonUser | |
12 -> svcQuerySessionUserToken | |
13 -> svcGetConstrainedUserTokenFromAppcontainer | |
14 -> svcEnumerateSessionUsers | |
15 -> svcQueryUserTokenFromName | |
16 -> svcQueryUserContextFromName | |
17 -> svcQueryUserTokenFromSid | |
18 -> svcQueryUserContextFromSid | |
19 -> svcOpenProcessHandleForAccess | |
20 -> svcOpenProcessTokenForQuery | |
21 -> svcUMSetCachedCredentials | |
22 -> svcUMGetCachedCredentials | |
23 -> svcInformFlags | |
24 -> svcChangeSessionUserToken | |
25 -> svcConnectLocalUser | |
26 -> svcDisconnectLocalUser | |
27 -> svcGetImpersonationTokenForContext | |
28 -> svcGetDefaultSignInAccount | |
29 -> svcClearDefaultSignInAccount | |
30 -> svcGetSessionActiveShellUserToken | |
31 -> svcChangeSessionActiveShellUser | |
32 -> svcIsCandidateUser | |
33 -> svcIsEphemeralCandidateUser | |
34 -> svcGetCandidateAccountCredz | |
35 -> svcConnectCandidateUser | |
36 -> svcGetNonCandidateUserSessionIds | |
37 -> svcGetCandidateUserSessionIds | |
38 -> svcRefreshCandidateUser | |
39 -> svcCleanupDisardedCandidateAccounts | |
RPC 0d3c7f20-1c8d-4654-a1b3-51563b298bda (1.0) -- c:\windows\system32\usermgr.dll | |
0 -> svcGetUserMarshalData | |
OLE 100eb64b-b24c-4c38-8964-720d926d05a4 (0.0) -- Windows.System.Internal.ISignInStateManager | |
OLE 039a83e3-d5bd-491a-9e47-3feba3427a92 (0.0) -- Windows.System.Internal.IUserManagerStatics2 | |
OLE 155eb23b-242a-45e0-a2e9-3171fc6a7fbb (0.0) -- Windows.System.IUserWatcher | |
OLE df9a26c6-e746-4bcd-b5d4-120103c4209b (0.0) -- Windows.System.IUser | |
OLE 086459dc-18c6-48db-bc99-724fb9203ccc (0.0) -- Windows.System.IUserChangedEventArgs | |
OLE 00000141-0000-0000-c000-000000000046 (0.0) -- IDLLHost | |
OLE e44ea1df-bb85-5a8c-bddc-c8e960c355c9 (0.0) -- Windows.Foundation.IAsyncOperation[Windows.Foundation.Collections.IVectorView[Windows.System.User]] | |
OLE 8cbd762a-1222-5ee5-b745-489e7a42c6ec (0.0) -- Windows.Foundation.Collections.IVectorView[Windows.System.User] | |
OLE d1bacd1f-0376-5823-8c29-1d45b9f4c191 (0.0) -- Windows.Foundation.Collections.IIterable[Windows.System.User] | |
OLE 326fe162-582b-5659-b8a4-68ff0f525745 (0.0) -- Windows.Foundation.Collections.IIterator[Windows.System.User] | |
Endpoints : | |
ncalrpc : OLEA77733BCBA2363EA22EE88F88799 | |
ncalrpc : LRPC-6aa8542cba4ba33921 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2752 at 0x5319518L> | |
64 | |
['Winmgmt'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE f309ad18-d86a-11d0-a075-00c04fb68820 (0.0) -- IWbemLevel1Login | |
OLE d4781cd6-e5d3-44df-ad94-930efe48a887 (0.0) -- IWbemLoginClientID | |
OLE 9f6c78ef-fce5-42fa-abea-3e7df91921dc (0.0) -- IWbemLoginClientIDEx | |
OLE 9556dc99-828c-11cf-a37e-00aa003240c7 (0.0) -- IWbemServices | |
OLE 21cd80a2-b305-4f37-9d4c-4534a8d9b568 (0.0) -- _IWmiProviderFactory | |
OLE 027947e1-d731-11ce-a357-000000000001 (0.0) -- IEnumWbemClassObject | |
OLE 1c1c45ee-4395-11d2-b60b-00104b703efd (0.0) -- IWbemFetchSmartEnum | |
OLE 423ec01e-2e35-11d2-b604-00104b703efd (0.0) -- IWbemWCOSmartEnum | |
OLE eb658b8a-7a64-4ddc-9b8d-a92610db0206 (0.0) -- _IWmiProviderQuota | |
OLE 7c857801-7381-11cf-884d-00aa004b2e24 (0.0) -- IWbemObjectSink | |
OLE a359dec5-e813-4834-8a2a-ba7f1d777d76 (0.0) -- IWbemBackupRestoreEx | |
OLE 44aca675-e8fc-11d0-a07c-00c04fb68820 (0.0) -- IWbemCallResult | |
OLE 2c9273e0-1dc3-11d3-b364-00105a1f8177 (0.0) -- IWbemRefreshingServices | |
OLE e8107bdf-baaf-4c7c-bb5f-9d732e8d8f07 (0.0) -- _IWmiProvSS | |
OLE b7b31df9-d515-11d3-a11c-00105a1f515a (0.0) -- IWbemShutdown | |
Endpoints : | |
ncalrpc : OLE11083159669C9FB82CBA07C20342 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2764 at 0x5319a20L> | |
64 | |
['WinHttpAutoProxySvc'] | |
Interfaces : | |
