gpprefcl.dll
Description: Group Policy Preference Client
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 29de6321f8d9f0106a450b52983c696e
File Size: 762.5 KB
Uploaded At: Dec. 1, 2025, 7:28 a.m.
Views: 7
Exported Functions
- ProcessGroupPolicyMitigationOptions (Ordinal: 1, Address: 0x4a700)
- ProcessGroupPolicyProcessMitigationOptions (Ordinal: 2, Address: 0x4aa00)
- DllCanUnloadNow (Ordinal: 3, Address: 0x3a010)
- DllGetClassObject (Ordinal: 4, Address: 0x3a030)
- DllRegisterServer (Ordinal: 5, Address: 0x3a190)
- DllUnregisterServer (Ordinal: 6, Address: 0x3a240)
- GenerateGroupPolicyApplications (Ordinal: 7, Address: 0x37b20)
- GenerateGroupPolicyDataSources (Ordinal: 8, Address: 0x384e0)
- GenerateGroupPolicyDevices (Ordinal: 9, Address: 0x38750)
- GenerateGroupPolicyDrives (Ordinal: 10, Address: 0x36ef0)
- GenerateGroupPolicyEnviron (Ordinal: 11, Address: 0x36c80)
- GenerateGroupPolicyFiles (Ordinal: 12, Address: 0x373d0)
- GenerateGroupPolicyFolderOptions (Ordinal: 13, Address: 0x389c0)
- GenerateGroupPolicyFolders (Ordinal: 14, Address: 0x37160)
- GenerateGroupPolicyIniFile (Ordinal: 15, Address: 0x37640)
- GenerateGroupPolicyInternet (Ordinal: 16, Address: 0x38000)
- GenerateGroupPolicyLocUsAndGroups (Ordinal: 17, Address: 0x38c30)
- GenerateGroupPolicyNetShares (Ordinal: 18, Address: 0x39d40)
- GenerateGroupPolicyNetworkOptions (Ordinal: 19, Address: 0x38ea0)
- GenerateGroupPolicyPowerOptions (Ordinal: 20, Address: 0x39110)
- GenerateGroupPolicyPrinters (Ordinal: 21, Address: 0x37d90)
- GenerateGroupPolicyRegionOptions (Ordinal: 22, Address: 0x39380)
- GenerateGroupPolicyRegistry (Ordinal: 23, Address: 0x378b0)
- GenerateGroupPolicySchedTasks (Ordinal: 24, Address: 0x395f0)
- GenerateGroupPolicyServices (Ordinal: 25, Address: 0x39860)
- GenerateGroupPolicyShortcuts (Ordinal: 26, Address: 0x38270)
- GenerateGroupPolicyStartMenu (Ordinal: 27, Address: 0x39ad0)
- ProcessGroupPolicyApplications (Ordinal: 28, Address: 0x37be0)
- ProcessGroupPolicyDataSources (Ordinal: 29, Address: 0x385a0)
- ProcessGroupPolicyDevices (Ordinal: 30, Address: 0x38810)
- ProcessGroupPolicyDrives (Ordinal: 31, Address: 0x36fb0)
- ProcessGroupPolicyEnviron (Ordinal: 32, Address: 0x36d40)
- ProcessGroupPolicyExApplications (Ordinal: 33, Address: 0x37cb0)
- ProcessGroupPolicyExDataSources (Ordinal: 34, Address: 0x38670)
- ProcessGroupPolicyExDevices (Ordinal: 35, Address: 0x388e0)
- ProcessGroupPolicyExDrives (Ordinal: 36, Address: 0x37080)
- ProcessGroupPolicyExEnviron (Ordinal: 37, Address: 0x36e10)
- ProcessGroupPolicyExFiles (Ordinal: 38, Address: 0x37560)
- ProcessGroupPolicyExFolderOptions (Ordinal: 39, Address: 0x38b50)
- ProcessGroupPolicyExFolders (Ordinal: 40, Address: 0x372f0)
- ProcessGroupPolicyExIniFile (Ordinal: 41, Address: 0x377d0)
- ProcessGroupPolicyExInternet (Ordinal: 42, Address: 0x38190)
- ProcessGroupPolicyExLocUsAndGroups (Ordinal: 43, Address: 0x38dc0)
- ProcessGroupPolicyExNetShares (Ordinal: 44, Address: 0x39ed0)
