UserOOBE.dll
Description: UserOOBE
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.1265
Architecture: 64-bit
Operating System: Windows NT
SHA256: 7fb64c456bdb4db93267ee05e03391ac
File Size: 411.5 KB
Uploaded At: Dec. 1, 2025, 8:13 a.m.
Views: 14
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x5890)
- DllGetClassObject (Ordinal: 2, Address: 0x58e0)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-l1-1-1.dll
- FindPackagesByPackageFamily (Address: 0x180048da8)
api-ms-win-appmodel-state-l1-2-0.dll
- CloseState (Address: 0x180048db8)
- GetSystemAppDataKey (Address: 0x180048dc0)
- OpenStateExplicit (Address: 0x180048dc8)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180048dd8)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x180048e40)
- CoCreateFreeThreadedMarshaler (Address: 0x180048e00)
- CoCreateInstance (Address: 0x180048df0)
- CoGetApartmentType (Address: 0x180048de8)
- CoGetCallContext (Address: 0x180048e30)
- CoGetMalloc (Address: 0x180048e50)
- CoGetStdMarshalEx (Address: 0x180048e78)
- CoImpersonateClient (Address: 0x180048e10)
- CoRegisterClassObject (Address: 0x180048e18)
- CoRevertToSelf (Address: 0x180048e70)
- CoRevokeClassObject (Address: 0x180048e20)
- CoSetProxyBlanket (Address: 0x180048df8)
- CoTaskMemAlloc (Address: 0x180048e68)
- CoTaskMemFree (Address: 0x180048e60)
- CoTaskMemRealloc (Address: 0x180048e08)
- CoWaitForMultipleHandles (Address: 0x180048e38)
- StringFromCLSID (Address: 0x180048e58)
- StringFromGUID2 (Address: 0x180048e48)
- StringFromIID (Address: 0x180048e28)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x180048e88)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180048ea8)
- IsDebuggerPresent (Address: 0x180048e98)
- OutputDebugStringW (Address: 0x180048ea0)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180048eb8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180048ec8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180048ee0)
- RaiseException (Address: 0x180048ef8)
- SetLastError (Address: 0x180048ee8)
- SetUnhandledExceptionFilter (Address: 0x180048ef0)
- UnhandledExceptionFilter (Address: 0x180048ed8)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x180048f28)
- CreateFileW (Address: 0x180048f50)
- DeleteFileW (Address: 0x180048f10)
- FindClose (Address: 0x180048f18)
- FindFirstFileW (Address: 0x180048f40)
- FindNextFileW (Address: 0x180048f38)
- FlushFileBuffers (Address: 0x180048f20)
- GetFileAttributesW (Address: 0x180048f48)
- GetFileInformationByHandle (Address: 0x180048f58)
- GetFullPathNameW (Address: 0x180048f30)
- SetFileInformationByHandle (Address: 0x180048f08)
api-ms-win-core-file-l2-1-0.dll
- GetFileInformationByHandleEx (Address: 0x180048f68)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180048f78)
- DuplicateHandle (Address: 0x180048f80)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180048f98)
- HeapAlloc (Address: 0x180048fa0)
- HeapFree (Address: 0x180048f90)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180048fb0)
- LocalFree (Address: 0x180048fb8)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x180048fc8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- MulDiv (Address: 0x180048fd8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x180049028)
