offreg.dll
Description: Offline registry DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5129
Architecture: 32-bit
Operating System: Windows NT
SHA256: fefff8b327259d7b107104b353ca1b0d
File Size: 63.0 KB
Uploaded At: Dec. 1, 2025, 8:02 a.m.
Views: 13
Exported Functions
- ORCloseHive (Ordinal: 1, Address: 0x19a0)
- ORCloseKey (Ordinal: 2, Address: 0x2b10)
- ORCreateHive (Ordinal: 3, Address: 0x1650)
- ORCreateKey (Ordinal: 4, Address: 0x1fb0)
- ORDeleteKey (Ordinal: 5, Address: 0x24f0)
- ORDeleteValue (Ordinal: 6, Address: 0x3740)
- OREnumKey (Ordinal: 7, Address: 0x2860)
- OREnumValue (Ordinal: 8, Address: 0x35d0)
- ORGetKeySecurity (Ordinal: 9, Address: 0x3b60)
- ORGetValue (Ordinal: 10, Address: 0x2f70)
- ORGetVersion (Ordinal: 11, Address: 0x3de0)
- ORGetVirtualFlags (Ordinal: 12, Address: 0x2b70)
- ORMergeHives (Ordinal: 13, Address: 0x4f90)
- OROpenHive (Ordinal: 14, Address: 0x1900)
- OROpenHiveByHandle (Ordinal: 15, Address: 0x18e0)
- OROpenKey (Ordinal: 16, Address: 0x1e80)
- ORQueryInfoKey (Ordinal: 17, Address: 0x2670)
- ORRenameKey (Ordinal: 18, Address: 0x2c70)
- ORSaveHive (Ordinal: 19, Address: 0x1b20)
- ORSetKeySecurity (Ordinal: 20, Address: 0x3c90)
- ORSetValue (Ordinal: 21, Address: 0x3470)
- ORSetVirtualFlags (Ordinal: 22, Address: 0x2be0)
Imported DLLs & Functions
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x10011004)
- SetUnhandledExceptionFilter (Address: 0x10011000)
- UnhandledExceptionFilter (Address: 0x10011008)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x10011014)
- FlushFileBuffers (Address: 0x10011018)
- GetFileSizeEx (Address: 0x10011020)
- GetFinalPathNameByHandleW (Address: 0x10011010)
- ReadFile (Address: 0x10011024)
- WriteFile (Address: 0x1001101c)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1001102c)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleHandleW (Address: 0x10011034)
- GetProcAddress (Address: 0x10011038)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x10011050)
- GetCurrentProcessId (Address: 0x1001105c)
- GetCurrentThreadId (Address: 0x10011040)
- TerminateProcess (Address: 0x10011044)
- TlsAlloc (Address: 0x1001104c)
- TlsFree (Address: 0x10011054)
- TlsGetValue (Address: 0x10011058)
- TlsSetValue (Address: 0x10011048)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x10011064)
api-ms-win-core-synch-l1-1-0.dll
- DeleteCriticalSection (Address: 0x10011070)
- EnterCriticalSection (Address: 0x10011078)
- InitializeCriticalSectionAndSpinCount (Address: 0x1001106c)
- LeaveCriticalSection (Address: 0x10011074)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x10011080)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1001108c)
- GetTickCount (Address: 0x10011088)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x100110dc)
- CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x10011098)
- DestroyPrivateObjectSecurity (Address: 0x100110a0)
- GetAce (Address: 0x100110ac)
- GetLengthSid (Address: 0x100110d8)
- GetSecurityDescriptorControl (Address: 0x100110b4)
- GetSecurityDescriptorLength (Address: 0x100110c0)
- GetSidLengthRequired (Address: 0x10011094)
- GetSidSubAuthority (Address: 0x100110b8)
- InitializeAcl (Address: 0x100110cc)
- InitializeSecurityDescriptor (Address: 0x100110b0)
- InitializeSid (Address: 0x1001109c)
- IsValidSecurityDescriptor (Address: 0x100110c4)
- IsValidSid (Address: 0x100110a4)
- MakeSelfRelativeSD (Address: 0x100110a8)
- SetPrivateObjectSecurityEx (Address: 0x100110d4)
- SetSecurityDescriptorDacl (Address: 0x100110c8)
- SetSecurityDescriptorGroup (Address: 0x100110d0)
- SetSecurityDescriptorOwner (Address: 0x100110bc)
msvcrt.dll
- _aligned_free (Address: 0x1001110c)
- _aligned_malloc (Address: 0x10011108)
- _amsg_exit (Address: 0x10011118)
- _except_handler4_common (Address: 0x100110e4)
- _initterm (Address: 0x100110e8)
- _wcsicmp (Address: 0x1001111c)
- _wcsnicmp (Address: 0x100110f8)
- _XcptFilter (Address: 0x100110f4)
- free (Address: 0x10011114)
- malloc (Address: 0x100110ec)
- memcmp (Address: 0x10011124)
- memcpy (Address: 0x10011120)
- memmove (Address: 0x100110f0)
- memset (Address: 0x10011128)
- qsort (Address: 0x10011110)
- wcscat_s (Address: 0x10011100)
- wcsncpy_s (Address: 0x100110fc)
- wcsnlen (Address: 0x10011104)
ntdll.dll
- RtlAcquireSRWLockExclusive (Address: 0x10011150)
- RtlAllocateHeap (Address: 0x10011158)
- RtlFindNextForwardRunClear (Address: 0x10011140)
- RtlFreeHeap (Address: 0x10011154)
- RtlInitializeSRWLock (Address: 0x10011148)
- RtlInitUnicodeString (Address: 0x10011130)
- RtlNtStatusToDosError (Address: 0x1001115c)
- RtlNumberOfSetBits (Address: 0x10011144)
- RtlReleaseSRWLockExclusive (Address: 0x1001114c)
- RtlRunOnceBeginInitialize (Address: 0x1001113c)
- RtlRunOnceComplete (Address: 0x10011138)
- RtlUpcaseUnicodeChar (Address: 0x10011134)