- ProcessGroupPolicyExNetworkOptions (Ordinal: 45, Address: 0x39030)
- ProcessGroupPolicyExPowerOptions (Ordinal: 46, Address: 0x392a0)
- ProcessGroupPolicyExPrinters (Ordinal: 47, Address: 0x37f20)
- ProcessGroupPolicyExRegionOptions (Ordinal: 48, Address: 0x39510)
- ProcessGroupPolicyExRegistry (Ordinal: 49, Address: 0x37a40)
- ProcessGroupPolicyExSchedTasks (Ordinal: 50, Address: 0x39780)
- ProcessGroupPolicyExServices (Ordinal: 51, Address: 0x399f0)
- ProcessGroupPolicyExShortcuts (Ordinal: 52, Address: 0x38400)
- ProcessGroupPolicyExStartMenu (Ordinal: 53, Address: 0x39c60)
- ProcessGroupPolicyFiles (Ordinal: 54, Address: 0x37490)
- ProcessGroupPolicyFolderOptions (Ordinal: 55, Address: 0x38a80)
- ProcessGroupPolicyFolders (Ordinal: 56, Address: 0x37220)
- ProcessGroupPolicyIniFile (Ordinal: 57, Address: 0x37700)
- ProcessGroupPolicyInternet (Ordinal: 58, Address: 0x380c0)
- ProcessGroupPolicyLocUsAndGroups (Ordinal: 59, Address: 0x38cf0)
- ProcessGroupPolicyNetShares (Ordinal: 60, Address: 0x39e00)
- ProcessGroupPolicyNetworkOptions (Ordinal: 61, Address: 0x38f60)
- ProcessGroupPolicyPowerOptions (Ordinal: 62, Address: 0x391d0)
- ProcessGroupPolicyPrinters (Ordinal: 63, Address: 0x37e50)
- ProcessGroupPolicyRegionOptions (Ordinal: 64, Address: 0x39440)
- ProcessGroupPolicyRegistry (Ordinal: 65, Address: 0x37970)
- ProcessGroupPolicySchedTasks (Ordinal: 66, Address: 0x396b0)
- ProcessGroupPolicyServices (Ordinal: 67, Address: 0x39920)
- ProcessGroupPolicyShortcuts (Ordinal: 68, Address: 0x38330)
- ProcessGroupPolicyStartMenu (Ordinal: 69, Address: 0x39b90)
Imported DLLs & Functions
ACTIVEDS.dll
- (Address: 0x180079590)
- (Address: 0x180079598)
- (Address: 0x1800795a0)
- (Address: 0x1800795a8)
- (Address: 0x1800795b0)
- (Address: 0x1800795b8)
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x1800796a0)
- ChangeServiceConfig2W (Address: 0x1800795c8)
- ChangeServiceConfigW (Address: 0x1800795e8)
- CheckTokenMembership (Address: 0x1800796d8)
- CloseEventLog (Address: 0x180079678)
- CloseServiceHandle (Address: 0x180079600)
- ControlService (Address: 0x1800795d8)
- CryptAcquireContextW (Address: 0x180079620)
- CryptCreateHash (Address: 0x180079630)
- CryptDecrypt (Address: 0x180079628)
- CryptDeriveKey (Address: 0x180079638)
- CryptDestroyHash (Address: 0x180079648)
- CryptDestroyKey (Address: 0x180079738)
- CryptHashData (Address: 0x180079640)
- CryptReleaseContext (Address: 0x180079650)
- DuplicateToken (Address: 0x1800796e0)
- EqualSid (Address: 0x1800796a8)
- GetAce (Address: 0x1800796c8)
- GetNamedSecurityInfoW (Address: 0x180079718)
- GetSidIdentifierAuthority (Address: 0x180079660)
- LockServiceDatabase (Address: 0x1800795d0)
- LookupAccountNameW (Address: 0x180079670)
- LookupAccountSidW (Address: 0x180079668)
- LookupPrivilegeValueW (Address: 0x180079698)
- LsaAddAccountRights (Address: 0x180079728)
- LsaClose (Address: 0x1800796e8)
- LsaEnumerateAccountRights (Address: 0x180079730)