- FindResourceExW (Address: 0x180049038)
- FreeLibrary (Address: 0x180049030)
- GetModuleFileNameA (Address: 0x180049010)
- GetModuleFileNameW (Address: 0x180049008)
- GetModuleHandleExW (Address: 0x180048fe8)
- GetModuleHandleW (Address: 0x180049000)
- GetProcAddress (Address: 0x180049020)
- LoadLibraryExW (Address: 0x180049018)
- LoadResource (Address: 0x180048ff8)
- LockResource (Address: 0x180048ff0)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x180049048)
api-ms-win-core-path-l1-1-0.dll
- PathCchCombine (Address: 0x180049058)
api-ms-win-core-privateprofile-l1-1-0.dll
- WritePrivateProfileStringW (Address: 0x180049068)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x180049078)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessW (Address: 0x180049088)
- GetCurrentProcess (Address: 0x1800490c8)
- GetCurrentProcessId (Address: 0x180049098)
- GetCurrentThread (Address: 0x1800490b8)
- GetCurrentThreadId (Address: 0x1800490a0)
- GetProcessId (Address: 0x1800490a8)
- OpenProcessToken (Address: 0x1800490c0)
- OpenThreadToken (Address: 0x180049090)
- ProcessIdToSessionId (Address: 0x1800490d0)
- TerminateProcess (Address: 0x1800490b0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800490e0)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180049158)
- RegCreateKeyExW (Address: 0x180049150)
- RegDeleteKeyExW (Address: 0x180049110)
- RegDeleteTreeW (Address: 0x180049118)
- RegDeleteValueW (Address: 0x180049108)
- RegEnumKeyExW (Address: 0x180049128)
- RegEnumValueW (Address: 0x180049138)
- RegFlushKey (Address: 0x180049140)
- RegGetValueW (Address: 0x1800490f0)
- RegOpenCurrentUser (Address: 0x180049120)
- RegOpenKeyExW (Address: 0x180049148)
- RegQueryInfoKeyW (Address: 0x1800490f8)
- RegQueryValueExW (Address: 0x180049130)
- RegSetValueExW (Address: 0x180049100)
api-ms-win-core-registryuserspecific-l1-1-0.dll
- SHRegGetUSValueW (Address: 0x180049168)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x180049188)
- RtlLookupFunctionEntry (Address: 0x180049178)
- RtlVirtualUnwind (Address: 0x180049180)
api-ms-win-core-shutdown-l1-1-0.dll
- InitiateSystemShutdownExW (Address: 0x180049198)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1800491a8)
- CompareStringW (Address: 0x1800491b0)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180049238)
- AcquireSRWLockShared (Address: 0x180049228)
- CreateEventExW (Address: 0x180049258)
- CreateEventW (Address: 0x1800491f0)
- CreateMutexExW (Address: 0x1800491e8)
- CreateMutexW (Address: 0x1800491e0)
- CreateSemaphoreExW (Address: 0x180049270)
- DeleteCriticalSection (Address: 0x180049278)
- EnterCriticalSection (Address: 0x180049218)
- InitializeCriticalSection (Address: 0x1800491f8)
- InitializeCriticalSectionEx (Address: 0x180049208)
- InitializeSRWLock (Address: 0x180049248)
- LeaveCriticalSection (Address: 0x180049260)
- OpenEventW (Address: 0x1800491d0)
- OpenSemaphoreW (Address: 0x1800491c8)
- ReleaseMutex (Address: 0x180049240)
- ReleaseSemaphore (Address: 0x180049210)
- ReleaseSRWLockExclusive (Address: 0x180049200)
- ReleaseSRWLockShared (Address: 0x180049230)
- ResetEvent (Address: 0x1800491c0)
- SetEvent (Address: 0x180049268)
- WaitForMultipleObjectsEx (Address: 0x180049250)
- WaitForSingleObject (Address: 0x1800491d8)
