SettingSyncCore.dll
Description: Setting Synchronization Core
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 32-bit
Operating System: Windows NT
SHA256: 253076d7bacfa8fea1bd00632f5e835d
File Size: 746.0 KB
Uploaded At: Dec. 1, 2025, 8:04 a.m.
Views: 15
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x1e5d0)
- DllGetActivationFactory (Ordinal: 2, Address: 0x1e620)
- DllGetClassObject (Ordinal: 3, Address: 0x1e600)
Imported DLLs & Functions
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1009f024)
- IsDebuggerPresent (Address: 0x1009f028)
- OutputDebugStringW (Address: 0x1009f02c)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1009f034)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1009f03c)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1009f044)
- RaiseException (Address: 0x1009f04c)
- SetLastError (Address: 0x1009f050)
- SetUnhandledExceptionFilter (Address: 0x1009f054)
- UnhandledExceptionFilter (Address: 0x1009f048)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x1009f08c)
- CreateDirectoryW (Address: 0x1009f078)
- CreateFileW (Address: 0x1009f090)
- DeleteFileW (Address: 0x1009f060)
- FindClose (Address: 0x1009f07c)
- FindFirstFileW (Address: 0x1009f094)
- FindNextFileW (Address: 0x1009f074)
- GetDriveTypeW (Address: 0x1009f06c)
- GetFileAttributesExW (Address: 0x1009f088)
- GetFileAttributesW (Address: 0x1009f080)
- GetFileTime (Address: 0x1009f070)
- GetFullPathNameW (Address: 0x1009f098)
- GetTempFileNameW (Address: 0x1009f05c)
- RemoveDirectoryW (Address: 0x1009f068)
- SetFileAttributesW (Address: 0x1009f064)
- SetFileTime (Address: 0x1009f084)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x1009f0a0)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x1009f0a8)
- CreateHardLinkW (Address: 0x1009f0b4)
- GetFileInformationByHandleEx (Address: 0x1009f0b8)
- MoveFileExW (Address: 0x1009f0ac)
- ReadDirectoryChangesW (Address: 0x1009f0b0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1009f0c0)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1009f0cc)
- HeapAlloc (Address: 0x1009f0c8)
- HeapFree (Address: 0x1009f0d0)
- HeapReAlloc (Address: 0x1009f0d4)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1009f0dc)
- LocalFree (Address: 0x1009f0e0)
- LocalReAlloc (Address: 0x1009f0e4)
api-ms-win-core-io-l1-1-0.dll
- CancelIoEx (Address: 0x1009f0f0)
- DeviceIoControl (Address: 0x1009f0ec)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
- VerifyVersionInfoW (Address: 0x1009f0f8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1009f104)
- FindStringOrdinal (Address: 0x1009f108)
- GetModuleFileNameA (Address: 0x1009f110)
- GetModuleHandleExW (Address: 0x1009f10c)
- GetModuleHandleW (Address: 0x1009f100)
- GetProcAddress (Address: 0x1009f114)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1009f11c)
- LCMapStringEx (Address: 0x1009f120)
api-ms-win-core-path-l1-1-0.dll
- PathAllocCanonicalize (Address: 0x1009f128)
- PathAllocCombine (Address: 0x1009f134)
- PathCchAppend (Address: 0x1009f12c)
- PathCchCombine (Address: 0x1009f130)
- PathCchRemoveFileSpec (Address: 0x1009f138)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x1009f140)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1009f148)
- GetCurrentProcessId (Address: 0x1009f164)
- GetCurrentThread (Address: 0x1009f158)
- GetCurrentThreadId (Address: 0x1009f15c)
- OpenProcessToken (Address: 0x1009f150)
- OpenThreadToken (Address: 0x1009f160)
- ProcessIdToSessionId (Address: 0x1009f154)
