gpsvc.dll
Description: Group Policy Client
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 4f19613a337846e4d4d96aa27a5621c9
File Size: 1.3 MB
Uploaded At: Dec. 1, 2025, 7:28 a.m.
Views: 8
Exported Functions
- (Ordinal: 106, Address: 0xa1800)
- GroupPolicyClientServiceMain (Ordinal: 107, Address: 0x5780)
- SvchostPushServiceGlobals (Ordinal: 108, Address: 0x261a0)
- DllCanUnloadNow (Ordinal: 109, Address: 0x9e3e0)
- DllGetClassObject (Ordinal: 110, Address: 0x9e410)
- GenerateRsopPolicy (Ordinal: 111, Address: 0x72310)
- IsSecureCachingDisabled (Ordinal: 112, Address: 0x34b20)
- ProcessGroupPolicyCompletedExInternal (Ordinal: 113, Address: 0x7ce50)
- ProcessGroupPolicyCompletedInternal (Ordinal: 114, Address: 0x7dd00)
- RsopAccessCheckByTypeInternal (Ordinal: 115, Address: 0xa1240)
- RsopFileAccessCheckInternal (Ordinal: 116, Address: 0xa15a0)
- RsopResetPolicySettingStatusInternal (Ordinal: 117, Address: 0xa1940)
- RsopSetPolicySettingStatusInternal (Ordinal: 118, Address: 0xa1d90)
Imported DLLs & Functions
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800c7e68)
- IsDebuggerPresent (Address: 0x1800c7e70)
- OutputDebugStringW (Address: 0x1800c7e60)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800c7e80)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800c7e90)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800c7eb0)
- SetLastError (Address: 0x1800c7ea0)
- SetUnhandledExceptionFilter (Address: 0x1800c7eb8)
- UnhandledExceptionFilter (Address: 0x1800c7ea8)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x1800c7ed8)
- CreateDirectoryW (Address: 0x1800c7f28)
- CreateFileW (Address: 0x1800c7ec8)
- DeleteFileW (Address: 0x1800c7ef0)
- FindClose (Address: 0x1800c7f10)
- FindFirstFileW (Address: 0x1800c7f00)
- FindNextFileW (Address: 0x1800c7ee8)
- GetFileAttributesExW (Address: 0x1800c7ee0)
- GetFileAttributesW (Address: 0x1800c7f40)
- GetFileSizeEx (Address: 0x1800c7f08)
- GetFileTime (Address: 0x1800c7f30)
- ReadFile (Address: 0x1800c7f38)
- RemoveDirectoryW (Address: 0x1800c7ed0)
- SetFileAttributesW (Address: 0x1800c7ef8)
- SetFilePointer (Address: 0x1800c7f18)
- WriteFile (Address: 0x1800c7f20)
api-ms-win-core-file-l2-1-0.dll
- MoveFileExW (Address: 0x1800c7f50)
api-ms-win-core-file-l2-1-2.dll
- CopyFileW (Address: 0x1800c7f60)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800c7f70)
- DuplicateHandle (Address: 0x1800c7f78)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800c7f88)
- HeapAlloc (Address: 0x1800c7f98)
- HeapFree (Address: 0x1800c7f90)
api-ms-win-core-heap-l2-1-0.dll
- GlobalAlloc (Address: 0x1800c7fa8)
- GlobalFree (Address: 0x1800c7fb8)
- LocalAlloc (Address: 0x1800c7fc0)
- LocalFree (Address: 0x1800c7fb0)
- LocalReAlloc (Address: 0x1800c7fc8)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalFlags (Address: 0x1800c7fd8)
api-ms-win-core-job-l2-1-0.dll
- AssignProcessToJobObject (Address: 0x1800c7ff0)
- CreateJobObjectW (Address: 0x1800c8000)
- SetInformationJobObject (Address: 0x1800c7ff8)
- TerminateJobObject (Address: 0x1800c7fe8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- GetComputerNameW (Address: 0x1800c8018)
- WTSGetActiveConsoleSessionId (Address: 0x1800c8010)
api-ms-win-core-kernel32-legacy-l1-1-5.dll
