lsasrv.dll
Description: LSA Server DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6456
Architecture: 64-bit
Operating System: Windows NT
SHA256: 875f6725c5203b0ff4c038110242e522
File Size: 1.6 MB
Uploaded At: Dec. 1, 2025, 7:32 a.m.
Views: 8
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- InitializeLsaExtension (Ordinal: 1, Address: 0x51170)
- QueryLsaInterface (Ordinal: 2, Address: 0x72df0)
- IsTraceLevelEnabled (Ordinal: 3, Address: 0xfe9f0)
- LsaDbLookupSidChainRequest (Ordinal: 4, Address: 0xff3f0)
- LsaIAddNamesToLogonSession (Ordinal: 5, Address: 0x18d70)
- LsaIAdjustTokenObjectIntegrity (Ordinal: 6, Address: 0x1ecd0)
- LsaIAdtAuditingEnabledByCategory (Ordinal: 7, Address: 0x6c4f0)
- LsaIAdtAuditingEnabledBySubCategory (Ordinal: 8, Address: 0xe2a20)
- LsaIAllocateHeap (Ordinal: 9, Address: 0x4be30)
- LsaIAllocateHeapZero (Ordinal: 10, Address: 0x3c370)
- LsaIAllowProtectedCredLogon (Ordinal: 11, Address: 0xcdc20)
- LsaIAuditAccountLogon (Ordinal: 12, Address: 0xe2b10)
- LsaIAuditAccountLogonEx (Ordinal: 13, Address: 0x19d30)
- LsaIAuditInitializeParametersAndWriteEvent (Ordinal: 14, Address: 0xe2ef0)
- LsaIAuditKdcEvent (Ordinal: 15, Address: 0xe2fc0)
- LsaIAuditKerberosLogon (Ordinal: 16, Address: 0xe33a0)
- LsaIAuditLogonEx (Ordinal: 17, Address: 0x4c180)
- LsaIAuditLogonUsingExplicitCreds (Ordinal: 18, Address: 0x1b150)
- LsaIAuditNotifyPackageLoad (Ordinal: 19, Address: 0x72910)
- LsaIAuditPasswordAccessEvent (Ordinal: 20, Address: 0xe3440)
- LsaIAuditReplay (Ordinal: 21, Address: 0xe3630)
- LsaIAuditSamEvent (Ordinal: 22, Address: 0x2e6c0)
- LsaICallPackage (Ordinal: 23, Address: 0xd22f0)
- LsaICallPackageEx (Ordinal: 24, Address: 0x43280)
- LsaICallPackagePassthrough (Ordinal: 25, Address: 0xd2330)
- LsaICancelNotification (Ordinal: 26, Address: 0x47ba0)
- LsaIChangeSecretCipherKey (Ordinal: 27, Address: 0x100e90)
- LsaICheckProtectedUserByTokenInfo (Ordinal: 28, Address: 0x18cd0)
- LsaICheckRestrictedMode (Ordinal: 29, Address: 0xe4fb0)
- LsaIClearOldSyskey (Ordinal: 30, Address: 0x100f50)
- LsaICryptProtectData (Ordinal: 31, Address: 0x48c80)
- LsaICryptProtectDataEx (Ordinal: 32, Address: 0xca1c0)
- LsaICryptUnprotectData (Ordinal: 33, Address: 0x485c0)
- LsaICryptUnprotectDataEx (Ordinal: 34, Address: 0xca270)
- LsaIDereferenceCredHandle (Ordinal: 35, Address: 0xd1300)
- LsaIDeriveCredentialKey (Ordinal: 36, Address: 0xca320)
- LsaIDsNotifiedObjectChange (Ordinal: 37, Address: 0x1016a0)
- LsaIEfsAcceptSmartcardCredentials (Ordinal: 38, Address: 0xc2630)
- LsaIEqualLogonProcessName (Ordinal: 39, Address: 0xd2460)
- LsaIEqualSupplementalTokenInfo (Ordinal: 40, Address: 0x44c0)
- LsaIEventWritePackageNoCredential (Ordinal: 41, Address: 0xc6680)
- LsaIEventWritePackageNotCacheLogonUser (Ordinal: 42, Address: 0x30520)
- LsaIExtractTargetInfo (Ordinal: 43, Address: 0x79a10)
- LsaIFilterInboundNamespace (Ordinal: 44, Address: 0x7d2b0)
- LsaIFilterNamespace (Ordinal: 45, Address: 0x101740)
- LsaIFilterSids (Ordinal: 46, Address: 0x102780)
- LsaIFlushIdentityCacheForSid (Ordinal: 47, Address: 0xe4fd0)
- LsaIForestTrustFindMatch (Ordinal: 48, Address: 0x1017d0)
- LsaIFreeFilterInboundNamespaceResult (Ordinal: 49, Address: 0x7d340)
- LsaIFreeForestTrustInfo (Ordinal: 50, Address: 0x101830)
- LsaIFreeHeap (Ordinal: 51, Address: 0x2f2f0)
- LsaIFreeReturnBuffer (Ordinal: 52, Address: 0x43210)
- LsaIFreeSupplementalTokenInfo (Ordinal: 53, Address: 0x47d30)
- LsaIFree_LSAI_PRIVATE_DATA (Ordinal: 54, Address: 0xe52f0)
- LsaIFree_LSAI_SECRET_ENUM_BUFFER (Ordinal: 55, Address: 0xe5320)
- LsaIFree_LSAPR_ACCOUNT_ENUM_BUFFER (Ordinal: 56, Address: 0xe5390)
- LsaIFree_LSAPR_CR_CIPHER_VALUE (Ordinal: 57, Address: 0x3d0d0)
- LsaIFree_LSAPR_POLICY_DOMAIN_INFORMATION (Ordinal: 58, Address: 0xe53b0)
- LsaIFree_LSAPR_POLICY_INFORMATION (Ordinal: 59, Address: 0x3cf80)
- LsaIFree_LSAPR_PRIVILEGE_ENUM_BUFFER (Ordinal: 60, Address: 0xe53e0)
- LsaIFree_LSAPR_PRIVILEGE_SET (Ordinal: 61, Address: 0xe52f0)
- LsaIFree_LSAPR_REFERENCED_DOMAIN_LIST (Ordinal: 62, Address: 0x4d2e0)
- LsaIFree_LSAPR_SR_SECURITY_DESCRIPTOR (Ordinal: 63, Address: 0xe5400)
- LsaIFree_LSAPR_TRANSLATED_NAMES (Ordinal: 64, Address: 0x72160)
- LsaIFree_LSAPR_TRANSLATED_SIDS (Ordinal: 65, Address: 0xe5440)
- LsaIFree_LSAPR_TRUSTED_DOMAIN_INFO (Ordinal: 66, Address: 0xe5470)
- LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER (Ordinal: 67, Address: 0xe54b0)
- LsaIFree_LSAPR_TRUSTED_ENUM_BUFFER_EX (Ordinal: 68, Address: 0xe54d0)
- LsaIFree_LSAPR_TRUST_INFORMATION (Ordinal: 69, Address: 0xe54f0)
- LsaIFree_LSAPR_UNICODE_STRING (Ordinal: 70, Address: 0xe5400)
- LsaIFree_LSAPR_UNICODE_STRING_BUFFER (Ordinal: 71, Address: 0xe5440)
- LsaIFree_LSAP_SITENAME_INFO (Ordinal: 72, Address: 0x103440)
- LsaIFree_LSAP_SITE_INFO (Ordinal: 73, Address: 0x1034a0)
- LsaIFree_LSAP_SUBNET_INFO (Ordinal: 74, Address: 0x103520)
- LsaIFree_LSAP_UPN_SUFFIXES (Ordinal: 75, Address: 0x1034a0)
- LsaIFree_LSA_FOREST_TRUST_COLLISION_INFORMATION (Ordinal: 76, Address: 0x101870)
- LsaIFree_LSA_FOREST_TRUST_INFORMATION (Ordinal: 77, Address: 0x1018b0)
- LsaIGetCallInfo (Ordinal: 78, Address: 0x20ba0)
- LsaIGetCcgClient (Ordinal: 79, Address: 0xb4a00)
- LsaIGetClientOsInfo (Ordinal: 80, Address: 0x7d350)
- LsaIGetForestTrustInformation (Ordinal: 81, Address: 0x1018f0)
- LsaIGetLogonGuid (Ordinal: 82, Address: 0xe3b60)
- LsaIGetNameFromLuid (Ordinal: 83, Address: 0xc67a0)
- LsaIGetNbAndDnsDomainNames (Ordinal: 84, Address: 0x46b50)
- LsaIGetNego2Package (Ordinal: 85, Address: 0x703b0)
- LsaIGetRemoteCredGuardLogonBuffer (Ordinal: 86, Address: 0xd24c0)
- LsaIGetRemoteCredGuardSupplementalCreds (Ordinal: 87, Address: 0xd2590)
- LsaIGetSiteName (Ordinal: 88, Address: 0x101940)
- LsaIGetSupplementalTokenInfo (Ordinal: 89, Address: 0x45400)
- LsaIGetTokenInformationForLocalUser (Ordinal: 90, Address: 0xe4ff0)
- LsaIHealthCheck (Ordinal: 91, Address: 0x715a0)
- LsaIImpersonateClient (Ordinal: 92, Address: 0x48f00)
- LsaIInitializeNetlogonFuncPtrs (Ordinal: 93, Address: 0xe5520)
