fwbase.dll
Description: Firewall Base DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6328
Architecture: 64-bit
Operating System: Windows NT
SHA256: 3f49f6a0fa08341c55e89a5dd549489b
File Size: 200.5 KB
Uploaded At: Dec. 1, 2025, 7:28 a.m.
Views: 8
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- FwExtractPortNumber (Ordinal: 1, Address: 0x6e80)
- FwIsValidPorts (Ordinal: 2, Address: 0x1d460)
- FwPortsToString (Ordinal: 3, Address: 0x1d530)
- FWIndicatePortInUse_Helper (Ordinal: 4, Address: 0x6d90)
- FwAddrChangeSourceInitialize (Ordinal: 5, Address: 0x6b50)
- FwAddrChangeSourceShutdown (Ordinal: 6, Address: 0x1dd80)
- FwAddrChangeSourceSignal (Ordinal: 7, Address: 0x6090)
- FwAlloc (Ordinal: 8, Address: 0x3510)
- FwAllocArray (Ordinal: 9, Address: 0x1980)
- FwAllocCheckSize (Ordinal: 10, Address: 0x1bd0)
- FwArrayAppend (Ordinal: 11, Address: 0x3410)
- FwArrayCat (Ordinal: 12, Address: 0x5d30)
- FwArrayCopy (Ordinal: 13, Address: 0x2d60)
- FwArrayCreateFromRegistry (Ordinal: 14, Address: 0x1c090)
- FwArrayDestroy (Ordinal: 15, Address: 0x1a20)
- FwArrayErase (Ordinal: 16, Address: 0x1c280)
- FwAuthSuiteEmpty (Ordinal: 17, Address: 0x1fab0)
- FwAuthSuiteEmptyByVersion (Ordinal: 18, Address: 0x1fac0)
- FwAuthorizedAppEncode (Ordinal: 19, Address: 0x1e9c0)
- FwBaseAlloc (Ordinal: 20, Address: 0x3510)
- FwBaseAllocCheckSize (Ordinal: 21, Address: 0x1bd0)
- FwBaseFree (Ordinal: 22, Address: 0x33d0)
- FwBoolIsEqual (Ordinal: 23, Address: 0x5fd0)
- FwBuildIndirectString (Ordinal: 24, Address: 0x1a7f0)
- FwCanonizeAuthorizedApps (Ordinal: 25, Address: 0x5f30)
- FwChangeSinkCreate (Ordinal: 26, Address: 0x1420)
- FwChangeSinkDestroy (Ordinal: 27, Address: 0x1ddc0)
- FwChangeSourceInitialize (Ordinal: 28, Address: 0x6b40)
- FwChangeSourceShutdown (Ordinal: 29, Address: 0x1ddf0)
- FwChangeSourceSignal (Ordinal: 30, Address: 0x5960)
- FwChangeSourceSignalStart (Ordinal: 31, Address: 0x75e0)
- FwCloseHandle (Ordinal: 32, Address: 0x5020)
- FwConstructRemoteMachineSPN (Ordinal: 33, Address: 0x1a880)
- FwCreateDirectory (Ordinal: 34, Address: 0x1aa10)
- FwCreateSDDLStringFromPolicyAppId (Ordinal: 35, Address: 0xd6d0)
- FwCriticalSectionCreate (Ordinal: 36, Address: 0x5770)
- FwCriticalSectionDestroy (Ordinal: 37, Address: 0x1220)
- FwCriticalSectionEnter (Ordinal: 38, Address: 0x5660)
- FwCriticalSectionLeave (Ordinal: 39, Address: 0x5640)
- FwDWordMultiply (Ordinal: 40, Address: 0x1ab80)
- FwEnableMemTracing (Ordinal: 41, Address: 0x5a60)
- FwEnablePrivilege (Ordinal: 42, Address: 0x1abb0)
- FwExpandEnvironmentStrings (Ordinal: 43, Address: 0x5a80)
- FwFieldNameMatchStringBegining (Ordinal: 44, Address: 0x4df0)
- FwFinalHash (Ordinal: 45, Address: 0x1caa0)
- FwFree (Ordinal: 46, Address: 0x33d0)
- FwFreeCertCriteria (Ordinal: 47, Address: 0x1fb60)
- FwFreeRpcCallersProcessInfo (Ordinal: 48, Address: 0x3330)
