dbghelp.dll
Description: Windows Image Helper
Authors: © Microsoft Corporation. All rights reserved.
Version: 6.13.4.983
Architecture: 32-bit
Operating System: Windows NT
SHA256: 250f9e70439e0163c9ad92afacb7597e
File Size: 1.0 MB
Uploaded At: Dec. 2, 2025, 2:44 p.m.
Views: 9
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- SymGetOmapBlockBase (Ordinal: 1, Address: 0x30b33)
- DbgHelpCreateUserDump (Ordinal: 2, Address: 0x3dba1)
- DbgHelpCreateUserDumpW (Ordinal: 3, Address: 0x3dc34)
- EnumDirTree (Ordinal: 4, Address: 0x346a6)
- EnumDirTreeW (Ordinal: 5, Address: 0x3479c)
- EnumerateLoadedModules64 (Ordinal: 6, Address: 0x2ff3d)
- EnumerateLoadedModules (Ordinal: 7, Address: 0x2fec0)
- EnumerateLoadedModulesEx (Ordinal: 8, Address: 0x30037)
- EnumerateLoadedModulesExW (Ordinal: 9, Address: 0x300b4)
- EnumerateLoadedModulesW64 (Ordinal: 10, Address: 0x2ffba)
- ExtensionApiVersion (Ordinal: 11, Address: 0x226b0)
- FindDebugInfoFile (Ordinal: 12, Address: 0x33514)
- FindDebugInfoFileEx (Ordinal: 13, Address: 0x340d8)
- FindDebugInfoFileExW (Ordinal: 14, Address: 0x340a1)
- FindExecutableImage (Ordinal: 15, Address: 0x32998)
- FindExecutableImageEx (Ordinal: 16, Address: 0x332ac)
- FindExecutableImageExW (Ordinal: 17, Address: 0x33391)
- FindFileInPath (Ordinal: 18, Address: 0x3293f)
- FindFileInSearchPath (Ordinal: 19, Address: 0x3296e)
- GetTimestampForLoadedLibrary (Ordinal: 20, Address: 0x27acf)
- ImageDirectoryEntryToData (Ordinal: 21, Address: 0x2778a)
- ImageDirectoryEntryToDataEx (Ordinal: 22, Address: 0x276d5)
- ImageNtHeader (Ordinal: 23, Address: 0x274ea)
- ImageRvaToSection (Ordinal: 24, Address: 0x277ab)
- ImageRvaToVa (Ordinal: 25, Address: 0x27803)
- ImagehlpApiVersion (Ordinal: 26, Address: 0x349fe)
- ImagehlpApiVersionEx (Ordinal: 27, Address: 0x34a09)
- MakeSureDirectoryPathExists (Ordinal: 28, Address: 0x348db)
- MapDebugInformation (Ordinal: 29, Address: 0x31eb6)
- MiniDumpReadDumpStream (Ordinal: 30, Address: 0x46c94)
- MiniDumpWriteDump (Ordinal: 31, Address: 0x46a9d)
- SearchTreeForFile (Ordinal: 32, Address: 0x347dc)
- SearchTreeForFileW (Ordinal: 33, Address: 0x347fe)
- StackWalk64 (Ordinal: 34, Address: 0x42490)
- StackWalk (Ordinal: 35, Address: 0x422d8)
- SymAddSourceStream (Ordinal: 36, Address: 0x2defb)
- SymAddSourceStreamA (Ordinal: 37, Address: 0x2debb)
- SymAddSourceStreamW (Ordinal: 38, Address: 0x2ddb6)
- SymAddSymbol (Ordinal: 39, Address: 0x30705)
- SymAddSymbolW (Ordinal: 40, Address: 0x30656)
- SymCleanup (Ordinal: 41, Address: 0x2c406)
- SymDeleteSymbol (Ordinal: 42, Address: 0x307e6)
- SymDeleteSymbolW (Ordinal: 43, Address: 0x3074b)
- SymEnumLines (Ordinal: 44, Address: 0x2e271)
- SymEnumLinesW (Ordinal: 45, Address: 0x2e2f3)
- SymEnumProcesses (Ordinal: 46, Address: 0x2cf70)
- SymEnumSourceFileTokens (Ordinal: 47, Address: 0x2e0be)
