PackageStateRoaming.dll
Description: Package State Roaming
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 32-bit
Operating System: Windows NT
SHA256: 1b4eee885d93b1a2043ebfb6db722c44
File Size: 190.5 KB
Uploaded At: Dec. 1, 2025, 8:02 a.m.
Views: 17
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0xf540)
- DllGetClassObject (Ordinal: 2, Address: 0xba10)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-internal-l1-1-1.dll
- GetPackageStatus (Address: 0x1002804c)
api-ms-win-appmodel-runtime-l1-1-0.dll
- GetApplicationUserModelId (Address: 0x10028054)
- GetPackagesByPackageFamily (Address: 0x10028058)
api-ms-win-appmodel-runtime-l1-1-1.dll
- GetStagedPackageOrigin (Address: 0x10028060)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x10028070)
- IsDebuggerPresent (Address: 0x1002806c)
- OutputDebugStringW (Address: 0x10028068)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x10028078)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x10028080)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1002808c)
- SetLastError (Address: 0x10028090)
- SetUnhandledExceptionFilter (Address: 0x10028088)
- UnhandledExceptionFilter (Address: 0x10028094)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x1002809c)
- FindClose (Address: 0x100280a4)
- FindFirstFileW (Address: 0x100280a0)
- FindNextFileW (Address: 0x100280a8)
- GetFileAttributesW (Address: 0x100280ac)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x100280b4)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x100280bc)
- HeapAlloc (Address: 0x100280c4)
- HeapFree (Address: 0x100280c0)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x100280cc)
- LocalFree (Address: 0x100280d0)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x100280d8)
- FreeLibrary (Address: 0x100280e8)
- GetModuleFileNameA (Address: 0x100280e0)
- GetModuleHandleExW (Address: 0x100280e4)
- GetModuleHandleW (Address: 0x100280dc)
- GetProcAddress (Address: 0x100280ec)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x100280f4)
api-ms-win-core-path-l1-1-0.dll
- PathAllocCombine (Address: 0x10028100)
- PathCchCombine (Address: 0x100280fc)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x10028108)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x10028118)
- GetCurrentProcessId (Address: 0x10028128)
- GetCurrentThread (Address: 0x10028120)
- GetCurrentThreadId (Address: 0x1002811c)
- ProcessIdToSessionId (Address: 0x10028114)
- SetThreadPriority (Address: 0x10028124)
- TerminateProcess (Address: 0x10028110)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x10028130)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x10028138)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x10028154)
- RegCreateKeyExW (Address: 0x1002814c)
- RegDeleteValueW (Address: 0x10028150)
- RegGetValueW (Address: 0x10028158)
- RegOpenCurrentUser (Address: 0x10028144)
- RegOpenKeyExW (Address: 0x10028140)
- RegQueryValueExW (Address: 0x1002815c)
- RegSetValueExW (Address: 0x10028148)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFindFileNameW (Address: 0x10028168)
- PathRemoveBackslashW (Address: 0x10028164)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- QISearch (Address: 0x10028178)
- StrRChrW (Address: 0x10028174)
- StrStrIW (Address: 0x10028170)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x10028180)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x100281cc)
- AcquireSRWLockShared (Address: 0x10028190)
- CreateEventExW (Address: 0x10028194)
- CreateMutexExW (Address: 0x10028198)
- CreateSemaphoreExW (Address: 0x100281a0)
- DeleteCriticalSection (Address: 0x100281a8)
- EnterCriticalSection (Address: 0x100281b0)
- InitializeCriticalSectionEx (Address: 0x100281ac)
- InitializeSRWLock (Address: 0x1002818c)
- LeaveCriticalSection (Address: 0x100281b4)
- OpenSemaphoreW (Address: 0x1002819c)
- ReleaseMutex (Address: 0x100281d0)
