File details
File name: termsrv.dll
Name: Terminal Server Service
Description: Microsoft® Windows® Operating System
Version: 5.1.2600.5512 (xpsp.080413-2111)
Product version: 5.1.2600.5512
Size: 288.5 KB
Original file name: termsrv.exe
Windows file protection:
Yes
Resource utilization |  |
Total CPU: 0.0001806259%
Privileged CPU: 0.0000036464%
User CPU: 0.0001769795%
Module memory size:
332 KB
Hosted service details
Name: 27c6d03bcdb8cfeb96b716f3d8be3e18
Command: TermService
Image hashes
MD5: ff3477c03be7201c294c35f684b3479f
SHA-1: 86773aed393573d4bd59481185910bbaaf85790f
PE image details
Subsystem: Windows Console
Langauge*: Microsoft Visual C++
File packed: No
Import Table
advapi32.dll

GetSidSubAuthorityCount
GetSidSubAuthority
AccessCheckAndAuditAlarmW
AllocateAndInitializeSid
SetEntriesInAclW
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
RegEnumKeyW
DeregisterEventSource
CryptAcquireContextW
CryptCreateHash
CryptImportKey
CryptVerifySignatureW
CryptDestroyKey
CryptDestroyHash
CryptReleaseContext
AddAce
GetAce
GetAclInformation
GetUserNameA
CryptHashData
RegisterServiceCtrlHandlerW
GetSidIdentifierAuthority
IsValidSid
GetTokenInformation
EqualSid
LookupAccountSidW
RegSetValueExW
CryptGenRandom
RegisterEventSourceW
ReportEventW
SetServiceBits
RegOpenKeyW
GetUserNameW
SetServiceStatus
RegOpenKeyExW
GetSecurityDescriptorDacl
LsaDelete
LsaSetSecret
LsaClose
LsaOpenSecret
LsaCreateSecret
LsaOpenPolicy
LsaFreeMemory
LsaQuerySecret
GetEventLogInformation
LsaQueryInformationPolicy
RegQueryValueExW
RegCloseKey
LogonUserW
AddAccessAllowedAce
InitializeAcl
GetLengthSid
OpenThreadToken
CheckTokenMembership
MakeSelfRelativeSD
MakeAbsoluteSD
IsValidSecurityDescriptor
ElfReportEventW
ElfRegisterEventSourceW
I_ScSendTSMessage
RegNotifyChangeKeyValue
RegCreateKeyExW
RegQueryValueExA
RegOpenKeyExA
GetCurrentHwProfileA
RegEnumKeyExA
RegEnumKeyExW
LsaStorePrivateData
LsaNtStatusToWinError
LsaRetrievePrivateData
RegDeleteValueW
OpenProcessToken
authz.dll

AuthzFreeResourceManager
AuthziAllocateAuditParams
AuthziInitializeAuditParamsWithRM
AuthziInitializeAuditEvent
AuthziLogAuditEvent
AuthzFreeAuditEvent
AuthziFreeAuditParams
AuthzInitializeResourceManager
AuthziInitializeAuditEventType
AuthziFreeAuditEventType
crypt32.dll

CertCloseStore
CertCreateCertificateContext
CertOpenStore
CertDuplicateCertificateContext
CertFreeCertificateContext
CertGetIssuerCertificateFromStore
CertVerifySubjectCertificateContext
CryptExportPublicKeyInfo
CertEnumCertificatesInStore
CertFindExtension
CertVerifyCertificateChainPolicy
CertComparePublicKeyInfo
CryptDecodeObject
CryptVerifyCertificateSignature
CryptBinaryToStringW
icaapi.dll

IcaOpen
IcaStackCallback
IcaStackConnectionWait
IcaStackConnectionRequest
IcaStackConnectionAccept
_IcaStackIoControl
IcaStackUnlock
IcaStackReconnect
IcaStackTerminate
IcaChannelClose
IcaStackIoControl
IcaPushConsoleStack
IcaChannelOpen
IcaChannelIoControl
IcaStackConnectionClose
IcaStackClose
IcaClose
IcaIoControl
IcaStackOpen
IcaStackDisconnect
kernel32.dll

GetLocalTime
GetDiskFreeSpaceA
GetDateFormatW
FileTimeToSystemTime
InitializeCriticalSection
GetVersion
CreateMutexW
GetModuleHandleA
InterlockedExchange
OutputDebugStringA
GetProcessAffinityMask
SetThreadAffinityMask
ResumeThread
GetExitCodeThread
GetSystemInfo
GetLogicalDriveStringsA
GetDriveTypeA
GetVolumeInformationW
GetVolumeInformationA
GlobalMemoryStatus
lstrlenA
lstrcpyA
GetFileSize
WriteFile
SetFilePointer
ReadFile
CreateFileA
HeapAlloc
HeapFree
CompareFileTime
CreateWaitableTimerW
SetWaitableTimer
FormatMessageW
LeaveCriticalSection
GetSystemDefaultLCID
SystemTimeToFileTime
LoadLibraryExA
GetVersionExA
SetUnhandledExceptionFilter
UnhandledExceptionFilter
TerminateProcess
GetCurrentThreadId
QueryPerformanceCounter
LoadLibraryA
InterlockedCompareExchange
DelayLoadFailureHook
lstrcpynW
GetACP
MultiByteToWideChar
SetLastError
lstrlenW
LocalFree
LocalAlloc
GetProcessHeap
DisableThreadLibraryCalls
DebugBreak
Sleep
CloseHandle
CreateProcessW
GetCurrentProcessId
IsDebuggerPresent
GetVersionExW
ResetEvent
SetEvent
VerifyVersionInfoW
CreateEventW
GetLastError
ReleaseMutex
UnmapViewOfFile
MapViewOfFile
OpenFileMappingW
WaitForMultipleObjects
OpenEventW
OpenMutexW
InterlockedDecrement
CreateThread
CreateFileW
GetSystemDirectoryW
GetSystemTime
GetComputerNameA
GetSystemTimeAsFileTime
UnregisterWait
WaitForSingleObject
InterlockedIncrement
lstrcpyW
ExitThread
QueryDosDeviceW
ProcessIdToSessionId
IsBadReadPtr
IsBadWritePtr
OpenProcess
GetComputerNameW
FreeLibrary
GetProcAddress
LoadLibraryW
GetProfileStringW
GetTickCount
RegisterWaitForSingleObject
lstrcatW
lstrcmpiW
GetProfileIntW
GetWindowsDirectoryW
SetThreadPriority
GetCurrentThread
LocalSize
GetCurrentProcess
PulseEvent
GetComputerNameExW
WideCharToMultiByte
InitializeCriticalSectionAndSpinCount
EnterCriticalSection
DeleteCriticalSection
msvcrt.dll
ntdll.dll