- SymEnumSourceFiles (Ordinal: 48, Address: 0x31a24)
- SymEnumSourceFilesW (Ordinal: 49, Address: 0x31a9f)
- SymEnumSourceLines (Ordinal: 50, Address: 0x2e354)
- SymEnumSourceLinesW (Ordinal: 51, Address: 0x2e3dc)
- SymEnumSym (Ordinal: 52, Address: 0x31302)
- SymEnumSymbols (Ordinal: 53, Address: 0x30b9d)
- SymEnumSymbolsForAddr (Ordinal: 54, Address: 0x3115a)
- SymEnumSymbolsForAddrW (Ordinal: 55, Address: 0x3122c)
- SymEnumSymbolsW (Ordinal: 56, Address: 0x30c0b)
- SymEnumTypes (Ordinal: 57, Address: 0x314ef)
- SymEnumTypesByName (Ordinal: 58, Address: 0x315a6)
- SymEnumTypesByNameW (Ordinal: 59, Address: 0x3164c)
- SymEnumTypesW (Ordinal: 60, Address: 0x31549)
- SymEnumerateModules64 (Ordinal: 61, Address: 0x2d0e0)
- SymEnumerateModules (Ordinal: 62, Address: 0x2d0a0)
- SymEnumerateModulesW64 (Ordinal: 63, Address: 0x2d120)
- SymEnumerateSymbols64 (Ordinal: 64, Address: 0x2d349)
- SymEnumerateSymbols (Ordinal: 65, Address: 0x2d2a3)
- SymEnumerateSymbolsW64 (Ordinal: 66, Address: 0x2d39d)
- SymEnumerateSymbolsW (Ordinal: 67, Address: 0x2d2f6)
- SymFindDebugInfoFile (Ordinal: 68, Address: 0x3419f)
- SymFindDebugInfoFileW (Ordinal: 69, Address: 0x3427b)
- SymFindExecutableImage (Ordinal: 70, Address: 0x333c9)
- SymFindExecutableImageW (Ordinal: 71, Address: 0x334c1)
- SymFindFileInPath (Ordinal: 72, Address: 0x3283c)
- SymFindFileInPathW (Ordinal: 73, Address: 0x328fa)
- SymFromAddr (Ordinal: 74, Address: 0x30829)
- SymFromAddrW (Ordinal: 75, Address: 0x30877)
- SymFromIndex (Ordinal: 76, Address: 0x30fd5)
- SymFromIndexW (Ordinal: 77, Address: 0x31046)
- SymFromName (Ordinal: 78, Address: 0x309fb)
- SymFromNameW (Ordinal: 79, Address: 0x30a5c)
- SymFromToken (Ordinal: 80, Address: 0x308c3)
- SymFromTokenW (Ordinal: 81, Address: 0x30950)
- SymFunctionTableAccess64 (Ordinal: 82, Address: 0x2f068)
- SymFunctionTableAccess (Ordinal: 83, Address: 0x2f047)
- SymGetFileLineOffsets64 (Ordinal: 84, Address: 0x28770)
- SymGetHomeDirectory (Ordinal: 85, Address: 0x2c9e3)
- SymGetHomeDirectoryW (Ordinal: 86, Address: 0x2c95c)
- SymGetLineFromAddr64 (Ordinal: 87, Address: 0x2e443)
- SymGetLineFromAddr (Ordinal: 88, Address: 0x2e60a)
- SymGetLineFromAddrW64 (Ordinal: 89, Address: 0x2e4ec)
- SymGetLineFromName64 (Ordinal: 90, Address: 0x2ea49)
- SymGetLineFromName (Ordinal: 91, Address: 0x2eac5)
- SymGetLineFromNameW64 (Ordinal: 92, Address: 0x2e652)
- SymGetLineNext64 (Ordinal: 93, Address: 0x2ec62)
- SymGetLineNext (Ordinal: 94, Address: 0x2ecd4)
- SymGetLineNextW64 (Ordinal: 95, Address: 0x2ecb9)
- SymGetLinePrev64 (Ordinal: 96, Address: 0x2ed2a)
- SymGetLinePrev (Ordinal: 97, Address: 0x2ed9c)
- SymGetLinePrevW64 (Ordinal: 98, Address: 0x2ed81)
- SymGetModuleBase64 (Ordinal: 99, Address: 0x2f771)
- SymGetModuleBase (Ordinal: 100, Address: 0x2f7e9)
- SymGetModuleInfo64 (Ordinal: 101, Address: 0x2f362)