- LsaFreeMemory (Address: 0x1800796f0)
- LsaNtStatusToWinError (Address: 0x180079700)
- LsaOpenPolicy (Address: 0x180079708)
- LsaQueryInformationPolicy (Address: 0x1800796f8)
- OpenEventLogW (Address: 0x180079680)
- OpenProcessToken (Address: 0x1800796d0)
- OpenSCManagerW (Address: 0x180079608)
- OpenServiceW (Address: 0x180079618)
- OpenThreadToken (Address: 0x180079658)
- QueryServiceConfig2W (Address: 0x1800795f0)
- QueryServiceConfigW (Address: 0x1800795e0)
- QueryServiceStatus (Address: 0x1800795f8)
- RegDeleteKeyW (Address: 0x1800796b0)
- RegDeleteValueW (Address: 0x180079690)
- RegEnumKeyExW (Address: 0x1800796b8)
- RegSetValueExW (Address: 0x1800796c0)
- ReportEventW (Address: 0x180079688)
- SetNamedSecurityInfoW (Address: 0x180079710)
- StartServiceW (Address: 0x180079610)
- UnlockServiceDatabase (Address: 0x180079720)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x180079dc8)
- CoCreateInstance (Address: 0x180079dc0)
- CoInitializeEx (Address: 0x180079dd0)
- CoSetProxyBlanket (Address: 0x180079db8)
- CoTaskMemFree (Address: 0x180079de8)
- CoUninitialize (Address: 0x180079de0)
- StringFromGUID2 (Address: 0x180079dd8)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180079e00)
- IsDebuggerPresent (Address: 0x180079e08)
- OutputDebugStringA (Address: 0x180079e10)
- OutputDebugStringW (Address: 0x180079df8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180079e28)
- RaiseException (Address: 0x180079e38)
- SetLastError (Address: 0x180079e30)
- SetUnhandledExceptionFilter (Address: 0x180079e40)
- UnhandledExceptionFilter (Address: 0x180079e20)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x180079e90)
- FindClose (Address: 0x180079e80)
- FindFirstFileW (Address: 0x180079e98)
- FindNextFileW (Address: 0x180079e88)
- GetDiskFreeSpaceExW (Address: 0x180079e58)
- GetDiskFreeSpaceW (Address: 0x180079e60)
- GetFileAttributesW (Address: 0x180079e68)
- GetFileSize (Address: 0x180079e78)
- ReadFile (Address: 0x180079e50)
- SetFileAttributesW (Address: 0x180079e70)
api-ms-win-core-file-l2-1-0.dll
- MoveFileExW (Address: 0x180079ea8)
api-ms-win-core-file-l2-1-2.dll
- CopyFileW (Address: 0x180079eb8)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180079ec8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180079ee8)
- HeapAlloc (Address: 0x180079ee0)
- HeapFree (Address: 0x180079ed8)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180079f00)
- LocalFree (Address: 0x180079ef8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x180079f30)
- FindResourceExW (Address: 0x180079f48)
- FreeLibrary (Address: 0x180079f50)
- GetModuleFileNameA (Address: 0x180079f58)
- GetModuleFileNameW (Address: 0x180079f40)
- GetModuleHandleExW (Address: 0x180079f20)
- GetModuleHandleW (Address: 0x180079f18)
- GetProcAddress (Address: 0x180079f68)
- LoadLibraryExW (Address: 0x180079f28)
- LoadResource (Address: 0x180079f60)
- LockResource (Address: 0x180079f10)
