ftpsvc.dll

Description: Protocol Handler for FTPSVC

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 00d5bb7b08c21b8cdd376e2d91e1c060

File Size: 421.0 KB

Uploaded At: Dec. 1, 2025, 8:12 a.m.

Views: 12

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ServiceMain (Ordinal: 1, Address: 0x51c0)
  • DllRegisterServer (Ordinal: 2, Address: 0x18110)
  • DllUnregisterServer (Ordinal: 3, Address: 0x188e0)

Imported DLLs & Functions

ADVAPI32.dll
  • AddAccessAllowedAce (Address: 0x18004e9d8)
  • CheckTokenMembership (Address: 0x18004e9b8)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18004e9c0)
  • CreateWellKnownSid (Address: 0x18004ea00)
  • CryptAcquireContextW (Address: 0x18004ead0)
  • CryptCreateHash (Address: 0x18004eac0)
  • CryptDestroyHash (Address: 0x18004eaa8)
  • CryptGetHashParam (Address: 0x18004eab0)
  • CryptGetProvParam (Address: 0x18004e9e8)
  • CryptHashData (Address: 0x18004eab8)
  • CryptReleaseContext (Address: 0x18004eac8)
  • DuplicateTokenEx (Address: 0x18004eae0)
  • EqualSid (Address: 0x18004e9b0)
  • EventRegister (Address: 0x18004ea98)
  • EventSetInformation (Address: 0x18004eaa0)
  • EventUnregister (Address: 0x18004ea90)
  • EventWriteTransfer (Address: 0x18004ea88)
  • GetLengthSid (Address: 0x18004e9c8)
  • GetTokenInformation (Address: 0x18004e990)
  • GetTraceLoggerHandle (Address: 0x18004ea78)
  • ImpersonateLoggedOnUser (Address: 0x18004ead8)
  • InitializeAcl (Address: 0x18004e9d0)
  • InitializeSecurityDescriptor (Address: 0x18004ea60)
  • LogonUserExW (Address: 0x18004e9a0)
  • LookupAccountNameW (Address: 0x18004e9a8)
  • MakeSelfRelativeSD (Address: 0x18004e9e0)
  • OpenProcessToken (Address: 0x18004e998)
  • RegCloseKey (Address: 0x18004ea38)
  • RegCreateKeyExW (Address: 0x18004eaf8)
  • RegDeleteKeyW (Address: 0x18004eae8)
  • RegisterServiceCtrlHandlerExW (Address: 0x18004ea40)
  • RegisterTraceGuidsW (Address: 0x18004ea70)
  • RegOpenKeyExA (Address: 0x18004e9f0)
  • RegOpenKeyExW (Address: 0x18004ea28)
  • RegOpenKeyW (Address: 0x18004ea50)
  • RegQueryValueExA (Address: 0x18004e9f8)
  • RegQueryValueExW (Address: 0x18004ea30)
  • RegSetValueExW (Address: 0x18004eaf0)
  • RevertToSelf (Address: 0x18004ea80)
  • SetEntriesInAclW (Address: 0x18004ea08)
  • SetSecurityDescriptorDacl (Address: 0x18004ea20)
  • SetSecurityDescriptorGroup (Address: 0x18004ea18)
  • SetSecurityDescriptorOwner (Address: 0x18004ea10)
  • SetServiceStatus (Address: 0x18004ea48)
  • SetThreadToken (Address: 0x18004ea58)
  • TraceEvent (Address: 0x18004ea68)
  • UnregisterTraceGuids (Address: 0x18004e988)
CRYPT32.dll
  • CertCloseStore (Address: 0x18004eb60)
  • CertControlStore (Address: 0x18004eb68)
