userinitext.dll

Description: UserInit Utility Extension DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: a1d7468e803e3d3ad06b8e8777ab402b

File Size: 21.0 KB

Uploaded At: Dec. 1, 2025, 8:05 a.m.

Views: 12

Exported Functions

  • CreateExplorerSessionKey (Ordinal: 1, Address: 0x3980)
  • DisplayMessageAndExitWindows (Ordinal: 2, Address: 0x27f0)
  • ImmWorker (Ordinal: 3, Address: 0x36a0)
  • IsSubDesktopSession (Ordinal: 4, Address: 0x2c40)
  • IsTSAppCompatOn (Ordinal: 5, Address: 0x3890)
  • LoadRemoteFontsAndInitMiscWorker (Ordinal: 6, Address: 0x2ba0)
  • PerformXForestLogonCheck (Ordinal: 7, Address: 0x2820)
  • ProcesRemoteSessionInitialCommand (Ordinal: 8, Address: 0x32b0)
  • ProcessTermSrvIniFiles (Ordinal: 9, Address: 0x3910)
  • SetShellDesktopSwitchEvent (Ordinal: 10, Address: 0x2cb0)
  • SetupHotKeyForKeyboardLayout (Ordinal: 11, Address: 0x3710)
  • UserinitExt (Ordinal: 12, Address: 0x3a50)

Imported DLLs & Functions

api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x10006024)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1000602c)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1000603c)
  • SetLastError (Address: 0x10006040)
  • SetUnhandledExceptionFilter (Address: 0x10006038)
  • UnhandledExceptionFilter (Address: 0x10006034)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x10006048)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x10006050)
  • LocalFree (Address: 0x10006054)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x10006068)
  • GetModuleFileNameA (Address: 0x10006060)
  • GetProcAddress (Address: 0x10006064)
  • LoadLibraryExW (Address: 0x1000606c)
  • LoadStringW (Address: 0x1000605c)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x10006078)
  • GetUserDefaultLangID (Address: 0x10006074)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x10006080)
  • SetCurrentDirectoryW (Address: 0x10006084)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x10006098)
  • GetCurrentProcess (Address: 0x10006090)
  • OpenProcessToken (Address: 0x1000608c)
  • TerminateProcess (Address: 0x10006094)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x100060a4)
  • RegCreateKeyExW (Address: 0x100060b0)
  • RegDeleteTreeW (Address: 0x100060b8)
  • RegGetValueW (Address: 0x100060a8)
  • RegOpenKeyExW (Address: 0x100060ac)
  • RegQueryValueExW (Address: 0x100060a0)
  • RegSetValueExW (Address: 0x100060b4)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x100060c8)
  • CreateEventW (Address: 0x100060c4)
  • OpenEventW (Address: 0x100060cc)
  • ReleaseSRWLockExclusive (Address: 0x100060c0)
  • SetEvent (Address: 0x100060d4)
  • WaitForSingleObject (Address: 0x100060d0)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x100060dc)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetTickCount (Address: 0x100060e8)
  • GetTickCount64 (Address: 0x100060e4)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x100060fc)
  • EventRegister (Address: 0x100060f4)
  • EventSetInformation (Address: 0x100060f8)
  • EventUnregister (Address: 0x100060f0)
  • EventWriteTransfer (Address: 0x10006100)
msvcrt.dll
  • _vsnwprintf (Address: 0x10006110)
  • memmove (Address: 0x10006108)
  • memset (Address: 0x10006114)
  • toupper (Address: 0x1000610c)
ntdll.dll
  • DbgPrint (Address: 0x10006128)
  • NtClose (Address: 0x10006124)
  • NtOpenKey (Address: 0x10006120)
  • RtlInitUnicodeString (Address: 0x1000611c)
USER32.dll
  • ExitWindowsEx (Address: 0x1000600c)
  • GetKeyboardLayout (Address: 0x10006010)
  • GetSystemMetrics (Address: 0x10006008)
  • LoadRemoteFonts (Address: 0x10006004)
  • MessageBoxW (Address: 0x10006000)
  • SystemParametersInfoW (Address: 0x10006014)
USERENV.dll
  • (Address: 0x1000601c)