- FwGetAppBlockList (Ordinal: 49, Address: 0x6750)
- FwGetAuthorizedApp (Ordinal: 50, Address: 0x1eaf0)
- FwGetExpandedCanonicalLongPathName (Ordinal: 51, Address: 0x6840)
- FwGetIcmpSettings (Ordinal: 52, Address: 0x1ebe0)
- FwGetLongPathName (Ordinal: 53, Address: 0x5c10)
- FwGetPolicyAppIdFromSDDLString (Ordinal: 54, Address: 0xd770)
- FwGetProfileIndexFromProfileType (Ordinal: 55, Address: 0x4fa0)
- FwGetProfileTypeFromProfileIndex (Ordinal: 56, Address: 0x4f80)
- FwGetRemoteAdminSettings (Ordinal: 57, Address: 0x1ecc0)
- FwGetRpcCallersProcessImageName (Ordinal: 58, Address: 0x1cce0)
- FwGetRpcCallersProcessInfo (Ordinal: 59, Address: 0x1c20)
- FwGetService (Ordinal: 60, Address: 0x1fdf0)
- FwGetServiceTypes (Ordinal: 61, Address: 0x1fe50)
- FwGetServices (Ordinal: 62, Address: 0x1ed10)
- FwGetStaticFwPort (Ordinal: 63, Address: 0x1ee00)
- FwGetStringId (Ordinal: 64, Address: 0x5dd0)
- FwGetStringIdForStatusCode (Ordinal: 65, Address: 0x7250)
- FwGetSysPathName (Ordinal: 66, Address: 0x1ae20)
- FwGetTokenInformation (Ordinal: 67, Address: 0x25a0)
- FwHResultToWindowsError (Ordinal: 68, Address: 0x4ff0)
- FwHashtableCreate (Ordinal: 69, Address: 0x6ff0)
- FwHashtableDestroy (Ordinal: 70, Address: 0x1cab0)
- FwHashtableEmpty (Ordinal: 71, Address: 0x58c0)
- FwHashtableFind (Ordinal: 72, Address: 0x1cb50)
- FwHashtableGetNext (Ordinal: 73, Address: 0x1cb70)
- FwHashtableInsert (Ordinal: 74, Address: 0x1cb90)
- FwHashtableIsEmpty (Ordinal: 75, Address: 0xef50)
- FwHashtableRemove (Ordinal: 76, Address: 0x1cc00)
- FwIOReadPortUseIndications (Ordinal: 77, Address: 0x6260)
- FwIOWritePortUseIndications (Ordinal: 78, Address: 0x60e0)
- FwIcfAuthBypassServicesDestroy (Ordinal: 79, Address: 0x19b0)
- FwIcfAuthBypassSubNetsDestroy (Ordinal: 80, Address: 0x19d0)
- FwIcfAuthorizedAppCopy (Ordinal: 81, Address: 0x1c420)
- FwIcfAuthorizedAppsCopy (Ordinal: 82, Address: 0x1c5c0)
- FwIcfAuthorizedAppsDestroy (Ordinal: 83, Address: 0x1c660)
- FwIcfDynamicFwPortDestroy (Ordinal: 84, Address: 0x5e00)
- FwIcfIpV4SubNetsCanonize (Ordinal: 85, Address: 0x5680)
- FwIcfIpV6SubNetsCanonize (Ordinal: 86, Address: 0x5720)
- FwIcfSubNetsCopy (Ordinal: 87, Address: 0x1c9f0)
- FwIcfSubNetsDestroy (Ordinal: 88, Address: 0x5e40)
- FwIcfSubNetsGetScope (Ordinal: 89, Address: 0x1ca80)
- FwIcfSubNetsIsEqual (Ordinal: 90, Address: 0x5ef0)
- FwImageListDestroy (Ordinal: 91, Address: 0x1ef10)
- FwImageListHasImage (Ordinal: 92, Address: 0x1ef30)
- FwInitMemoryMgr (Ordinal: 93, Address: 0x5a60)
- FwInitializeHashContext (Ordinal: 94, Address: 0x1cc20)
- FwIpV4SubNetDecode (Ordinal: 95, Address: 0x1efa0)
- FwIsBuiltInPort (Ordinal: 96, Address: 0x1ff50)
- FwIsMachineLocalHost (Ordinal: 97, Address: 0x5090)
- FwLicensingIsIoT (Ordinal: 98, Address: 0x7580)
- FwLicensingIsNetIsolationOnly (Ordinal: 99, Address: 0x48b0)
