wdscore.dll

Description: Panther Engine Module

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1704

Architecture: 32-bit

Operating System: Windows NT

SHA256: 1c0aa14365cf96928c878d2137338443

File Size: 203.3 KB

Uploaded At: Dec. 1, 2025, 8:44 a.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • WdsGetPointer (Ordinal: 1, Address: 0x11010)
  • g_Kernel32 (Ordinal: 2, Address: 0x2d160)
  • g_bEnableDiagnosticMode (Ordinal: 3, Address: 0x2d568)
  • ConstructPartialMsgIfA (Ordinal: 4, Address: 0x1fe00)
  • ConstructPartialMsgIfW (Ordinal: 5, Address: 0x1fe30)
  • ConstructPartialMsgVA (Ordinal: 6, Address: 0x1fe60)
  • ConstructPartialMsgVW (Ordinal: 7, Address: 0x1ff30)
  • CurrentIP (Ordinal: 8, Address: 0x20070)
  • EndMajorTask (Ordinal: 9, Address: 0x20080)
  • EndMinorTask (Ordinal: 10, Address: 0x200c0)
  • GetMajorTask (Ordinal: 11, Address: 0x20110)
  • GetMajorTaskA (Ordinal: 12, Address: 0x20150)
  • GetMinorTask (Ordinal: 13, Address: 0x20190)
  • GetMinorTaskA (Ordinal: 14, Address: 0x201e0)
  • StartMajorTask (Ordinal: 15, Address: 0x20230)
  • StartMinorTask (Ordinal: 16, Address: 0x20310)
  • WdsAbortBlackboardItemEnum (Ordinal: 17, Address: 0x1db30)
  • WdsAddModule (Ordinal: 18, Address: 0x12700)
  • WdsAddUsmtLogStack (Ordinal: 19, Address: 0x20360)
  • WdsAllocCollection (Ordinal: 20, Address: 0x12780)
  • WdsCollectionAddValue (Ordinal: 21, Address: 0x127a0)
  • WdsCollectionGetValue (Ordinal: 22, Address: 0x12830)
  • WdsCopyBlackboardItems (Ordinal: 23, Address: 0x1dc00)
  • WdsCopyBlackboardItemsEx (Ordinal: 24, Address: 0x1dc30)
  • WdsCreateBlackboard (Ordinal: 25, Address: 0x1deb0)
  • WdsDeleteBlackboardValue (Ordinal: 26, Address: 0x1df10)
  • WdsDeleteEvent (Ordinal: 27, Address: 0x128b0)
  • WdsDestroyBlackboard (Ordinal: 28, Address: 0x1dff0)
  • WdsDuplicateData (Ordinal: 29, Address: 0x128d0)
  • WdsEnableDiagnosticMode (Ordinal: 30, Address: 0x208c0)
  • WdsEnableExit (Ordinal: 31, Address: 0x129b0)
  • WdsEnableExitEx (Ordinal: 32, Address: 0x129d0)
  • WdsEnumFirstBlackboardItem (Ordinal: 33, Address: 0x1e040)
  • WdsEnumFirstCollectionValue (Ordinal: 34, Address: 0x12a50)
  • WdsEnumNextBlackboardItem (Ordinal: 35, Address: 0x1e260)
  • WdsEnumNextCollectionValue (Ordinal: 36, Address: 0x12a70)
  • WdsExecuteWorkQueue2 (Ordinal: 37, Address: 0x12aa0)
  • WdsExecuteWorkQueue (Ordinal: 38, Address: 0x13030)
  • WdsExecuteWorkQueueEx (Ordinal: 39, Address: 0x13530)
  • WdsExitImmediately (Ordinal: 40, Address: 0x13570)
  • WdsExitImmediatelyEx (Ordinal: 41, Address: 0x13590)
  • WdsFreeCollection (Ordinal: 42, Address: 0x13610)
  • WdsFreeData (Ordinal: 43, Address: 0x13650)
  • WdsGenericSetupLogInit (Ordinal: 44, Address: 0x208e0)
  • WdsGetAssertFlags (Ordinal: 45, Address: 0x20c40)