RPC 3473dd4d-2e88-4006-9cba-22570909dd10 (5.1) -- c:\windows\system32\winhttp.dll | |
0 -> GetProxyForUrl | |
1 -> ResetAutoProxy | |
2 -> SaveProxyCredentials | |
3 -> StoreSavedProxyCredentialsForCurrentUser | |
4 -> DeleteSavedProxyCredentials | |
5 -> ReindicateAllProxies | |
6 -> ReadProxySettings | |
7 -> WriteProxySettings | |
8 -> ConnectionUpdateIfIndexTable | |
9 -> ConnectionSetPolicyEntries | |
10 -> ConnectionDeletePolicyEntries | |
RPC 824d8d77-a27f-4915-a536-36e9283dce29 (5.1) -- c:\windows\system32\winhttp.dll | |
0 -> s_PacWorkerCallbackInitSessionRpc | |
1 -> s_PacWorkerCallbackCloseSessionRpc | |
2 -> s_PacWorkerCallbackIsResolvableRpc | |
3 -> s_PacWorkerCallbackIsResolvableExRpc | |
4 -> s_PacWorkerCallbackIsInNetRpc | |
5 -> s_PacWorkerCallbackIsInNetExRpc | |
6 -> s_PacWorkerCallbackDnsResolveRpc | |
7 -> s_PacWorkerCallbackDnsResolveExRpc | |
8 -> s_PacWorkerCallbackMyIpAddressRpc | |
9 -> s_PacWorkerCallbackMyIpAddressExRpc | |
10 -> s_PacWorkerCallbackSortIpAddressListRpc | |
Endpoints : | |
ncalrpc : LRPC-1106d284665f4b3d5d | |
ncalrpc : a13b2b26-4e2b-4250-bff3-06ba3da81956 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2252 at 0x5319240L> | |
64 | |
['Wcmsvc'] | |
Interfaces : | |
RPC abfb6ca3-0c5e-4734-9285-0aee72fe8d1c (1.0) -- c:\windows\system32\wcmsvc.dll | |
0 -> RpcOpenHandle | |
1 -> RpcCloseHandle | |
2 -> RpcEnumInterfaces | |
3 -> RpcQueryParameter | |
4 -> RpcSetParameter | |
5 -> RpcQueryPublicParameter | |
6 -> RpcSetPublicParameter | |
7 -> RpcSetProfileList | |
8 -> RpcGetProfileList | |
9 -> RpcGetProfileListByPurpose | |
10 -> RpcGetTokens | |
11 -> RpcOrderConnection | |
12 -> RpcBeginIgnoreProfileList | |
13 -> RpcResetIgnoreProfileList | |
14 -> RpcEndIgnoreProfileList | |
15 -> RpcOpenOnDemandRequestHandle | |
16 -> RpcOpenOnDemandRequestHandleByWwanProfileName | |
17 -> RpcStartOnDemandRequest | |
18 -> RpcCancelOnDemandRequest | |
19 -> RpcCloseOnDemandRequestHandle | |
20 -> RpcQueryOnDemandRequestStateInfo | |
RPC b37f900a-eae4-4304-a2ab-12bb668c0188 (1.0) -- c:\windows\system32\wcmsvc.dll | |
0 -> RpcRegisterForNotifications | |
1 -> RpcGetPendingNotification | |
2 -> RpcCloseNotificationsHandle | |
3 -> RpcAcquireSelectableConnectionAsync | |
4 -> RpcReleaseSelectableConnection | |
5 -> RpcGetSelectableConnectionList | |
6 -> RpcGetInterfaceContextTable | |
7 -> RpcAddRoutePolicy | |
8 -> RpcRemoveRoutePolicy | |
9 -> RpcRemoveMatchingRoutePolicy | |
10 -> RpcGetRoutingHint | |
11 -> RpcCheckCapabilityStatus | |
RPC e7f76134-9ef5-4949-a2d6-3368cc0988f3 (1.0) -- c:\windows\system32\wcmsvc.dll | |
0 -> RpcEnterConnectedStandby | |
1 -> RpcExitConnectedStandby | |
2 -> RpcEnterNetQuiet | |
3 -> RpcExitNetQuiet | |
RPC 7aeb6705-3ae6-471a-882d-f39c109edc12 (1.0) -- c:\windows\system32\wcmsvc.dll | |
0 -> RpcSetOperatorDataplanStatus | |
1 -> RpcSetOperatorConnectionCost | |
2 -> RpcSetOperatorCycleData | |
RPC f44e62af-dab1-44c2-8013-049a9de417d6 (1.0) -- c:\windows\system32\wcmsvc.dll | |
0 -> RpcUpdateCapabilityAccess | |
1 -> RpcDeprovisionCapability | |
RPC c2d1b5dd-fa81-4460-9dd6-e7658b85454b (1.0) -- c:\windows\system32\wcmsvc.dll | |
0 -> RpcSetProxyInformation | |
1 -> RpcDeleteProxyInformation | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
Endpoints : | |
ncalrpc : LRPC-96b557c995f0059b6f | |
ncalrpc : OLE961E91843456DD6F0DD0A79DF5BB | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2464 at 0x5319978L> | |
64 | |
['DusmSvc'] | |
Interfaces : | |
RPC c27f3c08-92ba-478c-b446-b419c4cef0e2 (1.0) -- c:\windows\system32\dusmsvc.dll | |
0 -> DusmRpcEnumConnectionList | |
1 -> DusmRpcEnumProfileList | |
2 -> DusmRpcQueryConnectionProperties | |
3 -> DusmRpcQueryCost | |
4 -> DusmRpcQueryUserCost | |
