SystemSettings.DataModel.dll

Description: SystemSettings.Datamodel private API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6396

Architecture: 64-bit

Operating System: Windows NT

SHA256: 79f40cd1d5f599beba1841469490e3b8

File Size: 470.9 KB

Uploaded At: Dec. 1, 2025, 7:40 a.m.

Views: 34

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0xa610)
  • DllGetActivationFactory (Ordinal: 2, Address: 0xa120)
  • DllGetClassObject (Ordinal: 3, Address: 0x9e70)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateFreeThreadedMarshaler (Address: 0x180057458)
  • CoCreateInstance (Address: 0x1800574b0)
  • CoGetApartmentType (Address: 0x180057488)
  • CoGetCallContext (Address: 0x1800574a8)
  • CoGetInterfaceAndReleaseStream (Address: 0x1800574b8)
  • CoGetMalloc (Address: 0x180057480)
  • CoImpersonateClient (Address: 0x180057460)
  • CoIncrementMTAUsage (Address: 0x180057478)
  • CoMarshalInterface (Address: 0x180057498)
  • CoReleaseMarshalData (Address: 0x1800574c0)
  • CoRevertToSelf (Address: 0x180057468)
  • CoTaskMemAlloc (Address: 0x180057470)
  • CoTaskMemFree (Address: 0x180057450)
  • CoTaskMemRealloc (Address: 0x180057448)
  • CoWaitForMultipleHandles (Address: 0x180057490)
  • CreateStreamOnHGlobal (Address: 0x1800574a0)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x1800574d0)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • CStdStubBuffer2_Connect (Address: 0x180057580)
  • CStdStubBuffer2_CountRefs (Address: 0x180057548)
  • CStdStubBuffer2_Disconnect (Address: 0x180057510)
  • CStdStubBuffer2_QueryInterface (Address: 0x1800574e0)
  • NdrProxyForwardingFunction3 (Address: 0x180057570)
  • NdrProxyForwardingFunction4 (Address: 0x180057508)
  • NdrProxyForwardingFunction5 (Address: 0x180057558)
  • ObjectStublessClient10 (Address: 0x180057540)
  • ObjectStublessClient11 (Address: 0x180057550)
  • ObjectStublessClient12 (Address: 0x180057578)
  • ObjectStublessClient13 (Address: 0x1800574f8)
  • ObjectStublessClient14 (Address: 0x180057568)
  • ObjectStublessClient15 (Address: 0x180057588)
  • ObjectStublessClient16 (Address: 0x180057560)
  • ObjectStublessClient17 (Address: 0x180057538)
  • ObjectStublessClient18 (Address: 0x1800574f0)
  • ObjectStublessClient19 (Address: 0x1800574e8)
  • ObjectStublessClient3 (Address: 0x180057530)
  • ObjectStublessClient6 (Address: 0x180057518)
  • ObjectStublessClient7 (Address: 0x180057500)
  • ObjectStublessClient8 (Address: 0x180057520)
  • ObjectStublessClient9 (Address: 0x180057528)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800575a0)
  • IsDebuggerPresent (Address: 0x180057598)
  • OutputDebugStringW (Address: 0x1800575a8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800575b8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800575c8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800575d8)
  • RaiseException (Address: 0x1800575f0)
  • SetLastError (Address: 0x1800575e8)
  • SetUnhandledExceptionFilter (Address: 0x1800575f8)
  • UnhandledExceptionFilter (Address: 0x1800575e0)
api-ms-win-core-errorhandling-l1-1-2.dll
  • RaiseFailFastException (Address: 0x180057608)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180057618)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180057630)
  • HeapAlloc (Address: 0x180057628)
  • HeapFree (Address: 0x180057638)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180057658)
  • InterlockedFlushSList (Address: 0x180057648)
