fveapi.dll

Description: Windows BitLocker Drive Encryption API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6456

Architecture: 64-bit

Operating System: Windows NT

SHA256: 8577d753f24fdd60a0c656e04d9025ef

File Size: 968.5 KB

Uploaded At: Dec. 1, 2025, 7:28 a.m.

Views: 12

Exported Functions

  • InternalFveIsVolumeEncrypted (Ordinal: 1, Address: 0x445d0)
  • NgscbCheckDmaSecurity (Ordinal: 2, Address: 0x798d0)
  • NgscbCheckDmaSecurityEx (Ordinal: 3, Address: 0x798e0)
  • NgscbCheckHSTIPrerequisitesVerified (Ordinal: 4, Address: 0x799d0)
  • NgscbCheckIsAOACDevice (Ordinal: 5, Address: 0x207f0)
  • NgscbCheckIsHSTIVerified (Ordinal: 6, Address: 0x20690)
  • NgscbCheckPreventDeviceEncryption (Ordinal: 7, Address: 0x7ab80)
  • NgscbCheckPreventDeviceEncryptionForAad (Ordinal: 8, Address: 0x7ac40)
  • NgscbGetWinReConfiguration (Ordinal: 9, Address: 0x7c4f0)
  • NgscbIsHostOsOnRoamableDrive (Ordinal: 10, Address: 0x208e0)
  • FveAddAuthMethodInformation (Ordinal: 11, Address: 0x1f6e0)
  • FveAddAuthMethodSid (Ordinal: 12, Address: 0x46130)
  • FveAddPredictiveTpmProtector (Ordinal: 13, Address: 0x2c550)
  • FveApplyGroupPolicy (Ordinal: 14, Address: 0xa7b0)
  • FveApplyNkpCertChanges (Ordinal: 15, Address: 0x21e0)
  • FveAttemptAutoUnlock (Ordinal: 16, Address: 0x46290)
  • FveAuthElementFromPassPhraseW (Ordinal: 17, Address: 0x446e0)
  • FveAuthElementFromPinW (Ordinal: 18, Address: 0x447a0)
  • FveAuthElementFromRecoveryPasswordW (Ordinal: 19, Address: 0x10360)
  • FveAuthElementGetKeyFileNameW (Ordinal: 20, Address: 0x44880)
  • FveAuthElementReadExternalKeyW (Ordinal: 21, Address: 0x44960)
  • FveAuthElementToRecoveryPasswordW (Ordinal: 22, Address: 0x102c0)
  • FveAuthElementWriteExternalKeyW (Ordinal: 23, Address: 0x44a50)
  • FveBackupRecoveryInformationToAD (Ordinal: 24, Address: 0x46380)
  • FveBackupRecoveryInformationToADEx (Ordinal: 25, Address: 0x46480)
  • FveBindDataVolume (Ordinal: 26, Address: 0x465b0)
  • FveCanPinExceptionPolicyBeApplied (Ordinal: 27, Address: 0x44b10)
  • FveCanStandardUsersChangePassphraseByProxy (Ordinal: 28, Address: 0x20f30)
  • FveCanStandardUsersChangePin (Ordinal: 29, Address: 0x20ed0)
  • FveCheckADRecoveryInfoBackupPolicy (Ordinal: 30, Address: 0x466c0)
  • FveCheckADRecoveryInfoBackupPolicyEx (Ordinal: 31, Address: 0x467b0)
  • FveCheckPassphrasePolicy (Ordinal: 32, Address: 0x46890)
  • FveCheckTpmCapability (Ordinal: 33, Address: 0x46970)
  • FveClearUserFlags (Ordinal: 34, Address: 0x44b20)
  • FveCloseHandle (Ordinal: 35, Address: 0x26fe0)
  • FveCloseVolume (Ordinal: 36, Address: 0x26f60)
  • FveCommitChanges (Ordinal: 37, Address: 0x1f620)
  • FveCommitChangesEx (Ordinal: 38, Address: 0x1f630)
  • FveControl (Ordinal: 39, Address: 0x2c480)
  • FveConversionDecrypt (Ordinal: 40, Address: 0x44b30)
  • FveConversionDecryptEx (Ordinal: 41, Address: 0x44b40)
