UserOOBE.dll

Description: UserOOBE

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1265

Architecture: 64-bit

Operating System: Windows NT

SHA256: 7fb64c456bdb4db93267ee05e03391ac

File Size: 411.5 KB

Uploaded At: Dec. 1, 2025, 8:13 a.m.

Views: 14

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x5890)
  • DllGetClassObject (Ordinal: 2, Address: 0x58e0)

Imported DLLs & Functions

api-ms-win-appmodel-runtime-l1-1-1.dll
  • FindPackagesByPackageFamily (Address: 0x180048da8)
api-ms-win-appmodel-state-l1-2-0.dll
  • CloseState (Address: 0x180048db8)
  • GetSystemAppDataKey (Address: 0x180048dc0)
  • OpenStateExplicit (Address: 0x180048dc8)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180048dd8)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x180048e40)
  • CoCreateFreeThreadedMarshaler (Address: 0x180048e00)
  • CoCreateInstance (Address: 0x180048df0)
  • CoGetApartmentType (Address: 0x180048de8)
  • CoGetCallContext (Address: 0x180048e30)
  • CoGetMalloc (Address: 0x180048e50)
  • CoGetStdMarshalEx (Address: 0x180048e78)
  • CoImpersonateClient (Address: 0x180048e10)
  • CoRegisterClassObject (Address: 0x180048e18)
  • CoRevertToSelf (Address: 0x180048e70)
  • CoRevokeClassObject (Address: 0x180048e20)
  • CoSetProxyBlanket (Address: 0x180048df8)
  • CoTaskMemAlloc (Address: 0x180048e68)
  • CoTaskMemFree (Address: 0x180048e60)
  • CoTaskMemRealloc (Address: 0x180048e08)
  • CoWaitForMultipleHandles (Address: 0x180048e38)
  • StringFromCLSID (Address: 0x180048e58)
  • StringFromGUID2 (Address: 0x180048e48)
  • StringFromIID (Address: 0x180048e28)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x180048e88)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180048ea8)
  • IsDebuggerPresent (Address: 0x180048e98)
  • OutputDebugStringW (Address: 0x180048ea0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180048eb8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180048ec8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180048ee0)
  • RaiseException (Address: 0x180048ef8)
  • SetLastError (Address: 0x180048ee8)
  • SetUnhandledExceptionFilter (Address: 0x180048ef0)
  • UnhandledExceptionFilter (Address: 0x180048ed8)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x180048f28)
  • CreateFileW (Address: 0x180048f50)
  • DeleteFileW (Address: 0x180048f10)
  • FindClose (Address: 0x180048f18)
  • FindFirstFileW (Address: 0x180048f40)
  • FindNextFileW (Address: 0x180048f38)
  • FlushFileBuffers (Address: 0x180048f20)
  • GetFileAttributesW (Address: 0x180048f48)
  • GetFileInformationByHandle (Address: 0x180048f58)
  • GetFullPathNameW (Address: 0x180048f30)
  • SetFileInformationByHandle (Address: 0x180048f08)
api-ms-win-core-file-l2-1-0.dll
  • GetFileInformationByHandleEx (Address: 0x180048f68)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180048f78)
  • DuplicateHandle (Address: 0x180048f80)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180048f98)
  • HeapAlloc (Address: 0x180048fa0)
  • HeapFree (Address: 0x180048f90)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180048fb0)
  • LocalFree (Address: 0x180048fb8)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x180048fc8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • MulDiv (Address: 0x180048fd8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180049028)
