keepaliveprovider.dll

Description: Keep alive provider API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 254420df275eef1fa36f629640a7f0b1

File Size: 70.5 KB

Uploaded At: Dec. 1, 2025, 7:31 a.m.

Views: 6

Exported Functions

  • KAMSS_DeregisterProvider (Ordinal: 1, Address: 0xb4e0)
  • KAMSS_RegisterProvider (Ordinal: 2, Address: 0xaf30)

Imported DLLs & Functions

api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18000e768)
  • SetLastError (Address: 0x18000e760)
  • SetUnhandledExceptionFilter (Address: 0x18000e770)
  • UnhandledExceptionFilter (Address: 0x18000e758)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18000e780)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18000e7a0)
  • HeapAlloc (Address: 0x18000e790)
  • HeapFree (Address: 0x18000e798)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18000e7b0)
  • LocalFree (Address: 0x18000e7b8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18000e7e8)
  • FreeLibrary (Address: 0x18000e7c8)
  • GetModuleFileNameW (Address: 0x18000e7e0)
  • GetModuleHandleExW (Address: 0x18000e7d0)
  • GetProcAddress (Address: 0x18000e7d8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18000e808)
  • GetCurrentProcessId (Address: 0x18000e7f8)
  • GetCurrentThreadId (Address: 0x18000e800)
  • TerminateProcess (Address: 0x18000e810)
api-ms-win-core-processthreads-l1-1-1.dll
  • GetProcessMitigationPolicy (Address: 0x18000e820)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18000e830)
api-ms-win-core-synch-l1-1-0.dll
  • CreateEventW (Address: 0x18000e848)
  • WaitForSingleObject (Address: 0x18000e840)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18000e858)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18000e868)
  • GetTickCount (Address: 0x18000e870)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • UnregisterWaitEx (Address: 0x18000e880)
api-ms-win-core-threadpool-private-l1-1-0.dll
  • RegisterWaitForSingleObjectEx (Address: 0x18000e890)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x18000e8c0)
  • GetTraceEnableLevel (Address: 0x18000e8c8)
  • GetTraceLoggerHandle (Address: 0x18000e8b8)
  • RegisterTraceGuidsW (Address: 0x18000e8a0)
  • TraceMessage (Address: 0x18000e8b0)
  • UnregisterTraceGuids (Address: 0x18000e8a8)
api-ms-win-security-base-l1-1-0.dll
  • CreateWellKnownSid (Address: 0x18000e8d8)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000e908)
  • _amsg_exit (Address: 0x18000e918)
  • _initterm (Address: 0x18000e8f8)
  • _XcptFilter (Address: 0x18000e920)
  • free (Address: 0x18000e910)
  • malloc (Address: 0x18000e900)
  • memcpy (Address: 0x18000e8f0)
  • memset (Address: 0x18000e8e8)
  • wcscmp (Address: 0x18000e928)
ntdll.dll
  • RtlCaptureContext (Address: 0x18000e940)
  • RtlLookupFunctionEntry (Address: 0x18000e938)
  • RtlVirtualUnwind (Address: 0x18000e948)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x18000e740)
  • Ndr64AsyncClientCall (Address: 0x18000e6f8)
  • NdrClientCall3 (Address: 0x18000e748)
  • RpcAsyncCancelCall (Address: 0x18000e720)
  • RpcAsyncCompleteCall (Address: 0x18000e728)
  • RpcAsyncInitializeHandle (Address: 0x18000e730)
  • RpcBindingBind (Address: 0x18000e700)
  • RpcBindingCreateW (Address: 0x18000e710)
  • RpcBindingFree (Address: 0x18000e718)
  • RpcBindingSetOption (Address: 0x18000e708)
  • RpcBindingUnbind (Address: 0x18000e738)