mprdim.dll

Description: Dynamic Interface Manager

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6456

Architecture: 64-bit

Operating System: Windows NT

SHA256: 6f743aaca89851a9b0be591492a9a177

File Size: 545.0 KB

Uploaded At: Dec. 1, 2025, 7:33 a.m.

Views: 8

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ServiceMain (Ordinal: 1, Address: 0x8830)
  • SvchostPushServiceGlobals (Ordinal: 2, Address: 0x8220)

Imported DLLs & Functions

adsldpc.dll
  • ADSICloseDSObject (Address: 0x18005f698)
  • ADSICreateDSObject (Address: 0x18005f6a0)
  • ADSIGetObjectAttributes (Address: 0x18005f6a8)
  • ADSIOpenDSObject (Address: 0x18005f6b8)
  • ADSISetObjectAttributes (Address: 0x18005f6b0)
api-ms-win-core-com-l1-1-0.dll
  • CoInitializeEx (Address: 0x18005f6c8)
  • CoUninitialize (Address: 0x18005f6d0)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18005f6f0)
  • IsDebuggerPresent (Address: 0x18005f6e0)
  • OutputDebugStringW (Address: 0x18005f6e8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18005f700)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18005f710)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18005f738)
  • SetLastError (Address: 0x18005f720)
  • SetUnhandledExceptionFilter (Address: 0x18005f728)
  • UnhandledExceptionFilter (Address: 0x18005f730)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18005f748)
  • DuplicateHandle (Address: 0x18005f750)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18005f778)
  • HeapAlloc (Address: 0x18005f768)
  • HeapCreate (Address: 0x18005f770)
  • HeapDestroy (Address: 0x18005f788)
  • HeapFree (Address: 0x18005f760)
  • HeapReAlloc (Address: 0x18005f780)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18005f7a0)
  • LocalFree (Address: 0x18005f798)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x18005f7d0)
  • GetModuleFileNameA (Address: 0x18005f7d8)
  • GetModuleHandleExW (Address: 0x18005f7b0)
  • GetModuleHandleW (Address: 0x18005f7b8)
  • GetProcAddress (Address: 0x18005f7c0)
  • LoadLibraryExW (Address: 0x18005f7c8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18005f7e8)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18005f7f8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18005f808)
  • GetCurrentProcessId (Address: 0x18005f828)
  • GetCurrentThreadId (Address: 0x18005f830)
  • TerminateProcess (Address: 0x18005f810)
  • TlsGetValue (Address: 0x18005f818)
  • TlsSetValue (Address: 0x18005f820)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18005f840)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18005f850)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x18005f860)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18005f8f8)
  • AcquireSRWLockShared (Address: 0x18005f8f0)
  • CreateEventW (Address: 0x18005f900)
  • CreateMutexExW (Address: 0x18005f878)
  • CreateSemaphoreExW (Address: 0x18005f880)
  • DeleteCriticalSection (Address: 0x18005f8d8)
  • EnterCriticalSection (Address: 0x18005f8e8)
  • InitializeCriticalSection (Address: 0x18005f8e0)
  • InitializeCriticalSectionEx (Address: 0x18005f8b8)
  • InitializeSRWLock (Address: 0x18005f8c0)
  • LeaveCriticalSection (Address: 0x18005f890)
  • OpenSemaphoreW (Address: 0x18005f8a0)
  • ReleaseMutex (Address: 0x18005f870)
  • ReleaseSemaphore (Address: 0x18005f888)