  • FveConversionEncrypt (Ordinal: 42, Address: 0x46a50)
  • FveConversionEncryptEx (Ordinal: 43, Address: 0x1730)
  • FveConversionEncryptPendingReboot (Ordinal: 44, Address: 0x46ae0)
  • FveConversionEncryptPendingRebootEx (Ordinal: 45, Address: 0x46af0)
  • FveConversionPause (Ordinal: 46, Address: 0x44c40)
  • FveConversionResume (Ordinal: 47, Address: 0x44d30)
  • FveConversionStop (Ordinal: 48, Address: 0x44e20)
  • FveConversionStopEx (Ordinal: 49, Address: 0x44e30)
  • FveDecrementClearKeyCounter (Ordinal: 50, Address: 0x46bd0)
  • FveDeleteAuthMethod (Ordinal: 51, Address: 0x46ca0)
  • FveDeleteDeviceEncryptionOptOutForVolumeW (Ordinal: 52, Address: 0x46db0)
  • FveDisableDeviceLockoutState (Ordinal: 53, Address: 0x46f00)
  • FveDiscardChanges (Ordinal: 54, Address: 0x44f30)
  • FveDraCertPresentInRegistry (Ordinal: 55, Address: 0x46fe0)
  • FveEnableRawAccess (Ordinal: 56, Address: 0x45010)
  • FveEnableRawAccessEx (Ordinal: 57, Address: 0x45020)
  • FveEnableRawAccessW (Ordinal: 58, Address: 0x45110)
  • FveEraseDrive (Ordinal: 59, Address: 0x10210)
  • FveEscrowEncryptedRecoveryKeyForRetailUnlock (Ordinal: 60, Address: 0x47090)
  • FveExternalDataCreateEntry (Ordinal: 61, Address: 0x2be70)
  • FveExternalDataDeleteEntries (Ordinal: 62, Address: 0x2bf80)
  • FveExternalDataGetEntryInfo (Ordinal: 63, Address: 0x2c070)
  • FveExternalDataGetEntryRawData (Ordinal: 64, Address: 0x2c1a0)
  • FveFindFirstVolume (Ordinal: 65, Address: 0x63e0)
  • FveFindNextVolume (Ordinal: 66, Address: 0x6a00)
  • FveFlagsToProtectorType (Ordinal: 67, Address: 0xef90)
  • FveGenerateNbp (Ordinal: 68, Address: 0x47140)
  • FveGenerateNkpSessionKeys (Ordinal: 69, Address: 0x24a0)
  • FveGetAllowKeyExport (Ordinal: 70, Address: 0x1d720)
  • FveGetAuthMethodGuids (Ordinal: 71, Address: 0x13460)
  • FveGetAuthMethodInformation (Ordinal: 72, Address: 0x13a50)
  • FveGetAuthMethodSid (Ordinal: 73, Address: 0x47230)
  • FveGetAuthMethodSidInformation (Ordinal: 74, Address: 0x47330)
  • FveGetClearKeyCounter (Ordinal: 75, Address: 0x1f2f0)
  • FveGetDataSet (Ordinal: 76, Address: 0x45210)
  • FveGetDescriptionW (Ordinal: 77, Address: 0x474e0)
  • FveGetDeviceLockoutData (Ordinal: 78, Address: 0x475f0)
  • FveGetExternalKeyBlob (Ordinal: 79, Address: 0x476e0)
  • FveGetFipsAllowDisabled (Ordinal: 80, Address: 0x45320)
  • FveGetFveMethod (Ordinal: 81, Address: 0x133b0)
  • FveGetFveMethodEDrv (Ordinal: 82, Address: 0x453d0)
  • FveGetFveMethodEx (Ordinal: 83, Address: 0x13da0)
  • FveGetIdentificationFieldW (Ordinal: 84, Address: 0x10f30)
  • FveGetIdentity (Ordinal: 85, Address: 0x13ca0)
  • FveGetKeyPackage (Ordinal: 86, Address: 0x454d0)
  • FveGetRecoveryPasswordBackupInformation (Ordinal: 87, Address: 0x455f0)
  • FveGetSecureBootBindingState (Ordinal: 88, Address: 0x28630)
  • FveGetStatus (Ordinal: 89, Address: 0x22be0)
