mqqm.dll
Description: Message Queuing Manager
Authors: © Microsoft Corporation. All rights reserved.
Version: 5.0.1.1
Architecture: 64-bit
Operating System: Windows NT
SHA256: f239bdf07356cc17d4cc6b1d5ba6d6f3
File Size: 1.4 MB
Uploaded At: Dec. 1, 2025, 8:13 a.m.
Views: 15
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- QMMain (Ordinal: 1, Address: 0x2ff20)
Imported DLLs & Functions
ACTIVEDS.dll
- (Address: 0x18010c590)
- (Address: 0x18010c598)
ADVAPI32.dll
- AddAccessAllowedAce (Address: 0x18010c7f8)
- ConvertSidToStringSidW (Address: 0x18010c6c0)
- CopySid (Address: 0x18010c5c0)
- CryptAcquireContextW (Address: 0x18010c770)
- CryptCreateHash (Address: 0x18010c618)
- CryptDecrypt (Address: 0x18010c788)
- CryptDestroyHash (Address: 0x18010c650)
- CryptDestroyKey (Address: 0x18010c6b0)
- CryptEncrypt (Address: 0x18010c6f0)
- CryptExportKey (Address: 0x18010c6e8)
- CryptGenKey (Address: 0x18010c6e0)
- CryptGenRandom (Address: 0x18010c750)
- CryptGetHashParam (Address: 0x18010c758)
- CryptGetUserKey (Address: 0x18010c7c0)
- CryptHashData (Address: 0x18010c760)
- CryptImportKey (Address: 0x18010c6f8)
- CryptReleaseContext (Address: 0x18010c778)
- CryptSetKeyParam (Address: 0x18010c780)
- CryptVerifySignatureW (Address: 0x18010c848)
- EnableTrace (Address: 0x18010c738)
- EqualSid (Address: 0x18010c768)
- EventActivityIdControl (Address: 0x18010c5b8)
- EventEnabled (Address: 0x18010c5b0)
- EventRegister (Address: 0x18010c7b0)
- EventSetInformation (Address: 0x18010c7a8)
- EventUnregister (Address: 0x18010c7b8)
- EventWrite (Address: 0x18010c5a8)
- EventWriteTransfer (Address: 0x18010c7f0)
- GetAce (Address: 0x18010c6c8)
- GetAclInformation (Address: 0x18010c6d0)
- GetFileSecurityW (Address: 0x18010c658)
- GetLengthSid (Address: 0x18010c7e0)
- GetSecurityDescriptorControl (Address: 0x18010c6a8)
- GetSecurityDescriptorDacl (Address: 0x18010c6d8)
- GetSecurityDescriptorGroup (Address: 0x18010c810)
- GetSecurityDescriptorLength (Address: 0x18010c828)
- GetSecurityDescriptorOwner (Address: 0x18010c7e8)
- GetSecurityDescriptorSacl (Address: 0x18010c6a0)
- GetTokenInformation (Address: 0x18010c5d0)
- GetTraceEnableFlags (Address: 0x18010c638)
- GetTraceEnableLevel (Address: 0x18010c640)
- GetTraceLoggerHandle (Address: 0x18010c648)
- InitializeAcl (Address: 0x18010c7d0)
- InitializeSecurityDescriptor (Address: 0x18010c800)
- IsValidRelativeSecurityDescriptor (Address: 0x18010c5c8)
- IsValidSecurityDescriptor (Address: 0x18010c7c8)
- IsValidSid (Address: 0x18010c838)
- LookupAccountNameW (Address: 0x18010c840)
- LookupAccountSidW (Address: 0x18010c6b8)
- MakeSelfRelativeSD (Address: 0x18010c830)
- OpenProcessToken (Address: 0x18010c5d8)
- PerfCreateInstance (Address: 0x18010c5f8)
- PerfDeleteInstance (Address: 0x18010c5e8)
- PerfSetCounterRefValue (Address: 0x18010c5f0)
