gpsvc.dll

Description: Group Policy Client

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 4f19613a337846e4d4d96aa27a5621c9

File Size: 1.3 MB

Uploaded At: Dec. 1, 2025, 7:28 a.m.

Views: 8

Exported Functions

  • (Ordinal: 106, Address: 0xa1800)
  • GroupPolicyClientServiceMain (Ordinal: 107, Address: 0x5780)
  • SvchostPushServiceGlobals (Ordinal: 108, Address: 0x261a0)
  • DllCanUnloadNow (Ordinal: 109, Address: 0x9e3e0)
  • DllGetClassObject (Ordinal: 110, Address: 0x9e410)
  • GenerateRsopPolicy (Ordinal: 111, Address: 0x72310)
  • IsSecureCachingDisabled (Ordinal: 112, Address: 0x34b20)
  • ProcessGroupPolicyCompletedExInternal (Ordinal: 113, Address: 0x7ce50)
  • ProcessGroupPolicyCompletedInternal (Ordinal: 114, Address: 0x7dd00)
  • RsopAccessCheckByTypeInternal (Ordinal: 115, Address: 0xa1240)
  • RsopFileAccessCheckInternal (Ordinal: 116, Address: 0xa15a0)
  • RsopResetPolicySettingStatusInternal (Ordinal: 117, Address: 0xa1940)
  • RsopSetPolicySettingStatusInternal (Ordinal: 118, Address: 0xa1d90)

