fveapi.dll
Description: Windows BitLocker Drive Encryption API
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6456
Architecture: 64-bit
Operating System: Windows NT
SHA256: 8577d753f24fdd60a0c656e04d9025ef
File Size: 968.5 KB
Uploaded At: Dec. 1, 2025, 7:28 a.m.
Views: 12
Exported Functions
- InternalFveIsVolumeEncrypted (Ordinal: 1, Address: 0x445d0)
- NgscbCheckDmaSecurity (Ordinal: 2, Address: 0x798d0)
- NgscbCheckDmaSecurityEx (Ordinal: 3, Address: 0x798e0)
- NgscbCheckHSTIPrerequisitesVerified (Ordinal: 4, Address: 0x799d0)
- NgscbCheckIsAOACDevice (Ordinal: 5, Address: 0x207f0)
- NgscbCheckIsHSTIVerified (Ordinal: 6, Address: 0x20690)
- NgscbCheckPreventDeviceEncryption (Ordinal: 7, Address: 0x7ab80)
- NgscbCheckPreventDeviceEncryptionForAad (Ordinal: 8, Address: 0x7ac40)
- NgscbGetWinReConfiguration (Ordinal: 9, Address: 0x7c4f0)
- NgscbIsHostOsOnRoamableDrive (Ordinal: 10, Address: 0x208e0)
- FveAddAuthMethodInformation (Ordinal: 11, Address: 0x1f6e0)
- FveAddAuthMethodSid (Ordinal: 12, Address: 0x46130)
- FveAddPredictiveTpmProtector (Ordinal: 13, Address: 0x2c550)
- FveApplyGroupPolicy (Ordinal: 14, Address: 0xa7b0)
- FveApplyNkpCertChanges (Ordinal: 15, Address: 0x21e0)
- FveAttemptAutoUnlock (Ordinal: 16, Address: 0x46290)
- FveAuthElementFromPassPhraseW (Ordinal: 17, Address: 0x446e0)
- FveAuthElementFromPinW (Ordinal: 18, Address: 0x447a0)
- FveAuthElementFromRecoveryPasswordW (Ordinal: 19, Address: 0x10360)
- FveAuthElementGetKeyFileNameW (Ordinal: 20, Address: 0x44880)
- FveAuthElementReadExternalKeyW (Ordinal: 21, Address: 0x44960)
- FveAuthElementToRecoveryPasswordW (Ordinal: 22, Address: 0x102c0)
- FveAuthElementWriteExternalKeyW (Ordinal: 23, Address: 0x44a50)
- FveBackupRecoveryInformationToAD (Ordinal: 24, Address: 0x46380)
- FveBackupRecoveryInformationToADEx (Ordinal: 25, Address: 0x46480)
- FveBindDataVolume (Ordinal: 26, Address: 0x465b0)
- FveCanPinExceptionPolicyBeApplied (Ordinal: 27, Address: 0x44b10)
- FveCanStandardUsersChangePassphraseByProxy (Ordinal: 28, Address: 0x20f30)
- FveCanStandardUsersChangePin (Ordinal: 29, Address: 0x20ed0)
- FveCheckADRecoveryInfoBackupPolicy (Ordinal: 30, Address: 0x466c0)
- FveCheckADRecoveryInfoBackupPolicyEx (Ordinal: 31, Address: 0x467b0)
- FveCheckPassphrasePolicy (Ordinal: 32, Address: 0x46890)
- FveCheckTpmCapability (Ordinal: 33, Address: 0x46970)
- FveClearUserFlags (Ordinal: 34, Address: 0x44b20)
- FveCloseHandle (Ordinal: 35, Address: 0x26fe0)
- FveCloseVolume (Ordinal: 36, Address: 0x26f60)
- FveCommitChanges (Ordinal: 37, Address: 0x1f620)
- FveCommitChangesEx (Ordinal: 38, Address: 0x1f630)
- FveControl (Ordinal: 39, Address: 0x2c480)
- FveConversionDecrypt (Ordinal: 40, Address: 0x44b30)
- FveConversionDecryptEx (Ordinal: 41, Address: 0x44b40)
- FveConversionEncrypt (Ordinal: 42, Address: 0x46a50)
- FveConversionEncryptEx (Ordinal: 43, Address: 0x1730)
- FveConversionEncryptPendingReboot (Ordinal: 44, Address: 0x46ae0)
- FveConversionEncryptPendingRebootEx (Ordinal: 45, Address: 0x46af0)
- FveConversionPause (Ordinal: 46, Address: 0x44c40)
- FveConversionResume (Ordinal: 47, Address: 0x44d30)
- FveConversionStop (Ordinal: 48, Address: 0x44e20)