- PerfSetCounterSetInfo (Address: 0x18010c600)
- PerfStartProviderEx (Address: 0x18010c608)
- PerfStopProvider (Address: 0x18010c610)
- QueryTraceW (Address: 0x18010c748)
- RegCloseKey (Address: 0x18010c7a0)
- RegCreateKeyExW (Address: 0x18010c680)
- RegCreateKeyTransactedW (Address: 0x18010c688)
- RegDeleteValueW (Address: 0x18010c670)
- RegEnumKeyExW (Address: 0x18010c660)
- RegEnumValueW (Address: 0x18010c5e0)
- RegGetValueW (Address: 0x18010c620)
- RegisterEventSourceW (Address: 0x18010c720)
- RegisterServiceCtrlHandlerW (Address: 0x18010c708)
- RegisterTraceGuidsW (Address: 0x18010c630)
- RegOpenKeyExW (Address: 0x18010c798)
- RegOpenKeyTransactedW (Address: 0x18010c668)
- RegQueryInfoKeyW (Address: 0x18010c678)
- RegQueryValueExW (Address: 0x18010c790)
- RegSetValueExW (Address: 0x18010c690)
- ReportEventW (Address: 0x18010c718)
- SetFileSecurityW (Address: 0x18010c698)
- SetSecurityDescriptorDacl (Address: 0x18010c820)
- SetSecurityDescriptorGroup (Address: 0x18010c818)
- SetSecurityDescriptorOwner (Address: 0x18010c808)
- SetServiceStatus (Address: 0x18010c700)
- StartServiceCtrlDispatcherW (Address: 0x18010c710)
- StartTraceW (Address: 0x18010c730)
- StopTraceW (Address: 0x18010c740)
- TraceEvent (Address: 0x18010c728)
- TraceMessage (Address: 0x18010c7d8)
- UnregisterTraceGuids (Address: 0x18010c628)
AUTHZ.dll
- AuthzAccessCheck (Address: 0x18010c870)
- AuthzFreeContext (Address: 0x18010c880)
- AuthzFreeResourceManager (Address: 0x18010c878)
- AuthzGetInformationFromContext (Address: 0x18010c868)
- AuthzInitializeContextFromSid (Address: 0x18010c860)
- AuthzInitializeResourceManager (Address: 0x18010c858)
bcrypt.dll
- BCryptGenRandom (Address: 0x18010d068)
CLUSAPI.dll
- CloseCluster (Address: 0x18010c8c0)
- CloseClusterResource (Address: 0x18010c8c8)
- ClusterResourceCloseEnum (Address: 0x18010c8b0)
- ClusterResourceControl (Address: 0x18010c890)
- ClusterResourceEnum (Address: 0x18010c8a0)
- ClusterResourceOpenEnum (Address: 0x18010c898)
- OpenCluster (Address: 0x18010c8b8)
- OpenClusterResource (Address: 0x18010c8a8)
CRYPT32.dll
- CertCloseStore (Address: 0x18010c8d8)
- CertFindCertificateInStore (Address: 0x18010c900)
- CertFreeCertificateChain (Address: 0x18010c8f8)
- CertFreeCertificateContext (Address: 0x18010c908)
- CertGetCertificateChain (Address: 0x18010c8e8)
- CertOpenStore (Address: 0x18010c910)
- CertOpenSystemStoreW (Address: 0x18010c8f0)
- CertVerifyCertificateChainPolicy (Address: 0x18010c8e0)
DSPARSE.dll
- DsMakeSpnW (Address: 0x18010c920)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18010ca58)
- AcquireSRWLockShared (Address: 0x18010ca68)
- CloseHandle (Address: 0x18010ca80)
- CloseThreadpoolTimer (Address: 0x18010caa8)
- CompareStringW (Address: 0x18010cb60)
- CopyFileExW (Address: 0x18010cba8)
- CopyFileW (Address: 0x18010c938)