- SizeofResource (Address: 0x180079f38)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryA (Address: 0x180079f78)
api-ms-win-core-localization-l1-2-0.dll
- EnumSystemLocalesW (Address: 0x180079fb0)
- FormatMessageW (Address: 0x180079f88)
- GetACP (Address: 0x180079fb8)
- GetLocaleInfoW (Address: 0x180079fd0)
- GetSystemDefaultLangID (Address: 0x180079fa8)
- GetUserDefaultLangID (Address: 0x180079fa0)
- GetUserDefaultLCID (Address: 0x180079f90)
- IsValidLocale (Address: 0x180079f98)
- SetCalendarInfoW (Address: 0x180079fc8)
- SetLocaleInfoW (Address: 0x180079fc0)
api-ms-win-core-path-l1-1-0.dll
- PathCchRemoveBackslash (Address: 0x180079fe0)
- PathCchStripToRoot (Address: 0x180079fe8)
api-ms-win-core-processenvironment-l1-1-0.dll
- GetEnvironmentVariableW (Address: 0x180079ff8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18007a030)
- GetCurrentProcessId (Address: 0x18007a020)
- GetCurrentThread (Address: 0x18007a010)
- GetCurrentThreadId (Address: 0x18007a018)
- SetThreadPriority (Address: 0x18007a008)
- TerminateProcess (Address: 0x18007a028)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18007a040)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18007a080)
- RegCreateKeyExW (Address: 0x18007a078)
- RegEnumValueW (Address: 0x18007a068)
- RegOpenCurrentUser (Address: 0x18007a050)
- RegOpenKeyExW (Address: 0x18007a070)
- RegQueryInfoKeyW (Address: 0x18007a060)
- RegQueryValueExW (Address: 0x18007a058)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18007a098)
- RtlLookupFunctionEntry (Address: 0x18007a090)
- RtlVirtualUnwind (Address: 0x18007a0a0)
api-ms-win-core-string-l1-1-0.dll
- CompareStringW (Address: 0x18007a0b8)
- MultiByteToWideChar (Address: 0x18007a0b0)
- WideCharToMultiByte (Address: 0x18007a0c0)
api-ms-win-core-string-l2-1-0.dll
- CharLowerW (Address: 0x18007a0d0)
- CharNextW (Address: 0x18007a0e0)
- CharUpperW (Address: 0x18007a0d8)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18007a140)
- AcquireSRWLockShared (Address: 0x18007a148)
- CreateMutexExW (Address: 0x18007a168)
- CreateSemaphoreExW (Address: 0x18007a160)
- DeleteCriticalSection (Address: 0x18007a0f8)
- EnterCriticalSection (Address: 0x18007a108)
- InitializeCriticalSection (Address: 0x18007a0f0)
- InitializeCriticalSectionEx (Address: 0x18007a128)
- LeaveCriticalSection (Address: 0x18007a150)
- OpenSemaphoreW (Address: 0x18007a138)
- ReleaseMutex (Address: 0x18007a118)
- ReleaseSemaphore (Address: 0x18007a110)
- ReleaseSRWLockExclusive (Address: 0x18007a158)
- ReleaseSRWLockShared (Address: 0x18007a100)
- WaitForSingleObject (Address: 0x18007a130)
- WaitForSingleObjectEx (Address: 0x18007a120)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x18007a180)
- SleepConditionVariableSRW (Address: 0x18007a188)
- WakeAllConditionVariable (Address: 0x18007a178)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetLocalTime (Address: 0x18007a1b8)
- GetSystemInfo (Address: 0x18007a1c0)
- GetSystemTime (Address: 0x18007a198)
- GetSystemTimeAsFileTime (Address: 0x18007a1a8)