- LsaIIsContainerized (Ordinal: 94, Address: 0xb4a10)
- LsaIIsDomainWithinForest (Ordinal: 95, Address: 0x101990)
- LsaIIsDsPaused (Ordinal: 96, Address: 0x101a30)
- LsaIIsInEmulatedDomainJoinMode (Ordinal: 97, Address: 0x48bb0)
- LsaIIsLastInteractiveLogonInfoEnabled (Ordinal: 98, Address: 0x48fc0)
- LsaIIsLocalHost (Ordinal: 99, Address: 0xceb80)
- LsaIIsMachineSecureByDefault (Ordinal: 100, Address: 0xe5540)
- LsaIIsSuppressChannelBindingInfo (Ordinal: 101, Address: 0xcf8e0)
- LsaIIsTargetPrivate (Ordinal: 102, Address: 0xd44a0)
- LsaIIsTrustedDomainsEnabled (Ordinal: 103, Address: 0x101a70)
- LsaIIsUserMSA (Ordinal: 104, Address: 0xe5000)
- LsaIKerberosRegisterTrustNotification (Ordinal: 105, Address: 0x101a80)
- LsaILookupUserAccountType (Ordinal: 106, Address: 0x489d0)
- LsaILookupWellKnownName (Ordinal: 107, Address: 0x103710)
- LsaIModifyPerformanceCounter (Ordinal: 108, Address: 0x3be50)
- LsaINoConnectedUserPolicy (Ordinal: 109, Address: 0x46e70)
- LsaINoMoreWin2KDomain (Ordinal: 110, Address: 0x48e70)
- LsaINotifyChangeNotification (Ordinal: 111, Address: 0x104950)
- LsaINotifyGCStatusChange (Ordinal: 112, Address: 0x101ad0)
- LsaINotifyNetlogonParametersChangeW (Ordinal: 113, Address: 0x1035d0)
- LsaINotifyNewPassword (Ordinal: 114, Address: 0xbf9d0)
- LsaINotifyPasswordChanged (Ordinal: 115, Address: 0xbf9e0)
- LsaIOpenPolicyTrusted (Ordinal: 116, Address: 0x72530)
- LsaIQueryForestTrustInfo (Ordinal: 117, Address: 0x101b10)
- LsaIQueryForestTrustInformation (Ordinal: 118, Address: 0x101b70)
- LsaIQueryInformationPolicyTrusted (Ordinal: 119, Address: 0x48b90)
- LsaIQueryPackageAttrInLogonSession (Ordinal: 120, Address: 0x45350)
- LsaIQuerySiteInfo (Ordinal: 121, Address: 0x101ba0)
- LsaIQuerySubnetInfo (Ordinal: 122, Address: 0x101bf0)
- LsaIQueryUpnSuffixes (Ordinal: 123, Address: 0x101c40)
- LsaIReferenceCredHandle (Ordinal: 124, Address: 0xd1340)
- LsaIRegisterLogonSessionCallback (Ordinal: 125, Address: 0x48ea0)
- LsaIRegisterNotification (Ordinal: 126, Address: 0x5b970)
- LsaIRegisterPolicyChangeNotificationCallback (Ordinal: 127, Address: 0x6b590)
- LsaIRenewCertificate (Ordinal: 128, Address: 0xe5020)
- LsaIReplicateClientObject (Ordinal: 129, Address: 0x101c90)
- LsaIRetrieveCurrentUserSid (Ordinal: 130, Address: 0x3d4f0)
- LsaISafeMode (Ordinal: 131, Address: 0x56550)
- LsaISamIndicatedDsStarted (Ordinal: 132, Address: 0x101cf0)
- LsaISanitizeSAMName (Ordinal: 133, Address: 0xe5040)
- LsaISetClientDnsHostName (Ordinal: 134, Address: 0x101d40)
- LsaISetLogonGuidInLogonSession (Ordinal: 135, Address: 0xc6900)
- LsaISetLogonInfo (Ordinal: 136, Address: 0x47980)
- LsaISetNewSyskey (Ordinal: 137, Address: 0x100fa0)
- LsaISetPackageAttrInLogonSession (Ordinal: 138, Address: 0xc6af0)
- LsaISetSupplementalTokenInfo (Ordinal: 139, Address: 0x4be60)
- LsaISetTokenDacl (Ordinal: 140, Address: 0xe55b0)
- LsaISetUserFlags (Ordinal: 141, Address: 0x44ba0)
- LsaITransformAuthorizationData (Ordinal: 142, Address: 0x1068e0)
- LsaIUnregisterAllPolicyChangeNotificationCallback (Ordinal: 143, Address: 0x104a00)
- LsaIUnregisterLogonSessionCallback (Ordinal: 144, Address: 0xc6ba0)
- LsaIUnregisterPolicyChangeNotificationCallback (Ordinal: 145, Address: 0x104b70)
- LsaIUpdateForestTrustInformation (Ordinal: 146, Address: 0x101de0)
- LsaIUpdateKerbMaxTokenSize (Ordinal: 147, Address: 0xcebc0)
- LsaIUpdateLogonSession (Ordinal: 148, Address: 0x2a30)
- LsaIValidateTargetInfo (Ordinal: 149, Address: 0xd2650)
- LsaIVerifyCachability (Ordinal: 150, Address: 0x101e50)
- LsaIVerifyCachabilityEx (Ordinal: 151, Address: 0x7d3d0)
- LsaIWasLogonNotifiedOfProfileLoad (Ordinal: 152, Address: 0x7b130)
- LsaIWriteAuditEvent (Ordinal: 153, Address: 0xe3cb0)
- LsaIWriteKdcAuthenticationEvent (Ordinal: 154, Address: 0xe3d70)
- LsaLookupPerfCounterAddAmount (Ordinal: 155, Address: 0x7b6b0)
- LsaLookupPerfCounterAddLargeAmount (Ordinal: 156, Address: 0x7b720)
- LsaLookupPerfCounterDecrementCount (Ordinal: 157, Address: 0x7b790)
- LsaLookupPerfCounterDecrementLargeCount (Ordinal: 158, Address: 0x7b800)
- LsaLookupPerfCounterIncrementCount (Ordinal: 159, Address: 0x7b870)
- LsaLookupPerfCounterIncrementLargeCount (Ordinal: 160, Address: 0x7b8e0)
- LsapAdtAuditingEnabledByLogonId (Ordinal: 161, Address: 0x1e1f0)
- LsapAdtAuditingEnabledBySubCategory (Ordinal: 162, Address: 0x1e2b0)
- LsapAdtAuditingEnabledHint (Ordinal: 163, Address: 0xe6ac0)
- LsapAdtGetCallerProcessInfo (Ordinal: 164, Address: 0x30f80)
- LsapAdtInitParametersArray (Ordinal: 165, Address: 0x1ae70)
- LsapAdtWriteLog (Ordinal: 166, Address: 0x4b2b0)
- LsapAllocateLsaHeap (Ordinal: 167, Address: 0x3c370)
- LsapAllocatePrivateHeap (Ordinal: 168, Address: 0x3c370)
- LsapAuOpenSam (Ordinal: 169, Address: 0x525e0)
- LsapAuditFailed (Ordinal: 170, Address: 0xe7250)
- LsapBuildPrivilegeAuditString (Ordinal: 171, Address: 0x106a90)
- LsapCheckBootMode (Ordinal: 172, Address: 0x51830)
- LsapCloseHandle (Ordinal: 173, Address: 0x44730)
- LsapCompareDomainNames (Ordinal: 174, Address: 0x5410)
- LsapCrServerGetSessionKey (Ordinal: 175, Address: 0x4eab0)
- LsapCrServerGetSessionKeySafe (Ordinal: 176, Address: 0xe8670)
- LsapDbAcquireLockEx (Ordinal: 177, Address: 0x12760)
- LsapDbApplyTransaction (Ordinal: 178, Address: 0x444c0)
- LsapDbBuildObjectCaches (Ordinal: 179, Address: 0x558c0)
- LsapDbCloseHandle (Ordinal: 180, Address: 0x1088c0)
- LsapDbCloseObject (Ordinal: 181, Address: 0x44820)
- LsapDbCopyUnicodeAttribute (Ordinal: 182, Address: 0x56310)
- LsapDbCopyUnicodeAttributeNoAlloc (Ordinal: 183, Address: 0x109ec0)
- LsapDbCreateObject (Ordinal: 184, Address: 0x108b40)
- LsapDbDeleteAttributesObject (Ordinal: 185, Address: 0x109040)
- LsapDbDeleteObject (Ordinal: 186, Address: 0x1090e0)
- LsapDbDereferenceHandle (Ordinal: 187, Address: 0x13270)
- LsapDbDereferenceObject (Ordinal: 188, Address: 0x11fa0)
- LsapDbEnumerateSids (Ordinal: 189, Address: 0x56c10)
- LsapDbEnumerateTrustedDomainsEx (Ordinal: 190, Address: 0x10acc0)
