lsasrv.dll

Description: LSA Server DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6456

Architecture: 64-bit

Operating System: Windows NT

SHA256: 875f6725c5203b0ff4c038110242e522

File Size: 1.6 MB

Uploaded At: Dec. 1, 2025, 7:32 a.m.

Views: 8

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • InitializeLsaExtension (Ordinal: 1, Address: 0x51170)
  • QueryLsaInterface (Ordinal: 2, Address: 0x72df0)
  • IsTraceLevelEnabled (Ordinal: 3, Address: 0xfe9f0)
  • LsaDbLookupSidChainRequest (Ordinal: 4, Address: 0xff3f0)
  • LsaIAddNamesToLogonSession (Ordinal: 5, Address: 0x18d70)
  • LsaIAdjustTokenObjectIntegrity (Ordinal: 6, Address: 0x1ecd0)
  • LsaIAdtAuditingEnabledByCategory (Ordinal: 7, Address: 0x6c4f0)
  • LsaIAdtAuditingEnabledBySubCategory (Ordinal: 8, Address: 0xe2a20)
  • LsaIAllocateHeap (Ordinal: 9, Address: 0x4be30)
  • LsaIAllocateHeapZero (Ordinal: 10, Address: 0x3c370)
  • LsaIAllowProtectedCredLogon (Ordinal: 11, Address: 0xcdc20)
  • LsaIAuditAccountLogon (Ordinal: 12, Address: 0xe2b10)
  • LsaIAuditAccountLogonEx (Ordinal: 13, Address: 0x19d30)
  • LsaIAuditInitializeParametersAndWriteEvent (Ordinal: 14, Address: 0xe2ef0)
  • LsaIAuditKdcEvent (Ordinal: 15, Address: 0xe2fc0)
  • LsaIAuditKerberosLogon (Ordinal: 16, Address: 0xe33a0)
  • LsaIAuditLogonEx (Ordinal: 17, Address: 0x4c180)
  • LsaIAuditLogonUsingExplicitCreds (Ordinal: 18, Address: 0x1b150)
  • LsaIAuditNotifyPackageLoad (Ordinal: 19, Address: 0x72910)
  • LsaIAuditPasswordAccessEvent (Ordinal: 20, Address: 0xe3440)
  • LsaIAuditReplay (Ordinal: 21, Address: 0xe3630)
  • LsaIAuditSamEvent (Ordinal: 22, Address: 0x2e6c0)
  • LsaICallPackage (Ordinal: 23, Address: 0xd22f0)
  • LsaICallPackageEx (Ordinal: 24, Address: 0x43280)
  • LsaICallPackagePassthrough (Ordinal: 25, Address: 0xd2330)
  • LsaICancelNotification (Ordinal: 26, Address: 0x47ba0)
  • LsaIChangeSecretCipherKey (Ordinal: 27, Address: 0x100e90)
  • LsaICheckProtectedUserByTokenInfo (Ordinal: 28, Address: 0x18cd0)
  • LsaICheckRestrictedMode (Ordinal: 29, Address: 0xe4fb0)
  • LsaIClearOldSyskey (Ordinal: 30, Address: 0x100f50)
  • LsaICryptProtectData (Ordinal: 31, Address: 0x48c80)
  • LsaICryptProtectDataEx (Ordinal: 32, Address: 0xca1c0)
  • LsaICryptUnprotectData (Ordinal: 33, Address: 0x485c0)
  • LsaICryptUnprotectDataEx (Ordinal: 34, Address: 0xca270)
  • LsaIDereferenceCredHandle (Ordinal: 35, Address: 0xd1300)
  • LsaIDeriveCredentialKey (Ordinal: 36, Address: 0xca320)
  • LsaIDsNotifiedObjectChange (Ordinal: 37, Address: 0x1016a0)
  • LsaIEfsAcceptSmartcardCredentials (Ordinal: 38, Address: 0xc2630)
  • LsaIEqualLogonProcessName (Ordinal: 39, Address: 0xd2460)
  • LsaIEqualSupplementalTokenInfo (Ordinal: 40, Address: 0x44c0)
  • LsaIEventWritePackageNoCredential (Ordinal: 41, Address: 0xc6680)
  • LsaIEventWritePackageNotCacheLogonUser (Ordinal: 42, Address: 0x30520)
  • LsaIExtractTargetInfo (Ordinal: 43, Address: 0x79a10)
  • LsaIFilterInboundNamespace (Ordinal: 44, Address: 0x7d2b0)
  • LsaIFilterNamespace (Ordinal: 45, Address: 0x101740)
  • LsaIFilterSids (Ordinal: 46, Address: 0x102780)
  • LsaIFlushIdentityCacheForSid (Ordinal: 47, Address: 0xe4fd0)
  • LsaIForestTrustFindMatch (Ordinal: 48, Address: 0x1017d0)
  • LsaIFreeFilterInboundNamespaceResult (Ordinal: 49, Address: 0x7d340)
  • LsaIFreeForestTrustInfo (Ordinal: 50, Address: 0x101830)
  • LsaIFreeHeap (Ordinal: 51, Address: 0x2f2f0)
  • LsaIFreeReturnBuffer (Ordinal: 52, Address: 0x43210)
  • LsaIFreeSupplementalTokenInfo (Ordinal: 53, Address: 0x47d30)
  • LsaIFree_LSAI_PRIVATE_DATA (Ordinal: 54, Address: 0xe52f0)
  • LsaIFree_LSAI_SECRET_ENUM_BUFFER (Ordinal: 55, Address: 0xe5320)
  • LsaIFree_LSAPR_ACCOUNT_ENUM_BUFFER (Ordinal: 56, Address: 0xe5390)
  • LsaIFree_LSAPR_CR_CIPHER_VALUE (Ordinal: 57, Address: 0x3d0d0)
  • LsaIFree_LSAPR_POLICY_DOMAIN_INFORMATION (Ordinal: 58, Address: 0xe53b0)
  • LsaIFree_LSAPR_POLICY_INFORMATION (Ordinal: 59, Address: 0x3cf80)
  • LsaIFree_LSAPR_PRIVILEGE_ENUM_BUFFER (Ordinal: 60, Address: 0xe53e0)
  • LsaIFree_LSAPR_PRIVILEGE_SET (Ordinal: 61, Address: 0xe52f0)
  • LsaIFree_LSAPR_REFERENCED_DOMAIN_LIST (Ordinal: 62, Address: 0x4d2e0)
  • LsaIFree_LSAPR_SR_SECURITY_DESCRIPTOR (Ordinal: 63, Address: 0xe5400)
  • LsaIFree_LSAPR_TRANSLATED_NAMES (Ordinal: 64, Address: 0x72160)
  • LsaIFree_LSAPR_TRANSLATED_SIDS (Ordinal: 65, Address: 0xe5440)
  • LsaIFree_LSAPR_TRUSTED_DOMAIN_INFO (Ordinal: 66, Address: 0xe5470)
  • LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER (Ordinal: 67, Address: 0xe54b0)
  • LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER_EX (Ordinal: 68, Address: 0xe54d0)
  • LsaIFree_LSAPR_TRUST_INFORMATION (Ordinal: 69, Address: 0xe54f0)
  • LsaIFree_LSAPR_UNICODE_STRING (Ordinal: 70, Address: 0xe5400)
  • LsaIFree_LSAPR_UNICODE_STRING_BUFFER (Ordinal: 71, Address: 0xe5440)
  • LsaIFree_LSAP_SITENAME_INFO (Ordinal: 72, Address: 0x103440)
  • LsaIFree_LSAP_SITE_INFO (Ordinal: 73, Address: 0x1034a0)
  • LsaIFree_LSAP_SUBNET_INFO (Ordinal: 74, Address: 0x103520)
  • LsaIFree_LSAP_UPN_SUFFIXES (Ordinal: 75, Address: 0x1034a0)
  • LsaIFree_LSA_FOREST_TRUST_COLLISION_INFORMATION (Ordinal: 76, Address: 0x101870)
  • LsaIFree_LSA_FOREST_TRUST_INFORMATION (Ordinal: 77, Address: 0x1018b0)
  • LsaIGetCallInfo (Ordinal: 78, Address: 0x20ba0)
  • LsaIGetCcgClient (Ordinal: 79, Address: 0xb4a00)
  • LsaIGetClientOsInfo (Ordinal: 80, Address: 0x7d350)
  • LsaIGetForestTrustInformation (Ordinal: 81, Address: 0x1018f0)
  • LsaIGetLogonGuid (Ordinal: 82, Address: 0xe3b60)
  • LsaIGetNameFromLuid (Ordinal: 83, Address: 0xc67a0)
  • LsaIGetNbAndDnsDomainNames (Ordinal: 84, Address: 0x46b50)
  • LsaIGetNego2Package (Ordinal: 85, Address: 0x703b0)
  • LsaIGetRemoteCredGuardLogonBuffer (Ordinal: 86, Address: 0xd24c0)
  • LsaIGetRemoteCredGuardSupplementalCreds (Ordinal: 87, Address: 0xd2590)
  • LsaIGetSiteName (Ordinal: 88, Address: 0x101940)
  • LsaIGetSupplementalTokenInfo (Ordinal: 89, Address: 0x45400)
  • LsaIGetTokenInformationForLocalUser (Ordinal: 90, Address: 0xe4ff0)
  • LsaIHealthCheck (Ordinal: 91, Address: 0x715a0)
  • LsaIImpersonateClient (Ordinal: 92, Address: 0x48f00)
  • LsaIInitializeNetlogonFuncPtrs (Ordinal: 93, Address: 0xe5520)
