ngcrecovery.dll

Description: Windows Hello Recovery Helper

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 0b516a98371ad648c202db8fb7b83ec5

File Size: 277.5 KB

Uploaded At: Dec. 1, 2025, 7:35 a.m.

Views: 6

Exported Functions

  • NgcIsPinRecoveryEnabled (Ordinal: 1, Address: 0x1a6a0)
  • NgcProtectPinRecoverySecret (Ordinal: 2, Address: 0x1ab60)
  • NgcRecoverPin (Ordinal: 3, Address: 0x1b520)
  • NgcRecoverPinSilent (Ordinal: 4, Address: 0x1bf00)
  • NgcVerifyPinRecoverySecret (Ordinal: 5, Address: 0x1c810)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180034190)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateFreeThreadedMarshaler (Address: 0x1800341c0)
  • CoInitializeEx (Address: 0x1800341b0)
  • CoTaskMemAlloc (Address: 0x1800341b8)
  • CoTaskMemFree (Address: 0x1800341a0)
  • CoUninitialize (Address: 0x1800341a8)
  • CoWaitForMultipleHandles (Address: 0x1800341c8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800341d8)
  • IsDebuggerPresent (Address: 0x1800341e0)
  • OutputDebugStringW (Address: 0x1800341e8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800341f8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180034208)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180034218)
  • RaiseException (Address: 0x180034238)
  • SetLastError (Address: 0x180034230)
  • SetUnhandledExceptionFilter (Address: 0x180034220)
  • UnhandledExceptionFilter (Address: 0x180034228)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180034248)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180034258)
  • HeapAlloc (Address: 0x180034260)
  • HeapFree (Address: 0x180034268)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180034280)
  • LocalFree (Address: 0x180034278)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180034290)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x1800342a0)
  • GetModuleHandleExW (Address: 0x1800342b8)
  • GetModuleHandleW (Address: 0x1800342b0)
  • GetProcAddress (Address: 0x1800342a8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800342c8)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800342d8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800342f0)
  • GetCurrentProcessId (Address: 0x1800342e8)
  • GetCurrentThreadId (Address: 0x1800342f8)
  • TerminateProcess (Address: 0x180034300)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180034310)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180034320)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180034350)
  • RegEnumKeyExW (Address: 0x180034338)
  • RegGetValueW (Address: 0x180034330)
  • RegOpenKeyExW (Address: 0x180034348)
  • RegQueryInfoKeyW (Address: 0x180034340)
  • RegQueryValueExW (Address: 0x180034358)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180034370)
  • RtlLookupFunctionEntry (Address: 0x180034368)
  • RtlVirtualUnwind (Address: 0x180034378)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800343a8)
  • AcquireSRWLockShared (Address: 0x1800343c8)
  • CreateEventExW (Address: 0x180034408)
  • CreateEventW (Address: 0x1800343f0)
  • CreateMutexExW (Address: 0x180034388)
  • CreateSemaphoreExW (Address: 0x180034428)
  • DeleteCriticalSection (Address: 0x180034420)
  • EnterCriticalSection (Address: 0x180034400)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800343d8)
  • InitializeCriticalSectionEx (Address: 0x180034390)
  • InitializeSRWLock (Address: 0x1800343d0)
  • LeaveCriticalSection (Address: 0x1800343c0)
  • OpenSemaphoreW (Address: 0x1800343b8)
  • ReleaseMutex (Address: 0x1800343e8)
  • ReleaseSemaphore (Address: 0x180034410)
  • ReleaseSRWLockExclusive (Address: 0x180034398)
  • ReleaseSRWLockShared (Address: 0x1800343b0)
  • ResetEvent (Address: 0x1800343e0)
  • SetEvent (Address: 0x1800343a0)
  • WaitForSingleObject (Address: 0x1800343f8)
  • WaitForSingleObjectEx (Address: 0x180034418)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180034438)
  • InitOnceComplete (Address: 0x180034440)
  • Sleep (Address: 0x180034448)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180034460)
