generaltel.dll

Description: General Telemetry

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6280

Architecture: 64-bit

Operating System: Windows NT

SHA256: 7e7842017cbf94f2c512c11f655cfc58

File Size: 629.4 KB

Uploaded At: Dec. 1, 2025, 7:28 a.m.

Views: 8

Exported Functions

  • CalculateCensusId (Ordinal: 1, Address: 0x44a10)
  • DoCensusRun (Ordinal: 2, Address: 0x24770)
  • EnumerateOfficeAddins (Ordinal: 3, Address: 0x292a0)
  • EnumerateOfficeDocuments (Ordinal: 4, Address: 0x29ad0)
  • GetCITDataApr (Ordinal: 5, Address: 0x3d600)
  • GetCITTelemetryPoints (Ordinal: 6, Address: 0x3d690)
  • RunGeneralTelemetry (Ordinal: 7, Address: 0x4a240)
  • RunInUserCxtW (Ordinal: 8, Address: 0x23f30)
  • SysprepCleanupEnableCustomTrigger (Ordinal: 9, Address: 0x44a40)

Imported DLLs & Functions

bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x18006dec0)
  • BCryptCreateHash (Address: 0x18006deb8)
  • BCryptDestroyHash (Address: 0x18006de90)
  • BCryptFinishHash (Address: 0x18006de98)
  • BCryptGetProperty (Address: 0x18006dea8)
  • BCryptHashData (Address: 0x18006deb0)
  • BCryptOpenAlgorithmProvider (Address: 0x18006dea0)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18006dcd8)
  • AcquireSRWLockShared (Address: 0x18006dd28)
  • CloseHandle (Address: 0x18006dcf0)
  • CloseThreadpoolTimer (Address: 0x18006dcd0)
  • CompareStringOrdinal (Address: 0x18006dd68)
  • CreateEventExW (Address: 0x18006de48)
  • CreateEventW (Address: 0x18006db20)
  • CreateFileW (Address: 0x18006dd70)
  • CreateMutexExW (Address: 0x18006dd20)
  • CreateMutexW (Address: 0x18006db50)
  • CreateSemaphoreExW (Address: 0x18006dc50)
  • CreateSemaphoreW (Address: 0x18006db10)
  • CreateThreadpoolTimer (Address: 0x18006dd08)
  • CreateWaitableTimerW (Address: 0x18006db30)
  • DebugBreak (Address: 0x18006dd50)
  • DelayLoadFailureHook (Address: 0x18006dab8)
  • DeleteCriticalSection (Address: 0x18006dd30)
  • DeleteFileW (Address: 0x18006db70)
  • DeviceIoControl (Address: 0x18006dd80)
  • EnterCriticalSection (Address: 0x18006dc68)
  • ExpandEnvironmentStringsW (Address: 0x18006de38)
  • FindClose (Address: 0x18006dc28)
  • FindFirstFileW (Address: 0x18006dc20)
  • FindNextFileW (Address: 0x18006dc30)
  • FormatMessageW (Address: 0x18006dcb0)
  • FreeLibrary (Address: 0x18006ddd0)
  • GetCommandLineW (Address: 0x18006db48)
  • GetComputerNameExW (Address: 0x18006dda8)
  • GetComputerNameW (Address: 0x18006dbf0)
  • GetCurrentProcess (Address: 0x18006de20)
  • GetCurrentProcessId (Address: 0x18006dd38)
  • GetCurrentThread (Address: 0x18006dbe0)
  • GetCurrentThreadId (Address: 0x18006dca0)
  • GetFileAttributesExW (Address: 0x18006de28)
  • GetFileAttributesW (Address: 0x18006db78)
  • GetLastError (Address: 0x18006dcb8)
  • GetLocalTime (Address: 0x18006dc18)
  • GetLogicalDriveStringsW (Address: 0x18006dac8)
  • GetLongPathNameW (Address: 0x18006de30)
  • GetModuleFileNameA (Address: 0x18006dc48)
  • GetModuleFileNameW (Address: 0x18006ddf8)
  • GetModuleHandleExA (Address: 0x18006de00)