  • InterlockedPushEntrySList (Address: 0x180057650)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180057670)
  • FreeLibrary (Address: 0x180057680)
  • GetModuleFileNameA (Address: 0x180057688)
  • GetModuleHandleExW (Address: 0x180057668)
  • GetModuleHandleW (Address: 0x180057678)
  • GetProcAddress (Address: 0x180057698)
  • LoadLibraryExW (Address: 0x180057690)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800576b8)
  • GetGeoInfoW (Address: 0x1800576a8)
  • GetUserGeoID (Address: 0x1800576b0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800576c8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800576f8)
  • GetCurrentProcessId (Address: 0x1800576e8)
  • GetCurrentThread (Address: 0x1800576d8)
  • GetCurrentThreadId (Address: 0x180057700)
  • OpenProcessToken (Address: 0x1800576e0)
  • OpenThreadToken (Address: 0x1800576f0)
  • ProcessIdToSessionId (Address: 0x180057710)
  • TerminateProcess (Address: 0x180057708)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180057728)
  • OpenProcess (Address: 0x180057720)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180057738)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180057778)
  • RegCreateKeyExW (Address: 0x180057758)
  • RegDeleteValueW (Address: 0x180057768)
  • RegEnumKeyExW (Address: 0x180057770)
  • RegGetValueW (Address: 0x180057748)
  • RegOpenKeyExW (Address: 0x180057750)
  • RegSetValueExW (Address: 0x180057760)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180057798)
  • RtlLookupFunctionEntry (Address: 0x180057790)
  • RtlVirtualUnwind (Address: 0x180057788)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1800577b0)
  • MultiByteToWideChar (Address: 0x1800577a8)
api-ms-win-core-string-l2-1-0.dll
  • CharLowerBuffW (Address: 0x1800577c0)
api-ms-win-core-string-l2-1-1.dll
  • SHLoadIndirectString (Address: 0x1800577d0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800577f0)
  • AcquireSRWLockShared (Address: 0x1800577e0)
  • CreateEventExW (Address: 0x180057808)
  • CreateEventW (Address: 0x180057830)
  • CreateMutexExW (Address: 0x180057870)
  • CreateSemaphoreExW (Address: 0x180057860)
  • DeleteCriticalSection (Address: 0x180057828)
  • EnterCriticalSection (Address: 0x1800577f8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180057848)
  • InitializeCriticalSectionEx (Address: 0x180057818)
  • InitializeSRWLock (Address: 0x180057888)
  • LeaveCriticalSection (Address: 0x180057868)
  • OpenSemaphoreW (Address: 0x180057858)
  • ReleaseMutex (Address: 0x180057820)
  • ReleaseSemaphore (Address: 0x1800577e8)
  • ReleaseSRWLockExclusive (Address: 0x180057878)
  • ReleaseSRWLockShared (Address: 0x180057880)
  • ResetEvent (Address: 0x180057838)
  • SetEvent (Address: 0x180057840)
  • WaitForMultipleObjectsEx (Address: 0x180057810)
  • WaitForSingleObject (Address: 0x180057850)
  • WaitForSingleObjectEx (Address: 0x180057800)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x1800578a8)
  • InitOnceComplete (Address: 0x1800578a0)
  • InitOnceExecuteOnce (Address: 0x180057898)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x1800578b8)
  • GetSystemTimeAsFileTime (Address: 0x1800578c8)
  • GetTickCount (Address: 0x1800578c0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x1800578e0)
  • CreateThreadpoolTimer (Address: 0x1800578e8)
  • SetThreadpoolTimer (Address: 0x1800578f0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800578d8)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180057900)