  • FindResourceExW (Address: 0x180049038)
  • FreeLibrary (Address: 0x180049030)
  • GetModuleFileNameA (Address: 0x180049010)
  • GetModuleFileNameW (Address: 0x180049008)
  • GetModuleHandleExW (Address: 0x180048fe8)
  • GetModuleHandleW (Address: 0x180049000)
  • GetProcAddress (Address: 0x180049020)
  • LoadLibraryExW (Address: 0x180049018)
  • LoadResource (Address: 0x180048ff8)
  • LockResource (Address: 0x180048ff0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180049048)
api-ms-win-core-path-l1-1-0.dll
  • PathCchCombine (Address: 0x180049058)
api-ms-win-core-privateprofile-l1-1-0.dll
  • WritePrivateProfileStringW (Address: 0x180049068)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x180049078)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x180049088)
  • GetCurrentProcess (Address: 0x1800490c8)
  • GetCurrentProcessId (Address: 0x180049098)
  • GetCurrentThread (Address: 0x1800490b8)
  • GetCurrentThreadId (Address: 0x1800490a0)
  • GetProcessId (Address: 0x1800490a8)
  • OpenProcessToken (Address: 0x1800490c0)
  • OpenThreadToken (Address: 0x180049090)
  • ProcessIdToSessionId (Address: 0x1800490d0)
  • TerminateProcess (Address: 0x1800490b0)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800490e0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180049158)
  • RegCreateKeyExW (Address: 0x180049150)
  • RegDeleteKeyExW (Address: 0x180049110)
  • RegDeleteTreeW (Address: 0x180049118)
  • RegDeleteValueW (Address: 0x180049108)
  • RegEnumKeyExW (Address: 0x180049128)
  • RegEnumValueW (Address: 0x180049138)
  • RegFlushKey (Address: 0x180049140)
  • RegGetValueW (Address: 0x1800490f0)
  • RegOpenCurrentUser (Address: 0x180049120)
  • RegOpenKeyExW (Address: 0x180049148)
  • RegQueryInfoKeyW (Address: 0x1800490f8)
  • RegQueryValueExW (Address: 0x180049130)
  • RegSetValueExW (Address: 0x180049100)
api-ms-win-core-registryuserspecific-l1-1-0.dll
  • SHRegGetUSValueW (Address: 0x180049168)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180049188)
  • RtlLookupFunctionEntry (Address: 0x180049178)
  • RtlVirtualUnwind (Address: 0x180049180)
api-ms-win-core-shutdown-l1-1-0.dll
  • InitiateSystemShutdownExW (Address: 0x180049198)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1800491a8)
  • CompareStringW (Address: 0x1800491b0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180049238)
  • AcquireSRWLockShared (Address: 0x180049228)
  • CreateEventExW (Address: 0x180049258)
  • CreateEventW (Address: 0x1800491f0)
  • CreateMutexExW (Address: 0x1800491e8)
  • CreateMutexW (Address: 0x1800491e0)
  • CreateSemaphoreExW (Address: 0x180049270)
  • DeleteCriticalSection (Address: 0x180049278)
  • EnterCriticalSection (Address: 0x180049218)
  • InitializeCriticalSection (Address: 0x1800491f8)
  • InitializeCriticalSectionEx (Address: 0x180049208)
  • InitializeSRWLock (Address: 0x180049248)
  • LeaveCriticalSection (Address: 0x180049260)
  • OpenEventW (Address: 0x1800491d0)
  • OpenSemaphoreW (Address: 0x1800491c8)
  • ReleaseMutex (Address: 0x180049240)
  • ReleaseSemaphore (Address: 0x180049210)
  • ReleaseSRWLockExclusive (Address: 0x180049200)
  • ReleaseSRWLockShared (Address: 0x180049230)
  • ResetEvent (Address: 0x1800491c0)
  • SetEvent (Address: 0x180049268)
  • WaitForMultipleObjectsEx (Address: 0x180049250)