- SymGetModuleInfo (Ordinal: 102, Address: 0x2f6e5)
- SymGetModuleInfoW64 (Ordinal: 103, Address: 0x2f3e2)
- SymGetModuleInfoW (Ordinal: 104, Address: 0x2f654)
- SymGetOmaps (Ordinal: 105, Address: 0x30a84)
- SymGetOptions (Ordinal: 106, Address: 0x2cba5)
- SymGetScope (Ordinal: 107, Address: 0x30e93)
- SymGetScopeW (Ordinal: 108, Address: 0x30f09)
- SymGetSearchPath (Ordinal: 109, Address: 0x2fb49)
- SymGetSearchPathW (Ordinal: 110, Address: 0x2fb99)
- SymGetSourceFile (Ordinal: 111, Address: 0x2dc3e)
- SymGetSourceFileFromToken (Ordinal: 112, Address: 0x2df25)
- SymGetSourceFileFromTokenW (Ordinal: 113, Address: 0x2df8c)
- SymGetSourceFileToken (Ordinal: 114, Address: 0x2dcfe)
- SymGetSourceFileTokenW (Ordinal: 115, Address: 0x2dd3e)
- SymGetSourceFileW (Ordinal: 116, Address: 0x2dc9e)
- SymGetSourceVarFromToken (Ordinal: 117, Address: 0x2dfd5)
- SymGetSourceVarFromTokenW (Ordinal: 118, Address: 0x2e05d)
- SymGetSymFromAddr64 (Ordinal: 119, Address: 0x2d48a)
- SymGetSymFromAddr (Ordinal: 120, Address: 0x2d4c2)
- SymGetSymFromName64 (Ordinal: 121, Address: 0x2d71a)
- SymGetSymFromName (Ordinal: 122, Address: 0x2d766)
- SymGetSymNext64 (Ordinal: 123, Address: 0x2da07)
- SymGetSymNext (Ordinal: 124, Address: 0x2d8e3)
- SymGetSymPrev64 (Ordinal: 125, Address: 0x2da7f)
- SymGetSymPrev (Ordinal: 126, Address: 0x2da22)
- SymGetSymbolFile (Ordinal: 127, Address: 0x3d737)
- SymGetSymbolFileW (Ordinal: 128, Address: 0x3d335)
- SymGetTypeFromName (Ordinal: 129, Address: 0x316aa)
- SymGetTypeFromNameW (Ordinal: 130, Address: 0x31757)
- SymGetTypeInfo (Ordinal: 131, Address: 0x31cf4)
- SymGetTypeInfoEx (Ordinal: 132, Address: 0x31d31)
- SymGetUnwindInfo (Ordinal: 133, Address: 0x2f1fa)
- SymInitialize (Ordinal: 134, Address: 0x2c28b)
- SymInitializeW (Ordinal: 135, Address: 0x2c0a5)
- SymLoadModule64 (Ordinal: 136, Address: 0x2fa06)
- SymLoadModule (Ordinal: 137, Address: 0x2fa37)
- SymLoadModuleEx (Ordinal: 138, Address: 0x2f904)
- SymLoadModuleExW (Ordinal: 139, Address: 0x2f99b)
- SymMatchFileName (Ordinal: 140, Address: 0x2edf2)
- SymMatchFileNameW (Ordinal: 141, Address: 0x2eea7)
- SymMatchString (Ordinal: 142, Address: 0x318b7)
- SymMatchStringA (Ordinal: 143, Address: 0x318f0)
- SymMatchStringW (Ordinal: 144, Address: 0x31900)
- SymNext (Ordinal: 145, Address: 0x2d7b1)
- SymNextW (Ordinal: 146, Address: 0x2d82f)
- SymPrev (Ordinal: 147, Address: 0x2d84a)
- SymPrevW (Ordinal: 148, Address: 0x2d8c8)
- SymRefreshModuleList (Ordinal: 149, Address: 0x2c027)
- SymRegisterCallback64 (Ordinal: 150, Address: 0x301ab)
- SymRegisterCallback (Ordinal: 151, Address: 0x30131)
- SymRegisterCallbackW64 (Ordinal: 152, Address: 0x30227)
- SymRegisterFunctionEntryCallback64 (Ordinal: 153, Address: 0x2efcf)
- SymRegisterFunctionEntryCallback (Ordinal: 154, Address: 0x2ef59)
- SymSearch (Ordinal: 155, Address: 0x30dc2)
