PenImc_cor3.dll

Description: PenImc

Authors: © Microsoft Corporation. All rights reserved.

Version: 9.0.925.42101

Architecture: 64-bit

Operating System: Windows NT

SHA256: 911141448b5eea97a1d6c5cc10f110de

File Size: 154.3 KB

Uploaded At: Dec. 1, 2025, 2:48 p.m.

Views: 7

Exported Functions

  • CreateResetEvent (Ordinal: 1, Address: 0x80f0)
  • DestroyResetEvent (Ordinal: 2, Address: 0x8140)
  • DllCanUnloadNow (Ordinal: 3, Address: 0x17f0)
  • DllGetClassObject (Ordinal: 4, Address: 0x1830)
  • DllRegisterServer (Ordinal: 5, Address: 0x19c0)
  • DllUnregisterServer (Ordinal: 6, Address: 0x1a70)
  • GetLastSystemEventData (Ordinal: 7, Address: 0x8050)
  • GetPenEvent (Ordinal: 8, Address: 0x7f00)
  • GetPenEventMultiple (Ordinal: 9, Address: 0x7f90)
  • GetProxyDllInfo (Ordinal: 10, Address: 0x1160)
  • LockWispObjectFromGit (Ordinal: 11, Address: 0xd850)
  • RaiseResetEvent (Ordinal: 12, Address: 0x8170)
  • RegisterDllForSxSCOM (Ordinal: 13, Address: 0xd770)
  • UnlockWispObjectFromGit (Ordinal: 14, Address: 0xd890)

