OmaDmAgent.dll

Description: omadmagent

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: a824ac66b88faa1319c97ead1df7bafa

File Size: 225.5 KB

Uploaded At: Dec. 1, 2025, 7:35 a.m.

Views: 3

Exported Functions

  • OmaDmRunPostSessionWork (Ordinal: 1, Address: 0x4ac0)
  • ResourceManagerUninstallWmiApp (Ordinal: 2, Address: 0x5c40)

Imported DLLs & Functions

ADVAPI32.dll
  • CheckTokenMembership (Address: 0x18002b920)
  • ConvertSidToStringSidW (Address: 0x18002b8f0)
  • CopySid (Address: 0x18002b8d8)
  • CreateProcessAsUserW (Address: 0x18002b968)
  • EventRegister (Address: 0x18002b970)
  • EventSetInformation (Address: 0x18002b988)
  • EventUnregister (Address: 0x18002b980)
  • EventWriteTransfer (Address: 0x18002b960)
  • GetLengthSid (Address: 0x18002b8d0)
  • GetTokenInformation (Address: 0x18002b8c8)
  • ImpersonateLoggedOnUser (Address: 0x18002b928)
  • OpenProcessToken (Address: 0x18002b8e8)
  • OpenThreadToken (Address: 0x18002b8e0)
  • RegCloseKey (Address: 0x18002b900)
  • RegCreateKeyExW (Address: 0x18002b8c0)
  • RegDeleteKeyExW (Address: 0x18002b918)
  • RegDeleteValueW (Address: 0x18002b940)
  • RegEnumKeyExW (Address: 0x18002b8f8)
  • RegEnumValueW (Address: 0x18002b948)
  • RegGetValueW (Address: 0x18002b958)
  • RegOpenCurrentUser (Address: 0x18002b930)
  • RegOpenKeyExW (Address: 0x18002b910)
  • RegQueryInfoKeyW (Address: 0x18002b938)
  • RegQueryValueExW (Address: 0x18002b908)
  • RegSetValueExW (Address: 0x18002b8b8)
  • RevertToSelf (Address: 0x18002b950)
  • TraceMessage (Address: 0x18002b978)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x18002bc90)
  • RoTransformError (Address: 0x18002bc88)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x18002bcb8)
  • RoGetActivationFactory (Address: 0x18002bca8)
  • RoInitialize (Address: 0x18002bcb0)
  • RoUninitialize (Address: 0x18002bca0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x18002bce0)
  • WindowsCreateStringReference (Address: 0x18002bcd8)
  • WindowsDeleteString (Address: 0x18002bcc8)
  • WindowsGetStringRawBuffer (Address: 0x18002bcd0)
DMCmnUtils.dll
  • DmGetActiveUserSid (Address: 0x18002b9a0)
  • DmGetCurrentUserSid (Address: 0x18002b998)
  • DmGetUserTokenFromSid (Address: 0x18002b9b8)
  • DmImpersonate (Address: 0x18002b9b0)
  • DmRevertToSelf (Address: 0x18002b9a8)
  • OmaDmRegistryGetDWORD (Address: 0x18002b9c0)
dmEnrollEngine.DLL
  • (Address: 0x18002bd00)
  • GetEnrollmentSID (Address: 0x18002bcf0)
  • GetEnrollmentType (Address: 0x18002bcf8)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18002ba08)
  • AcquireSRWLockShared (Address: 0x18002ba98)
  • CloseHandle (Address: 0x18002b9e8)
  • CloseThreadpoolTimer (Address: 0x18002bb38)
  • CreateEventW (Address: 0x18002bb60)
  • CreateFileW (Address: 0x18002bab0)
  • CreateMutexExW (Address: 0x18002ba00)
  • CreateSemaphoreExW (Address: 0x18002bb00)
  • CreateThread (Address: 0x18002bb90)
  • CreateThreadpoolTimer (Address: 0x18002bb48)
