rundll32.exe
Description: Windows host process (Rundll32)
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.26100.8328
Architecture: 64-bit
Operating System: Windows NT
SHA256: 4d90fff3e33bf3cb2bea5e08e6487325
File Size: 96.0 KB
Uploaded At: May 17, 2026, 10:55 a.m.
Views: 22
Exported Functions
No exported functions.
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x14000e428)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x14000e488)
- CoAddRefServerProcess (Address: 0x14000e460)
- CoCreateInstance (Address: 0x14000e448)
- CoInitializeEx (Address: 0x14000e440)
- CoInitializeSecurity (Address: 0x14000e450)
- CoRegisterClassObject (Address: 0x14000e458)
- CoReleaseServerProcess (Address: 0x14000e478)
- CoResumeClassObjects (Address: 0x14000e468)
- CoRevokeClassObject (Address: 0x14000e438)
- CoUninitialize (Address: 0x14000e470)
- CoWaitForMultipleHandles (Address: 0x14000e480)
api-ms-win-core-console-l1-1-0.dll
- WriteConsoleW (Address: 0x14000e498)
api-ms-win-core-console-l1-2-0.dll
- AttachConsole (Address: 0x14000e4a8)
- FreeConsole (Address: 0x14000e4b0)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x14000e4c0)
- IsDebuggerPresent (Address: 0x14000e4d0)
- OutputDebugStringW (Address: 0x14000e4c8)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x14000e4e0)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x14000e4f0)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x14000e520)
- SetErrorMode (Address: 0x14000e500)
- SetLastError (Address: 0x14000e518)
- SetUnhandledExceptionFilter (Address: 0x14000e508)
- UnhandledExceptionFilter (Address: 0x14000e510)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x14000e548)
- GetFileAttributesW (Address: 0x14000e540)
- ReadFile (Address: 0x14000e530)
- SetFilePointer (Address: 0x14000e538)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x14000e558)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x14000e580)
- HeapAlloc (Address: 0x14000e570)
- HeapFree (Address: 0x14000e568)
- HeapSetInformation (Address: 0x14000e578)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x14000e590)
- LocalFree (Address: 0x14000e598)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x14000e5a8)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x14000e5c0)
- GetModuleFileNameA (Address: 0x14000e5d0)
- GetModuleHandleExW (Address: 0x14000e5d8)
- GetModuleHandleW (Address: 0x14000e5e0)
- GetProcAddress (Address: 0x14000e5b8)
- LoadLibraryExW (Address: 0x14000e5e8)
- LoadStringW (Address: 0x14000e5c8)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x14000e5f8)
api-ms-win-core-path-l1-1-0.dll
- PathCchAppend (Address: 0x14000e608)
api-ms-win-core-processenvironment-l1-1-0.dll
- GetCommandLineW (Address: 0x14000e618)
- SearchPathW (Address: 0x14000e620)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessW (Address: 0x14000e658)
- DeleteProcThreadAttributeList (Address: 0x14000e678)
- ExitProcess (Address: 0x14000e668)
- GetCurrentProcess (Address: 0x14000e630)
- GetCurrentProcessId (Address: 0x14000e640)
- GetCurrentThreadId (Address: 0x14000e638)
- GetStartupInfoW (Address: 0x14000e648)
- InitializeProcThreadAttributeList (Address: 0x14000e670)
- TerminateProcess (Address: 0x14000e660)
- UpdateProcThreadAttribute (Address: 0x14000e650)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x14000e688)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x14000e698)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x14000e6b0)
- RtlLookupFunctionEntry (Address: 0x14000e6b8)
- RtlVirtualUnwind (Address: 0x14000e6a8)
api-ms-win-core-sidebyside-l1-1-0.dll
- ActivateActCtx (Address: 0x14000e6c8)
- CreateActCtxW (Address: 0x14000e6e8)
- DeactivateActCtx (Address: 0x14000e6d0)
- QueryActCtxW (Address: 0x14000e6e0)
- ReleaseActCtx (Address: 0x14000e6d8)
api-ms-win-core-string-l1-1-0.dll
- CompareStringW (Address: 0x14000e6f8)
- WideCharToMultiByte (Address: 0x14000e700)
api-ms-win-core-string-l2-1-0.dll
- CharNextW (Address: 0x14000e710)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x14000e788)