- FveConversionStopEx (Ordinal: 49, Address: 0x44e30)
- FveDecrementClearKeyCounter (Ordinal: 50, Address: 0x46bd0)
- FveDeleteAuthMethod (Ordinal: 51, Address: 0x46ca0)
- FveDeleteDeviceEncryptionOptOutForVolumeW (Ordinal: 52, Address: 0x46db0)
- FveDisableDeviceLockoutState (Ordinal: 53, Address: 0x46f00)
- FveDiscardChanges (Ordinal: 54, Address: 0x44f30)
- FveDraCertPresentInRegistry (Ordinal: 55, Address: 0x46fe0)
- FveEnableRawAccess (Ordinal: 56, Address: 0x45010)
- FveEnableRawAccessEx (Ordinal: 57, Address: 0x45020)
- FveEnableRawAccessW (Ordinal: 58, Address: 0x45110)
- FveEraseDrive (Ordinal: 59, Address: 0x10210)
- FveEscrowEncryptedRecoveryKeyForRetailUnlock (Ordinal: 60, Address: 0x47090)
- FveExternalDataCreateEntry (Ordinal: 61, Address: 0x2be70)
- FveExternalDataDeleteEntries (Ordinal: 62, Address: 0x2bf80)
- FveExternalDataGetEntryInfo (Ordinal: 63, Address: 0x2c070)
- FveExternalDataGetEntryRawData (Ordinal: 64, Address: 0x2c1a0)
- FveFindFirstVolume (Ordinal: 65, Address: 0x63e0)
- FveFindNextVolume (Ordinal: 66, Address: 0x6a00)
- FveFlagsToProtectorType (Ordinal: 67, Address: 0xef90)
- FveGenerateNbp (Ordinal: 68, Address: 0x47140)
- FveGenerateNkpSessionKeys (Ordinal: 69, Address: 0x24a0)
- FveGetAllowKeyExport (Ordinal: 70, Address: 0x1d720)
- FveGetAuthMethodGuids (Ordinal: 71, Address: 0x13460)
- FveGetAuthMethodInformation (Ordinal: 72, Address: 0x13a50)
- FveGetAuthMethodSid (Ordinal: 73, Address: 0x47230)
- FveGetAuthMethodSidInformation (Ordinal: 74, Address: 0x47330)
- FveGetClearKeyCounter (Ordinal: 75, Address: 0x1f2f0)
- FveGetDataSet (Ordinal: 76, Address: 0x45210)
- FveGetDescriptionW (Ordinal: 77, Address: 0x474e0)
- FveGetDeviceLockoutData (Ordinal: 78, Address: 0x475f0)
- FveGetExternalKeyBlob (Ordinal: 79, Address: 0x476e0)
- FveGetFipsAllowDisabled (Ordinal: 80, Address: 0x45320)
- FveGetFveMethod (Ordinal: 81, Address: 0x133b0)
- FveGetFveMethodEDrv (Ordinal: 82, Address: 0x453d0)
- FveGetFveMethodEx (Ordinal: 83, Address: 0x13da0)
- FveGetIdentificationFieldW (Ordinal: 84, Address: 0x10f30)
- FveGetIdentity (Ordinal: 85, Address: 0x13ca0)
- FveGetKeyPackage (Ordinal: 86, Address: 0x454d0)
- FveGetRecoveryPasswordBackupInformation (Ordinal: 87, Address: 0x455f0)
- FveGetSecureBootBindingState (Ordinal: 88, Address: 0x28630)
- FveGetStatus (Ordinal: 89, Address: 0x22be0)
- FveGetStatusW (Ordinal: 90, Address: 0x456e0)
- FveGetUserFlags (Ordinal: 91, Address: 0x44b20)
- FveGetVolumeNameW (Ordinal: 92, Address: 0x6f70)
- FveInitVolume (Ordinal: 93, Address: 0x477a0)
- FveInitVolumeEx (Ordinal: 94, Address: 0x1fbd0)
- FveInitializeDeviceEncryption (Ordinal: 95, Address: 0x47840)
- FveInitializeDeviceEncryption2 (Ordinal: 96, Address: 0x47a90)
- FveIsAnyDataVolumeBoundToOSVolume (Ordinal: 97, Address: 0x47c40)
- FveIsBoundDataVolume (Ordinal: 98, Address: 0x11760)
- FveIsBoundDataVolumeToOSVolume (Ordinal: 99, Address: 0x47d30)
- FveIsDeviceLockable (Ordinal: 100, Address: 0x47e50)
- FveIsDeviceLockedOut (Ordinal: 101, Address: 0x47f50)
- FveIsHardwareReadyForConversion (Ordinal: 102, Address: 0x45800)
- FveIsHybridVolume (Ordinal: 103, Address: 0x48030)