  • FveGetStatusW (Ordinal: 90, Address: 0x456e0)
  • FveGetUserFlags (Ordinal: 91, Address: 0x44b20)
  • FveGetVolumeNameW (Ordinal: 92, Address: 0x6f70)
  • FveInitVolume (Ordinal: 93, Address: 0x477a0)
  • FveInitVolumeEx (Ordinal: 94, Address: 0x1fbd0)
  • FveInitializeDeviceEncryption (Ordinal: 95, Address: 0x47840)
  • FveInitializeDeviceEncryption2 (Ordinal: 96, Address: 0x47a90)
  • FveIsAnyDataVolumeBoundToOSVolume (Ordinal: 97, Address: 0x47c40)
  • FveIsBoundDataVolume (Ordinal: 98, Address: 0x11760)
  • FveIsBoundDataVolumeToOSVolume (Ordinal: 99, Address: 0x47d30)
  • FveIsDeviceLockable (Ordinal: 100, Address: 0x47e50)
  • FveIsDeviceLockedOut (Ordinal: 101, Address: 0x47f50)
  • FveIsHardwareReadyForConversion (Ordinal: 102, Address: 0x45800)
  • FveIsHybridVolume (Ordinal: 103, Address: 0x48030)
  • FveIsHybridVolumeW (Ordinal: 104, Address: 0x48140)
  • FveIsPassphraseCompatibleW (Ordinal: 105, Address: 0x45890)
  • FveIsRecoveryPasswordGroupValidW (Ordinal: 106, Address: 0x45960)
  • FveIsRecoveryPasswordValidW (Ordinal: 107, Address: 0xf3b0)
  • FveIsSchemaExtInstalled (Ordinal: 108, Address: 0x48240)
  • FveIsVolumeEncryptable (Ordinal: 109, Address: 0x25df0)
  • FveKeyManagement (Ordinal: 110, Address: 0x482f0)
  • FveLockDevice (Ordinal: 111, Address: 0x48430)
  • FveLockVolume (Ordinal: 112, Address: 0xe4c0)
  • FveLogRecoveryReason (Ordinal: 113, Address: 0x48500)
  • FveNeedsDiscoveryVolumeUpdate (Ordinal: 114, Address: 0x48600)
  • FveNotifyVolumeAfterFormat (Ordinal: 115, Address: 0x103e0)
  • FveOpenVolumeByHandle (Ordinal: 116, Address: 0x71d0)
  • FveOpenVolumeExW (Ordinal: 117, Address: 0x22190)
  • FveOpenVolumeW (Ordinal: 118, Address: 0x22160)
  • FveProtectorTypeToFlags (Ordinal: 119, Address: 0x1da40)
  • FveQuery (Ordinal: 120, Address: 0x48710)
  • FveQueryDeviceEncryptionSupport (Ordinal: 121, Address: 0x201b0)
  • FveRecalculateOffsetsAndMoveMetadata (Ordinal: 122, Address: 0x487d0)
  • FveRegenerateNbpSessionKey (Ordinal: 123, Address: 0x1e170)
  • FveResetTpmDictionaryAttackParameters (Ordinal: 124, Address: 0x488f0)
  • FveRevertVolume (Ordinal: 125, Address: 0x45a20)
  • FveSaveRecoveryPasswordBackupFlag (Ordinal: 126, Address: 0x45af0)
  • FveSelectBestRecoveryPasswordByBackupInformation (Ordinal: 127, Address: 0x45be0)
  • FveServiceDiscoveryVolume (Ordinal: 128, Address: 0x48a30)
  • FveSetAllowKeyExport (Ordinal: 129, Address: 0x1d850)
  • FveSetDescriptionW (Ordinal: 130, Address: 0x48b00)
  • FveSetFipsAllowDisabled (Ordinal: 131, Address: 0x28600)
  • FveSetFveMethod (Ordinal: 132, Address: 0xe370)
  • FveSetIdentificationFieldW (Ordinal: 133, Address: 0x48c00)
  • FveSetRecoveryPasswordBackupInformation (Ordinal: 134, Address: 0x45cc0)
  • FveSetUserFlags (Ordinal: 135, Address: 0x44b20)
  • FveSetupTpmCallback (Ordinal: 136, Address: 0x2c980)
  • FveSysClearUserFlags (Ordinal: 137, Address: 0x1dd70)