- CreateDirectoryW (Address: 0x18010cca0)
- CreateEventW (Address: 0x18010cbf8)
- CreateFileA (Address: 0x18010ccb0)
- CreateFileMappingW (Address: 0x18010cc20)
- CreateFileW (Address: 0x18010cb28)
- CreateIoCompletionPort (Address: 0x18010c970)
- CreateMutexExW (Address: 0x18010caf8)
- CreateSemaphoreExW (Address: 0x18010cb00)
- CreateSemaphoreW (Address: 0x18010c968)
- CreateThread (Address: 0x18010cc30)
- CreateThreadpoolTimer (Address: 0x18010cae0)
- DebugBreak (Address: 0x18010ca28)
- DeleteCriticalSection (Address: 0x18010cac8)
- DeleteFileW (Address: 0x18010cbc8)
- DuplicateHandle (Address: 0x18010cb50)
- EnterCriticalSection (Address: 0x18010cab8)
- ExitProcess (Address: 0x18010cc40)
- ExpandEnvironmentStringsW (Address: 0x18010c960)
- FindClose (Address: 0x18010cb78)
- FindFirstFileW (Address: 0x18010cb88)
- FindNextFileW (Address: 0x18010cb90)
- FlushFileBuffers (Address: 0x18010cb80)
- FlushViewOfFile (Address: 0x18010cb70)
- FormatMessageW (Address: 0x18010c9f0)
- FreeLibrary (Address: 0x18010c930)
- GetComputerNameExW (Address: 0x18010cb38)
- GetComputerNameW (Address: 0x18010cb40)
- GetCurrentProcess (Address: 0x18010cb58)
- GetCurrentProcessId (Address: 0x18010caf0)
- GetCurrentThreadId (Address: 0x18010c9f8)
- GetDateFormatW (Address: 0x18010cb18)
- GetExitCodeThread (Address: 0x18010ccc8)
- GetFileAttributesW (Address: 0x18010cc90)
- GetFileSize (Address: 0x18010cbd8)
- GetLastError (Address: 0x18010ca40)
- GetLocalTime (Address: 0x18010cb10)
- GetModuleFileNameA (Address: 0x18010ca20)
- GetModuleHandleExW (Address: 0x18010ca18)
- GetModuleHandleW (Address: 0x18010ca30)
- GetPrivateProfileStringW (Address: 0x18010cbd0)
- GetProcAddress (Address: 0x18010ca38)
- GetProcessHeap (Address: 0x18010ca08)
- GetQueuedCompletionStatus (Address: 0x18010c980)
- GetSystemInfo (Address: 0x18010cbe8)
- GetSystemTimeAsFileTime (Address: 0x18010cb48)
- GetTickCount (Address: 0x18010cc50)
- GetTimeFormatW (Address: 0x18010cb20)
- GetVersionExW (Address: 0x18010cc10)
- HeapAlloc (Address: 0x18010ca00)
- HeapFree (Address: 0x18010ca10)
- HeapSetInformation (Address: 0x18010c998)
- InitializeCriticalSection (Address: 0x18010cb08)
- InitializeCriticalSectionAndSpinCount (Address: 0x18010cb30)
- InitializeCriticalSectionEx (Address: 0x18010cac0)
- IsDebuggerPresent (Address: 0x18010ca48)
- LeaveCriticalSection (Address: 0x18010cae8)
- LoadLibraryExW (Address: 0x18010c940)
- LoadLibraryW (Address: 0x18010ccb8)
- LocalAlloc (Address: 0x18010c990)
- LocalFree (Address: 0x18010cc58)
- MapViewOfFile (Address: 0x18010cc28)
- MoveFileExW (Address: 0x18010cbb8)
- MultiByteToWideChar (Address: 0x18010cc48)
- OpenProcess (Address: 0x18010cc38)
- OpenSemaphoreW (Address: 0x18010cad8)
- OutputDebugStringA (Address: 0x18010c9c8)
- OutputDebugStringW (Address: 0x18010ca50)