5 -> DusmRpcQueryOperatorCost | |
6 -> DusmRpcSetUserCost | |
7 -> DusmRpcSetOperatorCost | |
8 -> DusmRpcQueryDataPlan | |
9 -> DusmRpcQueryUserDataPlan | |
10 -> DusmRpcQueryOperatorDataPlan | |
11 -> DusmRpcSetUserDataPlan | |
12 -> DusmRpcSetOperatorDataPlan | |
13 -> DusmRpcQuerySource | |
14 -> DusmRpcSetSource | |
15 -> DusmRpcQueryBackgroundRestriction | |
16 -> DusmRpcSetBackgroundRestriction | |
17 -> DusmRpcQueryGlobalDpuState | |
18 -> DusmRpcGetAttributedNetworkUsage | |
19 -> DusmRpcGetConnectionListNetworkUsage | |
20 -> DusmRpcGetNetworkUsage | |
21 -> DusmRpcGetProviderNetworkUsage | |
22 -> DusmRpcSetAttributionMapping | |
23 -> DusmRpcResetNetworkUsage | |
24 -> DusmRpcFlushCostCache | |
Endpoints : | |
ncalrpc : LRPC-fe377b929e997d74df | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 2608 at 0x5319c88L> | |
64 | |
['ShellHWDetection'] | |
Interfaces : | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
OLE 00000132-0000-0000-c000-000000000046 (0.0) -- ILocalSystemActivator | |
OLE 3b0f86b5-8113-439d-b2a3-2766c839d073 (0.0) -- IHardwareDevices | |
OLE 1c0eb79b-2cde-44ec-bb35-fc471024c13c (0.0) -- IHardwareDevicesVolumesEnum | |
OLE ee93d145-9b4e-480c-8385-1e8119a6f7b2 (0.0) -- IHardwareDevicesMountPointsEnum | |
Endpoints : | |
ncalrpc : OLE28559BD9733DFB8A3F87F8481E47 | |
-------------------------------------------------------------------------------- | |
<WinProcess "spoolsv.exe" pid 3012 at 0x5319d68L> | |
64 | |
['Spooler'] | |
Interfaces : | |
RPC 12345678-1234-abcd-ef00-0123456789ab (1.0) -- C:\windows\System32\spoolsv.exe | |
0 -> RpcEnumPrinters | |
1 -> RpcOpenPrinter | |
2 -> RpcSetJob | |
3 -> RpcGetJob | |
4 -> RpcEnumJobs | |
5 -> RpcAddPrinter | |
6 -> RpcDeletePrinter | |
7 -> RpcSetPrinter | |
8 -> RpcGetPrinter | |
9 -> RpcAddPrinterDriver | |
10 -> RpcEnumPrinterDrivers | |
11 -> RpcGetPrinterDriver | |
12 -> RpcGetPrinterDriverDirectory | |
13 -> RpcDeletePrinterDriver | |
14 -> RpcAddPrintProcessor | |
15 -> RpcEnumPrintProcessors | |
16 -> RpcGetPrintProcessorDirectory | |
17 -> RpcStartDocPrinter | |
18 -> RpcStartPagePrinter | |
19 -> RpcWritePrinter | |
20 -> RpcEndPagePrinter | |
21 -> RpcAbortPrinter | |
22 -> RpcReadPrinter | |
23 -> RpcEndDocPrinter | |
24 -> RpcAddJob | |
25 -> RpcScheduleJob | |
26 -> RpcGetPrinterData | |
27 -> RpcSetPrinterData | |
28 -> RpcWaitForPrinterChange | |
29 -> RpcClosePrinter | |
30 -> RpcAddForm | |
31 -> RpcDeleteForm | |
32 -> RpcGetForm | |
33 -> RpcSetForm | |
34 -> RpcEnumForms | |
35 -> RpcEnumPorts | |
36 -> RpcEnumMonitors | |
37 -> RpcAddPort | |
38 -> RpcConfigurePort | |
39 -> RpcDeletePort | |
40 -> RpcCreatePrinterIC | |
41 -> RpcPlayGdiScriptOnPrinterIC | |
42 -> RpcDeletePrinterIC | |
43 -> RpcAddPrinterConnection | |
44 -> RpcDeletePrinterConnection | |
45 -> RpcPrinterMessageBox | |
46 -> RpcAddMonitor | |
47 -> RpcDeleteMonitor | |
48 -> RpcDeletePrintProcessor | |
49 -> RpcAddPrintProvidor | |
50 -> RpcDeletePrintProvidor | |
51 -> RpcEnumPrintProcessorDatatypes | |
52 -> RpcResetPrinter | |
53 -> RpcGetPrinterDriver2 | |
54 -> RpcClientFindFirstPrinterChangeNotification | |
55 -> RpcFindNextPrinterChangeNotification | |
56 -> RpcFindClosePrinterChangeNotification | |
57 -> NThreadingLibrary::TWorkItem::NotifyCancel | |
58 -> RpcReplyOpenPrinter | |
59 -> RpcRouterReplyPrinter | |
60 -> RpcReplyClosePrinter | |
61 -> RpcAddPortEx | |
62 -> RpcRemoteFindFirstPrinterChangeNotification | |
63 -> RpcSetAllocFailCount | |
64 -> RpcResetPrinterEx | |
65 -> RpcRemoteFindFirstPrinterChangeNotificationEx | |
66 -> RpcRouterReplyPrinterEx | |
67 -> RpcRouterRefreshPrinterChangeNotification | |
68 -> RpcSetAllocFailCount | |
69 -> RpcOpenPrinterEx | |