- FwLicensingIsXbox (Ordinal: 100, Address: 0x55e0)
- FwLoadIndirectString (Ordinal: 101, Address: 0x2360)
- FwLoadString (Ordinal: 102, Address: 0x64b0)
- FwLookupAccountSid (Ordinal: 103, Address: 0x7040)
- FwMarshalledMetaDataCopy (Ordinal: 104, Address: 0x4eb0)
- FwMarshalledMetaDataInitialize (Ordinal: 105, Address: 0x4fd0)
- FwMetaDataAddEnforcementState (Ordinal: 106, Address: 0x5070)
- FwMetaDataCopy (Ordinal: 107, Address: 0x1af80)
- FwMetaDataFree (Ordinal: 108, Address: 0x5600)
- FwMetaDataIsEnforcementStatePresent (Ordinal: 109, Address: 0x5470)
- FwModifySDDLStringWithPolicyAppId (Ordinal: 110, Address: 0xd840)
- FwMultiByteToWideChar (Ordinal: 111, Address: 0x1b0d0)
- FwNtStatusToHResult (Ordinal: 112, Address: 0xdbd0)
- FwParseEdpCloudResourceStringToNrptRuleList (Ordinal: 113, Address: 0x1cdc0)
- FwProfileTypesToString (Ordinal: 114, Address: 0x2880)
- FwRegCloseKey (Ordinal: 115, Address: 0x55b0)
- FwRegCreateKey (Ordinal: 116, Address: 0x1350)
- FwRegDeleteAllValues (Ordinal: 117, Address: 0x19ed0)
- FwRegDeleteKey (Ordinal: 118, Address: 0x1a000)
- FwRegDeleteValue (Ordinal: 119, Address: 0x1180)
- FwRegEnumValueNameAndValueData (Ordinal: 120, Address: 0x2e70)
- FwRegNotifyCreate (Ordinal: 121, Address: 0x14e0)
- FwRegNotifyDestroy (Ordinal: 122, Address: 0x1a220)
- FwRegOpenKey (Ordinal: 123, Address: 0x18e0)
- FwRegQueryDWord (Ordinal: 124, Address: 0x1790)
- FwRegQueryNumKeys (Ordinal: 125, Address: 0x1a2a0)
- FwRegQueryNumValues (Ordinal: 126, Address: 0x57f0)
- FwRegQueryString (Ordinal: 127, Address: 0x26c0)
- FwRegSetDWord (Ordinal: 128, Address: 0x59b0)
- FwRegSetString (Ordinal: 129, Address: 0x54e0)
- FwReleasePrivilege (Ordinal: 130, Address: 0x1b350)
- FwRemovePolicyAppIdFromSDDLString (Ordinal: 131, Address: 0xdc30)
- FwReplacePolicyAppIdInSDDLString (Ordinal: 132, Address: 0xdeb0)
- FwReportErrorAsNtStatus (Ordinal: 133, Address: 0x1b420)
- FwReportErrorAsWinError (Ordinal: 134, Address: 0x66f0)
- FwReportReturnError (Ordinal: 135, Address: 0x2560)
- FwResolveIndirectString (Ordinal: 136, Address: 0x22b0)
- FwRestructureHashtable (Ordinal: 137, Address: 0x1cc30)
- FwServiceSidCreateInPlace (Ordinal: 138, Address: 0x7290)
- FwSetMemLeakPolicy (Ordinal: 139, Address: 0x5a60)
- FwShutdownMemoryMgr (Ordinal: 140, Address: 0x5a60)
- FwSidCreate (Ordinal: 141, Address: 0x6f00)
- FwSidDestroy (Ordinal: 142, Address: 0x1b470)
- FwSizeTAdd (Ordinal: 143, Address: 0x1b4a0)
- FwSizeTMultiply (Ordinal: 144, Address: 0x3560)
- FwSortAddresses (Ordinal: 145, Address: 0x5e70)
- FwSortInterfaceLUIDs (Ordinal: 146, Address: 0x5ff0)
- FwStaticFwPortEncode (Ordinal: 147, Address: 0x1f380)
- FwStaticFwPortEncodeValueName (Ordinal: 148, Address: 0x1f4c0)
- FwStringArrayCopy (Ordinal: 149, Address: 0xdff0)
- FwStringBuild (Ordinal: 150, Address: 0x35a0)