- PostQueuedCompletionStatus (Address: 0x18010c978)
- PulseEvent (Address: 0x18010ccc0)
- QueryPerformanceCounter (Address: 0x18010c9e0)
- ReadFile (Address: 0x18010cbe0)
- ReleaseMutex (Address: 0x18010ca90)
- ReleaseSemaphore (Address: 0x18010ca88)
- ReleaseSRWLockExclusive (Address: 0x18010ca60)
- ReleaseSRWLockShared (Address: 0x18010ca70)
- RemoveDirectoryW (Address: 0x18010ccd0)
- ReplaceFileW (Address: 0x18010cbc0)
- ResetEvent (Address: 0x18010cc88)
- RtlCaptureContext (Address: 0x18010c9a0)
- RtlLookupFunctionEntry (Address: 0x18010c9a8)
- RtlVirtualUnwind (Address: 0x18010c9b0)
- SetEnvironmentVariableW (Address: 0x18010cbf0)
- SetEvent (Address: 0x18010cc78)
- SetFileAttributesW (Address: 0x18010cbb0)
- SetFilePointer (Address: 0x18010cca8)
- SetLastError (Address: 0x18010ca78)
- SetProcessMitigationPolicy (Address: 0x18010cc00)
- SetThreadpoolTimer (Address: 0x18010ca98)
- SetThreadStackGuarantee (Address: 0x18010c9e8)
- SetUnhandledExceptionFilter (Address: 0x18010c9b8)
- Sleep (Address: 0x18010cb68)
- SleepConditionVariableSRW (Address: 0x18010c9d8)
- SystemTimeToFileTime (Address: 0x18010c988)
- TerminateProcess (Address: 0x18010c9c0)
- TlsAlloc (Address: 0x18010cc60)
- TlsGetValue (Address: 0x18010cc68)
- TlsSetValue (Address: 0x18010cc70)
- UnhandledExceptionFilter (Address: 0x18010cc08)
- UnmapViewOfFile (Address: 0x18010cc18)
- VirtualAlloc (Address: 0x18010c950)
- VirtualProtect (Address: 0x18010c948)
- VirtualQuery (Address: 0x18010c958)
- WaitForMultipleObjects (Address: 0x18010cc80)
- WaitForSingleObject (Address: 0x18010cad0)
- WaitForSingleObjectEx (Address: 0x18010cab0)
- WaitForThreadpoolTimerCallbacks (Address: 0x18010caa0)
- WakeAllConditionVariable (Address: 0x18010c9d0)
- WideCharToMultiByte (Address: 0x18010cc98)
- WriteFile (Address: 0x18010cba0)
- WritePrivateProfileStringW (Address: 0x18010cb98)
ktmw32.dll
- CommitTransaction (Address: 0x18010d080)
- CreateTransaction (Address: 0x18010d078)
mqsec.dll
- ??0CColumns@@QEAA@I@Z (Address: 0x18010d240)
- ??0CDSBaseUpdate@@QEAA@XZ (Address: 0x18010d298)
- ??1CColumns@@QEAA@XZ (Address: 0x18010d248)
- ??1CDSBaseUpdate@@QEAA@XZ (Address: 0x18010d288)
- ?Add@CColumns@@QEAAXAEBK@Z (Address: 0x18010d250)
- ?GetFalconSectionName@@YAJAEAV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator_static@_W@2@V_STL70@@@std@@@Z (Address: 0x18010d200)
- ?GetObjectType@CDSBaseUpdate@@QEAAKXZ (Address: 0x18010d290)
- ?Init@CCancelRpc@@QEAAXXZ (Address: 0x18010d208)
- ?Init@CDSBaseUpdate@@QEAAJPEAVBufferReader@@H@Z (Address: 0x18010d280)
- ?KeepErrorHistory@COutputReport@@QEAAXPEB_WGJ@Z (Address: 0x18010d228)
- ComposeRPCEndPointName (Address: 0x18010d110)
- DeleteFalconKeyValue (Address: 0x18010d130)
- g_CancelRpc (Address: 0x18010d210)
- g_hProvVer (Address: 0x18010d0e0)
- GetComputerDnsNameInternal (Address: 0x18010d1f0)