  • LsaIIsContainerized (Ordinal: 94, Address: 0xb4a10)
  • LsaIIsDomainWithinForest (Ordinal: 95, Address: 0x101990)
  • LsaIIsDsPaused (Ordinal: 96, Address: 0x101a30)
  • LsaIIsInEmulatedDomainJoinMode (Ordinal: 97, Address: 0x48bb0)
  • LsaIIsLastInteractiveLogonInfoEnabled (Ordinal: 98, Address: 0x48fc0)
  • LsaIIsLocalHost (Ordinal: 99, Address: 0xceb80)
  • LsaIIsMachineSecureByDefault (Ordinal: 100, Address: 0xe5540)
  • LsaIIsSuppressChannelBindingInfo (Ordinal: 101, Address: 0xcf8e0)
  • LsaIIsTargetPrivate (Ordinal: 102, Address: 0xd44a0)
  • LsaIIsTrustedDomainsEnabled (Ordinal: 103, Address: 0x101a70)
  • LsaIIsUserMSA (Ordinal: 104, Address: 0xe5000)
  • LsaIKerberosRegisterTrustNotification (Ordinal: 105, Address: 0x101a80)
  • LsaILookupUserAccountType (Ordinal: 106, Address: 0x489d0)
  • LsaILookupWellKnownName (Ordinal: 107, Address: 0x103710)
  • LsaIModifyPerformanceCounter (Ordinal: 108, Address: 0x3be50)
  • LsaINoConnectedUserPolicy (Ordinal: 109, Address: 0x46e70)
  • LsaINoMoreWin2KDomain (Ordinal: 110, Address: 0x48e70)
  • LsaINotifyChangeNotification (Ordinal: 111, Address: 0x104950)
  • LsaINotifyGCStatusChange (Ordinal: 112, Address: 0x101ad0)
  • LsaINotifyNetlogonParametersChangeW (Ordinal: 113, Address: 0x1035d0)
  • LsaINotifyNewPassword (Ordinal: 114, Address: 0xbf9d0)
  • LsaINotifyPasswordChanged (Ordinal: 115, Address: 0xbf9e0)
  • LsaIOpenPolicyTrusted (Ordinal: 116, Address: 0x72530)
  • LsaIQueryForestTrustInfo (Ordinal: 117, Address: 0x101b10)
  • LsaIQueryForestTrustInformation (Ordinal: 118, Address: 0x101b70)
  • LsaIQueryInformationPolicyTrusted (Ordinal: 119, Address: 0x48b90)
  • LsaIQueryPackageAttrInLogonSession (Ordinal: 120, Address: 0x45350)
  • LsaIQuerySiteInfo (Ordinal: 121, Address: 0x101ba0)
  • LsaIQuerySubnetInfo (Ordinal: 122, Address: 0x101bf0)
  • LsaIQueryUpnSuffixes (Ordinal: 123, Address: 0x101c40)
  • LsaIReferenceCredHandle (Ordinal: 124, Address: 0xd1340)
  • LsaIRegisterLogonSessionCallback (Ordinal: 125, Address: 0x48ea0)
  • LsaIRegisterNotification (Ordinal: 126, Address: 0x5b970)
  • LsaIRegisterPolicyChangeNotificationCallback (Ordinal: 127, Address: 0x6b590)
  • LsaIRenewCertificate (Ordinal: 128, Address: 0xe5020)
  • LsaIReplicateClientObject (Ordinal: 129, Address: 0x101c90)
  • LsaIRetrieveCurrentUserSid (Ordinal: 130, Address: 0x3d4f0)
  • LsaISafeMode (Ordinal: 131, Address: 0x56550)
  • LsaISamIndicatedDsStarted (Ordinal: 132, Address: 0x101cf0)
  • LsaISanitizeSAMName (Ordinal: 133, Address: 0xe5040)
  • LsaISetClientDnsHostName (Ordinal: 134, Address: 0x101d40)
  • LsaISetLogonGuidInLogonSession (Ordinal: 135, Address: 0xc6900)
  • LsaISetLogonInfo (Ordinal: 136, Address: 0x47980)
  • LsaISetNewSyskey (Ordinal: 137, Address: 0x100fa0)
  • LsaISetPackageAttrInLogonSession (Ordinal: 138, Address: 0xc6af0)
  • LsaISetSupplementalTokenInfo (Ordinal: 139, Address: 0x4be60)
  • LsaISetTokenDacl (Ordinal: 140, Address: 0xe55b0)
  • LsaISetUserFlags (Ordinal: 141, Address: 0x44ba0)
  • LsaITransformAuthorizationData (Ordinal: 142, Address: 0x1068e0)
  • LsaIUnregisterAllPolicyChangeNotificationCallback (Ordinal: 143, Address: 0x104a00)
  • LsaIUnregisterLogonSessionCallback (Ordinal: 144, Address: 0xc6ba0)
  • LsaIUnregisterPolicyChangeNotificationCallback (Ordinal: 145, Address: 0x104b70)
  • LsaIUpdateForestTrustInformation (Ordinal: 146, Address: 0x101de0)
  • LsaIUpdateKerbMaxTokenSize (Ordinal: 147, Address: 0xcebc0)
  • LsaIUpdateLogonSession (Ordinal: 148, Address: 0x2a30)
  • LsaIValidateTargetInfo (Ordinal: 149, Address: 0xd2650)
  • LsaIVerifyCachability (Ordinal: 150, Address: 0x101e50)
  • LsaIVerifyCachabilityEx (Ordinal: 151, Address: 0x7d3d0)
  • LsaIWasLogonNotifiedOfProfileLoad (Ordinal: 152, Address: 0x7b130)
  • LsaIWriteAuditEvent (Ordinal: 153, Address: 0xe3cb0)
  • LsaIWriteKdcAuthenticationEvent (Ordinal: 154, Address: 0xe3d70)
  • LsaLookupPerfCounterAddAmount (Ordinal: 155, Address: 0x7b6b0)
  • LsaLookupPerfCounterAddLargeAmount (Ordinal: 156, Address: 0x7b720)
  • LsaLookupPerfCounterDecrementCount (Ordinal: 157, Address: 0x7b790)
  • LsaLookupPerfCounterDecrementLargeCount (Ordinal: 158, Address: 0x7b800)
  • LsaLookupPerfCounterIncrementCount (Ordinal: 159, Address: 0x7b870)
  • LsaLookupPerfCounterIncrementLargeCount (Ordinal: 160, Address: 0x7b8e0)
  • LsapAdtAuditingEnabledByLogonId (Ordinal: 161, Address: 0x1e1f0)
  • LsapAdtAuditingEnabledBySubCategory (Ordinal: 162, Address: 0x1e2b0)
  • LsapAdtAuditingEnabledHint (Ordinal: 163, Address: 0xe6ac0)
  • LsapAdtGetCallerProcessInfo (Ordinal: 164, Address: 0x30f80)
  • LsapAdtInitParametersArray (Ordinal: 165, Address: 0x1ae70)
  • LsapAdtWriteLog (Ordinal: 166, Address: 0x4b2b0)
  • LsapAllocateLsaHeap (Ordinal: 167, Address: 0x3c370)
  • LsapAllocatePrivateHeap (Ordinal: 168, Address: 0x3c370)
  • LsapAuOpenSam (Ordinal: 169, Address: 0x525e0)
  • LsapAuditFailed (Ordinal: 170, Address: 0xe7250)
  • LsapBuildPrivilegeAuditString (Ordinal: 171, Address: 0x106a90)
  • LsapCheckBootMode (Ordinal: 172, Address: 0x51830)
  • LsapCloseHandle (Ordinal: 173, Address: 0x44730)
  • LsapCompareDomainNames (Ordinal: 174, Address: 0x5410)
  • LsapCrServerGetSessionKey (Ordinal: 175, Address: 0x4eab0)
  • LsapCrServerGetSessionKeySafe (Ordinal: 176, Address: 0xe8670)
  • LsapDbAcquireLockEx (Ordinal: 177, Address: 0x12760)
  • LsapDbApplyTransaction (Ordinal: 178, Address: 0x444c0)
  • LsapDbBuildObjectCaches (Ordinal: 179, Address: 0x558c0)
  • LsapDbCloseHandle (Ordinal: 180, Address: 0x1088c0)
  • LsapDbCloseObject (Ordinal: 181, Address: 0x44820)
  • LsapDbCopyUnicodeAttribute (Ordinal: 182, Address: 0x56310)
  • LsapDbCopyUnicodeAttributeNoAlloc (Ordinal: 183, Address: 0x109ec0)
  • LsapDbCreateObject (Ordinal: 184, Address: 0x108b40)
  • LsapDbDeleteAttributesObject (Ordinal: 185, Address: 0x109040)
  • LsapDbDeleteObject (Ordinal: 186, Address: 0x1090e0)
  • LsapDbDereferenceHandle (Ordinal: 187, Address: 0x13270)
  • LsapDbDereferenceObject (Ordinal: 188, Address: 0x11fa0)
  • LsapDbEnumerateSids (Ordinal: 189, Address: 0x56c10)
  • LsapDbEnumerateTrustedDomainsEx (Ordinal: 190, Address: 0x10acc0)
