EhStorAPI.dll
Description: Windows Enhanced Storage API
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: db9ead835612cd3b26918f5b8949831a
File Size: 131.5 KB
Uploaded At: Dec. 1, 2025, 7:27 a.m.
Views: 7
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x8f80)
- DllGetClassObject (Ordinal: 2, Address: 0x8fa0)
- DllRegisterServer (Ordinal: 3, Address: 0x90d0)
- DllUnregisterServer (Ordinal: 4, Address: 0x90d0)
Imported DLLs & Functions
ADVAPI32.dll
- CreateProcessAsUserW (Address: 0x18000f688)
- GetTraceEnableFlags (Address: 0x18000f670)
- GetTraceEnableLevel (Address: 0x18000f678)
- GetTraceLoggerHandle (Address: 0x18000f680)
- GetUserNameW (Address: 0x18000f690)
- RegCloseKey (Address: 0x18000f658)
- RegCreateKeyExW (Address: 0x18000f630)
- RegDeleteValueW (Address: 0x18000f628)
- RegEnumKeyExW (Address: 0x18000f648)
- RegisterTraceGuidsW (Address: 0x18000f668)
- RegOpenKeyExW (Address: 0x18000f640)
- RegQueryInfoKeyW (Address: 0x18000f650)
- RegSetValueExW (Address: 0x18000f638)
- TraceMessage (Address: 0x18000f698)
- UnregisterTraceGuids (Address: 0x18000f660)
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x18000f8d8)
- CoTaskMemAlloc (Address: 0x18000f8c0)
- CoTaskMemFree (Address: 0x18000f8d0)
- CoTaskMemRealloc (Address: 0x18000f8c8)
KERNEL32.dll
- CloseHandle (Address: 0x18000f7a0)
- CreateFileW (Address: 0x18000f788)
- CreateProcessW (Address: 0x18000f7c8)
- DeleteCriticalSection (Address: 0x18000f780)
- DeviceIoControl (Address: 0x18000f798)
- DisableThreadLibraryCalls (Address: 0x18000f6d0)
- EnterCriticalSection (Address: 0x18000f6f8)
- ExpandEnvironmentStringsW (Address: 0x18000f7b8)
- FindResourceExW (Address: 0x18000f6d8)
- FreeLibrary (Address: 0x18000f7e8)
- GetCurrentProcess (Address: 0x18000f730)
- GetCurrentProcessId (Address: 0x18000f748)
- GetCurrentThreadId (Address: 0x18000f750)
- GetExitCodeProcess (Address: 0x18000f7d8)
- GetLastError (Address: 0x18000f790)
- GetModuleFileNameW (Address: 0x18000f7e0)
- GetModuleHandleW (Address: 0x18000f800)
- GetProcAddress (Address: 0x18000f778)
- GetProcessHeap (Address: 0x18000f6b0)
- GetSystemTimeAsFileTime (Address: 0x18000f758)
- GetTickCount (Address: 0x18000f760)
- HeapAlloc (Address: 0x18000f770)
- HeapDestroy (Address: 0x18000f6a8)
- HeapFree (Address: 0x18000f6b8)
- HeapReAlloc (Address: 0x18000f6c0)
- HeapSize (Address: 0x18000f6c8)
- InitializeCriticalSection (Address: 0x18000f7a8)
- LeaveCriticalSection (Address: 0x18000f810)
- LoadLibraryExW (Address: 0x18000f7f8)
- LoadResource (Address: 0x18000f6e0)
- lstrcmpiW (Address: 0x18000f808)
- MultiByteToWideChar (Address: 0x18000f6f0)
- OutputDebugStringA (Address: 0x18000f768)
- QueryPerformanceCounter (Address: 0x18000f740)
- RaiseException (Address: 0x18000f7f0)
- RtlCaptureContext (Address: 0x18000f708)
- RtlLookupFunctionEntry (Address: 0x18000f710)
- RtlVirtualUnwind (Address: 0x18000f718)
- SetEnvironmentVariableW (Address: 0x18000f7b0)
- SetUnhandledExceptionFilter (Address: 0x18000f728)
- SizeofResource (Address: 0x18000f6e8)
- Sleep (Address: 0x18000f700)
- TerminateProcess (Address: 0x18000f738)
- UnhandledExceptionFilter (Address: 0x18000f720)
- WaitForSingleObject (Address: 0x18000f7d0)
- WTSGetActiveConsoleSessionId (Address: 0x18000f7c0)
msvcrt.dll
- __C_specific_handler (Address: 0x18000f900)
- __CxxFrameHandler3 (Address: 0x18000f9a8)
- __dllonexit (Address: 0x18000f988)
- _amsg_exit (Address: 0x18000f948)
- _callnewh (Address: 0x18000f938)
- _CxxThrowException (Address: 0x18000f9b0)
- _errno (Address: 0x18000f968)
- _initterm (Address: 0x18000f950)
- _lock (Address: 0x18000f978)
- _onexit (Address: 0x18000f990)
- _purecall (Address: 0x18000f930)
- _unlock (Address: 0x18000f980)
- _wcsicmp (Address: 0x18000f918)
- _XcptFilter (Address: 0x18000f940)
- ??1type_info@@UEAA@XZ (Address: 0x18000f960)
- ?terminate@@YAXXZ (Address: 0x18000f958)
- calloc (Address: 0x18000f910)
- free (Address: 0x18000f8f8)
- malloc (Address: 0x18000f9a0)
- mbstowcs (Address: 0x18000f8f0)
- memcpy (Address: 0x18000f998)
- memcpy_s (Address: 0x18000f8e8)
- memmove_s (Address: 0x18000f908)
- memset (Address: 0x18000f9b8)
- realloc (Address: 0x18000f970)
- wcsncpy_s (Address: 0x18000f928)
- wcsrchr (Address: 0x18000f920)
OLEAUT32.dll
- VarUI4FromStr (Address: 0x18000f820)
SETUPAPI.dll
- SetupDiCreateDeviceInfoList (Address: 0x18000f850)
- SetupDiDestroyDeviceInfoList (Address: 0x18000f848)
- SetupDiEnumDeviceInterfaces (Address: 0x18000f838)
- SetupDiGetClassDevsExW (Address: 0x18000f830)
- SetupDiGetClassDevsW (Address: 0x18000f868)
- SetupDiGetCustomDevicePropertyW (Address: 0x18000f870)
- SetupDiGetDeviceInterfaceAlias (Address: 0x18000f860)
- SetupDiGetDeviceInterfaceDetailW (Address: 0x18000f840)
- SetupDiOpenDeviceInterfaceW (Address: 0x18000f858)
SHLWAPI.dll
- (Address: 0x18000f880)
USER32.dll
- AllowSetForegroundWindow (Address: 0x18000f898)
- CharNextW (Address: 0x18000f8a0)
- UnregisterClassA (Address: 0x18000f890)
WTSAPI32.dll
- WTSQueryUserToken (Address: 0x18000f8b0)