ftpsvc.dll
Description: Protocol Handler for FTPSVC
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: 00d5bb7b08c21b8cdd376e2d91e1c060
File Size: 421.0 KB
Uploaded At: Dec. 1, 2025, 8:12 a.m.
Views: 12
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- ServiceMain (Ordinal: 1, Address: 0x51c0)
- DllRegisterServer (Ordinal: 2, Address: 0x18110)
- DllUnregisterServer (Ordinal: 3, Address: 0x188e0)
Imported DLLs & Functions
ADVAPI32.dll
- AddAccessAllowedAce (Address: 0x18004e9d8)
- CheckTokenMembership (Address: 0x18004e9b8)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18004e9c0)
- CreateWellKnownSid (Address: 0x18004ea00)
- CryptAcquireContextW (Address: 0x18004ead0)
- CryptCreateHash (Address: 0x18004eac0)
- CryptDestroyHash (Address: 0x18004eaa8)
- CryptGetHashParam (Address: 0x18004eab0)
- CryptGetProvParam (Address: 0x18004e9e8)
- CryptHashData (Address: 0x18004eab8)
- CryptReleaseContext (Address: 0x18004eac8)
- DuplicateTokenEx (Address: 0x18004eae0)
- EqualSid (Address: 0x18004e9b0)
- EventRegister (Address: 0x18004ea98)
- EventSetInformation (Address: 0x18004eaa0)
- EventUnregister (Address: 0x18004ea90)
- EventWriteTransfer (Address: 0x18004ea88)
- GetLengthSid (Address: 0x18004e9c8)
- GetTokenInformation (Address: 0x18004e990)
- GetTraceLoggerHandle (Address: 0x18004ea78)
- ImpersonateLoggedOnUser (Address: 0x18004ead8)
- InitializeAcl (Address: 0x18004e9d0)
- InitializeSecurityDescriptor (Address: 0x18004ea60)
- LogonUserExW (Address: 0x18004e9a0)
- LookupAccountNameW (Address: 0x18004e9a8)
- MakeSelfRelativeSD (Address: 0x18004e9e0)
- OpenProcessToken (Address: 0x18004e998)
- RegCloseKey (Address: 0x18004ea38)
- RegCreateKeyExW (Address: 0x18004eaf8)
- RegDeleteKeyW (Address: 0x18004eae8)
- RegisterServiceCtrlHandlerExW (Address: 0x18004ea40)
- RegisterTraceGuidsW (Address: 0x18004ea70)
- RegOpenKeyExA (Address: 0x18004e9f0)
- RegOpenKeyExW (Address: 0x18004ea28)
- RegOpenKeyW (Address: 0x18004ea50)
- RegQueryValueExA (Address: 0x18004e9f8)
- RegQueryValueExW (Address: 0x18004ea30)
- RegSetValueExW (Address: 0x18004eaf0)
- RevertToSelf (Address: 0x18004ea80)
- SetEntriesInAclW (Address: 0x18004ea08)
- SetSecurityDescriptorDacl (Address: 0x18004ea20)
- SetSecurityDescriptorGroup (Address: 0x18004ea18)
- SetSecurityDescriptorOwner (Address: 0x18004ea10)
- SetServiceStatus (Address: 0x18004ea48)
- SetThreadToken (Address: 0x18004ea58)
- TraceEvent (Address: 0x18004ea68)
- UnregisterTraceGuids (Address: 0x18004e988)
CRYPT32.dll
- CertCloseStore (Address: 0x18004eb60)
- CertControlStore (Address: 0x18004eb68)