- TerminateProcess (Address: 0x1009f14c)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x1009f16c)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1009f174)
api-ms-win-core-psapi-l1-1-0.dll
- QueryFullProcessImageNameW (Address: 0x1009f17c)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1009f1b0)
- RegCreateKeyExW (Address: 0x1009f1a8)
- RegDeleteTreeW (Address: 0x1009f190)
- RegDeleteValueW (Address: 0x1009f18c)
- RegEnumKeyExW (Address: 0x1009f1b4)
- RegEnumValueW (Address: 0x1009f19c)
- RegGetValueW (Address: 0x1009f194)
- RegNotifyChangeKeyValue (Address: 0x1009f198)
- RegOpenCurrentUser (Address: 0x1009f188)
- RegOpenKeyExW (Address: 0x1009f184)
- RegQueryInfoKeyW (Address: 0x1009f1a4)
- RegQueryValueExW (Address: 0x1009f1a0)
- RegSetValueExW (Address: 0x1009f1ac)
api-ms-win-core-registry-l1-1-1.dll
- RegDeleteKeyValueW (Address: 0x1009f1bc)
api-ms-win-core-registry-l2-1-0.dll
- RegDeleteKeyW (Address: 0x1009f1c4)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFileExistsW (Address: 0x1009f1e0)
- PathFindExtensionW (Address: 0x1009f1d8)
- PathFindFileNameW (Address: 0x1009f1cc)
- PathGetCharTypeW (Address: 0x1009f1dc)
- PathGetDriveNumberW (Address: 0x1009f1d4)
- PathIsUNCW (Address: 0x1009f1e4)
- PathRemoveFileSpecW (Address: 0x1009f1e8)
- PathStripPathW (Address: 0x1009f1d0)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- QISearch (Address: 0x1009f1f8)
- StrRChrW (Address: 0x1009f1f0)
- StrToIntExW (Address: 0x1009f1f4)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1009f200)
api-ms-win-core-string-l2-1-0.dll
- CharLowerBuffW (Address: 0x1009f208)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1009f224)
- AcquireSRWLockShared (Address: 0x1009f258)
- CreateEventExW (Address: 0x1009f254)
- CreateMutexExW (Address: 0x1009f21c)
- CreateSemaphoreExW (Address: 0x1009f238)
- DeleteCriticalSection (Address: 0x1009f244)
- EnterCriticalSection (Address: 0x1009f24c)
- InitializeCriticalSectionEx (Address: 0x1009f240)
- InitializeSRWLock (Address: 0x1009f234)
- LeaveCriticalSection (Address: 0x1009f248)
- OpenEventW (Address: 0x1009f25c)
- OpenSemaphoreW (Address: 0x1009f220)
- ReleaseMutex (Address: 0x1009f228)
- ReleaseSemaphore (Address: 0x1009f230)
- ReleaseSRWLockExclusive (Address: 0x1009f210)
- ReleaseSRWLockShared (Address: 0x1009f250)
- SetEvent (Address: 0x1009f214)
- TryAcquireSRWLockExclusive (Address: 0x1009f218)
- WaitForSingleObject (Address: 0x1009f22c)
- WaitForSingleObjectEx (Address: 0x1009f23c)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1009f264)
- InitOnceComplete (Address: 0x1009f268)
- InitOnceExecuteOnce (Address: 0x1009f270)
- Sleep (Address: 0x1009f26c)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTime (Address: 0x1009f280)
- GetSystemTimeAsFileTime (Address: 0x1009f27c)
- GetTickCount (Address: 0x1009f278)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetOsSafeBootMode (Address: 0x1009f288)
- VerSetConditionMask (Address: 0x1009f28c)
api-ms-win-core-threadpool-l1-2-0.dll
- CancelThreadpoolIo (Address: 0x1009f2ac)
- CloseThreadpoolIo (Address: 0x1009f2c4)
- CloseThreadpoolTimer (Address: 0x1009f29c)
- CloseThreadpoolWait (Address: 0x1009f2c0)
- CreateThreadpoolIo (Address: 0x1009f2bc)
- CreateThreadpoolTimer (Address: 0x1009f2a0)
- CreateThreadpoolWait (Address: 0x1009f2a8)
- DisassociateCurrentThreadFromCallback (Address: 0x1009f2b4)
- SetThreadpoolTimer (Address: 0x1009f298)
- SetThreadpoolWait (Address: 0x1009f2b0)