Imported DLLs & Functions

api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800c7e68)
  • IsDebuggerPresent (Address: 0x1800c7e70)
  • OutputDebugStringW (Address: 0x1800c7e60)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800c7e80)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800c7e90)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800c7eb0)
  • SetLastError (Address: 0x1800c7ea0)
  • SetUnhandledExceptionFilter (Address: 0x1800c7eb8)
  • UnhandledExceptionFilter (Address: 0x1800c7ea8)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x1800c7ed8)
  • CreateDirectoryW (Address: 0x1800c7f28)
  • CreateFileW (Address: 0x1800c7ec8)
  • DeleteFileW (Address: 0x1800c7ef0)
  • FindClose (Address: 0x1800c7f10)
  • FindFirstFileW (Address: 0x1800c7f00)
  • FindNextFileW (Address: 0x1800c7ee8)
  • GetFileAttributesExW (Address: 0x1800c7ee0)
  • GetFileAttributesW (Address: 0x1800c7f40)
  • GetFileSizeEx (Address: 0x1800c7f08)
  • GetFileTime (Address: 0x1800c7f30)
  • ReadFile (Address: 0x1800c7f38)
  • RemoveDirectoryW (Address: 0x1800c7ed0)
  • SetFileAttributesW (Address: 0x1800c7ef8)
  • SetFilePointer (Address: 0x1800c7f18)
  • WriteFile (Address: 0x1800c7f20)
api-ms-win-core-file-l2-1-0.dll
  • MoveFileExW (Address: 0x1800c7f50)
api-ms-win-core-file-l2-1-2.dll
  • CopyFileW (Address: 0x1800c7f60)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800c7f70)
  • DuplicateHandle (Address: 0x1800c7f78)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1800c7f88)
  • HeapAlloc (Address: 0x1800c7f98)
  • HeapFree (Address: 0x1800c7f90)
api-ms-win-core-heap-l2-1-0.dll
  • GlobalAlloc (Address: 0x1800c7fa8)
  • GlobalFree (Address: 0x1800c7fb8)
  • LocalAlloc (Address: 0x1800c7fc0)
  • LocalFree (Address: 0x1800c7fb0)
  • LocalReAlloc (Address: 0x1800c7fc8)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • LocalFlags (Address: 0x1800c7fd8)
api-ms-win-core-job-l2-1-0.dll
  • AssignProcessToJobObject (Address: 0x1800c7ff0)
  • CreateJobObjectW (Address: 0x1800c8000)
  • SetInformationJobObject (Address: 0x1800c7ff8)
  • TerminateJobObject (Address: 0x1800c7fe8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x1800c8018)
  • WTSGetActiveConsoleSessionId (Address: 0x1800c8010)
api-ms-win-core-kernel32-legacy-l1-1-5.dll
  • SetThreadExecutionState (Address: 0x1800c8028)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x1800c8038)
  • FreeLibraryAndExitThread (Address: 0x1800c8040)
  • GetModuleFileNameA (Address: 0x1800c8058)
  • GetModuleHandleExW (Address: 0x1800c8060)
  • GetModuleHandleW (Address: 0x1800c8070)
  • GetProcAddress (Address: 0x1800c8050)
  • LoadLibraryExW (Address: 0x1800c8068)
  • LoadStringW (Address: 0x1800c8048)
api-ms-win-core-localization-l1-2-0.dll
  • FindNLSString (Address: 0x1800c8080)
  • FormatMessageW (Address: 0x1800c8088)
api-ms-win-core-localization-obsolete-l1-2-0.dll
  • CompareStringA (Address: 0x1800c8098)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x1800c80b8)
  • MapViewOfFile (Address: 0x1800c80b0)
  • UnmapViewOfFile (Address: 0x1800c80a8)
api-ms-win-core-path-l1-1-0.dll
  • PathCchCombineEx (Address: 0x1800c80c8)
api-ms-win-core-privateprofile-l1-1-0.dll
  • GetPrivateProfileIntW (Address: 0x1800c80e0)
  • GetPrivateProfileStringW (Address: 0x1800c80e8)
  • GetProfileIntW (Address: 0x1800c80d8)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800c80f8)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessAsUserW (Address: 0x1800c8150)
  • CreateThread (Address: 0x1800c8140)
  • GetCurrentProcess (Address: 0x1800c8158)
  • GetCurrentProcessId (Address: 0x1800c8168)
  • GetCurrentThread (Address: 0x1800c8138)
  • GetCurrentThreadId (Address: 0x1800c8160)
  • OpenProcessToken (Address: 0x1800c8108)
  • OpenThreadToken (Address: 0x1800c8130)
  • ResumeThread (Address: 0x1800c8110)
  • SetPriorityClass (Address: 0x1800c8118)
  • SetThreadPriority (Address: 0x1800c8120)
  • SetThreadToken (Address: 0x1800c8148)