- GetTickCount (Address: 0x18007a1b0)
- GetVersionExW (Address: 0x18007a1a0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x18007a1d8)
- CreateThreadpoolTimer (Address: 0x18007a1d0)
- SetThreadpoolTimer (Address: 0x18007a1e8)
- WaitForThreadpoolTimerCallbacks (Address: 0x18007a1e0)
api-ms-win-power-setting-l1-1-0.dll
- PowerGetActiveScheme (Address: 0x18007a210)
- PowerSetActiveScheme (Address: 0x18007a208)
- PowerWriteACValueIndex (Address: 0x18007a200)
- PowerWriteDCValueIndex (Address: 0x18007a1f8)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x18007a260)
- AllocateAndInitializeSid (Address: 0x18007a250)
- CopySid (Address: 0x18007a220)
- CreateWellKnownSid (Address: 0x18007a238)
- FreeSid (Address: 0x18007a288)
- GetLengthSid (Address: 0x18007a228)
- GetSidSubAuthority (Address: 0x18007a230)
- GetSidSubAuthorityCount (Address: 0x18007a270)
- GetTokenInformation (Address: 0x18007a268)
- ImpersonateLoggedOnUser (Address: 0x18007a240)
- InitializeAcl (Address: 0x18007a290)
- InitializeSecurityDescriptor (Address: 0x18007a248)
- IsValidSid (Address: 0x18007a278)
- RevertToSelf (Address: 0x18007a280)
- SetSecurityDescriptorDacl (Address: 0x18007a258)
DSROLE.dll
- DsRoleFreeMemory (Address: 0x180079750)
- DsRoleGetPrimaryDomainInformation (Address: 0x180079748)
IPHLPAPI.DLL
- GetIfTable (Address: 0x180079760)
KERNEL32.dll
- ActivateActCtx (Address: 0x1800797d8)
- CompareFileTime (Address: 0x1800798a0)
- CreateActCtxW (Address: 0x1800797d0)
- CreateDirectoryW (Address: 0x1800797c0)
- DeactivateActCtx (Address: 0x180079818)
- DeleteFileW (Address: 0x180079840)
- EnumResourceLanguagesW (Address: 0x180079770)
- ExpandEnvironmentStringsW (Address: 0x180079850)
- FileTimeToSystemTime (Address: 0x180079838)
- FindActCtxSectionStringW (Address: 0x180079810)
- GetComputerNameW (Address: 0x180079880)
- GetDriveTypeW (Address: 0x1800798b0)
- GetFileInformationByHandle (Address: 0x180079830)
- GetFileInformationByHandleEx (Address: 0x1800797e0)
- GetFileSizeEx (Address: 0x1800797e8)
- GetFinalPathNameByHandleW (Address: 0x180079800)
- GetSystemDirectoryW (Address: 0x180079860)
- GetSystemPowerStatus (Address: 0x180079788)
- GetSystemWindowsDirectoryW (Address: 0x180079898)
- GetTimeZoneInformation (Address: 0x180079868)
- GetVolumeInformationW (Address: 0x1800798a8)
- GetWindowsDirectoryW (Address: 0x180079870)
- GlobalAlloc (Address: 0x1800797a0)
- GlobalFree (Address: 0x1800797a8)
- GlobalLock (Address: 0x1800797b0)
- GlobalMemoryStatus (Address: 0x180079778)
- GlobalUnlock (Address: 0x1800797b8)
- LoadLibraryW (Address: 0x180079848)
- lstrcmpiW (Address: 0x180079790)
- lstrcmpW (Address: 0x180079798)
- QueryActCtxW (Address: 0x180079828)
- RemoveDirectoryW (Address: 0x1800797f8)
- SetDllDirectoryW (Address: 0x180079820)
- SetEnvironmentVariableW (Address: 0x180079858)
- SetFilePointer (Address: 0x180079808)
- SystemTimeToFileTime (Address: 0x180079888)
- VerifyVersionInfoW (Address: 0x180079890)
