dingtalk_elf.dll
Description: dingtalk_elf Module
Authors: Alibaba software (Shanghai) Corporation. All rights reserved.
Version: 1.0.0.1
Architecture: 64-bit
Operating System: Windows
SHA256: 21067031ef0b5d0a43dfd01ef0ffd815
File Size: 213.6 KB
Uploaded At: Dec. 2, 2025, 2:41 p.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory, OpenProcess
Exported Functions
- ??0DingTalkProtect@dt_protect@@QEAA@XZ (Ordinal: 1, Address: 0x6730)
- ??1DingTalkProtect@dt_protect@@QEAA@XZ (Ordinal: 2, Address: 0x1b540)
- ??4DingTalkProtect@dt_protect@@QEAAAEAV01@AEBV01@@Z (Ordinal: 3, Address: 0x6730)
- ?ClearAntiThreadReasonList@DingTalkProtect@dt_protect@@SAXXZ (Ordinal: 4, Address: 0x1b550)
- ?ClearDebugDeniedFile@DingTalkProtect@dt_protect@@SAXXZ (Ordinal: 5, Address: 0x1b570)
- ?ClearDebugProtectCostTimeList@DingTalkProtect@dt_protect@@SAXXZ (Ordinal: 6, Address: 0x1b590)
- ?ClearDutterGPUCrashCount@DingTalkProtect@dt_protect@@SAXXZ (Ordinal: 7, Address: 0x1b5b0)
- ?ClearThirdPartyCrashPath@DingTalkProtect@dt_protect@@SAXXZ (Ordinal: 8, Address: 0x1b5d0)
- ?Execute@DingTalkProtect@dt_protect@@SA_NXZ (Ordinal: 9, Address: 0x1b5f0)
- ?ExecuteV2@DingTalkProtect@dt_protect@@SA_NXZ (Ordinal: 10, Address: 0x1b630)
- ?GetAndCleanConflictingFile@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 11, Address: 0x1b670)
- ?GetAndClearThirdPartyCrashPath@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 12, Address: 0x1b6c0)
- ?GetAntiThreadReasonList@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 13, Address: 0x1b710)
- ?GetBlackList@DingTalkProtect@dt_protect@@SA?AV?$vector@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V?$allocator@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@std@@XZ (Ordinal: 14, Address: 0x1b740)
- ?GetBlockModuleList@DingTalkProtect@dt_protect@@SA?AV?$list@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@V?$allocator@V?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@2@@std@@XZ (Ordinal: 15, Address: 0x1b770)
- ?GetDebugDeniedFile@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 16, Address: 0x1b7a0)
- ?GetDebugProtectCostTimeList@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 17, Address: 0x1b7d0)
- ?GetDebugProtectDeniedInfo@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 18, Address: 0x1b800)
- ?GetDebugProtectEnable@DingTalkProtect@dt_protect@@SA_NXZ (Ordinal: 19, Address: 0x1b830)
- ?GetDenyList@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 20, Address: 0x1b850)
- ?GetDllCheckResult@DingTalkProtect@dt_protect@@SA?AW4ModuleType@@AEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z (Ordinal: 21, Address: 0x1b880)
- ?GetDutterGPUCrashCount@DingTalkProtect@dt_protect@@SAHXZ (Ordinal: 22, Address: 0x1b8b0)
- ?GetForceOpenDebugProtectSwitch@DingTalkProtect@dt_protect@@SA_NXZ (Ordinal: 23, Address: 0x1b8d0)
- ?GetGrayDenyList@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 24, Address: 0x1b8f0)
- ?GetLocalDenyList@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 25, Address: 0x1b920)
- ?GetManualOperateDebugProtect@DingTalkProtect@dt_protect@@SA_NXZ (Ordinal: 26, Address: 0x1b950)
- ?GetSubjectDenyList@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 27, Address: 0x1b970)
- ?GetThirdPartyCrashPath@DingTalkProtect@dt_protect@@SA?AV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@XZ (Ordinal: 28, Address: 0x1b9a0)
- ?IsLaunchAppInDebugMode@DingTalkProtect@dt_protect@@SA_NXZ (Ordinal: 29, Address: 0x1b9d0)