- SetThreadExecutionState (Address: 0x1800c8028)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x1800c8038)
- FreeLibraryAndExitThread (Address: 0x1800c8040)
- GetModuleFileNameA (Address: 0x1800c8058)
- GetModuleHandleExW (Address: 0x1800c8060)
- GetModuleHandleW (Address: 0x1800c8070)
- GetProcAddress (Address: 0x1800c8050)
- LoadLibraryExW (Address: 0x1800c8068)
- LoadStringW (Address: 0x1800c8048)
api-ms-win-core-localization-l1-2-0.dll
- FindNLSString (Address: 0x1800c8080)
- FormatMessageW (Address: 0x1800c8088)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- CompareStringA (Address: 0x1800c8098)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x1800c80b8)
- MapViewOfFile (Address: 0x1800c80b0)
- UnmapViewOfFile (Address: 0x1800c80a8)
api-ms-win-core-path-l1-1-0.dll
- PathCchCombineEx (Address: 0x1800c80c8)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetPrivateProfileIntW (Address: 0x1800c80e0)
- GetPrivateProfileStringW (Address: 0x1800c80e8)
- GetProfileIntW (Address: 0x1800c80d8)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x1800c80f8)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessAsUserW (Address: 0x1800c8150)
- CreateThread (Address: 0x1800c8140)
- GetCurrentProcess (Address: 0x1800c8158)
- GetCurrentProcessId (Address: 0x1800c8168)
- GetCurrentThread (Address: 0x1800c8138)
- GetCurrentThreadId (Address: 0x1800c8160)
- OpenProcessToken (Address: 0x1800c8108)
- OpenThreadToken (Address: 0x1800c8130)
- ResumeThread (Address: 0x1800c8110)
- SetPriorityClass (Address: 0x1800c8118)
- SetThreadPriority (Address: 0x1800c8120)
- SetThreadToken (Address: 0x1800c8148)
- TerminateProcess (Address: 0x1800c8128)
api-ms-win-core-processthreads-l1-1-1.dll
- GetProcessMitigationPolicy (Address: 0x1800c8178)
- SetProcessMitigationPolicy (Address: 0x1800c8180)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800c8190)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800c81c8)
- RegCreateKeyExW (Address: 0x1800c81e8)
- RegDeleteKeyExW (Address: 0x1800c81b8)
- RegDeleteValueW (Address: 0x1800c81f8)
- RegEnumKeyExW (Address: 0x1800c81c0)
- RegEnumValueW (Address: 0x1800c8218)
- RegGetKeySecurity (Address: 0x1800c81a8)
- RegGetValueW (Address: 0x1800c81d0)
- RegNotifyChangeKeyValue (Address: 0x1800c8210)
- RegOpenCurrentUser (Address: 0x1800c8208)
- RegOpenKeyExW (Address: 0x1800c8200)
- RegQueryInfoKeyW (Address: 0x1800c81a0)
- RegQueryValueExA (Address: 0x1800c81b0)
- RegQueryValueExW (Address: 0x1800c81d8)
- RegSetKeySecurity (Address: 0x1800c81e0)
- RegSetValueExW (Address: 0x1800c81f0)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800c8238)
- RtlLookupFunctionEntry (Address: 0x1800c8228)
- RtlVirtualUnwind (Address: 0x1800c8230)
api-ms-win-core-string-l1-1-0.dll
- CompareStringEx (Address: 0x1800c8248)
- CompareStringW (Address: 0x1800c8250)
- MultiByteToWideChar (Address: 0x1800c8258)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x1800c8270)
- lstrcmpW (Address: 0x1800c8268)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800c82a0)
- AcquireSRWLockShared (Address: 0x1800c82a8)
- CreateEventW (Address: 0x1800c82f8)
- CreateMutexExW (Address: 0x1800c82b8)
- CreateSemaphoreExW (Address: 0x1800c82e0)
- CreateWaitableTimerExW (Address: 0x1800c82d0)
- DeleteCriticalSection (Address: 0x1800c82c0)