  • WaitForSingleObject (Address: 0x1800491d8)
  • WaitForSingleObjectEx (Address: 0x180049220)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180049290)
  • InitOnceComplete (Address: 0x1800492b0)
  • InitOnceExecuteOnce (Address: 0x180049288)
  • Sleep (Address: 0x180049298)
  • SleepConditionVariableSRW (Address: 0x1800492a0)
  • WakeAllConditionVariable (Address: 0x1800492a8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x1800492c0)
  • GetSystemTimeAsFileTime (Address: 0x1800492d0)
  • GetTickCount (Address: 0x1800492d8)
  • GetTickCount64 (Address: 0x1800492e0)
  • GetVersionExW (Address: 0x1800492c8)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetProductInfo (Address: 0x1800492f0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180049318)
  • CreateThreadpoolTimer (Address: 0x180049300)
  • SetThreadpoolTimer (Address: 0x180049310)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180049308)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x180049328)
  • DeleteTimerQueueTimer (Address: 0x180049330)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x180049348)
  • SystemTimeToFileTime (Address: 0x180049340)
api-ms-win-core-url-l1-1-0.dll
  • ParseURLW (Address: 0x180049358)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180049368)
  • EncodePointer (Address: 0x180049370)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x180049388)
  • RoTransformError (Address: 0x180049380)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180049398)
  • RoGetActivationFactory (Address: 0x1800493a0)
api-ms-win-core-winrt-propertysetprivate-l1-1-1.dll
  • RoCreatePropertySetSerializer (Address: 0x1800493b0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x1800493d0)
  • WindowsCreateStringReference (Address: 0x1800493e0)
  • WindowsDeleteString (Address: 0x1800493d8)
  • WindowsDuplicateString (Address: 0x1800493c0)
  • WindowsGetStringRawBuffer (Address: 0x1800493e8)
  • WindowsSubstringWithSpecifiedLength (Address: 0x1800493c8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180049410)
  • GetTraceEnableLevel (Address: 0x180049400)
  • GetTraceLoggerHandle (Address: 0x180049408)
  • RegisterTraceGuidsW (Address: 0x1800493f8)
  • TraceMessage (Address: 0x180049420)
  • UnregisterTraceGuids (Address: 0x180049418)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x180049440)
  • EventRegister (Address: 0x180049448)
  • EventSetInformation (Address: 0x180049438)
  • EventUnregister (Address: 0x180049430)
  • EventWriteTransfer (Address: 0x180049450)
api-ms-win-ntuser-ie-message-l1-1-0.dll
  • DispatchMessageW (Address: 0x180049470)
  • MsgWaitForMultipleObjectsEx (Address: 0x180049460)
  • PeekMessageW (Address: 0x180049478)
  • PostQuitMessage (Address: 0x180049480)
  • TranslateMessage (Address: 0x180049468)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • GetMonitorInfoW (Address: 0x180049490)
  • GetSystemMetrics (Address: 0x180049498)
api-ms-win-oobe-notification-l1-1-0.dll
  • OOBEComplete (Address: 0x1800494a8)
api-ms-win-rtcore-ntuser-private-l1-1-0.dll
  • CreateWindowInBand (Address: 0x1800494b8)
  • GetWindowBand (Address: 0x1800494c0)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • CreateWindowExW (Address: 0x180049518)
  • DefWindowProcW (Address: 0x1800494d0)
  • DestroyWindow (Address: 0x180049528)
  • EnumWindows (Address: 0x180049510)