- VerSetConditionMask (Address: 0x180079878)
- WriteFile (Address: 0x1800797f0)
- WritePrivateProfileStringW (Address: 0x1800797c8)
- WTSGetActiveConsoleSessionId (Address: 0x180079780)
logoncli.dll
- DsGetSiteNameW (Address: 0x18007a2a0)
MPR.dll
- WNetCancelConnection2W (Address: 0x1800798c8)
- WNetGetConnectionW (Address: 0x1800798d0)
- WNetUseConnectionW (Address: 0x1800798c0)
msi.dll
- (Address: 0x18007a2b0)
- (Address: 0x18007a2b8)
- (Address: 0x18007a2c0)
- (Address: 0x18007a2c8)
- (Address: 0x18007a2d0)
- (Address: 0x18007a2d8)
- (Address: 0x18007a2e0)
- (Address: 0x18007a2e8)
msvcrt.dll
- __C_specific_handler (Address: 0x18007a310)
- __CxxFrameHandler3 (Address: 0x18007a398)
- __dllonexit (Address: 0x18007a3e8)
- _amsg_exit (Address: 0x18007a3c0)
- _callnewh (Address: 0x18007a3b0)
- _CxxThrowException (Address: 0x18007a2f8)
- _errno (Address: 0x18007a400)
- _initterm (Address: 0x18007a3c8)
- _lock (Address: 0x18007a3d8)
- _onexit (Address: 0x18007a3f0)
- _purecall (Address: 0x18007a328)
- _unlock (Address: 0x18007a3e0)
- _vsnprintf_s (Address: 0x18007a360)
- _vsnwprintf (Address: 0x18007a320)
- _vsnwprintf_s (Address: 0x18007a300)
- _wcsnicmp (Address: 0x18007a440)
- _wtof (Address: 0x18007a390)
- _wtoi (Address: 0x18007a370)
- _wtol (Address: 0x18007a3a0)
- _XcptFilter (Address: 0x18007a3b8)
- ?_set_se_translator@@YAP6AXIPEAU_EXCEPTION_POINTERS@@@ZP6AXI0@Z@Z (Address: 0x18007a438)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x18007a358)
- ??0exception@@QEAA@XZ (Address: 0x18007a368)
- ??1exception@@UEAA@XZ (Address: 0x18007a350)
- ??1type_info@@UEAA@XZ (Address: 0x18007a3f8)
- ?terminate@@YAXXZ (Address: 0x18007a3d0)
- calloc (Address: 0x18007a340)
- free (Address: 0x18007a318)
- malloc (Address: 0x18007a3a8)
- memcmp (Address: 0x18007a420)
- memcpy (Address: 0x18007a428)
- memcpy_s (Address: 0x18007a338)
- memmove (Address: 0x18007a430)
- memmove_s (Address: 0x18007a348)
- memset (Address: 0x18007a410)
- realloc (Address: 0x18007a408)
- swscanf (Address: 0x18007a308)
- wcscat_s (Address: 0x18007a380)
- wcscmp (Address: 0x18007a448)
- wcscpy_s (Address: 0x18007a378)
- wcsncmp (Address: 0x18007a330)
- wcsncpy_s (Address: 0x18007a388)
- wcsnlen (Address: 0x18007a418)
NETAPI32.dll
- Netbios (Address: 0x1800798f8)
- NetLocalGroupAdd (Address: 0x180079940)
- NetLocalGroupAddMembers (Address: 0x180079920)
- NetLocalGroupDel (Address: 0x180079928)
- NetLocalGroupDelMembers (Address: 0x180079930)
- NetLocalGroupGetInfo (Address: 0x180079918)
- NetLocalGroupGetMembers (Address: 0x180079938)
- NetLocalGroupSetInfo (Address: 0x180079910)
- NetUserAdd (Address: 0x180079900)
- NetUserDel (Address: 0x1800798e8)
- NetUserGetInfo (Address: 0x1800798f0)
- NetUserSetInfo (Address: 0x180079908)
- NetWkstaGetInfo (Address: 0x1800798e0)
netutils.dll
- NetApiBufferFree (Address: 0x18007a458)
ntdll.dll
- NtClose (Address: 0x18007a468)
- NtCreateFile (Address: 0x18007a478)
- NtFsControlFile (Address: 0x18007a488)