- GetComputerNameInternal (Address: 0x18010d1e8)
- GetDomainFQDNName (Address: 0x18010d1c8)
- GetFalconKey (Address: 0x18010d238)
- GetFalconKeyValue (Address: 0x18010d128)
- GetFalconServiceName (Address: 0x18010d268)
- HashMessageProperties (Address: 0x18010d0d8)
- IdnNameCompare (Address: 0x18010d270)
- IsLocalSystemCluster (Address: 0x18010d1e0)
- mqrpcBindQMService (Address: 0x18010d120)
- mqrpcIsLocalCall (Address: 0x18010d258)
- mqrpcIsTcpipTransport (Address: 0x18010d118)
- MQSec_AccessCheck (Address: 0x18010d1c0)
- MQSec_AcquireCryptoProvider (Address: 0x18010d218)
- MQSec_CalculateServiceSid (Address: 0x18010d170)
- MQSec_CanGenerateAudit (Address: 0x18010d0e8)
- MQSec_ChooseBestAlgorithm (Address: 0x18010d090)
- MQSec_ConvertSDToNT4Format (Address: 0x18010d1a0)
- MQSec_CopySecurityDescriptor (Address: 0x18010d1b0)
- MQSec_GetAdminSid (Address: 0x18010d180)
- MQSec_GetAnonymousSid (Address: 0x18010d178)
- MQSec_GetDefaultPrivateQueueSecurityDescriptor (Address: 0x18010d190)
- MQSec_GetDefaultPublicQueueSecurityDescriptor (Address: 0x18010d260)
- MQSec_GetDefaultQueueAuthentication (Address: 0x18010d1a8)
- MQSec_GetDefaultSecDescriptor (Address: 0x18010d148)
- MQSec_GetImpersonationObject (Address: 0x18010d0f8)
- MQSec_GetLocalMachineSid (Address: 0x18010d198)
- MQSec_GetNetworkServiceSid (Address: 0x18010d188)
- MQSec_GetPrivLevelForProvider (Address: 0x18010d0c0)
- MQSec_GetProviderForPrivLevel (Address: 0x18010d2a0)
- MQSec_GetPubKeysFromDS (Address: 0x18010d0a8)
- MQSec_GetWorldSid (Address: 0x18010d150)
- MQSec_IsDC (Address: 0x18010d1d0)
- MQSec_IsWeakHashAlgorithm (Address: 0x18010d0c8)
- MQSec_MakeAbsoluteSD (Address: 0x18010d1b8)
- MQSec_MakeSelfRelative (Address: 0x18010d158)
- MQSec_RemovePrivilegesFromProcessToken (Address: 0x18010d1d8)
- MQSec_RpcAuthnLevel (Address: 0x18010d0f0)
- MQSec_SetDirectorySecurityForService (Address: 0x18010d0b8)
- MQSec_SetPrivilegeInThread (Address: 0x18010d278)
- MQSec_StorePubKeys (Address: 0x18010d160)
- MQSec_StorePubKeysInDS (Address: 0x18010d0b0)
- MQSec_TraceThreadTokenInfo (Address: 0x18010d100)
- MQSec_UpdateLocalMachineSid (Address: 0x18010d140)
- MQSigCreateCertificate (Address: 0x18010d108)
- MQSigHashMessageProperties (Address: 0x18010d0d0)
- MQUInitGlobalScurityVars (Address: 0x18010d220)
- MSMQGetOperatingSystem (Address: 0x18010d168)
- ProduceRPCErrorTracing (Address: 0x18010d2a8)
- Report (Address: 0x18010d230)
- SetFalconKeyValue (Address: 0x18010d138)
- SetFalconServiceName (Address: 0x18010d1f8)
- XactGetDTC (Address: 0x18010d098)
- XactGetWhereabouts (Address: 0x18010d0a0)
mqutil.dll
- MQGetResourceHandle (Address: 0x18010d2b8)
msvcrt.dll
- ___lc_codepage_func (Address: 0x18010d418)
- ___lc_handle_func (Address: 0x18010d420)
- ___mb_cur_max_func (Address: 0x18010d430)