- ?ManualOperateDebugProtect@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 30, Address: 0x1b9f0)
- ?SetAntiInjectRepairIAT@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 31, Address: 0x1ba10)
- ?SetAntiRemoteThreadEnable@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 32, Address: 0x1ba30)
- ?SetBlackList@DingTalkProtect@dt_protect@@SAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z (Ordinal: 33, Address: 0x1ba50)
- ?SetConflictModuleDetectCallback@DingTalkProtect@dt_protect@@SAXV?$function@$$A6AXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z@std@@@Z (Ordinal: 34, Address: 0x1ba70)
- ?SetDebugProtectEnable@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 35, Address: 0x1bb00)
- ?SetDutterGPUCrashCount@DingTalkProtect@dt_protect@@SAXH@Z (Ordinal: 36, Address: 0x1bb20)
- ?SetEnableSafeMode@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 37, Address: 0x1bb40)
- ?SetEncryptBlackListSwitch@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 38, Address: 0x1bb60)
- ?SetFixAntiInjectCrashSwitch@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 39, Address: 0x1bb80)
- ?SetFixAntiThreadCrashSwitch@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 40, Address: 0x1bba0)
- ?SetFixHookFailedSwitch@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 41, Address: 0x1bbc0)
- ?SetForceOpenDebugProtectSwitch@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 42, Address: 0x1bbe0)
- ?SetGrayDenyList@DingTalkProtect@dt_protect@@SAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z (Ordinal: 43, Address: 0x1bc00)
- ?SetLaunchStatus@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 44, Address: 0x1bc20)
- ?SetLocalDenyList@DingTalkProtect@dt_protect@@SAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z (Ordinal: 45, Address: 0x1bc40)
- ?SetSubjectDenyList@DingTalkProtect@dt_protect@@SAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z (Ordinal: 46, Address: 0x1bc60)
- ?SetSwitchV4@DingTalkProtect@dt_protect@@SAX_N@Z (Ordinal: 47, Address: 0x1bc80)
- ?SetThirdPartyCrashPath@DingTalkProtect@dt_protect@@SAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z (Ordinal: 48, Address: 0x1bca0)
- ?SetWhiteList@DingTalkProtect@dt_protect@@SAXAEBV?$basic_string@_WU?$char_traits@_W@std@@V?$allocator@_W@2@@std@@@Z (Ordinal: 49, Address: 0x1bcc0)
Imported DLLs & Functions
api-ms-win-crt-convert-l1-1-0.dll
- _wtol (Address: 0x180020588)
- wcstol (Address: 0x180020590)
api-ms-win-crt-environment-l1-1-0.dll
- _wputenv_s (Address: 0x1800205a0)
api-ms-win-crt-filesystem-l1-1-0.dll
- _lock_file (Address: 0x1800205b8)
- _unlock_file (Address: 0x1800205b0)
api-ms-win-crt-heap-l1-1-0.dll
- _callnewh (Address: 0x1800205d0)
- _recalloc (Address: 0x1800205d8)
- calloc (Address: 0x1800205e0)
- free (Address: 0x1800205e8)
- malloc (Address: 0x1800205c8)
api-ms-win-crt-math-l1-1-0.dll
- ceilf (Address: 0x1800205f8)
api-ms-win-crt-runtime-l1-1-0.dll
- _beginthreadex (Address: 0x180020610)
- _cexit (Address: 0x180020678)
- _configure_narrow_argv (Address: 0x180020648)
- _crt_atexit (Address: 0x180020638)
- _errno (Address: 0x180020628)
- _execute_onexit_table (Address: 0x180020668)
- _initialize_narrow_environment (Address: 0x180020650)
- _initialize_onexit_table (Address: 0x180020658)
- _initterm (Address: 0x180020640)
- _initterm_e (Address: 0x180020608)
- _invalid_parameter_noinfo (Address: 0x180020630)
- _invalid_parameter_noinfo_noreturn (Address: 0x180020620)