  • FveSysCloseVolume (Ordinal: 138, Address: 0x1f290)
  • FveSysGetUserFlags (Ordinal: 139, Address: 0x1d900)
  • FveSysOpenVolumeW (Ordinal: 140, Address: 0x48d10)
  • FveSysSetUserFlags (Ordinal: 141, Address: 0x1de10)
  • FveUnbindAllDataVolumeFromOSVolume (Ordinal: 142, Address: 0x48dc0)
  • FveUnbindDataVolume (Ordinal: 143, Address: 0x492a0)
  • FveUnlockVolume (Ordinal: 144, Address: 0x1fa30)
  • FveUnlockVolumeAuthMethodSid (Ordinal: 145, Address: 0x49380)
  • FveUnlockVolumeWithAccessMode (Ordinal: 146, Address: 0x49470)
  • FveUpdateBandIdBcd (Ordinal: 147, Address: 0x1e510)
  • FveUpdateDeviceLockoutState (Ordinal: 148, Address: 0x495c0)
  • FveUpdateDeviceLockoutStateEx (Ordinal: 149, Address: 0x49670)
  • FveUpdatePinW (Ordinal: 150, Address: 0x49780)
  • FveUpgradeVolume (Ordinal: 151, Address: 0x45dd0)
  • FveValidateDeviceLockoutState (Ordinal: 152, Address: 0x49890)
  • FveValidateExistingPassphraseW (Ordinal: 153, Address: 0x49960)
  • FveValidateExistingPinW (Ordinal: 154, Address: 0x49a70)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x1800bd030)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x1800bd050)
  • CoCreateGuid (Address: 0x1800bd068)
  • CoGetCallContext (Address: 0x1800bd060)
  • CoInitializeEx (Address: 0x1800bd040)
  • CoUninitialize (Address: 0x1800bd048)
  • StringFromGUID2 (Address: 0x1800bd058)
api-ms-win-core-datetime-l1-1-0.dll
  • GetDateFormatW (Address: 0x1800bd080)
  • GetTimeFormatW (Address: 0x1800bd078)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800bd0a0)
  • IsDebuggerPresent (Address: 0x1800bd098)
  • OutputDebugStringW (Address: 0x1800bd090)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800bd0b0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800bd0c0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800bd0e8)
  • SetLastError (Address: 0x1800bd0d0)
  • SetUnhandledExceptionFilter (Address: 0x1800bd0e0)
  • UnhandledExceptionFilter (Address: 0x1800bd0d8)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x1800bd100)
  • CreateFileW (Address: 0x1800bd110)
  • DeleteFileW (Address: 0x1800bd1a0)
  • FileTimeToLocalFileTime (Address: 0x1800bd188)
  • FindClose (Address: 0x1800bd130)
  • FindFirstFileW (Address: 0x1800bd108)
  • FindFirstVolumeW (Address: 0x1800bd150)
  • FindNextFileW (Address: 0x1800bd180)
  • FindNextVolumeW (Address: 0x1800bd158)
  • FindVolumeClose (Address: 0x1800bd160)
  • FlushFileBuffers (Address: 0x1800bd190)
  • GetDiskFreeSpaceW (Address: 0x1800bd118)
  • GetDriveTypeW (Address: 0x1800bd1c0)
  • GetFileAttributesW (Address: 0x1800bd138)
  • GetFileInformationByHandle (Address: 0x1800bd0f8)
  • GetFileSize (Address: 0x1800bd168)
  • GetFileSizeEx (Address: 0x1800bd1b0)
  • GetLogicalDrives (Address: 0x1800bd140)
  • GetVolumeInformationW (Address: 0x1800bd128)
  • GetVolumePathNameW (Address: 0x1800bd1a8)
