EventsInstaller.dll

Description: Events Offline Installer

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5363

Architecture: 32-bit

Operating System: Windows NT

SHA256: 5f35968058640e77c815011b31ef13f5

File Size: 214.0 KB

Uploaded At: Dec. 1, 2025, 8:36 a.m.

Views: 11

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x5c40)
  • DllCsiGetHandler (Ordinal: 2, Address: 0x5c70)

Imported DLLs & Functions

api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x10026040)
  • IsDebuggerPresent (Address: 0x10026044)
  • OutputDebugStringW (Address: 0x10026048)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1002605c)
  • SetLastError (Address: 0x10026050)
  • SetUnhandledExceptionFilter (Address: 0x10026058)
  • UnhandledExceptionFilter (Address: 0x10026054)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x10026064)
  • GetFileAttributesW (Address: 0x10026068)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x10026070)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1002607c)
  • HeapAlloc (Address: 0x10026080)
  • HeapFree (Address: 0x10026078)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • LocalAlloc (Address: 0x1002608c)
  • LocalFree (Address: 0x10026088)
api-ms-win-core-libraryloader-l1-1-0.dll
  • DisableThreadLibraryCalls (Address: 0x100260c0)
  • FindResourceExW (Address: 0x100260a4)
  • FreeLibrary (Address: 0x100260ac)
  • FreeResource (Address: 0x100260b4)
  • GetModuleFileNameA (Address: 0x100260a8)
  • GetModuleHandleExW (Address: 0x10026094)
  • GetModuleHandleW (Address: 0x100260bc)
  • GetProcAddress (Address: 0x1002609c)
  • LoadLibraryExW (Address: 0x10026098)
  • LoadResource (Address: 0x100260a0)
  • LockResource (Address: 0x100260b0)
  • SizeofResource (Address: 0x100260b8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x100260c8)
api-ms-win-core-memory-l1-1-0.dll
  • UnmapViewOfFile (Address: 0x100260d0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x100260d8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x100260e8)
  • GetCurrentProcessId (Address: 0x100260ec)
  • GetCurrentThreadId (Address: 0x100260e0)
  • TerminateProcess (Address: 0x100260e4)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x100260f4)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x10026118)
  • RegCreateKeyExW (Address: 0x1002610c)
  • RegDeleteKeyExW (Address: 0x10026100)
  • RegDeleteValueW (Address: 0x10026110)
  • RegEnumKeyExW (Address: 0x10026104)
  • RegGetKeySecurity (Address: 0x10026120)
  • RegGetValueW (Address: 0x1002611c)
  • RegOpenKeyExW (Address: 0x10026124)
  • RegQueryInfoKeyW (Address: 0x100260fc)
  • RegQueryValueExW (Address: 0x10026114)
  • RegSetValueExW (Address: 0x10026108)
api-ms-win-core-registry-l2-1-0.dll
  • RegCreateKeyTransactedW (Address: 0x1002612c)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x10026134)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1002615c)
  • AcquireSRWLockShared (Address: 0x1002613c)
  • CreateMutexExW (Address: 0x10026178)
  • CreateSemaphoreExW (Address: 0x10026164)
  • DeleteCriticalSection (Address: 0x10026160)
  • EnterCriticalSection (Address: 0x10026154)
  • InitializeCriticalSection (Address: 0x1002614c)
  • InitializeCriticalSectionEx (Address: 0x1002616c)
  • LeaveCriticalSection (Address: 0x10026148)
  • OpenSemaphoreW (Address: 0x10026170)
  • ReleaseMutex (Address: 0x10026168)
  • ReleaseSemaphore (Address: 0x10026150)
  • ReleaseSRWLockExclusive (Address: 0x10026140)
  • ReleaseSRWLockShared (Address: 0x10026144)
  • WaitForSingleObject (Address: 0x10026158)
  • WaitForSingleObjectEx (Address: 0x10026174)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x10026180)
  • InitOnceComplete (Address: 0x10026184)
  • Sleep (Address: 0x10026188)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x10026194)
  • GetTickCount (Address: 0x10026190)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x100261a8)
  • CreateThreadpoolTimer (Address: 0x100261a4)
  • SetThreadpoolTimer (Address: 0x1002619c)
  • WaitForThreadpoolTimerCallbacks (Address: 0x100261a0)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x100261b0)
  • EncodePointer (Address: 0x100261b4)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x100261bc)
  • GetTraceEnableLevel (Address: 0x100261c0)
  • GetTraceLoggerHandle (Address: 0x100261c4)