  • TerminateProcess (Address: 0x1800c8128)
api-ms-win-core-processthreads-l1-1-1.dll
  • GetProcessMitigationPolicy (Address: 0x1800c8178)
  • SetProcessMitigationPolicy (Address: 0x1800c8180)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800c8190)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800c81c8)
  • RegCreateKeyExW (Address: 0x1800c81e8)
  • RegDeleteKeyExW (Address: 0x1800c81b8)
  • RegDeleteValueW (Address: 0x1800c81f8)
  • RegEnumKeyExW (Address: 0x1800c81c0)
  • RegEnumValueW (Address: 0x1800c8218)
  • RegGetKeySecurity (Address: 0x1800c81a8)
  • RegGetValueW (Address: 0x1800c81d0)
  • RegNotifyChangeKeyValue (Address: 0x1800c8210)
  • RegOpenCurrentUser (Address: 0x1800c8208)
  • RegOpenKeyExW (Address: 0x1800c8200)
  • RegQueryInfoKeyW (Address: 0x1800c81a0)
  • RegQueryValueExA (Address: 0x1800c81b0)
  • RegQueryValueExW (Address: 0x1800c81d8)
  • RegSetKeySecurity (Address: 0x1800c81e0)
  • RegSetValueExW (Address: 0x1800c81f0)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800c8238)
  • RtlLookupFunctionEntry (Address: 0x1800c8228)
  • RtlVirtualUnwind (Address: 0x1800c8230)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringEx (Address: 0x1800c8248)
  • CompareStringW (Address: 0x1800c8250)
  • MultiByteToWideChar (Address: 0x1800c8258)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x1800c8270)
  • lstrcmpW (Address: 0x1800c8268)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800c82a0)
  • AcquireSRWLockShared (Address: 0x1800c82a8)
  • CreateEventW (Address: 0x1800c82f8)
  • CreateMutexExW (Address: 0x1800c82b8)
  • CreateSemaphoreExW (Address: 0x1800c82e0)
  • CreateWaitableTimerExW (Address: 0x1800c82d0)
  • DeleteCriticalSection (Address: 0x1800c82c0)
  • EnterCriticalSection (Address: 0x1800c8308)
  • InitializeCriticalSection (Address: 0x1800c8310)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800c8338)
  • InitializeCriticalSectionEx (Address: 0x1800c8328)
  • LeaveCriticalSection (Address: 0x1800c8320)
  • OpenEventW (Address: 0x1800c82f0)
  • OpenSemaphoreW (Address: 0x1800c8288)
  • ReleaseMutex (Address: 0x1800c82e8)
  • ReleaseSemaphore (Address: 0x1800c8318)
  • ReleaseSRWLockExclusive (Address: 0x1800c82b0)
  • ReleaseSRWLockShared (Address: 0x1800c8280)
  • ResetEvent (Address: 0x1800c8330)
  • SetEvent (Address: 0x1800c8290)
  • SetWaitableTimer (Address: 0x1800c82c8)
  • WaitForMultipleObjectsEx (Address: 0x1800c82d8)
  • WaitForSingleObject (Address: 0x1800c8300)
  • WaitForSingleObjectEx (Address: 0x1800c8298)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x1800c8348)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x1800c8370)
  • GetLocalTime (Address: 0x1800c8388)
  • GetSystemDirectoryW (Address: 0x1800c8358)
  • GetSystemTime (Address: 0x1800c8380)
  • GetSystemTimeAsFileTime (Address: 0x1800c8360)
  • GetTickCount (Address: 0x1800c8368)
  • GetVersionExW (Address: 0x1800c8378)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetOsSafeBootMode (Address: 0x1800c83a0)
  • GetProductInfo (Address: 0x1800c8398)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x1800c83b0)
  • CloseThreadpoolWait (Address: 0x1800c83c0)
  • CreateThreadpoolTimer (Address: 0x1800c83c8)
  • CreateThreadpoolWait (Address: 0x1800c83d8)
  • SetThreadpoolTimer (Address: 0x1800c83b8)
  • SetThreadpoolWait (Address: 0x1800c83e8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800c83e0)
  • WaitForThreadpoolWaitCallbacks (Address: 0x1800c83d0)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • QueueUserWorkItem (Address: 0x1800c8400)
  • UnregisterWaitEx (Address: 0x1800c83f8)
api-ms-win-core-threadpool-private-l1-1-0.dll
  • RegisterWaitForSingleObjectEx (Address: 0x1800c8410)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x1800c8428)
  • SystemTimeToFileTime (Address: 0x1800c8420)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x1800c8438)
  • EventRegister (Address: 0x1800c8440)
  • EventSetInformation (Address: 0x1800c8458)