- FveIsHybridVolumeW (Ordinal: 104, Address: 0x48140)
- FveIsPassphraseCompatibleW (Ordinal: 105, Address: 0x45890)
- FveIsRecoveryPasswordGroupValidW (Ordinal: 106, Address: 0x45960)
- FveIsRecoveryPasswordValidW (Ordinal: 107, Address: 0xf3b0)
- FveIsSchemaExtInstalled (Ordinal: 108, Address: 0x48240)
- FveIsVolumeEncryptable (Ordinal: 109, Address: 0x25df0)
- FveKeyManagement (Ordinal: 110, Address: 0x482f0)
- FveLockDevice (Ordinal: 111, Address: 0x48430)
- FveLockVolume (Ordinal: 112, Address: 0xe4c0)
- FveLogRecoveryReason (Ordinal: 113, Address: 0x48500)
- FveNeedsDiscoveryVolumeUpdate (Ordinal: 114, Address: 0x48600)
- FveNotifyVolumeAfterFormat (Ordinal: 115, Address: 0x103e0)
- FveOpenVolumeByHandle (Ordinal: 116, Address: 0x71d0)
- FveOpenVolumeExW (Ordinal: 117, Address: 0x22190)
- FveOpenVolumeW (Ordinal: 118, Address: 0x22160)
- FveProtectorTypeToFlags (Ordinal: 119, Address: 0x1da40)
- FveQuery (Ordinal: 120, Address: 0x48710)
- FveQueryDeviceEncryptionSupport (Ordinal: 121, Address: 0x201b0)
- FveRecalculateOffsetsAndMoveMetadata (Ordinal: 122, Address: 0x487d0)
- FveRegenerateNbpSessionKey (Ordinal: 123, Address: 0x1e170)
- FveResetTpmDictionaryAttackParameters (Ordinal: 124, Address: 0x488f0)
- FveRevertVolume (Ordinal: 125, Address: 0x45a20)
- FveSaveRecoveryPasswordBackupFlag (Ordinal: 126, Address: 0x45af0)
- FveSelectBestRecoveryPasswordByBackupInformation (Ordinal: 127, Address: 0x45be0)
- FveServiceDiscoveryVolume (Ordinal: 128, Address: 0x48a30)
- FveSetAllowKeyExport (Ordinal: 129, Address: 0x1d850)
- FveSetDescriptionW (Ordinal: 130, Address: 0x48b00)
- FveSetFipsAllowDisabled (Ordinal: 131, Address: 0x28600)
- FveSetFveMethod (Ordinal: 132, Address: 0xe370)
- FveSetIdentificationFieldW (Ordinal: 133, Address: 0x48c00)
- FveSetRecoveryPasswordBackupInformation (Ordinal: 134, Address: 0x45cc0)
- FveSetUserFlags (Ordinal: 135, Address: 0x44b20)
- FveSetupTpmCallback (Ordinal: 136, Address: 0x2c980)
- FveSysClearUserFlags (Ordinal: 137, Address: 0x1dd70)
- FveSysCloseVolume (Ordinal: 138, Address: 0x1f290)
- FveSysGetUserFlags (Ordinal: 139, Address: 0x1d900)
- FveSysOpenVolumeW (Ordinal: 140, Address: 0x48d10)
- FveSysSetUserFlags (Ordinal: 141, Address: 0x1de10)
- FveUnbindAllDataVolumeFromOSVolume (Ordinal: 142, Address: 0x48dc0)
- FveUnbindDataVolume (Ordinal: 143, Address: 0x492a0)
- FveUnlockVolume (Ordinal: 144, Address: 0x1fa30)
- FveUnlockVolumeAuthMethodSid (Ordinal: 145, Address: 0x49380)
- FveUnlockVolumeWithAccessMode (Ordinal: 146, Address: 0x49470)
- FveUpdateBandIdBcd (Ordinal: 147, Address: 0x1e510)
- FveUpdateDeviceLockoutState (Ordinal: 148, Address: 0x495c0)
- FveUpdateDeviceLockoutStateEx (Ordinal: 149, Address: 0x49670)
- FveUpdatePinW (Ordinal: 150, Address: 0x49780)
- FveUpgradeVolume (Ordinal: 151, Address: 0x45dd0)
- FveValidateDeviceLockoutState (Ordinal: 152, Address: 0x49890)
- FveValidateExistingPassphraseW (Ordinal: 153, Address: 0x49960)
- FveValidateExistingPinW (Ordinal: 154, Address: 0x49a70)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x1800bd030)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x1800bd050)
- CoCreateGuid (Address: 0x1800bd068)