  • GetModuleHandleExW (Address: 0x18006dc78)
  • GetModuleHandleW (Address: 0x18006dd48)
  • GetPriorityClass (Address: 0x18006dbc8)
  • GetProcAddress (Address: 0x18006dd18)
  • GetProcessHeap (Address: 0x18006dd40)
  • GetProductInfo (Address: 0x18006ddb8)
  • GetSystemDirectoryA (Address: 0x18006de08)
  • GetSystemDirectoryW (Address: 0x18006db58)
  • GetSystemFirmwareTable (Address: 0x18006dbf8)
  • GetSystemTime (Address: 0x18006dda0)
  • GetSystemTimeAsFileTime (Address: 0x18006dd88)
  • GetSystemWindowsDirectoryW (Address: 0x18006dc08)
  • GetTempFileNameW (Address: 0x18006db60)
  • GetTempPathW (Address: 0x18006db68)
  • GetTickCount (Address: 0x18006dde8)
  • GetVersionExW (Address: 0x18006ddb0)
  • HeapAlloc (Address: 0x18006dd10)
  • HeapFree (Address: 0x18006dc58)
  • HeapReAlloc (Address: 0x18006ddd8)
  • InitializeCriticalSection (Address: 0x18006dc38)
  • InitializeCriticalSectionEx (Address: 0x18006dc88)
  • IsDebuggerPresent (Address: 0x18006dd58)
  • LeaveCriticalSection (Address: 0x18006dc80)
  • LoadLibraryA (Address: 0x18006de10)
  • LoadLibraryExA (Address: 0x18006de50)
  • LoadLibraryExW (Address: 0x18006ddc8)
  • LoadLibraryW (Address: 0x18006dc00)
  • LocalAlloc (Address: 0x18006dad0)
  • LocalFree (Address: 0x18006de18)
  • lstrcmpiA (Address: 0x18006ddc0)
  • lstrcmpiW (Address: 0x18006dbe8)
  • lstrcmpW (Address: 0x18006dd60)
  • MoveFileExW (Address: 0x18006db40)
  • MultiByteToWideChar (Address: 0x18006de40)
  • OpenSemaphoreW (Address: 0x18006dce8)
  • OpenWaitableTimerW (Address: 0x18006db18)
  • OutputDebugStringA (Address: 0x18006dae8)
  • OutputDebugStringW (Address: 0x18006dcc8)
  • QueryDosDeviceW (Address: 0x18006dac0)
  • QueryPerformanceCounter (Address: 0x18006db80)
  • QueryProcessCycleTime (Address: 0x18006dbd8)
  • RaiseException (Address: 0x18006dde0)
  • ReadFile (Address: 0x18006dd78)
  • ReleaseMutex (Address: 0x18006dca8)
  • ReleaseSemaphore (Address: 0x18006dc70)
  • ReleaseSRWLockExclusive (Address: 0x18006dcc0)
  • ReleaseSRWLockShared (Address: 0x18006dd00)
  • RtlCaptureContext (Address: 0x18006dbb8)
  • RtlCompareMemory (Address: 0x18006dad8)
  • RtlLookupFunctionEntry (Address: 0x18006dbb0)
  • RtlVirtualUnwind (Address: 0x18006dab0)
  • SetEvent (Address: 0x18006dc40)
  • SetLastError (Address: 0x18006dc60)
  • SetNamedPipeHandleState (Address: 0x18006daf8)
  • SetPriorityClass (Address: 0x18006dbd0)
  • SetThreadpoolTimer (Address: 0x18006dcf8)
  • SetUnhandledExceptionFilter (Address: 0x18006dba0)
  • SetWaitableTimer (Address: 0x18006db38)
  • Sleep (Address: 0x18006dbc0)
  • SleepConditionVariableSRW (Address: 0x18006db88)
  • SystemTimeToFileTime (Address: 0x18006dc10)
  • TerminateProcess (Address: 0x18006db98)
  • UnhandledExceptionFilter (Address: 0x18006dba8)
  • VerifyVersionInfoW (Address: 0x18006dd90)
  • VerSetConditionMask (Address: 0x18006dd98)
  • VirtualAlloc (Address: 0x18006db08)
  • VirtualFree (Address: 0x18006db00)
  • WaitForMultipleObjects (Address: 0x18006db28)