- AcquireSRWLockShared (Address: 0x14000e780)
- CreateEventW (Address: 0x14000e770)
- CreateMutexExW (Address: 0x14000e720)
- CreateSemaphoreExW (Address: 0x14000e728)
- DeleteCriticalSection (Address: 0x14000e738)
- EnterCriticalSection (Address: 0x14000e740)
- InitializeCriticalSectionEx (Address: 0x14000e730)
- LeaveCriticalSection (Address: 0x14000e748)
- OpenSemaphoreW (Address: 0x14000e798)
- ReleaseMutex (Address: 0x14000e760)
- ReleaseSemaphore (Address: 0x14000e750)
- ReleaseSRWLockExclusive (Address: 0x14000e778)
- ReleaseSRWLockShared (Address: 0x14000e790)
- SetEvent (Address: 0x14000e768)
- WaitForSingleObject (Address: 0x14000e758)
- WaitForSingleObjectEx (Address: 0x14000e7a0)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x14000e7b0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x14000e7c0)
- GetSystemTimeAsFileTime (Address: 0x14000e7c8)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x14000e7e8)
- CreateThreadpoolTimer (Address: 0x14000e7d8)
- SetThreadpoolTimer (Address: 0x14000e7f0)
- WaitForThreadpoolTimerCallbacks (Address: 0x14000e7e0)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x14000e800)
- EncodePointer (Address: 0x14000e808)
api-ms-win-core-winrt-error-l1-1-0.dll
- RoOriginateError (Address: 0x14000e820)
- RoOriginateErrorW (Address: 0x14000e818)
api-ms-win-core-wow64-l1-1-0.dll
- Wow64EnableWow64FsRedirection (Address: 0x14000e830)
api-ms-win-core-wow64-l1-1-1.dll
- GetSystemWow64Directory2W (Address: 0x14000e848)
- IsWow64Process2 (Address: 0x14000e840)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x14000e8f8)
- __current_exception (Address: 0x14000e908)
- __current_exception_context (Address: 0x14000e910)
- __CxxFrameHandler3 (Address: 0x14000e900)
- _CxxThrowException (Address: 0x14000e918)
- _o___p__commode (Address: 0x14000e958)
- _o___std_exception_copy (Address: 0x14000e940)
- _o___std_exception_destroy (Address: 0x14000e938)
- _o___stdio_common_vswprintf (Address: 0x14000e930)
- _o__callnewh (Address: 0x14000e920)
- _o__cexit (Address: 0x14000e8b8)
- _o__configthreadlocale (Address: 0x14000e950)
- _o__configure_wide_argv (Address: 0x14000e948)
- _o__crt_atexit (Address: 0x14000e928)
- _o__errno (Address: 0x14000e858)
- _o__exit (Address: 0x14000e860)
- _o__get_wide_winmain_command_line (Address: 0x14000e868)
- _o__initialize_onexit_table (Address: 0x14000e870)
- _o__initialize_wide_environment (Address: 0x14000e878)
- _o__invalid_parameter_noinfo (Address: 0x14000e880)
- _o__purecall (Address: 0x14000e888)
- _o__register_onexit_function (Address: 0x14000e890)
- _o__seh_filter_exe (Address: 0x14000e898)
- _o__set_app_type (Address: 0x14000e8a0)
- _o__set_fmode (Address: 0x14000e8a8)
- _o__set_new_mode (Address: 0x14000e8b0)
- _o__wtoi (Address: 0x14000e8c8)
- _o_exit (Address: 0x14000e8d0)
- _o_free (Address: 0x14000e8d8)
- _o_malloc (Address: 0x14000e8e0)
- _o_memcpy_s (Address: 0x14000e8e8)
- _o_terminate (Address: 0x14000e8f0)
- memcmp (Address: 0x14000e960)
- memcpy (Address: 0x14000e8c0)
api-ms-win-crt-runtime-l1-1-0.dll
- _c_exit (Address: 0x14000e970)
- _initterm (Address: 0x14000e988)
- _initterm_e (Address: 0x14000e980)
- _register_thread_local_exe_atexit_callback (Address: 0x14000e978)
api-ms-win-crt-string-l1-1-0.dll
- memmove_s (Address: 0x14000e998)
- memset (Address: 0x14000e9a0)
api-ms-win-downlevel-shlwapi-l1-1-0.dll
- PathIsRelativeW (Address: 0x14000e9b0)
api-ms-win-downlevel-shlwapi-l2-1-0.dll
- SHSetThreadRef (Address: 0x14000e9c0)
imagehlp.dll
- ImageDirectoryEntryToData (Address: 0x14000e9d0)
ntdll.dll
- NtClose (Address: 0x14000ea20)
- NtOpenProcessToken (Address: 0x14000e9e0)
- NtQueryInformationToken (Address: 0x14000ea00)
- NtQuerySystemInformation (Address: 0x14000e9f0)
- NtSetInformationToken (Address: 0x14000ea08)
- RtlImageNtHeader (Address: 0x14000e9e8)
- RtlNtStatusToDosError (Address: 0x14000ea18)
- RtlSetSearchPathMode (Address: 0x14000e9f8)
- RtlWow64IsWowGuestMachineSupported (Address: 0x14000ea10)