- CoGetCallContext (Address: 0x1800bd060)
- CoInitializeEx (Address: 0x1800bd040)
- CoUninitialize (Address: 0x1800bd048)
- StringFromGUID2 (Address: 0x1800bd058)
api-ms-win-core-datetime-l1-1-0.dll
- GetDateFormatW (Address: 0x1800bd080)
- GetTimeFormatW (Address: 0x1800bd078)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800bd0a0)
- IsDebuggerPresent (Address: 0x1800bd098)
- OutputDebugStringW (Address: 0x1800bd090)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800bd0b0)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800bd0c0)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800bd0e8)
- SetLastError (Address: 0x1800bd0d0)
- SetUnhandledExceptionFilter (Address: 0x1800bd0e0)
- UnhandledExceptionFilter (Address: 0x1800bd0d8)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x1800bd100)
- CreateFileW (Address: 0x1800bd110)
- DeleteFileW (Address: 0x1800bd1a0)
- FileTimeToLocalFileTime (Address: 0x1800bd188)
- FindClose (Address: 0x1800bd130)
- FindFirstFileW (Address: 0x1800bd108)
- FindFirstVolumeW (Address: 0x1800bd150)
- FindNextFileW (Address: 0x1800bd180)
- FindNextVolumeW (Address: 0x1800bd158)
- FindVolumeClose (Address: 0x1800bd160)
- FlushFileBuffers (Address: 0x1800bd190)
- GetDiskFreeSpaceW (Address: 0x1800bd118)
- GetDriveTypeW (Address: 0x1800bd1c0)
- GetFileAttributesW (Address: 0x1800bd138)
- GetFileInformationByHandle (Address: 0x1800bd0f8)
- GetFileSize (Address: 0x1800bd168)
- GetFileSizeEx (Address: 0x1800bd1b0)
- GetLogicalDrives (Address: 0x1800bd140)
- GetVolumeInformationW (Address: 0x1800bd128)
- GetVolumePathNameW (Address: 0x1800bd1a8)
- ReadFile (Address: 0x1800bd120)
- RemoveDirectoryW (Address: 0x1800bd1b8)
- SetEndOfFile (Address: 0x1800bd178)
- SetFileAttributesW (Address: 0x1800bd1c8)
- SetFilePointer (Address: 0x1800bd170)
- SetFilePointerEx (Address: 0x1800bd148)
- WriteFile (Address: 0x1800bd198)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x1800bd1e0)
- GetVolumeNameForVolumeMountPointW (Address: 0x1800bd1d8)
- GetVolumePathNamesForVolumeNameW (Address: 0x1800bd1e8)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800bd1f8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800bd210)
- HeapAlloc (Address: 0x1800bd220)
- HeapFree (Address: 0x1800bd218)
- HeapSize (Address: 0x1800bd208)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1800bd230)
- LocalFree (Address: 0x1800bd238)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x1800bd248)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x1800bd278)
- GetModuleFileNameA (Address: 0x1800bd258)
- GetModuleFileNameW (Address: 0x1800bd260)
- GetModuleHandleExW (Address: 0x1800bd270)
- GetModuleHandleW (Address: 0x1800bd268)
- GetProcAddress (Address: 0x1800bd280)
- LoadLibraryExW (Address: 0x1800bd290)
- LoadStringW (Address: 0x1800bd288)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800bd2a8)
- IsDBCSLeadByte (Address: 0x1800bd2a0)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x1800bd2b8)
- MapViewOfFile (Address: 0x1800bd2c0)
- UnmapViewOfFile (Address: 0x1800bd2c8)
- VirtualAlloc (Address: 0x1800bd2d0)
- VirtualFree (Address: 0x1800bd2d8)
api-ms-win-core-path-l1-1-0.dll