- __C_specific_handler (Address: 0x18010d5b8)
- __crtGetStringTypeW (Address: 0x18010d3e0)
- __crtLCMapStringA (Address: 0x18010d400)
- __crtLCMapStringW (Address: 0x18010d3e8)
- __CxxFrameHandler3 (Address: 0x18010d568)
- __dllonexit (Address: 0x18010d348)
- __mb_cur_max (Address: 0x18010d3f0)
- __pctype_func (Address: 0x18010d410)
- __uncaught_exception (Address: 0x18010d3d0)
- _amsg_exit (Address: 0x18010d2d0)
- _CxxThrowException (Address: 0x18010d440)
- _errno (Address: 0x18010d428)
- _initterm (Address: 0x18010d2d8)
- _itow_s (Address: 0x18010d4a8)
- _lock (Address: 0x18010d2f0)
- _ltow (Address: 0x18010d530)
- _onexit (Address: 0x18010d308)
- _purecall (Address: 0x18010d538)
- _resetstkoflw (Address: 0x18010d450)
- _snscanf_s (Address: 0x18010d3c0)
- _snwscanf_s (Address: 0x18010d548)
- _strnicmp (Address: 0x18010d358)
- _unlock (Address: 0x18010d2f8)
- _vsnprintf (Address: 0x18010d3b8)
- _vsnprintf_s (Address: 0x18010d588)
- _vsnwprintf (Address: 0x18010d5b0)
- _waccess (Address: 0x18010d4f0)
- _wcsicmp (Address: 0x18010d510)
- _wcsnicmp (Address: 0x18010d4f8)
- _wstrtime (Address: 0x18010d480)
- _wtoi (Address: 0x18010d478)
- _wtoi64 (Address: 0x18010d3a8)
- _wtol (Address: 0x18010d4a0)
- _XcptFilter (Address: 0x18010d2c8)
- ?_set_se_translator@@YAP6AXIPEAU_EXCEPTION_POINTERS@@@ZP6AXI0@Z@Z (Address: 0x18010d4e0)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18010d528)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18010d540)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x18010d5a8)
- ??0exception@@QEAA@XZ (Address: 0x18010d598)
- ??1exception@@UEAA@XZ (Address: 0x18010d5a0)
- ??1type_info@@UEAA@XZ (Address: 0x18010d2e0)
- ?set_terminate@@YAP6AXXZP6AXXZ@Z (Address: 0x18010d4d8)
- ?terminate@@YAXXZ (Address: 0x18010d2e8)
- ?what@exception@@UEBAPEBDXZ (Address: 0x18010d580)
- abort (Address: 0x18010d300)
- atoi (Address: 0x18010d360)
- exit (Address: 0x18010d460)
- free (Address: 0x18010d448)
- gmtime (Address: 0x18010d3c8)
- isalnum (Address: 0x18010d560)
- isalpha (Address: 0x18010d490)
- iscntrl (Address: 0x18010d5c0)
- isdigit (Address: 0x18010d558)
- isgraph (Address: 0x18010d550)
- islower (Address: 0x18010d3d8)
- isprint (Address: 0x18010d340)
- ispunct (Address: 0x18010d338)
- isspace (Address: 0x18010d4c0)
- isupper (Address: 0x18010d408)
- iswalpha (Address: 0x18010d350)
- iswdigit (Address: 0x18010d470)
- iswspace (Address: 0x18010d468)
- isxdigit (Address: 0x18010d4c8)
- localeconv (Address: 0x18010d380)
- malloc (Address: 0x18010d3f8)
- memchr (Address: 0x18010d330)
- memcmp (Address: 0x18010d328)
- memcpy (Address: 0x18010d320)
- memcpy_s (Address: 0x18010d590)
- memmove (Address: 0x18010d318)
- memmove_s (Address: 0x18010d578)
- memset (Address: 0x18010d310)
- rand (Address: 0x18010d498)
- rand_s (Address: 0x18010d390)