  • WaitForSingleObject (Address: 0x18006dc98)
  • WaitForSingleObjectEx (Address: 0x18006dce0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18006dc90)
  • WaitNamedPipeW (Address: 0x18006dae0)
  • WakeAllConditionVariable (Address: 0x18006db90)
  • WriteFile (Address: 0x18006daf0)
  • WTSGetActiveConsoleSessionId (Address: 0x18006ddf0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18006df00)
  • __CxxFrameHandler3 (Address: 0x18006e0d0)
  • __dllonexit (Address: 0x18006dee8)
  • _amsg_exit (Address: 0x18006df10)
  • _callnewh (Address: 0x18006df40)
  • _CxxThrowException (Address: 0x18006df38)
  • _errno (Address: 0x18006dfd8)
  • _initterm (Address: 0x18006df08)
  • _lock (Address: 0x18006def8)
  • _onexit (Address: 0x18006dee0)
  • _purecall (Address: 0x18006e098)
  • _set_errno (Address: 0x18006dfc8)
  • _strnicmp (Address: 0x18006e000)
  • _swprintf_c_l (Address: 0x18006dfb8)
  • _unlock (Address: 0x18006def0)
  • _vscwprintf (Address: 0x18006e0f8)
  • _vsnprintf (Address: 0x18006dfe8)
  • _vsnprintf_s (Address: 0x18006e078)
  • _vsnwprintf (Address: 0x18006e0a8)
  • _wcsicmp (Address: 0x18006e028)
  • _wcslwr (Address: 0x18006e0e8)
  • _wcslwr_s (Address: 0x18006e020)
  • _wcsnicmp (Address: 0x18006df98)
  • _wcstoui64 (Address: 0x18006dfa0)
  • _wfopen_s (Address: 0x18006df68)
  • _wtof (Address: 0x18006df78)
  • _wtoi (Address: 0x18006e008)
  • _wtol (Address: 0x18006df90)
  • _XcptFilter (Address: 0x18006df18)
  • ??_V@YAXPEAX@Z (Address: 0x18006dff8)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18006e060)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18006df48)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18006e080)
  • ??0exception@@QEAA@XZ (Address: 0x18006e088)
  • ??1exception@@UEAA@XZ (Address: 0x18006e090)
  • ??1type_info@@UEAA@XZ (Address: 0x18006df88)
  • ??3@YAXPEAX@Z (Address: 0x18006ded0)
  • ?terminate@@YAXXZ (Address: 0x18006ded8)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18006e068)
  • fclose (Address: 0x18006df50)
  • fread (Address: 0x18006df60)
  • free (Address: 0x18006dfa8)
  • isdigit (Address: 0x18006e050)
  • isspace (Address: 0x18006df30)
  • iswdigit (Address: 0x18006df58)
  • malloc (Address: 0x18006df70)
  • memchr (Address: 0x18006df20)
  • memcmp (Address: 0x18006e0c8)
  • memcpy (Address: 0x18006e0c0)
  • memcpy_s (Address: 0x18006e0a0)
  • memmove (Address: 0x18006e0b8)
  • memmove_s (Address: 0x18006e070)
  • memset (Address: 0x18006e0b0)
  • sprintf_s (Address: 0x18006e048)
  • strchr (Address: 0x18006dfc0)
  • strcpy_s (Address: 0x18006e0d8)
  • strncmp (Address: 0x18006e0e0)
  • strncpy_s (Address: 0x18006dfe0)
  • strnlen (Address: 0x18006e0f0)
  • strrchr (Address: 0x18006dff0)
  • strstr (Address: 0x18006df80)
  • strtol (Address: 0x18006dfd0)
  • tolower (Address: 0x18006df28)
  • wcscat_s (Address: 0x18006e018)
  • wcschr (Address: 0x18006e038)
  • wcscmp (Address: 0x18006e100)
  • wcscpy_s (Address: 0x18006dfb0)
  • wcsncmp (Address: 0x18006e058)