- LsapDbExpAcquireReadLockTrustedDomainList (Ordinal: 191, Address: 0x10b8a0)
- LsapDbExpAcquireWriteLockTrustedDomainList (Ordinal: 192, Address: 0x10b8d0)
- LsapDbExpConvertReadLockTrustedDomainListToExclusive (Ordinal: 193, Address: 0x10b900)
- LsapDbExpConvertWriteLockTrustedDomainListToShared (Ordinal: 194, Address: 0x10b920)
- LsapDbExpIsCacheBuilding (Ordinal: 195, Address: 0x10b940)
- LsapDbExpIsCacheValid (Ordinal: 196, Address: 0x10b960)
- LsapDbExpIsLockedTrustedDomainList (Ordinal: 197, Address: 0x10b980)
- LsapDbExpMakeCacheBuilding (Ordinal: 198, Address: 0x10b9d0)
- LsapDbExpMakeCacheInvalid (Ordinal: 199, Address: 0x10b9f0)
- LsapDbExpMakeCacheValid (Ordinal: 200, Address: 0x10ba10)
- LsapDbExpReleaseLockTrustedDomainList (Ordinal: 201, Address: 0x10ba30)
- LsapDbFreeAttributes (Ordinal: 202, Address: 0x54f90)
- LsapDbFreeTrustedDomainsEx (Ordinal: 203, Address: 0x10ae70)
- LsapDbGetDbObjectTypeName (Ordinal: 204, Address: 0x10ba50)
- LsapDbGetDbPolicyHandle (Ordinal: 205, Address: 0x10ba70)
- LsapDbGetSecretType (Ordinal: 206, Address: 0x44530)
- LsapDbInitializeAttribute (Ordinal: 207, Address: 0x4e110)
- LsapDbIsStatusConnectionFailure (Ordinal: 208, Address: 0xff900)
- LsapDbLookupAddListReferencedDomains (Ordinal: 209, Address: 0xbd80)
- LsapDbLookupCreateListReferencedDomains (Ordinal: 210, Address: 0xff930)
- LsapDbLookupGetDomainInfo (Ordinal: 211, Address: 0x46530)
- LsapDbLookupListReferencedDomains (Ordinal: 212, Address: 0x5790)
- LsapDbLookupMergeDisjointReferencedDomains (Ordinal: 213, Address: 0xfff50)
- LsapDbLookupNameChainRequest (Ordinal: 214, Address: 0x1001f0)
- LsapDbLookupNamesInPrimaryDomain (Ordinal: 215, Address: 0x103c40)
- LsapDbLookupSidsInPrimaryDomain (Ordinal: 216, Address: 0x10a650)
- LsapDbMakeGuidAttribute (Ordinal: 217, Address: 0x109f30)
- LsapDbMakeSidAttribute (Ordinal: 218, Address: 0x109f90)
- LsapDbMakeUnicodeAttribute (Ordinal: 219, Address: 0x10a020)
- LsapDbOpenObject (Ordinal: 220, Address: 0x10750)
- LsapDbQueryInformationPolicy (Ordinal: 221, Address: 0xddb0)
- LsapDbReadAttribute (Ordinal: 222, Address: 0x550e0)
- LsapDbReadAttributesObject (Ordinal: 223, Address: 0x4dfc0)
- LsapDbReferenceObject (Ordinal: 224, Address: 0x13710)
- LsapDbReleaseLockEx (Ordinal: 225, Address: 0x105f0)
- LsapDbSecretIsMachineAcc (Ordinal: 226, Address: 0x10bbc0)
- LsapDbSidToLogicalNameObject (Ordinal: 227, Address: 0x44470)
- LsapDbSlowEnumerateTrustedDomains (Ordinal: 228, Address: 0x10b010)
- LsapDbUpdateCountCompUnmappedNames (Ordinal: 229, Address: 0x1041e0)
- LsapDbVerifyHandle (Ordinal: 230, Address: 0x138f0)
- LsapDbVerifyInfoQueryTrustedDomain (Ordinal: 231, Address: 0x10ba80)
- LsapDbVerifyInfoSetTrustedDomain (Ordinal: 232, Address: 0x10baa0)
- LsapDbWriteAttributesObject (Ordinal: 233, Address: 0x1094a0)
- LsapDomainRenameHandlerForLogonSessions (Ordinal: 234, Address: 0xc82b0)
- LsapDsInitializeDsStateInfo (Ordinal: 235, Address: 0x101e80)
- LsapDsUnitializeDsStateInfo (Ordinal: 236, Address: 0x101ec0)
- LsapDssetupInitializeGetPrimaryDomainInformationOpState (Ordinal: 237, Address: 0xe5550)
- LsapDuplicateSid (Ordinal: 238, Address: 0x18770)
- LsapDuplicateString (Ordinal: 239, Address: 0x17ec0)
- LsapFreeLsaHeap (Ordinal: 240, Address: 0x2f2f0)
- LsapFreePrivateHeap (Ordinal: 241, Address: 0x2f2f0)
- LsapFreeString (Ordinal: 242, Address: 0x18480)
- LsapGetAccountDomainHandle (Ordinal: 243, Address: 0x10bac0)
- LsapGetCapeNamesForCap (Ordinal: 244, Address: 0xe8850)
- LsapGetGlobalRestrictAnonymous (Ordinal: 245, Address: 0x10bad0)
- LsapGetHourlyLogLevel (Ordinal: 246, Address: 0x10bae0)
- LsapGetLogonSessionAccountInfoEx (Ordinal: 247, Address: 0x17430)
- LsapGetLookupRestrictIsolatedNameLevel (Ordinal: 248, Address: 0x100950)
- LsapGetPolicyHandle (Ordinal: 249, Address: 0x10baf0)
- LsapGetWellKnownSid (Ordinal: 250, Address: 0x10bb10)
- LsapInitLsa (Ordinal: 251, Address: 0x5cf40)
- LsapInitializeLsaDb (Ordinal: 252, Address: 0x10bb30)
- LsapIsBuiltinDomain (Ordinal: 253, Address: 0x100960)
- LsapIsSamOpened (Ordinal: 254, Address: 0x10bbb0)
- LsapOpenSam (Ordinal: 255, Address: 0xe55a0)
- LsapQueryClientInfo (Ordinal: 256, Address: 0x2f320)
- LsapRemoveTrailingDot (Ordinal: 257, Address: 0xb3640)
- LsapRpcCopySid (Ordinal: 258, Address: 0x56b0)
- LsapRpcCopyUnicodeString (Ordinal: 259, Address: 0x4790)
- LsapRtlValidateControllerTrustedDomain (Ordinal: 260, Address: 0x1009a0)
- LsapRtlValidateControllerTrustedDomainByHandle (Ordinal: 261, Address: 0x100b40)
- LsapSetErrorInfo (Ordinal: 262, Address: 0xca4b0)
- LsapSidListSize (Ordinal: 263, Address: 0xe7550)
- LsapTraceEvent (Ordinal: 264, Address: 0x44860)
- LsapTraceEventWithData (Ordinal: 265, Address: 0x11f30)
- LsapTruncateUnicodeString (Ordinal: 266, Address: 0xb3680)
- LsarClose (Ordinal: 267, Address: 0x11d00)
- LsarCreateSecret (Ordinal: 268, Address: 0x10c500)
- LsarDeleteObject (Ordinal: 269, Address: 0x1068a0)
- LsarEnumerateTrustedDomainsEx (Ordinal: 270, Address: 0x10b270)
- LsarLookupSids (Ordinal: 271, Address: 0x4d3b0)
- LsarOpenPolicy (Ordinal: 272, Address: 0x105c50)
- LsarOpenSecret (Ordinal: 273, Address: 0x43de0)
- LsarQueryDomainInformationPolicy (Ordinal: 274, Address: 0x10cf20)
- LsarQueryInformationPolicy (Ordinal: 275, Address: 0x128e0)
- LsarQuerySecret (Ordinal: 276, Address: 0x4d970)
- LsarQueryTrustedDomainInfoByName (Ordinal: 277, Address: 0x10b3e0)
- LsarRetrievePrivateData (Ordinal: 278, Address: 0x10def0)
- LsarSetInformationPolicy (Ordinal: 279, Address: 0x106010)
- LsarSetSecret (Ordinal: 280, Address: 0x10c7f0)
- LsarSetTrustedDomainInfoByName (Ordinal: 281, Address: 0x10b6a0)
- LsarStorePrivateData (Ordinal: 282, Address: 0x10dfa0)
- ServiceInit (Ordinal: 283, Address: 0x516f0)
- SpmpEventWrite (Ordinal: 284, Address: 0x32bb0)
- TracePrint (Ordinal: 285, Address: 0x9c10)
- TracePrintCallerInformation (Ordinal: 286, Address: 0xfee70)
- _fgs__LSAPR_TRUSTED_DOMAIN_FULL_INFORMATION2 (Ordinal: 287, Address: 0xe9ae0)