  • GetTickCount (Address: 0x180034458)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180034488)
  • CreateThreadpoolTimer (Address: 0x180034478)
  • SetThreadpoolTimer (Address: 0x180034480)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180034470)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1800344a0)
  • RoGetActivationFactory (Address: 0x180034498)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x1800344b8)
  • WindowsDeleteString (Address: 0x1800344b0)
  • WindowsGetStringRawBuffer (Address: 0x1800344c0)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x180034560)
  • __CxxFrameHandler3 (Address: 0x180034568)
  • __CxxFrameHandler4 (Address: 0x1800345e0)
  • __std_terminate (Address: 0x1800345d8)
  • _CxxThrowException (Address: 0x180034570)
  • _o___std_exception_copy (Address: 0x1800345f0)
  • _o___std_exception_destroy (Address: 0x1800345e8)
  • _o___std_type_info_destroy_list (Address: 0x1800345d0)
  • _o___stdio_common_vsnprintf_s (Address: 0x1800345c8)
  • _o___stdio_common_vsprintf_s (Address: 0x1800345c0)
  • _o___stdio_common_vswprintf (Address: 0x1800345b8)
  • _o__callnewh (Address: 0x1800345a0)
  • _o__cexit (Address: 0x180034598)
  • _o__configure_narrow_argv (Address: 0x180034590)
  • _o__crt_atexit (Address: 0x180034588)
  • _o__errno (Address: 0x180034580)
  • _o__execute_onexit_table (Address: 0x180034578)
  • _o__free_base (Address: 0x1800344d0)
  • _o__initialize_narrow_environment (Address: 0x1800344d8)
  • _o__initialize_onexit_table (Address: 0x1800344e0)
  • _o__invalid_parameter_noinfo (Address: 0x1800344e8)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x1800344f0)
  • _o__malloc_base (Address: 0x1800344f8)
  • _o__purecall (Address: 0x180034500)
  • _o__register_onexit_function (Address: 0x180034508)
  • _o__seh_filter_dll (Address: 0x180034510)
  • _o__set_errno (Address: 0x180034518)
  • _o__wcsicmp (Address: 0x180034520)
  • _o_free (Address: 0x180034530)
  • _o_malloc (Address: 0x180034538)
  • _o_strncpy_s (Address: 0x180034540)
  • _o_strtol (Address: 0x180034548)
  • _o_terminate (Address: 0x180034550)
  • _o_toupper (Address: 0x180034558)
  • memcmp (Address: 0x1800345f8)
  • memcpy (Address: 0x180034600)
  • memmove (Address: 0x180034528)
  • strchr (Address: 0x1800345b0)
  • strrchr (Address: 0x1800345a8)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180034618)
  • _initterm_e (Address: 0x180034610)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180034628)
  • strcmp (Address: 0x180034630)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x180034658)
  • EventProviderEnabled (Address: 0x180034660)
  • EventRegister (Address: 0x180034640)
  • EventSetInformation (Address: 0x180034648)
  • EventUnregister (Address: 0x180034650)
  • EventWriteTransfer (Address: 0x180034668)
api-ms-win-security-base-l1-1-0.dll
  • CopySid (Address: 0x180034680)
  • EqualSid (Address: 0x180034688)
  • GetLengthSid (Address: 0x180034698)
  • GetTokenInformation (Address: 0x180034690)
  • IsValidSid (Address: 0x180034678)
api-ms-win-security-lsalookup-l1-1-0.dll
  • LookupAccountSidLocalW (Address: 0x1800346a8)
api-ms-win-security-lsalookup-l1-1-2.dll
  • LsaLookupUserAccountType (Address: 0x1800346b8)
api-ms-win-security-lsapolicy-l1-1-0.dll
  • LsaClose (Address: 0x1800346e0)
  • LsaFreeMemory (Address: 0x1800346d0)
  • LsaLookupSids2 (Address: 0x1800346c8)
  • LsaOpenPolicy (Address: 0x1800346d8)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x1800346f0)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800346f8)
  • ConvertStringSidToSidW (Address: 0x180034700)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x180034710)
bcrypt.dll
  • BCryptDestroyKey (Address: 0x180034720)
  • BCryptEncrypt (Address: 0x180034728)
  • BCryptGenerateSymmetricKey (Address: 0x180034730)
  • BCryptGenRandom (Address: 0x180034738)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x180034060)
  • CertCloseStore (Address: 0x180034090)
