OSProvider.dll
Description: DISM OS Services Provider
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 32-bit
Operating System: Windows NT
SHA256: ac2c152a6f32046bec517651c4de784d
File Size: 114.9 KB
Uploaded At: Dec. 1, 2025, 8:09 a.m.
Views: 17
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DLLGetDISMProviderCLSID (Ordinal: 1, Address: 0x8020)
- DllCanUnloadNow (Ordinal: 2, Address: 0x8050)
- DllGetClassObject (Ordinal: 3, Address: 0x8080)
- DllRegisterServer (Ordinal: 4, Address: 0x80b0)
- DllUnregisterServer (Ordinal: 5, Address: 0x80f0)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x10019014)
- LookupPrivilegeValueW (Address: 0x10019018)
- OpenProcessToken (Address: 0x1001901c)
- RegCloseKey (Address: 0x1001902c)
- RegCreateKeyExW (Address: 0x10019000)
- RegFlushKey (Address: 0x10019008)
- RegLoadKeyW (Address: 0x10019010)
- RegOpenKeyExW (Address: 0x10019024)
- RegQueryInfoKeyW (Address: 0x10019028)
- RegQueryValueExW (Address: 0x10019020)
- RegSetValueExW (Address: 0x10019004)
- RegUnLoadKeyW (Address: 0x1001900c)
KERNEL32.dll
- CloseHandle (Address: 0x10019088)
- CreateFileMappingW (Address: 0x10019108)
- CreateFileW (Address: 0x100190dc)
- DeleteCriticalSection (Address: 0x10019040)
- DisableThreadLibraryCalls (Address: 0x10019034)
- EnterCriticalSection (Address: 0x10019060)
- FindResourceExW (Address: 0x100190a4)
- FormatMessageW (Address: 0x100190e8)
- FreeLibrary (Address: 0x10019090)
- GetCurrentProcess (Address: 0x10019084)
- GetCurrentProcessId (Address: 0x10019070)
- GetCurrentThreadId (Address: 0x1001906c)
- GetEnvironmentVariableW (Address: 0x10019094)
- GetFileAttributesW (Address: 0x100190fc)
- GetFileInformationByHandle (Address: 0x100190e4)
- GetFullPathNameW (Address: 0x100190d8)
- GetLastError (Address: 0x10019048)
- GetModuleFileNameW (Address: 0x1001904c)
- GetModuleHandleExW (Address: 0x10019114)
- GetModuleHandleW (Address: 0x10019058)
- GetProcAddress (Address: 0x10019050)
- GetProcessHeap (Address: 0x100190b8)
- GetSystemInfo (Address: 0x10019118)
- GetSystemTimeAsFileTime (Address: 0x100190d0)
- GetSystemWindowsDirectoryW (Address: 0x10019100)
- GetThreadLocale (Address: 0x10019038)
- GetTickCount (Address: 0x100190d4)
- GetVersionExW (Address: 0x100190f8)
- HeapAlloc (Address: 0x100190b4)
- HeapDestroy (Address: 0x100190bc)
- HeapFree (Address: 0x100190b0)
- HeapReAlloc (Address: 0x100190ac)
- HeapSize (Address: 0x100190a8)
- InitializeCriticalSection (Address: 0x1001905c)
- LeaveCriticalSection (Address: 0x10019064)
- LoadLibraryExW (Address: 0x10019054)
- LoadResource (Address: 0x100190a0)
- LocalFree (Address: 0x100190e0)
- LockResource (Address: 0x1001909c)
- MapViewOfFile (Address: 0x10019104)
- MultiByteToWideChar (Address: 0x10019074)
- OpenProcess (Address: 0x10019080)
- OutputDebugStringW (Address: 0x10019078)
- QueryPerformanceCounter (Address: 0x100190cc)
- RaiseException (Address: 0x10019044)
- ReadFile (Address: 0x100190ec)
- SearchPathW (Address: 0x10019110)
- SetEnvironmentVariableW (Address: 0x1001908c)
