offreg.dll

Description: Offline registry DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5129

Architecture: 64-bit

Operating System: Windows NT

SHA256: 6997580caa3c0c8244198d16c8f167c0

File Size: 88.0 KB

Uploaded At: Dec. 1, 2025, 7:35 a.m.

Views: 4

Exported Functions

  • ORCloseHive (Ordinal: 1, Address: 0x1490)
  • ORCloseKey (Ordinal: 2, Address: 0x2c20)
  • ORCreateHive (Ordinal: 3, Address: 0x1060)
  • ORCreateKey (Ordinal: 4, Address: 0x1c80)
  • ORDeleteKey (Ordinal: 5, Address: 0x2350)
  • ORDeleteValue (Ordinal: 6, Address: 0x3d80)
  • OREnumKey (Ordinal: 7, Address: 0x2810)
  • OREnumValue (Ordinal: 8, Address: 0x3b50)
  • ORGetKeySecurity (Ordinal: 9, Address: 0x42c0)
  • ORGetValue (Ordinal: 10, Address: 0x32b0)
  • ORGetVersion (Ordinal: 11, Address: 0x4630)
  • ORGetVirtualFlags (Ordinal: 12, Address: 0x2cb0)
  • ORMergeHives (Ordinal: 13, Address: 0x5c50)
  • OROpenHive (Ordinal: 14, Address: 0x1390)
  • OROpenHiveByHandle (Ordinal: 15, Address: 0x1380)
  • OROpenKey (Ordinal: 16, Address: 0x1ad0)
  • ORQueryInfoKey (Ordinal: 17, Address: 0x2550)
  • ORRenameKey (Ordinal: 18, Address: 0x2e20)
  • ORSaveHive (Ordinal: 19, Address: 0x1670)
  • ORSetKeySecurity (Ordinal: 20, Address: 0x4470)
  • ORSetValue (Ordinal: 21, Address: 0x3960)
  • ORSetVirtualFlags (Ordinal: 22, Address: 0x2d50)

Imported DLLs & Functions

api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180014148)
  • SetUnhandledExceptionFilter (Address: 0x180014150)
  • UnhandledExceptionFilter (Address: 0x180014158)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x180014170)
  • FlushFileBuffers (Address: 0x180014178)
  • GetFileSizeEx (Address: 0x180014188)
  • GetFinalPathNameByHandleW (Address: 0x180014168)
  • ReadFile (Address: 0x180014190)
  • WriteFile (Address: 0x180014180)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800141a0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleHandleW (Address: 0x1800141b0)
  • GetProcAddress (Address: 0x1800141b8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800141e8)
  • GetCurrentProcessId (Address: 0x1800141d8)
  • GetCurrentThreadId (Address: 0x1800141c8)
  • TerminateProcess (Address: 0x1800141f0)
  • TlsAlloc (Address: 0x1800141e0)
  • TlsFree (Address: 0x1800141d0)
  • TlsGetValue (Address: 0x1800141f8)
  • TlsSetValue (Address: 0x180014200)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180014210)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180014220)
  • RtlLookupFunctionEntry (Address: 0x180014230)
  • RtlVirtualUnwind (Address: 0x180014228)
api-ms-win-core-synch-l1-1-0.dll
  • DeleteCriticalSection (Address: 0x180014240)
  • EnterCriticalSection (Address: 0x180014258)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180014248)
  • LeaveCriticalSection (Address: 0x180014250)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180014268)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180014280)
  • GetTickCount (Address: 0x180014278)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x180014320)
  • CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x180014290)
  • DestroyPrivateObjectSecurity (Address: 0x1800142a8)
  • GetAce (Address: 0x1800142e8)
  • GetLengthSid (Address: 0x180014318)
  • GetSecurityDescriptorControl (Address: 0x1800142d0)
  • GetSecurityDescriptorLength (Address: 0x1800142f0)
  • GetSidLengthRequired (Address: 0x1800142d8)
  • GetSidSubAuthority (Address: 0x1800142c8)
  • InitializeAcl (Address: 0x1800142f8)
  • InitializeSecurityDescriptor (Address: 0x180014308)
  • InitializeSid (Address: 0x180014298)
  • IsValidSecurityDescriptor (Address: 0x1800142a0)
  • IsValidSid (Address: 0x1800142c0)
  • MakeSelfRelativeSD (Address: 0x1800142b8)
  • SetPrivateObjectSecurityEx (Address: 0x180014310)
  • SetSecurityDescriptorDacl (Address: 0x180014300)
  • SetSecurityDescriptorGroup (Address: 0x1800142b0)
  • SetSecurityDescriptorOwner (Address: 0x1800142e0)
msvcrt.dll
  • __C_specific_handler (Address: 0x180014330)
  • _aligned_free (Address: 0x180014368)
  • _aligned_malloc (Address: 0x180014370)
  • _amsg_exit (Address: 0x180014398)
  • _initterm (Address: 0x180014338)
  • _wcsicmp (Address: 0x180014358)
  • _wcsnicmp (Address: 0x1800143a0)
  • _XcptFilter (Address: 0x180014350)
  • free (Address: 0x180014390)
  • malloc (Address: 0x180014340)
  • memcmp (Address: 0x1800143b0)
  • memcpy (Address: 0x1800143a8)
  • memmove (Address: 0x180014348)
  • memset (Address: 0x1800143b8)
  • qsort (Address: 0x180014360)
  • wcscat_s (Address: 0x180014380)
  • wcsncpy_s (Address: 0x180014388)
  • wcsnlen (Address: 0x180014378)
ntdll.dll
  • RtlAcquireSRWLockExclusive (Address: 0x180014408)
  • RtlAllocateHeap (Address: 0x180014418)
  • RtlFindNextForwardRunClear (Address: 0x1800143e8)
  • RtlFreeHeap (Address: 0x180014410)
  • RtlInitializeSRWLock (Address: 0x1800143f8)
  • RtlInitUnicodeString (Address: 0x1800143c8)
  • RtlNtStatusToDosError (Address: 0x180014420)
  • RtlNumberOfSetBits (Address: 0x1800143f0)
  • RtlReleaseSRWLockExclusive (Address: 0x180014400)
  • RtlRunOnceBeginInitialize (Address: 0x1800143e0)
  • RtlRunOnceComplete (Address: 0x1800143d8)
  • RtlUpcaseUnicodeChar (Address: 0x1800143d0)