  • FindWindowW (Address: 0x180049500)
  • GetPropW (Address: 0x1800494f8)
  • GetWindowThreadProcessId (Address: 0x180049508)
  • IsWindowVisible (Address: 0x180049520)
  • RegisterClassExW (Address: 0x1800494e0)
  • SetForegroundWindow (Address: 0x1800494f0)
  • SetPropW (Address: 0x180049530)
  • SetWindowPos (Address: 0x180049538)
  • ShowWindow (Address: 0x1800494e8)
  • UnregisterClassW (Address: 0x1800494d8)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x180049568)
  • AllocateAndInitializeSid (Address: 0x180049598)
  • CopySid (Address: 0x180049570)
  • CreateWellKnownSid (Address: 0x180049580)
  • EqualSid (Address: 0x180049590)
  • GetLengthSid (Address: 0x180049588)
  • GetTokenInformation (Address: 0x180049560)
  • ImpersonateLoggedOnUser (Address: 0x180049548)
  • IsValidSid (Address: 0x180049578)
  • RevertToSelf (Address: 0x180049550)
  • SetTokenInformation (Address: 0x180049558)
api-ms-win-security-lsalookup-l1-1-2.dll
  • LsaLookupUserAccountType (Address: 0x1800495a8)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountNameW (Address: 0x1800495b8)
  • LookupAccountSidW (Address: 0x1800495c8)
  • LookupPrivilegeValueW (Address: 0x1800495c0)
api-ms-win-security-lsapolicy-l1-1-0.dll
  • LsaClose (Address: 0x1800495f8)
  • LsaFreeMemory (Address: 0x1800495e0)
  • LsaLookupNames2 (Address: 0x1800495d8)
  • LsaOpenPolicy (Address: 0x1800495f0)
  • LsaRetrievePrivateData (Address: 0x1800495e8)
  • LsaStorePrivateData (Address: 0x180049600)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180049618)
  • ConvertStringSidToSidW (Address: 0x180049610)
api-ms-win-shcore-comhelpers-l1-1-0.dll
  • IUnknown_QueryService (Address: 0x180049628)
api-ms-win-shcore-obsolete-l1-1-0.dll
  • SHStrDupW (Address: 0x180049638)
api-ms-win-shcore-registry-l1-1-0.dll
  • SHDeleteKeyW (Address: 0x180049648)
  • SHDeleteValueW (Address: 0x180049650)
api-ms-win-shcore-scaling-l1-1-1.dll
  • GetDpiForMonitor (Address: 0x180049660)
api-ms-win-shcore-stream-l1-1-0.dll
  • IStream_Write (Address: 0x180049670)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolQueueTask (Address: 0x180049680)
api-ms-win-shcore-thread-l1-1-0.dll
  • SHCreateThreadWithHandle (Address: 0x180049698)
  • SHGetThreadRef (Address: 0x180049690)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x1800496a8)
credui.dll
  • CredUnPackAuthenticationBufferW (Address: 0x1800496b8)
CRYPT32.dll
  • CryptProtectData (Address: 0x180048cc0)
DUI70.dll
  • ?Create@RichText@DirectUI@@SAJPEAVElement@2@PEAKPEAPEAV32@@Z (Address: 0x180048cd8)
  • ?Destroy@Element@DirectUI@@QEAAJ_N@Z (Address: 0x180048ce0)
  • ?SetAccessible@Element@DirectUI@@QEAAJ_N@Z (Address: 0x180048d08)
  • ?SetAccRole@Element@DirectUI@@QEAAJH@Z (Address: 0x180048cf0)
  • ?SetConstrainLayout@RichText@DirectUI@@QEAAJH@Z (Address: 0x180048ce8)
  • ?SetContentAlign@Element@DirectUI@@QEAAJH@Z (Address: 0x180048cd0)
  • ?SetContentString@Element@DirectUI@@QEAAJPEBG@Z (Address: 0x180048cf8)
  • ?SetID@Element@DirectUI@@QEAAJPEBG@Z (Address: 0x180048d00)
msvcrt.dll
  • __C_specific_handler (Address: 0x180049738)
  • __CxxFrameHandler3 (Address: 0x1800496e8)
  • __dllonexit (Address: 0x180049718)
  • _amsg_exit (Address: 0x180049748)
  • _callnewh (Address: 0x180049758)
  • _CxxThrowException (Address: 0x180049770)
  • _errno (Address: 0x1800497d0)