  • CertDuplicateCertificateContext (Address: 0x18004eb10)
  • CertFindCertificateInStore (Address: 0x18004eb28)
  • CertFreeCertificateChain (Address: 0x18004eb48)
  • CertFreeCertificateContext (Address: 0x18004eb18)
  • CertGetCertificateChain (Address: 0x18004eb20)
  • CertGetCertificateContextProperty (Address: 0x18004eb08)
  • CertGetPublicKeyLength (Address: 0x18004eb50)
  • CertNameToStrA (Address: 0x18004eb30)
  • CertNameToStrW (Address: 0x18004eb58)
  • CertOpenStore (Address: 0x18004eb70)
  • CertVerifyCertificateChainPolicy (Address: 0x18004eb40)
  • CryptAcquireCertificatePrivateKey (Address: 0x18004eb38)
iisutil.dll
  • ??0ALLOC_CACHE_HANDLER@@QEAA@PEBDPEBUALLOC_CACHE_CONFIGURATION@@H@Z (Address: 0x18004f190)
  • ??0BUFFER@@QEAA@PEAEK@Z (Address: 0x18004f128)
  • ??0BUFFER@@QEAA@XZ (Address: 0x18004f348)
  • ??0CEtwTracer@@QEAA@XZ (Address: 0x18004f330)
  • ??0CLKRHashTable_Iterator@@QEAA@AEBV0@@Z (Address: 0x18004f228)
  • ??0CLKRHashTable@@QEAA@PEBDP6A?B_KPEBX@ZP6AK_K@ZP6A_N33@ZP6AX1H@ZNKK_N@Z (Address: 0x18004f1c8)
  • ??0EVENT_LOG@@QEAA@PEBG@Z (Address: 0x18004f378)
  • ??0MULTISZ@@QEAA@XZ (Address: 0x18004f2e0)
  • ??0STRA@@QEAA@PEADK@Z (Address: 0x18004f140)
  • ??0STRA@@QEAA@XZ (Address: 0x18004f2d8)
  • ??0STRU@@QEAA@PEAGK@Z (Address: 0x18004f2c8)
  • ??0STRU@@QEAA@XZ (Address: 0x18004f350)
  • ??1ALLOC_CACHE_HANDLER@@QEAA@XZ (Address: 0x18004f180)
  • ??1BUFFER@@QEAA@XZ (Address: 0x18004f220)
  • ??1CEtwTracer@@QEAA@XZ (Address: 0x18004f338)
  • ??1CLKRHashTable_Iterator@@QEAA@XZ (Address: 0x18004f250)
  • ??1CLKRHashTable@@QEAA@XZ (Address: 0x18004f290)
  • ??1CReaderWriterLock3@@QEAA@XZ (Address: 0x18004f1a0)
  • ??1CSmallSpinLock@@QEAA@XZ (Address: 0x18004f198)
  • ??1CSpinLock@@QEAA@XZ (Address: 0x18004f3a0)
  • ??1MULTISZ@@QEAA@XZ (Address: 0x18004f308)
  • ??1STRA@@QEAA@XZ (Address: 0x18004f1a8)
  • ??1STRU@@QEAA@XZ (Address: 0x18004f408)
  • ??9CLKRHashTable_Iterator@@QEBA_NAEBV0@@Z (Address: 0x18004f260)
  • ?Alloc@ALLOC_CACHE_HANDLER@@QEAAPEAXXZ (Address: 0x18004f2f0)
  • ?Append@MULTISZ@@QEAAHPEBG@Z (Address: 0x18004f3e8)
  • ?Append@MULTISZ@@QEAAHPEBGK@Z (Address: 0x18004f210)
  • ?Append@STRA@@QEAAJPEBD@Z (Address: 0x18004f3d8)
  • ?Append@STRA@@QEAAJPEBDK@Z (Address: 0x18004f3d0)
  • ?Append@STRU@@QEAAJG@Z (Address: 0x18004f328)
  • ?Append@STRU@@QEAAJPEBG@Z (Address: 0x18004f2f8)
  • ?Append@STRU@@QEAAJPEBGK@Z (Address: 0x18004f118)
  • ?AppendA@STRU@@QEAAJPEBD@Z (Address: 0x18004f1f8)
  • ?Apply@CLKRHashTable@@QEAAKP6A?AW4LK_ACTION@@PEBXPEAX@Z1W4LK_LOCKTYPE@@@Z (Address: 0x18004f230)
  • ?Begin@CLKRHashTable@@QEAA?AVCLKRHashTable_Iterator@@XZ (Address: 0x18004f240)
  • ?Clear@CLKRHashTable@@QEAAXXZ (Address: 0x18004f178)