- setlocale (Address: 0x18010d438)
- sprintf_s (Address: 0x18010d378)
- srand (Address: 0x18010d368)
- strchr (Address: 0x18010d3a0)
- strcspn (Address: 0x18010d388)
- strncmp (Address: 0x18010d398)
- strtoul (Address: 0x18010d4d0)
- swscanf_s (Address: 0x18010d488)
- time (Address: 0x18010d520)
- towupper (Address: 0x18010d370)
- wcschr (Address: 0x18010d518)
- wcscmp (Address: 0x18010d5c8)
- wcscspn (Address: 0x18010d4b8)
- wcsncmp (Address: 0x18010d570)
- wcspbrk (Address: 0x18010d500)
- wcsrchr (Address: 0x18010d508)
- wcsspn (Address: 0x18010d4b0)
- wcsstr (Address: 0x18010d4e8)
- wcstombs (Address: 0x18010d458)
- wcstoul (Address: 0x18010d3b0)
NETAPI32.dll
- DsGetDcNameW (Address: 0x18010cce8)
- NetApiBufferFree (Address: 0x18010ccf0)
- NetGetJoinInformation (Address: 0x18010cce0)
ntdll.dll
- NtClose (Address: 0x18010d5e0)
- NtDeviceIoControlFile (Address: 0x18010d5e8)
- NtOpenEvent (Address: 0x18010d600)
- RtlImageNtHeader (Address: 0x18010d5d8)
- RtlInitUnicodeString (Address: 0x18010d608)
- RtlIpv4AddressToStringW (Address: 0x18010d5f8)
- RtlIpv6AddressToStringA (Address: 0x18010d610)
- RtlIpv6AddressToStringW (Address: 0x18010d5f0)
ole32.dll
- CoTaskMemFree (Address: 0x18010d620)
- IIDFromString (Address: 0x18010d630)
- StringFromGUID2 (Address: 0x18010d628)
OLEAUT32.dll
- BSTR_UserFree (Address: 0x18010cd60)
- BSTR_UserFree64 (Address: 0x18010cd30)
- BSTR_UserMarshal (Address: 0x18010cd70)
- BSTR_UserMarshal64 (Address: 0x18010cd18)
- BSTR_UserSize (Address: 0x18010cd98)
- BSTR_UserSize64 (Address: 0x18010cd28)
- BSTR_UserUnmarshal (Address: 0x18010cd78)
- BSTR_UserUnmarshal64 (Address: 0x18010cd50)
- LPSAFEARRAY_UserFree (Address: 0x18010cd90)
- LPSAFEARRAY_UserFree64 (Address: 0x18010cd48)
- LPSAFEARRAY_UserMarshal (Address: 0x18010cd38)
- LPSAFEARRAY_UserMarshal64 (Address: 0x18010cd80)
- LPSAFEARRAY_UserSize (Address: 0x18010cd58)
- LPSAFEARRAY_UserSize64 (Address: 0x18010cd68)
- LPSAFEARRAY_UserUnmarshal (Address: 0x18010cd88)
- LPSAFEARRAY_UserUnmarshal64 (Address: 0x18010cd40)
- SysFreeString (Address: 0x18010cd20)
- SysStringLen (Address: 0x18010cd10)
- VariantClear (Address: 0x18010cd08)
- VariantInit (Address: 0x18010cd00)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x18010ce38)
- I_RpcServerUseProtseq2W (Address: 0x18010ce10)
- I_RpcServerUseProtseqEp2W (Address: 0x18010ce18)
- Ndr64AsyncClientCall (Address: 0x18010ce50)
- Ndr64AsyncServerCallAll (Address: 0x18010ce68)
- NdrAsyncServerCall (Address: 0x18010ce58)
- NdrClientCall3 (Address: 0x18010ceb8)
- NdrServerCall2 (Address: 0x18010ce70)
- NdrServerCallAll (Address: 0x18010ce60)
- RpcAsyncAbortCall (Address: 0x18010cdc8)
- RpcAsyncCompleteCall (Address: 0x18010cdd8)
- RpcAsyncInitializeHandle (Address: 0x18010cdd0)
- RpcBindingFree (Address: 0x18010ce98)
- RpcBindingInqAuthClientW (Address: 0x18010cea0)
