rundll32.exe

Description: Windows host process (Rundll32)

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.26100.8328

Architecture: 64-bit

Operating System: Windows NT

SHA256: 4d90fff3e33bf3cb2bea5e08e6487325

File Size: 96.0 KB

Uploaded At: May 17, 2026, 10:55 a.m.

Views: 22

Exported Functions

No exported functions.

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x14000e428)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x14000e488)
  • CoAddRefServerProcess (Address: 0x14000e460)
  • CoCreateInstance (Address: 0x14000e448)
  • CoInitializeEx (Address: 0x14000e440)
  • CoInitializeSecurity (Address: 0x14000e450)
  • CoRegisterClassObject (Address: 0x14000e458)
  • CoReleaseServerProcess (Address: 0x14000e478)
  • CoResumeClassObjects (Address: 0x14000e468)
  • CoRevokeClassObject (Address: 0x14000e438)
  • CoUninitialize (Address: 0x14000e470)
  • CoWaitForMultipleHandles (Address: 0x14000e480)
api-ms-win-core-console-l1-1-0.dll
  • WriteConsoleW (Address: 0x14000e498)
api-ms-win-core-console-l1-2-0.dll
  • AttachConsole (Address: 0x14000e4a8)
  • FreeConsole (Address: 0x14000e4b0)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x14000e4c0)
  • IsDebuggerPresent (Address: 0x14000e4d0)
  • OutputDebugStringW (Address: 0x14000e4c8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x14000e4e0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x14000e4f0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x14000e520)
  • SetErrorMode (Address: 0x14000e500)
  • SetLastError (Address: 0x14000e518)
  • SetUnhandledExceptionFilter (Address: 0x14000e508)
  • UnhandledExceptionFilter (Address: 0x14000e510)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x14000e548)
  • GetFileAttributesW (Address: 0x14000e540)
  • ReadFile (Address: 0x14000e530)
  • SetFilePointer (Address: 0x14000e538)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x14000e558)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x14000e580)
  • HeapAlloc (Address: 0x14000e570)
  • HeapFree (Address: 0x14000e568)
  • HeapSetInformation (Address: 0x14000e578)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x14000e590)
  • LocalFree (Address: 0x14000e598)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x14000e5a8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x14000e5c0)
  • GetModuleFileNameA (Address: 0x14000e5d0)
  • GetModuleHandleExW (Address: 0x14000e5d8)
  • GetModuleHandleW (Address: 0x14000e5e0)
  • GetProcAddress (Address: 0x14000e5b8)
  • LoadLibraryExW (Address: 0x14000e5e8)
  • LoadStringW (Address: 0x14000e5c8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x14000e5f8)
api-ms-win-core-path-l1-1-0.dll
  • PathCchAppend (Address: 0x14000e608)
api-ms-win-core-processenvironment-l1-1-0.dll
  • GetCommandLineW (Address: 0x14000e618)
  • SearchPathW (Address: 0x14000e620)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x14000e658)
  • DeleteProcThreadAttributeList (Address: 0x14000e678)
  • ExitProcess (Address: 0x14000e668)
  • GetCurrentProcess (Address: 0x14000e630)
  • GetCurrentProcessId (Address: 0x14000e640)
  • GetCurrentThreadId (Address: 0x14000e638)
  • GetStartupInfoW (Address: 0x14000e648)
  • InitializeProcThreadAttributeList (Address: 0x14000e670)
  • TerminateProcess (Address: 0x14000e660)
  • UpdateProcThreadAttribute (Address: 0x14000e650)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x14000e688)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x14000e698)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x14000e6b0)
  • RtlLookupFunctionEntry (Address: 0x14000e6b8)
  • RtlVirtualUnwind (Address: 0x14000e6a8)
api-ms-win-core-sidebyside-l1-1-0.dll
  • ActivateActCtx (Address: 0x14000e6c8)
  • CreateActCtxW (Address: 0x14000e6e8)
  • DeactivateActCtx (Address: 0x14000e6d0)
  • QueryActCtxW (Address: 0x14000e6e0)
  • ReleaseActCtx (Address: 0x14000e6d8)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringW (Address: 0x14000e6f8)
  • WideCharToMultiByte (Address: 0x14000e700)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x14000e710)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x14000e788)