  • ReadFile (Address: 0x1800bd120)
  • RemoveDirectoryW (Address: 0x1800bd1b8)
  • SetEndOfFile (Address: 0x1800bd178)
  • SetFileAttributesW (Address: 0x1800bd1c8)
  • SetFilePointer (Address: 0x1800bd170)
  • SetFilePointerEx (Address: 0x1800bd148)
  • WriteFile (Address: 0x1800bd198)
api-ms-win-core-file-l1-2-0.dll
  • GetTempPathW (Address: 0x1800bd1e0)
  • GetVolumeNameForVolumeMountPointW (Address: 0x1800bd1d8)
  • GetVolumePathNamesForVolumeNameW (Address: 0x1800bd1e8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800bd1f8)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1800bd210)
  • HeapAlloc (Address: 0x1800bd220)
  • HeapFree (Address: 0x1800bd218)
  • HeapSize (Address: 0x1800bd208)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1800bd230)
  • LocalFree (Address: 0x1800bd238)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x1800bd248)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x1800bd278)
  • GetModuleFileNameA (Address: 0x1800bd258)
  • GetModuleFileNameW (Address: 0x1800bd260)
  • GetModuleHandleExW (Address: 0x1800bd270)
  • GetModuleHandleW (Address: 0x1800bd268)
  • GetProcAddress (Address: 0x1800bd280)
  • LoadLibraryExW (Address: 0x1800bd290)
  • LoadStringW (Address: 0x1800bd288)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800bd2a8)
  • IsDBCSLeadByte (Address: 0x1800bd2a0)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x1800bd2b8)
  • MapViewOfFile (Address: 0x1800bd2c0)
  • UnmapViewOfFile (Address: 0x1800bd2c8)
  • VirtualAlloc (Address: 0x1800bd2d0)
  • VirtualFree (Address: 0x1800bd2d8)
api-ms-win-core-path-l1-1-0.dll
  • PathCchCombine (Address: 0x1800bd2e8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800bd330)
  • GetCurrentProcessId (Address: 0x1800bd2f8)
  • GetCurrentThread (Address: 0x1800bd348)
  • GetCurrentThreadId (Address: 0x1800bd308)
  • OpenProcessToken (Address: 0x1800bd300)
  • OpenThreadToken (Address: 0x1800bd328)
  • SetThreadToken (Address: 0x1800bd310)
  • TerminateProcess (Address: 0x1800bd320)
  • TlsAlloc (Address: 0x1800bd318)
  • TlsFree (Address: 0x1800bd338)
  • TlsGetValue (Address: 0x1800bd340)
  • TlsSetValue (Address: 0x1800bd350)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800bd360)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800bd390)
  • RegCreateKeyExW (Address: 0x1800bd388)
  • RegDeleteKeyExW (Address: 0x1800bd3d8)
  • RegDeleteValueW (Address: 0x1800bd3d0)
  • RegEnumKeyExW (Address: 0x1800bd370)
  • RegEnumValueW (Address: 0x1800bd3b8)
  • RegFlushKey (Address: 0x1800bd378)
  • RegGetValueA (Address: 0x1800bd3e0)
  • RegGetValueW (Address: 0x1800bd3a8)
  • RegLoadKeyW (Address: 0x1800bd3c0)
  • RegOpenKeyExW (Address: 0x1800bd3a0)
  • RegQueryInfoKeyW (Address: 0x1800bd3b0)
  • RegQueryValueExW (Address: 0x1800bd398)
  • RegSetValueExW (Address: 0x1800bd380)