- _register_onexit_function (Address: 0x180020660)
- _seh_filter_dll (Address: 0x180020670)
- terminate (Address: 0x180020618)
api-ms-win-crt-stdio-l1-1-0.dll
- __stdio_common_vsnwprintf_s (Address: 0x1800206a0)
- __stdio_common_vswprintf_s (Address: 0x1800206a8)
- _fseeki64 (Address: 0x180020708)
- _get_stream_buffer_pointers (Address: 0x180020688)
- fclose (Address: 0x180020690)
- fflush (Address: 0x180020698)
- fgetc (Address: 0x180020700)
- fgetpos (Address: 0x1800206f8)
- fgetwc (Address: 0x1800206d0)
- fputc (Address: 0x1800206f0)
- fputwc (Address: 0x1800206c8)
- fread (Address: 0x1800206e8)
- fsetpos (Address: 0x1800206e0)
- fwrite (Address: 0x1800206d8)
- setvbuf (Address: 0x1800206c0)
- ungetc (Address: 0x1800206b8)
- ungetwc (Address: 0x1800206b0)
api-ms-win-crt-string-l1-1-0.dll
- _wcsicmp (Address: 0x180020740)
- strnlen (Address: 0x180020738)
- tolower (Address: 0x180020728)
- towlower (Address: 0x180020720)
- wcsnlen (Address: 0x180020730)
- wmemcpy_s (Address: 0x180020718)
KERNEL32.dll
- CloseHandle (Address: 0x180020000)
- ContinueDebugEvent (Address: 0x180020108)
- CopyFileW (Address: 0x1800201d8)
- CreateEventW (Address: 0x180020268)
- CreateFileMappingW (Address: 0x1800200b0)
- CreateFileW (Address: 0x1800200e0)
- DebugActiveProcessStop (Address: 0x180020118)
- DeleteCriticalSection (Address: 0x180020210)
- EnterCriticalSection (Address: 0x180020158)
- FindResourceExW (Address: 0x180020190)
- FindResourceW (Address: 0x1800201b8)
- FlushInstructionCache (Address: 0x180020080)
- GetCommandLineW (Address: 0x1800200d0)
- GetCurrentProcess (Address: 0x180020050)
- GetCurrentProcessId (Address: 0x180020168)
- GetCurrentThread (Address: 0x180020058)
- GetCurrentThreadId (Address: 0x180020060)
- GetFileAttributesW (Address: 0x1800200e8)
- GetFileSize (Address: 0x1800200a8)
- GetLastError (Address: 0x180020008)
- GetModuleFileNameW (Address: 0x180020198)
- GetModuleHandleW (Address: 0x1800200c0)
- GetPrivateProfileStringW (Address: 0x1800201c8)
- GetProcAddress (Address: 0x1800200c8)
- GetProcessHeap (Address: 0x180020148)
- GetProcessId (Address: 0x180020178)
- GetSystemDefaultLangID (Address: 0x1800201f8)
- GetSystemTimeAsFileTime (Address: 0x180020228)
- GetThreadContext (Address: 0x180020070)
- GetTickCount (Address: 0x180020180)
- GetUserDefaultLangID (Address: 0x1800201f0)
- HeapAlloc (Address: 0x180020128)
- HeapDestroy (Address: 0x180020120)
- HeapFree (Address: 0x180020138)
- HeapReAlloc (Address: 0x180020130)
- HeapSize (Address: 0x180020140)
- InitializeCriticalSection (Address: 0x180020150)
- InitializeCriticalSectionAndSpinCount (Address: 0x180020208)
- InitializeSListHead (Address: 0x180020220)
- IsDebuggerPresent (Address: 0x1800200f8)
- IsProcessorFeaturePresent (Address: 0x180020238)
- LeaveCriticalSection (Address: 0x180020160)
- LoadLibraryW (Address: 0x1800201c0)
- LoadResource (Address: 0x1800201a0)
- LocalFree (Address: 0x180020280)
- LockResource (Address: 0x1800201a8)
- MapViewOfFile (Address: 0x180020188)
- MultiByteToWideChar (Address: 0x1800201e0)
- OpenProcess (Address: 0x180020028)
- OutputDebugStringW (Address: 0x180020100)
- QueryPerformanceCounter (Address: 0x180020230)
- RaiseException (Address: 0x180020200)
- ReadFile (Address: 0x1800200f0)
- ReadProcessMemory (Address: 0x180020040)
- ResetEvent (Address: 0x180020278)
- ResumeThread (Address: 0x180020020)
- RtlCaptureContext (Address: 0x180020260)
- RtlLookupFunctionEntry (Address: 0x180020258)
- RtlVirtualUnwind (Address: 0x180020250)
