efsutil.dll
Description: EFS Utility Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.1
Architecture: 64-bit
Operating System: Windows NT
SHA256: 897a2cdcef5ce938dfb2cee403768db0
File Size: 46.0 KB
Uploaded At: Dec. 1, 2025, 7:27 a.m.
Views: 13
Exported Functions
- EfsUtilApplyGroupPolicy (Ordinal: 1, Address: 0x65b0)
- EfsUtilCheckCurrentKeyCapabilities (Ordinal: 2, Address: 0x2920)
- EfsUtilCreateSelfSignedCertificate (Ordinal: 3, Address: 0x3550)
- EfsUtilFreeParsedRecoveryPolicy (Ordinal: 4, Address: 0x4c40)
- EfsUtilGetCertContextFromCertHash (Ordinal: 5, Address: 0x2c60)
- EfsUtilGetCertDisplayInformation (Ordinal: 6, Address: 0x4f90)
- EfsUtilGetCertNameFromCertContext (Ordinal: 7, Address: 0x4de0)
- EfsUtilGetCurrentKey (Ordinal: 8, Address: 0x2960)
- EfsUtilGetCurrentKey_Deprecated (Ordinal: 9, Address: 0x4360)
- EfsUtilGetCurrentUserInformation (Ordinal: 10, Address: 0x3d50)
- EfsUtilGetProvider (Ordinal: 11, Address: 0x12b0)
- EfsUtilGetPublicKeyType (Ordinal: 12, Address: 0x57d0)
- EfsUtilGetSmartcardProviderName (Ordinal: 13, Address: 0x4040)
- EfsUtilGetUserKey (Ordinal: 14, Address: 0x20d0)
- EfsUtilIsSmartcardKey (Ordinal: 15, Address: 0x21a0)
- EfsUtilIsSmartcardProvider (Ordinal: 16, Address: 0x14c0)
- EfsUtilParseDataRecoveryPolicy_1_1 (Ordinal: 17, Address: 0x4370)
- EfsUtilReleaseProvider (Ordinal: 18, Address: 0x1460)
- EfsUtilReleaseUserKey (Ordinal: 19, Address: 0x2290)
- EfsUtilSetCurrentKey (Ordinal: 20, Address: 0x2b10)
- EfsUtilSetSmartcardPin (Ordinal: 21, Address: 0x1580)
- EfsUtilSmartcardCredsNeededError (Ordinal: 22, Address: 0x1280)
Imported DLLs & Functions
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800091f0)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180009200)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180009228)
- SetLastError (Address: 0x180009218)
- SetUnhandledExceptionFilter (Address: 0x180009220)
- UnhandledExceptionFilter (Address: 0x180009210)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180009238)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180009248)
- HeapAlloc (Address: 0x180009258)
- HeapFree (Address: 0x180009250)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180009268)
- LocalFree (Address: 0x180009270)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleFileNameA (Address: 0x180009280)
api-ms-win-core-memory-l1-1-0.dll
- VirtualAlloc (Address: 0x180009298)
- VirtualProtect (Address: 0x1800092a0)
- VirtualQuery (Address: 0x180009290)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1800092e0)
- GetCurrentProcessId (Address: 0x1800092c0)
- GetCurrentThread (Address: 0x1800092d0)
- GetCurrentThreadId (Address: 0x1800092e8)
- OpenProcessToken (Address: 0x1800092d8)
- OpenThreadToken (Address: 0x1800092c8)
- SetThreadStackGuarantee (Address: 0x1800092b8)
- TerminateProcess (Address: 0x1800092b0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800092f8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180009308)
- RegCreateKeyExW (Address: 0x180009320)
- RegGetValueW (Address: 0x180009330)
- RegOpenKeyExW (Address: 0x180009318)
- RegQueryValueExW (Address: 0x180009310)
- RegSetValueExW (Address: 0x180009328)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x180009350)
- RtlLookupFunctionEntry (Address: 0x180009340)