- SymSearchW (Ordinal: 156, Address: 0x30e2d)
- SymSetContext (Ordinal: 157, Address: 0x2cbb0)
- SymSetHomeDirectory (Ordinal: 158, Address: 0x2c8ea)
- SymSetHomeDirectoryW (Ordinal: 159, Address: 0x2c88a)
- SymSetOptions (Ordinal: 160, Address: 0x2ca34)
- SymSetParentWindow (Ordinal: 161, Address: 0x2c45c)
- SymSetScopeFromAddr (Ordinal: 162, Address: 0x2cc09)
- SymSetScopeFromIndex (Ordinal: 163, Address: 0x2cd36)
- SymSetSearchPath (Ordinal: 164, Address: 0x2fc0e)
- SymSetSearchPathW (Ordinal: 165, Address: 0x2fc8d)
- SymSrvDeltaName (Ordinal: 166, Address: 0x3c9fe)
- SymSrvDeltaNameW (Ordinal: 167, Address: 0x3c872)
- SymSrvGetFileIndexInfo (Ordinal: 168, Address: 0x3d8c2)
- SymSrvGetFileIndexInfoW (Ordinal: 169, Address: 0x3d971)
- SymSrvGetFileIndexString (Ordinal: 170, Address: 0x3cf3f)
- SymSrvGetFileIndexStringW (Ordinal: 171, Address: 0x3ce77)
- SymSrvGetFileIndexes (Ordinal: 172, Address: 0x3ce3f)
- SymSrvGetFileIndexesW (Ordinal: 173, Address: 0x3cdb2)
- SymSrvGetSupplement (Ordinal: 174, Address: 0x3cb92)
- SymSrvGetSupplementW (Ordinal: 175, Address: 0x3ca8c)
- SymSrvIsStore (Ordinal: 176, Address: 0x3c843)
- SymSrvIsStoreW (Ordinal: 177, Address: 0x3c786)
- SymSrvStoreFile (Ordinal: 178, Address: 0x3d07a)
- SymSrvStoreFileW (Ordinal: 179, Address: 0x3cfdf)
- SymSrvStoreSupplement (Ordinal: 180, Address: 0x3cd37)
- SymSrvStoreSupplementW (Ordinal: 181, Address: 0x3cc0a)
- SymUnDName64 (Ordinal: 182, Address: 0x2fad6)
- SymUnDName (Ordinal: 183, Address: 0x2fa63)
- SymUnloadModule64 (Ordinal: 184, Address: 0x2f804)
- SymUnloadModule (Ordinal: 185, Address: 0x2f8e4)
- UnDecorateSymbolName (Ordinal: 186, Address: 0x31d91)
- UnDecorateSymbolNameW (Ordinal: 187, Address: 0x31e15)
- UnmapDebugInformation (Ordinal: 188, Address: 0x320c4)
- WinDbgExtensionDllInit (Ordinal: 189, Address: 0x226bb)
- block (Ordinal: 190, Address: 0x241b3)
- chksym (Ordinal: 191, Address: 0x24035)
- dbghelp (Ordinal: 192, Address: 0x2cedd)
- dh (Ordinal: 193, Address: 0x2549a)
- fptr (Ordinal: 194, Address: 0x22841)
- homedir (Ordinal: 195, Address: 0x2448c)
- itoldyouso (Ordinal: 196, Address: 0x23eb7)
- lmi (Ordinal: 197, Address: 0x230e0)
- lminfo (Ordinal: 198, Address: 0x22e7d)
- omap (Ordinal: 199, Address: 0x2431b)
- optdbgdump (Ordinal: 200, Address: 0x266d2)
- srcfiles (Ordinal: 201, Address: 0x245f4)
- stack_force_ebp (Ordinal: 202, Address: 0x22ae3)
- stackdbg (Ordinal: 203, Address: 0x228e4)
- sym (Ordinal: 204, Address: 0x22c92)
- symsrv (Ordinal: 205, Address: 0x22da5)
- vc7fpo (Ordinal: 206, Address: 0x228b6)
Imported DLLs & Functions
KERNEL32.dll
- CloseHandle (Address: 0x300111c)
- CopyFileExW (Address: 0x300101c)
- CreateDirectoryA (Address: 0x30010dc)
- CreateFileA (Address: 0x3001110)
- CreateFileMappingA (Address: 0x30010c8)
- CreateFileMappingW (Address: 0x3001024)