  • ?ConvertSharedToExclusive@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f138)
  • ?Copy@STRA@@QEAAJPEBD@Z (Address: 0x18004f410)
  • ?Copy@STRA@@QEAAJPEBDK@Z (Address: 0x18004f3f8)
  • ?Copy@STRU@@QEAAJAEBV1@@Z (Address: 0x18004f3e0)
  • ?Copy@STRU@@QEAAJPEBG@Z (Address: 0x18004f298)
  • ?Copy@STRU@@QEAAJPEBGK@Z (Address: 0x18004f2c0)
  • ?Copy@STRU@@QEAAJPEBV1@@Z (Address: 0x18004f368)
  • ?CopyA@STRU@@QEAAJPEBD@Z (Address: 0x18004f1d8)
  • ?CopyW@STRA@@QEAAJPEBG@Z (Address: 0x18004f1f0)
  • ?CopyWToUTF8Unescaped@STRA@@QEAAJPEBG@Z (Address: 0x18004f1e8)
  • ?DeleteIf@CLKRHashTable@@QEAAKP6A?AW4LK_PREDICATE@@PEBXPEAX@Z1@Z (Address: 0x18004f238)
  • ?DeleteKey@CLKRHashTable@@QEAA?AW4LK_RETCODE@@_K@Z (Address: 0x18004f3b0)
  • ?DeleteRecord@CLKRHashTable@@QEAA?AW4LK_RETCODE@@PEBX@Z (Address: 0x18004f270)
  • ?End@CLKRHashTable@@QEAA?AVCLKRHashTable_Iterator@@XZ (Address: 0x18004f248)
  • ?Equals@STRA@@QEBA_NAEBV1@@Z (Address: 0x18004f148)
  • ?Equals@STRU@@QEBA_NAEBV1@@Z (Address: 0x18004f370)
  • ?EtwTraceEvent@CEtwTracer@@QEAAKPEAU_EVENT_TRACE_HEADER@@@Z (Address: 0x18004f358)
  • ?FindKey@CLKRHashTable@@QEBA?AW4LK_RETCODE@@_KPEAPEBX@Z (Address: 0x18004f278)
  • ?FindString@MULTISZ@@QEAAHPEBG@Z (Address: 0x18004f3f0)
  • ?Free@ALLOC_CACHE_HANDLER@@QEAAHPEAX@Z (Address: 0x18004f1b0)
  • ?Increment@CLKRHashTable_Iterator@@QEAA_NXZ (Address: 0x18004f258)
  • ?InsertRecord@CLKRHashTable@@QEAA?AW4LK_RETCODE@@PEBX_N@Z (Address: 0x18004f268)
  • ?IsValid@CLKRHashTable@@QEBA_NXZ (Address: 0x18004f1c0)
  • ?LogEvent@EVENT_LOG@@QEAAXKGQEAPEBGK@Z (Address: 0x18004f130)
  • ?ReadLock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f150)
  • ?ReadLock@CSpinLock@@QEAAXXZ (Address: 0x18004f208)
  • ?ReadUnlock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f2d0)
  • ?ReadUnlock@CSpinLock@@QEAAXXZ (Address: 0x18004f200)
  • ?Register@CEtwTracer@@QEAAKPEBU_GUID@@PEAG1@Z (Address: 0x18004f2b8)
  • ?Reset@MULTISZ@@QEAAXXZ (Address: 0x18004f2e8)
  • ?Resize@BUFFER@@QEAA_NK@Z (Address: 0x18004f340)
  • ?Resize@STRA@@QEAAJK@Z (Address: 0x18004f3c8)
  • ?Resize@STRU@@QEAAJK@Z (Address: 0x18004f400)
  • ?SetLen@STRU@@QEAA_NK@Z (Address: 0x18004f108)
  • ?Size@CLKRHashTable@@QEBAKXZ (Address: 0x18004f280)
  • ?SyncWithBuffer@STRA@@QEAAXXZ (Address: 0x18004f1e0)
  • ?SyncWithBuffer@STRU@@QEAAXXZ (Address: 0x18004f120)
  • ?UnRegister@CEtwTracer@@QEAAKXZ (Address: 0x18004f168)
  • ?WriteLock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f158)
  • ?WriteLock@CSmallSpinLock@@QEAAXXZ (Address: 0x18004f3c0)
  • ?WriteLock@CSpinLock@@QEAAXXZ (Address: 0x18004f218)
  • ?WriteUnlock@CReaderWriterLock3@@QEAAXXZ (Address: 0x18004f160)
  • ?WriteUnlock@CSmallSpinLock@@QEAAXXZ (Address: 0x18004f3b8)