- WaitForSingleObjectEx (Address: 0x180049220)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x180049290)
- InitOnceComplete (Address: 0x1800492b0)
- InitOnceExecuteOnce (Address: 0x180049288)
- Sleep (Address: 0x180049298)
- SleepConditionVariableSRW (Address: 0x1800492a0)
- WakeAllConditionVariable (Address: 0x1800492a8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetLocalTime (Address: 0x1800492c0)
- GetSystemTimeAsFileTime (Address: 0x1800492d0)
- GetTickCount (Address: 0x1800492d8)
- GetTickCount64 (Address: 0x1800492e0)
- GetVersionExW (Address: 0x1800492c8)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetProductInfo (Address: 0x1800492f0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x180049318)
- CreateThreadpoolTimer (Address: 0x180049300)
- SetThreadpoolTimer (Address: 0x180049310)
- WaitForThreadpoolTimerCallbacks (Address: 0x180049308)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueueTimer (Address: 0x180049328)
- DeleteTimerQueueTimer (Address: 0x180049330)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x180049348)
- SystemTimeToFileTime (Address: 0x180049340)
api-ms-win-core-url-l1-1-0.dll
- ParseURLW (Address: 0x180049358)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x180049368)
- EncodePointer (Address: 0x180049370)
api-ms-win-core-winrt-error-l1-1-0.dll
- RoOriginateError (Address: 0x180049388)
- RoTransformError (Address: 0x180049380)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x180049398)
- RoGetActivationFactory (Address: 0x1800493a0)
api-ms-win-core-winrt-propertysetprivate-l1-1-1.dll
- RoCreatePropertySetSerializer (Address: 0x1800493b0)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateString (Address: 0x1800493d0)
- WindowsCreateStringReference (Address: 0x1800493e0)
- WindowsDeleteString (Address: 0x1800493d8)
- WindowsDuplicateString (Address: 0x1800493c0)
- WindowsGetStringRawBuffer (Address: 0x1800493e8)
- WindowsSubstringWithSpecifiedLength (Address: 0x1800493c8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x180049410)
- GetTraceEnableLevel (Address: 0x180049400)
- GetTraceLoggerHandle (Address: 0x180049408)
- RegisterTraceGuidsW (Address: 0x1800493f8)
- TraceMessage (Address: 0x180049420)
- UnregisterTraceGuids (Address: 0x180049418)
api-ms-win-eventing-provider-l1-1-0.dll
- EventProviderEnabled (Address: 0x180049440)
- EventRegister (Address: 0x180049448)
- EventSetInformation (Address: 0x180049438)
- EventUnregister (Address: 0x180049430)
- EventWriteTransfer (Address: 0x180049450)
api-ms-win-ntuser-ie-message-l1-1-0.dll
- DispatchMessageW (Address: 0x180049470)
- MsgWaitForMultipleObjectsEx (Address: 0x180049460)
- PeekMessageW (Address: 0x180049478)
- PostQuitMessage (Address: 0x180049480)
- TranslateMessage (Address: 0x180049468)
api-ms-win-ntuser-sysparams-l1-1-0.dll
- GetMonitorInfoW (Address: 0x180049490)
- GetSystemMetrics (Address: 0x180049498)
api-ms-win-oobe-notification-l1-1-0.dll
- OOBEComplete (Address: 0x1800494a8)
api-ms-win-rtcore-ntuser-private-l1-1-0.dll
- CreateWindowInBand (Address: 0x1800494b8)
- GetWindowBand (Address: 0x1800494c0)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
- CreateWindowExW (Address: 0x180049518)
- DefWindowProcW (Address: 0x1800494d0)