  • RegUnLoadKeyW (Address: 0x1800bd3c8)
api-ms-win-core-registry-l1-1-1.dll
  • RegSetKeyValueW (Address: 0x1800bd3f0)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1800bd408)
  • CompareStringW (Address: 0x1800bd400)
  • MultiByteToWideChar (Address: 0x1800bd418)
  • WideCharToMultiByte (Address: 0x1800bd410)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800bd468)
  • AcquireSRWLockShared (Address: 0x1800bd450)
  • CreateEventW (Address: 0x1800bd478)
  • CreateMutexExW (Address: 0x1800bd470)
  • CreateSemaphoreExW (Address: 0x1800bd458)
  • DeleteCriticalSection (Address: 0x1800bd428)
  • EnterCriticalSection (Address: 0x1800bd490)
  • InitializeCriticalSection (Address: 0x1800bd480)
  • InitializeCriticalSectionEx (Address: 0x1800bd488)
  • InitializeSRWLock (Address: 0x1800bd4a0)
  • LeaveCriticalSection (Address: 0x1800bd460)
  • OpenSemaphoreW (Address: 0x1800bd430)
  • ReleaseMutex (Address: 0x1800bd4b8)
  • ReleaseSemaphore (Address: 0x1800bd4a8)
  • ReleaseSRWLockExclusive (Address: 0x1800bd440)
  • ReleaseSRWLockShared (Address: 0x1800bd448)
  • SetEvent (Address: 0x1800bd498)
  • WaitForSingleObject (Address: 0x1800bd4b0)
  • WaitForSingleObjectEx (Address: 0x1800bd438)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x1800bd4c8)
  • Sleep (Address: 0x1800bd4d0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x1800bd510)
  • GetLocalTime (Address: 0x1800bd4f8)
  • GetSystemTime (Address: 0x1800bd4e8)
  • GetSystemTimeAsFileTime (Address: 0x1800bd508)
  • GetSystemWindowsDirectoryW (Address: 0x1800bd500)
  • GetTickCount (Address: 0x1800bd518)
  • GetTickCount64 (Address: 0x1800bd4e0)
  • GetVersionExW (Address: 0x1800bd4f0)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetProductInfo (Address: 0x1800bd528)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x1800bd550)
  • CreateThreadpoolTimer (Address: 0x1800bd538)
  • SetThreadpoolTimer (Address: 0x1800bd540)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800bd548)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x1800bd560)
  • GetTimeZoneInformation (Address: 0x1800bd570)
  • SystemTimeToFileTime (Address: 0x1800bd568)
api-ms-win-devices-config-l1-1-1.dll
  • CM_Register_Notification (Address: 0x1800bd580)
  • CM_Unregister_Notification (Address: 0x1800bd588)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x1800bd5a8)
  • GetTraceEnableLevel (Address: 0x1800bd598)
  • GetTraceLoggerHandle (Address: 0x1800bd5b8)
  • RegisterTraceGuidsW (Address: 0x1800bd5b0)
  • TraceMessage (Address: 0x1800bd5c0)
  • UnregisterTraceGuids (Address: 0x1800bd5a0)
api-ms-win-eventing-controller-l1-1-0.dll
  • ControlTraceW (Address: 0x1800bd5e0)
  • EnableTraceEx2 (Address: 0x1800bd5d0)
  • StartTraceW (Address: 0x1800bd5d8)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x1800bd610)
  • EventRegister (Address: 0x1800bd5f8)