  • ?WriteUnlock@CSpinLock@@QEAAXXZ (Address: 0x18004f1b8)
  • AllocateAndCreateWellKnownSid (Address: 0x18004f320)
  • DestroyRefTraceLog (Address: 0x18004f188)
  • DisableTokenBackupPrivilege (Address: 0x18004f3a8)
  • FreeWellKnownSid (Address: 0x18004f318)
  • GetCurrentTimeInSeconds (Address: 0x18004f310)
  • HandleMigration (Address: 0x18004f2b0)
  • IISGetPlatformType (Address: 0x18004f388)
  • InitializeLocalRequest (Address: 0x18004f2a0)
  • IsLocalRequest (Address: 0x18004f1d0)
  • IsStringEqualOrdinalIgnoreCase (Address: 0x18004f288)
  • MakePathCanonicalizationProof (Address: 0x18004f110)
  • PuCreateDebugPrintsObject (Address: 0x18004f398)
  • PuDbgPrint (Address: 0x18004f2a8)
  • PuDbgPrintError (Address: 0x18004f360)
  • PuDeleteDebugPrintsObject (Address: 0x18004f380)
  • PuLoadDebugFlagsFromRegStr (Address: 0x18004f390)
  • TerminateLocalRequest (Address: 0x18004f170)
  • WriteRefTraceLog (Address: 0x18004f300)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18004ee28)
  • AcquireSRWLockShared (Address: 0x18004ee18)
  • CheckRemoteDebuggerPresent (Address: 0x18004ebd8)
  • CloseHandle (Address: 0x18004ed68)
  • CreateDirectoryW (Address: 0x18004ec60)
  • CreateEventW (Address: 0x18004ecb8)
  • CreateFileW (Address: 0x18004ec50)
  • CreateIoCompletionPort (Address: 0x18004ee08)
  • CreateRemoteThreadEx (Address: 0x18004ed20)
  • CreateThread (Address: 0x18004ecd8)
  • CreateTimerQueueTimer (Address: 0x18004ec68)
  • DeleteCriticalSection (Address: 0x18004ed10)
  • DeleteFileW (Address: 0x18004ebb0)
  • DeleteProcThreadAttributeList (Address: 0x18004edc0)
  • DeleteTimerQueueTimer (Address: 0x18004ed00)
  • DisableThreadLibraryCalls (Address: 0x18004ed80)
  • EnterCriticalSection (Address: 0x18004ecb0)
  • ExpandEnvironmentStringsW (Address: 0x18004ece0)
  • FileTimeToLocalFileTime (Address: 0x18004ed58)
  • FileTimeToSystemTime (Address: 0x18004ed50)
  • FindClose (Address: 0x18004ec40)
  • FindFirstFileW (Address: 0x18004ec30)
  • FindNextFileW (Address: 0x18004ec28)
  • FormatMessageA (Address: 0x18004ee58)
  • FreeLibrary (Address: 0x18004ecf0)
  • FreeLibraryAndExitThread (Address: 0x18004eda8)
  • GetComputerNameExW (Address: 0x18004ee38)
  • GetCurrentProcess (Address: 0x18004ec18)
  • GetCurrentProcessId (Address: 0x18004ebf0)
  • GetCurrentThread (Address: 0x18004edf8)
  • GetCurrentThreadId (Address: 0x18004ebf8)
  • GetDiskFreeSpaceExW (Address: 0x18004eb88)
  • GetExitCodeThread (Address: 0x18004ecc8)
  • GetFileAttributesExW (Address: 0x18004eb90)
  • GetFileInformationByHandle (Address: 0x18004ec48)
  • GetFileSizeEx (Address: 0x18004ebe8)
  • GetFileType (Address: 0x18004eba8)
  • GetLastError (Address: 0x18004ed08)