- NtQueryInformationToken (Address: 0x18007a470)
- RtlInitUnicodeString (Address: 0x18007a490)
- RtlIpv6StringToAddressW (Address: 0x18007a480)
NTDSAPI.dll
- DsBindW (Address: 0x180079960)
- DsCrackNamesW (Address: 0x180079950)
- DsFreeNameResultW (Address: 0x180079958)
- DsUnBindW (Address: 0x180079968)
OLEAUT32.dll
- LoadTypeLib (Address: 0x180079978)
- RegisterTypeLib (Address: 0x180079998)
- SafeArrayAccessData (Address: 0x1800799b8)
- SafeArrayCopy (Address: 0x1800799e8)
- SafeArrayCreate (Address: 0x180079988)
- SafeArrayDestroy (Address: 0x180079a08)
- SafeArrayGetLBound (Address: 0x1800799f0)
- SafeArrayGetUBound (Address: 0x1800799f8)
- SafeArrayGetVartype (Address: 0x1800799e0)
- SafeArrayLock (Address: 0x180079a00)
- SafeArrayRedim (Address: 0x180079990)
- SafeArrayUnaccessData (Address: 0x1800799c0)
- SafeArrayUnlock (Address: 0x180079a18)
- SysAllocString (Address: 0x1800799b0)
- SysAllocStringLen (Address: 0x1800799a8)
- SysFreeString (Address: 0x1800799d8)
- SysStringLen (Address: 0x180079a10)
- UnRegisterTypeLib (Address: 0x1800799a0)
- VarBstrCat (Address: 0x1800799c8)
- VariantChangeType (Address: 0x180079980)
- VariantClear (Address: 0x180079a28)
- VariantCopy (Address: 0x1800799d0)
- VariantInit (Address: 0x180079a20)
POWRPROF.dll
- CallNtPowerInformation (Address: 0x180079a98)
- DeletePwrScheme (Address: 0x180079a50)
- EnumPwrSchemes (Address: 0x180079a40)
- GetActivePwrScheme (Address: 0x180079a60)
- GetPwrCapabilities (Address: 0x180079aa8)
- PowerDeleteScheme (Address: 0x180079a80)
- PowerDeterminePlatformRole (Address: 0x180079aa0)
- PowerDuplicateScheme (Address: 0x180079a70)
- PowerEnumerate (Address: 0x180079a88)
- PowerReadFriendlyName (Address: 0x180079a90)
- PowerWriteFriendlyName (Address: 0x180079a78)
- ReadGlobalPwrPolicy (Address: 0x180079a58)
- ReadPwrScheme (Address: 0x180079a48)
- SetActivePwrScheme (Address: 0x180079a68)
- WriteGlobalPwrPolicy (Address: 0x180079ab0)
- WritePwrScheme (Address: 0x180079a38)
RPCRT4.dll
- RpcStringFreeW (Address: 0x180079ad0)
- UuidCreate (Address: 0x180079ac8)
- UuidEqual (Address: 0x180079ac0)
- UuidToStringW (Address: 0x180079ad8)
samcli.dll
- NetUserGetGroups (Address: 0x18007a4a8)
- NetUserGetLocalGroups (Address: 0x18007a4a0)
Secur32.dll
- AcceptSecurityContext (Address: 0x180079b68)
- AcquireCredentialsHandleW (Address: 0x180079b88)
- DeleteSecurityContext (Address: 0x180079b80)
- FreeContextBuffer (Address: 0x180079b78)
- FreeCredentialsHandle (Address: 0x180079b90)
- InitializeSecurityContextW (Address: 0x180079ba0)
- QuerySecurityContextToken (Address: 0x180079b60)
- QuerySecurityPackageInfoW (Address: 0x180079ba8)
- SeciAllocateAndSetIPAddress (Address: 0x180079b98)
- SeciFreeCallContext (Address: 0x180079b70)
SETUPAPI.dll
- SetupDiCallClassInstaller (Address: 0x180079b10)
- SetupDiDestroyDeviceInfoList (Address: 0x180079ae8)
- SetupDiEnumDeviceInfo (Address: 0x180079af8)
- SetupDiGetDeviceInstanceIdW (Address: 0x180079b08)