  • wcsrchr (Address: 0x18006e010)
  • wcsstr (Address: 0x18006e030)
  • wctob (Address: 0x18006e040)
ntdll.dll
  • EtwEventRegister (Address: 0x18006e1f8)
  • EtwEventUnregister (Address: 0x18006e1e8)
  • EtwEventWrite (Address: 0x18006e1f0)
  • LdrResSearchResource (Address: 0x18006e198)
  • NtLoadKeyEx (Address: 0x18006e2d0)
  • NtQueryKey (Address: 0x18006e280)
  • NtQueryLicenseValue (Address: 0x18006e130)
  • RtlAdjustPrivilege (Address: 0x18006e2a0)
  • RtlAllocateAndInitializeSid (Address: 0x18006e298)
  • RtlAllocateHeap (Address: 0x18006e288)
  • RtlAnsiStringToUnicodeString (Address: 0x18006e210)
  • RtlAppendUnicodeStringToString (Address: 0x18006e258)
  • RtlAppendUnicodeToString (Address: 0x18006e260)
  • RtlComputeCrc32 (Address: 0x18006e2b0)
  • RtlDecompressBuffer (Address: 0x18006e2b8)
  • RtlDeleteCriticalSection (Address: 0x18006e238)
  • RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x18006e128)
  • RtlDosPathNameToRelativeNtPathName_U (Address: 0x18006e240)
  • RtlEnterCriticalSection (Address: 0x18006e1c0)
  • RtlEqualString (Address: 0x18006e1b8)
  • RtlFreeHeap (Address: 0x18006e278)
  • RtlFreeSid (Address: 0x18006e290)
  • RtlFreeUnicodeString (Address: 0x18006e250)
  • RtlGetNativeSystemInformation (Address: 0x18006e220)
  • RtlGetThreadErrorMode (Address: 0x18006e118)
  • RtlGetVersion (Address: 0x18006e2c0)
  • RtlImageDirectoryEntryToData (Address: 0x18006e1a8)
  • RtlInitAnsiString (Address: 0x18006e1c8)
  • RtlInitializeCriticalSection (Address: 0x18006e1d8)
  • RtlInitString (Address: 0x18006e200)
  • RtlInitUnicodeString (Address: 0x18006e110)
  • RtlInitUnicodeStringEx (Address: 0x18006e248)
  • RtlLeaveCriticalSection (Address: 0x18006e1e0)
  • RtlMultiByteToUnicodeN (Address: 0x18006e1d0)
  • RtlNtStatusToDosError (Address: 0x18006e2c8)
  • RtlRandomEx (Address: 0x18006e270)
  • RtlReAllocateHeap (Address: 0x18006e178)
  • RtlReleaseRelativeName (Address: 0x18006e1b0)
  • RtlSecondsSince1970ToTime (Address: 0x18006e170)
  • RtlSetThreadErrorMode (Address: 0x18006e120)
  • RtlStringFromGUID (Address: 0x18006e268)
  • RtlTimeToSecondsSince1970 (Address: 0x18006e230)
  • RtlTimeToTimeFields (Address: 0x18006e190)
  • RtlUpcaseUnicodeChar (Address: 0x18006e218)
  • RtlVerifyVersionInfo (Address: 0x18006e1a0)
  • RtlxAnsiStringToUnicodeSize (Address: 0x18006e208)
  • WinSqmIsOptedInEx (Address: 0x18006e2a8)
  • ZwClose (Address: 0x18006e138)
  • ZwCreateFile (Address: 0x18006e158)
  • ZwCreateSection (Address: 0x18006e168)
  • ZwEnumerateKey (Address: 0x18006e148)
  • ZwMapViewOfSection (Address: 0x18006e188)
  • ZwOpenKey (Address: 0x18006e140)
  • ZwQueryInformationFile (Address: 0x18006e160)
  • ZwQuerySystemInformation (Address: 0x18006e228)
  • ZwQueryValueKey (Address: 0x18006e150)
  • ZwUnmapViewOfSection (Address: 0x18006e180)
RPCRT4.dll
  • UuidCreate (Address: 0x18006de60)
WDSCORE.dll
  • ConstructPartialMsgVW (Address: 0x18006de70)
  • CurrentIP (Address: 0x18006de78)
  • WdsSetupLogMessageW (Address: 0x18006de80)