- CertDuplicateCertificateContext (Address: 0x18004eb10)
- CertFindCertificateInStore (Address: 0x18004eb28)
- CertFreeCertificateChain (Address: 0x18004eb48)
- CertFreeCertificateContext (Address: 0x18004eb18)
- CertGetCertificateChain (Address: 0x18004eb20)
- CertGetCertificateContextProperty (Address: 0x18004eb08)
- CertGetPublicKeyLength (Address: 0x18004eb50)
- CertNameToStrA (Address: 0x18004eb30)
- CertNameToStrW (Address: 0x18004eb58)
- CertOpenStore (Address: 0x18004eb70)
- CertVerifyCertificateChainPolicy (Address: 0x18004eb40)
- CryptAcquireCertificatePrivateKey (Address: 0x18004eb38)
iisutil.dll
- ??0ALLOC_CACHE_HANDLER@@QEAA@PEBDPEBUALLOC_CACHE_CONFIGURATION@@H@Z (Address: 0x18004f190)
- ??0BUFFER@@QEAA@PEAEK@Z (Address: 0x18004f128)
- ??0BUFFER@@QEAA@XZ (Address: 0x18004f348)
- ??0CEtwTracer@@QEAA@XZ (Address: 0x18004f330)
- ??0CLKRHashTable_Iterator@@QEAA@AEBV0@@Z (Address: 0x18004f228)
- ??0CLKRHashTable@@QEAA@PEBDP6A?B_KPEBX@ZP6AK_K@ZP6A_N33@ZP6AX1H@ZNKK_N@Z (Address: 0x18004f1c8)
- ??0EVENT_LOG@@QEAA@PEBG@Z (Address: 0x18004f378)
- ??0MULTISZ@@QEAA@XZ (Address: 0x18004f2e0)
- ??0STRA@@QEAA@PEADK@Z (Address: 0x18004f140)
- ??0STRA@@QEAA@XZ (Address: 0x18004f2d8)
- ??0STRU@@QEAA@PEAGK@Z (Address: 0x18004f2c8)
- ??0STRU@@QEAA@XZ (Address: 0x18004f350)
- ??1ALLOC_CACHE_HANDLER@@QEAA@XZ (Address: 0x18004f180)
- ??1BUFFER@@QEAA@XZ (Address: 0x18004f220)
- ??1CEtwTracer@@QEAA@XZ (Address: 0x18004f338)
- ??1CLKRHashTable_Iterator@@QEAA@XZ (Address: 0x18004f250)
- ??1CLKRHashTable@@QEAA@XZ (Address: 0x18004f290)
- ??1CReaderWriterLock3@@QEAA@XZ (Address: 0x18004f1a0)
- ??1CSmallSpinLock@@QEAA@XZ (Address: 0x18004f198)
- ??1CSpinLock@@QEAA@XZ (Address: 0x18004f3a0)
- ??1MULTISZ@@QEAA@XZ (Address: 0x18004f308)
- ??1STRA@@QEAA@XZ (Address: 0x18004f1a8)
- ??1STRU@@QEAA@XZ (Address: 0x18004f408)
- ??9CLKRHashTable_Iterator@@QEBA_NAEBV0@@Z (Address: 0x18004f260)
- ?Alloc@ALLOC_CACHE_HANDLER@@QEAAPEAXXZ (Address: 0x18004f2f0)
- ?Append@MULTISZ@@QEAAHPEBG@Z (Address: 0x18004f3e8)
- ?Append@MULTISZ@@QEAAHPEBGK@Z (Address: 0x18004f210)
- ?Append@STRA@@QEAAJPEBD@Z (Address: 0x18004f3d8)
- ?Append@STRA@@QEAAJPEBDK@Z (Address: 0x18004f3d0)
- ?Append@STRU@@QEAAJG@Z (Address: 0x18004f328)
- ?Append@STRU@@QEAAJPEBG@Z (Address: 0x18004f2f8)
- ?Append@STRU@@QEAAJPEBGK@Z (Address: 0x18004f118)
- ?AppendA@STRU@@QEAAJPEBD@Z (Address: 0x18004f1f8)
- ?Apply@CLKRHashTable@@QEAAKP6A?AW4LK_ACTION@@PEBXPEAX@Z1W4LK_LOCKTYPE@@@Z (Address: 0x18004f230)
- ?Begin@CLKRHashTable@@QEAA?AVCLKRHashTable_Iterator@@XZ (Address: 0x18004f240)
- ?Clear@CLKRHashTable@@QEAAXXZ (Address: 0x18004f178)
