¿Para qué sirve la dll kd.dll?

Local Kernel Debugger

Dependencias de la dll kd.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\kd.dll

File Type: DLL

  Image has the following dependencies:

    ntoskrnl.exe

  Summary

        1000 .data
        1000 .edata
        1000 .idata
        1000 .pdata
        1000 .rdata
        1000 .reloc
        1000 .rsrc
        1000 .text
        1000 GFIDS
        1000 INIT

Funciones que tiene la dll kd.dll


1    0 00001020 KdInitialize
2    1 00001080 KdPower
3    2 00001070 KdReceivePacket
4    3 00001060 KdSendPacket
5    4 000010A0 KdSetHiberRange

Información avanzada sobre funciones que tiene la dll kd.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\kd.dll

File Type: DLL

  Section contains the following exports for KD.dll

    00000000 characteristics
    FE185FA8 time date stamp
        0.00 version
           1 ordinal base
           5 number of functions
           5 number of names

    ordinal hint RVA      name

          1    0 00001020 KdInitialize
          2    1 00001080 KdPower
          3    2 00001070 KdReceivePacket
          4    3 00001060 KdSendPacket
          5    4 000010A0 KdSetHiberRange

  Summary

        1000 .data
        1000 .edata
        1000 .idata
        1000 .pdata
        1000 .rdata
        1000 .reloc
        1000 .rsrc
        1000 .text
        1000 GFIDS
        1000 INIT

Integridad de la dll kd.dll



Algorithm       Hash                                                                   Path                                         
---------       ----                                                                   ----                                         
SHA256          9785DABDED2D3D2B18790EA7AB4B7460088E18CFF7AD4D38692D26B529784ECD       C:\Windows\System32\kd.dll                   


Detalles sobre el fichero dll kd.dll




PSPath            : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32\kd.dll
PSParentPath      : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32
PSChildName       : kd.dll
PSDrive           : C
PSProvider        : Microsoft.PowerShell.Core\FileSystem
PSIsContainer     : False
Mode              : -a----
VersionInfo       : File:             C:\Windows\System32\kd.dll
                    InternalName:     kd.dll
                    OriginalFilename: kd.dll
                    FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
                    FileDescription:  Local Kernel Debugger
                    Product:          Microsoft® Windows® Operating System
                    ProductVersion:   10.0.19041.1
                    Debug:            False
                    Patched:          False
                    PreRelease:       False
                    PrivateBuild:     False
                    SpecialBuild:     False
                    Language:         Inglés (Estados Unidos)
                    
BaseName          : kd
Target            : {C:\Windows\WinSxS\amd64_microsoft-windows-b..ggertransport-local_31bf3856ad364e35_10.0.19041.1_none_8f235c7e147
                    ee665\kd.dll}
LinkType          : HardLink
Name              : kd.dll
Length            : 15672
DirectoryName     : C:\Windows\System32
Directory         : C:\Windows\System32
IsReadOnly        : False
Exists            : True
FullName          : C:\Windows\System32\kd.dll
Extension         : .dll
CreationTime      : 07/12/2019 10:08:49
CreationTimeUtc   : 07/12/2019 9:08:49
LastAccessTime    : 03/12/2020 12:09:24
LastAccessTimeUtc : 03/12/2020 11:09:24
LastWriteTime     : 07/12/2019 10:08:49
LastWriteTimeUtc  : 07/12/2019 9:08:49
Attributes        : Archive



Procesos que utilizan la dll kd.dll