- RtlVirtualUnwind (Address: 0x180009348)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x180009360)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180009378)
- ReleaseSRWLockExclusive (Address: 0x180009370)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x180009388)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemInfo (Address: 0x180009398)
- GetSystemTime (Address: 0x1800093a0)
- GetSystemTimeAsFileTime (Address: 0x1800093a8)
- GetTickCount (Address: 0x1800093b0)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x1800093c0)
- SystemTimeToFileTime (Address: 0x1800093c8)
api-ms-win-eventing-provider-l1-1-0.dll
- EventProviderEnabled (Address: 0x1800093f0)
- EventRegister (Address: 0x1800093e8)
- EventSetInformation (Address: 0x1800093e0)
- EventUnregister (Address: 0x1800093f8)
- EventWriteTransfer (Address: 0x1800093d8)
api-ms-win-security-base-l1-1-0.dll
- DuplicateToken (Address: 0x180009408)
- GetLengthSid (Address: 0x180009420)
- GetTokenInformation (Address: 0x180009410)
- IsValidSid (Address: 0x180009418)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x180009430)
bcrypt.dll
- BCryptDestroyKey (Address: 0x180009440)
- BCryptGetProperty (Address: 0x180009448)
CRYPT32.dll
- CertAddCertificateContextToStore (Address: 0x180009128)
- CertCloseStore (Address: 0x1800091b0)
- CertCompareCertificateName (Address: 0x180009190)
- CertCreateCertificateContext (Address: 0x180009160)
- CertCreateSelfSignCertificate (Address: 0x180009180)
- CertDeleteCertificateFromStore (Address: 0x180009170)
- CertFindCertificateInStore (Address: 0x1800091b8)
- CertFindExtension (Address: 0x180009158)
- CertFreeCertificateContext (Address: 0x1800091a0)
- CertGetCertificateContextProperty (Address: 0x1800091c0)
- CertGetEnhancedKeyUsage (Address: 0x180009198)
- CertGetIntendedKeyUsage (Address: 0x180009138)
- CertGetNameStringW (Address: 0x180009148)
- CertOpenStore (Address: 0x1800091c8)
- CertSetCertificateContextProperty (Address: 0x180009178)
- CertStrToNameW (Address: 0x180009188)
- CertVerifyTimeValidity (Address: 0x180009168)
- CryptAcquireCertificatePrivateKey (Address: 0x180009140)
- CryptDecodeObject (Address: 0x180009150)
- CryptEncodeObject (Address: 0x1800091a8)
- CryptImportPublicKeyInfoEx2 (Address: 0x180009130)
DSROLE.dll
- DsRoleFreeMemory (Address: 0x1800091e0)
- DsRoleGetPrimaryDomainInformation (Address: 0x1800091d8)
msvcrt.dll
- __C_specific_handler (Address: 0x180009470)
- _amsg_exit (Address: 0x1800094a8)
- _initterm (Address: 0x180009490)
- _XcptFilter (Address: 0x1800094b0)
- free (Address: 0x1800094a0)
- malloc (Address: 0x180009498)
- memcmp (Address: 0x180009458)
- memcpy (Address: 0x180009460)
- memmove (Address: 0x180009468)
- memset (Address: 0x180009480)
- strcmp (Address: 0x180009488)
- toupper (Address: 0x180009478)
- wcscmp (Address: 0x1800094b8)
ncrypt.dll
- NCryptCreatePersistedKey (Address: 0x1800094f0)
- NCryptDeleteKey (Address: 0x1800094e0)
- NCryptFinalizeKey (Address: 0x1800094e8)
- NCryptFreeObject (Address: 0x1800094f8)
- NCryptGetProperty (Address: 0x1800094d0)
- NCryptOpenStorageProvider (Address: 0x1800094c8)
- NCryptSetProperty (Address: 0x1800094d8)
ntdll.dll
- EtwEventEnabled (Address: 0x180009530)
- EtwEventWrite (Address: 0x180009508)
- RtlImageNtHeader (Address: 0x180009510)
- RtlInitUnicodeString (Address: 0x180009518)
- RtlNtStatusToDosError (Address: 0x180009520)
- RtlUnicodeStringToAnsiString (Address: 0x180009528)