  • EncodePointer (Address: 0x180057908)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180057918)
  • RoGetActivationFactory (Address: 0x180057920)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x180057930)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x1800579a8)
  • __CxxFrameHandler3 (Address: 0x1800579b0)
  • __CxxFrameHandler4 (Address: 0x180057a18)
  • __std_terminate (Address: 0x180057a10)
  • _CxxThrowException (Address: 0x1800579c0)
  • _o___std_exception_copy (Address: 0x180057a08)
  • _o___std_exception_destroy (Address: 0x180057a00)
  • _o___std_type_info_destroy_list (Address: 0x1800579f8)
  • _o___stdio_common_vsnprintf_s (Address: 0x1800579f0)
  • _o___stdio_common_vswprintf (Address: 0x1800579e8)
  • _o__callnewh (Address: 0x1800579e0)
  • _o__cexit (Address: 0x1800579d8)
  • _o__configure_narrow_argv (Address: 0x1800579d0)
  • _o__crt_atexit (Address: 0x1800579c8)
  • _o__errno (Address: 0x1800579b8)
  • _o__execute_onexit_table (Address: 0x180057a20)
  • _o__initialize_narrow_environment (Address: 0x180057940)
  • _o__initialize_onexit_table (Address: 0x180057948)
  • _o__invalid_parameter_noinfo (Address: 0x180057950)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x180057958)
  • _o__purecall (Address: 0x180057960)
  • _o__register_onexit_function (Address: 0x180057968)
  • _o__seh_filter_dll (Address: 0x180057970)
  • _o_free (Address: 0x180057980)
  • _o_iswspace (Address: 0x180057988)
  • _o_malloc (Address: 0x180057990)
  • _o_realloc (Address: 0x180057998)
  • _o_terminate (Address: 0x1800579a0)
  • memcmp (Address: 0x180057a28)
  • memcpy (Address: 0x180057a30)
  • memmove (Address: 0x180057978)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180057a40)
  • _initterm_e (Address: 0x180057a48)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180057a58)
  • wcsncmp (Address: 0x180057a60)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x180057a70)
  • EventSetInformation (Address: 0x180057a78)
  • EventUnregister (Address: 0x180057a88)
  • EventWriteTransfer (Address: 0x180057a80)
api-ms-win-oobe-notification-l1-1-0.dll
  • OOBEComplete (Address: 0x180057a98)
api-ms-win-rtcore-ntuser-synch-l1-1-0.dll
  • MsgWaitForMultipleObjectsEx (Address: 0x180057aa8)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • AllowSetForegroundWindow (Address: 0x180057ad0)
  • DispatchMessageW (Address: 0x180057ac8)
  • PeekMessageW (Address: 0x180057ac0)
  • PostQuitMessage (Address: 0x180057ab8)
  • TranslateMessage (Address: 0x180057ad8)
api-ms-win-security-base-l1-1-0.dll
  • DuplicateTokenEx (Address: 0x180057b00)
  • EqualSid (Address: 0x180057ae8)
  • GetTokenInformation (Address: 0x180057af0)
  • IsValidSid (Address: 0x180057af8)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x180057b10)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertStringSidToSidW (Address: 0x180057b20)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolAllowThreadReuse (Address: 0x180057b38)
  • SHTaskPoolGetUniqueContext (Address: 0x180057b30)
  • SHTaskPoolQueueTask (Address: 0x180057b40)
combase.dll
  • (Address: 0x180057b50)
  • (Address: 0x180057b58)
msvcp_win.dll
  • _Cnd_broadcast (Address: 0x180057c48)
  • _Cnd_destroy_in_situ (Address: 0x180057c20)
  • _Cnd_init_in_situ (Address: 0x180057bc0)
  • _Cnd_wait (Address: 0x180057c38)
  • _Mtx_destroy_in_situ (Address: 0x180057c60)
