offreg.dll

Description: Offline registry DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5129

Architecture: 32-bit

Operating System: Windows NT

SHA256: fefff8b327259d7b107104b353ca1b0d

File Size: 63.0 KB

Uploaded At: Dec. 1, 2025, 8:02 a.m.

Views: 13

Exported Functions

  • ORCloseHive (Ordinal: 1, Address: 0x19a0)
  • ORCloseKey (Ordinal: 2, Address: 0x2b10)
  • ORCreateHive (Ordinal: 3, Address: 0x1650)
  • ORCreateKey (Ordinal: 4, Address: 0x1fb0)
  • ORDeleteKey (Ordinal: 5, Address: 0x24f0)
  • ORDeleteValue (Ordinal: 6, Address: 0x3740)
  • OREnumKey (Ordinal: 7, Address: 0x2860)
  • OREnumValue (Ordinal: 8, Address: 0x35d0)
  • ORGetKeySecurity (Ordinal: 9, Address: 0x3b60)
  • ORGetValue (Ordinal: 10, Address: 0x2f70)
  • ORGetVersion (Ordinal: 11, Address: 0x3de0)
  • ORGetVirtualFlags (Ordinal: 12, Address: 0x2b70)
  • ORMergeHives (Ordinal: 13, Address: 0x4f90)
  • OROpenHive (Ordinal: 14, Address: 0x1900)
  • OROpenHiveByHandle (Ordinal: 15, Address: 0x18e0)
  • OROpenKey (Ordinal: 16, Address: 0x1e80)
  • ORQueryInfoKey (Ordinal: 17, Address: 0x2670)
  • ORRenameKey (Ordinal: 18, Address: 0x2c70)
  • ORSaveHive (Ordinal: 19, Address: 0x1b20)
  • ORSetKeySecurity (Ordinal: 20, Address: 0x3c90)
  • ORSetValue (Ordinal: 21, Address: 0x3470)
  • ORSetVirtualFlags (Ordinal: 22, Address: 0x2be0)

Imported DLLs & Functions

api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x10011004)
  • SetUnhandledExceptionFilter (Address: 0x10011000)
  • UnhandledExceptionFilter (Address: 0x10011008)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x10011014)
  • FlushFileBuffers (Address: 0x10011018)
  • GetFileSizeEx (Address: 0x10011020)
  • GetFinalPathNameByHandleW (Address: 0x10011010)
  • ReadFile (Address: 0x10011024)
  • WriteFile (Address: 0x1001101c)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1001102c)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleHandleW (Address: 0x10011034)
  • GetProcAddress (Address: 0x10011038)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x10011050)
  • GetCurrentProcessId (Address: 0x1001105c)
  • GetCurrentThreadId (Address: 0x10011040)
  • TerminateProcess (Address: 0x10011044)
  • TlsAlloc (Address: 0x1001104c)
  • TlsFree (Address: 0x10011054)
  • TlsGetValue (Address: 0x10011058)
  • TlsSetValue (Address: 0x10011048)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x10011064)
api-ms-win-core-synch-l1-1-0.dll
  • DeleteCriticalSection (Address: 0x10011070)
  • EnterCriticalSection (Address: 0x10011078)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1001106c)
  • LeaveCriticalSection (Address: 0x10011074)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x10011080)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1001108c)
  • GetTickCount (Address: 0x10011088)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x100110dc)
  • CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x10011098)
  • DestroyPrivateObjectSecurity (Address: 0x100110a0)
  • GetAce (Address: 0x100110ac)
  • GetLengthSid (Address: 0x100110d8)
  • GetSecurityDescriptorControl (Address: 0x100110b4)
  • GetSecurityDescriptorLength (Address: 0x100110c0)
  • GetSidLengthRequired (Address: 0x10011094)
  • GetSidSubAuthority (Address: 0x100110b8)
  • InitializeAcl (Address: 0x100110cc)
  • InitializeSecurityDescriptor (Address: 0x100110b0)
  • InitializeSid (Address: 0x1001109c)
  • IsValidSecurityDescriptor (Address: 0x100110c4)
  • IsValidSid (Address: 0x100110a4)
  • MakeSelfRelativeSD (Address: 0x100110a8)
  • SetPrivateObjectSecurityEx (Address: 0x100110d4)
  • SetSecurityDescriptorDacl (Address: 0x100110c8)
  • SetSecurityDescriptorGroup (Address: 0x100110d0)
  • SetSecurityDescriptorOwner (Address: 0x100110bc)
msvcrt.dll
  • _aligned_free (Address: 0x1001110c)
  • _aligned_malloc (Address: 0x10011108)
  • _amsg_exit (Address: 0x10011118)
  • _except_handler4_common (Address: 0x100110e4)
  • _initterm (Address: 0x100110e8)
  • _wcsicmp (Address: 0x1001111c)
  • _wcsnicmp (Address: 0x100110f8)
  • _XcptFilter (Address: 0x100110f4)
  • free (Address: 0x10011114)
  • malloc (Address: 0x100110ec)
  • memcmp (Address: 0x10011124)
  • memcpy (Address: 0x10011120)
  • memmove (Address: 0x100110f0)
  • memset (Address: 0x10011128)
  • qsort (Address: 0x10011110)
  • wcscat_s (Address: 0x10011100)
  • wcsncpy_s (Address: 0x100110fc)
  • wcsnlen (Address: 0x10011104)
ntdll.dll
  • RtlAcquireSRWLockExclusive (Address: 0x10011150)
  • RtlAllocateHeap (Address: 0x10011158)
  • RtlFindNextForwardRunClear (Address: 0x10011140)
  • RtlFreeHeap (Address: 0x10011154)
  • RtlInitializeSRWLock (Address: 0x10011148)
  • RtlInitUnicodeString (Address: 0x10011130)
  • RtlNtStatusToDosError (Address: 0x1001115c)
  • RtlNumberOfSetBits (Address: 0x10011144)
  • RtlReleaseSRWLockExclusive (Address: 0x1001114c)
  • RtlRunOnceBeginInitialize (Address: 0x1001113c)
  • RtlRunOnceComplete (Address: 0x10011138)
  • RtlUpcaseUnicodeChar (Address: 0x10011134)