  • DebugBreak (Address: 0x18002ba30)
  • DeleteCriticalSection (Address: 0x18002bbb8)
  • DeleteFileW (Address: 0x18002bb78)
  • DisableThreadLibraryCalls (Address: 0x18002bb10)
  • EnterCriticalSection (Address: 0x18002bb98)
  • ExpandEnvironmentStringsW (Address: 0x18002bb50)
  • FormatMessageW (Address: 0x18002bac8)
  • GetCurrentProcess (Address: 0x18002ba70)
  • GetCurrentProcessId (Address: 0x18002ba18)
  • GetCurrentThread (Address: 0x18002bb88)
  • GetCurrentThreadId (Address: 0x18002bae0)
  • GetLastError (Address: 0x18002ba48)
  • GetModuleFileNameA (Address: 0x18002bb08)
  • GetModuleHandleExW (Address: 0x18002baf8)
  • GetModuleHandleW (Address: 0x18002ba28)
  • GetProcAddress (Address: 0x18002b9f8)
  • GetProcessHeap (Address: 0x18002ba20)
  • GetSystemDirectoryW (Address: 0x18002bad0)
  • GetSystemTimeAsFileTime (Address: 0x18002ba88)
  • GetTickCount (Address: 0x18002ba90)
  • HeapAlloc (Address: 0x18002b9f0)
  • HeapFree (Address: 0x18002bac0)
  • InitializeCriticalSection (Address: 0x18002bba8)
  • InitializeCriticalSectionEx (Address: 0x18002bb40)
  • InitializeSRWLock (Address: 0x18002bb18)
  • IsDebuggerPresent (Address: 0x18002ba38)
  • LeaveCriticalSection (Address: 0x18002bba0)
  • LocalAlloc (Address: 0x18002bbc0)
  • LocalFree (Address: 0x18002bbb0)
  • OpenSemaphoreW (Address: 0x18002b9e0)
  • OutputDebugStringW (Address: 0x18002b9d0)
  • QueryPerformanceCounter (Address: 0x18002ba80)
  • RaiseException (Address: 0x18002bb68)
  • ReleaseMutex (Address: 0x18002bad8)
  • ReleaseSemaphore (Address: 0x18002ba60)
  • ReleaseSRWLockExclusive (Address: 0x18002baa0)
  • ReleaseSRWLockShared (Address: 0x18002baa8)
  • RtlCaptureContext (Address: 0x18002baf0)
  • RtlLookupFunctionEntry (Address: 0x18002ba50)
  • RtlVirtualUnwind (Address: 0x18002ba58)
  • SetEvent (Address: 0x18002bb58)
  • SetLastError (Address: 0x18002bab8)
  • SetThreadpoolTimer (Address: 0x18002bb28)
  • SetUnhandledExceptionFilter (Address: 0x18002ba68)
  • Sleep (Address: 0x18002ba40)
  • TerminateProcess (Address: 0x18002ba78)
  • UnhandledExceptionFilter (Address: 0x18002bb70)
  • WaitForSingleObject (Address: 0x18002bae8)
  • WaitForSingleObjectEx (Address: 0x18002b9d8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18002bb30)
  • WideCharToMultiByte (Address: 0x18002bb80)
  • WriteFile (Address: 0x18002bb20)
  • WTSGetActiveConsoleSessionId (Address: 0x18002ba10)
MDMRegistration.DLL
  • IsDeviceRegisteredWithManagement (Address: 0x18002bbd8)
  • UnregisterDeviceWithManagement (Address: 0x18002bbd0)
mi.dll
  • MI_Application_InitializeV1 (Address: 0x18002bd10)
msvcp110_win.dll
  • ?_Add_vtordisp1@?$basic_istream@DU?$char_traits@D@std@@@std@@UEAAXXZ (Address: 0x18002bd98)
  • ?_Add_vtordisp2@?$basic_ios@DU?$char_traits@D@std@@@std@@UEAAXXZ (Address: 0x18002bd90)
  • ?_BADOFF@std@@3_JB (Address: 0x18002bdd0)
  • ?_Fiopen@std@@YAPEAU_iobuf@@PEBGHH@Z (Address: 0x18002bd28)
  • ?_Getcat@?$codecvt@DDH@std@@SA_KPEAPEBVfacet@locale@2@PEBV42@@Z (Address: 0x18002bda0)