  • LsapDbExpAcquireReadLockTrustedDomainList (Ordinal: 191, Address: 0x10b8a0)
  • LsapDbExpAcquireWriteLockTrustedDomainList (Ordinal: 192, Address: 0x10b8d0)
  • LsapDbExpConvertReadLockTrustedDomainListToExclusive (Ordinal: 193, Address: 0x10b900)
  • LsapDbExpConvertWriteLockTrustedDomainListToShared (Ordinal: 194, Address: 0x10b920)
  • LsapDbExpIsCacheBuilding (Ordinal: 195, Address: 0x10b940)
  • LsapDbExpIsCacheValid (Ordinal: 196, Address: 0x10b960)
  • LsapDbExpIsLockedTrustedDomainList (Ordinal: 197, Address: 0x10b980)
  • LsapDbExpMakeCacheBuilding (Ordinal: 198, Address: 0x10b9d0)
  • LsapDbExpMakeCacheInvalid (Ordinal: 199, Address: 0x10b9f0)
  • LsapDbExpMakeCacheValid (Ordinal: 200, Address: 0x10ba10)
  • LsapDbExpReleaseLockTrustedDomainList (Ordinal: 201, Address: 0x10ba30)
  • LsapDbFreeAttributes (Ordinal: 202, Address: 0x54f90)
  • LsapDbFreeTrustedDomainsEx (Ordinal: 203, Address: 0x10ae70)
  • LsapDbGetDbObjectTypeName (Ordinal: 204, Address: 0x10ba50)
  • LsapDbGetDbPolicyHandle (Ordinal: 205, Address: 0x10ba70)
  • LsapDbGetSecretType (Ordinal: 206, Address: 0x44530)
  • LsapDbInitializeAttribute (Ordinal: 207, Address: 0x4e110)
  • LsapDbIsStatusConnectionFailure (Ordinal: 208, Address: 0xff900)
  • LsapDbLookupAddListReferencedDomains (Ordinal: 209, Address: 0xbd80)
  • LsapDbLookupCreateListReferencedDomains (Ordinal: 210, Address: 0xff930)
  • LsapDbLookupGetDomainInfo (Ordinal: 211, Address: 0x46530)
  • LsapDbLookupListReferencedDomains (Ordinal: 212, Address: 0x5790)
  • LsapDbLookupMergeDisjointReferencedDomains (Ordinal: 213, Address: 0xfff50)
  • LsapDbLookupNameChainRequest (Ordinal: 214, Address: 0x1001f0)
  • LsapDbLookupNamesInPrimaryDomain (Ordinal: 215, Address: 0x103c40)
  • LsapDbLookupSidsInPrimaryDomain (Ordinal: 216, Address: 0x10a650)
  • LsapDbMakeGuidAttribute (Ordinal: 217, Address: 0x109f30)
  • LsapDbMakeSidAttribute (Ordinal: 218, Address: 0x109f90)
  • LsapDbMakeUnicodeAttribute (Ordinal: 219, Address: 0x10a020)
  • LsapDbOpenObject (Ordinal: 220, Address: 0x10750)
  • LsapDbQueryInformationPolicy (Ordinal: 221, Address: 0xddb0)
  • LsapDbReadAttribute (Ordinal: 222, Address: 0x550e0)
  • LsapDbReadAttributesObject (Ordinal: 223, Address: 0x4dfc0)
  • LsapDbReferenceObject (Ordinal: 224, Address: 0x13710)
  • LsapDbReleaseLockEx (Ordinal: 225, Address: 0x105f0)
  • LsapDbSecretIsMachineAcc (Ordinal: 226, Address: 0x10bbc0)
  • LsapDbSidToLogicalNameObject (Ordinal: 227, Address: 0x44470)
  • LsapDbSlowEnumerateTrustedDomains (Ordinal: 228, Address: 0x10b010)
  • LsapDbUpdateCountCompUnmappedNames (Ordinal: 229, Address: 0x1041e0)
  • LsapDbVerifyHandle (Ordinal: 230, Address: 0x138f0)
  • LsapDbVerifyInfoQueryTrustedDomain (Ordinal: 231, Address: 0x10ba80)
  • LsapDbVerifyInfoSetTrustedDomain (Ordinal: 232, Address: 0x10baa0)
  • LsapDbWriteAttributesObject (Ordinal: 233, Address: 0x1094a0)
  • LsapDomainRenameHandlerForLogonSessions (Ordinal: 234, Address: 0xc82b0)
  • LsapDsInitializeDsStateInfo (Ordinal: 235, Address: 0x101e80)
  • LsapDsUnitializeDsStateInfo (Ordinal: 236, Address: 0x101ec0)
  • LsapDssetupInitializeGetPrimaryDomainInformationOpState (Ordinal: 237, Address: 0xe5550)
  • LsapDuplicateSid (Ordinal: 238, Address: 0x18770)
  • LsapDuplicateString (Ordinal: 239, Address: 0x17ec0)
  • LsapFreeLsaHeap (Ordinal: 240, Address: 0x2f2f0)
  • LsapFreePrivateHeap (Ordinal: 241, Address: 0x2f2f0)
  • LsapFreeString (Ordinal: 242, Address: 0x18480)
  • LsapGetAccountDomainHandle (Ordinal: 243, Address: 0x10bac0)
  • LsapGetCapeNamesForCap (Ordinal: 244, Address: 0xe8850)
  • LsapGetGlobalRestrictAnonymous (Ordinal: 245, Address: 0x10bad0)
  • LsapGetHourlyLogLevel (Ordinal: 246, Address: 0x10bae0)
  • LsapGetLogonSessionAccountInfoEx (Ordinal: 247, Address: 0x17430)
  • LsapGetLookupRestrictIsolatedNameLevel (Ordinal: 248, Address: 0x100950)
  • LsapGetPolicyHandle (Ordinal: 249, Address: 0x10baf0)
  • LsapGetWellKnownSid (Ordinal: 250, Address: 0x10bb10)
  • LsapInitLsa (Ordinal: 251, Address: 0x5cf40)
  • LsapInitializeLsaDb (Ordinal: 252, Address: 0x10bb30)
  • LsapIsBuiltinDomain (Ordinal: 253, Address: 0x100960)
  • LsapIsSamOpened (Ordinal: 254, Address: 0x10bbb0)
  • LsapOpenSam (Ordinal: 255, Address: 0xe55a0)
  • LsapQueryClientInfo (Ordinal: 256, Address: 0x2f320)
  • LsapRemoveTrailingDot (Ordinal: 257, Address: 0xb3640)
  • LsapRpcCopySid (Ordinal: 258, Address: 0x56b0)
  • LsapRpcCopyUnicodeString (Ordinal: 259, Address: 0x4790)
  • LsapRtlValidateControllerTrustedDomain (Ordinal: 260, Address: 0x1009a0)
  • LsapRtlValidateControllerTrustedDomainByHandle (Ordinal: 261, Address: 0x100b40)
  • LsapSetErrorInfo (Ordinal: 262, Address: 0xca4b0)
  • LsapSidListSize (Ordinal: 263, Address: 0xe7550)
  • LsapTraceEvent (Ordinal: 264, Address: 0x44860)
  • LsapTraceEventWithData (Ordinal: 265, Address: 0x11f30)
  • LsapTruncateUnicodeString (Ordinal: 266, Address: 0xb3680)
  • LsarClose (Ordinal: 267, Address: 0x11d00)
  • LsarCreateSecret (Ordinal: 268, Address: 0x10c500)
  • LsarDeleteObject (Ordinal: 269, Address: 0x1068a0)
  • LsarEnumerateTrustedDomainsEx (Ordinal: 270, Address: 0x10b270)
  • LsarLookupSids (Ordinal: 271, Address: 0x4d3b0)
  • LsarOpenPolicy (Ordinal: 272, Address: 0x105c50)
  • LsarOpenSecret (Ordinal: 273, Address: 0x43de0)
  • LsarQueryDomainInformationPolicy (Ordinal: 274, Address: 0x10cf20)
  • LsarQueryInformationPolicy (Ordinal: 275, Address: 0x128e0)
  • LsarQuerySecret (Ordinal: 276, Address: 0x4d970)
  • LsarQueryTrustedDomainInfoByName (Ordinal: 277, Address: 0x10b3e0)
  • LsarRetrievePrivateData (Ordinal: 278, Address: 0x10def0)
  • LsarSetInformationPolicy (Ordinal: 279, Address: 0x106010)
  • LsarSetSecret (Ordinal: 280, Address: 0x10c7f0)
  • LsarSetTrustedDomainInfoByName (Ordinal: 281, Address: 0x10b6a0)
  • LsarStorePrivateData (Ordinal: 282, Address: 0x10dfa0)
  • ServiceInit (Ordinal: 283, Address: 0x516f0)
  • SpmpEventWrite (Ordinal: 284, Address: 0x32bb0)
  • TracePrint (Ordinal: 285, Address: 0x9c10)
  • TracePrintCallerInformation (Ordinal: 286, Address: 0xfee70)
  • _fgs__LSAPR_TRUSTED_DOMAIN_FULL_INFORMATION2 (Ordinal: 287, Address: 0xe9ae0)
  • _fgs__LSAPR_TRUSTED_DOMAIN_INFORMATION_EX2 (Ordinal: 288, Address: 0xe9b60)