  • WdsGetBlackboardBinaryData (Ordinal: 46, Address: 0x1e2f0)
  • WdsGetBlackboardStringA (Ordinal: 47, Address: 0x1e460)
  • WdsGetBlackboardStringW (Ordinal: 48, Address: 0x1e650)
  • WdsGetBlackboardUintPtr (Ordinal: 49, Address: 0x1e7d0)
  • WdsGetBlackboardValue (Ordinal: 50, Address: 0x1e910)
  • WdsGetCurrentExecutionGroup (Ordinal: 51, Address: 0x136a0)
  • WdsGetSetupLog (Ordinal: 52, Address: 0x20c50)
  • WdsGetTempDir (Ordinal: 53, Address: 0x136d0)
  • WdsInitialize (Ordinal: 54, Address: 0x13840)
  • WdsInitializeCallbackArray (Ordinal: 55, Address: 0xe0e0)
  • WdsInitializeDataBinary (Ordinal: 56, Address: 0x139c0)
  • WdsInitializeDataStringA (Ordinal: 57, Address: 0x13a30)
  • WdsInitializeDataStringW (Ordinal: 58, Address: 0x13aa0)
  • WdsInitializeDataUInt32 (Ordinal: 59, Address: 0x13b10)
  • WdsInitializeDataUInt64 (Ordinal: 60, Address: 0x13b40)
  • WdsIsDiagnosticModeEnabled (Ordinal: 61, Address: 0x20d00)
  • WdsIterateOfflineQueue (Ordinal: 62, Address: 0x13b70)
  • WdsIterateQueue (Ordinal: 63, Address: 0x13c00)
  • WdsLockBlackboardValue (Ordinal: 64, Address: 0x1ea10)
  • WdsLockExecutionGroup (Ordinal: 65, Address: 0x13c40)
  • WdsLogCreate (Ordinal: 66, Address: 0x23db0)
  • WdsLogDestroy (Ordinal: 67, Address: 0x23e10)
  • WdsLogRegStockProviders (Ordinal: 68, Address: 0x24280)
  • WdsLogRegisterProvider (Ordinal: 69, Address: 0x24310)
  • WdsLogStructuredException (Ordinal: 70, Address: 0x20d10)
  • WdsLogUnRegStockProviders (Ordinal: 71, Address: 0x243f0)
  • WdsLogUnRegisterProvider (Ordinal: 72, Address: 0x24450)
  • WdsPackCollection (Ordinal: 73, Address: 0x13c50)
  • WdsPublish (Ordinal: 74, Address: 0x13df0)
  • WdsPublishEx (Ordinal: 75, Address: 0x13e30)
  • WdsPublishImmediateAsync (Ordinal: 76, Address: 0x13e70)
  • WdsPublishImmediateEx (Ordinal: 77, Address: 0x13eb0)
  • WdsPublishOffline (Ordinal: 78, Address: 0x13ee0)
  • WdsSeqAlloc (Ordinal: 79, Address: 0x13fb0)
  • WdsSeqFree (Ordinal: 80, Address: 0xb5b0)
  • WdsSetAssertFlags (Ordinal: 81, Address: 0x20ef0)
  • WdsSetBlackboardValue (Ordinal: 82, Address: 0x1eaf0)
  • WdsSetNextExecutionGroup (Ordinal: 83, Address: 0x13ff0)
  • WdsSetUILanguage (Ordinal: 84, Address: 0x14020)
  • WdsSetupLogDestroy (Ordinal: 85, Address: 0x20f10)
  • WdsSetupLogInit (Ordinal: 86, Address: 0x20fd0)
  • WdsSetupLogMessageA (Ordinal: 87, Address: 0x21ae0)
  • WdsSetupLogMessageW (Ordinal: 88, Address: 0x21d20)
  • WdsSubscribeEx (Ordinal: 89, Address: 0x14040)
  • WdsTerminate (Ordinal: 90, Address: 0x14080)
  • WdsUnlockExecutionGroup (Ordinal: 91, Address: 0x14100)
  • WdsUnpackCollection (Ordinal: 92, Address: 0x14110)
  • WdsUnsubscribe (Ordinal: 93, Address: 0x14340)
  • WdsUnsubscribeEx (Ordinal: 94, Address: 0x14370)
  • WdsValidBlackboard (Ordinal: 95, Address: 0x1ecf0)