- StartThreadpoolIo (Address: 0x1009f2a4)
- WaitForThreadpoolIoCallbacks (Address: 0x1009f2c8)
- WaitForThreadpoolTimerCallbacks (Address: 0x1009f294)
- WaitForThreadpoolWaitCallbacks (Address: 0x1009f2b8)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x1009f2d0)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1009f2d8)
- EncodePointer (Address: 0x1009f2dc)
api-ms-win-core-version-l1-1-0.dll
- GetFileVersionInfoExW (Address: 0x1009f2e4)
- GetFileVersionInfoSizeExW (Address: 0x1009f2ec)
- VerQueryValueW (Address: 0x1009f2e8)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x1009f2f8)
- RoOriginateError (Address: 0x1009f2fc)
- RoOriginateErrorW (Address: 0x1009f304)
- RoTransformError (Address: 0x1009f300)
- SetRestrictedErrorInfo (Address: 0x1009f2f4)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x1009f310)
- RoGetMatchingRestrictedErrorInfo (Address: 0x1009f314)
- RoReportFailedDelegate (Address: 0x1009f30c)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x1009f320)
- RoGetActivationFactory (Address: 0x1009f31c)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCompareStringOrdinal (Address: 0x1009f338)
- WindowsCreateString (Address: 0x1009f344)
- WindowsCreateStringReference (Address: 0x1009f33c)
- WindowsDeleteString (Address: 0x1009f328)
- WindowsDuplicateString (Address: 0x1009f334)
- WindowsGetStringRawBuffer (Address: 0x1009f330)
- WindowsIsStringEmpty (Address: 0x1009f340)
- WindowsStringHasEmbeddedNull (Address: 0x1009f32c)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x1009f34c)
- GetTraceEnableLevel (Address: 0x1009f358)
- GetTraceLoggerHandle (Address: 0x1009f35c)
- RegisterTraceGuidsW (Address: 0x1009f360)
- TraceMessage (Address: 0x1009f354)
- UnregisterTraceGuids (Address: 0x1009f350)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1009f374)
- EventRegister (Address: 0x1009f36c)
- EventSetInformation (Address: 0x1009f378)
- EventUnregister (Address: 0x1009f370)
- EventWriteTransfer (Address: 0x1009f368)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAceEx (Address: 0x1009f390)
- AddAccessDeniedAceEx (Address: 0x1009f38c)
- AddAce (Address: 0x1009f3b0)
- CopySid (Address: 0x1009f388)
- DeleteAce (Address: 0x1009f3ac)
- EqualSid (Address: 0x1009f398)
- GetAce (Address: 0x1009f3a4)
- GetAclInformation (Address: 0x1009f3a8)
- GetLengthSid (Address: 0x1009f39c)
- GetSecurityDescriptorControl (Address: 0x1009f394)
- GetSecurityDescriptorSacl (Address: 0x1009f3a0)
- GetTokenInformation (Address: 0x1009f380)
- InitializeAcl (Address: 0x1009f3b4)
- IsValidSid (Address: 0x1009f384)
api-ms-win-security-cryptoapi-l1-1-0.dll
- CryptAcquireContextW (Address: 0x1009f3c8)
- CryptCreateHash (Address: 0x1009f3c4)
- CryptDestroyHash (Address: 0x1009f3bc)
- CryptGetHashParam (Address: 0x1009f3d0)
- CryptHashData (Address: 0x1009f3cc)
- CryptReleaseContext (Address: 0x1009f3c0)
api-ms-win-shcore-obsolete-l1-1-0.dll
- SHStrDupW (Address: 0x1009f3d8)
api-ms-win-shcore-registry-l1-1-0.dll
- SHDeleteValueW (Address: 0x1009f3e4)
- SHGetValueW (Address: 0x1009f3e8)
- SHRegGetValueW (Address: 0x1009f3ec)
- SHSetValueW (Address: 0x1009f3e0)
api-ms-win-shcore-stream-l1-1-0.dll
- IStream_Copy (Address: 0x1009f3fc)
- IStream_Read (Address: 0x1009f404)
- IStream_Reset (Address: 0x1009f400)
- IStream_Size (Address: 0x1009f3f8)
- IStream_Write (Address: 0x1009f408)
- SHCreateMemStream (Address: 0x1009f3f4)
- SHCreateStreamOnFileEx (Address: 0x1009f40c)