- _fgs__LSAPR_TRUSTED_DOMAIN_INFORMATION_EX2 (Ordinal: 288, Address: 0xe9b60)
- _fgs__LSAPR_TRUSTED_ENUM_BUFFER (Ordinal: 289, Address: 0x4d310)
- _fgs__LSAPR_TRUSTED_ENUM_BUFFER_EX (Ordinal: 290, Address: 0xe9bc0)
- _fgs__LSAPR_TRUST_INFORMATION (Ordinal: 291, Address: 0x4d370)
- _fgu__LSAPR_TRUSTED_DOMAIN_INFO (Ordinal: 292, Address: 0xe9c80)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x18014cdb8)
api-ms-win-core-console-l1-1-0.dll
- SetConsoleCtrlHandler (Address: 0x18014cdc8)
api-ms-win-core-datetime-l1-1-0.dll
- GetDateFormatW (Address: 0x18014cdd8)
- GetTimeFormatW (Address: 0x18014cde0)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x18014cdf8)
- IsDebuggerPresent (Address: 0x18014ce08)
- OutputDebugStringA (Address: 0x18014cdf0)
- OutputDebugStringW (Address: 0x18014ce00)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x18014ce18)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x18014ce28)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18014ce58)
- RaiseException (Address: 0x18014ce48)
- SetLastError (Address: 0x18014ce50)
- SetUnhandledExceptionFilter (Address: 0x18014ce38)
- UnhandledExceptionFilter (Address: 0x18014ce40)
api-ms-win-core-errorhandling-l1-1-2.dll
- RaiseFailFastException (Address: 0x18014ce68)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x18014ced0)
- CreateDirectoryW (Address: 0x18014cec0)
- CreateFileW (Address: 0x18014cea8)
- DeleteFileW (Address: 0x18014ce98)
- FileTimeToLocalFileTime (Address: 0x18014cf08)
- FindClose (Address: 0x18014cee8)
- FindCloseChangeNotification (Address: 0x18014cec8)
- FindFirstChangeNotificationW (Address: 0x18014ced8)
- FindFirstFileExW (Address: 0x18014cee0)
- FindFirstFileW (Address: 0x18014ce80)
- FindNextChangeNotification (Address: 0x18014ceb8)
- FindNextFileW (Address: 0x18014ce78)
- GetFileSize (Address: 0x18014cf00)
- GetFileSizeEx (Address: 0x18014cef8)
- GetFileType (Address: 0x18014cea0)
- ReadFile (Address: 0x18014ce88)
- SetFileAttributesW (Address: 0x18014ceb0)
- SetFilePointer (Address: 0x18014cef0)
- WriteFile (Address: 0x18014ce90)
api-ms-win-core-file-l2-1-0.dll
- MoveFileExW (Address: 0x18014cf20)
- ReadDirectoryChangesW (Address: 0x18014cf18)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18014cf30)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18014cf58)
- HeapAlloc (Address: 0x18014cf40)
- HeapFree (Address: 0x18014cf50)
- HeapSetInformation (Address: 0x18014cf48)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x18014cf70)
- LocalFree (Address: 0x18014cf68)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x18014cf80)
api-ms-win-core-io-l1-1-0.dll
- GetOverlappedResult (Address: 0x18014cf90)
api-ms-win-core-io-l1-1-1.dll
- CancelIo (Address: 0x18014cfa0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- DnsHostnameToComputerNameW (Address: 0x18014cfc0)
- MoveFileW (Address: 0x18014cfb0)
- WTSGetActiveConsoleSessionId (Address: 0x18014cfb8)
api-ms-win-core-kernel32-private-l1-1-0.dll
- CheckElevationEnabled (Address: 0x18014cfd0)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x18014cfe0)
- FreeLibrary (Address: 0x18014d010)
- GetModuleFileNameA (Address: 0x18014cff8)
- GetModuleFileNameW (Address: 0x18014d020)
- GetModuleHandleExW (Address: 0x18014cfe8)
- GetModuleHandleW (Address: 0x18014cff0)
- GetProcAddress (Address: 0x18014d008)
- LoadLibraryExA (Address: 0x18014d018)
- LoadLibraryExW (Address: 0x18014d000)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18014d030)
api-ms-win-core-memory-l1-1-0.dll
- VirtualAlloc (Address: 0x18014d040)
- VirtualFree (Address: 0x18014d058)
- VirtualProtect (Address: 0x18014d050)
- VirtualQuery (Address: 0x18014d048)
api-ms-win-core-memory-l1-1-1.dll
- VirtualLock (Address: 0x18014d068)
api-ms-win-core-perfcounters-l1-1-0.dll
- PerfCreateInstance (Address: 0x18014d080)
- PerfSetCounterRefValue (Address: 0x18014d090)
- PerfSetCounterSetInfo (Address: 0x18014d088)
- PerfStartProviderEx (Address: 0x18014d098)
- PerfStopProvider (Address: 0x18014d078)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetProfileStringA (Address: 0x18014d0a8)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x18014d0b8)
- GetEnvironmentVariableW (Address: 0x18014d0c0)
- SearchPathW (Address: 0x18014d0c8)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x18014d0d8)
- GetCurrentProcess (Address: 0x18014d148)
- GetCurrentProcessId (Address: 0x18014d100)
- GetCurrentThread (Address: 0x18014d120)
- GetCurrentThreadId (Address: 0x18014d0f0)
- GetProcessTimes (Address: 0x18014d110)
- OpenProcessToken (Address: 0x18014d0e0)
- OpenThreadToken (Address: 0x18014d138)
- SetProcessShutdownParameters (Address: 0x18014d108)
- SetThreadStackGuarantee (Address: 0x18014d0f8)
- SetThreadToken (Address: 0x18014d140)
- TerminateProcess (Address: 0x18014d118)
- TlsAlloc (Address: 0x18014d0e8)
- TlsGetValue (Address: 0x18014d130)
- TlsSetValue (Address: 0x18014d128)
api-ms-win-core-processthreads-l1-1-1.dll
- GetProcessMitigationPolicy (Address: 0x18014d160)
- IsProcessorFeaturePresent (Address: 0x18014d168)
- OpenProcess (Address: 0x18014d158)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18014d180)
- QueryPerformanceFrequency (Address: 0x18014d178)
api-ms-win-core-psapi-l1-1-0.dll
- QueryFullProcessImageNameW (Address: 0x18014d190)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18014d230)
- RegCreateKeyExA (Address: 0x18014d1e8)
- RegCreateKeyExW (Address: 0x18014d248)
- RegDeleteKeyExA (Address: 0x18014d1c8)
- RegDeleteKeyExW (Address: 0x18014d238)
- RegDeleteTreeW (Address: 0x18014d1f8)
- RegDeleteValueW (Address: 0x18014d1a8)
- RegEnumKeyExW (Address: 0x18014d200)
- RegEnumValueW (Address: 0x18014d1a0)
- RegFlushKey (Address: 0x18014d1d0)
- RegGetValueW (Address: 0x18014d220)
- RegLoadKeyW (Address: 0x18014d210)
- RegNotifyChangeKeyValue (Address: 0x18014d1d8)
- RegOpenKeyExA (Address: 0x18014d1f0)
- RegOpenKeyExW (Address: 0x18014d218)
- RegQueryInfoKeyA (Address: 0x18014d1b8)
- RegQueryInfoKeyW (Address: 0x18014d1b0)
- RegQueryValueExA (Address: 0x18014d1e0)