  • AcquireSRWLockShared (Address: 0x14000e780)
  • CreateEventW (Address: 0x14000e770)
  • CreateMutexExW (Address: 0x14000e720)
  • CreateSemaphoreExW (Address: 0x14000e728)
  • DeleteCriticalSection (Address: 0x14000e738)
  • EnterCriticalSection (Address: 0x14000e740)
  • InitializeCriticalSectionEx (Address: 0x14000e730)
  • LeaveCriticalSection (Address: 0x14000e748)
  • OpenSemaphoreW (Address: 0x14000e798)
  • ReleaseMutex (Address: 0x14000e760)
  • ReleaseSemaphore (Address: 0x14000e750)
  • ReleaseSRWLockExclusive (Address: 0x14000e778)
  • ReleaseSRWLockShared (Address: 0x14000e790)
  • SetEvent (Address: 0x14000e768)
  • WaitForSingleObject (Address: 0x14000e758)
  • WaitForSingleObjectEx (Address: 0x14000e7a0)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x14000e7b0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x14000e7c0)
  • GetSystemTimeAsFileTime (Address: 0x14000e7c8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x14000e7e8)
  • CreateThreadpoolTimer (Address: 0x14000e7d8)
  • SetThreadpoolTimer (Address: 0x14000e7f0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x14000e7e0)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x14000e800)
  • EncodePointer (Address: 0x14000e808)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x14000e820)
  • RoOriginateErrorW (Address: 0x14000e818)
api-ms-win-core-wow64-l1-1-0.dll
  • Wow64EnableWow64FsRedirection (Address: 0x14000e830)
api-ms-win-core-wow64-l1-1-1.dll
  • GetSystemWow64Directory2W (Address: 0x14000e848)
  • IsWow64Process2 (Address: 0x14000e840)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x14000e8f8)
  • __current_exception (Address: 0x14000e908)
  • __current_exception_context (Address: 0x14000e910)
  • __CxxFrameHandler3 (Address: 0x14000e900)
  • _CxxThrowException (Address: 0x14000e918)
  • _o___p__commode (Address: 0x14000e958)
  • _o___std_exception_copy (Address: 0x14000e940)
  • _o___std_exception_destroy (Address: 0x14000e938)
  • _o___stdio_common_vswprintf (Address: 0x14000e930)
  • _o__callnewh (Address: 0x14000e920)
  • _o__cexit (Address: 0x14000e8b8)
  • _o__configthreadlocale (Address: 0x14000e950)
  • _o__configure_wide_argv (Address: 0x14000e948)
  • _o__crt_atexit (Address: 0x14000e928)
  • _o__errno (Address: 0x14000e858)
  • _o__exit (Address: 0x14000e860)
  • _o__get_wide_winmain_command_line (Address: 0x14000e868)
  • _o__initialize_onexit_table (Address: 0x14000e870)
  • _o__initialize_wide_environment (Address: 0x14000e878)
  • _o__invalid_parameter_noinfo (Address: 0x14000e880)
  • _o__purecall (Address: 0x14000e888)
  • _o__register_onexit_function (Address: 0x14000e890)
  • _o__seh_filter_exe (Address: 0x14000e898)
  • _o__set_app_type (Address: 0x14000e8a0)
  • _o__set_fmode (Address: 0x14000e8a8)
  • _o__set_new_mode (Address: 0x14000e8b0)
  • _o__wtoi (Address: 0x14000e8c8)
  • _o_exit (Address: 0x14000e8d0)
  • _o_free (Address: 0x14000e8d8)
  • _o_malloc (Address: 0x14000e8e0)
  • _o_memcpy_s (Address: 0x14000e8e8)
  • _o_terminate (Address: 0x14000e8f0)
  • memcmp (Address: 0x14000e960)
  • memcpy (Address: 0x14000e8c0)
api-ms-win-crt-runtime-l1-1-0.dll
  • _c_exit (Address: 0x14000e970)
  • _initterm (Address: 0x14000e988)
  • _initterm_e (Address: 0x14000e980)
  • _register_thread_local_exe_atexit_callback (Address: 0x14000e978)
api-ms-win-crt-string-l1-1-0.dll
  • memmove_s (Address: 0x14000e998)
  • memset (Address: 0x14000e9a0)
api-ms-win-downlevel-shlwapi-l1-1-0.dll
  • PathIsRelativeW (Address: 0x14000e9b0)
api-ms-win-downlevel-shlwapi-l2-1-0.dll
  • SHSetThreadRef (Address: 0x14000e9c0)
imagehlp.dll
  • ImageDirectoryEntryToData (Address: 0x14000e9d0)
ntdll.dll
  • NtClose (Address: 0x14000ea20)
  • NtOpenProcessToken (Address: 0x14000e9e0)
  • NtQueryInformationToken (Address: 0x14000ea00)
  • NtQuerySystemInformation (Address: 0x14000e9f0)
  • NtSetInformationToken (Address: 0x14000ea08)
  • RtlImageNtHeader (Address: 0x14000e9e8)
  • RtlNtStatusToDosError (Address: 0x14000ea18)
  • RtlSetSearchPathMode (Address: 0x14000e9f8)
  • RtlWow64IsWowGuestMachineSupported (Address: 0x14000ea10)