70 -> RpcAddPrinterEx | |
71 -> RpcSetPort | |
72 -> RpcEnumPrinterData | |
73 -> RpcDeletePrinterData | |
74 -> NThreadingLibrary::TWorkItem::NotifyCancel | |
75 -> NThreadingLibrary::TWorkItem::NotifyCancel | |
76 -> NThreadingLibrary::TWorkItem::NotifyCancel | |
77 -> RpcSetPrinterDataEx | |
78 -> RpcGetPrinterDataEx | |
79 -> RpcEnumPrinterDataEx | |
80 -> RpcEnumPrinterKey | |
81 -> RpcDeletePrinterDataEx | |
82 -> RpcDeletePrinterKey | |
83 -> RpcSeekPrinter | |
84 -> RpcDeletePrinterDriverEx | |
85 -> RpcAddPerMachineConnection | |
86 -> RpcDeletePerMachineConnection | |
87 -> RpcEnumPerMachineConnections | |
88 -> RpcXcvData | |
89 -> RpcAddPrinterDriverEx | |
90 -> RpcSplOpenPrinter | |
91 -> RpcGetSpoolFileInfo | |
92 -> RpcCommitSpoolData | |
93 -> RpcGetSpoolFileInfo2 | |
94 -> RpcCommitSpoolData2 | |
95 -> RpcCloseSpoolFileHandle | |
96 -> RpcFlushPrinter | |
97 -> RpcSendRecvBidiData | |
98 -> RpcAddDriverCatalog | |
99 -> RpcAddPrinterConnection2 | |
100 -> RpcInstallPrinterDriverFromPackage | |
101 -> RpcUploadPrinterDriverPackage | |
102 -> RpcGetCorePrinterDrivers | |
103 -> RpcCorePrinterDriverInstalled | |
104 -> RpcGetPrinterDriverPackagePath | |
105 -> RpcDeletePrinterDriverPackage | |
106 -> RpcFindCompatibleDriver | |
107 -> RpcReportJobProcessingProgress | |
108 -> RpcSetSpoolerPolicy | |
109 -> RpcInternalGetPrinterDriver | |
110 -> RpcGetJobNamedPropertyValue | |
111 -> RpcSetJobNamedProperty | |
112 -> RpcDeleteJobNamedProperty | |
113 -> RpcEnumJobNamedProperties | |
114 -> RpcCreateAppSandbox | |
115 -> RpcGetUserPropertyBag | |
116 -> RpcLogJobInfoForBranchOffice | |
RPC 0b6edbfa-4a24-4fc6-8a23-942b1eca65d1 (1.0) -- C:\windows\System32\spoolsv.exe | |
0 -> IRPCAsyncNotify_RegisterClient | |
1 -> IRPCAsyncNotify_UnregisterClient | |
2 -> IRPCAsyncNotify_GetServerRefferal | |
3 -> IRPCAsyncNotify_GetNewChannel | |
4 -> IRPCAsyncNotify_GetNotificationSendResponse | |
5 -> IRPCAsyncNotify_GetNotification | |
6 -> IRPCAsyncNotify_CloseChannel | |
RPC ae33069b-a2a8-46ee-a235-ddfd339be281 (1.0) -- C:\windows\System32\spoolsv.exe | |
0 -> IRPCRemoteObject_Create | |
1 -> IRPCRemoteObject_Delete | |
RPC 4a452661-8290-4b36-8fbe-7f4093a94978 (1.0) -- C:\windows\System32\spoolsv.exe | |
0 -> IRPCAsyncNotifyChannel_CreateChannel | |
1 -> IRPCAsyncNotifyChannel_SendNotification | |
2 -> IRPCAsyncNotifyChannel_SendNotificationGetResponse | |
3 -> IRPCAsyncNotifyChannel_CloseChannel | |
RPC 76f03f96-cdfd-44fc-a22c-64950a001209 (1.0) -- C:\windows\System32\spoolsv.exe | |
0 -> RpcAsyncOpenPrinter | |
1 -> RpcAsyncAddPrinter | |
2 -> RpcAsyncSetJob | |
3 -> RpcAsyncGetJob | |
4 -> RpcAsyncEnumJobs | |
5 -> RpcAsyncAddJob | |
6 -> RpcAsyncScheduleJob | |
7 -> RpcAsyncDeletePrinter | |
8 -> RpcAsyncSetPrinter | |
9 -> RpcAsyncGetPrinter | |
10 -> RpcAsyncStartDocPrinter | |
11 -> RpcAsyncStartPagePrinter | |
12 -> RpcAsyncWritePrinter | |
13 -> RpcAsyncEndPagePrinter | |
14 -> RpcAsyncEndDocPrinter | |
15 -> RpcAsyncAbortPrinter | |
16 -> RpcAsyncGetPrinterData | |
17 -> RpcAsyncGetPrinterDataEx | |
18 -> RpcAsyncSetPrinterData | |
19 -> RpcAsyncSetPrinterDataEx | |
20 -> RpcAsyncClosePrinter | |
21 -> RpcAsyncAddForm | |
22 -> RpcAsyncDeleteForm | |
23 -> RpcAsyncGetForm | |
24 -> RpcAsyncSetForm | |
25 -> RpcAsyncEnumForms | |
26 -> RpcAsyncGetPrinterDriver | |
27 -> RpcAsyncEnumPrinterData | |
28 -> RpcAsyncEnumPrinterDataEx | |
29 -> RpcAsyncEnumPrinterKey | |
30 -> RpcAsyncDeletePrinterData | |
31 -> RpcAsyncDeletePrinterDataEx | |
32 -> RpcAsyncDeletePrinterKey | |
33 -> RpcAsyncXcvData | |
34 -> RpcAsyncSendRecvBidiData | |
35 -> RpcAsyncCreatePrinterIC | |
36 -> RpcAsyncPlayGdiScriptOnPrinterIC | |
37 -> RpcAsyncDeletePrinterIC | |