  • GetLocalTime (Address: 0x18004ee40)
  • GetLogicalProcessorInformationEx (Address: 0x18004edb8)
  • GetModuleFileNameW (Address: 0x18004ed88)
  • GetModuleHandleW (Address: 0x18004ec80)
  • GetNumaHighestNodeNumber (Address: 0x18004ed28)
  • GetNumaNodeProcessorMaskEx (Address: 0x18004edd8)
  • GetProcAddress (Address: 0x18004ec78)
  • GetProcessAffinityMask (Address: 0x18004ec20)
  • GetProcessHeap (Address: 0x18004edd0)
  • GetQueuedCompletionStatus (Address: 0x18004ede8)
  • GetSystemInfo (Address: 0x18004ed70)
  • GetSystemTime (Address: 0x18004ebc0)
  • GetSystemTimeAsFileTime (Address: 0x18004eb98)
  • GetTickCount (Address: 0x18004ec00)
  • GetTickCount64 (Address: 0x18004ec38)
  • GetUserDefaultLCID (Address: 0x18004ec70)
  • GlobalMemoryStatus (Address: 0x18004ee00)
  • HeapAlloc (Address: 0x18004edc8)
  • HeapFree (Address: 0x18004ed18)
  • InitializeCriticalSection (Address: 0x18004ecf8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18004ecc0)
  • InitializeProcThreadAttributeList (Address: 0x18004ed90)
  • InitializeSRWLock (Address: 0x18004ee20)
  • LeaveCriticalSection (Address: 0x18004eca8)
  • LoadLibraryExW (Address: 0x18004ede0)
  • LoadLibraryW (Address: 0x18004ed38)
  • LocalAlloc (Address: 0x18004ed40)
  • LocalFree (Address: 0x18004ed60)
  • MoveFileExW (Address: 0x18004ebb8)
  • MultiByteToWideChar (Address: 0x18004ee48)
  • OpenProcess (Address: 0x18004ebd0)
  • OutputDebugStringA (Address: 0x18004ed78)
  • PostQueuedCompletionStatus (Address: 0x18004edf0)
  • QueryPerformanceCounter (Address: 0x18004ee50)
  • ReadFile (Address: 0x18004ec88)
  • RegisterWaitForSingleObject (Address: 0x18004ed48)
  • ReleaseSRWLockExclusive (Address: 0x18004ee30)
  • ReleaseSRWLockShared (Address: 0x18004ee10)
  • RemoveDirectoryW (Address: 0x18004ec58)
  • SetEndOfFile (Address: 0x18004eb80)
  • SetEvent (Address: 0x18004eca0)
  • SetFilePointerEx (Address: 0x18004ed98)
  • SetFileTime (Address: 0x18004eba0)
  • SetUnhandledExceptionFilter (Address: 0x18004ec10)
  • Sleep (Address: 0x18004ecd0)
  • SystemTimeToFileTime (Address: 0x18004ebc8)
  • TerminateProcess (Address: 0x18004ebe0)
  • UnhandledExceptionFilter (Address: 0x18004ec08)
  • UnregisterWaitEx (Address: 0x18004ed30)
  • UpdateProcThreadAttribute (Address: 0x18004edb0)
  • WaitForMultipleObjects (Address: 0x18004ec98)
  • WaitForMultipleObjectsEx (Address: 0x18004eda0)
  • WaitForSingleObject (Address: 0x18004ece8)
  • WideCharToMultiByte (Address: 0x18004ee60)
  • WriteFile (Address: 0x18004ec90)
msvcrt.dll
  • __C_specific_handler (Address: 0x18004f508)
  • __CxxFrameHandler3 (Address: 0x18004f4b8)
  • __dllonexit (Address: 0x18004f4e8)
  • _amsg_exit (Address: 0x18004f518)