  • _fgs__LSAPR_TRUSTED_ENUM_BUFFER (Ordinal: 289, Address: 0x4d310)
  • _fgs__LSAPR_TRUSTED_ENUM_BUFFER_EX (Ordinal: 290, Address: 0xe9bc0)
  • _fgs__LSAPR_TRUST_INFORMATION (Ordinal: 291, Address: 0x4d370)
  • _fgu__LSAPR_TRUSTED_DOMAIN_INFO (Ordinal: 292, Address: 0xe9c80)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18014cdb8)
api-ms-win-core-console-l1-1-0.dll
  • SetConsoleCtrlHandler (Address: 0x18014cdc8)
api-ms-win-core-datetime-l1-1-0.dll
  • GetDateFormatW (Address: 0x18014cdd8)
  • GetTimeFormatW (Address: 0x18014cde0)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18014cdf8)
  • IsDebuggerPresent (Address: 0x18014ce08)
  • OutputDebugStringA (Address: 0x18014cdf0)
  • OutputDebugStringW (Address: 0x18014ce00)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18014ce18)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18014ce28)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18014ce58)
  • RaiseException (Address: 0x18014ce48)
  • SetLastError (Address: 0x18014ce50)
  • SetUnhandledExceptionFilter (Address: 0x18014ce38)
  • UnhandledExceptionFilter (Address: 0x18014ce40)
api-ms-win-core-errorhandling-l1-1-2.dll
  • RaiseFailFastException (Address: 0x18014ce68)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18014ced0)
  • CreateDirectoryW (Address: 0x18014cec0)
  • CreateFileW (Address: 0x18014cea8)
  • DeleteFileW (Address: 0x18014ce98)
  • FileTimeToLocalFileTime (Address: 0x18014cf08)
  • FindClose (Address: 0x18014cee8)
  • FindCloseChangeNotification (Address: 0x18014cec8)
  • FindFirstChangeNotificationW (Address: 0x18014ced8)
  • FindFirstFileExW (Address: 0x18014cee0)
  • FindFirstFileW (Address: 0x18014ce80)
  • FindNextChangeNotification (Address: 0x18014ceb8)
  • FindNextFileW (Address: 0x18014ce78)
  • GetFileSize (Address: 0x18014cf00)
  • GetFileSizeEx (Address: 0x18014cef8)
  • GetFileType (Address: 0x18014cea0)
  • ReadFile (Address: 0x18014ce88)
  • SetFileAttributesW (Address: 0x18014ceb0)
  • SetFilePointer (Address: 0x18014cef0)
  • WriteFile (Address: 0x18014ce90)
api-ms-win-core-file-l2-1-0.dll
  • MoveFileExW (Address: 0x18014cf20)
  • ReadDirectoryChangesW (Address: 0x18014cf18)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18014cf30)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18014cf58)
  • HeapAlloc (Address: 0x18014cf40)
  • HeapFree (Address: 0x18014cf50)
  • HeapSetInformation (Address: 0x18014cf48)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18014cf70)
  • LocalFree (Address: 0x18014cf68)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x18014cf80)
api-ms-win-core-io-l1-1-0.dll
  • GetOverlappedResult (Address: 0x18014cf90)
api-ms-win-core-io-l1-1-1.dll
  • CancelIo (Address: 0x18014cfa0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • DnsHostnameToComputerNameW (Address: 0x18014cfc0)
  • MoveFileW (Address: 0x18014cfb0)
  • WTSGetActiveConsoleSessionId (Address: 0x18014cfb8)
api-ms-win-core-kernel32-private-l1-1-0.dll
  • CheckElevationEnabled (Address: 0x18014cfd0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18014cfe0)
  • FreeLibrary (Address: 0x18014d010)
  • GetModuleFileNameA (Address: 0x18014cff8)
  • GetModuleFileNameW (Address: 0x18014d020)
  • GetModuleHandleExW (Address: 0x18014cfe8)
  • GetModuleHandleW (Address: 0x18014cff0)
  • GetProcAddress (Address: 0x18014d008)
  • LoadLibraryExA (Address: 0x18014d018)
  • LoadLibraryExW (Address: 0x18014d000)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18014d030)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x18014d040)
  • VirtualFree (Address: 0x18014d058)
  • VirtualProtect (Address: 0x18014d050)
  • VirtualQuery (Address: 0x18014d048)
api-ms-win-core-memory-l1-1-1.dll
  • VirtualLock (Address: 0x18014d068)
api-ms-win-core-perfcounters-l1-1-0.dll
  • PerfCreateInstance (Address: 0x18014d080)
  • PerfSetCounterRefValue (Address: 0x18014d090)
  • PerfSetCounterSetInfo (Address: 0x18014d088)
  • PerfStartProviderEx (Address: 0x18014d098)
  • PerfStopProvider (Address: 0x18014d078)
api-ms-win-core-privateprofile-l1-1-0.dll
  • GetProfileStringA (Address: 0x18014d0a8)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18014d0b8)
  • GetEnvironmentVariableW (Address: 0x18014d0c0)
  • SearchPathW (Address: 0x18014d0c8)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x18014d0d8)
  • GetCurrentProcess (Address: 0x18014d148)
  • GetCurrentProcessId (Address: 0x18014d100)
  • GetCurrentThread (Address: 0x18014d120)
  • GetCurrentThreadId (Address: 0x18014d0f0)
  • GetProcessTimes (Address: 0x18014d110)
  • OpenProcessToken (Address: 0x18014d0e0)
  • OpenThreadToken (Address: 0x18014d138)
  • SetProcessShutdownParameters (Address: 0x18014d108)
  • SetThreadStackGuarantee (Address: 0x18014d0f8)
  • SetThreadToken (Address: 0x18014d140)
  • TerminateProcess (Address: 0x18014d118)
  • TlsAlloc (Address: 0x18014d0e8)
  • TlsGetValue (Address: 0x18014d130)
  • TlsSetValue (Address: 0x18014d128)
api-ms-win-core-processthreads-l1-1-1.dll
  • GetProcessMitigationPolicy (Address: 0x18014d160)
  • IsProcessorFeaturePresent (Address: 0x18014d168)
  • OpenProcess (Address: 0x18014d158)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18014d180)
  • QueryPerformanceFrequency (Address: 0x18014d178)
api-ms-win-core-psapi-l1-1-0.dll
  • QueryFullProcessImageNameW (Address: 0x18014d190)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18014d230)
  • RegCreateKeyExA (Address: 0x18014d1e8)
  • RegCreateKeyExW (Address: 0x18014d248)
  • RegDeleteKeyExA (Address: 0x18014d1c8)
  • RegDeleteKeyExW (Address: 0x18014d238)
  • RegDeleteTreeW (Address: 0x18014d1f8)
  • RegDeleteValueW (Address: 0x18014d1a8)
  • RegEnumKeyExW (Address: 0x18014d200)
  • RegEnumValueW (Address: 0x18014d1a0)
  • RegFlushKey (Address: 0x18014d1d0)
  • RegGetValueW (Address: 0x18014d220)
  • RegLoadKeyW (Address: 0x18014d210)
  • RegNotifyChangeKeyValue (Address: 0x18014d1d8)
  • RegOpenKeyExA (Address: 0x18014d1f0)
  • RegOpenKeyExW (Address: 0x18014d218)
  • RegQueryInfoKeyA (Address: 0x18014d1b8)
  • RegQueryInfoKeyW (Address: 0x18014d1b0)
  • RegQueryValueExA (Address: 0x18014d1e0)
  • RegQueryValueExW (Address: 0x18014d240)
  • RegSetValueExA (Address: 0x18014d1c0)