- SetEnvironmentVariableW (Address: 0x1800200d8)
- SetEvent (Address: 0x180020218)
- SetLastError (Address: 0x180020010)
- SetThreadContext (Address: 0x180020078)
- SetUnhandledExceptionFilter (Address: 0x180020240)
- SizeofResource (Address: 0x1800201b0)
- SuspendThread (Address: 0x180020068)
- TerminateProcess (Address: 0x180020018)
- TerminateThread (Address: 0x180020170)
- UnhandledExceptionFilter (Address: 0x180020248)
- UnmapViewOfFile (Address: 0x1800200b8)
- VirtualAlloc (Address: 0x180020088)
- VirtualFree (Address: 0x180020098)
- VirtualProtect (Address: 0x180020090)
- VirtualProtectEx (Address: 0x180020030)
- VirtualQuery (Address: 0x1800200a0)
- VirtualQueryEx (Address: 0x180020038)
- WaitForDebugEvent (Address: 0x180020110)
- WaitForSingleObjectEx (Address: 0x180020270)
- WideCharToMultiByte (Address: 0x1800201e8)
- WritePrivateProfileStringW (Address: 0x1800201d0)
- WriteProcessMemory (Address: 0x180020048)
MSVCP140.dll
- _Cnd_broadcast (Address: 0x180020308)
- _Cnd_destroy_in_situ (Address: 0x1800202f8)
- _Cnd_do_broadcast_at_thread_exit (Address: 0x180020310)
- _Cnd_init_in_situ (Address: 0x1800202f0)
- _Cnd_wait (Address: 0x180020300)
- _Mtx_destroy_in_situ (Address: 0x1800202d8)
- _Mtx_init_in_situ (Address: 0x1800202d0)
- _Mtx_lock (Address: 0x1800202e0)
- _Mtx_unlock (Address: 0x1800202e8)
- ?_Fiopen@std@@YAPEAU_iobuf@@PEB_WHH@Z (Address: 0x180020480)
- ?_Getcat@?$codecvt@_WDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z (Address: 0x180020358)
- ?_Getcat@?$codecvt@DDU_Mbstatet@@@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z (Address: 0x180020378)
- ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ (Address: 0x180020330)
- ?_Init@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAXXZ (Address: 0x1800203d8)
- ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ (Address: 0x1800203a0)
- ?_Pninc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAAPEA_WXZ (Address: 0x1800203d0)
- ?_Pninc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ (Address: 0x180020398)
- ?_Throw_C_error@std@@YAXH@Z (Address: 0x180020318)
- ?_Throw_Cpp_error@std@@YAXH@Z (Address: 0x180020320)
- ?_Xbad_function_call@std@@YAXXZ (Address: 0x180020478)
- ?_Xinvalid_argument@std@@YAXPEBD@Z (Address: 0x1800202b8)
- ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800202c0)
- ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800202c8)
- ??0_Lockit@std@@QEAA@H@Z (Address: 0x1800202a8)
- ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IEAA@XZ (Address: 0x180020418)
- ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ (Address: 0x180020400)
- ??0?$basic_iostream@_WU?$char_traits@_W@std@@@std@@QEAA@PEAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@@Z (Address: 0x180020468)
- ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z (Address: 0x180020438)
- ??0?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z (Address: 0x180020420)
- ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IEAA@XZ (Address: 0x1800203b8)
- ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ (Address: 0x180020380)
- ??1_Lockit@std@@QEAA@XZ (Address: 0x1800202b0)
- ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UEAA@XZ (Address: 0x180020408)
- ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x1800203f0)
- ??1?$basic_iostream@_WU?$char_traits@_W@std@@@std@@UEAA@XZ (Address: 0x180020470)
- ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x180020440)