Imported DLLs & Functions

ADVAPI32.dll
  • AllocateAndInitializeSid (Address: 0x180017018)
  • ConvertSidToStringSidW (Address: 0x180017000)
  • EqualSid (Address: 0x180017010)
  • FreeSid (Address: 0x180017008)
  • GetTokenInformation (Address: 0x180017020)
  • OpenProcessToken (Address: 0x180017028)
  • RegCloseKey (Address: 0x180017060)
  • RegCreateKeyExW (Address: 0x180017038)
  • RegDeleteKeyW (Address: 0x180017068)
  • RegDeleteValueW (Address: 0x180017030)
  • RegEnumKeyExW (Address: 0x180017050)
  • RegOpenKeyExW (Address: 0x180017048)
  • RegQueryInfoKeyW (Address: 0x180017058)
  • RegSetValueExW (Address: 0x180017040)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x180017438)
  • _recalloc (Address: 0x180017458)
  • calloc (Address: 0x180017450)
  • free (Address: 0x180017448)
  • malloc (Address: 0x180017440)
  • realloc (Address: 0x180017460)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x1800174c0)
  • _configure_narrow_argv (Address: 0x180017478)
  • _crt_atexit (Address: 0x1800174b8)
  • _errno (Address: 0x1800174d0)
  • _execute_onexit_table (Address: 0x1800174b0)
  • _initialize_narrow_environment (Address: 0x180017488)
  • _initialize_onexit_table (Address: 0x1800174a0)
  • _initterm (Address: 0x1800174c8)
  • _initterm_e (Address: 0x1800174d8)
  • _invalid_parameter_noinfo (Address: 0x180017490)
  • _register_onexit_function (Address: 0x1800174a8)
  • _seh_filter_dll (Address: 0x180017470)
  • abort (Address: 0x180017480)
  • terminate (Address: 0x180017498)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vswprintf (Address: 0x1800174e8)
api-ms-win-crt-string-l1-1-0.dll
  • strcmp (Address: 0x180017500)
  • strcpy_s (Address: 0x180017520)
  • strlen (Address: 0x1800174f8)
  • wcscat_s (Address: 0x180017510)
  • wcscpy_s (Address: 0x180017508)
  • wcsncmp (Address: 0x180017518)
  • wcsncpy_s (Address: 0x180017528)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1800171b0)
  • ActivateActCtx (Address: 0x180017168)
  • CancelWaitableTimer (Address: 0x180017158)
  • CloseHandle (Address: 0x180017208)
  • CreateActCtxW (Address: 0x180017160)
  • CreateEventW (Address: 0x1800170d0)
  • CreateMutexW (Address: 0x180017200)
  • CreateThread (Address: 0x180017140)
  • CreateWaitableTimerW (Address: 0x180017268)
  • DecodePointer (Address: 0x180017098)
  • DeleteCriticalSection (Address: 0x180017080)
  • EncodePointer (Address: 0x1800170a0)
  • EnterCriticalSection (Address: 0x1800170a8)
  • FindResourceW (Address: 0x180017220)
  • FreeLibrary (Address: 0x180017260)
  • GetCurrentProcess (Address: 0x180017128)
  • GetCurrentProcessId (Address: 0x1800170d8)
  • GetCurrentThreadId (Address: 0x1800172b0)
  • GetLastError (Address: 0x180017240)
  • GetModuleFileNameW (Address: 0x180017210)
  • GetModuleHandleW (Address: 0x180017250)
  • GetProcAddress (Address: 0x180017258)
  • GetSystemTimeAsFileTime (Address: 0x180017188)
  • GetThreadLocale (Address: 0x180017138)
  • InitializeCriticalSection (Address: 0x1800170c8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180017290)
  • InitializeCriticalSectionEx (Address: 0x180017090)
  • InitializeSListHead (Address: 0x180017180)
  • InterlockedFlushSList (Address: 0x1800171f8)
  • IsDebuggerPresent (Address: 0x180017198)
  • IsProcessorFeaturePresent (Address: 0x1800171c0)
  • IsWow64Process (Address: 0x180017120)
  • LeaveCriticalSection (Address: 0x1800170b0)
  • LoadLibraryExW (Address: 0x180017218)
  • LoadLibraryW (Address: 0x180017178)
  • LoadResource (Address: 0x180017228)
  • LocalFree (Address: 0x180017110)
  • lstrcmpiW (Address: 0x180017248)
  • MapViewOfFile (Address: 0x1800170f8)
  • MultiByteToWideChar (Address: 0x180017238)
  • OpenEventW (Address: 0x1800170e0)
  • OpenFileMappingW (Address: 0x1800170f0)
  • OpenMutexW (Address: 0x1800170e8)
  • OutputDebugStringW (Address: 0x180017130)
  • QueryPerformanceCounter (Address: 0x180017190)
  • QueueUserAPC (Address: 0x180017148)
  • RaiseException (Address: 0x180017088)
  • ReleaseMutex (Address: 0x1800170c0)
  • ReleaseSRWLockExclusive (Address: 0x1800171b8)
  • RtlCaptureContext (Address: 0x1800171e8)
  • RtlLookupFunctionEntry (Address: 0x1800172a8)
  • RtlPcToFileHeader (Address: 0x1800171f0)
  • RtlUnwindEx (Address: 0x1800172a0)
  • RtlVirtualUnwind (Address: 0x1800171e0)
  • SetEvent (Address: 0x180017108)
  • SetLastError (Address: 0x180017298)
  • SetThreadLocale (Address: 0x180017078)
  • SetUnhandledExceptionFilter (Address: 0x1800171d0)
  • SetWaitableTimer (Address: 0x180017150)
  • SignalObjectAndWait (Address: 0x180017118)
  • SizeofResource (Address: 0x180017230)
  • SleepConditionVariableSRW (Address: 0x1800171a0)
  • TerminateProcess (Address: 0x1800171c8)
  • TlsAlloc (Address: 0x180017288)
  • TlsFree (Address: 0x180017270)
  • TlsGetValue (Address: 0x180017280)
  • TlsSetValue (Address: 0x180017278)
  • UnhandledExceptionFilter (Address: 0x1800171d8)
  • UnmapViewOfFile (Address: 0x180017100)
  • VerSetConditionMask (Address: 0x180017170)
  • WaitForSingleObject (Address: 0x1800170b8)
  • WakeAllConditionVariable (Address: 0x1800171a8)
ole32.dll
  • CoCreateInstance (Address: 0x180017550)
  • CoGetApartmentType (Address: 0x180017568)
  • CoLockObjectExternal (Address: 0x180017560)
  • CoTaskMemAlloc (Address: 0x180017540)
  • CoTaskMemFree (Address: 0x180017558)
  • CoTaskMemRealloc (Address: 0x180017538)
  • StringFromGUID2 (Address: 0x180017548)
OLEAUT32.dll
  • LoadTypeLib (Address: 0x1800172f0)
  • RegisterTypeLib (Address: 0x1800172e0)
  • SysAllocString (Address: 0x1800172c0)
  • SysFreeString (Address: 0x1800172d8)
  • SysStringLen (Address: 0x1800172e8)
  • UnRegisterTypeLib (Address: 0x1800172c8)
  • VarUI4FromStr (Address: 0x1800172d0)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x180017370)
  • CStdStubBuffer_Connect (Address: 0x180017308)
  • CStdStubBuffer_CountRefs (Address: 0x180017358)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x180017380)
  • CStdStubBuffer_DebugServerRelease (Address: 0x180017340)
  • CStdStubBuffer_Disconnect (Address: 0x180017328)
  • CStdStubBuffer_Invoke (Address: 0x180017390)
  • CStdStubBuffer_IsIIDSupported (Address: 0x180017318)
  • CStdStubBuffer_QueryInterface (Address: 0x180017350)
  • IUnknown_AddRef_Proxy (Address: 0x180017368)
  • IUnknown_QueryInterface_Proxy (Address: 0x180017320)
  • IUnknown_Release_Proxy (Address: 0x180017388)
  • NdrCStdStubBuffer_Release (Address: 0x180017300)
  • NdrDllCanUnloadNow (Address: 0x180017310)
  • NdrDllGetClassObject (Address: 0x180017330)
  • NdrDllRegisterProxy (Address: 0x180017338)
  • NdrDllUnregisterProxy (Address: 0x180017360)
  • NdrOleAllocate (Address: 0x180017348)
  • NdrOleFree (Address: 0x180017378)
SHELL32.dll
  • ShellExecuteExW (Address: 0x1800173a0)
USER32.dll
  • CallNextHookEx (Address: 0x1800173b8)
  • CharNextW (Address: 0x1800173f8)
  • EqualRect (Address: 0x1800173c8)
  • GetDesktopWindow (Address: 0x180017420)
  • GetMonitorInfoW (Address: 0x180017410)
  • GetParent (Address: 0x1800173e8)
  • GetSystemMetrics (Address: 0x180017408)
  • GetWindow (Address: 0x1800173d0)
  • GetWindowRect (Address: 0x1800173c0)
  • GetWindowThreadProcessId (Address: 0x1800173f0)
  • IsWindow (Address: 0x1800173e0)
  • MonitorFromWindow (Address: 0x180017418)
  • MsgWaitForMultipleObjectsEx (Address: 0x1800173d8)
  • PeekMessageW (Address: 0x180017428)
  • SetWindowsHookExW (Address: 0x1800173b0)
  • UnhookWindowsHookEx (Address: 0x180017400)