- PathCchCombine (Address: 0x1800bd2e8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1800bd330)
- GetCurrentProcessId (Address: 0x1800bd2f8)
- GetCurrentThread (Address: 0x1800bd348)
- GetCurrentThreadId (Address: 0x1800bd308)
- OpenProcessToken (Address: 0x1800bd300)
- OpenThreadToken (Address: 0x1800bd328)
- SetThreadToken (Address: 0x1800bd310)
- TerminateProcess (Address: 0x1800bd320)
- TlsAlloc (Address: 0x1800bd318)
- TlsFree (Address: 0x1800bd338)
- TlsGetValue (Address: 0x1800bd340)
- TlsSetValue (Address: 0x1800bd350)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800bd360)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800bd390)
- RegCreateKeyExW (Address: 0x1800bd388)
- RegDeleteKeyExW (Address: 0x1800bd3d8)
- RegDeleteValueW (Address: 0x1800bd3d0)
- RegEnumKeyExW (Address: 0x1800bd370)
- RegEnumValueW (Address: 0x1800bd3b8)
- RegFlushKey (Address: 0x1800bd378)
- RegGetValueA (Address: 0x1800bd3e0)
- RegGetValueW (Address: 0x1800bd3a8)
- RegLoadKeyW (Address: 0x1800bd3c0)
- RegOpenKeyExW (Address: 0x1800bd3a0)
- RegQueryInfoKeyW (Address: 0x1800bd3b0)
- RegQueryValueExW (Address: 0x1800bd398)
- RegSetValueExW (Address: 0x1800bd380)
- RegUnLoadKeyW (Address: 0x1800bd3c8)
api-ms-win-core-registry-l1-1-1.dll
- RegSetKeyValueW (Address: 0x1800bd3f0)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1800bd408)
- CompareStringW (Address: 0x1800bd400)
- MultiByteToWideChar (Address: 0x1800bd418)
- WideCharToMultiByte (Address: 0x1800bd410)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800bd468)
- AcquireSRWLockShared (Address: 0x1800bd450)
- CreateEventW (Address: 0x1800bd478)
- CreateMutexExW (Address: 0x1800bd470)
- CreateSemaphoreExW (Address: 0x1800bd458)
- DeleteCriticalSection (Address: 0x1800bd428)
- EnterCriticalSection (Address: 0x1800bd490)
- InitializeCriticalSection (Address: 0x1800bd480)
- InitializeCriticalSectionEx (Address: 0x1800bd488)
- InitializeSRWLock (Address: 0x1800bd4a0)
- LeaveCriticalSection (Address: 0x1800bd460)
- OpenSemaphoreW (Address: 0x1800bd430)
- ReleaseMutex (Address: 0x1800bd4b8)
- ReleaseSemaphore (Address: 0x1800bd4a8)
- ReleaseSRWLockExclusive (Address: 0x1800bd440)
- ReleaseSRWLockShared (Address: 0x1800bd448)
- SetEvent (Address: 0x1800bd498)
- WaitForSingleObject (Address: 0x1800bd4b0)
- WaitForSingleObjectEx (Address: 0x1800bd438)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x1800bd4c8)
- Sleep (Address: 0x1800bd4d0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x1800bd510)
- GetLocalTime (Address: 0x1800bd4f8)
- GetSystemTime (Address: 0x1800bd4e8)
- GetSystemTimeAsFileTime (Address: 0x1800bd508)
- GetSystemWindowsDirectoryW (Address: 0x1800bd500)
- GetTickCount (Address: 0x1800bd518)
- GetTickCount64 (Address: 0x1800bd4e0)
- GetVersionExW (Address: 0x1800bd4f0)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetProductInfo (Address: 0x1800bd528)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1800bd550)
- CreateThreadpoolTimer (Address: 0x1800bd538)
- SetThreadpoolTimer (Address: 0x1800bd540)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800bd548)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x1800bd560)