- ?ConvertSharedToExclusive@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f138)
- ?Copy@STRA@@QEAAJPEBD@Z (Address: 0x18004f410)
- ?Copy@STRA@@QEAAJPEBDK@Z (Address: 0x18004f3f8)
- ?Copy@STRU@@QEAAJAEBV1@@Z (Address: 0x18004f3e0)
- ?Copy@STRU@@QEAAJPEBG@Z (Address: 0x18004f298)
- ?Copy@STRU@@QEAAJPEBGK@Z (Address: 0x18004f2c0)
- ?Copy@STRU@@QEAAJPEBV1@@Z (Address: 0x18004f368)
- ?CopyA@STRU@@QEAAJPEBD@Z (Address: 0x18004f1d8)
- ?CopyW@STRA@@QEAAJPEBG@Z (Address: 0x18004f1f0)
- ?CopyWToUTF8Unescaped@STRA@@QEAAJPEBG@Z (Address: 0x18004f1e8)
- ?DeleteIf@CLKRHashTable@@QEAAKP6A?AW4LK_PREDICATE@@PEBXPEAX@Z1@Z (Address: 0x18004f238)
- ?DeleteKey@CLKRHashTable@@QEAA?AW4LK_RETCODE@@_K@Z (Address: 0x18004f3b0)
- ?DeleteRecord@CLKRHashTable@@QEAA?AW4LK_RETCODE@@PEBX@Z (Address: 0x18004f270)
- ?End@CLKRHashTable@@QEAA?AVCLKRHashTable_Iterator@@XZ (Address: 0x18004f248)
- ?Equals@STRA@@QEBA_NAEBV1@@Z (Address: 0x18004f148)
- ?Equals@STRU@@QEBA_NAEBV1@@Z (Address: 0x18004f370)
- ?EtwTraceEvent@CEtwTracer@@QEAAKPEAU_EVENT_TRACE_HEADER@@@Z (Address: 0x18004f358)
- ?FindKey@CLKRHashTable@@QEBA?AW4LK_RETCODE@@_KPEAPEBX@Z (Address: 0x18004f278)
- ?FindString@MULTISZ@@QEAAHPEBG@Z (Address: 0x18004f3f0)
- ?Free@ALLOC_CACHE_HANDLER@@QEAAHPEAX@Z (Address: 0x18004f1b0)
- ?Increment@CLKRHashTable_Iterator@@QEAA_NXZ (Address: 0x18004f258)
- ?InsertRecord@CLKRHashTable@@QEAA?AW4LK_RETCODE@@PEBX_N@Z (Address: 0x18004f268)
- ?IsValid@CLKRHashTable@@QEBA_NXZ (Address: 0x18004f1c0)
- ?LogEvent@EVENT_LOG@@QEAAXKGQEAPEBGK@Z (Address: 0x18004f130)
- ?ReadLock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f150)
- ?ReadLock@CSpinLock@@QEAAXXZ (Address: 0x18004f208)
- ?ReadUnlock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f2d0)
- ?ReadUnlock@CSpinLock@@QEAAXXZ (Address: 0x18004f200)
- ?Register@CEtwTracer@@QEAAKPEBU_GUID@@PEAG1@Z (Address: 0x18004f2b8)
- ?Reset@MULTISZ@@QEAAXXZ (Address: 0x18004f2e8)
- ?Resize@BUFFER@@QEAA_NK@Z (Address: 0x18004f340)
- ?Resize@STRA@@QEAAJK@Z (Address: 0x18004f3c8)
- ?Resize@STRU@@QEAAJK@Z (Address: 0x18004f400)
- ?SetLen@STRU@@QEAA_NK@Z (Address: 0x18004f108)
- ?Size@CLKRHashTable@@QEBAKXZ (Address: 0x18004f280)
- ?SyncWithBuffer@STRA@@QEAAXXZ (Address: 0x18004f1e0)
- ?SyncWithBuffer@STRU@@QEAAXXZ (Address: 0x18004f120)
- ?UnRegister@CEtwTracer@@QEAAKXZ (Address: 0x18004f168)
- ?WriteLock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f158)
- ?WriteLock@CSmallSpinLock@@QEAAXXZ (Address: 0x18004f3c0)
- ?WriteLock@CSpinLock@@QEAAXXZ (Address: 0x18004f218)
- ?WriteUnlock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f160)