api-ms-win-shcore-sysinfo-l1-1-0.dll
- IsOS (Address: 0x1009f414)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolAllowThreadReuse (Address: 0x1009f420)
- SHTaskPoolQueueTask (Address: 0x1009f41c)
api-ms-win-shell-shdirectory-l1-1-0.dll
- (Address: 0x1009f428)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1009f438)
- BCryptCreateHash (Address: 0x1009f440)
- BCryptDestroyHash (Address: 0x1009f434)
- BCryptFinishHash (Address: 0x1009f448)
- BCryptGetProperty (Address: 0x1009f444)
- BCryptHashData (Address: 0x1009f43c)
- BCryptOpenAlgorithmProvider (Address: 0x1009f430)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x1009f4cc)
- __dllonexit (Address: 0x1009f470)
- _amsg_exit (Address: 0x1009f488)
- _CxxThrowException (Address: 0x1009f4e4)
- _except_handler4_common (Address: 0x1009f454)
- _ftol2 (Address: 0x1009f4d0)
- _get_errno (Address: 0x1009f4bc)
- _initterm (Address: 0x1009f47c)
- _lock (Address: 0x1009f478)
- _onexit (Address: 0x1009f46c)
- _purecall (Address: 0x1009f4a8)
- _set_errno (Address: 0x1009f4c0)
- _unlock (Address: 0x1009f474)
- _vsnprintf_s (Address: 0x1009f490)
- _vsnwprintf (Address: 0x1009f4d4)
- _wcsicmp (Address: 0x1009f460)
- _XcptFilter (Address: 0x1009f48c)
- ??0exception@@QAE@ABQBD@Z (Address: 0x1009f4d8)
- ??0exception@@QAE@ABQBDH@Z (Address: 0x1009f4dc)
- ??0exception@@QAE@ABV0@@Z (Address: 0x1009f494)
- ??0exception@@QAE@XZ (Address: 0x1009f49c)
- ??1exception@@UAE@XZ (Address: 0x1009f4a4)
- ??1type_info@@UAE@XZ (Address: 0x1009f458)
- ?terminate@@YAXXZ (Address: 0x1009f468)
- ?what@exception@@UBEPBDXZ (Address: 0x1009f4e0)
- free (Address: 0x1009f4f0)
- iswalnum (Address: 0x1009f484)
- malloc (Address: 0x1009f480)
- memcmp (Address: 0x1009f450)
- memcpy (Address: 0x1009f4e8)
- memcpy_s (Address: 0x1009f4b8)
- memmove (Address: 0x1009f4ec)
- memmove_s (Address: 0x1009f4b4)
- memset (Address: 0x1009f4f4)
- realloc (Address: 0x1009f4b0)
- swscanf_s (Address: 0x1009f4c8)
- wcschr (Address: 0x1009f498)
- wcsncmp (Address: 0x1009f4a0)
- wcsncpy_s (Address: 0x1009f45c)
- wcsrchr (Address: 0x1009f464)
- wcsstr (Address: 0x1009f4c4)
- wcstok_s (Address: 0x1009f4ac)
ntdll.dll
- EtwEventWriteTransfer (Address: 0x1009f540)
- NtCreateWnfStateName (Address: 0x1009f52c)
- NtDeleteWnfStateName (Address: 0x1009f524)
- NtQueryWnfStateData (Address: 0x1009f510)
- NtSetInformationFile (Address: 0x1009f50c)
- RtlAcquireResourceExclusive (Address: 0x1009f508)
- RtlAcquireResourceShared (Address: 0x1009f4fc)
- RtlAllocateHeap (Address: 0x1009f518)
- RtlComputeCrc32 (Address: 0x1009f520)
- RtlConvertSidToUnicodeString (Address: 0x1009f514)
- RtlDeleteResource (Address: 0x1009f500)
- RtlFreeHeap (Address: 0x1009f51c)
- RtlFreeUnicodeString (Address: 0x1009f53c)
- RtlInitializeResource (Address: 0x1009f504)
- RtlMapGenericMask (Address: 0x1009f538)
- RtlNtStatusToDosError (Address: 0x1009f530)
- RtlReleaseResource (Address: 0x1009f544)
- RtlSubscribeWnfStateChangeNotification (Address: 0x1009f528)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1009f534)
policymanager.dll
- PolicyManager_GetPolicyInt (Address: 0x1009f54c)
profapi.dll
- (Address: 0x1009f554)
SHCORE.dll
- (Address: 0x1009f004)
- (Address: 0x1009f000)
- (Address: 0x1009f008)
UMPDC.dll
- Pdcv2ActivationClientActivate (Address: 0x1009f010)
- Pdcv2ActivationClientDeactivate (Address: 0x1009f01c)
- Pdcv2ActivationClientRegister (Address: 0x1009f014)
- Pdcv2ActivationClientUnregister (Address: 0x1009f018)