  • _get_errno (Address: 0x1800497b8)
  • _initterm (Address: 0x180049740)
  • _lock (Address: 0x180049728)
  • _onexit (Address: 0x180049710)
  • _purecall (Address: 0x1800497e0)
  • _set_errno (Address: 0x1800497c0)
  • _unlock (Address: 0x180049720)
  • _vscwprintf (Address: 0x1800497b0)
  • _vsnprintf (Address: 0x1800496c8)
  • _vsnprintf_s (Address: 0x1800497e8)
  • _vsnwprintf (Address: 0x180049818)
  • _wcsicmp (Address: 0x1800496e0)
  • _wcsnicmp (Address: 0x1800496f8)
  • _XcptFilter (Address: 0x180049750)
  • ??_V@YAXPEAX@Z (Address: 0x180049820)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180049788)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180049780)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800497f0)
  • ??0exception@@QEAA@XZ (Address: 0x1800497f8)
  • ??1exception@@UEAA@XZ (Address: 0x180049800)
  • ??1type_info@@UEAA@XZ (Address: 0x180049708)
  • ??3@YAXPEAX@Z (Address: 0x180049808)
  • ?terminate@@YAXXZ (Address: 0x180049730)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180049778)
  • free (Address: 0x1800497a0)
  • malloc (Address: 0x1800497a8)
  • memcmp (Address: 0x180049700)
  • memcpy (Address: 0x180049768)
  • memcpy_s (Address: 0x180049810)
  • memmove (Address: 0x180049760)
  • memmove_s (Address: 0x1800497d8)
  • memset (Address: 0x180049830)
  • realloc (Address: 0x180049790)
  • toupper (Address: 0x1800496d8)
  • wcschr (Address: 0x1800496f0)
  • wcscspn (Address: 0x1800496d0)
  • wcsrchr (Address: 0x180049828)
  • wcstok_s (Address: 0x180049798)
  • wcstol (Address: 0x1800497c8)
netutils.dll
  • NetApiBufferFree (Address: 0x180049840)
ntdll.dll
  • NtQueryInformationToken (Address: 0x1800498b0)
  • NtQueryWnfStateData (Address: 0x1800498a8)
  • NtSetInformationFile (Address: 0x180049858)
  • RtlAllocateHeap (Address: 0x180049868)
  • RtlCompareUnicodeString (Address: 0x180049878)
  • RtlFreeHeap (Address: 0x180049860)
  • RtlInitString (Address: 0x1800498a0)
  • RtlInitUnicodeString (Address: 0x180049880)
  • RtlNtStatusToDosError (Address: 0x180049850)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x180049870)
  • RtlPublishWnfStateData (Address: 0x180049890)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x180049888)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x180049898)
ole32.dll
  • CoAllowSetForegroundWindow (Address: 0x1800498c0)
OLEAUT32.dll
  • SysAllocString (Address: 0x180048d18)
  • SysFreeString (Address: 0x180048d20)
policymanager.dll
  • PolicyManager_FreeGetPolicyData (Address: 0x1800498d8)
  • PolicyManager_GetPolicy (Address: 0x1800498d0)
samcli.dll
  • NetLocalGroupDelMembers (Address: 0x180049900)
  • NetUserDel (Address: 0x1800498f0)
  • NetUserGetInfo (Address: 0x1800498e8)
  • NetUserSetInfo (Address: 0x1800498f8)
SHCORE.dll
  • (Address: 0x180048d30)
SLC.dll
  • SLGetWindowsInformationDWORD (Address: 0x180048d40)
USER32.dll
  • CallNextHookEx (Address: 0x180048d78)
  • GetAsyncKeyState (Address: 0x180048d70)
  • LoadCursorW (Address: 0x180048d50)
  • MonitorFromPoint (Address: 0x180048d58)
  • MonitorFromWindow (Address: 0x180048d80)
  • SetCursor (Address: 0x180048d88)
  • SetWindowsHookExW (Address: 0x180048d60)
  • UnhookWindowsHookEx (Address: 0x180048d68)
USERENV.dll
  • DeleteProfileW (Address: 0x180048d98)
wkscli.dll
  • NetGetJoinInformation (Address: 0x180049910)