  • _Mtx_init_in_situ (Address: 0x180057b90)
  • _Mtx_lock (Address: 0x180057c50)
  • _Mtx_unlock (Address: 0x180057bf8)
  • ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z (Address: 0x180057c40)
  • ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z (Address: 0x180057bc8)
  • ?__ExceptionPtrCreate@@YAXPEAX@Z (Address: 0x180057b98)
  • ?__ExceptionPtrCurrentException@@YAXPEAX@Z (Address: 0x180057c68)
  • ?__ExceptionPtrDestroy@@YAXPEAX@Z (Address: 0x180057c70)
  • ?__ExceptionPtrRethrow@@YAXPEBX@Z (Address: 0x180057b70)
  • ?__ExceptionPtrToBool@@YA_NPEBX@Z (Address: 0x180057bb8)
  • ?_CallInContext@_ContextCallback@details@Concurrency@@QEBAXV?$function@$$A6AXXZ@std@@_N@Z (Address: 0x180057be8)
  • ?_Capture@_ContextCallback@details@Concurrency@@AEAAXXZ (Address: 0x180057c00)
  • ?_Execute_once@std@@YAHAEAUonce_flag@1@P6AHPEAX1PEAPEAX@Z1@Z (Address: 0x180057bb0)
  • ?_LogCancelTask@_TaskEventLogger@details@Concurrency@@QEAAXXZ (Address: 0x180057ba8)
  • ?_LogScheduleTask@_TaskEventLogger@details@Concurrency@@QEAAX_N@Z (Address: 0x180057ba0)
  • ?_LogTaskCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ (Address: 0x180057bd8)
  • ?_LogTaskExecutionCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ (Address: 0x180057bd0)
  • ?_LogWorkItemCompleted@_TaskEventLogger@details@Concurrency@@QEAAXXZ (Address: 0x180057b88)
  • ?_LogWorkItemStarted@_TaskEventLogger@details@Concurrency@@QEAAXXZ (Address: 0x180057b80)
  • ?_Release_chore@details@Concurrency@@YAXPEAU_Threadpool_chore@12@@Z (Address: 0x180057c30)
  • ?_ReportUnobservedException@details@Concurrency@@YAXXZ (Address: 0x180057b68)
  • ?_Reset@_ContextCallback@details@Concurrency@@AEAAXXZ (Address: 0x180057bf0)
  • ?_Schedule_chore@details@Concurrency@@YAHPEAU_Threadpool_chore@12@@Z (Address: 0x180057c28)
  • ?_Throw_C_error@std@@YAXH@Z (Address: 0x180057be0)
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x180057c08)
  • ?_XGetLastError@std@@YAXXZ (Address: 0x180057c58)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x180057c78)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180057c18)
  • ??0task_continuation_context@Concurrency@@AEAA@XZ (Address: 0x180057b78)
  • ?GetCurrentThreadId@platform@details@Concurrency@@YAJXZ (Address: 0x180057c10)
ntdll.dll
  • RtlPublishWnfStateData (Address: 0x180057c88)
OLEAUT32.dll
  • SysFreeString (Address: 0x180057388)
  • SysStringLen (Address: 0x180057390)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x180057418)
  • CStdStubBuffer_Connect (Address: 0x180057400)
  • CStdStubBuffer_CountRefs (Address: 0x180057428)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800573f8)
  • CStdStubBuffer_DebugServerRelease (Address: 0x180057408)
  • CStdStubBuffer_Disconnect (Address: 0x1800573b8)
  • CStdStubBuffer_Invoke (Address: 0x1800573e0)
  • CStdStubBuffer_IsIIDSupported (Address: 0x1800573b0)
  • CStdStubBuffer_QueryInterface (Address: 0x180057438)
  • IUnknown_AddRef_Proxy (Address: 0x1800573f0)
  • IUnknown_QueryInterface_Proxy (Address: 0x1800573a0)
  • IUnknown_Release_Proxy (Address: 0x180057420)
  • NdrCStdStubBuffer_Release (Address: 0x1800573d8)
  • NdrCStdStubBuffer2_Release (Address: 0x1800573c0)
  • NdrDllCanUnloadNow (Address: 0x1800573d0)
  • NdrDllGetClassObject (Address: 0x1800573c8)
  • NdrOleAllocate (Address: 0x180057430)
  • NdrOleFree (Address: 0x180057410)
  • NdrStubCall3 (Address: 0x1800573a8)
  • NdrStubForwardingFunction (Address: 0x1800573e8)