- FwStringBuildWithPrefix (Ordinal: 151, Address: 0xe120)
- FwStringCanonicalizeCopy (Ordinal: 152, Address: 0x1b4c0)
- FwStringConcat (Ordinal: 153, Address: 0xe2d0)
- FwStringCopy (Ordinal: 154, Address: 0x1a80)
- FwStringCopyA (Ordinal: 155, Address: 0x1b690)
- FwStringCopyAtoWAlloc (Ordinal: 156, Address: 0x1b780)
- FwStringCopyWtoAAlloc (Ordinal: 157, Address: 0x1b8d0)
- FwStringPrefixConcat (Ordinal: 158, Address: 0xe360)
- FwStringPrefixCopy (Ordinal: 159, Address: 0xe3f0)
- FwSubNetsEncode (Ordinal: 160, Address: 0x1f940)
- FwSubstituteDeviceName (Ordinal: 161, Address: 0x1ba30)
- FwTriggerGetEventForSource (Ordinal: 162, Address: 0x7600)
- FwTriggerRearm (Ordinal: 163, Address: 0x74e0)
- FwTriggerRegisterWait (Ordinal: 164, Address: 0x7380)
- FwTriggerUnregisterWait (Ordinal: 165, Address: 0x1d2b0)
- FwUpdateHash (Ordinal: 166, Address: 0x1ccb0)
- FwVerifyAuthenticationSet (Ordinal: 167, Address: 0x1ff70)
- FwVerifyAuthenticationSetQuery (Ordinal: 168, Address: 0x200d0)
- FwVerifyConnectionSecurityRule (Ordinal: 169, Address: 0x20230)
- FwVerifyConnectionSecurityRuleQuery (Ordinal: 170, Address: 0x203e0)
- FwVerifyCryptoSet (Ordinal: 171, Address: 0x20540)
- FwVerifyCryptoSetQuery (Ordinal: 172, Address: 0x206a0)
- FwVerifyFirewallRule (Ordinal: 173, Address: 0x20800)
- FwVerifyFirewallRuleQuery (Ordinal: 174, Address: 0x5120)
- FwVerifyMainModeRule (Ordinal: 175, Address: 0x20930)
- FwVerifyMainModeRuleQuery (Ordinal: 176, Address: 0x20a60)
- FwVerifyNoHeapLeaks (Ordinal: 177, Address: 0x5a60)
- FwWcsICmp (Ordinal: 178, Address: 0x75c0)
- Int_FWVerifyAuthenticationSet (Ordinal: 179, Address: 0x218a0)
- Int_FWVerifyConnectionSecurityRule (Ordinal: 180, Address: 0x21e70)
- Int_FWVerifyCryptoSet (Ordinal: 181, Address: 0x23330)
- Int_FWVerifyFirewallRule (Ordinal: 182, Address: 0x3bc0)
- Int_FWVerifyMainModeRule (Ordinal: 183, Address: 0x237e0)
- Int_FwIPV4RangeContainsMulticast (Ordinal: 184, Address: 0x23d70)
- Int_FwIPV6RangeContainsMulticast (Ordinal: 185, Address: 0x23db0)
- Int_FwIsV6AddrLoopback (Ordinal: 186, Address: 0x6fc0)
- Int_FwValidateAndMigrateSecurityDescriptor (Ordinal: 187, Address: 0x4c50)
- Int_FwValidateComplianceAndReduceAuthSetToVersion (Ordinal: 188, Address: 0x23dd0)
- Int_FwValidateComplianceAndReduceConnSecRuleToVersion (Ordinal: 189, Address: 0x24010)
- Int_FwValidateComplianceAndReduceCryptoSetToVersion (Ordinal: 190, Address: 0x244e0)
- Int_FwValidateComplianceAndReduceFirewallRuleToVersion (Ordinal: 191, Address: 0x37d0)
- Int_FwValidateComplianceAndReduceMainModeRuleToVersion (Ordinal: 192, Address: 0x24960)
- Int_FwValidateSecurityDescriptor (Ordinal: 193, Address: 0x4400)
- IsAddressesEmpty (Ordinal: 194, Address: 0x6e40)
- IsCSRuleTunnelMode (Ordinal: 195, Address: 0x1fbd0)
- IsRuleOldAuthApp (Ordinal: 196, Address: 0x5430)