  • RegSetValueExW (Address: 0x18014d228)
  • RegUnLoadKeyW (Address: 0x18014d208)
api-ms-win-core-registry-l1-1-1.dll
  • RegSetKeyValueW (Address: 0x18014d258)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18014d268)
  • RtlLookupFunctionEntry (Address: 0x18014d270)
  • RtlVirtualUnwind (Address: 0x18014d278)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringW (Address: 0x18014d290)
  • GetStringTypeW (Address: 0x18014d288)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x18014d2a0)
  • lstrlenA (Address: 0x18014d2a8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18014d360)
  • AcquireSRWLockShared (Address: 0x18014d340)
  • CreateEventW (Address: 0x18014d2f0)
  • CreateMutexExW (Address: 0x18014d320)
  • CreateSemaphoreExW (Address: 0x18014d2f8)
  • DeleteCriticalSection (Address: 0x18014d350)
  • EnterCriticalSection (Address: 0x18014d338)
  • InitializeCriticalSection (Address: 0x18014d308)
  • InitializeCriticalSectionEx (Address: 0x18014d310)
  • InitializeSRWLock (Address: 0x18014d2d0)
  • LeaveCriticalSection (Address: 0x18014d318)
  • OpenEventW (Address: 0x18014d348)
  • OpenSemaphoreW (Address: 0x18014d2c0)
  • ReleaseMutex (Address: 0x18014d2d8)
  • ReleaseSemaphore (Address: 0x18014d358)
  • ReleaseSRWLockExclusive (Address: 0x18014d2c8)
  • ReleaseSRWLockShared (Address: 0x18014d2e0)
  • ResetEvent (Address: 0x18014d2b8)
  • SetEvent (Address: 0x18014d328)
  • TryAcquireSRWLockExclusive (Address: 0x18014d300)
  • WaitForSingleObject (Address: 0x18014d2e8)
  • WaitForSingleObjectEx (Address: 0x18014d330)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x18014d370)
  • Sleep (Address: 0x18014d378)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x18014d398)
  • GetLocalTime (Address: 0x18014d3d0)
  • GetSystemDirectoryW (Address: 0x18014d3b0)
  • GetSystemInfo (Address: 0x18014d3a8)
  • GetSystemTime (Address: 0x18014d390)
  • GetSystemTimeAsFileTime (Address: 0x18014d3c0)
  • GetSystemWindowsDirectoryW (Address: 0x18014d3b8)
  • GetTickCount (Address: 0x18014d3a0)
  • GetTickCount64 (Address: 0x18014d3c8)
  • GetWindowsDirectoryW (Address: 0x18014d388)
api-ms-win-core-sysinfo-l1-2-0.dll
  • VerSetConditionMask (Address: 0x18014d3e0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18014d418)
  • CloseThreadpoolWait (Address: 0x18014d400)
  • CreateThreadpoolTimer (Address: 0x18014d408)
  • CreateThreadpoolWait (Address: 0x18014d420)
  • SetThreadpoolTimer (Address: 0x18014d3f0)
  • SetThreadpoolWait (Address: 0x18014d3f8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18014d410)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x18014d440)
  • DeleteTimerQueueTimer (Address: 0x18014d438)
  • QueueUserWorkItem (Address: 0x18014d448)
  • UnregisterWaitEx (Address: 0x18014d430)
api-ms-win-core-threadpool-private-l1-1-0.dll
  • RegisterWaitForSingleObjectEx (Address: 0x18014d458)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x18014d470)
  • SystemTimeToFileTime (Address: 0x18014d468)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x18014d5f8)
  • __CxxFrameHandler3 (Address: 0x18014d568)
  • __CxxFrameHandler4 (Address: 0x18014d578)
  • __std_terminate (Address: 0x18014d570)
  • _CxxThrowException (Address: 0x18014d560)
  • _local_unwind (Address: 0x18014d610)
  • _o___std_exception_copy (Address: 0x18014d5f0)
  • _o___std_exception_destroy (Address: 0x18014d5e8)
  • _o___std_type_info_destroy_list (Address: 0x18014d5e0)
  • _o___stdio_common_vsnprintf_s (Address: 0x18014d5d8)
  • _o___stdio_common_vsnwprintf_s (Address: 0x18014d5d0)
  • _o___stdio_common_vswprintf (Address: 0x18014d5c8)
  • _o___stdio_common_vswprintf_s (Address: 0x18014d5c0)
  • _o___stdio_common_vswscanf (Address: 0x18014d5b8)
  • _o__callnewh (Address: 0x18014d5b0)
  • _o__cexit (Address: 0x18014d5a8)
  • _o__configure_narrow_argv (Address: 0x18014d590)
  • _o__crt_atexit (Address: 0x18014d580)
  • _o__errno (Address: 0x18014d558)
  • _o__execute_onexit_table (Address: 0x18014d550)
  • _o__initialize_narrow_environment (Address: 0x18014d5a0)
  • _o__initialize_onexit_table (Address: 0x18014d598)
  • _o__invalid_parameter_noinfo (Address: 0x18014d588)
  • _o__purecall (Address: 0x18014d480)
  • _o__register_onexit_function (Address: 0x18014d488)
  • _o__seh_filter_dll (Address: 0x18014d490)
  • _o__stricmp (Address: 0x18014d498)
  • _o__ultow (Address: 0x18014d4a0)
  • _o__ultow_s (Address: 0x18014d4a8)
  • _o__wcsicmp (Address: 0x18014d4b0)
  • _o__wcsnicmp (Address: 0x18014d4b8)
  • _o__wsplitpath_s (Address: 0x18014d4c0)
  • _o__wtoi (Address: 0x18014d4c8)
  • _o__wtol (Address: 0x18014d4d0)
  • _o_bsearch_s (Address: 0x18014d4d8)
  • _o_free (Address: 0x18014d4e0)
  • _o_malloc (Address: 0x18014d4f0)
  • _o_mbstowcs (Address: 0x18014d4f8)
  • _o_memcpy_s (Address: 0x18014d500)
  • _o_qsort (Address: 0x18014d508)
  • _o_qsort_s (Address: 0x18014d510)
  • _o_strtok (Address: 0x18014d518)
  • _o_toupper (Address: 0x18014d520)
  • _o_wcscat_s (Address: 0x18014d528)
  • _o_wcscpy_s (Address: 0x18014d530)
  • _o_wcsncat_s (Address: 0x18014d538)
  • _o_wcsncpy_s (Address: 0x18014d540)
  • _o_wcstoul (Address: 0x18014d548)
  • memcmp (Address: 0x18014d618)
  • memcpy (Address: 0x18014d620)
  • memmove (Address: 0x18014d4e8)
  • wcschr (Address: 0x18014d608)
  • wcsrchr (Address: 0x18014d600)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x18014d630)
  • _initterm_e (Address: 0x18014d638)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x18014d648)
  • wcscmp (Address: 0x18014d650)
  • wcsnlen (Address: 0x18014d658)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • TraceMessage (Address: 0x18014d668)
api-ms-win-eventing-controller-l1-1-0.dll
  • ControlTraceW (Address: 0x18014d688)
  • EnableTraceEx2 (Address: 0x18014d678)
  • StartTraceW (Address: 0x18014d680)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x18014d6c0)
  • EventProviderEnabled (Address: 0x18014d6a0)
  • EventRegister (Address: 0x18014d6b8)
  • EventSetInformation (Address: 0x18014d698)
  • EventUnregister (Address: 0x18014d6a8)
  • EventWriteTransfer (Address: 0x18014d6b0)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheck (Address: 0x18014d780)
  • AdjustTokenPrivileges (Address: 0x18014d748)