NtOpenProcessToken
NtQueryInformationToken
RtlLengthSid
RtlCopySid
NtAllocateVirtualMemory
NtFreeVirtualMemory
RtlAcquireResourceShared
NtDelayExecution
DbgBreakPoint
RtlPrefixUnicodeString
NtResetEvent
NtWaitForMultipleObjects
RtlInitializeGenericTable
RtlDeleteCriticalSection
NtOpenProcess
NtQueryVirtualMemory
RtlLookupElementGenericTable
RtlCompareMemory
RtlInsertElementGenericTable
RtlDeleteElementGenericTable
RtlInitializeResource
NtCreateEvent
NtDuplicateObject
NtQuerySystemTime
RtlEqualSid
RtlAdjustPrivilege
RtlInitializeCriticalSection
NtTerminateProcess
RtlLengthRequiredSid
NtReleaseMutant
NtWaitForSingleObject
NtCreateMutant
NtQueryInformationProcess
NtDuplicateToken
NtSetInformationThread
RtlpNtEnumerateSubKey
NtRequestPort
NtConnectPort
NtSetEvent
RtlEnterCriticalSection
RtlAllocateHeap
NtOpenThreadToken
NtReplyPort
NtCompleteConnectPort
NtAcceptConnectPort
NtCreateSection
NtReplyWaitReceivePort
RtlFreeUnicodeString
NtCreatePort
RtlAnsiStringToUnicodeString
RtlInitAnsiString
RtlQueryRegistryValues
NtDeviceIoControlFile
RtlExtendedLargeIntegerDivide
RtlConvertExclusiveToShared
RtlConvertSharedToExclusive
RtlDeleteResource
NtRequestWaitReplyPort
RtlFreeHeap
RtlLeaveCriticalSection
RtlAcquireResourceExclusive
RtlReleaseResource
RtlInitUnicodeString
NtOpenKey
NtQueryValueKey
NtClose
VerSetConditionMask
RtlCreateEnvironment
RtlSetProcessIsCritical
DbgPrint
NtQuerySystemInformation
NtSetTimer
NtCreateTimer
RtlCopySecurityDescriptor
RtlNtStatusToDosError
RtlDeleteAce
RtlGetAce
RtlQueryInformationAcl
RtlGetDaclSecurityDescriptor
RtlMapGenericMask
RtlSubAuthoritySid
RtlInitializeSid
RtlCreateUserSecurityObject
RtlSetDaclSecurityDescriptor
RtlAddAccessAllowedAce
RtlCreateAcl
RtlCreateSecurityDescriptor
RtlWriteRegistryValue
RtlCreateRegistryKey
RtlLengthSecurityDescriptor
RtlSetGroupSecurityDescriptor
RtlGetGroupSecurityDescriptor
RtlGetOwnerSecurityDescriptor
NtSetSecurityObject
NtQuerySecurityObject
NtOpenSymbolicLinkObject
NtQueryDirectoryObject
NtCreateDirectoryObject
RtlFreeSid
RtlAllocateAndInitializeSid
RtlIntegerToUnicodeString
RtlAppendUnicodeToString
NtQueryMutant
rpcrt4.dll

RpcServerInqDefaultPrincNameW
RpcServerRegisterAuthInfoW
RpcServerRegisterIfEx
RpcBindingToStringBindingW
RpcServerListen
RpcImpersonateClient
I_RpcBindingIsClientLocal
RpcRevertToSelf
RpcServerUseProtseqEpW
I_RpcBindingInqLocalClientPID
RpcStringFreeW
RpcRaiseException
RpcSsContextLockExclusive
NdrServerCall2
RpcServerRegisterIf
RpcStringBindingParseW
secur32.dll

setupapi.dll

SetupDiGetDeviceRegistryPropertyA
SetupDiGetClassDevsA
SetupDiEnumDeviceInfo
SetupDiDestroyDeviceInfoList
shell32.dll

shlwapi.dll

user32.dll

GetCursorPos
wvsprintfA
BroadcastSystemMessageA
wsprintfA
GetSystemMetrics
wsprintfW
ExitWindowsEx
LoadStringW
MessageBeep
GetMessageTime
wintrust.dll

CryptCATAdminCalcHashFromFileHandle
CryptCATAdminEnumCatalogFromHash
CryptCATCatalogInfoFromContext
CryptCATAdminReleaseCatalogContext
CryptCATAdminReleaseContext
WTHelperProvDataFromStateData
WTHelperGetProvSignerFromChain
CryptCATAdminAcquireContext
WinVerifyTrust
ws2_32.dll