- GetTimeZoneInformation (Address: 0x1800bd570)
- SystemTimeToFileTime (Address: 0x1800bd568)
api-ms-win-devices-config-l1-1-1.dll
- CM_Register_Notification (Address: 0x1800bd580)
- CM_Unregister_Notification (Address: 0x1800bd588)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x1800bd5a8)
- GetTraceEnableLevel (Address: 0x1800bd598)
- GetTraceLoggerHandle (Address: 0x1800bd5b8)
- RegisterTraceGuidsW (Address: 0x1800bd5b0)
- TraceMessage (Address: 0x1800bd5c0)
- UnregisterTraceGuids (Address: 0x1800bd5a0)
api-ms-win-eventing-controller-l1-1-0.dll
- ControlTraceW (Address: 0x1800bd5e0)
- EnableTraceEx2 (Address: 0x1800bd5d0)
- StartTraceW (Address: 0x1800bd5d8)
api-ms-win-eventing-provider-l1-1-0.dll
- EventProviderEnabled (Address: 0x1800bd610)
- EventRegister (Address: 0x1800bd5f8)
- EventSetInformation (Address: 0x1800bd5f0)
- EventUnregister (Address: 0x1800bd608)
- EventWriteTransfer (Address: 0x1800bd600)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x1800bd640)
- AllocateAndInitializeSid (Address: 0x1800bd630)
- CheckTokenMembership (Address: 0x1800bd648)
- CopySid (Address: 0x1800bd628)
- DuplicateTokenEx (Address: 0x1800bd660)
- FreeSid (Address: 0x1800bd638)
- GetLengthSid (Address: 0x1800bd620)
- GetTokenInformation (Address: 0x1800bd668)
- ImpersonateSelf (Address: 0x1800bd650)
- RevertToSelf (Address: 0x1800bd658)
api-ms-win-security-lsapolicy-l1-1-0.dll
- LsaClose (Address: 0x1800bd688)
- LsaFreeMemory (Address: 0x1800bd678)
- LsaOpenPolicy (Address: 0x1800bd690)
- LsaQueryInformationPolicy (Address: 0x1800bd680)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1800bd6a8)
- ConvertStringSidToSidW (Address: 0x1800bd6a0)
api-ms-win-service-private-l1-1-0.dll
- I_QueryTagInformation (Address: 0x1800bd6b8)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1800bd6d0)
- BCryptCreateHash (Address: 0x1800bd738)
- BCryptDecrypt (Address: 0x1800bd760)
- BCryptDeriveKey (Address: 0x1800bd720)
- BCryptDeriveKeyPBKDF2 (Address: 0x1800bd6f8)
- BCryptDestroyHash (Address: 0x1800bd758)
- BCryptDestroyKey (Address: 0x1800bd740)
- BCryptDestroySecret (Address: 0x1800bd728)
- BCryptEncrypt (Address: 0x1800bd6d8)
- BCryptExportKey (Address: 0x1800bd6f0)
- BCryptFinalizeKeyPair (Address: 0x1800bd710)
- BCryptFinishHash (Address: 0x1800bd750)
- BCryptGenerateKeyPair (Address: 0x1800bd708)
- BCryptGenerateSymmetricKey (Address: 0x1800bd770)
- BCryptGenRandom (Address: 0x1800bd6e8)
- BCryptGetFipsAlgorithmMode (Address: 0x1800bd6c8)
- BCryptGetProperty (Address: 0x1800bd700)
- BCryptHashData (Address: 0x1800bd748)
- BCryptImportKeyPair (Address: 0x1800bd6e0)
- BCryptOpenAlgorithmProvider (Address: 0x1800bd730)
- BCryptSecretAgreement (Address: 0x1800bd718)
- BCryptSetProperty (Address: 0x1800bd768)
msvcrt.dll
- __C_specific_handler (Address: 0x1800bd868)
- __CxxFrameHandler3 (Address: 0x1800bd858)
- __dllonexit (Address: 0x1800bd8d0)
- _amsg_exit (Address: 0x1800bd838)
- _callnewh (Address: 0x1800bd8b0)
- _CxxThrowException (Address: 0x1800bd860)
- _errno (Address: 0x1800bd828)
- _initterm (Address: 0x1800bd8f0)
- _lock (Address: 0x1800bd8e0)
- _onexit (Address: 0x1800bd8c8)