- RpcBindingInqAuthInfoW (Address: 0x18010ce30)
- RpcBindingServerFromClient (Address: 0x18010cdc0)
- RpcBindingSetOption (Address: 0x18010ce48)
- RpcBindingToStringBindingW (Address: 0x18010cdb8)
- RpcEpRegisterW (Address: 0x18010cdf0)
- RpcMgmtSetComTimeout (Address: 0x18010ce40)
- RpcMgmtStopServerListening (Address: 0x18010ce90)
- RpcRaiseException (Address: 0x18010ce80)
- RpcServerInqBindings (Address: 0x18010cde8)
- RpcServerInqCallAttributesW (Address: 0x18010ce20)
- RpcServerListen (Address: 0x18010ce88)
- RpcServerRegisterAuthInfoW (Address: 0x18010cde0)
- RpcServerRegisterIf2 (Address: 0x18010cea8)
- RpcServerRegisterIfEx (Address: 0x18010cdf8)
- RpcServerUseProtseqEpW (Address: 0x18010ce08)
- RpcServerUseProtseqW (Address: 0x18010ce00)
- RpcSsDestroyClientContext (Address: 0x18010ceb0)
- RpcStringBindingParseW (Address: 0x18010cdb0)
- RpcStringFreeW (Address: 0x18010cda8)
- UuidCreate (Address: 0x18010ce78)
- UuidToStringW (Address: 0x18010ce28)
Secur32.dll
- AcquireCredentialsHandleW (Address: 0x18010cee0)
- DecryptMessage (Address: 0x18010cf08)
- DeleteSecurityContext (Address: 0x18010cee8)
- EncryptMessage (Address: 0x18010cf10)
- FreeContextBuffer (Address: 0x18010cef0)
- FreeCredentialsHandle (Address: 0x18010ced8)
- GetComputerObjectNameW (Address: 0x18010cf20)
- GetUserNameExW (Address: 0x18010cf18)
- InitializeSecurityContextW (Address: 0x18010cef8)
- QueryContextAttributesW (Address: 0x18010cf00)
SHELL32.dll
- SHGetKnownFolderPath (Address: 0x18010cec8)
USER32.dll
- CharLowerW (Address: 0x18010cf30)
- LoadStringW (Address: 0x18010cf38)
VSSAPI.DLL
- CreateWriter (Address: 0x18010cf48)
WINHTTP.dll
- WinHttpCrackUrl (Address: 0x18010cf58)
- WinHttpCreateUrl (Address: 0x18010cf60)
WS2_32.dll
- freeaddrinfo (Address: 0x18010cf80)
- FreeAddrInfoW (Address: 0x18010cfb8)
- getaddrinfo (Address: 0x18010cf88)
- GetAddrInfoW (Address: 0x18010cfc0)
- WSAAddressToStringW (Address: 0x18010cfa0)
- WSAConnect (Address: 0x18010cf90)
- WSAEnumProtocolsW (Address: 0x18010cf98)
- WSAIoctl (Address: 0x18010cfb0)
- WSARecv (Address: 0x18010cf70)
- WSASend (Address: 0x18010cf78)
- WSASocketW (Address: 0x18010cfa8)
- WSAStringToAddressW (Address: 0x18010cfc8)
WSOCK32.dll
- __WSAFDIsSet (Address: 0x18010cfe0)
- accept (Address: 0x18010cfd8)
- AcceptEx (Address: 0x18010d050)
- bind (Address: 0x18010d020)
- closesocket (Address: 0x18010cfe8)
- GetAcceptExSockaddrs (Address: 0x18010d048)
- getsockopt (Address: 0x18010d030)
- htons (Address: 0x18010d028)
- inet_ntoa (Address: 0x18010cff0)
- listen (Address: 0x18010d000)
- recvfrom (Address: 0x18010d010)
- select (Address: 0x18010d018)
- sendto (Address: 0x18010cff8)
- setsockopt (Address: 0x18010d038)
- socket (Address: 0x18010d008)
- WSAGetLastError (Address: 0x18010d040)
- WSAStartup (Address: 0x18010d058)