- ?WriteUnlock@CSmallSpinLock@@QEAAXXZ (Address: 0x18004f3b8)
- ?WriteUnlock@CSpinLock@@QEAAXXZ (Address: 0x18004f1b8)
- AllocateAndCreateWellKnownSid (Address: 0x18004f320)
- DestroyRefTraceLog (Address: 0x18004f188)
- DisableTokenBackupPrivilege (Address: 0x18004f3a8)
- FreeWellKnownSid (Address: 0x18004f318)
- GetCurrentTimeInSeconds (Address: 0x18004f310)
- HandleMigration (Address: 0x18004f2b0)
- IISGetPlatformType (Address: 0x18004f388)
- InitializeLocalRequest (Address: 0x18004f2a0)
- IsLocalRequest (Address: 0x18004f1d0)
- IsStringEqualOrdinalIgnoreCase (Address: 0x18004f288)
- MakePathCanonicalizationProof (Address: 0x18004f110)
- PuCreateDebugPrintsObject (Address: 0x18004f398)
- PuDbgPrint (Address: 0x18004f2a8)
- PuDbgPrintError (Address: 0x18004f360)
- PuDeleteDebugPrintsObject (Address: 0x18004f380)
- PuLoadDebugFlagsFromRegStr (Address: 0x18004f390)
- TerminateLocalRequest (Address: 0x18004f170)
- WriteRefTraceLog (Address: 0x18004f300)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18004ee28)
- AcquireSRWLockShared (Address: 0x18004ee18)
- CheckRemoteDebuggerPresent (Address: 0x18004ebd8)
- CloseHandle (Address: 0x18004ed68)
- CreateDirectoryW (Address: 0x18004ec60)
- CreateEventW (Address: 0x18004ecb8)
- CreateFileW (Address: 0x18004ec50)
- CreateIoCompletionPort (Address: 0x18004ee08)
- CreateRemoteThreadEx (Address: 0x18004ed20)
- CreateThread (Address: 0x18004ecd8)
- CreateTimerQueueTimer (Address: 0x18004ec68)
- DeleteCriticalSection (Address: 0x18004ed10)
- DeleteFileW (Address: 0x18004ebb0)
- DeleteProcThreadAttributeList (Address: 0x18004edc0)
- DeleteTimerQueueTimer (Address: 0x18004ed00)
- DisableThreadLibraryCalls (Address: 0x18004ed80)
- EnterCriticalSection (Address: 0x18004ecb0)
- ExpandEnvironmentStringsW (Address: 0x18004ece0)
- FileTimeToLocalFileTime (Address: 0x18004ed58)
- FileTimeToSystemTime (Address: 0x18004ed50)
- FindClose (Address: 0x18004ec40)
- FindFirstFileW (Address: 0x18004ec30)
- FindNextFileW (Address: 0x18004ec28)
- FormatMessageA (Address: 0x18004ee58)
- FreeLibrary (Address: 0x18004ecf0)
- FreeLibraryAndExitThread (Address: 0x18004eda8)
- GetComputerNameExW (Address: 0x18004ee38)
- GetCurrentProcess (Address: 0x18004ec18)
- GetCurrentProcessId (Address: 0x18004ebf0)
- GetCurrentThread (Address: 0x18004edf8)
- GetCurrentThreadId (Address: 0x18004ebf8)
- GetDiskFreeSpaceExW (Address: 0x18004eb88)
- GetExitCodeThread (Address: 0x18004ecc8)
- GetFileAttributesExW (Address: 0x18004eb90)
- GetFileInformationByHandle (Address: 0x18004ec48)
- GetFileSizeEx (Address: 0x18004ebe8)
- GetFileType (Address: 0x18004eba8)