Imported DLLs & Functions

api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1002f014)
  • IsDebuggerPresent (Address: 0x1002f00c)
  • OutputDebugStringA (Address: 0x1002f010)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1002f01c)
  • RaiseException (Address: 0x1002f028)
  • SetErrorMode (Address: 0x1002f024)
  • SetLastError (Address: 0x1002f030)
  • SetUnhandledExceptionFilter (Address: 0x1002f02c)
  • UnhandledExceptionFilter (Address: 0x1002f020)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x1002f074)
  • CreateFileA (Address: 0x1002f054)
  • CreateFileW (Address: 0x1002f080)
  • DeleteFileA (Address: 0x1002f070)
  • DeleteFileW (Address: 0x1002f07c)
  • FindClose (Address: 0x1002f084)
  • FindFirstFileW (Address: 0x1002f0a0)
  • FindNextFileW (Address: 0x1002f09c)
  • FlushFileBuffers (Address: 0x1002f0a8)
  • GetDiskFreeSpaceExW (Address: 0x1002f038)
  • GetDiskFreeSpaceW (Address: 0x1002f05c)
  • GetDriveTypeW (Address: 0x1002f044)
  • GetFileAttributesW (Address: 0x1002f094)
  • GetFileSize (Address: 0x1002f03c)
  • GetFileSizeEx (Address: 0x1002f090)
  • GetFileType (Address: 0x1002f040)
  • GetFullPathNameW (Address: 0x1002f064)
  • GetLogicalDrives (Address: 0x1002f068)
  • GetLogicalDriveStringsW (Address: 0x1002f048)
  • GetShortPathNameW (Address: 0x1002f060)
  • GetTempFileNameW (Address: 0x1002f078)
  • GetVolumeInformationW (Address: 0x1002f06c)
  • ReadFile (Address: 0x1002f0a4)
  • RemoveDirectoryW (Address: 0x1002f08c)
  • SetEndOfFile (Address: 0x1002f050)
  • SetFileAttributesW (Address: 0x1002f04c)
  • SetFilePointer (Address: 0x1002f088)
  • SetFileTime (Address: 0x1002f058)
  • WriteFile (Address: 0x1002f098)
api-ms-win-core-file-l1-2-0.dll
  • GetTempPathW (Address: 0x1002f0b0)
api-ms-win-core-file-l2-1-0.dll
  • CopyFileExW (Address: 0x1002f0bc)
  • MoveFileExW (Address: 0x1002f0b8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1002f0c4)
  • DuplicateHandle (Address: 0x1002f0c8)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1002f0f0)
  • HeapAlloc (Address: 0x1002f0ec)
  • HeapCompact (Address: 0x1002f0d4)
  • HeapCreate (Address: 0x1002f0d0)
  • HeapDestroy (Address: 0x1002f0dc)
  • HeapFree (Address: 0x1002f0e8)
  • HeapReAlloc (Address: 0x1002f0d8)
  • HeapSize (Address: 0x1002f0f4)
  • HeapValidate (Address: 0x1002f0e4)
  • HeapWalk (Address: 0x1002f0e0)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • GlobalAlloc (Address: 0x1002f108)
  • GlobalFree (Address: 0x1002f104)
  • GlobalLock (Address: 0x1002f100)
  • GlobalSize (Address: 0x1002f0fc)
  • GlobalUnlock (Address: 0x1002f10c)
  • LocalAlloc (Address: 0x1002f114)
  • LocalFree (Address: 0x1002f110)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x1002f120)
  • GetOverlappedResult (Address: 0x1002f11c)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • CreateFileMappingA (Address: 0x1002f128)