38 -> RpcAsyncEnumPrinters | |
39 -> RpcAsyncAddPrinterDriver | |
40 -> RpcAsyncEnumPrinterDrivers | |
41 -> RpcAsyncGetPrinterDriverDirectory | |
42 -> RpcAsyncDeletePrinterDriver | |
43 -> RpcAsyncDeletePrinterDriverEx | |
44 -> RpcAsyncAddPrintProcessor | |
45 -> RpcAsyncEnumPrintProcessors | |
46 -> RpcAsyncGetPrintProcessorDirectory | |
47 -> RpcAsyncEnumPorts | |
48 -> RpcAsyncEnumMonitors | |
49 -> RpcAsyncAddPort | |
50 -> RpcAsyncSetPort | |
51 -> RpcAsyncAddMonitor | |
52 -> RpcAsyncDeleteMonitor | |
53 -> RpcAsyncDeletePrintProcessor | |
54 -> RpcAsyncEnumPrintProcessorDatatypes | |
55 -> RpcAsyncAddPerMachineConnection | |
56 -> RpcAsyncDeletePerMachineConnection | |
57 -> RpcAsyncEnumPerMachineConnections | |
58 -> RpcSyncRegisterForRemoteNotifications | |
59 -> RpcSyncUnRegisterForRemoteNotifications | |
60 -> RpcSyncRefreshRemoteNotifications | |
61 -> RpcAsyncGetRemoteNotifications | |
62 -> RpcAsyncInstallPrinterDriverFromPackage | |
63 -> RpcAsyncUploadPrinterDriverPackage | |
64 -> RpcAsyncGetCorePrinterDrivers | |
65 -> RpcAsyncCorePrinterDriverInstalled | |
66 -> RpcAsyncGetPrinterDriverPackagePath | |
67 -> RpcAsyncDeletePrinterDriverPackage | |
68 -> RpcAsyncReadPrinter | |
69 -> RpcAsyncResetPrinter | |
70 -> RpcAsyncGetJobNamedPropertyValue | |
71 -> RpcAsyncSetJobNamedProperty | |
72 -> RpcAsyncDeleteJobNamedProperty | |
73 -> RpcAsyncEnumJobNamedProperties | |
74 -> RpcAsyncLogJobInfoForBranchOffice | |
OLE 00000134-0000-0000-c000-000000000046 (0.0) -- IRundown | |
RPC 18f70770-8e64-11cf-9af1-0020af6e72f4 (0.0) -- C:\windows\System32\combase.dll | |
0 -> _UseProtseq | |
1 -> _GetCustomProtseqInfo | |
2 -> _UpdateResolverBindings | |
3 -> _NotifyFDT | |
4 -> _ControlTracing | |
OLE 00000131-0000-0000-c000-000000000046 (0.0) -- IRemUnknown | |
OLE 00000143-0000-0000-c000-000000000046 (0.0) -- IRemUnknown2 | |
Endpoints : | |
ncalrpc : LRPC-a7109f2c2cdeefba97 | |
ncacn_np : \pipe\spoolss | |
ncacn_ip_tcp : 49676 | |
ncalrpc : OLE2D77958200DDBE189A720E9EED55 | |
-------------------------------------------------------------------------------- | |
<WinProcess "svchost.exe" pid 3120 at 0x5319eb8L> | |
64 | |
['BFE', 'mpssvc'] | |
Interfaces : | |
RPC dd490425-5325-4565-b774-7e27d6c09c24 (1.0) -- c:\windows\system32\bfe.dll | |
0 -> BfeRpcGetNextNotificationBatch | |
1 -> BfeRpcNotifyComplete | |
2 -> BfeRpcEngineOpen | |
3 -> BfeRpcEngineClose | |
4 -> BfeRpcEngineGetOption | |
5 -> BfeRpcEngineSetOption | |
6 -> BfeRpcEngineGetSecurityInfo | |
7 -> BfeRpcEngineSetSecurityInfo | |
8 -> BfeRpcSessionCreateEnumHandle | |
9 -> BfeRpcAleEndpointEnum | |
10 -> BfeRpcAleEndpointDestroyEnumHandle | |
11 -> BfeRpcTransactionBegin | |
12 -> BfeRpcTransactionCommit | |
13 -> BfeRpcTransactionAbort | |
14 -> BfeRpcProviderAdd | |
15 -> BfeRpcProviderDeleteByKey | |
16 -> BfeRpcProviderGetByKey | |
17 -> BfeRpcProviderCreateEnumHandle | |
18 -> BfeRpcAleEndpointEnum | |
19 -> BfeRpcAleEndpointDestroyEnumHandle | |
20 -> BfeRpcProviderGetSecurityInfoByKey | |
21 -> BfeRpcProviderSetSecurityInfoByKey | |
22 -> BfeRpcProviderSubscribeChanges | |
23 -> BfeRpcProviderUnsubscribeChanges | |
24 -> BfeRpcProviderSubscriptionsGet | |
25 -> BfeRpcProviderContextAdd | |
26 -> BfeRpcProviderContextDeleteById | |
27 -> BfeRpcProviderContextDeleteByKey | |
28 -> BfeRpcProviderContextGetById | |
29 -> BfeRpcProviderContextGetByKey | |
30 -> BfeRpcProviderContextCreateEnumHandle | |
31 -> BfeRpcAleEndpointEnum | |
32 -> BfeRpcAleEndpointDestroyEnumHandle | |
33 -> BfeRpcProviderContextGetSecurityInfoByKey | |
34 -> BfeRpcProviderContextSetSecurityInfoByKey | |
35 -> BfeRpcProviderContextSubscribeChanges | |
36 -> BfeRpcProviderContextUnsubscribeChanges | |
