EventsInstaller.dll
Description: Events Offline Installer
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5911
Architecture: 64-bit
Operating System: Windows NT
SHA256: 5389bd28958ae6a4f72804577be5b369
File Size: 273.4 KB
Uploaded At: Dec. 1, 2025, 8:16 a.m.
Views: 10
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x2130)
- DllCsiGetHandler (Ordinal: 2, Address: 0x2170)
Imported DLLs & Functions
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180029f58)
- IsDebuggerPresent (Address: 0x180029f48)
- OutputDebugStringW (Address: 0x180029f50)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180029f68)
- SetLastError (Address: 0x180029f80)
- SetUnhandledExceptionFilter (Address: 0x180029f70)
- UnhandledExceptionFilter (Address: 0x180029f78)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x180029f90)
- GetFileAttributesW (Address: 0x180029f98)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180029fa8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180029fb8)
- HeapAlloc (Address: 0x180029fc0)
- HeapFree (Address: 0x180029fc8)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalAlloc (Address: 0x180029fe0)
- LocalFree (Address: 0x180029fd8)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x180029ff0)
- FindResourceExW (Address: 0x18002a030)
- FreeLibrary (Address: 0x18002a020)
- FreeResource (Address: 0x18002a000)
- GetModuleFileNameA (Address: 0x18002a048)
- GetModuleHandleExW (Address: 0x180029ff8)
- GetModuleHandleW (Address: 0x18002a010)
- GetProcAddress (Address: 0x18002a018)
- LoadLibraryExW (Address: 0x18002a008)
- LoadResource (Address: 0x18002a028)
- LockResource (Address: 0x18002a038)
- SizeofResource (Address: 0x18002a040)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18002a058)
api-ms-win-core-memory-l1-1-0.dll
- UnmapViewOfFile (Address: 0x18002a068)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x18002a078)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18002a098)
- GetCurrentProcessId (Address: 0x18002a088)
- GetCurrentThreadId (Address: 0x18002a090)
- TerminateProcess (Address: 0x18002a0a0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18002a0b0)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18002a0c0)
- RegCreateKeyExW (Address: 0x18002a0e8)
- RegDeleteKeyExW (Address: 0x18002a0d0)
- RegDeleteValueW (Address: 0x18002a100)
- RegEnumKeyExW (Address: 0x18002a0f8)
- RegGetKeySecurity (Address: 0x18002a110)
- RegGetValueW (Address: 0x18002a108)
- RegOpenKeyExW (Address: 0x18002a0d8)
- RegQueryInfoKeyW (Address: 0x18002a0e0)
- RegQueryValueExW (Address: 0x18002a0f0)
- RegSetValueExW (Address: 0x18002a0c8)
api-ms-win-core-registry-l2-1-0.dll
- RegCreateKeyTransactedW (Address: 0x18002a120)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18002a130)
- RtlLookupFunctionEntry (Address: 0x18002a140)
- RtlVirtualUnwind (Address: 0x18002a138)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x18002a150)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18002a1a0)
- AcquireSRWLockShared (Address: 0x18002a178)
- CreateMutexExW (Address: 0x18002a198)
- CreateSemaphoreExW (Address: 0x18002a1a8)
- DeleteCriticalSection (Address: 0x18002a188)
- EnterCriticalSection (Address: 0x18002a168)
- InitializeCriticalSection (Address: 0x18002a170)
- InitializeCriticalSectionEx (Address: 0x18002a1b0)
- LeaveCriticalSection (Address: 0x18002a1d8)
- OpenSemaphoreW (Address: 0x18002a1c0)
- ReleaseMutex (Address: 0x18002a1d0)
- ReleaseSemaphore (Address: 0x18002a1b8)
- ReleaseSRWLockExclusive (Address: 0x18002a180)
- ReleaseSRWLockShared (Address: 0x18002a190)
- WaitForSingleObject (Address: 0x18002a160)
- WaitForSingleObjectEx (Address: 0x18002a1c8)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x18002a1e8)
- InitOnceComplete (Address: 0x18002a1f0)
- Sleep (Address: 0x18002a1f8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x18002a210)
- GetTickCount (Address: 0x18002a208)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x18002a220)
- CreateThreadpoolTimer (Address: 0x18002a230)
- SetThreadpoolTimer (Address: 0x18002a238)
- WaitForThreadpoolTimerCallbacks (Address: 0x18002a228)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x18002a248)
- EncodePointer (Address: 0x18002a250)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x18002a280)
- GetTraceEnableLevel (Address: 0x18002a268)
- GetTraceLoggerHandle (Address: 0x18002a270)