  • EventSetInformation (Address: 0x1800bd5f0)
  • EventUnregister (Address: 0x1800bd608)
  • EventWriteTransfer (Address: 0x1800bd600)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x1800bd640)
  • AllocateAndInitializeSid (Address: 0x1800bd630)
  • CheckTokenMembership (Address: 0x1800bd648)
  • CopySid (Address: 0x1800bd628)
  • DuplicateTokenEx (Address: 0x1800bd660)
  • FreeSid (Address: 0x1800bd638)
  • GetLengthSid (Address: 0x1800bd620)
  • GetTokenInformation (Address: 0x1800bd668)
  • ImpersonateSelf (Address: 0x1800bd650)
  • RevertToSelf (Address: 0x1800bd658)
api-ms-win-security-lsapolicy-l1-1-0.dll
  • LsaClose (Address: 0x1800bd688)
  • LsaFreeMemory (Address: 0x1800bd678)
  • LsaOpenPolicy (Address: 0x1800bd690)
  • LsaQueryInformationPolicy (Address: 0x1800bd680)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x1800bd6a8)
  • ConvertStringSidToSidW (Address: 0x1800bd6a0)
api-ms-win-service-private-l1-1-0.dll
  • I_QueryTagInformation (Address: 0x1800bd6b8)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x1800bd6d0)
  • BCryptCreateHash (Address: 0x1800bd738)
  • BCryptDecrypt (Address: 0x1800bd760)
  • BCryptDeriveKey (Address: 0x1800bd720)
  • BCryptDeriveKeyPBKDF2 (Address: 0x1800bd6f8)
  • BCryptDestroyHash (Address: 0x1800bd758)
  • BCryptDestroyKey (Address: 0x1800bd740)
  • BCryptDestroySecret (Address: 0x1800bd728)
  • BCryptEncrypt (Address: 0x1800bd6d8)
  • BCryptExportKey (Address: 0x1800bd6f0)
  • BCryptFinalizeKeyPair (Address: 0x1800bd710)
  • BCryptFinishHash (Address: 0x1800bd750)
  • BCryptGenerateKeyPair (Address: 0x1800bd708)
  • BCryptGenerateSymmetricKey (Address: 0x1800bd770)
  • BCryptGenRandom (Address: 0x1800bd6e8)
  • BCryptGetFipsAlgorithmMode (Address: 0x1800bd6c8)
  • BCryptGetProperty (Address: 0x1800bd700)
  • BCryptHashData (Address: 0x1800bd748)
  • BCryptImportKeyPair (Address: 0x1800bd6e0)
  • BCryptOpenAlgorithmProvider (Address: 0x1800bd730)
  • BCryptSecretAgreement (Address: 0x1800bd718)
  • BCryptSetProperty (Address: 0x1800bd768)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800bd868)
  • __CxxFrameHandler3 (Address: 0x1800bd858)
  • __dllonexit (Address: 0x1800bd8d0)
  • _amsg_exit (Address: 0x1800bd838)
  • _callnewh (Address: 0x1800bd8b0)
  • _CxxThrowException (Address: 0x1800bd860)
  • _errno (Address: 0x1800bd828)
  • _initterm (Address: 0x1800bd8f0)
  • _lock (Address: 0x1800bd8e0)
  • _onexit (Address: 0x1800bd8c8)
  • _purecall (Address: 0x1800bd8a8)
  • _scwprintf (Address: 0x1800bd800)
  • _stricmp (Address: 0x1800bd7e8)
  • _strnicmp (Address: 0x1800bd878)
  • _unlock (Address: 0x1800bd8d8)
  • _vsnwprintf (Address: 0x1800bd798)
  • _wcsicmp (Address: 0x1800bd780)
  • _wcsupr (Address: 0x1800bd810)
  • _wtempnam (Address: 0x1800bd7b0)
  • _XcptFilter (Address: 0x1800bd840)