- EnterCriticalSection (Address: 0x1800c8308)
- InitializeCriticalSection (Address: 0x1800c8310)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800c8338)
- InitializeCriticalSectionEx (Address: 0x1800c8328)
- LeaveCriticalSection (Address: 0x1800c8320)
- OpenEventW (Address: 0x1800c82f0)
- OpenSemaphoreW (Address: 0x1800c8288)
- ReleaseMutex (Address: 0x1800c82e8)
- ReleaseSemaphore (Address: 0x1800c8318)
- ReleaseSRWLockExclusive (Address: 0x1800c82b0)
- ReleaseSRWLockShared (Address: 0x1800c8280)
- ResetEvent (Address: 0x1800c8330)
- SetEvent (Address: 0x1800c8290)
- SetWaitableTimer (Address: 0x1800c82c8)
- WaitForMultipleObjectsEx (Address: 0x1800c82d8)
- WaitForSingleObject (Address: 0x1800c8300)
- WaitForSingleObjectEx (Address: 0x1800c8298)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x1800c8348)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x1800c8370)
- GetLocalTime (Address: 0x1800c8388)
- GetSystemDirectoryW (Address: 0x1800c8358)
- GetSystemTime (Address: 0x1800c8380)
- GetSystemTimeAsFileTime (Address: 0x1800c8360)
- GetTickCount (Address: 0x1800c8368)
- GetVersionExW (Address: 0x1800c8378)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetOsSafeBootMode (Address: 0x1800c83a0)
- GetProductInfo (Address: 0x1800c8398)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1800c83b0)
- CloseThreadpoolWait (Address: 0x1800c83c0)
- CreateThreadpoolTimer (Address: 0x1800c83c8)
- CreateThreadpoolWait (Address: 0x1800c83d8)
- SetThreadpoolTimer (Address: 0x1800c83b8)
- SetThreadpoolWait (Address: 0x1800c83e8)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800c83e0)
- WaitForThreadpoolWaitCallbacks (Address: 0x1800c83d0)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- QueueUserWorkItem (Address: 0x1800c8400)
- UnregisterWaitEx (Address: 0x1800c83f8)
api-ms-win-core-threadpool-private-l1-1-0.dll
- RegisterWaitForSingleObjectEx (Address: 0x1800c8410)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x1800c8428)
- SystemTimeToFileTime (Address: 0x1800c8420)
api-ms-win-eventing-provider-l1-1-0.dll
- EventProviderEnabled (Address: 0x1800c8438)
- EventRegister (Address: 0x1800c8440)
- EventSetInformation (Address: 0x1800c8458)
- EventUnregister (Address: 0x1800c8448)
- EventWriteTransfer (Address: 0x1800c8450)
api-ms-win-security-activedirectoryclient-l1-1-0.dll
- DsBindWithSpnExW (Address: 0x1800c8470)
- DsCrackNamesW (Address: 0x1800c8468)
- DsFreeNameResultW (Address: 0x1800c8478)
- DsUnBindW (Address: 0x1800c8480)
api-ms-win-security-base-l1-1-0.dll
- AccessCheck (Address: 0x1800c8590)
- AccessCheckByType (Address: 0x1800c84c0)
- AddAccessAllowedAce (Address: 0x1800c8550)
- AddAccessAllowedAceEx (Address: 0x1800c84e0)
- AllocateAndInitializeSid (Address: 0x1800c84f8)
- CheckTokenMembership (Address: 0x1800c8510)
- CopySid (Address: 0x1800c84a0)
- CreateWellKnownSid (Address: 0x1800c8508)
- DeleteAce (Address: 0x1800c8518)
- DuplicateTokenEx (Address: 0x1800c84b0)
- EqualSid (Address: 0x1800c8598)
- FreeSid (Address: 0x1800c8520)
- GetAce (Address: 0x1800c8558)
- GetLengthSid (Address: 0x1800c8528)
- GetSecurityDescriptorDacl (Address: 0x1800c8538)
- GetSecurityDescriptorLength (Address: 0x1800c84b8)
- GetSidSubAuthority (Address: 0x1800c84c8)
