PenImc_cor3.dll

Description: PenImc

Authors: © Microsoft Corporation. All rights reserved.

Version: 6.0.2724.7003

Architecture: 64-bit

Operating System: Windows NT

SHA256: 44027f5ed425df1fa31db20f6d2f621f

File Size: 158.3 KB

Uploaded At: Dec. 3, 2025, 2:41 a.m.

Views: 6

Exported Functions

  • CreateResetEvent (Ordinal: 1, Address: 0x80f0)
  • DestroyResetEvent (Ordinal: 2, Address: 0x8140)
  • DllCanUnloadNow (Ordinal: 3, Address: 0x17f0)
  • DllGetClassObject (Ordinal: 4, Address: 0x1830)
  • DllRegisterServer (Ordinal: 5, Address: 0x19c0)
  • DllUnregisterServer (Ordinal: 6, Address: 0x1a80)
  • GetLastSystemEventData (Ordinal: 7, Address: 0x8050)
  • GetPenEvent (Ordinal: 8, Address: 0x7f00)
  • GetPenEventMultiple (Ordinal: 9, Address: 0x7f90)
  • GetProxyDllInfo (Ordinal: 10, Address: 0x1160)
  • LockWispObjectFromGit (Ordinal: 11, Address: 0xd9a0)
  • RaiseResetEvent (Ordinal: 12, Address: 0x8170)
  • RegisterDllForSxSCOM (Ordinal: 13, Address: 0xd8c0)
  • UnlockWispObjectFromGit (Ordinal: 14, Address: 0xd9e0)