  • _callnewh (Address: 0x18004f528)
  • _i64toa_s (Address: 0x18004f498)
  • _initterm (Address: 0x18004f510)
  • _itoa_s (Address: 0x18004f4a0)
  • _itow (Address: 0x18004f460)
  • _lock (Address: 0x18004f4f8)
  • _memicmp (Address: 0x18004f450)
  • _onexit (Address: 0x18004f4e0)
  • _purecall (Address: 0x18004f588)
  • _stricmp (Address: 0x18004f458)
  • _strnicmp (Address: 0x18004f428)
  • _strtoui64 (Address: 0x18004f5a0)
  • _ultow (Address: 0x18004f548)
  • _unlock (Address: 0x18004f4f0)
  • _vsnprintf (Address: 0x18004f440)
  • _wcsicmp (Address: 0x18004f590)
  • _wcslwr (Address: 0x18004f488)
  • _wcsnicmp (Address: 0x18004f560)
  • _wcsupr (Address: 0x18004f540)
  • _XcptFilter (Address: 0x18004f520)
  • ?terminate@@YAXXZ (Address: 0x18004f500)
  • atol (Address: 0x18004f448)
  • free (Address: 0x18004f538)
  • isdigit (Address: 0x18004f420)
  • malloc (Address: 0x18004f530)
  • memcmp (Address: 0x18004f4c0)
  • memcpy (Address: 0x18004f4c8)
  • memcpy_s (Address: 0x18004f550)
  • memmove (Address: 0x18004f4d0)
  • memset (Address: 0x18004f4d8)
  • sprintf_s (Address: 0x18004f598)
  • strchr (Address: 0x18004f4a8)
  • strncmp (Address: 0x18004f430)
  • strstr (Address: 0x18004f438)
  • strtoul (Address: 0x18004f468)
  • swprintf_s (Address: 0x18004f578)
  • towupper (Address: 0x18004f4b0)
  • wcschr (Address: 0x18004f570)
  • wcscmp (Address: 0x18004f5a8)
  • wcscpy_s (Address: 0x18004f558)
  • wcscspn (Address: 0x18004f490)
  • wcsncpy_s (Address: 0x18004f580)
  • wcspbrk (Address: 0x18004f470)
  • wcsrchr (Address: 0x18004f478)
  • wcsstr (Address: 0x18004f480)
  • wcstoul (Address: 0x18004f568)
MSWSOCK.dll
  • AcceptEx (Address: 0x18004ee80)
  • GetAcceptExSockaddrs (Address: 0x18004ee78)
  • TransmitFile (Address: 0x18004ee70)
NETAPI32.dll
  • DsGetDcNameW (Address: 0x18004ee90)
  • NetApiBufferFree (Address: 0x18004ee98)
Normaliz.dll
  • IdnToAscii (Address: 0x18004eea8)
ntdll.dll
  • NtQueryInformationThread (Address: 0x18004f5c0)
  • NtQuerySystemInformation (Address: 0x18004f5b8)
  • RtlCaptureContext (Address: 0x18004f5d0)
  • RtlLookupFunctionEntry (Address: 0x18004f5d8)
  • RtlVirtualUnwind (Address: 0x18004f5e0)
  • WinSqmSetDWORD (Address: 0x18004f5c8)
ole32.dll
  • CoCreateInstance (Address: 0x18004f600)
  • CoDisconnectObject (Address: 0x18004f628)
  • CoInitializeEx (Address: 0x18004f610)
  • CoInitializeSecurity (Address: 0x18004f640)
  • CoRegisterClassObject (Address: 0x18004f5f8)
  • CoRevokeClassObject (Address: 0x18004f620)
  • CoTaskMemAlloc (Address: 0x18004f5f0)
  • CoTaskMemFree (Address: 0x18004f618)
  • CoUninitialize (Address: 0x18004f608)
  • StringFromGUID2 (Address: 0x18004f630)
  • StringFromIID (Address: 0x18004f638)
OLEAUT32.dll