- RegQueryValueExW (Address: 0x18014d240)
- RegSetValueExA (Address: 0x18014d1c0)
- RegSetValueExW (Address: 0x18014d228)
- RegUnLoadKeyW (Address: 0x18014d208)
api-ms-win-core-registry-l1-1-1.dll
- RegSetKeyValueW (Address: 0x18014d258)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18014d268)
- RtlLookupFunctionEntry (Address: 0x18014d270)
- RtlVirtualUnwind (Address: 0x18014d278)
api-ms-win-core-string-l1-1-0.dll
- CompareStringW (Address: 0x18014d290)
- GetStringTypeW (Address: 0x18014d288)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x18014d2a0)
- lstrlenA (Address: 0x18014d2a8)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18014d360)
- AcquireSRWLockShared (Address: 0x18014d340)
- CreateEventW (Address: 0x18014d2f0)
- CreateMutexExW (Address: 0x18014d320)
- CreateSemaphoreExW (Address: 0x18014d2f8)
- DeleteCriticalSection (Address: 0x18014d350)
- EnterCriticalSection (Address: 0x18014d338)
- InitializeCriticalSection (Address: 0x18014d308)
- InitializeCriticalSectionEx (Address: 0x18014d310)
- InitializeSRWLock (Address: 0x18014d2d0)
- LeaveCriticalSection (Address: 0x18014d318)
- OpenEventW (Address: 0x18014d348)
- OpenSemaphoreW (Address: 0x18014d2c0)
- ReleaseMutex (Address: 0x18014d2d8)
- ReleaseSemaphore (Address: 0x18014d358)
- ReleaseSRWLockExclusive (Address: 0x18014d2c8)
- ReleaseSRWLockShared (Address: 0x18014d2e0)
- ResetEvent (Address: 0x18014d2b8)
- SetEvent (Address: 0x18014d328)
- TryAcquireSRWLockExclusive (Address: 0x18014d300)
- WaitForSingleObject (Address: 0x18014d2e8)
- WaitForSingleObjectEx (Address: 0x18014d330)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x18014d370)
- Sleep (Address: 0x18014d378)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x18014d398)
- GetLocalTime (Address: 0x18014d3d0)
- GetSystemDirectoryW (Address: 0x18014d3b0)
- GetSystemInfo (Address: 0x18014d3a8)
- GetSystemTime (Address: 0x18014d390)
- GetSystemTimeAsFileTime (Address: 0x18014d3c0)
- GetSystemWindowsDirectoryW (Address: 0x18014d3b8)
- GetTickCount (Address: 0x18014d3a0)
- GetTickCount64 (Address: 0x18014d3c8)
- GetWindowsDirectoryW (Address: 0x18014d388)
api-ms-win-core-sysinfo-l1-2-0.dll
- VerSetConditionMask (Address: 0x18014d3e0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x18014d418)
- CloseThreadpoolWait (Address: 0x18014d400)
- CreateThreadpoolTimer (Address: 0x18014d408)
- CreateThreadpoolWait (Address: 0x18014d420)
- SetThreadpoolTimer (Address: 0x18014d3f0)
- SetThreadpoolWait (Address: 0x18014d3f8)
- WaitForThreadpoolTimerCallbacks (Address: 0x18014d410)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueueTimer (Address: 0x18014d440)
- DeleteTimerQueueTimer (Address: 0x18014d438)
- QueueUserWorkItem (Address: 0x18014d448)
- UnregisterWaitEx (Address: 0x18014d430)
api-ms-win-core-threadpool-private-l1-1-0.dll
- RegisterWaitForSingleObjectEx (Address: 0x18014d458)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x18014d470)
- SystemTimeToFileTime (Address: 0x18014d468)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x18014d5f8)
- __CxxFrameHandler3 (Address: 0x18014d568)
- __CxxFrameHandler4 (Address: 0x18014d578)
- __std_terminate (Address: 0x18014d570)
- _CxxThrowException (Address: 0x18014d560)
- _local_unwind (Address: 0x18014d610)
- _o___std_exception_copy (Address: 0x18014d5f0)
- _o___std_exception_destroy (Address: 0x18014d5e8)
- _o___std_type_info_destroy_list (Address: 0x18014d5e0)
- _o___stdio_common_vsnprintf_s (Address: 0x18014d5d8)
- _o___stdio_common_vsnwprintf_s (Address: 0x18014d5d0)
- _o___stdio_common_vswprintf (Address: 0x18014d5c8)
- _o___stdio_common_vswprintf_s (Address: 0x18014d5c0)
- _o___stdio_common_vswscanf (Address: 0x18014d5b8)
- _o__callnewh (Address: 0x18014d5b0)
- _o__cexit (Address: 0x18014d5a8)
- _o__configure_narrow_argv (Address: 0x18014d590)
- _o__crt_atexit (Address: 0x18014d580)
- _o__errno (Address: 0x18014d558)
- _o__execute_onexit_table (Address: 0x18014d550)
- _o__initialize_narrow_environment (Address: 0x18014d5a0)
- _o__initialize_onexit_table (Address: 0x18014d598)
- _o__invalid_parameter_noinfo (Address: 0x18014d588)
- _o__purecall (Address: 0x18014d480)
- _o__register_onexit_function (Address: 0x18014d488)
- _o__seh_filter_dll (Address: 0x18014d490)
- _o__stricmp (Address: 0x18014d498)
- _o__ultow (Address: 0x18014d4a0)
- _o__ultow_s (Address: 0x18014d4a8)
- _o__wcsicmp (Address: 0x18014d4b0)
- _o__wcsnicmp (Address: 0x18014d4b8)
- _o__wsplitpath_s (Address: 0x18014d4c0)
- _o__wtoi (Address: 0x18014d4c8)
- _o__wtol (Address: 0x18014d4d0)
- _o_bsearch_s (Address: 0x18014d4d8)
- _o_free (Address: 0x18014d4e0)
- _o_malloc (Address: 0x18014d4f0)
- _o_mbstowcs (Address: 0x18014d4f8)
- _o_memcpy_s (Address: 0x18014d500)
- _o_qsort (Address: 0x18014d508)
- _o_qsort_s (Address: 0x18014d510)
- _o_strtok (Address: 0x18014d518)
- _o_toupper (Address: 0x18014d520)
- _o_wcscat_s (Address: 0x18014d528)
- _o_wcscpy_s (Address: 0x18014d530)
- _o_wcsncat_s (Address: 0x18014d538)
- _o_wcsncpy_s (Address: 0x18014d540)
- _o_wcstoul (Address: 0x18014d548)
- memcmp (Address: 0x18014d618)
- memcpy (Address: 0x18014d620)
- memmove (Address: 0x18014d4e8)
- wcschr (Address: 0x18014d608)
- wcsrchr (Address: 0x18014d600)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x18014d630)
- _initterm_e (Address: 0x18014d638)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x18014d648)
- wcscmp (Address: 0x18014d650)
- wcsnlen (Address: 0x18014d658)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- TraceMessage (Address: 0x18014d668)
api-ms-win-eventing-controller-l1-1-0.dll
- ControlTraceW (Address: 0x18014d688)
- EnableTraceEx2 (Address: 0x18014d678)
- StartTraceW (Address: 0x18014d680)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x18014d6c0)
- EventProviderEnabled (Address: 0x18014d6a0)
- EventRegister (Address: 0x18014d6b8)
- EventSetInformation (Address: 0x18014d698)
- EventUnregister (Address: 0x18014d6a8)
- EventWriteTransfer (Address: 0x18014d6b0)
api-ms-win-security-base-l1-1-0.dll