37 -> BfeRpcProviderContextSubscriptionsGet | |
38 -> BfeRpcSubLayerAdd | |
39 -> BfeRpcSubLayerDeleteByKey | |
40 -> BfeRpcSubLayerGetByKey | |
41 -> BfeRpcSubLayerCreateEnumHandle | |
42 -> BfeRpcAleEndpointEnum | |
43 -> BfeRpcAleEndpointDestroyEnumHandle | |
44 -> BfeRpcSubLayerGetSecurityInfoByKey | |
45 -> BfeRpcSubLayerSetSecurityInfoByKey | |
46 -> BfeRpcSubLayerSubscribeChanges | |
47 -> BfeRpcSubLayerUnsubscribeChanges | |
48 -> BfeRpcSubLayerSubscriptionsGet | |
49 -> BfeRpcLayerGetById | |
50 -> BfeRpcLayerGetByKey | |
51 -> BfeRpcLayerCreateEnumHandle | |
52 -> BfeRpcAleEndpointEnum | |
53 -> BfeRpcAleEndpointDestroyEnumHandle | |
54 -> BfeRpcLayerGetSecurityInfoByKey | |
55 -> BfeRpcLayerSetSecurityInfoByKey | |
56 -> BfeRpcCalloutAdd | |
57 -> BfeRpcCalloutDeleteById | |
58 -> BfeRpcCalloutDeleteByKey | |
59 -> BfeRpcCalloutGetById | |
60 -> BfeRpcCalloutGetByKey | |
61 -> BfeRpcCalloutCreateEnumHandle | |
62 -> BfeRpcAleEndpointEnum | |
63 -> BfeRpcAleEndpointDestroyEnumHandle | |
64 -> BfeRpcCalloutGetSecurityInfoByKey | |
65 -> BfeRpcCalloutSetSecurityInfoByKey | |
66 -> BfeRpcCalloutSubscribeChanges | |
67 -> BfeRpcCalloutUnsubscribeChanges | |
68 -> BfeRpcCalloutSubscriptionsGet | |
69 -> BfeRpcFilterAdd | |
70 -> BfeRpcFilterDeleteById | |
71 -> BfeRpcFilterDeleteByKey | |
72 -> BfeRpcFilterGetById | |
73 -> BfeRpcFilterGetByKey | |
74 -> BfeRpcFilterCreateEnumHandle | |
75 -> BfeRpcAleEndpointEnum | |
76 -> BfeRpcAleEndpointDestroyEnumHandle | |
77 -> BfeRpcFilterGetSecurityInfoByKey | |
78 -> BfeRpcFilterSetSecurityInfoByKey | |
79 -> BfeRpcFilterSubscribeChanges | |
80 -> BfeRpcFilterUnsubscribeChanges | |
81 -> BfeRpcFilterSubscriptionsGet | |
82 -> BfeRpcBfeIPsecOffloadDone | |
83 -> BfeRpcBfeIPsecDosFWUsed | |
84 -> BfeRpcBfeIPsecGetStatistics | |
85 -> BfeRpcBfeIPsecSaContextCreate | |
86 -> BfeRpcBfeIPsecSaContextDeleteById | |
87 -> BfeRpcBfeIPsecSaContextGetById | |
88 -> BfeRpcBfeIPsecSaContextGetOrSetSpi | |
89 -> BfeRpcBfeIPsecSaContextAddInbound | |
90 -> BfeRpcBfeIPsecSaContextAddOutbound | |
91 -> BfeRpcBfeIPsecSaContextUpdate | |
92 -> BfeRpcBfeIPsecSaContextExpire | |
93 -> BfeRpcBfeIPsecSaContextCreateEnumHandle | |
94 -> BfeRpcAleEndpointEnum | |
95 -> BfeRpcAleEndpointDestroyEnumHandle | |
96 -> BfeRpcBfeIPsecSaContextSubscribe | |
97 -> BfeRpcBfeIPsecSaContextUnsubscribe | |
98 -> BfeRpcBfeIPsecSaContextSubscriptionsGet | |
99 -> BfeRpcBfeIPsecSaCreateEnumHandle | |
100 -> BfeRpcAleEndpointEnum | |
101 -> BfeRpcAleEndpointDestroyEnumHandle | |
102 -> BfeRpcBfeIPsecSaDbGetSecurityInfo | |
103 -> BfeRpcBfeIPsecSaDbSetSecurityInfo | |
104 -> BfeRpcBfeIPsecDospGetStatistics | |
105 -> BfeRpcBfeIPsecDospStateCreateEnumHandle | |
106 -> BfeRpcAleEndpointEnum | |
107 -> BfeRpcBfeIPsecDospStateDestroyEnumHandle | |
108 -> BfeRpcBfeIPsecDospGetSecurityInfo | |
109 -> BfeRpcBfeIPsecDospSetSecurityInfo | |
110 -> BfeRpcNetEventCreateEnumHandle | |
111 -> BfeRpcAleEndpointEnum | |
112 -> BfeRpcAleEndpointDestroyEnumHandle | |
113 -> BfeRpcNetEventsGetSecurityInfo | |
114 -> BfeRpcNetEventsSetSecurityInfo | |
115 -> BfeRpcNetEventSubscribe | |
116 -> BfeRpcNetEventUnsubscribe | |
117 -> BfeRpcNetEventSubscriptionsGet | |
118 -> BfeRpcNetEventsLost | |
119 -> BfeRpcConnectionGetById | |
120 -> BfeRpcConnectionGetByIPsecInfo | |
121 -> BfeRpcConnectionGetByS2STunnelId | |
122 -> BfeRpcConnectionCreateEnumHandle | |
123 -> BfeRpcAleEndpointEnum | |
124 -> BfeRpcAleEndpointDestroyEnumHandle | |
125 -> BfeRpcConnectionGetSecurityInfo | |
126 -> BfeRpcConnectionSetSecurityInfo | |
127 -> BfeRpcConnectionGetS2STunnelId | |
128 -> BfeRpcConnectionSubscribe | |
129 -> BfeRpcConnectionUnsubscribe | |
