offreg.dll
Description: Offline registry DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5129
Architecture: 64-bit
Operating System: Windows NT
SHA256: 6997580caa3c0c8244198d16c8f167c0
File Size: 88.0 KB
Uploaded At: Dec. 1, 2025, 7:35 a.m.
Views: 4
Exported Functions
- ORCloseHive (Ordinal: 1, Address: 0x1490)
- ORCloseKey (Ordinal: 2, Address: 0x2c20)
- ORCreateHive (Ordinal: 3, Address: 0x1060)
- ORCreateKey (Ordinal: 4, Address: 0x1c80)
- ORDeleteKey (Ordinal: 5, Address: 0x2350)
- ORDeleteValue (Ordinal: 6, Address: 0x3d80)
- OREnumKey (Ordinal: 7, Address: 0x2810)
- OREnumValue (Ordinal: 8, Address: 0x3b50)
- ORGetKeySecurity (Ordinal: 9, Address: 0x42c0)
- ORGetValue (Ordinal: 10, Address: 0x32b0)
- ORGetVersion (Ordinal: 11, Address: 0x4630)
- ORGetVirtualFlags (Ordinal: 12, Address: 0x2cb0)
- ORMergeHives (Ordinal: 13, Address: 0x5c50)
- OROpenHive (Ordinal: 14, Address: 0x1390)
- OROpenHiveByHandle (Ordinal: 15, Address: 0x1380)
- OROpenKey (Ordinal: 16, Address: 0x1ad0)
- ORQueryInfoKey (Ordinal: 17, Address: 0x2550)
- ORRenameKey (Ordinal: 18, Address: 0x2e20)
- ORSaveHive (Ordinal: 19, Address: 0x1670)
- ORSetKeySecurity (Ordinal: 20, Address: 0x4470)
- ORSetValue (Ordinal: 21, Address: 0x3960)
- ORSetVirtualFlags (Ordinal: 22, Address: 0x2d50)
Imported DLLs & Functions
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180014148)
- SetUnhandledExceptionFilter (Address: 0x180014150)
- UnhandledExceptionFilter (Address: 0x180014158)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x180014170)
- FlushFileBuffers (Address: 0x180014178)
- GetFileSizeEx (Address: 0x180014188)
- GetFinalPathNameByHandleW (Address: 0x180014168)
- ReadFile (Address: 0x180014190)
- WriteFile (Address: 0x180014180)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800141a0)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleHandleW (Address: 0x1800141b0)
- GetProcAddress (Address: 0x1800141b8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1800141e8)
- GetCurrentProcessId (Address: 0x1800141d8)
- GetCurrentThreadId (Address: 0x1800141c8)
- TerminateProcess (Address: 0x1800141f0)
- TlsAlloc (Address: 0x1800141e0)
- TlsFree (Address: 0x1800141d0)
- TlsGetValue (Address: 0x1800141f8)
- TlsSetValue (Address: 0x180014200)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180014210)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x180014220)
- RtlLookupFunctionEntry (Address: 0x180014230)
- RtlVirtualUnwind (Address: 0x180014228)
api-ms-win-core-synch-l1-1-0.dll
- DeleteCriticalSection (Address: 0x180014240)
- EnterCriticalSection (Address: 0x180014258)
- InitializeCriticalSectionAndSpinCount (Address: 0x180014248)
- LeaveCriticalSection (Address: 0x180014250)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x180014268)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x180014280)
- GetTickCount (Address: 0x180014278)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x180014320)
- CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x180014290)
- DestroyPrivateObjectSecurity (Address: 0x1800142a8)
- GetAce (Address: 0x1800142e8)
- GetLengthSid (Address: 0x180014318)
- GetSecurityDescriptorControl (Address: 0x1800142d0)
- GetSecurityDescriptorLength (Address: 0x1800142f0)
- GetSidLengthRequired (Address: 0x1800142d8)
- GetSidSubAuthority (Address: 0x1800142c8)
- InitializeAcl (Address: 0x1800142f8)
- InitializeSecurityDescriptor (Address: 0x180014308)
- InitializeSid (Address: 0x180014298)
- IsValidSecurityDescriptor (Address: 0x1800142a0)
- IsValidSid (Address: 0x1800142c0)
- MakeSelfRelativeSD (Address: 0x1800142b8)
- SetPrivateObjectSecurityEx (Address: 0x180014310)
- SetSecurityDescriptorDacl (Address: 0x180014300)
- SetSecurityDescriptorGroup (Address: 0x1800142b0)
- SetSecurityDescriptorOwner (Address: 0x1800142e0)
msvcrt.dll
- __C_specific_handler (Address: 0x180014330)
- _aligned_free (Address: 0x180014368)
- _aligned_malloc (Address: 0x180014370)
- _amsg_exit (Address: 0x180014398)
- _initterm (Address: 0x180014338)
- _wcsicmp (Address: 0x180014358)
- _wcsnicmp (Address: 0x1800143a0)
- _XcptFilter (Address: 0x180014350)
- free (Address: 0x180014390)
- malloc (Address: 0x180014340)
- memcmp (Address: 0x1800143b0)
- memcpy (Address: 0x1800143a8)
- memmove (Address: 0x180014348)
- memset (Address: 0x1800143b8)
- qsort (Address: 0x180014360)
- wcscat_s (Address: 0x180014380)
- wcsncpy_s (Address: 0x180014388)
- wcsnlen (Address: 0x180014378)
ntdll.dll
- RtlAcquireSRWLockExclusive (Address: 0x180014408)
- RtlAllocateHeap (Address: 0x180014418)
- RtlFindNextForwardRunClear (Address: 0x1800143e8)
- RtlFreeHeap (Address: 0x180014410)
- RtlInitializeSRWLock (Address: 0x1800143f8)
- RtlInitUnicodeString (Address: 0x1800143c8)
- RtlNtStatusToDosError (Address: 0x180014420)
- RtlNumberOfSetBits (Address: 0x1800143f0)
- RtlReleaseSRWLockExclusive (Address: 0x180014400)
- RtlRunOnceBeginInitialize (Address: 0x1800143e0)
- RtlRunOnceComplete (Address: 0x1800143d8)
- RtlUpcaseUnicodeChar (Address: 0x1800143d0)