- AccessCheck (Address: 0x18014d780)
- AdjustTokenPrivileges (Address: 0x18014d748)
- AllocateAndInitializeSid (Address: 0x18014d718)
- AllocateLocallyUniqueId (Address: 0x18014d708)
- CheckTokenMembership (Address: 0x18014d7a8)
- CopySid (Address: 0x18014d740)
- CreateWellKnownSid (Address: 0x18014d7a0)
- DuplicateToken (Address: 0x18014d788)
- DuplicateTokenEx (Address: 0x18014d710)
- EqualDomainSid (Address: 0x18014d758)
- FreeSid (Address: 0x18014d700)
- GetAclInformation (Address: 0x18014d720)
- GetLengthSid (Address: 0x18014d7b0)
- GetSidIdentifierAuthority (Address: 0x18014d6f8)
- GetSidSubAuthority (Address: 0x18014d6e8)
- GetSidSubAuthorityCount (Address: 0x18014d6f0)
- GetTokenInformation (Address: 0x18014d6d8)
- GetWindowsAccountDomainSid (Address: 0x18014d750)
- ImpersonateLoggedOnUser (Address: 0x18014d798)
- ImpersonateSelf (Address: 0x18014d778)
- InitializeSecurityDescriptor (Address: 0x18014d728)
- IsTokenRestricted (Address: 0x18014d6d0)
- IsValidSid (Address: 0x18014d770)
- IsWellKnownSid (Address: 0x18014d6e0)
- PrivilegeCheck (Address: 0x18014d738)
- QuerySecurityAccessMask (Address: 0x18014d760)
- RevertToSelf (Address: 0x18014d7b8)
- SetSecurityAccessMask (Address: 0x18014d768)
- SetSecurityDescriptorSacl (Address: 0x18014d730)
- SetTokenInformation (Address: 0x18014d790)
api-ms-win-security-base-l1-2-0.dll
- CheckTokenMembershipEx (Address: 0x18014d7c8)
api-ms-win-security-base-private-l1-1-1.dll
- CreateAppContainerToken (Address: 0x18014d7d8)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x18014d7e8)
api-ms-win-security-grouppolicy-l1-1-0.dll
- IsSyncForegroundPolicyRefresh (Address: 0x18014d7f8)
api-ms-win-service-core-l1-1-0.dll
- SetServiceStatus (Address: 0x18014d808)
- StartServiceCtrlDispatcherW (Address: 0x18014d810)
api-ms-win-service-private-l1-1-0.dll
- I_QueryTagInformation (Address: 0x18014d828)
- I_ScIsSecurityProcess (Address: 0x18014d820)
api-ms-win-service-winsvc-l1-1-0.dll
- RegisterServiceCtrlHandlerW (Address: 0x18014d838)
api-ms-win-stateseparation-helpers-l1-1-0.dll
- GetPersistedRegistryLocationW (Address: 0x18014d848)
MSASN1.dll
- ASN1_CloseDecoder (Address: 0x18014cad8)
- ASN1_CloseEncoder (Address: 0x18014cad0)
- ASN1_CreateDecoder (Address: 0x18014cac8)
- ASN1_CreateEncoder (Address: 0x18014cac0)
- ASN1_CreateModule (Address: 0x18014caa8)
- ASN1_Decode (Address: 0x18014cae0)
- ASN1_Encode (Address: 0x18014cae8)
- ASN1_FreeDecoded (Address: 0x18014caf0)
- ASN1_FreeEncoded (Address: 0x18014caf8)
- ASN1BERDecBitString (Address: 0x18014ca78)
- ASN1BERDecEndOfContents (Address: 0x18014ca30)
- ASN1BERDecExplicitTag (Address: 0x18014ca00)
- ASN1BERDecNotEndOfContents (Address: 0x18014ca20)
- ASN1BERDecObjectIdentifier (Address: 0x18014ca80)
- ASN1BERDecOctetString (Address: 0x18014ca18)
- ASN1BERDecPeekTag (Address: 0x18014ca08)
- ASN1BERDecSkip (Address: 0x18014ca58)
- ASN1BERDecU32Val (Address: 0x18014caa0)
- ASN1BERDecZeroCharString (Address: 0x18014ca90)
- ASN1BEREncEndOfContents (Address: 0x18014ca50)
- ASN1BEREncExplicitTag (Address: 0x18014ca28)
- ASN1BEREncObjectIdentifier (Address: 0x18014ca88)
- ASN1BEREncRemoveZeroBits (Address: 0x18014c9f0)
- ASN1BEREncU32 (Address: 0x18014ca10)
- ASN1bitstring_free (Address: 0x18014cab0)
- ASN1DecAlloc (Address: 0x18014ca68)
- ASN1DecSetError (Address: 0x18014c9f8)
- ASN1DEREncBitString (Address: 0x18014ca98)
- ASN1DEREncCharString (Address: 0x18014ca48)
- ASN1DEREncOctetString (Address: 0x18014ca70)
- ASN1EncSetError (Address: 0x18014ca40)
- ASN1Free (Address: 0x18014ca60)
- ASN1objectidentifier_free (Address: 0x18014ca38)
- ASN1octetstring_free (Address: 0x18014cb00)
- ASN1ztcharstring_free (Address: 0x18014cab8)
ntdll.dll
- _strcmpi (Address: 0x18014dd48)
- DbgPrint (Address: 0x18014d870)
- EtwEventActivityIdControl (Address: 0x18014dcf0)
- EtwEventEnabled (Address: 0x18014d890)
- EtwEventRegister (Address: 0x18014dde8)
- EtwEventSetInformation (Address: 0x18014ddf0)
- EtwEventUnregister (Address: 0x18014dac0)
- EtwEventWrite (Address: 0x18014dab8)
- EtwEventWriteTransfer (Address: 0x18014df20)
- EtwGetTraceEnableFlags (Address: 0x18014ddf8)
- EtwGetTraceEnableLevel (Address: 0x18014de00)
- EtwGetTraceLoggerHandle (Address: 0x18014dc80)
- EtwLogTraceEvent (Address: 0x18014dc78)
- EtwRegisterSecurityProvider (Address: 0x18014dd60)
- EtwRegisterTraceGuidsW (Address: 0x18014dc88)
- EtwTraceMessage (Address: 0x18014dc98)
- EtwWriteUMSecurityEvent (Address: 0x18014dd68)
- LdrLoadDll (Address: 0x18014dae8)
- NtAccessCheck (Address: 0x18014da88)
- NtAccessCheckAndAuditAlarm (Address: 0x18014da68)
- NtAccessCheckByTypeAndAuditAlarm (Address: 0x18014db10)
- NtAdjustPrivilegesToken (Address: 0x18014da30)
- NtAllocateLocallyUniqueId (Address: 0x18014dea8)
- NtAllocateVirtualMemory (Address: 0x18014dcb8)
- NtClose (Address: 0x18014dbe0)
- NtCloseObjectAuditAlarm (Address: 0x18014db08)
- NtCommitTransaction (Address: 0x18014d9b0)
- NtCreateEvent (Address: 0x18014ddc0)
- NtCreateKey (Address: 0x18014da18)
- NtCreateKeyTransacted (Address: 0x18014da10)
- NtCreateSection (Address: 0x18014d8d0)
- NtCreateToken (Address: 0x18014d8f8)
- NtCreateTokenEx (Address: 0x18014d910)
- NtCreateTransaction (Address: 0x18014d9a8)
- NtDeleteKey (Address: 0x18014da08)
- NtDeleteObjectAuditAlarm (Address: 0x18014dac8)
- NtDeleteValueKey (Address: 0x18014da20)
- NtDuplicateObject (Address: 0x18014dee8)
- NtDuplicateToken (Address: 0x18014dc48)
- NtEnumerateKey (Address: 0x18014d9e8)
- NtEnumerateValueKey (Address: 0x18014d978)
- NtFilterToken (Address: 0x18014d950)
- NtFlushKey (Address: 0x18014d928)
- NtFreeVirtualMemory (Address: 0x18014db60)
- NtImpersonateAnonymousToken (Address: 0x18014de78)
- NtLoadKey (Address: 0x18014df58)
- NtMapViewOfSection (Address: 0x18014d8d8)
- NtOpenEvent (Address: 0x18014ddb8)
- NtOpenKey (Address: 0x18014d918)
- NtOpenKeyTransacted (Address: 0x18014d9f0)
- NtOpenProcess (Address: 0x18014dcc0)
- NtOpenProcessToken (Address: 0x18014da38)
- NtOpenSession (Address: 0x18014db98)
- NtOpenSymbolicLinkObject (Address: 0x18014dd50)