- IsRuleOldGlobalOpenPort (Ordinal: 197, Address: 0x54a0)
- IsRuleOldv1Compliant (Ordinal: 198, Address: 0x1fc70)
- IsRuleOpenPortOrAuthApp (Ordinal: 199, Address: 0x1fcb0)
- Isv4AddressesEmpty (Ordinal: 200, Address: 0x5f90)
- Isv6AddressesEmpty (Ordinal: 201, Address: 0x5fb0)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180027480)
api-ms-win-core-com-l1-1-0.dll
- CoCreateGuid (Address: 0x180027498)
- StringFromGUID2 (Address: 0x180027490)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800274b8)
- IsDebuggerPresent (Address: 0x1800274a8)
- OutputDebugStringW (Address: 0x1800274b0)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800274c8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800274d8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800274f8)
- SetLastError (Address: 0x180027500)
- SetUnhandledExceptionFilter (Address: 0x1800274e8)
- UnhandledExceptionFilter (Address: 0x1800274f0)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x180027510)
- CreateFileW (Address: 0x180027520)
- GetLongPathNameW (Address: 0x180027518)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180027530)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180027540)
- HeapAlloc (Address: 0x180027548)
- HeapFree (Address: 0x180027550)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180027560)
- LocalFree (Address: 0x180027568)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x180027588)
- GetModuleFileNameA (Address: 0x180027590)
- GetModuleHandleExW (Address: 0x180027598)
- GetModuleHandleW (Address: 0x1800275a8)
- GetProcAddress (Address: 0x180027578)
- LoadLibraryExW (Address: 0x1800275a0)
- LoadStringW (Address: 0x180027580)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800275b8)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x1800275c8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1800275f0)
- GetCurrentProcessId (Address: 0x1800275e8)
- GetCurrentThread (Address: 0x1800275e0)
- GetCurrentThreadId (Address: 0x180027610)
- OpenProcessToken (Address: 0x180027608)
- OpenThreadToken (Address: 0x1800275d8)
- SetThreadToken (Address: 0x180027600)
- TerminateProcess (Address: 0x1800275f8)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x180027620)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180027630)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180027658)
- RegCreateKeyExW (Address: 0x180027688)
- RegDeleteTreeW (Address: 0x180027648)
- RegDeleteValueW (Address: 0x180027650)
- RegEnumValueW (Address: 0x180027668)
- RegNotifyChangeKeyValue (Address: 0x180027680)
- RegOpenKeyExW (Address: 0x180027660)
- RegQueryInfoKeyW (Address: 0x180027670)
- RegQueryValueExW (Address: 0x180027678)
- RegSetValueExW (Address: 0x180027640)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800276a8)
- RtlLookupFunctionEntry (Address: 0x1800276a0)