- DestroyWindow (Address: 0x180049528)
- EnumWindows (Address: 0x180049510)
- FindWindowW (Address: 0x180049500)
- GetPropW (Address: 0x1800494f8)
- GetWindowThreadProcessId (Address: 0x180049508)
- IsWindowVisible (Address: 0x180049520)
- RegisterClassExW (Address: 0x1800494e0)
- SetForegroundWindow (Address: 0x1800494f0)
- SetPropW (Address: 0x180049530)
- SetWindowPos (Address: 0x180049538)
- ShowWindow (Address: 0x1800494e8)
- UnregisterClassW (Address: 0x1800494d8)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x180049568)
- AllocateAndInitializeSid (Address: 0x180049598)
- CopySid (Address: 0x180049570)
- CreateWellKnownSid (Address: 0x180049580)
- EqualSid (Address: 0x180049590)
- GetLengthSid (Address: 0x180049588)
- GetTokenInformation (Address: 0x180049560)
- ImpersonateLoggedOnUser (Address: 0x180049548)
- IsValidSid (Address: 0x180049578)
- RevertToSelf (Address: 0x180049550)
- SetTokenInformation (Address: 0x180049558)
api-ms-win-security-lsalookup-l1-1-2.dll
- LsaLookupUserAccountType (Address: 0x1800495a8)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupAccountNameW (Address: 0x1800495b8)
- LookupAccountSidW (Address: 0x1800495c8)
- LookupPrivilegeValueW (Address: 0x1800495c0)
api-ms-win-security-lsapolicy-l1-1-0.dll
- LsaClose (Address: 0x1800495f8)
- LsaFreeMemory (Address: 0x1800495e0)
- LsaLookupNames2 (Address: 0x1800495d8)
- LsaOpenPolicy (Address: 0x1800495f0)
- LsaRetrievePrivateData (Address: 0x1800495e8)
- LsaStorePrivateData (Address: 0x180049600)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x180049618)
- ConvertStringSidToSidW (Address: 0x180049610)
api-ms-win-shcore-comhelpers-l1-1-0.dll
- IUnknown_QueryService (Address: 0x180049628)
api-ms-win-shcore-obsolete-l1-1-0.dll
- SHStrDupW (Address: 0x180049638)
api-ms-win-shcore-registry-l1-1-0.dll
- SHDeleteKeyW (Address: 0x180049648)
- SHDeleteValueW (Address: 0x180049650)
api-ms-win-shcore-scaling-l1-1-1.dll
- GetDpiForMonitor (Address: 0x180049660)
api-ms-win-shcore-stream-l1-1-0.dll
- IStream_Write (Address: 0x180049670)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolQueueTask (Address: 0x180049680)
api-ms-win-shcore-thread-l1-1-0.dll
- SHCreateThreadWithHandle (Address: 0x180049698)
- SHGetThreadRef (Address: 0x180049690)
api-ms-win-stateseparation-helpers-l1-1-0.dll
- GetPersistedRegistryLocationW (Address: 0x1800496a8)
credui.dll
- CredUnPackAuthenticationBufferW (Address: 0x1800496b8)
CRYPT32.dll
- CryptProtectData (Address: 0x180048cc0)
DUI70.dll
- ?Create@RichText@DirectUI@@SAJPEAVElement@2@PEAKPEAPEAV32@@Z (Address: 0x180048cd8)
- ?Destroy@Element@DirectUI@@QEAAJ_N@Z (Address: 0x180048ce0)
- ?SetAccessible@Element@DirectUI@@QEAAJ_N@Z (Address: 0x180048d08)
- ?SetAccRole@Element@DirectUI@@QEAAJH@Z (Address: 0x180048cf0)
- ?SetConstrainLayout@RichText@DirectUI@@QEAAJH@Z (Address: 0x180048ce8)
- ?SetContentAlign@Element@DirectUI@@QEAAJH@Z (Address: 0x180048cd0)
- ?SetContentString@Element@DirectUI@@QEAAJPEBG@Z (Address: 0x180048cf8)
- ?SetID@Element@DirectUI@@QEAAJPEBG@Z (Address: 0x180048d00)
msvcrt.dll
- __C_specific_handler (Address: 0x180049738)
- __CxxFrameHandler3 (Address: 0x1800496e8)
- __dllonexit (Address: 0x180049718)
- _amsg_exit (Address: 0x180049748)
- _callnewh (Address: 0x180049758)