  • ReleaseSRWLockExclusive (Address: 0x18005f8a8)
  • ReleaseSRWLockShared (Address: 0x18005f898)
  • SetEvent (Address: 0x18005f8c8)
  • WaitForSingleObject (Address: 0x18005f8d0)
  • WaitForSingleObjectEx (Address: 0x18005f8b0)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18005f910)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x18005f930)
  • GetSystemTimeAsFileTime (Address: 0x18005f928)
  • GetTickCount (Address: 0x18005f938)
  • GetTickCount64 (Address: 0x18005f920)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpool (Address: 0x18005f990)
  • CloseThreadpoolCleanupGroup (Address: 0x18005f988)
  • CloseThreadpoolCleanupGroupMembers (Address: 0x18005f980)
  • CloseThreadpoolTimer (Address: 0x18005f968)
  • CreateThreadpool (Address: 0x18005f9a8)
  • CreateThreadpoolCleanupGroup (Address: 0x18005f950)
  • CreateThreadpoolTimer (Address: 0x18005f960)
  • CreateThreadpoolWork (Address: 0x18005f998)
  • SetThreadpoolThreadMaximum (Address: 0x18005f948)
  • SetThreadpoolThreadMinimum (Address: 0x18005f958)
  • SetThreadpoolTimer (Address: 0x18005f978)
  • SubmitThreadpoolWork (Address: 0x18005f9a0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18005f970)
api-ms-win-devices-config-l1-1-1.dll
  • CM_Get_Device_IDW (Address: 0x18005f9b8)
  • CM_Locate_DevNodeW (Address: 0x18005f9c0)
api-ms-win-devices-query-l1-1-0.dll
  • DevCloseObjectQuery (Address: 0x18005f9d8)
  • DevCreateObjectQuery (Address: 0x18005f9d0)
api-ms-win-devices-swdevice-l1-1-0.dll
  • SwDeviceClose (Address: 0x18005f9e8)
  • SwDeviceCreate (Address: 0x18005f9f0)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheckAndAuditAlarmW (Address: 0x18005fa30)
  • AddAccessAllowedAce (Address: 0x18005fa58)
  • CheckTokenMembership (Address: 0x18005fa38)
  • CreatePrivateObjectSecurity (Address: 0x18005fa20)
  • DestroyPrivateObjectSecurity (Address: 0x18005fa10)
  • GetLengthSid (Address: 0x18005fa50)
  • GetSidLengthRequired (Address: 0x18005fa18)
  • GetSidSubAuthority (Address: 0x18005fa08)
  • InitializeAcl (Address: 0x18005fa48)
  • InitializeSecurityDescriptor (Address: 0x18005fa40)
  • InitializeSid (Address: 0x18005fa70)
  • IsValidSecurityDescriptor (Address: 0x18005fa28)
  • SetSecurityDescriptorDacl (Address: 0x18005fa68)
  • SetSecurityDescriptorGroup (Address: 0x18005fa60)
  • SetSecurityDescriptorOwner (Address: 0x18005fa00)
api-ms-win-service-core-l1-1-0.dll
  • RegisterServiceCtrlHandlerExW (Address: 0x18005fa88)
  • SetServiceStatus (Address: 0x18005fa80)
CRYPT32.dll
  • CertAddEncodedCertificateToStore (Address: 0x18005f3d8)
  • CertCloseStore (Address: 0x18005f400)
  • CertFreeCertificateContext (Address: 0x18005f408)
  • CertGetNameStringW (Address: 0x18005f3f0)
  • CertNameToStrW (Address: 0x18005f3e8)
  • CertOpenStore (Address: 0x18005f3e0)
  • CryptDecodeObjectEx (Address: 0x18005f3f8)
IPHLPAPI.DLL
  • CancelMibChangeNotify2 (Address: 0x18005f418)
  • CloseCompartment (Address: 0x18005f458)
  • ConvertInterfaceGuidToLuid (Address: 0x18005f438)
  • ConvertInterfaceLuidToAlias (Address: 0x18005f468)
  • ConvertInterfaceLuidToIndex (Address: 0x18005f428)
  • GetAdaptersAddresses (Address: 0x18005f448)
  • GetCurrentThreadCompartmentId (Address: 0x18005f430)
  • GetIfEntry2 (Address: 0x18005f440)
  • NotifyCompartmentChange (Address: 0x18005f460)