- RtlVirtualUnwind (Address: 0x180027698)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathCanonicalizeW (Address: 0x1800276b8)
- PathFindNextComponentW (Address: 0x1800276d0)
- PathIsRelativeW (Address: 0x1800276c0)
- PathSkipRootW (Address: 0x1800276c8)
api-ms-win-core-string-l1-1-0.dll
- CompareStringW (Address: 0x1800276e0)
- MultiByteToWideChar (Address: 0x1800276f0)
- WideCharToMultiByte (Address: 0x1800276e8)
api-ms-win-core-string-l2-1-1.dll
- SHLoadIndirectString (Address: 0x180027700)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x180027710)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180027780)
- AcquireSRWLockShared (Address: 0x180027770)
- CreateEventW (Address: 0x1800277a8)
- CreateMutexExW (Address: 0x180027790)
- CreateSemaphoreExW (Address: 0x180027788)
- DeleteCriticalSection (Address: 0x180027728)
- EnterCriticalSection (Address: 0x180027738)
- InitializeCriticalSectionAndSpinCount (Address: 0x180027748)
- InitializeCriticalSectionEx (Address: 0x180027740)
- LeaveCriticalSection (Address: 0x1800277a0)
- OpenSemaphoreW (Address: 0x180027798)
- ReleaseMutex (Address: 0x180027750)
- ReleaseSemaphore (Address: 0x180027758)
- ReleaseSRWLockExclusive (Address: 0x180027778)
- ReleaseSRWLockShared (Address: 0x180027768)
- SetEvent (Address: 0x180027760)
- WaitForSingleObject (Address: 0x180027730)
- WaitForSingleObjectEx (Address: 0x180027720)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x1800277b8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x1800277d0)
- GetSystemTimeAsFileTime (Address: 0x1800277c8)
- GetTickCount (Address: 0x1800277e0)
- GetVersionExW (Address: 0x1800277d8)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x180027800)
- CloseThreadpoolWait (Address: 0x180027820)
- CreateThreadpoolTimer (Address: 0x1800277f8)
- CreateThreadpoolWait (Address: 0x180027828)
- SetThreadpoolTimer (Address: 0x180027818)
- SetThreadpoolWait (Address: 0x1800277f0)
- WaitForThreadpoolTimerCallbacks (Address: 0x180027808)
- WaitForThreadpoolWaitCallbacks (Address: 0x180027810)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- QueueUserWorkItem (Address: 0x180027838)
- UnregisterWaitEx (Address: 0x180027840)
api-ms-win-core-threadpool-private-l1-1-0.dll
- RegisterWaitForSingleObjectEx (Address: 0x180027850)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x180027898)
- AllocateAndInitializeSid (Address: 0x180027860)
- DuplicateTokenEx (Address: 0x180027890)
- FreeSid (Address: 0x180027888)
- GetAce (Address: 0x180027868)
- GetSecurityDescriptorDacl (Address: 0x180027870)
- GetTokenInformation (Address: 0x180027880)
- IsValidSecurityDescriptor (Address: 0x180027878)
msvcrt.dll
- __C_specific_handler (Address: 0x180027948)
- __CxxFrameHandler3 (Address: 0x1800278e0)
- __dllonexit (Address: 0x1800279c0)
- _amsg_exit (Address: 0x180027908)
- _CxxThrowException (Address: 0x1800278f8)
