winrnr.dll

Description: LDAP RnR Provider DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: 4a873b59b5318526887422345f916309

File Size: 33.5 KB

Uploaded At: Dec. 1, 2025, 8:07 a.m.

Views: 13

Exported Functions

  • InstallNTDSProvider (Ordinal: 1, Address: 0x45c0)
  • NSPStartup (Ordinal: 2, Address: 0x1d10)
  • RemoveNTDSProvider (Ordinal: 3, Address: 0x5e40)

Imported DLLs & Functions

api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x5c80a000)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x5c80a008)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x5c80a010)
  • SetLastError (Address: 0x5c80a014)
  • SetUnhandledExceptionFilter (Address: 0x5c80a01c)
  • UnhandledExceptionFilter (Address: 0x5c80a018)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x5c80a028)
  • HeapAlloc (Address: 0x5c80a024)
  • HeapFree (Address: 0x5c80a02c)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x5c80a034)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x5c80a040)
  • GetCurrentProcessId (Address: 0x5c80a044)
  • GetCurrentThreadId (Address: 0x5c80a048)
  • TerminateProcess (Address: 0x5c80a054)
  • TlsAlloc (Address: 0x5c80a03c)
  • TlsFree (Address: 0x5c80a050)
  • TlsGetValue (Address: 0x5c80a04c)
  • TlsSetValue (Address: 0x5c80a058)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x5c80a060)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x5c80a068)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x5c80a074)
  • GetTickCount (Address: 0x5c80a070)
msvcrt.dll
  • _amsg_exit (Address: 0x5c80a090)
  • _except_handler4_common (Address: 0x5c80a07c)
  • _initterm (Address: 0x5c80a080)
  • _XcptFilter (Address: 0x5c80a094)
  • free (Address: 0x5c80a08c)
  • malloc (Address: 0x5c80a088)
  • memcpy (Address: 0x5c80a098)
  • memset (Address: 0x5c80a09c)
  • wcschr (Address: 0x5c80a084)
ntdll.dll
  • EtwGetTraceEnableFlags (Address: 0x5c80a0a8)
  • EtwGetTraceEnableLevel (Address: 0x5c80a0b0)
  • EtwGetTraceLoggerHandle (Address: 0x5c80a0ac)
  • EtwRegisterTraceGuidsW (Address: 0x5c80a0b4)
  • EtwTraceMessageVa (Address: 0x5c80a0b8)
  • EtwUnregisterTraceGuids (Address: 0x5c80a0a4)