- RegisterTraceGuidsW (Address: 0x18002a260)
- TraceMessage (Address: 0x18002a288)
- UnregisterTraceGuids (Address: 0x18002a278)
api-ms-win-security-base-l1-1-0.dll
- AddAce (Address: 0x18002a2c8)
- GetAce (Address: 0x18002a298)
- GetAclInformation (Address: 0x18002a2b8)
- GetSecurityDescriptorControl (Address: 0x18002a2e0)
- GetSecurityDescriptorDacl (Address: 0x18002a2c0)
- GetSecurityDescriptorGroup (Address: 0x18002a2b0)
- GetSecurityDescriptorLength (Address: 0x18002a2d8)
- GetSecurityDescriptorOwner (Address: 0x18002a2a8)
- InitializeAcl (Address: 0x18002a2a0)
- InitializeSecurityDescriptor (Address: 0x18002a2d0)
- IsValidSecurityDescriptor (Address: 0x18002a300)
- MakeSelfRelativeSD (Address: 0x18002a2e8)
- MapGenericMask (Address: 0x18002a310)
- SetSecurityDescriptorDacl (Address: 0x18002a308)
- SetSecurityDescriptorGroup (Address: 0x18002a2f0)
- SetSecurityDescriptorOwner (Address: 0x18002a2f8)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x18002a320)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18002a328)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x18002a350)
- BCryptCreateHash (Address: 0x18002a338)
- BCryptDestroyHash (Address: 0x18002a348)
- BCryptFinishHash (Address: 0x18002a340)
- BCryptGetProperty (Address: 0x18002a360)
- BCryptHashData (Address: 0x18002a358)
- BCryptOpenAlgorithmProvider (Address: 0x18002a368)
msvcrt.dll
- __C_specific_handler (Address: 0x18002a3f8)
- __CxxFrameHandler3 (Address: 0x18002a438)
- __dllonexit (Address: 0x18002a418)
- _amsg_exit (Address: 0x18002a388)
- _CxxThrowException (Address: 0x18002a3a8)
- _errno (Address: 0x18002a428)
- _initterm (Address: 0x18002a380)
- _itow_s (Address: 0x18002a490)
- _lock (Address: 0x18002a408)
- _onexit (Address: 0x18002a420)
- _purecall (Address: 0x18002a4b0)
- _ultow_s (Address: 0x18002a488)
- _unlock (Address: 0x18002a410)
- _vsnprintf_s (Address: 0x18002a440)
- _vsnwprintf (Address: 0x18002a448)
- _wcsicmp (Address: 0x18002a460)
- _wcsnicmp (Address: 0x18002a498)
- _wcstoui64 (Address: 0x18002a468)
- _wtoi (Address: 0x18002a478)
- _XcptFilter (Address: 0x18002a390)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18002a3d0)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18002a3c8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x18002a3c0)
- ??0exception@@QEAA@XZ (Address: 0x18002a3e0)
- ??1exception@@UEAA@XZ (Address: 0x18002a3b8)
- ??1type_info@@UEAA@XZ (Address: 0x18002a4b8)
- ?terminate@@YAXXZ (Address: 0x18002a378)
- ?what@exception@@UEBAPEBDXZ (Address: 0x18002a3b0)
- free (Address: 0x18002a4a8)
- malloc (Address: 0x18002a400)
- memcmp (Address: 0x18002a3d8)
- memcpy (Address: 0x18002a3a0)
- memcpy_s (Address: 0x18002a450)
- memmove (Address: 0x18002a398)
- memmove_s (Address: 0x18002a458)
- memset (Address: 0x18002a430)
- towupper (Address: 0x18002a4a0)
- wcschr (Address: 0x18002a480)
- wcscmp (Address: 0x18002a4c0)
- wcscpy_s (Address: 0x18002a3e8)
- wcsncmp (Address: 0x18002a3f0)
- wcstoul (Address: 0x18002a470)
ntdll.dll
- NtCommitTransaction (Address: 0x18002a4d0)
- NtCreateTransaction (Address: 0x18002a4d8)
- RtlGetVersion (Address: 0x18002a4f0)
- RtlInitUnicodeStringEx (Address: 0x18002a4e0)
- RtlNtStatusToDosError (Address: 0x18002a4e8)
RPCRT4.dll
- UuidCreate (Address: 0x180029ec8)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YAKPEAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x180029ee8)
- ?RtlTraceFormat_PCbool@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x180029f20)
- ?RtlTraceFormat_PCHRESULT@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x180029f28)
- ?RtlTraceFormat_PCLONG@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x180029f00)
- ?RtlTraceFormat_PCSTR_AsLiteralString@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x180029f38)
- ?RtlTraceFormat_PCULONG_AsWin32Error@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x180029f30)
- ?RtlTraceFormat_PCULONG@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x180029ef8)
- ?RtlTraceFormat_PCWSTR_AsLiteralString@Rtl@WCP@Windows@@YAXPEAUIRtlFormattedOutputStream@13@PEBX@Z (Address: 0x180029ed8)
- ?RtlTraceVa@Rtl@WCP@Windows@@YAXKKPEAU_RTL_TRACING_FACILITY@123@QEBD_KPEAD@Z (Address: 0x180029ee0)
- RtlCalculateUtf16StringLengthFromLUtf8String (Address: 0x180029f18)
- RtlCopyLUtf8StringToLUnicodeString (Address: 0x180029f10)
- RtlCreateMicrodom (Address: 0x180029ef0)
- RtlFreeLUtf8String (Address: 0x180029f08)