- GetSidSubAuthorityCount (Address: 0x1800c84d0)
- GetTokenInformation (Address: 0x1800c8570)
- ImpersonateLoggedOnUser (Address: 0x1800c8580)
- InitializeAcl (Address: 0x1800c8548)
- InitializeSecurityDescriptor (Address: 0x1800c8560)
- IsValidSecurityDescriptor (Address: 0x1800c8498)
- IsValidSid (Address: 0x1800c84a8)
- IsWellKnownSid (Address: 0x1800c8568)
- MakeSelfRelativeSD (Address: 0x1800c8500)
- MapGenericMask (Address: 0x1800c8490)
- RevertToSelf (Address: 0x1800c8588)
- SetFileSecurityW (Address: 0x1800c84d8)
- SetSecurityDescriptorControl (Address: 0x1800c8530)
- SetSecurityDescriptorDacl (Address: 0x1800c8578)
- SetSecurityDescriptorGroup (Address: 0x1800c84e8)
- SetSecurityDescriptorOwner (Address: 0x1800c84f0)
- SetTokenInformation (Address: 0x1800c8540)
api-ms-win-security-grouppolicy-l1-1-0.dll
- LeaveCriticalPolicySectionInternal (Address: 0x1800c85a8)
- RsopLoggingEnabledInternal (Address: 0x1800c85b0)
api-ms-win-security-lsalookup-l1-1-0.dll
- LookupAccountSidLocalW (Address: 0x1800c85c0)
api-ms-win-security-lsalookup-l1-1-2.dll
- LsaLookupUserAccountType (Address: 0x1800c85d0)
msvcrt.dll
- __C_specific_handler (Address: 0x1800c86a8)
- __CxxFrameHandler3 (Address: 0x1800c86c0)
- __dllonexit (Address: 0x1800c8680)
- _amsg_exit (Address: 0x1800c8660)
- _callnewh (Address: 0x1800c86d0)
- _CxxThrowException (Address: 0x1800c86f0)
- _errno (Address: 0x1800c8758)
- _gmtime64 (Address: 0x1800c8780)
- _initterm (Address: 0x1800c8640)
- _itow (Address: 0x1800c8790)
- _itow_s (Address: 0x1800c8798)
- _lock (Address: 0x1800c8620)
- _onexit (Address: 0x1800c8690)
- _purecall (Address: 0x1800c8678)
- _time64 (Address: 0x1800c8778)
- _tzset (Address: 0x1800c8770)
- _unlock (Address: 0x1800c8618)
- _vsnprintf_s (Address: 0x1800c85e8)
- _vsnwprintf (Address: 0x1800c86e8)
- _wcsicmp (Address: 0x1800c8740)
- _wcsnicmp (Address: 0x1800c8700)
- _wtoi (Address: 0x1800c8720)
- _wtol (Address: 0x1800c8608)
- _XcptFilter (Address: 0x1800c8668)
- ??_V@YAXPEAX@Z (Address: 0x1800c8688)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800c86f8)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800c8670)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800c85f0)
- ??0exception@@QEAA@XZ (Address: 0x1800c8648)
- ??1exception@@UEAA@XZ (Address: 0x1800c8650)
- ??1type_info@@UEAA@XZ (Address: 0x1800c86a0)
- ??3@YAXPEAX@Z (Address: 0x1800c86d8)
- ?terminate@@YAXXZ (Address: 0x1800c8698)
- ?what@exception@@UEBAPEBDXZ (Address: 0x1800c8628)
- free (Address: 0x1800c8658)
- iswdigit (Address: 0x1800c8610)
- malloc (Address: 0x1800c8638)
- memcmp (Address: 0x1800c85f8)
- memcpy (Address: 0x1800c86b8)
- memcpy_s (Address: 0x1800c86e0)
- memmove (Address: 0x1800c86b0)
- memmove_s (Address: 0x1800c85e0)
- memset (Address: 0x1800c86c8)
- strchr (Address: 0x1800c8750)
- strtoul (Address: 0x1800c8760)
- swscanf_s (Address: 0x1800c8718)
- toupper (Address: 0x1800c8708)
- vswprintf_s (Address: 0x1800c8728)
- wcschr (Address: 0x1800c8768)
- wcscmp (Address: 0x1800c87a0)
- wcscpy_s (Address: 0x1800c8710)
- wcsftime (Address: 0x1800c8788)
- wcsncmp (Address: 0x1800c8600)
- wcsnlen (Address: 0x1800c8738)
- wcsrchr (Address: 0x1800c8730)
- wcsstr (Address: 0x1800c8630)
- wcstoul (Address: 0x1800c8748)
nlaapi.dll
- NlaAddToPluginRequests (Address: 0x1800c87d0)