- CreateThread (Address: 0x3001060)
- DelayLoadFailureHook (Address: 0x3001094)
- DeleteCriticalSection (Address: 0x3001144)
- DeviceIoControl (Address: 0x3001014)
- DuplicateHandle (Address: 0x30010cc)
- EnterCriticalSection (Address: 0x3001108)
- FindClose (Address: 0x30010fc)
- FlushViewOfFile (Address: 0x3001004)
- FormatMessageW (Address: 0x3001034)
- FreeLibrary (Address: 0x300112c)
- GetCurrentDirectoryW (Address: 0x3001010)
- GetCurrentProcess (Address: 0x30010e4)
- GetCurrentProcessId (Address: 0x30010bc)
- GetCurrentThreadId (Address: 0x3001088)
- GetFileAttributesA (Address: 0x30010a4)
- GetFileSize (Address: 0x3001114)
- GetFileType (Address: 0x3001018)
- GetLastError (Address: 0x3001100)
- GetModuleHandleA (Address: 0x30010c0)
- GetPriorityClass (Address: 0x3001078)
- GetProcessHeap (Address: 0x3001140)
- GetSystemInfo (Address: 0x3001090)
- GetSystemTimeAsFileTime (Address: 0x30010d8)
- GetThreadContext (Address: 0x300107c)
- GetThreadPriority (Address: 0x3001074)
- GetThreadSelectorEntry (Address: 0x3001058)
- GetThreadTimes (Address: 0x3001070)
- GetTickCount (Address: 0x3001048)
- GetVersion (Address: 0x3001038)
- GetVersionExA (Address: 0x3001138)
- HeapAlloc (Address: 0x30010f0)
- HeapCreate (Address: 0x3001064)
- HeapDestroy (Address: 0x3001068)
- HeapFree (Address: 0x30010ec)
- HeapReAlloc (Address: 0x30010f4)
- InitializeCriticalSection (Address: 0x300113c)
- InitializeCriticalSectionAndSpinCount (Address: 0x300100c)
- InterlockedCompareExchange (Address: 0x300109c)
- InterlockedDecrement (Address: 0x300102c)
- InterlockedExchange (Address: 0x3001054)
- InterlockedIncrement (Address: 0x3001030)
- IsDBCSLeadByte (Address: 0x3001000)
- LeaveCriticalSection (Address: 0x300110c)
- LoadLibraryA (Address: 0x3001128)
- LoadLibraryExA (Address: 0x3001098)
- LoadLibraryExW (Address: 0x3001008)
- LocalAlloc (Address: 0x3001104)
- LocalFree (Address: 0x3001028)
- MapViewOfFile (Address: 0x30010c4)
- MapViewOfFileEx (Address: 0x3001148)
- OpenProcess (Address: 0x30010b8)
- OutputDebugStringA (Address: 0x30010ac)
- QueryPerformanceCounter (Address: 0x300104c)
- ReadFile (Address: 0x3001118)
- ReadProcessMemory (Address: 0x30010a0)
- ResumeThread (Address: 0x3001080)
- RtlUnwind (Address: 0x3001050)
- SetErrorMode (Address: 0x30010a8)
- SetFileAttributesW (Address: 0x3001020)
- SetFilePointer (Address: 0x30010e8)
- SetLastError (Address: 0x30010f8)
- SetUnhandledExceptionFilter (Address: 0x3001040)
- Sleep (Address: 0x300108c)
- SuspendThread (Address: 0x3001084)
- TerminateProcess (Address: 0x300103c)
- TerminateThread (Address: 0x300105c)
- TlsAlloc (Address: 0x3001130)
- TlsFree (Address: 0x3001134)
- TlsGetValue (Address: 0x3001120)
- TlsSetValue (Address: 0x3001124)
- UnhandledExceptionFilter (Address: 0x3001044)
- UnmapViewOfFile (Address: 0x30010e0)
- VirtualAlloc (Address: 0x30010d4)