  • AllocateAndInitializeSid (Address: 0x18014d718)
  • AllocateLocallyUniqueId (Address: 0x18014d708)
  • CheckTokenMembership (Address: 0x18014d7a8)
  • CopySid (Address: 0x18014d740)
  • CreateWellKnownSid (Address: 0x18014d7a0)
  • DuplicateToken (Address: 0x18014d788)
  • DuplicateTokenEx (Address: 0x18014d710)
  • EqualDomainSid (Address: 0x18014d758)
  • FreeSid (Address: 0x18014d700)
  • GetAclInformation (Address: 0x18014d720)
  • GetLengthSid (Address: 0x18014d7b0)
  • GetSidIdentifierAuthority (Address: 0x18014d6f8)
  • GetSidSubAuthority (Address: 0x18014d6e8)
  • GetSidSubAuthorityCount (Address: 0x18014d6f0)
  • GetTokenInformation (Address: 0x18014d6d8)
  • GetWindowsAccountDomainSid (Address: 0x18014d750)
  • ImpersonateLoggedOnUser (Address: 0x18014d798)
  • ImpersonateSelf (Address: 0x18014d778)
  • InitializeSecurityDescriptor (Address: 0x18014d728)
  • IsTokenRestricted (Address: 0x18014d6d0)
  • IsValidSid (Address: 0x18014d770)
  • IsWellKnownSid (Address: 0x18014d6e0)
  • PrivilegeCheck (Address: 0x18014d738)
  • QuerySecurityAccessMask (Address: 0x18014d760)
  • RevertToSelf (Address: 0x18014d7b8)
  • SetSecurityAccessMask (Address: 0x18014d768)
  • SetSecurityDescriptorSacl (Address: 0x18014d730)
  • SetTokenInformation (Address: 0x18014d790)
api-ms-win-security-base-l1-2-0.dll
  • CheckTokenMembershipEx (Address: 0x18014d7c8)
api-ms-win-security-base-private-l1-1-1.dll
  • CreateAppContainerToken (Address: 0x18014d7d8)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x18014d7e8)
api-ms-win-security-grouppolicy-l1-1-0.dll
  • IsSyncForegroundPolicyRefresh (Address: 0x18014d7f8)
api-ms-win-service-core-l1-1-0.dll
  • SetServiceStatus (Address: 0x18014d808)
  • StartServiceCtrlDispatcherW (Address: 0x18014d810)
api-ms-win-service-private-l1-1-0.dll
  • I_QueryTagInformation (Address: 0x18014d828)
  • I_ScIsSecurityProcess (Address: 0x18014d820)
api-ms-win-service-winsvc-l1-1-0.dll
  • RegisterServiceCtrlHandlerW (Address: 0x18014d838)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x18014d848)
MSASN1.dll
  • ASN1_CloseDecoder (Address: 0x18014cad8)
  • ASN1_CloseEncoder (Address: 0x18014cad0)
  • ASN1_CreateDecoder (Address: 0x18014cac8)
  • ASN1_CreateEncoder (Address: 0x18014cac0)
  • ASN1_CreateModule (Address: 0x18014caa8)
  • ASN1_Decode (Address: 0x18014cae0)
  • ASN1_Encode (Address: 0x18014cae8)
  • ASN1_FreeDecoded (Address: 0x18014caf0)
  • ASN1_FreeEncoded (Address: 0x18014caf8)
  • ASN1BERDecBitString (Address: 0x18014ca78)
  • ASN1BERDecEndOfContents (Address: 0x18014ca30)
  • ASN1BERDecExplicitTag (Address: 0x18014ca00)
  • ASN1BERDecNotEndOfContents (Address: 0x18014ca20)
  • ASN1BERDecObjectIdentifier (Address: 0x18014ca80)
  • ASN1BERDecOctetString (Address: 0x18014ca18)
  • ASN1BERDecPeekTag (Address: 0x18014ca08)
  • ASN1BERDecSkip (Address: 0x18014ca58)
  • ASN1BERDecU32Val (Address: 0x18014caa0)
  • ASN1BERDecZeroCharString (Address: 0x18014ca90)
  • ASN1BEREncEndOfContents (Address: 0x18014ca50)
  • ASN1BEREncExplicitTag (Address: 0x18014ca28)
  • ASN1BEREncObjectIdentifier (Address: 0x18014ca88)
  • ASN1BEREncRemoveZeroBits (Address: 0x18014c9f0)
  • ASN1BEREncU32 (Address: 0x18014ca10)
  • ASN1bitstring_free (Address: 0x18014cab0)
  • ASN1DecAlloc (Address: 0x18014ca68)
  • ASN1DecSetError (Address: 0x18014c9f8)
  • ASN1DEREncBitString (Address: 0x18014ca98)
  • ASN1DEREncCharString (Address: 0x18014ca48)
  • ASN1DEREncOctetString (Address: 0x18014ca70)
  • ASN1EncSetError (Address: 0x18014ca40)
  • ASN1Free (Address: 0x18014ca60)
  • ASN1objectidentifier_free (Address: 0x18014ca38)
  • ASN1octetstring_free (Address: 0x18014cb00)
  • ASN1ztcharstring_free (Address: 0x18014cab8)
ntdll.dll
  • _strcmpi (Address: 0x18014dd48)
  • DbgPrint (Address: 0x18014d870)
  • EtwEventActivityIdControl (Address: 0x18014dcf0)
  • EtwEventEnabled (Address: 0x18014d890)
  • EtwEventRegister (Address: 0x18014dde8)
  • EtwEventSetInformation (Address: 0x18014ddf0)
  • EtwEventUnregister (Address: 0x18014dac0)
  • EtwEventWrite (Address: 0x18014dab8)
  • EtwEventWriteTransfer (Address: 0x18014df20)
  • EtwGetTraceEnableFlags (Address: 0x18014ddf8)
  • EtwGetTraceEnableLevel (Address: 0x18014de00)
  • EtwGetTraceLoggerHandle (Address: 0x18014dc80)
  • EtwLogTraceEvent (Address: 0x18014dc78)
  • EtwRegisterSecurityProvider (Address: 0x18014dd60)
  • EtwRegisterTraceGuidsW (Address: 0x18014dc88)
  • EtwTraceMessage (Address: 0x18014dc98)
  • EtwWriteUMSecurityEvent (Address: 0x18014dd68)
  • LdrLoadDll (Address: 0x18014dae8)
  • NtAccessCheck (Address: 0x18014da88)
  • NtAccessCheckAndAuditAlarm (Address: 0x18014da68)
  • NtAccessCheckByTypeAndAuditAlarm (Address: 0x18014db10)
  • NtAdjustPrivilegesToken (Address: 0x18014da30)
  • NtAllocateLocallyUniqueId (Address: 0x18014dea8)
  • NtAllocateVirtualMemory (Address: 0x18014dcb8)
  • NtClose (Address: 0x18014dbe0)
  • NtCloseObjectAuditAlarm (Address: 0x18014db08)
  • NtCommitTransaction (Address: 0x18014d9b0)
  • NtCreateEvent (Address: 0x18014ddc0)
  • NtCreateKey (Address: 0x18014da18)
  • NtCreateKeyTransacted (Address: 0x18014da10)
  • NtCreateSection (Address: 0x18014d8d0)
  • NtCreateToken (Address: 0x18014d8f8)
  • NtCreateTokenEx (Address: 0x18014d910)
  • NtCreateTransaction (Address: 0x18014d9a8)
  • NtDeleteKey (Address: 0x18014da08)
  • NtDeleteObjectAuditAlarm (Address: 0x18014dac8)
  • NtDeleteValueKey (Address: 0x18014da20)
  • NtDuplicateObject (Address: 0x18014dee8)
  • NtDuplicateToken (Address: 0x18014dc48)
  • NtEnumerateKey (Address: 0x18014d9e8)
  • NtEnumerateValueKey (Address: 0x18014d978)
  • NtFilterToken (Address: 0x18014d950)
  • NtFlushKey (Address: 0x18014d928)
  • NtFreeVirtualMemory (Address: 0x18014db60)
  • NtImpersonateAnonymousToken (Address: 0x18014de78)
  • NtLoadKey (Address: 0x18014df58)
  • NtMapViewOfSection (Address: 0x18014d8d8)
  • NtOpenEvent (Address: 0x18014ddb8)
  • NtOpenKey (Address: 0x18014d918)
  • NtOpenKeyTransacted (Address: 0x18014d9f0)
  • NtOpenProcess (Address: 0x18014dcc0)
  • NtOpenProcessToken (Address: 0x18014da38)
  • NtOpenSession (Address: 0x18014db98)
  • NtOpenSymbolicLinkObject (Address: 0x18014dd50)
  • NtOpenThreadToken (Address: 0x18014dc68)