- GetLastError (Address: 0x18004ed08)
- GetLocalTime (Address: 0x18004ee40)
- GetLogicalProcessorInformationEx (Address: 0x18004edb8)
- GetModuleFileNameW (Address: 0x18004ed88)
- GetModuleHandleW (Address: 0x18004ec80)
- GetNumaHighestNodeNumber (Address: 0x18004ed28)
- GetNumaNodeProcessorMaskEx (Address: 0x18004edd8)
- GetProcAddress (Address: 0x18004ec78)
- GetProcessAffinityMask (Address: 0x18004ec20)
- GetProcessHeap (Address: 0x18004edd0)
- GetQueuedCompletionStatus (Address: 0x18004ede8)
- GetSystemInfo (Address: 0x18004ed70)
- GetSystemTime (Address: 0x18004ebc0)
- GetSystemTimeAsFileTime (Address: 0x18004eb98)
- GetTickCount (Address: 0x18004ec00)
- GetTickCount64 (Address: 0x18004ec38)
- GetUserDefaultLCID (Address: 0x18004ec70)
- GlobalMemoryStatus (Address: 0x18004ee00)
- HeapAlloc (Address: 0x18004edc8)
- HeapFree (Address: 0x18004ed18)
- InitializeCriticalSection (Address: 0x18004ecf8)
- InitializeCriticalSectionAndSpinCount (Address: 0x18004ecc0)
- InitializeProcThreadAttributeList (Address: 0x18004ed90)
- InitializeSRWLock (Address: 0x18004ee20)
- LeaveCriticalSection (Address: 0x18004eca8)
- LoadLibraryExW (Address: 0x18004ede0)
- LoadLibraryW (Address: 0x18004ed38)
- LocalAlloc (Address: 0x18004ed40)
- LocalFree (Address: 0x18004ed60)
- MoveFileExW (Address: 0x18004ebb8)
- MultiByteToWideChar (Address: 0x18004ee48)
- OpenProcess (Address: 0x18004ebd0)
- OutputDebugStringA (Address: 0x18004ed78)
- PostQueuedCompletionStatus (Address: 0x18004edf0)
- QueryPerformanceCounter (Address: 0x18004ee50)
- ReadFile (Address: 0x18004ec88)
- RegisterWaitForSingleObject (Address: 0x18004ed48)
- ReleaseSRWLockExclusive (Address: 0x18004ee30)
- ReleaseSRWLockShared (Address: 0x18004ee10)
- RemoveDirectoryW (Address: 0x18004ec58)
- SetEndOfFile (Address: 0x18004eb80)
- SetEvent (Address: 0x18004eca0)
- SetFilePointerEx (Address: 0x18004ed98)
- SetFileTime (Address: 0x18004eba0)
- SetUnhandledExceptionFilter (Address: 0x18004ec10)
- Sleep (Address: 0x18004ecd0)
- SystemTimeToFileTime (Address: 0x18004ebc8)
- TerminateProcess (Address: 0x18004ebe0)
- UnhandledExceptionFilter (Address: 0x18004ec08)
- UnregisterWaitEx (Address: 0x18004ed30)
- UpdateProcThreadAttribute (Address: 0x18004edb0)
- WaitForMultipleObjects (Address: 0x18004ec98)
- WaitForMultipleObjectsEx (Address: 0x18004eda0)
- WaitForSingleObject (Address: 0x18004ece8)
- WideCharToMultiByte (Address: 0x18004ee60)
- WriteFile (Address: 0x18004ec90)
msvcrt.dll
- __C_specific_handler (Address: 0x18004f508)
- __CxxFrameHandler3 (Address: 0x18004f4b8)
- __dllonexit (Address: 0x18004f4e8)