- ??1?$basic_ostream@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x180020428)
- ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UEAA@XZ (Address: 0x1800203c0)
- ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x180020388)
- ??Bid@locale@std@@QEAA_KXZ (Address: 0x180020328)
- ?always_noconv@codecvt_base@std@@QEBA_NXZ (Address: 0x180020338)
- ?getline@?$basic_istream@_WU?$char_traits@_W@std@@@std@@QEAAAEAV12@PEA_W_J@Z (Address: 0x180020460)
- ?getloc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QEBA?AVlocale@2@XZ (Address: 0x1800203c8)
- ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ (Address: 0x180020390)
- ?id@?$codecvt@_WDU_Mbstatet@@@std@@2V0locale@2@A (Address: 0x180020298)
- ?id@?$codecvt@DDU_Mbstatet@@@std@@2V0locale@2@A (Address: 0x180020290)
- ?in@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEA_W3AEAPEA_W@Z (Address: 0x180020340)
- ?in@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z (Address: 0x180020360)
- ?out@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEB_W1AEAPEB_WPEAD3AEAPEAD@Z (Address: 0x180020348)
- ?out@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAD3AEAPEAD@Z (Address: 0x180020368)
- ?read@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEAD_J@Z (Address: 0x180020448)
- ?seekg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@_JH@Z (Address: 0x180020450)
- ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QEAAXH_N@Z (Address: 0x180020410)
- ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z (Address: 0x1800203f8)
- ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JXZ (Address: 0x1800202a0)
- ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ (Address: 0x180020488)
- ?tellg@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA?AV?$fpos@U_Mbstatet@@@2@XZ (Address: 0x180020458)
- ?unshift@?$codecvt@_WDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z (Address: 0x180020350)
- ?unshift@?$codecvt@DDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z (Address: 0x180020370)
- ?write@?$basic_ostream@DU?$char_traits@D@std@@@std@@QEAAAEAV12@PEBD_J@Z (Address: 0x180020430)
- ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEA_W_J@Z (Address: 0x1800203e0)
- ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z (Address: 0x1800203a8)
- ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MEAA_JPEB_W_J@Z (Address: 0x1800203e8)
- ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z (Address: 0x1800203b0)
OLEAUT32.dll
- SysAllocString (Address: 0x180020498)
- SysFreeString (Address: 0x1800204a0)
- VariantClear (Address: 0x1800204a8)
PSAPI.DLL
- GetMappedFileNameW (Address: 0x1800204c8)
- GetModuleBaseNameW (Address: 0x1800204c0)
- GetModuleFileNameExW (Address: 0x1800204b8)
SHELL32.dll
- SHCreateDirectoryExW (Address: 0x1800204d8)
- SHGetFolderPathW (Address: 0x1800204e0)
SHLWAPI.dll
- PathFileExistsW (Address: 0x1800204f0)
USER32.dll
- MessageBoxW (Address: 0x180020500)
VCRUNTIME140_1.dll
- __CxxFrameHandler4 (Address: 0x180020578)
VCRUNTIME140.dll
- __C_specific_handler (Address: 0x180020558)
- __std_exception_copy (Address: 0x180020510)
- __std_exception_destroy (Address: 0x180020518)
- __std_terminate (Address: 0x180020548)
- __std_type_info_destroy_list (Address: 0x180020530)
- _CxxThrowException (Address: 0x180020520)
- memcmp (Address: 0x180020528)
- memcpy (Address: 0x180020560)
- memmove (Address: 0x180020538)
- memset (Address: 0x180020550)
- wcsrchr (Address: 0x180020568)
- wcsstr (Address: 0x180020540)