  • EventUnregister (Address: 0x1800c8448)
  • EventWriteTransfer (Address: 0x1800c8450)
api-ms-win-security-activedirectoryclient-l1-1-0.dll
  • DsBindWithSpnExW (Address: 0x1800c8470)
  • DsCrackNamesW (Address: 0x1800c8468)
  • DsFreeNameResultW (Address: 0x1800c8478)
  • DsUnBindW (Address: 0x1800c8480)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheck (Address: 0x1800c8590)
  • AccessCheckByType (Address: 0x1800c84c0)
  • AddAccessAllowedAce (Address: 0x1800c8550)
  • AddAccessAllowedAceEx (Address: 0x1800c84e0)
  • AllocateAndInitializeSid (Address: 0x1800c84f8)
  • CheckTokenMembership (Address: 0x1800c8510)
  • CopySid (Address: 0x1800c84a0)
  • CreateWellKnownSid (Address: 0x1800c8508)
  • DeleteAce (Address: 0x1800c8518)
  • DuplicateTokenEx (Address: 0x1800c84b0)
  • EqualSid (Address: 0x1800c8598)
  • FreeSid (Address: 0x1800c8520)
  • GetAce (Address: 0x1800c8558)
  • GetLengthSid (Address: 0x1800c8528)
  • GetSecurityDescriptorDacl (Address: 0x1800c8538)
  • GetSecurityDescriptorLength (Address: 0x1800c84b8)
  • GetSidSubAuthority (Address: 0x1800c84c8)
  • GetSidSubAuthorityCount (Address: 0x1800c84d0)
  • GetTokenInformation (Address: 0x1800c8570)
  • ImpersonateLoggedOnUser (Address: 0x1800c8580)
  • InitializeAcl (Address: 0x1800c8548)
  • InitializeSecurityDescriptor (Address: 0x1800c8560)
  • IsValidSecurityDescriptor (Address: 0x1800c8498)
  • IsValidSid (Address: 0x1800c84a8)
  • IsWellKnownSid (Address: 0x1800c8568)
  • MakeSelfRelativeSD (Address: 0x1800c8500)
  • MapGenericMask (Address: 0x1800c8490)
  • RevertToSelf (Address: 0x1800c8588)
  • SetFileSecurityW (Address: 0x1800c84d8)
  • SetSecurityDescriptorControl (Address: 0x1800c8530)
  • SetSecurityDescriptorDacl (Address: 0x1800c8578)
  • SetSecurityDescriptorGroup (Address: 0x1800c84e8)
  • SetSecurityDescriptorOwner (Address: 0x1800c84f0)
  • SetTokenInformation (Address: 0x1800c8540)
api-ms-win-security-grouppolicy-l1-1-0.dll
  • LeaveCriticalPolicySectionInternal (Address: 0x1800c85a8)
  • RsopLoggingEnabledInternal (Address: 0x1800c85b0)
api-ms-win-security-lsalookup-l1-1-0.dll
  • LookupAccountSidLocalW (Address: 0x1800c85c0)
api-ms-win-security-lsalookup-l1-1-2.dll
  • LsaLookupUserAccountType (Address: 0x1800c85d0)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800c86a8)
  • __CxxFrameHandler3 (Address: 0x1800c86c0)
  • __dllonexit (Address: 0x1800c8680)
  • _amsg_exit (Address: 0x1800c8660)
  • _callnewh (Address: 0x1800c86d0)
  • _CxxThrowException (Address: 0x1800c86f0)
  • _errno (Address: 0x1800c8758)
  • _gmtime64 (Address: 0x1800c8780)
  • _initterm (Address: 0x1800c8640)
  • _itow (Address: 0x1800c8790)
  • _itow_s (Address: 0x1800c8798)
  • _lock (Address: 0x1800c8620)
  • _onexit (Address: 0x1800c8690)
  • _purecall (Address: 0x1800c8678)
  • _time64 (Address: 0x1800c8778)
  • _tzset (Address: 0x1800c8770)
  • _unlock (Address: 0x1800c8618)
  • _vsnprintf_s (Address: 0x1800c85e8)
  • _vsnwprintf (Address: 0x1800c86e8)
  • _wcsicmp (Address: 0x1800c8740)
  • _wcsnicmp (Address: 0x1800c8700)
  • _wtoi (Address: 0x1800c8720)
  • _wtol (Address: 0x1800c8608)
  • _XcptFilter (Address: 0x1800c8668)
  • ??_V@YAXPEAX@Z (Address: 0x1800c8688)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800c86f8)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800c8670)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800c85f0)
  • ??0exception@@QEAA@XZ (Address: 0x1800c8648)
  • ??1exception@@UEAA@XZ (Address: 0x1800c8650)
  • ??1type_info@@UEAA@XZ (Address: 0x1800c86a0)
  • ??3@YAXPEAX@Z (Address: 0x1800c86d8)
  • ?terminate@@YAXXZ (Address: 0x1800c8698)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x1800c8628)
  • free (Address: 0x1800c8658)
  • iswdigit (Address: 0x1800c8610)
  • malloc (Address: 0x1800c8638)
  • memcmp (Address: 0x1800c85f8)
  • memcpy (Address: 0x1800c86b8)
  • memcpy_s (Address: 0x1800c86e0)
  • memmove (Address: 0x1800c86b0)
  • memmove_s (Address: 0x1800c85e0)