  • NtPrivilegeCheck (Address: 0x18014daf8)
  • NtPrivilegedServiceAuditAlarm (Address: 0x18014d878)
  • NtPrivilegeObjectAuditAlarm (Address: 0x18014d930)
  • NtQueryInformationProcess (Address: 0x18014dcc8)
  • NtQueryInformationToken (Address: 0x18014dc60)
  • NtQueryKey (Address: 0x18014da00)
  • NtQueryObject (Address: 0x18014dab0)
  • NtQuerySymbolicLinkObject (Address: 0x18014dd58)
  • NtQuerySystemInformation (Address: 0x18014dcd0)
  • NtQueryValueKey (Address: 0x18014d9f8)
  • NtRaiseHardError (Address: 0x18014dda8)
  • NtReadVirtualMemory (Address: 0x18014dca8)
  • NtReplyPort (Address: 0x18014d990)
  • NtRollbackTransaction (Address: 0x18014d9b8)
  • NtSetEvent (Address: 0x18014ddb0)
  • NtSetInformationThread (Address: 0x18014dc50)
  • NtSetInformationToken (Address: 0x18014dc40)
  • NtSetSecurityObject (Address: 0x18014d8c0)
  • NtSetValueKey (Address: 0x18014d920)
  • NtShutdownSystem (Address: 0x18014dd20)
  • NtUnloadKey (Address: 0x18014df68)
  • NtWaitForSingleObject (Address: 0x18014d8e0)
  • NtWriteVirtualMemory (Address: 0x18014dcb0)
  • RtlAbortRXact (Address: 0x18014db70)
  • RtlAcquireResourceExclusive (Address: 0x18014dbb8)
  • RtlAcquireResourceShared (Address: 0x18014df70)
  • RtlAcquireSRWLockExclusive (Address: 0x18014dec0)
  • RtlAcquireSRWLockShared (Address: 0x18014dce0)
  • RtlAddAccessAllowedAce (Address: 0x18014de30)
  • RtlAddAce (Address: 0x18014df80)
  • RtlAddActionToRXact (Address: 0x18014db78)
  • RtlAddMandatoryAce (Address: 0x18014d8b0)
  • RtlAdjustPrivilege (Address: 0x18014dd28)
  • RtlAllocateAndInitializeSid (Address: 0x18014ddd8)
  • RtlAllocateHeap (Address: 0x18014d9a0)
  • RtlAnsiStringToUnicodeString (Address: 0x18014df30)
  • RtlAppendUnicodeStringToString (Address: 0x18014daa8)
  • RtlAppendUnicodeToString (Address: 0x18014dcf8)
  • RtlApplyRXact (Address: 0x18014db68)
  • RtlAreAllAccessesGranted (Address: 0x18014db18)
  • RtlAvlInsertNodeEx (Address: 0x18014dd18)
  • RtlAvlRemoveNode (Address: 0x18014dd10)
  • RtlCapabilityCheck (Address: 0x18014d868)
  • RtlCheckTokenCapability (Address: 0x18014d860)
  • RtlCheckTokenMembershipEx (Address: 0x18014de20)
  • RtlCompareUnicodeString (Address: 0x18014dbf8)
  • RtlConvertExclusiveToShared (Address: 0x18014de90)
  • RtlConvertSharedToExclusive (Address: 0x18014de98)
  • RtlConvertSidToUnicodeString (Address: 0x18014dbd8)
  • RtlCopyLuid (Address: 0x18014dea0)
  • RtlCopySid (Address: 0x18014de70)
  • RtlCopyString (Address: 0x18014d980)
  • RtlCopyUnicodeString (Address: 0x18014dbe8)
  • RtlCreateAcl (Address: 0x18014de38)
  • RtlCreateSecurityDescriptor (Address: 0x18014d8a8)
  • RtlCreateServiceSid (Address: 0x18014df18)
  • RtlCreateUnicodeString (Address: 0x18014df48)
  • RtlCreateUnicodeStringFromAsciiz (Address: 0x18014dcd8)
  • RtlDeleteAce (Address: 0x18014da80)
  • RtlDeleteCriticalSection (Address: 0x18014dc00)
  • RtlDeleteElementGenericTableAvl (Address: 0x18014db38)
  • RtlDeleteResource (Address: 0x18014dec8)
  • RtlDosPathNameToRelativeNtPathName_U (Address: 0x18014df50)
  • RtlEnterCriticalSection (Address: 0x18014dc20)
  • RtlEnumerateGenericTableAvl (Address: 0x18014db30)
  • RtlEqualDomainName (Address: 0x18014da90)
  • RtlEqualPrefixSid (Address: 0x18014de18)
  • RtlEqualSid (Address: 0x18014dc10)
  • RtlEqualString (Address: 0x18014d988)
  • RtlEqualUnicodeString (Address: 0x18014dca0)
  • RtlEthernetAddressToStringW (Address: 0x18014dd80)
  • RtlFindAceByType (Address: 0x18014dd90)
  • RtlFindCharInUnicodeString (Address: 0x18014df40)
  • RtlFindMessage (Address: 0x18014dad0)
  • RtlFreeAnsiString (Address: 0x18014df78)
  • RtlFreeHeap (Address: 0x18014da48)
  • RtlFreeSid (Address: 0x18014dd08)
  • RtlFreeUnicodeString (Address: 0x18014dbd0)
  • RtlGetAce (Address: 0x18014da70)
  • RtlGetControlSecurityDescriptor (Address: 0x18014da58)
  • RtlGetCurrentServiceSessionId (Address: 0x18014dc70)
  • RtlGetDaclSecurityDescriptor (Address: 0x18014d9c0)
  • RtlGetDeviceFamilyInfoEnum (Address: 0x18014d8c8)
  • RtlGetLastNtStatus (Address: 0x18014dbf0)
  • RtlGetLastWin32Error (Address: 0x18014de88)
  • RtlGetNtProductType (Address: 0x18014deb0)
  • RtlGetSaclSecurityDescriptor (Address: 0x18014dd88)
  • RtlGetSuiteMask (Address: 0x18014d960)
  • RtlGetThreadPreferredUILanguages (Address: 0x18014dad8)
  • RtlGUIDFromString (Address: 0x18014dbb0)
  • RtlIdentifierAuthoritySid (Address: 0x18014dde0)
  • RtlImageNtHeader (Address: 0x18014dda0)
  • RtlImpersonateSelf (Address: 0x18014d938)
  • RtlImpersonateSelfEx (Address: 0x18014d858)
  • RtlInitAnsiString (Address: 0x18014dbc0)
  • RtlInitializeCriticalSection (Address: 0x18014dc38)
  • RtlInitializeCriticalSectionAndSpinCount (Address: 0x18014dee0)
  • RtlInitializeGenericTableAvl (Address: 0x18014db28)
  • RtlInitializeResource (Address: 0x18014ded0)
  • RtlInitializeRXact (Address: 0x18014daf0)
  • RtlInitializeSid (Address: 0x18014de08)
  • RtlInitializeSRWLock (Address: 0x18014da28)
  • RtlInitString (Address: 0x18014def0)
  • RtlInitUnicodeString (Address: 0x18014dc90)
  • RtlInitUnicodeStringEx (Address: 0x18014dc30)
  • RtlInsertElementGenericTableAvl (Address: 0x18014db48)
  • RtlIntegerToChar (Address: 0x18014df38)
  • RtlIntegerToUnicodeString (Address: 0x18014d9e0)
  • RtlIpv4AddressToStringW (Address: 0x18014dd70)
  • RtlIpv4StringToAddressExW (Address: 0x18014dba0)
  • RtlIpv6AddressToStringW (Address: 0x18014dd78)
  • RtlIpv6StringToAddressExW (Address: 0x18014dba8)
  • RtlIsElevatedRid (Address: 0x18014d948)
  • RtlIsMultiSessionSku (Address: 0x18014def8)
  • RtlIsStateSeparationEnabled (Address: 0x18014ddd0)
  • RtlLeaveCriticalSection (Address: 0x18014dc18)
  • RtlLengthRequiredSid (Address: 0x18014de10)
  • RtlLengthSecurityDescriptor (Address: 0x18014d9d0)
  • RtlLengthSid (Address: 0x18014dc08)
  • RtlLengthSidAsUnicodeString (Address: 0x18014dd30)
  • RtlLookupElementGenericTableAvl (Address: 0x18014db40)
  • RtlMakeSelfRelativeSD (Address: 0x18014d998)
  • RtlMapGenericMask (Address: 0x18014da78)
  • RtlNewSecurityObject (Address: 0x18014da40)
  • RtlNtStatusToDosError (Address: 0x18014dbc8)
  • RtlNumberGenericTableElementsAvl (Address: 0x18014db50)
  • RtlNumberOfSetBitsUlongPtr (Address: 0x18014db58)
