EhStorAPI.dll

Description: Windows Enhanced Storage API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: db9ead835612cd3b26918f5b8949831a

File Size: 131.5 KB

Uploaded At: Dec. 1, 2025, 7:27 a.m.

Views: 7

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x8f80)
  • DllGetClassObject (Ordinal: 2, Address: 0x8fa0)
  • DllRegisterServer (Ordinal: 3, Address: 0x90d0)
  • DllUnregisterServer (Ordinal: 4, Address: 0x90d0)

Imported DLLs & Functions

ADVAPI32.dll
  • CreateProcessAsUserW (Address: 0x18000f688)
  • GetTraceEnableFlags (Address: 0x18000f670)
  • GetTraceEnableLevel (Address: 0x18000f678)
  • GetTraceLoggerHandle (Address: 0x18000f680)
  • GetUserNameW (Address: 0x18000f690)
  • RegCloseKey (Address: 0x18000f658)
  • RegCreateKeyExW (Address: 0x18000f630)
  • RegDeleteValueW (Address: 0x18000f628)
  • RegEnumKeyExW (Address: 0x18000f648)
  • RegisterTraceGuidsW (Address: 0x18000f668)
  • RegOpenKeyExW (Address: 0x18000f640)
  • RegQueryInfoKeyW (Address: 0x18000f650)
  • RegSetValueExW (Address: 0x18000f638)
  • TraceMessage (Address: 0x18000f698)
  • UnregisterTraceGuids (Address: 0x18000f660)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x18000f8d8)
  • CoTaskMemAlloc (Address: 0x18000f8c0)
  • CoTaskMemFree (Address: 0x18000f8d0)
  • CoTaskMemRealloc (Address: 0x18000f8c8)
KERNEL32.dll
  • CloseHandle (Address: 0x18000f7a0)
  • CreateFileW (Address: 0x18000f788)
  • CreateProcessW (Address: 0x18000f7c8)
  • DeleteCriticalSection (Address: 0x18000f780)
  • DeviceIoControl (Address: 0x18000f798)
  • DisableThreadLibraryCalls (Address: 0x18000f6d0)
  • EnterCriticalSection (Address: 0x18000f6f8)
  • ExpandEnvironmentStringsW (Address: 0x18000f7b8)
  • FindResourceExW (Address: 0x18000f6d8)
  • FreeLibrary (Address: 0x18000f7e8)
  • GetCurrentProcess (Address: 0x18000f730)
  • GetCurrentProcessId (Address: 0x18000f748)
  • GetCurrentThreadId (Address: 0x18000f750)
  • GetExitCodeProcess (Address: 0x18000f7d8)
  • GetLastError (Address: 0x18000f790)
  • GetModuleFileNameW (Address: 0x18000f7e0)
  • GetModuleHandleW (Address: 0x18000f800)
  • GetProcAddress (Address: 0x18000f778)
  • GetProcessHeap (Address: 0x18000f6b0)
  • GetSystemTimeAsFileTime (Address: 0x18000f758)
  • GetTickCount (Address: 0x18000f760)
  • HeapAlloc (Address: 0x18000f770)
  • HeapDestroy (Address: 0x18000f6a8)
  • HeapFree (Address: 0x18000f6b8)
  • HeapReAlloc (Address: 0x18000f6c0)
  • HeapSize (Address: 0x18000f6c8)
  • InitializeCriticalSection (Address: 0x18000f7a8)
  • LeaveCriticalSection (Address: 0x18000f810)
  • LoadLibraryExW (Address: 0x18000f7f8)
  • LoadResource (Address: 0x18000f6e0)
  • lstrcmpiW (Address: 0x18000f808)
  • MultiByteToWideChar (Address: 0x18000f6f0)
  • OutputDebugStringA (Address: 0x18000f768)
  • QueryPerformanceCounter (Address: 0x18000f740)
  • RaiseException (Address: 0x18000f7f0)
  • RtlCaptureContext (Address: 0x18000f708)
  • RtlLookupFunctionEntry (Address: 0x18000f710)
  • RtlVirtualUnwind (Address: 0x18000f718)
  • SetEnvironmentVariableW (Address: 0x18000f7b0)
  • SetUnhandledExceptionFilter (Address: 0x18000f728)
  • SizeofResource (Address: 0x18000f6e8)
  • Sleep (Address: 0x18000f700)
  • TerminateProcess (Address: 0x18000f738)
  • UnhandledExceptionFilter (Address: 0x18000f720)
  • WaitForSingleObject (Address: 0x18000f7d0)
  • WTSGetActiveConsoleSessionId (Address: 0x18000f7c0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000f900)
  • __CxxFrameHandler3 (Address: 0x18000f9a8)
  • __dllonexit (Address: 0x18000f988)
  • _amsg_exit (Address: 0x18000f948)
  • _callnewh (Address: 0x18000f938)
  • _CxxThrowException (Address: 0x18000f9b0)
  • _errno (Address: 0x18000f968)
  • _initterm (Address: 0x18000f950)
  • _lock (Address: 0x18000f978)
  • _onexit (Address: 0x18000f990)
  • _purecall (Address: 0x18000f930)
  • _unlock (Address: 0x18000f980)
  • _wcsicmp (Address: 0x18000f918)
  • _XcptFilter (Address: 0x18000f940)
  • ??1type_info@@UEAA@XZ (Address: 0x18000f960)
  • ?terminate@@YAXXZ (Address: 0x18000f958)
  • calloc (Address: 0x18000f910)
  • free (Address: 0x18000f8f8)
  • malloc (Address: 0x18000f9a0)
  • mbstowcs (Address: 0x18000f8f0)
  • memcpy (Address: 0x18000f998)
  • memcpy_s (Address: 0x18000f8e8)
  • memmove_s (Address: 0x18000f908)
  • memset (Address: 0x18000f9b8)
  • realloc (Address: 0x18000f970)
  • wcsncpy_s (Address: 0x18000f928)
  • wcsrchr (Address: 0x18000f920)
OLEAUT32.dll
  • VarUI4FromStr (Address: 0x18000f820)
SETUPAPI.dll
  • SetupDiCreateDeviceInfoList (Address: 0x18000f850)
  • SetupDiDestroyDeviceInfoList (Address: 0x18000f848)
  • SetupDiEnumDeviceInterfaces (Address: 0x18000f838)
  • SetupDiGetClassDevsExW (Address: 0x18000f830)
  • SetupDiGetClassDevsW (Address: 0x18000f868)
  • SetupDiGetCustomDevicePropertyW (Address: 0x18000f870)
  • SetupDiGetDeviceInterfaceAlias (Address: 0x18000f860)
  • SetupDiGetDeviceInterfaceDetailW (Address: 0x18000f840)
  • SetupDiOpenDeviceInterfaceW (Address: 0x18000f858)
SHLWAPI.dll
  • (Address: 0x18000f880)
USER32.dll
  • AllowSetForegroundWindow (Address: 0x18000f898)
  • CharNextW (Address: 0x18000f8a0)
  • UnregisterClassA (Address: 0x18000f890)
WTSAPI32.dll
  • WTSQueryUserToken (Address: 0x18000f8b0)