130 -> BfeRpcConnectionSubscriptionsGet | |
131 -> BfeRpcConnectionsLost | |
132 -> BfeRpcClassify | |
133 -> BfeRpcAddLayerReplica | |
134 -> BfeRpcDeleteLayerReplica | |
135 -> BfeRpcSecureSocketAdd | |
136 -> BfeRpcBfeIPsecTunnelDeleteByKey | |
137 -> BfeRpcBfeIPsecTunnelAdd | |
138 -> BfeRpcBfeIPsecTunnelAddConditions | |
139 -> BfeRpcBfeIPsecS2STunnelAddConditions | |
140 -> BfeRpcBfeIPsecS2STunnelRemoveConditions | |
141 -> BfeRpcBfeIPsecTunnelDeleteByKey | |
142 -> BfeRpcBfeIPsecS2STunnelAddInterfaceToCompartment | |
143 -> BfeRpcBfeIPsecS2STunnelGetInterfaceForCompartment | |
144 -> BfeRpcBfeIPsecS2STunnelRemoveInterfaceFromCompartment | |
145 -> BfeRpcBfeIPsecSaInitiateAsync | |
146 -> BfeRpcOpenToken | |
147 -> BfeRpcCloseToken | |
148 -> BfeRpcAleExplicitCredentialsQuery | |
149 -> BfeRpcAleEndpointGetById | |
150 -> BfeRpcAleEndpointCreateEnumHandle | |
151 -> BfeRpcAleEndpointEnum | |
152 -> BfeRpcAleEndpointDestroyEnumHandle | |
153 -> BfeRpcAleEndpointGetSecurityInfo | |
154 -> BfeRpcAleEndpointSetSecurityInfo | |
155 -> BfeRpcAleGetPortStatus | |
156 -> BfeRpcIsUserAuthConfigured | |
157 -> BfeRpcKeyModuleAdd | |
158 -> BfeRpcKeyModuleDeleteByKey | |
159 -> BfeRpcKeyModuleUpdateAcquire | |
160 -> BfeRpcKeyDictatorCheck | |
161 -> BfeRpcGetKeyFromDictator | |
162 -> BfeRpcNotifyKey | |
163 -> BfeRpcKeyManagerAdd | |
164 -> BfeRpcKeyManagerDeleteByKey | |
165 -> BfeRpcKeyManagersGet | |
166 -> BfeRpcKeyManagerGetSecurityInfoByKey | |
167 -> BfeRpcKeyManagerSetSecurityInfoByKey | |
168 -> BfeRpcvSwitchEventFire | |
169 -> BfeRpcvSwitchEventsGetSecurityInfo | |
170 -> BfeRpcvSwitchEventsSetSecurityInfo | |
171 -> BfeRpcvSwitchEventSubscribe | |
172 -> BfeRpcvSwitchEventUnsubscribe | |
173 -> BfeRpcvSwitchEventSubscriptionsGet | |
174 -> BfeRpcBfeIPsecDriverInitiateAcquire | |
175 -> BfeRpcBfeIPsecDriverExpire | |
176 -> BfeRpcBfeIPsecDriverSaOffloaded | |
177 -> BfeRpcBfeIPsecDriverProcessClearTextResponse | |
178 -> BfeRpcBfeProcessNameResolutionEvent | |
179 -> BfeRpcVpnTriggerEventFire | |
180 -> BfeRpcVpnTriggerEventSubscribe | |
181 -> BfeRpcVpnTriggerEventUnsubscribe | |
182 -> BfeRpcVpnTriggerAddAppSids | |
183 -> BfeRpcVpnTriggerRemoveAppSids | |
184 -> BfeRpcVpnTriggerAddFilePaths | |
185 -> BfeRpcVpnTriggerRemoveFilePaths | |
186 -> BfeRpcVpnTriggerAddSecurityDescriptor | |
187 -> BfeRpcVpnTriggerRemoveSecurityDescriptor | |
188 -> BfeRpcVpnTriggerSetStateDisconnected | |
189 -> BfeRpcVpnTriggerInitializeNrptTriggering | |
190 -> BfeRpcVpnTriggerUninitializeNrptTriggering | |
191 -> BfeRpcVpnTriggerResetNrptTriggering | |
192 -> BfeRpcVpnTriggerConfigureParameters | |
193 -> BfeRpcBitmapIndexGet | |
194 -> BfeRpcBitmapIndexFree | |
RPC 7f9d11bf-7fb9-436b-a812-b2d50c5d4c03 (1.0) -- c:\windows\system32\mpssvc.dll | |
0 -> RPC_FWIndicatePortInUse | |
1 -> RPC_FWGetIndicatedPortInUse | |
2 -> RPC_FWIndicateTupleInUse | |
3 -> RPC_FWResetIndicatedTupleInUse | |
4 -> RPC_FWIndicateProxyForUrl | |
5 -> CNetProfileEventSink::NetworkAdded | |
6 -> RPC_FWIsTargetAProxy | |
7 -> RPC_NetworkIsolationSetupAppContainerBinaries | |
8 -> RPC_NetworkIsolationRegisterForAppContainerChanges | |
9 -> Rpc_NetworkIsolationRegistrationGetLastEvent | |
10 -> RPC_NetworkIsolationUnregisterForAppContainerChanges | |
11 -> RPC_NetworkIsolationGetAppContainer | |
12 -> RPC_NetworkIsolationEnumAppContainers | |
13 -> RPC_NetworkIsolationAddAllowEnterpriseIdRule | |
14 -> RPC_NetworkIsolationCreateAllInterfacesContainer | |
15 -> RPC_NetworkIsolationCreateInterfaceContainer | |
16 -> RPC_NetworkIsolationDeleteAllInterfacesContainer | |
17 -> RPC_NetworkIsolationDeleteInterfaceContainer | |
RPC f47433c3-3e9d-4157-aad4-83aa1f5c2d4c (1.0) -- c:\windows\system32\mpssvc.dll | |