  • GetErrorInfo (Address: 0x18004eec8)
  • GetRecordInfoFromGuids (Address: 0x18004eed0)
  • SafeArrayAccessData (Address: 0x18004ef18)
  • SafeArrayCreateVectorEx (Address: 0x18004eed8)
  • SafeArrayDestroy (Address: 0x18004eef8)
  • SafeArrayGetLBound (Address: 0x18004ef10)
  • SafeArrayGetUBound (Address: 0x18004eef0)
  • SafeArrayUnaccessData (Address: 0x18004eee0)
  • SysAllocString (Address: 0x18004eee8)
  • SysFreeString (Address: 0x18004eec0)
  • SysStringLen (Address: 0x18004ef08)
  • VariantChangeType (Address: 0x18004eeb8)
  • VariantClear (Address: 0x18004ef00)
  • VariantInit (Address: 0x18004ef20)
RPCRT4.dll
  • RpcStringFreeW (Address: 0x18004ef38)
  • UuidCreate (Address: 0x18004ef48)
  • UuidCreateSequential (Address: 0x18004ef40)
  • UuidToStringW (Address: 0x18004ef30)
Secur32.dll
  • AcceptSecurityContext (Address: 0x18004ef90)
  • AcquireCredentialsHandleW (Address: 0x18004ef68)
  • ApplyControlToken (Address: 0x18004ef70)
  • DecryptMessage (Address: 0x18004ef80)
  • DeleteSecurityContext (Address: 0x18004ef78)
  • EncryptMessage (Address: 0x18004efa8)
  • FreeContextBuffer (Address: 0x18004ef98)
  • FreeCredentialsHandle (Address: 0x18004ef60)
  • GetUserNameExW (Address: 0x18004efb0)
  • LsaFreeReturnBuffer (Address: 0x18004efa0)
  • QueryContextAttributesW (Address: 0x18004ef88)
  • QuerySecurityContextToken (Address: 0x18004ef58)
WLDAP32.dll
  • (Address: 0x18004f030)
  • (Address: 0x18004f028)
  • (Address: 0x18004f020)
  • (Address: 0x18004f018)
  • (Address: 0x18004f010)
  • (Address: 0x18004f008)
  • (Address: 0x18004f000)
  • (Address: 0x18004eff8)
  • (Address: 0x18004efc0)
  • (Address: 0x18004efc8)
  • (Address: 0x18004efd0)
  • (Address: 0x18004efd8)
  • (Address: 0x18004efe0)
  • (Address: 0x18004efe8)
  • (Address: 0x18004eff0)
WS2_32.dll
  • bind (Address: 0x18004f0a8)
  • closesocket (Address: 0x18004f0c0)
  • freeaddrinfo (Address: 0x18004f050)
  • FreeAddrInfoW (Address: 0x18004f078)
  • getaddrinfo (Address: 0x18004f048)
  • GetAddrInfoW (Address: 0x18004f058)
  • GetHostNameW (Address: 0x18004f0e0)
  • getnameinfo (Address: 0x18004f040)
  • GetNameInfoW (Address: 0x18004f068)
  • getpeername (Address: 0x18004f090)
  • getsockname (Address: 0x18004f0a0)
  • htons (Address: 0x18004f060)
  • listen (Address: 0x18004f098)
  • ntohs (Address: 0x18004f070)
  • send (Address: 0x18004f088)
  • setsockopt (Address: 0x18004f0b0)
  • shutdown (Address: 0x18004f080)
  • socket (Address: 0x18004f0d8)
  • WSACleanup (Address: 0x18004f0f8)
  • WSAGetLastError (Address: 0x18004f0d0)
  • WSAIoctl (Address: 0x18004f0c8)
  • WSASocketW (Address: 0x18004f0b8)
  • WSAStartup (Address: 0x18004f0f0)
  • WSAStringToAddressW (Address: 0x18004f0e8)