  • memset (Address: 0x1800c86c8)
  • strchr (Address: 0x1800c8750)
  • strtoul (Address: 0x1800c8760)
  • swscanf_s (Address: 0x1800c8718)
  • toupper (Address: 0x1800c8708)
  • vswprintf_s (Address: 0x1800c8728)
  • wcschr (Address: 0x1800c8768)
  • wcscmp (Address: 0x1800c87a0)
  • wcscpy_s (Address: 0x1800c8710)
  • wcsftime (Address: 0x1800c8788)
  • wcsncmp (Address: 0x1800c8600)
  • wcsnlen (Address: 0x1800c8738)
  • wcsrchr (Address: 0x1800c8730)
  • wcsstr (Address: 0x1800c8630)
  • wcstoul (Address: 0x1800c8748)
nlaapi.dll
  • NlaAddToPluginRequests (Address: 0x1800c87d0)
  • NlaAddToTypeSet (Address: 0x1800c8818)
  • NlaCloseQuery (Address: 0x1800c87e0)
  • NlaCreatePluginRequests (Address: 0x1800c87d8)
  • NlaCreateTypeSet (Address: 0x1800c8820)
  • NlaDeleteDataSet (Address: 0x1800c87f8)
  • NlaDeletePluginRequests (Address: 0x1800c87c8)
  • NlaDeleteTypeSet (Address: 0x1800c8828)
  • NlaGetInternetCapability (Address: 0x1800c87b8)
  • NlaGetIntranetCapability (Address: 0x1800c87f0)
  • NlaOpenQuery (Address: 0x1800c8810)
  • NlaQueryNetData (Address: 0x1800c8800)
  • NlaQueryNetDataEx (Address: 0x1800c87b0)
  • NlaQueryNetSignatures (Address: 0x1800c8808)
  • NlaRefreshQuery (Address: 0x1800c87c0)
  • NlaRegisterQuery (Address: 0x1800c87e8)
ntdll.dll
  • EtwEventActivityIdControl (Address: 0x1800c88a8)
  • EtwEventEnabled (Address: 0x1800c88f8)
  • EtwEventRegister (Address: 0x1800c8898)
  • EtwEventUnregister (Address: 0x1800c8890)
  • EtwEventWrite (Address: 0x1800c88a0)
  • NtClose (Address: 0x1800c88e8)
  • NtDuplicateToken (Address: 0x1800c8838)
  • NtFsControlFile (Address: 0x1800c8908)
  • NtOpenFile (Address: 0x1800c8868)
  • NtQueryInformationToken (Address: 0x1800c88b0)
  • NtQueryLicenseValue (Address: 0x1800c88f0)
  • NtQuerySystemTime (Address: 0x1800c8860)
  • NtSetInformationProcess (Address: 0x1800c8870)
  • RtlAdjustPrivilege (Address: 0x1800c8880)
  • RtlConvertSidToUnicodeString (Address: 0x1800c88c8)
  • RtlCopySid (Address: 0x1800c88d0)
  • RtlCrc32 (Address: 0x1800c8850)
  • RtlDeriveCapabilitySidsFromName (Address: 0x1800c8900)
  • RtlEqualSid (Address: 0x1800c8848)
  • RtlFreeUnicodeString (Address: 0x1800c88b8)
  • RtlInitUnicodeString (Address: 0x1800c88c0)
  • RtlIpv4AddressToStringW (Address: 0x1800c8840)
  • RtlLengthSid (Address: 0x1800c88d8)
  • RtlNtStatusToDosError (Address: 0x1800c88e0)
  • RtlPublishWnfStateData (Address: 0x1800c8878)
  • RtlTimeToSecondsSince1980 (Address: 0x1800c8858)
  • WinSqmSetDWORD (Address: 0x1800c8888)
RPCRT4.dll
  • Ndr64AsyncServerCallAll (Address: 0x1800c7de8)
  • NdrAsyncServerCall (Address: 0x1800c7de0)
  • NdrServerCall2 (Address: 0x1800c7dd8)
  • NdrServerCallAll (Address: 0x1800c7d68)
  • RpcAsyncAbortCall (Address: 0x1800c7df0)
  • RpcAsyncCompleteCall (Address: 0x1800c7e00)
  • RpcBindingToStringBindingW (Address: 0x1800c7db8)
  • RpcImpersonateClient (Address: 0x1800c7dc8)
  • RpcRaiseException (Address: 0x1800c7db0)
  • RpcRevertToSelf (Address: 0x1800c7dd0)
  • RpcServerInterfaceGroupActivate (Address: 0x1800c7d98)
  • RpcServerInterfaceGroupClose (Address: 0x1800c7da8)
  • RpcServerInterfaceGroupCreateW (Address: 0x1800c7d90)
  • RpcServerInterfaceGroupDeactivate (Address: 0x1800c7da0)
  • RpcServerSubscribeForNotification (Address: 0x1800c7df8)
  • RpcServerUnsubscribeForNotification (Address: 0x1800c7e08)
  • RpcStringBindingParseW (Address: 0x1800c7dc0)
  • RpcStringFreeW (Address: 0x1800c7d70)
  • UuidCreate (Address: 0x1800c7d80)
  • UuidFromStringW (Address: 0x1800c7d78)
  • UuidToStringW (Address: 0x1800c7d88)
SYSNTFY.dll
  • SysNotifyStartServer (Address: 0x1800c7e18)
  • SysNotifyStopServer (Address: 0x1800c7e20)
UMPDC.dll
  • Pdcv2ActivationClientActivate (Address: 0x1800c7e40)
  • Pdcv2ActivationClientDeactivate (Address: 0x1800c7e38)
  • Pdcv2ActivationClientRegister (Address: 0x1800c7e50)
  • Pdcv2ActivationClientRenewActivation (Address: 0x1800c7e30)
  • Pdcv2ActivationClientUnregister (Address: 0x1800c7e48)