- _CxxThrowException (Address: 0x180049770)
- _errno (Address: 0x1800497d0)
- _get_errno (Address: 0x1800497b8)
- _initterm (Address: 0x180049740)
- _lock (Address: 0x180049728)
- _onexit (Address: 0x180049710)
- _purecall (Address: 0x1800497e0)
- _set_errno (Address: 0x1800497c0)
- _unlock (Address: 0x180049720)
- _vscwprintf (Address: 0x1800497b0)
- _vsnprintf (Address: 0x1800496c8)
- _vsnprintf_s (Address: 0x1800497e8)
- _vsnwprintf (Address: 0x180049818)
- _wcsicmp (Address: 0x1800496e0)
- _wcsnicmp (Address: 0x1800496f8)
- _XcptFilter (Address: 0x180049750)
- ??_V@YAXPEAX@Z (Address: 0x180049820)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180049788)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180049780)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800497f0)
- ??0exception@@QEAA@XZ (Address: 0x1800497f8)
- ??1exception@@UEAA@XZ (Address: 0x180049800)
- ??1type_info@@UEAA@XZ (Address: 0x180049708)
- ??3@YAXPEAX@Z (Address: 0x180049808)
- ?terminate@@YAXXZ (Address: 0x180049730)
- ?what@exception@@UEBAPEBDXZ (Address: 0x180049778)
- free (Address: 0x1800497a0)
- malloc (Address: 0x1800497a8)
- memcmp (Address: 0x180049700)
- memcpy (Address: 0x180049768)
- memcpy_s (Address: 0x180049810)
- memmove (Address: 0x180049760)
- memmove_s (Address: 0x1800497d8)
- memset (Address: 0x180049830)
- realloc (Address: 0x180049790)
- toupper (Address: 0x1800496d8)
- wcschr (Address: 0x1800496f0)
- wcscspn (Address: 0x1800496d0)
- wcsrchr (Address: 0x180049828)
- wcstok_s (Address: 0x180049798)
- wcstol (Address: 0x1800497c8)
netutils.dll
- NetApiBufferFree (Address: 0x180049840)
ntdll.dll
- NtQueryInformationToken (Address: 0x1800498b0)
- NtQueryWnfStateData (Address: 0x1800498a8)
- NtSetInformationFile (Address: 0x180049858)
- RtlAllocateHeap (Address: 0x180049868)
- RtlCompareUnicodeString (Address: 0x180049878)
- RtlFreeHeap (Address: 0x180049860)
- RtlInitString (Address: 0x1800498a0)
- RtlInitUnicodeString (Address: 0x180049880)
- RtlNtStatusToDosError (Address: 0x180049850)
- RtlNtStatusToDosErrorNoTeb (Address: 0x180049870)
- RtlPublishWnfStateData (Address: 0x180049890)
- RtlSubscribeWnfStateChangeNotification (Address: 0x180049888)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x180049898)
ole32.dll
- CoAllowSetForegroundWindow (Address: 0x1800498c0)
OLEAUT32.dll
- SysAllocString (Address: 0x180048d18)
- SysFreeString (Address: 0x180048d20)
policymanager.dll
- PolicyManager_FreeGetPolicyData (Address: 0x1800498d8)
- PolicyManager_GetPolicy (Address: 0x1800498d0)
samcli.dll
- NetLocalGroupDelMembers (Address: 0x180049900)
- NetUserDel (Address: 0x1800498f0)
- NetUserGetInfo (Address: 0x1800498e8)
- NetUserSetInfo (Address: 0x1800498f8)
SHCORE.dll
- (Address: 0x180048d30)
SLC.dll
- SLGetWindowsInformationDWORD (Address: 0x180048d40)
USER32.dll
- CallNextHookEx (Address: 0x180048d78)
- GetAsyncKeyState (Address: 0x180048d70)
- LoadCursorW (Address: 0x180048d50)
- MonitorFromPoint (Address: 0x180048d58)
- MonitorFromWindow (Address: 0x180048d80)
- SetCursor (Address: 0x180048d88)
- SetWindowsHookExW (Address: 0x180048d60)
- UnhookWindowsHookEx (Address: 0x180048d68)
USERENV.dll
- DeleteProfileW (Address: 0x180048d98)
wkscli.dll
- NetGetJoinInformation (Address: 0x180049910)