- SetFilePointer (Address: 0x100190f0)
- SetLastError (Address: 0x100190f4)
- SetThreadLocale (Address: 0x1001903c)
- SetThreadUILanguage (Address: 0x10019068)
- SetUnhandledExceptionFilter (Address: 0x100190c4)
- SizeofResource (Address: 0x10019098)
- Sleep (Address: 0x1001907c)
- TerminateProcess (Address: 0x100190c8)
- UnhandledExceptionFilter (Address: 0x100190c0)
- UnmapViewOfFile (Address: 0x1001910c)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x1001921c)
- __dllonexit (Address: 0x100191b0)
- _amsg_exit (Address: 0x100191c8)
- _callnewh (Address: 0x100191d4)
- _CxxThrowException (Address: 0x100191d0)
- _except_handler4_common (Address: 0x100191bc)
- _initterm (Address: 0x100191c4)
- _lock (Address: 0x100191b8)
- _onexit (Address: 0x100191ac)
- _purecall (Address: 0x100191f4)
- _unlock (Address: 0x100191b4)
- _vscwprintf (Address: 0x10019204)
- _vsnwprintf (Address: 0x10019198)
- _wcsicmp (Address: 0x10019208)
- _wcslwr_s (Address: 0x100191fc)
- _wcsnicmp (Address: 0x10019190)
- _XcptFilter (Address: 0x100191cc)
- ??0exception@@QAE@ABV0@@Z (Address: 0x100191e0)
- ??0exception@@QAE@XZ (Address: 0x100191e4)
- ??1exception@@UAE@XZ (Address: 0x100191dc)
- ??1type_info@@UAE@XZ (Address: 0x100191a8)
- ?terminate@@YAXXZ (Address: 0x100191c0)
- ?what@exception@@UBEPBDXZ (Address: 0x100191d8)
- free (Address: 0x10019214)
- malloc (Address: 0x100191e8)
- memcmp (Address: 0x100191a0)
- memcpy (Address: 0x100191a4)
- memcpy_s (Address: 0x100191f0)
- memmove_s (Address: 0x100191ec)
- memset (Address: 0x1001919c)
- towupper (Address: 0x10019184)
- vswprintf_s (Address: 0x10019200)
- wcscat_s (Address: 0x10019210)
- wcschr (Address: 0x10019188)
- wcscpy_s (Address: 0x10019218)
- wcsncmp (Address: 0x10019194)
- wcsncpy_s (Address: 0x1001920c)
- wcsrchr (Address: 0x1001918c)
- wcsstr (Address: 0x100191f8)
ntdll.dll
- NtQueryInformationProcess (Address: 0x1001922c)
- NtQueryOpenSubKeysEx (Address: 0x10019230)
- NtUnloadKey2 (Address: 0x10019228)
- RtlAllocateHeap (Address: 0x10019224)
- RtlFreeHeap (Address: 0x10019238)
- RtlInitUnicodeString (Address: 0x10019234)
OLE32.dll
- CoCreateInstance (Address: 0x10019128)
- CoTaskMemFree (Address: 0x10019120)
- ProgIDFromCLSID (Address: 0x10019124)
- StringFromGUID2 (Address: 0x1001912c)
OLEAUT32.dll
- CreateErrorInfo (Address: 0x1001915c)
- LoadRegTypeLib (Address: 0x10019138)
- LoadTypeLib (Address: 0x1001914c)
- RegisterTypeLib (Address: 0x10019150)
- SetErrorInfo (Address: 0x1001913c)
- SysAllocString (Address: 0x10019148)
- SysAllocStringByteLen (Address: 0x10019134)
- SysAllocStringLen (Address: 0x10019158)
- SysFreeString (Address: 0x10019140)
- SysStringByteLen (Address: 0x10019160)
- SysStringLen (Address: 0x10019154)
- UnRegisterTypeLib (Address: 0x10019144)
USER32.dll
- CharNextW (Address: 0x1001916c)
- LoadStringW (Address: 0x10019168)
VERSION.dll
- GetFileVersionInfoExW (Address: 0x10019178)
- GetFileVersionInfoSizeExW (Address: 0x10019174)
- VerQueryValueW (Address: 0x1001917c)