- NlaAddToTypeSet (Address: 0x1800c8818)
- NlaCloseQuery (Address: 0x1800c87e0)
- NlaCreatePluginRequests (Address: 0x1800c87d8)
- NlaCreateTypeSet (Address: 0x1800c8820)
- NlaDeleteDataSet (Address: 0x1800c87f8)
- NlaDeletePluginRequests (Address: 0x1800c87c8)
- NlaDeleteTypeSet (Address: 0x1800c8828)
- NlaGetInternetCapability (Address: 0x1800c87b8)
- NlaGetIntranetCapability (Address: 0x1800c87f0)
- NlaOpenQuery (Address: 0x1800c8810)
- NlaQueryNetData (Address: 0x1800c8800)
- NlaQueryNetDataEx (Address: 0x1800c87b0)
- NlaQueryNetSignatures (Address: 0x1800c8808)
- NlaRefreshQuery (Address: 0x1800c87c0)
- NlaRegisterQuery (Address: 0x1800c87e8)
ntdll.dll
- EtwEventActivityIdControl (Address: 0x1800c88a8)
- EtwEventEnabled (Address: 0x1800c88f8)
- EtwEventRegister (Address: 0x1800c8898)
- EtwEventUnregister (Address: 0x1800c8890)
- EtwEventWrite (Address: 0x1800c88a0)
- NtClose (Address: 0x1800c88e8)
- NtDuplicateToken (Address: 0x1800c8838)
- NtFsControlFile (Address: 0x1800c8908)
- NtOpenFile (Address: 0x1800c8868)
- NtQueryInformationToken (Address: 0x1800c88b0)
- NtQueryLicenseValue (Address: 0x1800c88f0)
- NtQuerySystemTime (Address: 0x1800c8860)
- NtSetInformationProcess (Address: 0x1800c8870)
- RtlAdjustPrivilege (Address: 0x1800c8880)
- RtlConvertSidToUnicodeString (Address: 0x1800c88c8)
- RtlCopySid (Address: 0x1800c88d0)
- RtlCrc32 (Address: 0x1800c8850)
- RtlDeriveCapabilitySidsFromName (Address: 0x1800c8900)
- RtlEqualSid (Address: 0x1800c8848)
- RtlFreeUnicodeString (Address: 0x1800c88b8)
- RtlInitUnicodeString (Address: 0x1800c88c0)
- RtlIpv4AddressToStringW (Address: 0x1800c8840)
- RtlLengthSid (Address: 0x1800c88d8)
- RtlNtStatusToDosError (Address: 0x1800c88e0)
- RtlPublishWnfStateData (Address: 0x1800c8878)
- RtlTimeToSecondsSince1980 (Address: 0x1800c8858)
- WinSqmSetDWORD (Address: 0x1800c8888)
RPCRT4.dll
- Ndr64AsyncServerCallAll (Address: 0x1800c7de8)
- NdrAsyncServerCall (Address: 0x1800c7de0)
- NdrServerCall2 (Address: 0x1800c7dd8)
- NdrServerCallAll (Address: 0x1800c7d68)
- RpcAsyncAbortCall (Address: 0x1800c7df0)
- RpcAsyncCompleteCall (Address: 0x1800c7e00)
- RpcBindingToStringBindingW (Address: 0x1800c7db8)
- RpcImpersonateClient (Address: 0x1800c7dc8)
- RpcRaiseException (Address: 0x1800c7db0)
- RpcRevertToSelf (Address: 0x1800c7dd0)
- RpcServerInterfaceGroupActivate (Address: 0x1800c7d98)
- RpcServerInterfaceGroupClose (Address: 0x1800c7da8)
- RpcServerInterfaceGroupCreateW (Address: 0x1800c7d90)
- RpcServerInterfaceGroupDeactivate (Address: 0x1800c7da0)
- RpcServerSubscribeForNotification (Address: 0x1800c7df8)
- RpcServerUnsubscribeForNotification (Address: 0x1800c7e08)
- RpcStringBindingParseW (Address: 0x1800c7dc0)
- RpcStringFreeW (Address: 0x1800c7d70)
- UuidCreate (Address: 0x1800c7d80)
- UuidFromStringW (Address: 0x1800c7d78)
- UuidToStringW (Address: 0x1800c7d88)
SYSNTFY.dll
- SysNotifyStartServer (Address: 0x1800c7e18)
- SysNotifyStopServer (Address: 0x1800c7e20)
UMPDC.dll
- Pdcv2ActivationClientActivate (Address: 0x1800c7e40)
- Pdcv2ActivationClientDeactivate (Address: 0x1800c7e38)
- Pdcv2ActivationClientRegister (Address: 0x1800c7e50)
- Pdcv2ActivationClientRenewActivation (Address: 0x1800c7e30)
- Pdcv2ActivationClientUnregister (Address: 0x1800c7e48)