  • ?_Getgloballocale@locale@std@@CAPEAV_Locimp@12@XZ (Address: 0x18002bd60)
  • ?_Gndec@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAPEADXZ (Address: 0x18002bdf0)
  • ?_Init@?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAAXXZ (Address: 0x18002bdc8)
  • ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ (Address: 0x18002bd68)
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x18002be00)
  • ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAAXXZ (Address: 0x18002bd70)
  • ?_Winerror_map@std@@YAPEBDH@Z (Address: 0x18002be10)
  • ?_Xbad_alloc@std@@YAXXZ (Address: 0x18002be28)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x18002be08)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x18002be18)
  • ??0_Lockit@std@@QEAA@H@Z (Address: 0x18002bd58)
  • ??0?$basic_ios@DU?$char_traits@D@std@@@std@@IEAA@XZ (Address: 0x18002bd48)
  • ??0?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA@PEAV?$basic_streambuf@DU?$char_traits@D@std@@@1@_N@Z (Address: 0x18002bde8)
  • ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IEAA@XZ (Address: 0x18002bdc0)
  • ??1_Lockit@std@@QEAA@XZ (Address: 0x18002bd20)
  • ??1?$basic_ios@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x18002bda8)
  • ??1?$basic_istream@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x18002bd50)
  • ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UEAA@XZ (Address: 0x18002bdf8)
  • ??Bid@locale@std@@QEAA_KXZ (Address: 0x18002bdb0)
  • ?always_noconv@codecvt_base@std@@QEBA_NXZ (Address: 0x18002bd30)
  • ?getloc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEBA?AVlocale@2@XZ (Address: 0x18002bdb8)
  • ?id@?$codecvt@DDH@std@@2V0locale@2@A (Address: 0x18002bd40)
  • ?in@?$codecvt@DDH@std@@QEBAHAEAHPEBD1AEAPEBDPEAD3AEAPEAD@Z (Address: 0x18002bde0)
  • ?out@?$codecvt@DDH@std@@QEBAHAEAHPEBD1AEAPEBDPEAD3AEAPEAD@Z (Address: 0x18002bd38)
  • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z (Address: 0x18002be20)
  • ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JXZ (Address: 0x18002bd78)
  • ?unshift@?$codecvt@DDH@std@@QEBAHAEAHPEAD1AEAPEAD@Z (Address: 0x18002bdd8)
  • ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEAD_J@Z (Address: 0x18002bd80)
  • ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MEAA_JPEBD_J@Z (Address: 0x18002bd88)
msvcrt.dll
  • __C_specific_handler (Address: 0x18002bf40)
  • __CxxFrameHandler3 (Address: 0x18002bfc8)
  • __dllonexit (Address: 0x18002bf20)
  • _amsg_exit (Address: 0x18002bf58)
  • _callnewh (Address: 0x18002bf68)
  • _CxxThrowException (Address: 0x18002bee8)
  • _fseeki64 (Address: 0x18002be68)
  • _initterm (Address: 0x18002bf48)
  • _lock (Address: 0x18002bf30)
  • _onexit (Address: 0x18002bf18)
  • _purecall (Address: 0x18002bf98)
  • _snwprintf_s (Address: 0x18002bed8)
  • _unlock (Address: 0x18002bf28)
  • _vsnprintf_s (Address: 0x18002bf78)
  • _vsnwprintf (Address: 0x18002bfb8)
  • _wcsicmp (Address: 0x18002bfa8)