0 -> RPC_NetworkIsolationDiagnoseConnectFailure | |
1 -> RPC_NetworkIsolationGetEnterpriseIdAsync | |
2 -> RPC_NetworkIsolationCreateContainer | |
3 -> RPC_NetworkIsolationDeleteContainer | |
4 -> RPC_NetworkIsolationGetAppContainerConfig | |
5 -> RPC_NetworkIsolationSetAppContainerConfig | |
6 -> RPC_NetworkIsolationCreateAppContainer | |
7 -> RPC_NetworkIsolationDeleteAppContainer | |
8 -> RPC_NetworkIsolationCreateAppContainerLoopbackRules | |
9 -> RPC_NetworkIsolationDeleteAppContainerLoopbackRules | |
RPC 2fb92682-6599-42dc-ae13-bd2ca89bd11c (1.0) -- c:\windows\system32\mpssvc.dll | |
0 -> RPC_FWOpenPolicyStore | |
1 -> RPC_FWClosePolicyStore | |
2 -> RPC_FWRestoreDefaults | |
3 -> RPC_FWGetGlobalConfig | |
4 -> RPC_FWSetGlobalConfig | |
5 -> RPC_FWAddFirewallRule | |
6 -> RPC_FWSetFirewallRule | |
7 -> RPC_FWDeleteFirewallRule | |
8 -> RPC_FWDeleteAllFirewallRules | |
9 -> RPC_FWEnumFirewallRules | |
10 -> RPC_FWGetConfig | |
11 -> RPC_FWSetConfig | |
12 -> RPC_FWNotifyUnsupportedAttempt | |
13 -> RPC_FWAddConnectionSecurityRule | |
14 -> RPC_FWSetConnectionSecurityRule | |
15 -> RPC_FWDeleteConnectionSecurityRule | |
16 -> RPC_FWDeleteAllConnectionSecurityRules | |
17 -> RPC_FWEnumConnectionSecurityRules | |
18 -> RPC_FWAddAuthenticationSet | |
19 -> RPC_FWSetAuthenticationSet | |
20 -> RPC_FWDeleteAuthenticationSet | |
21 -> RPC_FWDeleteAllAuthenticationSets | |
22 -> RPC_FWEnumAuthenticationSets | |
23 -> RPC_FWAddCryptoSet | |
24 -> RPC_FWSetCryptoSet | |
25 -> RPC_FWDeleteCryptoSet | |
26 -> RPC_FWDeleteAllCryptoSets | |
27 -> RPC_FWEnumCryptoSets | |
28 -> RPC_FWEnumPhase1SAs | |
29 -> RPC_FWEnumPhase2SAs | |
30 -> RPC_FWDeletePhase1SAs | |
31 -> RPC_FWDeletePhase2SAs | |
32 -> RPC_FWRegisterProduct | |
33 -> RPC_FWUnregisterProduct | |
34 -> RPC_FWEnumProducts | |
35 -> RPC_FWAddMainModeRule | |
36 -> RPC_FWSetMainModeRule | |
37 -> RPC_FWDeleteMainModeRule | |
38 -> RPC_FWDeleteAllMainModeRules | |
39 -> RPC_FWEnumMainModeRules | |
40 -> RPC_FWQueryFirewallRules | |
41 -> RPC_FWQueryConnectionSecurityRules2_10 | |
42 -> RPC_FWQueryMainModeRules | |
43 -> RPC_FWQueryAuthenticationSets | |
44 -> RPC_FWQueryCryptoSets | |
45 -> RPC_FWEnumNetworks | |
46 -> RPC_FWEnumAdapters | |
47 -> RPC_FWGetGlobalConfig2_10 | |
48 -> RPC_FWGetConfig2_10 | |
49 -> RPC_FWAddFirewallRule2_10 | |
50 -> RPC_FWSetFirewallRule2_10 | |
51 -> RPC_FWEnumFirewallRules2_10 | |
52 -> RPC_FWAddConnectionSecurityRule2_10 | |
53 -> RPC_FWSetConnectionSecurityRule2_10 | |
54 -> RPC_FWEnumConnectionSecurityRules2_10 | |
55 -> RPC_FWAddAuthenticationSet2_10 | |
56 -> RPC_FWSetAuthenticationSet2_10 | |
57 -> RPC_FWEnumAuthenticationSets2_10 | |
58 -> RPC_FWAddCryptoSet2_10 | |
59 -> RPC_FWSetCryptoSet2_10 | |
60 -> RPC_FWEnumCryptoSets2_10 | |
61 -> RPC_FWDiagGetAppList | |
62 -> RPC_FWAddConnectionSecurityRule2_20 | |
63 -> RPC_FWSetConnectionSecurityRule2_20 | |
64 -> RPC_FWEnumConnectionSecurityRules2_20 | |
65 -> RPC_FWQueryConnectionSecurityRules2_20 | |
66 -> RPC_FWAddAuthenticationSet2_20 | |
67 -> RPC_FWSetAuthenticationSet2_20 | |
68 -> RPC_FWEnumAuthenticationSets2_20 | |
69 -> RPC_FWQueryAuthenticationSets2_20 | |
70 -> RPC_FWAddFirewallRule2_20 | |
71 -> RPC_FWSetFirewallRule2_20 | |
72 -> RPC_FWEnumFirewallRules2_20 | |
73 -> RPC_FWQueryFirewallRules2_20 | |
74 -> RPC_FWQueryIsolationType | |
75 -> RPC_FWSelectConSecRule | |
76 -> RPC_FWAddFirewallRule2_24 | |
77 -> RPC_FWSetFirewallRule2_24 | |
78 -> RPC_FWEnumFirewallRules2_24 | |
79 -> RPC_FWQueryFirewallRules2_24 | |
80 -> RPC_FWAddFirewallRule2_25 | |
81 -> RPC_FWSetFirewallRule2_25 | |
82 -> RPC_FWEnumFirewallRules2_25 | |
83 -> RPC_FWQueryFirewallRules2_25 | |
84 -> RPC_FWAddFirewallRule2_26 | |