- ReleaseSemaphore (Address: 0x100281c4)
- ReleaseSRWLockExclusive (Address: 0x100281c0)
- ReleaseSRWLockShared (Address: 0x100281bc)
- ResetEvent (Address: 0x100281b8)
- SetEvent (Address: 0x100281c8)
- WaitForSingleObject (Address: 0x10028188)
- WaitForSingleObjectEx (Address: 0x100281a4)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x100281dc)
- Sleep (Address: 0x100281d8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x100281e8)
- GetTickCount (Address: 0x100281e4)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- QueueUserWorkItem (Address: 0x100281f0)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x100281f8)
api-ms-win-core-winrt-error-l1-1-0.dll
- RoOriginateError (Address: 0x10028200)
- RoTransformError (Address: 0x10028204)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateString (Address: 0x1002820c)
api-ms-win-eventing-provider-l1-1-0.dll
- EventProviderEnabled (Address: 0x1002821c)
- EventRegister (Address: 0x10028214)
- EventSetInformation (Address: 0x10028224)
- EventUnregister (Address: 0x10028220)
- EventWriteTransfer (Address: 0x10028218)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x10028230)
- GetLengthSid (Address: 0x10028234)
- GetTokenInformation (Address: 0x1002823c)
- IsValidSecurityDescriptor (Address: 0x10028238)
- IsValidSid (Address: 0x1002822c)
api-ms-win-shcore-stream-l1-1-0.dll
- IStream_Read (Address: 0x10028244)
- IStream_Reset (Address: 0x10028254)
- IStream_Size (Address: 0x10028250)
- IStream_Write (Address: 0x1002824c)
- SHCreateMemStream (Address: 0x10028248)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x10028264)
- __dllonexit (Address: 0x10028270)
- _amsg_exit (Address: 0x10028288)
- _callnewh (Address: 0x10028290)
- _except_handler4_common (Address: 0x10028260)
- _initterm (Address: 0x10028284)
- _lock (Address: 0x10028278)
- _onexit (Address: 0x100282a8)
- _purecall (Address: 0x100282a4)
- _unlock (Address: 0x10028274)
- _vsnwprintf (Address: 0x10028280)
- _XcptFilter (Address: 0x1002828c)
- free (Address: 0x10028298)
- malloc (Address: 0x1002829c)
- memcpy (Address: 0x1002827c)
- memcpy_s (Address: 0x1002826c)
- memmove (Address: 0x1002825c)
- memmove_s (Address: 0x100282a0)
- memset (Address: 0x100282ac)
- realloc (Address: 0x10028294)
- toupper (Address: 0x10028268)
ntdll.dll
- EtwEventEnabled (Address: 0x100282bc)
- EtwEventRegister (Address: 0x100282d4)
- EtwEventUnregister (Address: 0x100282c8)
- EtwEventWrite (Address: 0x100282b8)
- RtlAcquireSRWLockExclusive (Address: 0x100282d0)
- RtlAcquireSRWLockShared (Address: 0x100282cc)
- RtlAllocateHeap (Address: 0x100282c0)
- RtlDeleteCriticalSection (Address: 0x100282dc)
- RtlEnterCriticalSection (Address: 0x100282ec)
- RtlFreeHeap (Address: 0x100282f0)
- RtlInitializeCriticalSection (Address: 0x100282e4)
- RtlLeaveCriticalSection (Address: 0x100282e8)
- RtlReleaseSRWLockExclusive (Address: 0x100282c4)
- RtlReleaseSRWLockShared (Address: 0x100282b4)
- RtlTryEnterCriticalSection (Address: 0x100282e0)
- WinSqmIncrementDWORD (Address: 0x100282d8)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x1002801c)
- NdrClientCall4 (Address: 0x10028028)
- NdrServerCall2 (Address: 0x10028020)
- RpcBindingFromStringBindingW (Address: 0x10028018)
- RpcBindingSetAuthInfoExW (Address: 0x10028014)
- RpcBindingVectorFree (Address: 0x10028010)
- RpcEpRegisterW (Address: 0x1002802c)
- RpcEpUnregister (Address: 0x1002800c)
- RpcImpersonateClient (Address: 0x10028008)
- RpcRevertToSelf (Address: 0x10028004)
- RpcServerInqBindings (Address: 0x10028038)
- RpcServerInqCallAttributesW (Address: 0x10028044)
- RpcServerRegisterIf3 (Address: 0x10028034)
- RpcServerUnregisterIf (Address: 0x10028040)
- RpcServerUseProtseqW (Address: 0x1002803c)
- RpcStringBindingComposeW (Address: 0x10028024)
- RpcStringFreeW (Address: 0x10028000)
- UuidFromStringW (Address: 0x10028030)