- _amsg_exit (Address: 0x18004f518)
- _callnewh (Address: 0x18004f528)
- _i64toa_s (Address: 0x18004f498)
- _initterm (Address: 0x18004f510)
- _itoa_s (Address: 0x18004f4a0)
- _itow (Address: 0x18004f460)
- _lock (Address: 0x18004f4f8)
- _memicmp (Address: 0x18004f450)
- _onexit (Address: 0x18004f4e0)
- _purecall (Address: 0x18004f588)
- _stricmp (Address: 0x18004f458)
- _strnicmp (Address: 0x18004f428)
- _strtoui64 (Address: 0x18004f5a0)
- _ultow (Address: 0x18004f548)
- _unlock (Address: 0x18004f4f0)
- _vsnprintf (Address: 0x18004f440)
- _wcsicmp (Address: 0x18004f590)
- _wcslwr (Address: 0x18004f488)
- _wcsnicmp (Address: 0x18004f560)
- _wcsupr (Address: 0x18004f540)
- _XcptFilter (Address: 0x18004f520)
- ?terminate@@YAXXZ (Address: 0x18004f500)
- atol (Address: 0x18004f448)
- free (Address: 0x18004f538)
- isdigit (Address: 0x18004f420)
- malloc (Address: 0x18004f530)
- memcmp (Address: 0x18004f4c0)
- memcpy (Address: 0x18004f4c8)
- memcpy_s (Address: 0x18004f550)
- memmove (Address: 0x18004f4d0)
- memset (Address: 0x18004f4d8)
- sprintf_s (Address: 0x18004f598)
- strchr (Address: 0x18004f4a8)
- strncmp (Address: 0x18004f430)
- strstr (Address: 0x18004f438)
- strtoul (Address: 0x18004f468)
- swprintf_s (Address: 0x18004f578)
- towupper (Address: 0x18004f4b0)
- wcschr (Address: 0x18004f570)
- wcscmp (Address: 0x18004f5a8)
- wcscpy_s (Address: 0x18004f558)
- wcscspn (Address: 0x18004f490)
- wcsncpy_s (Address: 0x18004f580)
- wcspbrk (Address: 0x18004f470)
- wcsrchr (Address: 0x18004f478)
- wcsstr (Address: 0x18004f480)
- wcstoul (Address: 0x18004f568)
MSWSOCK.dll
- AcceptEx (Address: 0x18004ee80)
- GetAcceptExSockaddrs (Address: 0x18004ee78)
- TransmitFile (Address: 0x18004ee70)
NETAPI32.dll
- DsGetDcNameW (Address: 0x18004ee90)
- NetApiBufferFree (Address: 0x18004ee98)
Normaliz.dll
- IdnToAscii (Address: 0x18004eea8)
ntdll.dll
- NtQueryInformationThread (Address: 0x18004f5c0)
- NtQuerySystemInformation (Address: 0x18004f5b8)
- RtlCaptureContext (Address: 0x18004f5d0)
- RtlLookupFunctionEntry (Address: 0x18004f5d8)
- RtlVirtualUnwind (Address: 0x18004f5e0)
- WinSqmSetDWORD (Address: 0x18004f5c8)
ole32.dll
- CoCreateInstance (Address: 0x18004f600)
- CoDisconnectObject (Address: 0x18004f628)
- CoInitializeEx (Address: 0x18004f610)
- CoInitializeSecurity (Address: 0x18004f640)
- CoRegisterClassObject (Address: 0x18004f5f8)
- CoRevokeClassObject (Address: 0x18004f620)
- CoTaskMemAlloc (Address: 0x18004f5f0)
- CoTaskMemFree (Address: 0x18004f618)
- CoUninitialize (Address: 0x18004f608)
- StringFromGUID2 (Address: 0x18004f630)
- StringFromIID (Address: 0x18004f638)