  • RtlOwnerAcesPresent (Address: 0x18014d9d8)
  • RtlpConvertAbsoluteToRelativeSecurityAttribute (Address: 0x18014d8e8)
  • RtlpConvertRelativeToAbsoluteSecurityAttribute (Address: 0x18014d8f0)
  • RtlpNtEnumerateSubKey (Address: 0x18014daa0)
  • RtlpNtOpenKey (Address: 0x18014da98)
  • RtlpNtQueryValueKey (Address: 0x18014db20)
  • RtlPrefixUnicodeString (Address: 0x18014de68)
  • RtlPublishWnfStateData (Address: 0x18014d970)
  • RtlQueryInformationAcl (Address: 0x18014d958)
  • RtlQueryTimeZoneInformation (Address: 0x18014dd98)
  • RtlReleaseRelativeName (Address: 0x18014df60)
  • RtlReleaseResource (Address: 0x18014df28)
  • RtlReleaseSRWLockExclusive (Address: 0x18014de50)
  • RtlReleaseSRWLockShared (Address: 0x18014dae0)
  • RtlRunDecodeUnicodeString (Address: 0x18014dd00)
  • RtlSetDaclSecurityDescriptor (Address: 0x18014d900)
  • RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x18014de80)
  • RtlSetOwnerSecurityDescriptor (Address: 0x18014d908)
  • RtlSetSaclSecurityDescriptor (Address: 0x18014d8b8)
  • RtlSetSecurityObject (Address: 0x18014da60)
  • RtlSetSystemBootStatus (Address: 0x18014ddc8)
  • RtlSetThreadPreferredUILanguages (Address: 0x18014df10)
  • RtlSidDominates (Address: 0x18014dc58)
  • RtlSidHashInitialize (Address: 0x18014d898)
  • RtlSidHashLookup (Address: 0x18014d8a0)
  • RtlSizeHeap (Address: 0x18014db90)
  • RtlStartRXact (Address: 0x18014deb8)
  • RtlStringFromGUID (Address: 0x18014db80)
  • RtlSubAuthorityCountSid (Address: 0x18014df00)
  • RtlSubAuthoritySid (Address: 0x18014df08)
  • RtlTestProtectedAccess (Address: 0x18014d880)
  • RtlTimeFieldsToTime (Address: 0x18014de48)
  • RtlTryEnterCriticalSection (Address: 0x18014d940)
  • RtlUnicodeStringToAnsiString (Address: 0x18014df88)
  • RtlUnicodeStringToInteger (Address: 0x18014db00)
  • RtlUpcaseUnicodeStringToOemString (Address: 0x18014dc28)
  • RtlValidRelativeSecurityDescriptor (Address: 0x18014da50)
  • RtlValidSecurityDescriptor (Address: 0x18014d9c8)
  • RtlValidSid (Address: 0x18014d888)
  • RtlVerifyVersionInfo (Address: 0x18014d968)
  • TpAllocTimer (Address: 0x18014ded8)
  • TpIsTimerSet (Address: 0x18014de58)
  • TpReleaseTimer (Address: 0x18014de28)
  • TpSetTimer (Address: 0x18014de60)
  • TpWaitForTimer (Address: 0x18014de40)
  • wcsncmp (Address: 0x18014dd38)
  • wcsstr (Address: 0x18014dd40)
  • WinSqmIncrementDWORD (Address: 0x18014dce8)
  • WinSqmSetString (Address: 0x18014db88)
RPCRT4.dll
  • I_RpcBindingInqClientTokenAttributes (Address: 0x18014cbb8)
  • I_RpcBindingInqLocalClientPID (Address: 0x18014cb58)
  • I_RpcBindingInqTransportType (Address: 0x18014cc08)
  • I_RpcBindingIsClientLocal (Address: 0x18014cc00)
  • I_RpcMapWin32Status (Address: 0x18014cb10)
  • I_RpcOpenClientProcess (Address: 0x18014cbd8)
  • I_RpcOpenClientThread (Address: 0x18014cbd0)
  • MesDecodeIncrementalHandleCreate (Address: 0x18014cba8)
  • MesEncodeIncrementalHandleCreate (Address: 0x18014cb88)
  • MesHandleFree (Address: 0x18014cc50)
  • MesIncrementalHandleReset (Address: 0x18014cbc0)
  • NdrClientCall3 (Address: 0x18014cb28)
  • NdrMesTypeAlignSize3 (Address: 0x18014cbe0)
  • NdrMesTypeDecode3 (Address: 0x18014cbf0)
  • NdrMesTypeEncode3 (Address: 0x18014cbe8)
  • NdrServerCall2 (Address: 0x18014cb70)
  • NdrServerCallAll (Address: 0x18014cb78)
  • RpcBindingFree (Address: 0x18014cb40)
  • RpcBindingFromStringBindingW (Address: 0x18014cb20)
  • RpcBindingInqAuthClientW (Address: 0x18014cc28)
  • RpcBindingInqMaxCalls (Address: 0x18014cb30)
  • RpcBindingServerFromClient (Address: 0x18014cc48)
  • RpcBindingSetAuthInfoW (Address: 0x18014cc38)
  • RpcBindingToStringBindingW (Address: 0x18014cc30)
  • RpcBindingVectorFree (Address: 0x18014cc60)
  • RpcEpRegisterW (Address: 0x18014cc78)
  • RpcExceptionFilter (Address: 0x18014cb48)
  • RpcImpersonateClient (Address: 0x18014cb60)
  • RpcMgmtEnableIdleCleanup (Address: 0x18014cc68)
  • RpcRevertToSelf (Address: 0x18014cb50)
  • RpcRevertToSelfEx (Address: 0x18014cbf8)
  • RpcServerInqBindings (Address: 0x18014cc10)
  • RpcServerInqCallAttributesW (Address: 0x18014cb68)
  • RpcServerInqDefaultPrincNameW (Address: 0x18014cbb0)
  • RpcServerRegisterAuthInfoW (Address: 0x18014cb98)
  • RpcServerRegisterIf (Address: 0x18014cba0)
  • RpcServerRegisterIf2 (Address: 0x18014cb80)
  • RpcServerRegisterIf3 (Address: 0x18014cc70)
  • RpcServerUseProtseqEpW (Address: 0x18014cb90)
  • RpcSsGetContextBinding (Address: 0x18014cc40)
  • RpcStringBindingComposeW (Address: 0x18014cb18)
  • RpcStringBindingParseW (Address: 0x18014cc58)
  • RpcStringFreeW (Address: 0x18014cb38)
  • RpcUserFree (Address: 0x18014cc20)
  • UuidEqual (Address: 0x18014cbc8)
  • UuidFromStringW (Address: 0x18014cc18)
SspiCli.dll
  • CredUnmarshalTargetInfo (Address: 0x18014cd38)
  • LogonUserExExW (Address: 0x18014cce8)
  • LsaCallAuthenticationPackage (Address: 0x18014ccd8)
  • LsaConnectUntrusted (Address: 0x18014cd18)
  • LsaDeregisterLogonProcess (Address: 0x18014cce0)
  • LsaFreeReturnBuffer (Address: 0x18014cd28)
  • LsaLogonUser (Address: 0x18014cd30)
  • LsaLookupAuthenticationPackage (Address: 0x18014ccd0)
  • LsaRegisterLogonProcess (Address: 0x18014ccc8)
  • LsaRegisterPolicyChangeNotification (Address: 0x18014cc98)
  • SecCacheSspiPackages (Address: 0x18014cc88)
  • SeciAllocateAndSetCallFlags (Address: 0x18014cc90)
  • SeciFreeCallContext (Address: 0x18014cca0)
  • SspiCopyAuthIdentity (Address: 0x18014ccb0)
  • SspiDecryptAuthIdentityEx (Address: 0x18014cd10)
  • SspiEncodeStringsAsAuthIdentity (Address: 0x18014ccc0)
  • SspiEncryptAuthIdentityEx (Address: 0x18014ccf8)
  • SspiFreeAuthIdentity (Address: 0x18014ccb8)
  • SspiLocalFree (Address: 0x18014cd00)
  • SspiMarshalAuthIdentity (Address: 0x18014cd08)
  • SspiUnmarshalAuthIdentity (Address: 0x18014cd20)
  • SspiUnmarshalAuthIdentityInternal (Address: 0x18014ccf0)
  • SspiValidateAuthIdentity (Address: 0x18014cca8)
WLDAP32.dll
  • (Address: 0x18014cd48)
  • (Address: 0x18014cd50)
  • (Address: 0x18014cd58)
  • (Address: 0x18014cd60)
  • (Address: 0x18014cd68)
  • (Address: 0x18014cd70)
  • (Address: 0x18014cd78)
  • (Address: 0x18014cd80)
  • (Address: 0x18014cd88)
  • (Address: 0x18014cd90)
  • (Address: 0x18014cd98)
WS2_32.dll
  • ntohl (Address: 0x18014cda8)