  • _wcsnicmp (Address: 0x18002bea8)
  • _wtoi (Address: 0x18002bed0)
  • _XcptFilter (Address: 0x18002bf60)
  • ??_V@YAXPEAX@Z (Address: 0x18002bfc0)
  • ??0bad_cast@@QEAA@AEBV0@@Z (Address: 0x18002be48)
  • ??0bad_cast@@QEAA@PEBD@Z (Address: 0x18002be38)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18002bf80)
  • ??0exception@@QEAA@XZ (Address: 0x18002bf88)
  • ??1bad_cast@@UEAA@XZ (Address: 0x18002be40)
  • ??1exception@@UEAA@XZ (Address: 0x18002bf90)
  • ??1type_info@@UEAA@XZ (Address: 0x18002bf10)
  • ??3@YAXPEAX@Z (Address: 0x18002bfa0)
  • ?terminate@@YAXXZ (Address: 0x18002bf38)
  • fclose (Address: 0x18002be50)
  • fflush (Address: 0x18002be80)
  • fgetc (Address: 0x18002be98)
  • fgetpos (Address: 0x18002be60)
  • fputc (Address: 0x18002be90)
  • free (Address: 0x18002bf50)
  • fsetpos (Address: 0x18002be70)
  • fwrite (Address: 0x18002be58)
  • malloc (Address: 0x18002bf70)
  • memcmp (Address: 0x18002bfd0)
  • memcpy (Address: 0x18002bef8)
  • memcpy_s (Address: 0x18002bfb0)
  • memmove (Address: 0x18002bf00)
  • memmove_s (Address: 0x18002bea0)
  • memset (Address: 0x18002bf08)
  • realloc (Address: 0x18002bec8)
  • setvbuf (Address: 0x18002be78)
  • toupper (Address: 0x18002bee0)
  • towlower (Address: 0x18002bec0)
  • ungetc (Address: 0x18002be88)
  • wcscmp (Address: 0x18002bfe0)
  • wcscpy_s (Address: 0x18002bfd8)
  • wcsncmp (Address: 0x18002bef0)
  • wcstol (Address: 0x18002beb0)
  • wcstoul (Address: 0x18002beb8)
ole32.dll
  • CLSIDFromString (Address: 0x18002c028)
  • CoCreateGuid (Address: 0x18002c000)
  • CoCreateInstance (Address: 0x18002c018)
  • CoGetApartmentType (Address: 0x18002c020)
  • CoInitializeEx (Address: 0x18002bff0)
  • CoSetProxyBlanket (Address: 0x18002c030)
  • CoTaskMemAlloc (Address: 0x18002c038)
  • CoTaskMemFree (Address: 0x18002c010)
  • CoUninitialize (Address: 0x18002bff8)
  • StringFromGUID2 (Address: 0x18002c008)
OLEAUT32.dll
  • SysAllocString (Address: 0x18002bbe8)
  • SysFreeString (Address: 0x18002bbf0)
omadmapi.dll
  • (Address: 0x18002c048)
  • (Address: 0x18002c050)
RPCRT4.dll
  • RpcStringFreeW (Address: 0x18002bc08)
  • UuidFromStringW (Address: 0x18002bc10)
  • UuidToStringW (Address: 0x18002bc00)
SHELL32.dll
  • SHCreateDirectoryExW (Address: 0x18002bc28)
  • SHGetFolderPathW (Address: 0x18002bc30)
  • SHGetSpecialFolderPathW (Address: 0x18002bc20)
SHLWAPI.dll
  • SHCreateStreamOnFileEx (Address: 0x18002bc48)
  • UrlUnescapeW (Address: 0x18002bc40)
sppc.dll
  • SLClose (Address: 0x18002c080)
  • SLGetLicensingStatusInformation (Address: 0x18002c078)
  • SLGetProductSkuInformation (Address: 0x18002c060)
  • SLGetSLIDList (Address: 0x18002c070)
  • SLOpen (Address: 0x18002c068)
urlmon.dll
  • IsValidURL (Address: 0x18002c090)
WSClient.dll
  • WSLicenseClose (Address: 0x18002bc60)
  • WSLicenseInstallLicense (Address: 0x18002bc58)
  • WSLicenseOpen (Address: 0x18002bc68)
WTSAPI32.dll
  • WTSQueryUserToken (Address: 0x18002bc78)