  • GlobalMemoryStatus (Address: 0x1002f12c)
api-ms-win-core-libraryloader-l1-1-0.dll
  • FindResourceExW (Address: 0x1002f14c)
  • FreeLibrary (Address: 0x1002f144)
  • GetModuleFileNameA (Address: 0x1002f150)
  • GetModuleFileNameW (Address: 0x1002f134)
  • GetModuleHandleExW (Address: 0x1002f140)
  • GetModuleHandleW (Address: 0x1002f148)
  • GetProcAddress (Address: 0x1002f158)
  • LoadLibraryExW (Address: 0x1002f13c)
  • LoadResource (Address: 0x1002f154)
  • LockResource (Address: 0x1002f138)
  • SizeofResource (Address: 0x1002f15c)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageA (Address: 0x1002f16c)
  • FormatMessageW (Address: 0x1002f168)
  • GetLocaleInfoW (Address: 0x1002f164)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x1002f178)
  • MapViewOfFile (Address: 0x1002f174)
  • UnmapViewOfFile (Address: 0x1002f17c)
  • VirtualAlloc (Address: 0x1002f188)
  • VirtualFree (Address: 0x1002f184)
  • VirtualQuery (Address: 0x1002f180)
api-ms-win-core-privateprofile-l1-1-0.dll
  • GetPrivateProfileStringW (Address: 0x1002f190)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1002f19c)
  • GetCommandLineW (Address: 0x1002f1a0)
  • GetEnvironmentVariableW (Address: 0x1002f198)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessA (Address: 0x1002f1e0)
  • CreateProcessW (Address: 0x1002f1dc)
  • CreateThread (Address: 0x1002f1b4)
  • ExitProcess (Address: 0x1002f1d8)
  • GetCurrentProcess (Address: 0x1002f1c0)
  • GetCurrentProcessId (Address: 0x1002f1ac)
  • GetCurrentThread (Address: 0x1002f1e4)
  • GetCurrentThreadId (Address: 0x1002f1bc)
  • GetExitCodeProcess (Address: 0x1002f1b0)
  • OpenProcessToken (Address: 0x1002f1cc)
  • OpenThreadToken (Address: 0x1002f1c4)
  • TerminateProcess (Address: 0x1002f1b8)
  • TlsAlloc (Address: 0x1002f1d4)
  • TlsFree (Address: 0x1002f1c8)
  • TlsGetValue (Address: 0x1002f1d0)
  • TlsSetValue (Address: 0x1002f1a8)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x1002f1ec)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1002f1f4)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1002f1fc)
  • RegOpenKeyExW (Address: 0x1002f204)
  • RegQueryValueExW (Address: 0x1002f200)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x1002f210)
  • WideCharToMultiByte (Address: 0x1002f20c)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1002f238)
  • CreateEventW (Address: 0x1002f224)
  • CreateMutexA (Address: 0x1002f240)
  • CreateMutexW (Address: 0x1002f244)
  • DeleteCriticalSection (Address: 0x1002f234)
  • EnterCriticalSection (Address: 0x1002f230)
  • InitializeCriticalSection (Address: 0x1002f21c)
  • LeaveCriticalSection (Address: 0x1002f22c)
  • OpenEventW (Address: 0x1002f23c)
  • ReleaseMutex (Address: 0x1002f248)
  • ReleaseSRWLockExclusive (Address: 0x1002f228)
  • ResetEvent (Address: 0x1002f24c)
  • SetEvent (Address: 0x1002f250)
  • WaitForMultipleObjectsEx (Address: 0x1002f218)