  • ??_V@YAXPEAX@Z (Address: 0x1800bd808)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800bd7d0)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800bd7c0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800bd7b8)
  • ??1exception@@UEAA@XZ (Address: 0x1800bd8b8)
  • ??1type_info@@UEAA@XZ (Address: 0x1800bd8c0)
  • ??3@YAXPEAX@Z (Address: 0x1800bd8a0)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x1800bd870)
  • ceil (Address: 0x1800bd880)
  • free (Address: 0x1800bd8f8)
  • iswascii (Address: 0x1800bd7f8)
  • iswdigit (Address: 0x1800bd7a0)
  • malloc (Address: 0x1800bd8e8)
  • memcmp (Address: 0x1800bd888)
  • memcpy (Address: 0x1800bd850)
  • memcpy_s (Address: 0x1800bd790)
  • memmove (Address: 0x1800bd848)
  • memmove_s (Address: 0x1800bd788)
  • memset (Address: 0x1800bd890)
  • sprintf_s (Address: 0x1800bd820)
  • strcmp (Address: 0x1800bd898)
  • time (Address: 0x1800bd818)
  • toupper (Address: 0x1800bd830)
  • wcschr (Address: 0x1800bd7f0)
  • wcscmp (Address: 0x1800bd900)
  • wcscpy_s (Address: 0x1800bd7c8)
  • wcsncat_s (Address: 0x1800bd7e0)
  • wcsncpy_s (Address: 0x1800bd7d8)
  • wcstoul (Address: 0x1800bd7a8)
ntdll.dll
  • EtwEventRegister (Address: 0x1800bd9c0)
  • EtwEventUnregister (Address: 0x1800bd9b8)
  • EtwEventWrite (Address: 0x1800bd9b0)
  • NtClose (Address: 0x1800bd998)
  • NtOpenFile (Address: 0x1800bd970)
  • NtOpenKey (Address: 0x1800bd9a8)
  • NtPowerInformation (Address: 0x1800bd940)
  • NtQueryInformationFile (Address: 0x1800bda28)
  • NtQuerySystemEnvironmentValueEx (Address: 0x1800bd950)
  • NtQuerySystemInformation (Address: 0x1800bd9e0)
  • NtQueryValueKey (Address: 0x1800bd9a0)
  • NtQueryVolumeInformationFile (Address: 0x1800bd9d8)
  • NtQueryWnfStateData (Address: 0x1800bd9d0)
  • RtlCaptureContext (Address: 0x1800bda10)
  • RtlCheckPortableOperatingSystem (Address: 0x1800bd948)
  • RtlCompareMemory (Address: 0x1800bd960)
  • RtlCreateSystemVolumeInformationFolder (Address: 0x1800bd930)
  • RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x1800bd938)
  • RtlFreeUnicodeString (Address: 0x1800bd988)
  • RtlGenerate8dot3Name (Address: 0x1800bd928)
  • RtlInitUnicodeString (Address: 0x1800bd958)
  • RtlIsMultiSessionSku (Address: 0x1800bda18)
  • RtlLengthSid (Address: 0x1800bda20)
  • RtlLookupFunctionEntry (Address: 0x1800bda08)
  • RtlNtStatusToDosError (Address: 0x1800bd9f0)
  • RtlPublishWnfStateData (Address: 0x1800bd9c8)
  • RtlSetThreadErrorMode (Address: 0x1800bd9e8)
  • RtlStringFromGUID (Address: 0x1800bd990)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x1800bd9f8)
  • RtlSystemTimeToLocalTime (Address: 0x1800bd910)
  • RtlTimeToTimeFields (Address: 0x1800bd918)
  • RtlUnicodeStringToCountedOemString (Address: 0x1800bd920)
  • RtlUnsubscribeWnfStateChangeNotification (Address: 0x1800bd968)
  • RtlVirtualUnwind (Address: 0x1800bda00)
  • WinSqmAddToStreamEx (Address: 0x1800bd980)
  • WinSqmSetDWORD (Address: 0x1800bd978)