- NtOpenThreadToken (Address: 0x18014dc68)
- NtPrivilegeCheck (Address: 0x18014daf8)
- NtPrivilegedServiceAuditAlarm (Address: 0x18014d878)
- NtPrivilegeObjectAuditAlarm (Address: 0x18014d930)
- NtQueryInformationProcess (Address: 0x18014dcc8)
- NtQueryInformationToken (Address: 0x18014dc60)
- NtQueryKey (Address: 0x18014da00)
- NtQueryObject (Address: 0x18014dab0)
- NtQuerySymbolicLinkObject (Address: 0x18014dd58)
- NtQuerySystemInformation (Address: 0x18014dcd0)
- NtQueryValueKey (Address: 0x18014d9f8)
- NtRaiseHardError (Address: 0x18014dda8)
- NtReadVirtualMemory (Address: 0x18014dca8)
- NtReplyPort (Address: 0x18014d990)
- NtRollbackTransaction (Address: 0x18014d9b8)
- NtSetEvent (Address: 0x18014ddb0)
- NtSetInformationThread (Address: 0x18014dc50)
- NtSetInformationToken (Address: 0x18014dc40)
- NtSetSecurityObject (Address: 0x18014d8c0)
- NtSetValueKey (Address: 0x18014d920)
- NtShutdownSystem (Address: 0x18014dd20)
- NtUnloadKey (Address: 0x18014df68)
- NtWaitForSingleObject (Address: 0x18014d8e0)
- NtWriteVirtualMemory (Address: 0x18014dcb0)
- RtlAbortRXact (Address: 0x18014db70)
- RtlAcquireResourceExclusive (Address: 0x18014dbb8)
- RtlAcquireResourceShared (Address: 0x18014df70)
- RtlAcquireSRWLockExclusive (Address: 0x18014dec0)
- RtlAcquireSRWLockShared (Address: 0x18014dce0)
- RtlAddAccessAllowedAce (Address: 0x18014de30)
- RtlAddAce (Address: 0x18014df80)
- RtlAddActionToRXact (Address: 0x18014db78)
- RtlAddMandatoryAce (Address: 0x18014d8b0)
- RtlAdjustPrivilege (Address: 0x18014dd28)
- RtlAllocateAndInitializeSid (Address: 0x18014ddd8)
- RtlAllocateHeap (Address: 0x18014d9a0)
- RtlAnsiStringToUnicodeString (Address: 0x18014df30)
- RtlAppendUnicodeStringToString (Address: 0x18014daa8)
- RtlAppendUnicodeToString (Address: 0x18014dcf8)
- RtlApplyRXact (Address: 0x18014db68)
- RtlAreAllAccessesGranted (Address: 0x18014db18)
- RtlAvlInsertNodeEx (Address: 0x18014dd18)
- RtlAvlRemoveNode (Address: 0x18014dd10)
- RtlCapabilityCheck (Address: 0x18014d868)
- RtlCheckTokenCapability (Address: 0x18014d860)
- RtlCheckTokenMembershipEx (Address: 0x18014de20)
- RtlCompareUnicodeString (Address: 0x18014dbf8)
- RtlConvertExclusiveToShared (Address: 0x18014de90)
- RtlConvertSharedToExclusive (Address: 0x18014de98)
- RtlConvertSidToUnicodeString (Address: 0x18014dbd8)
- RtlCopyLuid (Address: 0x18014dea0)
- RtlCopySid (Address: 0x18014de70)
- RtlCopyString (Address: 0x18014d980)
- RtlCopyUnicodeString (Address: 0x18014dbe8)
- RtlCreateAcl (Address: 0x18014de38)
- RtlCreateSecurityDescriptor (Address: 0x18014d8a8)
- RtlCreateServiceSid (Address: 0x18014df18)
- RtlCreateUnicodeString (Address: 0x18014df48)
- RtlCreateUnicodeStringFromAsciiz (Address: 0x18014dcd8)
- RtlDeleteAce (Address: 0x18014da80)
- RtlDeleteCriticalSection (Address: 0x18014dc00)
- RtlDeleteElementGenericTableAvl (Address: 0x18014db38)
- RtlDeleteResource (Address: 0x18014dec8)
- RtlDosPathNameToRelativeNtPathName_U (Address: 0x18014df50)
- RtlEnterCriticalSection (Address: 0x18014dc20)
- RtlEnumerateGenericTableAvl (Address: 0x18014db30)
- RtlEqualDomainName (Address: 0x18014da90)
- RtlEqualPrefixSid (Address: 0x18014de18)
- RtlEqualSid (Address: 0x18014dc10)
- RtlEqualString (Address: 0x18014d988)
- RtlEqualUnicodeString (Address: 0x18014dca0)
- RtlEthernetAddressToStringW (Address: 0x18014dd80)
- RtlFindAceByType (Address: 0x18014dd90)
- RtlFindCharInUnicodeString (Address: 0x18014df40)
- RtlFindMessage (Address: 0x18014dad0)
- RtlFreeAnsiString (Address: 0x18014df78)
- RtlFreeHeap (Address: 0x18014da48)
- RtlFreeSid (Address: 0x18014dd08)
- RtlFreeUnicodeString (Address: 0x18014dbd0)
- RtlGetAce (Address: 0x18014da70)
- RtlGetControlSecurityDescriptor (Address: 0x18014da58)
- RtlGetCurrentServiceSessionId (Address: 0x18014dc70)
- RtlGetDaclSecurityDescriptor (Address: 0x18014d9c0)
- RtlGetDeviceFamilyInfoEnum (Address: 0x18014d8c8)
- RtlGetLastNtStatus (Address: 0x18014dbf0)
- RtlGetLastWin32Error (Address: 0x18014de88)
- RtlGetNtProductType (Address: 0x18014deb0)
- RtlGetSaclSecurityDescriptor (Address: 0x18014dd88)
- RtlGetSuiteMask (Address: 0x18014d960)
- RtlGetThreadPreferredUILanguages (Address: 0x18014dad8)
- RtlGUIDFromString (Address: 0x18014dbb0)
- RtlIdentifierAuthoritySid (Address: 0x18014dde0)
- RtlImageNtHeader (Address: 0x18014dda0)
- RtlImpersonateSelf (Address: 0x18014d938)
- RtlImpersonateSelfEx (Address: 0x18014d858)
- RtlInitAnsiString (Address: 0x18014dbc0)
- RtlInitializeCriticalSection (Address: 0x18014dc38)
- RtlInitializeCriticalSectionAndSpinCount (Address: 0x18014dee0)
- RtlInitializeGenericTableAvl (Address: 0x18014db28)
- RtlInitializeResource (Address: 0x18014ded0)
- RtlInitializeRXact (Address: 0x18014daf0)
- RtlInitializeSid (Address: 0x18014de08)
- RtlInitializeSRWLock (Address: 0x18014da28)
- RtlInitString (Address: 0x18014def0)
- RtlInitUnicodeString (Address: 0x18014dc90)
- RtlInitUnicodeStringEx (Address: 0x18014dc30)
- RtlInsertElementGenericTableAvl (Address: 0x18014db48)
- RtlIntegerToChar (Address: 0x18014df38)
- RtlIntegerToUnicodeString (Address: 0x18014d9e0)
- RtlIpv4AddressToStringW (Address: 0x18014dd70)
- RtlIpv4StringToAddressExW (Address: 0x18014dba0)
- RtlIpv6AddressToStringW (Address: 0x18014dd78)
- RtlIpv6StringToAddressExW (Address: 0x18014dba8)
- RtlIsElevatedRid (Address: 0x18014d948)
- RtlIsMultiSessionSku (Address: 0x18014def8)
- RtlIsStateSeparationEnabled (Address: 0x18014ddd0)
- RtlLeaveCriticalSection (Address: 0x18014dc18)
- RtlLengthRequiredSid (Address: 0x18014de10)
- RtlLengthSecurityDescriptor (Address: 0x18014d9d0)
- RtlLengthSid (Address: 0x18014dc08)
- RtlLengthSidAsUnicodeString (Address: 0x18014dd30)
- RtlLookupElementGenericTableAvl (Address: 0x18014db40)
- RtlMakeSelfRelativeSD (Address: 0x18014d998)
- RtlMapGenericMask (Address: 0x18014da78)
- RtlNewSecurityObject (Address: 0x18014da40)
- RtlNtStatusToDosError (Address: 0x18014dbc8)
- RtlNumberGenericTableElementsAvl (Address: 0x18014db50)
- RtlNumberOfSetBitsUlongPtr (Address: 0x18014db58)