  • WaitForSingleObject (Address: 0x1002f220)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x1002f258)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x1002f264)
  • GetLocalTime (Address: 0x1002f278)
  • GetSystemInfo (Address: 0x1002f26c)
  • GetSystemTimeAsFileTime (Address: 0x1002f284)
  • GetTickCount (Address: 0x1002f274)
  • GetVersion (Address: 0x1002f280)
  • GetVersionExA (Address: 0x1002f268)
  • GetVersionExW (Address: 0x1002f260)
  • GetWindowsDirectoryA (Address: 0x1002f27c)
  • GetWindowsDirectoryW (Address: 0x1002f270)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x1002f290)
  • EventRegister (Address: 0x1002f28c)
  • EventUnregister (Address: 0x1002f294)
  • EventWriteTransfer (Address: 0x1002f298)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x1002f2ac)
  • AllocateAndInitializeSid (Address: 0x1002f2b4)
  • CheckTokenMembership (Address: 0x1002f2bc)
  • EqualSid (Address: 0x1002f2c0)
  • FreeSid (Address: 0x1002f2b8)
  • GetLengthSid (Address: 0x1002f2a8)
  • GetTokenInformation (Address: 0x1002f2c4)
  • InitializeAcl (Address: 0x1002f2a4)
  • InitializeSecurityDescriptor (Address: 0x1002f2a0)
  • SetSecurityDescriptorDacl (Address: 0x1002f2b0)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x1002f350)
  • __dllonexit (Address: 0x1002f368)
  • _amsg_exit (Address: 0x1002f320)
  • _callnewh (Address: 0x1002f310)
  • _CxxThrowException (Address: 0x1002f304)
  • _except_handler4_common (Address: 0x1002f32c)
  • _ftol2 (Address: 0x1002f300)
  • _initterm (Address: 0x1002f328)
  • _lock (Address: 0x1002f340)
  • _onexit (Address: 0x1002f370)
  • _purecall (Address: 0x1002f348)
  • _unlock (Address: 0x1002f364)
  • _vsnprintf (Address: 0x1002f34c)
  • _vsnwprintf (Address: 0x1002f338)
  • _wcsicmp (Address: 0x1002f360)
  • _wcslwr (Address: 0x1002f344)
  • _wcslwr_s (Address: 0x1002f308)
  • _wcsnicmp (Address: 0x1002f2e4)
  • _wfopen (Address: 0x1002f2cc)
  • _wtoi (Address: 0x1002f35c)
  • _XcptFilter (Address: 0x1002f318)
  • ??1type_info@@UAE@XZ (Address: 0x1002f2d8)
  • ?terminate@@YAXXZ (Address: 0x1002f2d0)
  • calloc (Address: 0x1002f31c)
  • fclose (Address: 0x1002f2dc)
  • feof (Address: 0x1002f30c)
  • fgetws (Address: 0x1002f2fc)
  • free (Address: 0x1002f2f8)
  • iswctype (Address: 0x1002f2e8)
  • malloc (Address: 0x1002f2f0)
  • memcpy (Address: 0x1002f36c)
  • memcpy_s (Address: 0x1002f314)
  • memmove (Address: 0x1002f334)
  • memmove_s (Address: 0x1002f2f4)
  • memset (Address: 0x1002f374)
  • strrchr (Address: 0x1002f324)
  • swscanf_s (Address: 0x1002f2e0)
  • toupper (Address: 0x1002f2ec)
  • towlower (Address: 0x1002f330)
  • wcschr (Address: 0x1002f33c)
  • wcsncmp (Address: 0x1002f358)
  • wcsrchr (Address: 0x1002f354)
  • wcstok_s (Address: 0x1002f2d4)
OLEAUT32.dll
  • SystemTimeToVariantTime (Address: 0x1002f004)
  • VariantTimeToSystemTime (Address: 0x1002f000)