- VirtualFree (Address: 0x30010b4)
- VirtualProtect (Address: 0x30010d0)
- VirtualQueryEx (Address: 0x300106c)
- WriteFile (Address: 0x30010b0)
msvcrt.dll
- __badioinfo (Address: 0x3001164)
- __CxxFrameHandler (Address: 0x30011b0)
- __dllonexit (Address: 0x3001188)
- __mb_cur_max (Address: 0x30011b8)
- __pioinfo (Address: 0x3001160)
- __unDName (Address: 0x3001254)
- _amsg_exit (Address: 0x30011a4)
- _chsize (Address: 0x3001278)
- _close (Address: 0x300127c)
- _CxxThrowException (Address: 0x300125c)
- _errno (Address: 0x30011bc)
- _fileno (Address: 0x300117c)
- _get_osfhandle (Address: 0x3001280)
- _initterm (Address: 0x30011a0)
- _iob (Address: 0x30011b4)
- _isatty (Address: 0x3001158)
- _ismbblead (Address: 0x300119c)
- _itoa (Address: 0x30011d0)
- _lock (Address: 0x3001190)
- _lseeki64 (Address: 0x3001150)
- _ltoa (Address: 0x30011ec)
- _mbscmp (Address: 0x300128c)
- _memicmp (Address: 0x3001290)
- _onexit (Address: 0x3001184)
- _open_osfhandle (Address: 0x3001284)
- _purecall (Address: 0x30011f4)
- _read (Address: 0x3001168)
- _snprintf (Address: 0x3001174)
- _stricmp (Address: 0x3001208)
- _strlwr (Address: 0x3001210)
- _strnicmp (Address: 0x30011f0)
- _unlock (Address: 0x300118c)
- _vsnwprintf (Address: 0x30011c4)
- _wcsdup (Address: 0x30011d4)
- _wcsicmp (Address: 0x300121c)
- _wcslwr (Address: 0x30011e0)
- _wcsnicmp (Address: 0x3001220)
- _wctime (Address: 0x30011e4)
- _wfsopen (Address: 0x3001268)
- _wfullpath (Address: 0x3001270)
- _wgetenv (Address: 0x3001274)
- _write (Address: 0x3001154)
- _wsopen (Address: 0x3001298)
- _XcptFilter (Address: 0x30011a8)
- ??1type_info@@UAE@XZ (Address: 0x3001294)
- ??2@YAPAXI@Z (Address: 0x300115c)
- ??3@YAXPAX@Z (Address: 0x3001238)
- atol (Address: 0x3001248)
- bsearch (Address: 0x3001258)
- calloc (Address: 0x30011cc)
- ctime (Address: 0x30011f8)
- fclose (Address: 0x300124c)
- ferror (Address: 0x300116c)
- fflush (Address: 0x3001244)
- fprintf (Address: 0x3001240)
- fread (Address: 0x3001260)
- free (Address: 0x300120c)
- fseek (Address: 0x3001264)
- ftell (Address: 0x3001288)
- isleadbyte (Address: 0x3001180)
- isspace (Address: 0x3001204)
- iswdigit (Address: 0x3001250)
- iswprint (Address: 0x300123c)
- iswspace (Address: 0x30011c8)
- iswxdigit (Address: 0x3001228)
- malloc (Address: 0x30011fc)
- mbtowc (Address: 0x3001178)
- memcmp (Address: 0x300129c)
- memcpy (Address: 0x3001198)
- memmove (Address: 0x30011ac)
- memset (Address: 0x3001194)
- qsort (Address: 0x3001224)
- strchr (Address: 0x30011c0)
- strncmp (Address: 0x3001200)
- strstr (Address: 0x3001218)
- time (Address: 0x30011e8)
- tolower (Address: 0x30011dc)
- towlower (Address: 0x30011d8)
- wcschr (Address: 0x3001234)
- wcsncmp (Address: 0x300122c)
- wcsrchr (Address: 0x3001214)
- wcsstr (Address: 0x3001230)
- wcstol (Address: 0x300126c)
- wctomb (Address: 0x3001170)