Imported DLLs & Functions

ADVAPI32.dll
  • AllocateAndInitializeSid (Address: 0x180018018)
  • ConvertSidToStringSidW (Address: 0x180018000)
  • EqualSid (Address: 0x180018010)
  • FreeSid (Address: 0x180018008)
  • GetTokenInformation (Address: 0x180018020)
  • OpenProcessToken (Address: 0x180018028)
  • RegCloseKey (Address: 0x180018060)
  • RegCreateKeyExW (Address: 0x180018038)
  • RegDeleteKeyW (Address: 0x180018068)
  • RegDeleteValueW (Address: 0x180018030)
  • RegEnumKeyExW (Address: 0x180018050)
  • RegOpenKeyExW (Address: 0x180018048)
  • RegQueryInfoKeyW (Address: 0x180018058)
  • RegSetValueExW (Address: 0x180018040)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x180018460)
  • _recalloc (Address: 0x180018458)
  • calloc (Address: 0x180018440)
  • free (Address: 0x180018448)
  • malloc (Address: 0x180018438)
  • realloc (Address: 0x180018450)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x1800184a0)
  • _configure_narrow_argv (Address: 0x1800184d8)
  • _crt_atexit (Address: 0x1800184a8)
  • _errno (Address: 0x1800184c8)
  • _execute_onexit_table (Address: 0x1800184b0)
  • _initialize_narrow_environment (Address: 0x1800184d0)
  • _initialize_onexit_table (Address: 0x1800184c0)
  • _initterm (Address: 0x180018490)
  • _initterm_e (Address: 0x180018498)
  • _invalid_parameter_noinfo (Address: 0x180018478)
  • _register_onexit_function (Address: 0x1800184b8)
  • _seh_filter_dll (Address: 0x180018470)
  • abort (Address: 0x180018480)
  • terminate (Address: 0x180018488)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vswprintf (Address: 0x1800184e8)
api-ms-win-crt-string-l1-1-0.dll
  • strcpy_s (Address: 0x1800184f8)
  • wcscat_s (Address: 0x180018508)
  • wcscpy_s (Address: 0x180018500)
  • wcsncmp (Address: 0x180018510)
  • wcsncpy_s (Address: 0x180018518)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1800181b0)
  • ActivateActCtx (Address: 0x180018168)
  • CancelWaitableTimer (Address: 0x180018158)
  • CloseHandle (Address: 0x180018208)
  • CreateActCtxW (Address: 0x180018160)
  • CreateEventW (Address: 0x1800180d0)
  • CreateMutexW (Address: 0x180018200)
  • CreateThread (Address: 0x180018140)
  • CreateWaitableTimerW (Address: 0x180018268)
  • DecodePointer (Address: 0x180018090)
  • DeleteCriticalSection (Address: 0x180018080)
  • EncodePointer (Address: 0x180018098)
  • EnterCriticalSection (Address: 0x1800180a0)
  • FindResourceW (Address: 0x180018220)
  • FreeLibrary (Address: 0x180018260)
  • GetCurrentProcess (Address: 0x180018128)
  • GetCurrentProcessId (Address: 0x1800180d8)
  • GetCurrentThreadId (Address: 0x1800182b0)
  • GetLastError (Address: 0x180018240)
  • GetModuleFileNameW (Address: 0x180018210)
  • GetModuleHandleW (Address: 0x180018250)
  • GetProcAddress (Address: 0x180018258)
  • GetSystemTimeAsFileTime (Address: 0x180018188)
  • GetThreadLocale (Address: 0x180018138)
  • InitializeCriticalSection (Address: 0x1800180c8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180018290)
  • InitializeCriticalSectionEx (Address: 0x1800180b0)
  • InitializeSListHead (Address: 0x180018180)
  • InterlockedFlushSList (Address: 0x1800181f8)
  • IsDebuggerPresent (Address: 0x180018198)
  • IsProcessorFeaturePresent (Address: 0x1800181c0)
  • IsWow64Process (Address: 0x180018120)
  • LeaveCriticalSection (Address: 0x1800180a8)
  • LoadLibraryExW (Address: 0x180018218)
  • LoadLibraryW (Address: 0x180018178)
  • LoadResource (Address: 0x180018228)
  • LocalFree (Address: 0x180018110)
  • lstrcmpiW (Address: 0x180018248)
  • MapViewOfFile (Address: 0x1800180f8)
  • MultiByteToWideChar (Address: 0x180018238)
  • OpenEventW (Address: 0x1800180e0)
  • OpenFileMappingW (Address: 0x1800180f0)
  • OpenMutexW (Address: 0x1800180e8)
  • OutputDebugStringW (Address: 0x180018130)
  • QueryPerformanceCounter (Address: 0x180018190)
  • QueueUserAPC (Address: 0x180018148)
  • RaiseException (Address: 0x180018088)
  • ReleaseMutex (Address: 0x1800180c0)
  • ReleaseSRWLockExclusive (Address: 0x1800181b8)
  • RtlCaptureContext (Address: 0x1800181e8)
  • RtlLookupFunctionEntry (Address: 0x1800182a8)
  • RtlPcToFileHeader (Address: 0x1800181f0)
  • RtlUnwindEx (Address: 0x1800182a0)
  • RtlVirtualUnwind (Address: 0x1800181e0)
  • SetEvent (Address: 0x180018108)
  • SetLastError (Address: 0x180018298)
  • SetThreadLocale (Address: 0x180018078)
  • SetUnhandledExceptionFilter (Address: 0x1800181d0)
  • SetWaitableTimer (Address: 0x180018150)
  • SignalObjectAndWait (Address: 0x180018118)
  • SizeofResource (Address: 0x180018230)
  • SleepConditionVariableSRW (Address: 0x1800181a0)
  • TerminateProcess (Address: 0x1800181c8)
  • TlsAlloc (Address: 0x180018288)
  • TlsFree (Address: 0x180018270)
  • TlsGetValue (Address: 0x180018280)
  • TlsSetValue (Address: 0x180018278)
  • UnhandledExceptionFilter (Address: 0x1800181d8)
  • UnmapViewOfFile (Address: 0x180018100)
  • VerSetConditionMask (Address: 0x180018170)
  • WaitForSingleObject (Address: 0x1800180b8)
  • WakeAllConditionVariable (Address: 0x1800181a8)
ole32.dll
  • CoCreateInstance (Address: 0x180018550)
  • CoGetApartmentType (Address: 0x180018558)
  • CoLockObjectExternal (Address: 0x180018540)
  • CoTaskMemAlloc (Address: 0x180018528)
  • CoTaskMemFree (Address: 0x180018538)
  • CoTaskMemRealloc (Address: 0x180018530)
  • StringFromGUID2 (Address: 0x180018548)
OLEAUT32.dll
  • LoadTypeLib (Address: 0x1800182d0)
  • RegisterTypeLib (Address: 0x1800182e0)
  • SysAllocString (Address: 0x1800182f0)
  • SysFreeString (Address: 0x1800182d8)
  • SysStringLen (Address: 0x1800182e8)
  • UnRegisterTypeLib (Address: 0x1800182c0)
  • VarUI4FromStr (Address: 0x1800182c8)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x180018370)
  • CStdStubBuffer_Connect (Address: 0x180018308)
  • CStdStubBuffer_CountRefs (Address: 0x180018358)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x180018360)
  • CStdStubBuffer_DebugServerRelease (Address: 0x180018340)
  • CStdStubBuffer_Disconnect (Address: 0x180018328)
  • CStdStubBuffer_Invoke (Address: 0x180018390)
  • CStdStubBuffer_IsIIDSupported (Address: 0x180018318)
  • CStdStubBuffer_QueryInterface (Address: 0x180018350)
  • IUnknown_AddRef_Proxy (Address: 0x180018388)
  • IUnknown_QueryInterface_Proxy (Address: 0x180018320)
  • IUnknown_Release_Proxy (Address: 0x180018368)
  • NdrCStdStubBuffer_Release (Address: 0x180018300)
  • NdrDllCanUnloadNow (Address: 0x180018310)
  • NdrDllGetClassObject (Address: 0x180018330)
  • NdrDllRegisterProxy (Address: 0x180018338)
  • NdrDllUnregisterProxy (Address: 0x180018380)
  • NdrOleAllocate (Address: 0x180018348)
  • NdrOleFree (Address: 0x180018378)
SHELL32.dll
  • ShellExecuteExW (Address: 0x1800183a0)
USER32.dll
  • CallNextHookEx (Address: 0x1800183c0)
  • CharNextW (Address: 0x1800183e8)
  • EqualRect (Address: 0x1800183d0)
  • GetDesktopWindow (Address: 0x180018428)
  • GetMonitorInfoW (Address: 0x180018420)
  • GetParent (Address: 0x1800183d8)
  • GetSystemMetrics (Address: 0x180018410)
  • GetWindow (Address: 0x1800183b0)
  • GetWindowRect (Address: 0x1800183b8)
  • GetWindowThreadProcessId (Address: 0x1800183e0)
  • IsWindow (Address: 0x180018400)
  • MonitorFromWindow (Address: 0x180018418)
  • MsgWaitForMultipleObjectsEx (Address: 0x1800183f8)
  • PeekMessageW (Address: 0x1800183f0)
  • SetWindowsHookExW (Address: 0x1800183c8)
  • UnhookWindowsHookEx (Address: 0x180018408)