  • NotifyIpInterfaceChange (Address: 0x18005f470)
  • OpenCompartment (Address: 0x18005f450)
  • SetCurrentThreadCompartmentId (Address: 0x18005f420)
KERNEL32.dll
  • CreateMutexW (Address: 0x18005f480)
  • lstrcmpiW (Address: 0x18005f4a8)
  • QueueUserWorkItem (Address: 0x18005f4a0)
  • RegDeleteKeyExW (Address: 0x18005f488)
  • RegDeleteValueW (Address: 0x18005f498)
  • RegGetValueW (Address: 0x18005f490)
  • UnregisterWait (Address: 0x18005f4b0)
  • VerifyVersionInfoW (Address: 0x18005f4b8)
MPRDDM.dll
  • DDMAdminConnectionClearStats (Address: 0x18005f598)
  • DDMAdminConnectionEnum (Address: 0x18005f5c8)
  • DDMAdminConnectionEnumEx (Address: 0x18005f630)
  • DDMAdminConnectionGetInfo (Address: 0x18005f648)
  • DDMAdminConnectionGetInfoEx (Address: 0x18005f5a8)
  • DDMAdminInterfaceConnect (Address: 0x18005f568)
  • DDMAdminInterfaceDisconnect (Address: 0x18005f550)
  • DDMAdminPortClearStats (Address: 0x18005f580)
  • DDMAdminPortDisconnect (Address: 0x18005f5d8)
  • DDMAdminPortEnum (Address: 0x18005f5a0)
  • DDMAdminPortGetInfo (Address: 0x18005f508)
  • DDMAdminPortReset (Address: 0x18005f640)
  • DDMAdminRemoveQuarantine (Address: 0x18005f588)
  • DDMAdminRoutingDomainConnectionEnumEx (Address: 0x18005f5d0)
  • DDMAdminServerGetInfo (Address: 0x18005f5e0)
  • DDMAdminServerGetInfoEx (Address: 0x18005f590)
  • DDMAdminServerSetInfo (Address: 0x18005f5b0)
  • DDMAdminServerSetInfoEx (Address: 0x18005f5b8)
  • DDMAdminUpdateConnection (Address: 0x18005f5c0)
  • DDMAdminUpdateQoSPolicies (Address: 0x18005f570)
  • DDMConnectInterface (Address: 0x18005f4e0)
  • DdmDeleteIkev2PskPolicy (Address: 0x18005f528)
  • DDMDisconnectInterface (Address: 0x18005f628)
  • DDMGetIdentityAttributes (Address: 0x18005f4d0)
  • DdmGetKey (Address: 0x18005f618)
  • DDMHandleRoutingDomainConfigChange (Address: 0x18005f4e8)
  • DdmPlumbIkev2PskPolicy (Address: 0x18005f530)
  • DDMPlumbRDIkev2TunnelPolicy (Address: 0x18005f540)
  • DDMPostCleanup (Address: 0x18005f548)
  • DDMRegisterConnectionNotification (Address: 0x18005f578)
  • DDMSendUserMessage (Address: 0x18005f638)
  • DDMServiceInitialize (Address: 0x18005f4f0)
  • DDMServicePostListens (Address: 0x18005f560)
  • DdmSetKey (Address: 0x18005f610)
  • DDMTransportCreate (Address: 0x18005f4d8)
  • DdmUpdateGlobalPhoneBookContext (Address: 0x18005f500)
  • IfObjectConnectionChangeNotification (Address: 0x18005f5f8)
  • IfObjectFreePhonebookContext (Address: 0x18005f4f8)
  • IfObjectGetStatistics (Address: 0x18005f608)
  • IfObjectLoadDestinationInfo (Address: 0x18005f538)
  • IfObjectLoadPhonebookInfo (Address: 0x18005f5f0)
  • IfObjectSetDialoutHoursRestriction (Address: 0x18005f558)
  • IfObjectUpdatePbkInfo (Address: 0x18005f5e8)
  • MarkInterfaceAsReachable (Address: 0x18005f620)
  • RasConnectionInitiate (Address: 0x18005f600)
  • ReConnectInterface (Address: 0x18005f520)
  • ReConnectPersistentInterface (Address: 0x18005f510)
  • TimerQInsert (Address: 0x18005f4c8)
  • TimerQRemove (Address: 0x18005f518)
msvcrt.dll
  • __C_specific_handler (Address: 0x18005fbd0)
  • __CxxFrameHandler3 (Address: 0x18005fbf8)
  • __dllonexit (Address: 0x18005fab0)
  • __RTDynamicCast (Address: 0x18005fbf0)
  • _amsg_exit (Address: 0x18005fc10)
  • _callnewh (Address: 0x18005faf8)