- RtlOwnerAcesPresent (Address: 0x18014d9d8)
- RtlpConvertAbsoluteToRelativeSecurityAttribute (Address: 0x18014d8e8)
- RtlpConvertRelativeToAbsoluteSecurityAttribute (Address: 0x18014d8f0)
- RtlpNtEnumerateSubKey (Address: 0x18014daa0)
- RtlpNtOpenKey (Address: 0x18014da98)
- RtlpNtQueryValueKey (Address: 0x18014db20)
- RtlPrefixUnicodeString (Address: 0x18014de68)
- RtlPublishWnfStateData (Address: 0x18014d970)
- RtlQueryInformationAcl (Address: 0x18014d958)
- RtlQueryTimeZoneInformation (Address: 0x18014dd98)
- RtlReleaseRelativeName (Address: 0x18014df60)
- RtlReleaseResource (Address: 0x18014df28)
- RtlReleaseSRWLockExclusive (Address: 0x18014de50)
- RtlReleaseSRWLockShared (Address: 0x18014dae0)
- RtlRunDecodeUnicodeString (Address: 0x18014dd00)
- RtlSetDaclSecurityDescriptor (Address: 0x18014d900)
- RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x18014de80)
- RtlSetOwnerSecurityDescriptor (Address: 0x18014d908)
- RtlSetSaclSecurityDescriptor (Address: 0x18014d8b8)
- RtlSetSecurityObject (Address: 0x18014da60)
- RtlSetSystemBootStatus (Address: 0x18014ddc8)
- RtlSetThreadPreferredUILanguages (Address: 0x18014df10)
- RtlSidDominates (Address: 0x18014dc58)
- RtlSidHashInitialize (Address: 0x18014d898)
- RtlSidHashLookup (Address: 0x18014d8a0)
- RtlSizeHeap (Address: 0x18014db90)
- RtlStartRXact (Address: 0x18014deb8)
- RtlStringFromGUID (Address: 0x18014db80)
- RtlSubAuthorityCountSid (Address: 0x18014df00)
- RtlSubAuthoritySid (Address: 0x18014df08)
- RtlTestProtectedAccess (Address: 0x18014d880)
- RtlTimeFieldsToTime (Address: 0x18014de48)
- RtlTryEnterCriticalSection (Address: 0x18014d940)
- RtlUnicodeStringToAnsiString (Address: 0x18014df88)
- RtlUnicodeStringToInteger (Address: 0x18014db00)
- RtlUpcaseUnicodeStringToOemString (Address: 0x18014dc28)
- RtlValidRelativeSecurityDescriptor (Address: 0x18014da50)
- RtlValidSecurityDescriptor (Address: 0x18014d9c8)
- RtlValidSid (Address: 0x18014d888)
- RtlVerifyVersionInfo (Address: 0x18014d968)
- TpAllocTimer (Address: 0x18014ded8)
- TpIsTimerSet (Address: 0x18014de58)
- TpReleaseTimer (Address: 0x18014de28)
- TpSetTimer (Address: 0x18014de60)
- TpWaitForTimer (Address: 0x18014de40)
- wcsncmp (Address: 0x18014dd38)
- wcsstr (Address: 0x18014dd40)
- WinSqmIncrementDWORD (Address: 0x18014dce8)
- WinSqmSetString (Address: 0x18014db88)
RPCRT4.dll
- I_RpcBindingInqClientTokenAttributes (Address: 0x18014cbb8)
- I_RpcBindingInqLocalClientPID (Address: 0x18014cb58)
- I_RpcBindingInqTransportType (Address: 0x18014cc08)
- I_RpcBindingIsClientLocal (Address: 0x18014cc00)
- I_RpcMapWin32Status (Address: 0x18014cb10)
- I_RpcOpenClientProcess (Address: 0x18014cbd8)
- I_RpcOpenClientThread (Address: 0x18014cbd0)
- MesDecodeIncrementalHandleCreate (Address: 0x18014cba8)
- MesEncodeIncrementalHandleCreate (Address: 0x18014cb88)
- MesHandleFree (Address: 0x18014cc50)
- MesIncrementalHandleReset (Address: 0x18014cbc0)
- NdrClientCall3 (Address: 0x18014cb28)
- NdrMesTypeAlignSize3 (Address: 0x18014cbe0)
- NdrMesTypeDecode3 (Address: 0x18014cbf0)
- NdrMesTypeEncode3 (Address: 0x18014cbe8)
- NdrServerCall2 (Address: 0x18014cb70)
- NdrServerCallAll (Address: 0x18014cb78)
- RpcBindingFree (Address: 0x18014cb40)
- RpcBindingFromStringBindingW (Address: 0x18014cb20)
- RpcBindingInqAuthClientW (Address: 0x18014cc28)
- RpcBindingInqMaxCalls (Address: 0x18014cb30)
- RpcBindingServerFromClient (Address: 0x18014cc48)
- RpcBindingSetAuthInfoW (Address: 0x18014cc38)
- RpcBindingToStringBindingW (Address: 0x18014cc30)
- RpcBindingVectorFree (Address: 0x18014cc60)
- RpcEpRegisterW (Address: 0x18014cc78)
- RpcExceptionFilter (Address: 0x18014cb48)
- RpcImpersonateClient (Address: 0x18014cb60)
- RpcMgmtEnableIdleCleanup (Address: 0x18014cc68)
- RpcRevertToSelf (Address: 0x18014cb50)
- RpcRevertToSelfEx (Address: 0x18014cbf8)
- RpcServerInqBindings (Address: 0x18014cc10)
- RpcServerInqCallAttributesW (Address: 0x18014cb68)
- RpcServerInqDefaultPrincNameW (Address: 0x18014cbb0)
- RpcServerRegisterAuthInfoW (Address: 0x18014cb98)
- RpcServerRegisterIf (Address: 0x18014cba0)
- RpcServerRegisterIf2 (Address: 0x18014cb80)
- RpcServerRegisterIf3 (Address: 0x18014cc70)
- RpcServerUseProtseqEpW (Address: 0x18014cb90)
- RpcSsGetContextBinding (Address: 0x18014cc40)
- RpcStringBindingComposeW (Address: 0x18014cb18)
- RpcStringBindingParseW (Address: 0x18014cc58)
- RpcStringFreeW (Address: 0x18014cb38)
- RpcUserFree (Address: 0x18014cc20)
- UuidEqual (Address: 0x18014cbc8)
- UuidFromStringW (Address: 0x18014cc18)
SspiCli.dll
- CredUnmarshalTargetInfo (Address: 0x18014cd38)
- LogonUserExExW (Address: 0x18014cce8)
- LsaCallAuthenticationPackage (Address: 0x18014ccd8)
- LsaConnectUntrusted (Address: 0x18014cd18)
- LsaDeregisterLogonProcess (Address: 0x18014cce0)
- LsaFreeReturnBuffer (Address: 0x18014cd28)
- LsaLogonUser (Address: 0x18014cd30)
- LsaLookupAuthenticationPackage (Address: 0x18014ccd0)
- LsaRegisterLogonProcess (Address: 0x18014ccc8)
- LsaRegisterPolicyChangeNotification (Address: 0x18014cc98)
- SecCacheSspiPackages (Address: 0x18014cc88)
- SeciAllocateAndSetCallFlags (Address: 0x18014cc90)
- SeciFreeCallContext (Address: 0x18014cca0)
- SspiCopyAuthIdentity (Address: 0x18014ccb0)
- SspiDecryptAuthIdentityEx (Address: 0x18014cd10)
- SspiEncodeStringsAsAuthIdentity (Address: 0x18014ccc0)
- SspiEncryptAuthIdentityEx (Address: 0x18014ccf8)
- SspiFreeAuthIdentity (Address: 0x18014ccb8)
- SspiLocalFree (Address: 0x18014cd00)
- SspiMarshalAuthIdentity (Address: 0x18014cd08)
- SspiUnmarshalAuthIdentity (Address: 0x18014cd20)
- SspiUnmarshalAuthIdentityInternal (Address: 0x18014ccf0)
- SspiValidateAuthIdentity (Address: 0x18014cca8)
WLDAP32.dll
- (Address: 0x18014cd48)
- (Address: 0x18014cd50)
- (Address: 0x18014cd58)
- (Address: 0x18014cd60)
- (Address: 0x18014cd68)
- (Address: 0x18014cd70)
- (Address: 0x18014cd78)
- (Address: 0x18014cd80)
- (Address: 0x18014cd88)
- (Address: 0x18014cd90)
- (Address: 0x18014cd98)
WS2_32.dll
- ntohl (Address: 0x18014cda8)