  • RegisterTraceGuidsW (Address: 0x100261cc)
  • TraceMessage (Address: 0x100261d0)
  • UnregisterTraceGuids (Address: 0x100261c8)
api-ms-win-security-base-l1-1-0.dll
  • AddAce (Address: 0x100261dc)
  • GetAce (Address: 0x10026214)
  • GetAclInformation (Address: 0x100261e4)
  • GetSecurityDescriptorControl (Address: 0x100261fc)
  • GetSecurityDescriptorDacl (Address: 0x100261ec)
  • GetSecurityDescriptorGroup (Address: 0x100261f4)
  • GetSecurityDescriptorLength (Address: 0x100261f0)
  • GetSecurityDescriptorOwner (Address: 0x100261e0)
  • InitializeAcl (Address: 0x100261e8)
  • InitializeSecurityDescriptor (Address: 0x10026210)
  • IsValidSecurityDescriptor (Address: 0x1002620c)
  • MakeSelfRelativeSD (Address: 0x100261f8)
  • MapGenericMask (Address: 0x100261d8)
  • SetSecurityDescriptorDacl (Address: 0x10026208)
  • SetSecurityDescriptorGroup (Address: 0x10026200)
  • SetSecurityDescriptorOwner (Address: 0x10026204)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x1002621c)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x10026220)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x10026234)
  • BCryptCreateHash (Address: 0x10026228)
  • BCryptDestroyHash (Address: 0x10026230)
  • BCryptFinishHash (Address: 0x1002622c)
  • BCryptGetProperty (Address: 0x1002623c)
  • BCryptHashData (Address: 0x10026238)
  • BCryptOpenAlgorithmProvider (Address: 0x10026240)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x100262a8)
  • __dllonexit (Address: 0x10026294)
  • _amsg_exit (Address: 0x10026254)
  • _CxxThrowException (Address: 0x10026264)
  • _errno (Address: 0x100262a0)
  • _except_handler4_common (Address: 0x100262e4)
  • _initterm (Address: 0x10026250)
  • _itow_s (Address: 0x100262d4)
  • _lock (Address: 0x10026248)
  • _onexit (Address: 0x10026298)
  • _purecall (Address: 0x100262e0)
  • _ultow_s (Address: 0x100262d0)
  • _unlock (Address: 0x10026290)
  • _vsnprintf_s (Address: 0x100262ac)
  • _vsnwprintf (Address: 0x100262b0)
  • _wcsicmp (Address: 0x100262bc)
  • _wcsnicmp (Address: 0x100262d8)
  • _wcstoui64 (Address: 0x100262c0)
  • _wtoi (Address: 0x100262c8)
  • _XcptFilter (Address: 0x10026258)
  • ??0exception@@QAE@ABQBD@Z (Address: 0x10026278)
  • ??0exception@@QAE@ABQBDH@Z (Address: 0x10026274)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x10026270)
  • ??0exception@@QAE@XZ (Address: 0x1002627c)
  • ??1exception@@UAE@XZ (Address: 0x1002626c)
  • ??1type_info@@UAE@XZ (Address: 0x1002629c)
  • ?terminate@@YAXXZ (Address: 0x1002624c)
  • ?what@exception@@UBEPBDXZ (Address: 0x10026268)
  • free (Address: 0x1002628c)
  • malloc (Address: 0x10026288)
  • memcmp (Address: 0x100262a4)
  • memcpy (Address: 0x10026260)
  • memcpy_s (Address: 0x100262b4)
  • memmove (Address: 0x1002625c)
  • memmove_s (Address: 0x100262b8)
  • memset (Address: 0x100262e8)
  • towupper (Address: 0x100262dc)
  • wcschr (Address: 0x100262cc)
  • wcscpy_s (Address: 0x10026280)
  • wcsncmp (Address: 0x10026284)
  • wcstoul (Address: 0x100262c4)
ntdll.dll
  • NtCommitTransaction (Address: 0x100262f0)
  • NtCreateTransaction (Address: 0x100262f4)
  • RtlGetVersion (Address: 0x10026300)
  • RtlInitUnicodeStringEx (Address: 0x100262f8)
  • RtlNtStatusToDosError (Address: 0x100262fc)
RPCRT4.dll
  • UuidCreate (Address: 0x10026000)
WCP.dll
  • ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x10026020)
  • ?RtlTraceFormat_PCbool@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x1002602c)
  • ?RtlTraceFormat_PCHRESULT@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10026030)
  • ?RtlTraceFormat_PCLONG@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10026018)
  • ?RtlTraceFormat_PCSTR_AsLiteralString@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10026038)
  • ?RtlTraceFormat_PCULONG_AsWin32Error@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10026034)
  • ?RtlTraceFormat_PCULONG@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10026008)
  • ?RtlTraceFormat_PCWSTR_AsLiteralString@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x1002601c)
  • ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x10026010)
  • RtlCalculateUtf16StringLengthFromLUtf8String (Address: 0x10026028)
  • RtlCopyLUtf8StringToLUnicodeString (Address: 0x10026024)
  • RtlCreateMicrodom (Address: 0x1002600c)
  • RtlFreeLUtf8String (Address: 0x10026014)