- _purecall (Address: 0x1800bd8a8)
- _scwprintf (Address: 0x1800bd800)
- _stricmp (Address: 0x1800bd7e8)
- _strnicmp (Address: 0x1800bd878)
- _unlock (Address: 0x1800bd8d8)
- _vsnwprintf (Address: 0x1800bd798)
- _wcsicmp (Address: 0x1800bd780)
- _wcsupr (Address: 0x1800bd810)
- _wtempnam (Address: 0x1800bd7b0)
- _XcptFilter (Address: 0x1800bd840)
- ??_V@YAXPEAX@Z (Address: 0x1800bd808)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800bd7d0)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800bd7c0)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800bd7b8)
- ??1exception@@UEAA@XZ (Address: 0x1800bd8b8)
- ??1type_info@@UEAA@XZ (Address: 0x1800bd8c0)
- ??3@YAXPEAX@Z (Address: 0x1800bd8a0)
- ?what@exception@@UEBAPEBDXZ (Address: 0x1800bd870)
- ceil (Address: 0x1800bd880)
- free (Address: 0x1800bd8f8)
- iswascii (Address: 0x1800bd7f8)
- iswdigit (Address: 0x1800bd7a0)
- malloc (Address: 0x1800bd8e8)
- memcmp (Address: 0x1800bd888)
- memcpy (Address: 0x1800bd850)
- memcpy_s (Address: 0x1800bd790)
- memmove (Address: 0x1800bd848)
- memmove_s (Address: 0x1800bd788)
- memset (Address: 0x1800bd890)
- sprintf_s (Address: 0x1800bd820)
- strcmp (Address: 0x1800bd898)
- time (Address: 0x1800bd818)
- toupper (Address: 0x1800bd830)
- wcschr (Address: 0x1800bd7f0)
- wcscmp (Address: 0x1800bd900)
- wcscpy_s (Address: 0x1800bd7c8)
- wcsncat_s (Address: 0x1800bd7e0)
- wcsncpy_s (Address: 0x1800bd7d8)
- wcstoul (Address: 0x1800bd7a8)
ntdll.dll
- EtwEventRegister (Address: 0x1800bd9c0)
- EtwEventUnregister (Address: 0x1800bd9b8)
- EtwEventWrite (Address: 0x1800bd9b0)
- NtClose (Address: 0x1800bd998)
- NtOpenFile (Address: 0x1800bd970)
- NtOpenKey (Address: 0x1800bd9a8)
- NtPowerInformation (Address: 0x1800bd940)
- NtQueryInformationFile (Address: 0x1800bda28)
- NtQuerySystemEnvironmentValueEx (Address: 0x1800bd950)
- NtQuerySystemInformation (Address: 0x1800bd9e0)
- NtQueryValueKey (Address: 0x1800bd9a0)
- NtQueryVolumeInformationFile (Address: 0x1800bd9d8)
- NtQueryWnfStateData (Address: 0x1800bd9d0)
- RtlCaptureContext (Address: 0x1800bda10)
- RtlCheckPortableOperatingSystem (Address: 0x1800bd948)
- RtlCompareMemory (Address: 0x1800bd960)
- RtlCreateSystemVolumeInformationFolder (Address: 0x1800bd930)
- RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x1800bd938)
- RtlFreeUnicodeString (Address: 0x1800bd988)
- RtlGenerate8dot3Name (Address: 0x1800bd928)
- RtlInitUnicodeString (Address: 0x1800bd958)
- RtlIsMultiSessionSku (Address: 0x1800bda18)
- RtlLengthSid (Address: 0x1800bda20)
- RtlLookupFunctionEntry (Address: 0x1800bda08)
- RtlNtStatusToDosError (Address: 0x1800bd9f0)
- RtlPublishWnfStateData (Address: 0x1800bd9c8)
- RtlSetThreadErrorMode (Address: 0x1800bd9e8)
- RtlStringFromGUID (Address: 0x1800bd990)
- RtlSubscribeWnfStateChangeNotification (Address: 0x1800bd9f8)
- RtlSystemTimeToLocalTime (Address: 0x1800bd910)
- RtlTimeToTimeFields (Address: 0x1800bd918)
- RtlUnicodeStringToCountedOemString (Address: 0x1800bd920)
- RtlUnsubscribeWnfStateChangeNotification (Address: 0x1800bd968)
- RtlVirtualUnwind (Address: 0x1800bda00)
- WinSqmAddToStreamEx (Address: 0x1800bd980)
- WinSqmSetDWORD (Address: 0x1800bd978)