  • CertCreateCertificateContext (Address: 0x180034040)
  • CertFindCertificateInStore (Address: 0x1800340a8)
  • CertFreeCertificateChain (Address: 0x1800340b0)
  • CertFreeCertificateContext (Address: 0x180034058)
  • CertGetCertificateChain (Address: 0x180034050)
  • CertGetEnhancedKeyUsage (Address: 0x180034048)
  • CertOpenStore (Address: 0x1800340a0)
  • CertVerifyCertificateChainPolicy (Address: 0x180034098)
  • CryptBinaryToStringA (Address: 0x180034080)
  • CryptBinaryToStringW (Address: 0x180034088)
  • CryptExportPublicKeyInfoEx (Address: 0x180034068)
  • CryptStringToBinaryA (Address: 0x180034078)
  • CryptStringToBinaryW (Address: 0x180034070)
msvcp_win.dll
  • _Query_perf_counter (Address: 0x1800347e0)
  • _Query_perf_frequency (Address: 0x1800347e8)
  • ?_Addfac@_Locimp@locale@std@@AEAAXPEAVfacet@23@_K@Z (Address: 0x1800347a0)
  • ?_Decref@facet@locale@std@@UEAAPEAV_Facet_base@3@XZ (Address: 0x1800347d0)
  • ?_Incref@facet@locale@std@@UEAAXXZ (Address: 0x180034780)
  • ?_Init@locale@std@@CAPEAV_Locimp@12@_N@Z (Address: 0x1800347c8)
  • ?_New_Locimp@_Locimp@locale@std@@CAPEAV123@AEBV123@@Z (Address: 0x180034798)
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x1800347c0)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800347f0)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180034800)
  • ??0?$codecvt@GDU_Mbstatet@@@std@@QEAA@_K@Z (Address: 0x1800347d8)
  • ??1?$codecvt@GDU_Mbstatet@@@std@@MEAA@XZ (Address: 0x180034770)
  • ??4?$_Yarn@D@std@@QEAAAEAV01@PEBD@Z (Address: 0x1800347b8)
  • ??Bid@locale@std@@QEAA_KXZ (Address: 0x1800347a8)
  • ?do_always_noconv@?$codecvt@GDU_Mbstatet@@@std@@MEBA_NXZ (Address: 0x180034778)
  • ?do_encoding@?$codecvt@GDU_Mbstatet@@@std@@MEBAHXZ (Address: 0x180034768)
  • ?do_in@?$codecvt@GDU_Mbstatet@@@std@@MEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAG3AEAPEAG@Z (Address: 0x180034760)
  • ?do_length@?$codecvt@GDU_Mbstatet@@@std@@MEBAHAEAU_Mbstatet@@PEBD1_K@Z (Address: 0x180034748)
  • ?do_max_length@?$codecvt@GDU_Mbstatet@@@std@@MEBAHXZ (Address: 0x1800347f8)
  • ?do_out@?$codecvt@GDU_Mbstatet@@@std@@MEBAHAEAU_Mbstatet@@PEBG1AEAPEBGPEAD3AEAPEAD@Z (Address: 0x180034758)
  • ?do_unshift@?$codecvt@GDU_Mbstatet@@@std@@MEBAHAEAU_Mbstatet@@PEAD1AEAPEAD@Z (Address: 0x180034750)
  • ?id@?$codecvt@GDU_Mbstatet@@@std@@2V0locale@2@A (Address: 0x1800347b0)
  • ?in@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBD1AEAPEBDPEAG3AEAPEAG@Z (Address: 0x180034790)
  • ?out@?$codecvt@GDU_Mbstatet@@@std@@QEBAHAEAU_Mbstatet@@PEBG1AEAPEBGPEAD3AEAPEAD@Z (Address: 0x180034788)
ncrypt.dll
  • NCryptEncrypt (Address: 0x180034820)
  • NCryptFreeObject (Address: 0x180034828)
  • NCryptGetProperty (Address: 0x180034810)
  • NCryptImportKey (Address: 0x180034838)
  • NCryptOpenKey (Address: 0x180034818)
  • NCryptOpenStorageProvider (Address: 0x180034830)
ntdll.dll
  • NtQuerySystemInformation (Address: 0x180034848)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x1800340d0)
  • RpcBindingBind (Address: 0x180034100)
  • RpcBindingCreateW (Address: 0x1800340f8)
  • RpcBindingFree (Address: 0x1800340c0)
  • RpcExceptionFilter (Address: 0x1800340c8)
  • RpcStringFreeW (Address: 0x1800340d8)
  • UuidCreate (Address: 0x1800340f0)
  • UuidFromStringW (Address: 0x1800340e8)
  • UuidToStringW (Address: 0x1800340e0)
UMPDC.dll
  • Pdcv2ActivationClientActivate (Address: 0x180034120)
  • Pdcv2ActivationClientDeactivate (Address: 0x180034128)
  • Pdcv2ActivationClientRegister (Address: 0x180034110)
  • Pdcv2ActivationClientRenewActivation (Address: 0x180034130)
  • Pdcv2ActivationClientUnregister (Address: 0x180034118)
WINHTTP.dll
  • WinHttpAddRequestHeaders (Address: 0x180034178)
  • WinHttpCloseHandle (Address: 0x180034150)
  • WinHttpConnect (Address: 0x180034168)
  • WinHttpOpen (Address: 0x180034170)
  • WinHttpOpenRequest (Address: 0x180034160)
  • WinHttpQueryDataAvailable (Address: 0x180034180)
  • WinHttpReadData (Address: 0x180034148)
  • WinHttpReceiveResponse (Address: 0x180034158)
  • WinHttpSendRequest (Address: 0x180034140)