- _initterm (Address: 0x1800279d8)
- _lock (Address: 0x180027988)
- _onexit (Address: 0x1800279c8)
- _purecall (Address: 0x180027928)
- _ultow (Address: 0x180027970)
- _unlock (Address: 0x1800279a0)
- _vsnprintf_s (Address: 0x1800278c8)
- _vsnwprintf (Address: 0x1800279b0)
- _wcsicmp (Address: 0x180027978)
- _wcsnicmp (Address: 0x180027968)
- _XcptFilter (Address: 0x1800278b0)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800278d0)
- ??0exception@@QEAA@XZ (Address: 0x1800278b8)
- ??1exception@@UEAA@XZ (Address: 0x1800278d8)
- ??1type_info@@UEAA@XZ (Address: 0x1800279b8)
- ??3@YAXPEAX@Z (Address: 0x1800279a8)
- free (Address: 0x1800278a8)
- iswalpha (Address: 0x180027918)
- iswdigit (Address: 0x180027960)
- malloc (Address: 0x180027900)
- memcmp (Address: 0x1800278f0)
- memcpy (Address: 0x1800278c0)
- memcpy_s (Address: 0x1800279d0)
- memmove (Address: 0x180027940)
- memmove_s (Address: 0x180027998)
- memset (Address: 0x1800279e0)
- qsort (Address: 0x180027930)
- towupper (Address: 0x1800278e8)
- wcschr (Address: 0x180027950)
- wcsncmp (Address: 0x180027990)
- wcsncpy_s (Address: 0x180027980)
- wcspbrk (Address: 0x180027910)
- wcsstr (Address: 0x180027938)
- wcstok_s (Address: 0x180027920)
- wcstoul (Address: 0x180027958)
ntdll.dll
- EtwEventWrite (Address: 0x180027a60)
- EtwGetTraceEnableFlags (Address: 0x180027ab8)
- EtwGetTraceEnableLevel (Address: 0x180027ac8)
- EtwGetTraceLoggerHandle (Address: 0x180027ac0)
- EtwRegisterTraceGuidsW (Address: 0x180027ad0)
- EtwTraceMessage (Address: 0x180027aa8)
- EtwUnregisterTraceGuids (Address: 0x180027ab0)
- NtClose (Address: 0x180027a88)
- NtOpenSymbolicLinkObject (Address: 0x180027a98)
- NtQueryInformationProcess (Address: 0x180027a00)
- NtQueryObject (Address: 0x180027a80)
- NtQuerySymbolicLinkObject (Address: 0x180027a90)
- RtlCanonicalizeDomainName (Address: 0x180027a68)
- RtlContractHashTable (Address: 0x180027a08)
- RtlCreateHashTable (Address: 0x180027a58)
- RtlCreateServiceSid (Address: 0x180027a78)
- RtlDeleteHashTable (Address: 0x180027a50)
- RtlEndEnumerationHashTable (Address: 0x180027a18)
- RtlEnumerateEntryHashTable (Address: 0x180027a20)
- RtlExpandHashTable (Address: 0x180027a10)
- RtlFreeUnicodeString (Address: 0x180027ad8)
- RtlGetNextEntryHashTable (Address: 0x180027a30)
- RtlInitEnumerationHashTable (Address: 0x180027a28)
- RtlInitUnicodeString (Address: 0x180027aa0)
- RtlInsertEntryHashTable (Address: 0x180027a48)
- RtlIpv4AddressToStringW (Address: 0x1800279f0)
- RtlIpv4StringToAddressW (Address: 0x1800279f8)
- RtlLookupEntryHashTable (Address: 0x180027a38)
- RtlNtStatusToDosError (Address: 0x180027a70)
- RtlRemoveEntryHashTable (Address: 0x180027a40)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x180027460)
- RpcImpersonateClient (Address: 0x180027470)
- RpcRevertToSelf (Address: 0x180027468)