OLEAUT32.dll
- GetErrorInfo (Address: 0x18004eec8)
- GetRecordInfoFromGuids (Address: 0x18004eed0)
- SafeArrayAccessData (Address: 0x18004ef18)
- SafeArrayCreateVectorEx (Address: 0x18004eed8)
- SafeArrayDestroy (Address: 0x18004eef8)
- SafeArrayGetLBound (Address: 0x18004ef10)
- SafeArrayGetUBound (Address: 0x18004eef0)
- SafeArrayUnaccessData (Address: 0x18004eee0)
- SysAllocString (Address: 0x18004eee8)
- SysFreeString (Address: 0x18004eec0)
- SysStringLen (Address: 0x18004ef08)
- VariantChangeType (Address: 0x18004eeb8)
- VariantClear (Address: 0x18004ef00)
- VariantInit (Address: 0x18004ef20)
RPCRT4.dll
- RpcStringFreeW (Address: 0x18004ef38)
- UuidCreate (Address: 0x18004ef48)
- UuidCreateSequential (Address: 0x18004ef40)
- UuidToStringW (Address: 0x18004ef30)
Secur32.dll
- AcceptSecurityContext (Address: 0x18004ef90)
- AcquireCredentialsHandleW (Address: 0x18004ef68)
- ApplyControlToken (Address: 0x18004ef70)
- DecryptMessage (Address: 0x18004ef80)
- DeleteSecurityContext (Address: 0x18004ef78)
- EncryptMessage (Address: 0x18004efa8)
- FreeContextBuffer (Address: 0x18004ef98)
- FreeCredentialsHandle (Address: 0x18004ef60)
- GetUserNameExW (Address: 0x18004efb0)
- LsaFreeReturnBuffer (Address: 0x18004efa0)
- QueryContextAttributesW (Address: 0x18004ef88)
- QuerySecurityContextToken (Address: 0x18004ef58)
WLDAP32.dll
- (Address: 0x18004f030)
- (Address: 0x18004f028)
- (Address: 0x18004f020)
- (Address: 0x18004f018)
- (Address: 0x18004f010)
- (Address: 0x18004f008)
- (Address: 0x18004f000)
- (Address: 0x18004eff8)
- (Address: 0x18004efc0)
- (Address: 0x18004efc8)
- (Address: 0x18004efd0)
- (Address: 0x18004efd8)
- (Address: 0x18004efe0)
- (Address: 0x18004efe8)
- (Address: 0x18004eff0)
WS2_32.dll
- bind (Address: 0x18004f0a8)
- closesocket (Address: 0x18004f0c0)
- freeaddrinfo (Address: 0x18004f050)
- FreeAddrInfoW (Address: 0x18004f078)
- getaddrinfo (Address: 0x18004f048)
- GetAddrInfoW (Address: 0x18004f058)
- GetHostNameW (Address: 0x18004f0e0)
- getnameinfo (Address: 0x18004f040)
- GetNameInfoW (Address: 0x18004f068)
- getpeername (Address: 0x18004f090)
- getsockname (Address: 0x18004f0a0)
- htons (Address: 0x18004f060)
- listen (Address: 0x18004f098)
- ntohs (Address: 0x18004f070)
- send (Address: 0x18004f088)
- setsockopt (Address: 0x18004f0b0)
- shutdown (Address: 0x18004f080)
- socket (Address: 0x18004f0d8)
- WSACleanup (Address: 0x18004f0f8)
- WSAGetLastError (Address: 0x18004f0d0)
- WSAIoctl (Address: 0x18004f0c8)
- WSASocketW (Address: 0x18004f0b8)
- WSAStartup (Address: 0x18004f0f0)
- WSAStringToAddressW (Address: 0x18004f0e8)