  • _CxxThrowException (Address: 0x18005faf0)
  • _initterm (Address: 0x18005fad8)
  • _itow (Address: 0x18005fba8)
  • _itow_s (Address: 0x18005fbb0)
  • _lock (Address: 0x18005fac0)
  • _onexit (Address: 0x18005faa8)
  • _purecall (Address: 0x18005fb38)
  • _time64 (Address: 0x18005fbd8)
  • _unlock (Address: 0x18005fab8)
  • _vsnprintf (Address: 0x18005fb80)
  • _vsnprintf_s (Address: 0x18005fb28)
  • _vsnwprintf (Address: 0x18005fb90)
  • _wcsicmp (Address: 0x18005fbc0)
  • _wcsnicmp (Address: 0x18005fb08)
  • _XcptFilter (Address: 0x18005fae8)
  • ??_V@YAXPEAX@Z (Address: 0x18005fb60)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18005fb40)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18005fb00)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18005fbe0)
  • ??0exception@@QEAA@XZ (Address: 0x18005fbe8)
  • ??1exception@@UEAA@XZ (Address: 0x18005fc00)
  • ??1type_info@@UEAA@XZ (Address: 0x18005fac8)
  • ??3@YAXPEAX@Z (Address: 0x18005fc08)
  • ?terminate@@YAXXZ (Address: 0x18005fad0)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18005fb48)
  • free (Address: 0x18005fb58)
  • malloc (Address: 0x18005fb50)
  • memcmp (Address: 0x18005fbb8)
  • memcpy (Address: 0x18005fae0)
  • memcpy_s (Address: 0x18005fb30)
  • memmove (Address: 0x18005fa98)
  • memmove_s (Address: 0x18005fb20)
  • memset (Address: 0x18005faa0)
  • scanf_s (Address: 0x18005fb78)
  • srand (Address: 0x18005fbc8)
  • strcmp (Address: 0x18005fc18)
  • strncmp (Address: 0x18005fb70)
  • swscanf (Address: 0x18005fb88)
  • wcschr (Address: 0x18005fb10)
  • wcscpy_s (Address: 0x18005fb18)
  • wcsnlen (Address: 0x18005fb68)
  • wcsrchr (Address: 0x18005fb98)
  • wcsstr (Address: 0x18005fba0)
NSI.dll
  • NsiAllocateAndGetTable (Address: 0x18005f668)
  • NsiFreeTable (Address: 0x18005f660)
  • NsiGetParameter (Address: 0x18005f658)
ntdll.dll
  • RtlAcquireResourceExclusive (Address: 0x18005fcc0)
  • RtlAcquireResourceShared (Address: 0x18005fcc8)
  • RtlCaptureContext (Address: 0x18005fcb0)
  • RtlCreateTimer (Address: 0x18005fc68)
  • RtlCreateTimerQueue (Address: 0x18005fc70)
  • RtlDeleteResource (Address: 0x18005fca8)
  • RtlDeleteTimer (Address: 0x18005fc78)
  • RtlDeleteTimerQueueEx (Address: 0x18005fc60)
  • RtlGUIDFromString (Address: 0x18005fc88)
  • RtlInitializeResource (Address: 0x18005fca0)
  • RtlInitUnicodeString (Address: 0x18005fc40)
  • RtlIpv4AddressToStringW (Address: 0x18005fc28)
  • RtlIpv4StringToAddressW (Address: 0x18005fc48)
  • RtlIpv6AddressToStringW (Address: 0x18005fc50)
  • RtlIpv6StringToAddressW (Address: 0x18005fc30)
  • RtlLookupFunctionEntry (Address: 0x18005fc98)
  • RtlNtStatusToDosError (Address: 0x18005fc38)
  • RtlQueueWorkItem (Address: 0x18005fc80)
  • RtlReleaseResource (Address: 0x18005fcb8)
  • RtlVirtualUnwind (Address: 0x18005fc90)
  • VerSetConditionMask (Address: 0x18005fc58)
rtutils.dll
  • RouterLogDeregisterW (Address: 0x18005fcf8)
  • RouterLogEventStringW (Address: 0x18005fcf0)
  • RouterLogEventW (Address: 0x18005fce8)
  • RouterLogRegisterW (Address: 0x18005fd00)
  • TraceDeregisterA (Address: 0x18005fcd8)
  • TraceRegisterExA (Address: 0x18005fce0)
USER32.dll
  • LoadStringW (Address: 0x18005f678)
  • RegisterDeviceNotificationW (Address: 0x18005f680)
  • UnregisterDeviceNotification (Address: 0x18005f688)