- SetupDiGetDevicePropertyW (Address: 0x180079af0)
- SetupDiSetClassInstallParamsW (Address: 0x180079b00)
SHELL32.dll
- SHChangeNotify (Address: 0x180079b30)
- Shell_NotifyIconW (Address: 0x180079b20)
- SHGetFolderPathW (Address: 0x180079b40)
- SHGetKnownFolderPath (Address: 0x180079b38)
- SHGetMalloc (Address: 0x180079b28)
SHLWAPI.dll
- (Address: 0x180079b50)
srvcli.dll
- NetShareAdd (Address: 0x18007a4c8)
- NetShareDel (Address: 0x18007a4d0)
- NetShareEnum (Address: 0x18007a4d8)
- NetShareGetInfo (Address: 0x18007a4c0)
- NetShareSetInfo (Address: 0x18007a4b8)
USER32.dll
- CharPrevW (Address: 0x180079c28)
- CharUpperBuffW (Address: 0x180079c20)
- CreateWindowExW (Address: 0x180079bd8)
- DefWindowProcW (Address: 0x180079c08)
- DestroyWindow (Address: 0x180079bb8)
- ExitWindowsEx (Address: 0x180079c10)
- GetSystemMetrics (Address: 0x180079bc0)
- GetWindowLongPtrW (Address: 0x180079c00)
- LoadIconW (Address: 0x180079bc8)
- MessageBoxW (Address: 0x180079c38)
- RegisterClassExW (Address: 0x180079bd0)
- SendMessageW (Address: 0x180079bf0)
- SendNotifyMessageW (Address: 0x180079c30)
- SetWindowLongPtrW (Address: 0x180079be0)
- SetWindowPos (Address: 0x180079be8)
- UnregisterClassA (Address: 0x180079c18)
- UnregisterClassW (Address: 0x180079bf8)
USERENV.dll
- CreateEnvironmentBlock (Address: 0x180079c70)
- DestroyEnvironmentBlock (Address: 0x180079c48)
- ProcessGroupPolicyCompleted (Address: 0x180079c58)
- ProcessGroupPolicyCompletedEx (Address: 0x180079c60)
- RsopResetPolicySettingStatus (Address: 0x180079c68)
- RsopSetPolicySettingStatus (Address: 0x180079c50)
VERSION.dll
- GetFileVersionInfoSizeW (Address: 0x180079c90)
- GetFileVersionInfoW (Address: 0x180079c80)
- VerQueryValueW (Address: 0x180079c88)
WINSPOOL.DRV
- (Address: 0x180079d00)
- AddPrinterConnectionW (Address: 0x180079cd8)
- AddPrinterDriverW (Address: 0x180079ce8)
- AddPrinterW (Address: 0x180079d08)
- ClosePrinter (Address: 0x180079d18)
- DeletePrinter (Address: 0x180079ca8)
- DeletePrinterConnectionW (Address: 0x180079cf8)
- EnumMonitorsW (Address: 0x180079cc0)
- EnumPortsW (Address: 0x180079ca0)
- EnumPrinterDriversW (Address: 0x180079cc8)
- EnumPrintersW (Address: 0x180079cd0)
- GetPrinterDriverDirectoryW (Address: 0x180079cf0)
- GetPrinterDriverW (Address: 0x180079d10)
- GetPrinterW (Address: 0x180079ce0)
- OpenPrinterW (Address: 0x180079cb0)
- XcvDataW (Address: 0x180079cb8)
WINSTA.dll
- WinStationBroadcastSystemMessage (Address: 0x180079d30)
- WinStationSendWindowMessage (Address: 0x180079d28)
WLDAP32.dll
- (Address: 0x180079d48)
- (Address: 0x180079d40)
WS2_32.dll
- FreeAddrInfoW (Address: 0x180079d58)
- GetAddrInfoW (Address: 0x180079d68)
- ntohl (Address: 0x180079d70)
- WSACleanup (Address: 0x180079d80)
- WSAGetLastError (Address: 0x180079d78)
- WSAStartup (Address: 0x180079d60)
WTSAPI32.dll
- WTSFreeMemory (Address: 0x180079d98)
- WTSQuerySessionInformationW (Address: 0x180079d90)
XmlLite.dll
- CreateXmlReader (Address: 0x180079da8)