PasswordEnrollmentManager.dll

Description: In-Proc WinRT server for PasswordEnrollmentManager

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6328

Architecture: 64-bit

Operating System: Windows NT

SHA256: 64ab6db3f4582e742e0e32d4169c1fcc

File Size: 267.0 KB

Uploaded At: Dec. 1, 2025, 7:36 a.m.

Views: 4

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x56c0)
  • DllGetActivationFactory (Ordinal: 2, Address: 0x53f0)
  • DllGetClassObject (Ordinal: 3, Address: 0x55d0)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180030798)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateFreeThreadedMarshaler (Address: 0x1800307c8)
  • CoCreateInstance (Address: 0x1800307c0)
  • CoGetInterfaceAndReleaseStream (Address: 0x1800307a8)
  • CoMarshalInterface (Address: 0x1800307f8)
  • CoReleaseMarshalData (Address: 0x1800307e8)
  • CoTaskMemAlloc (Address: 0x1800307e0)
  • CoTaskMemFree (Address: 0x1800307d0)
  • CoTaskMemRealloc (Address: 0x1800307d8)
  • CoWaitForMultipleHandles (Address: 0x1800307b8)
  • CreateStreamOnHGlobal (Address: 0x1800307f0)
  • PropVariantClear (Address: 0x1800307b0)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x180030808)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180030820)
  • IsDebuggerPresent (Address: 0x180030818)
  • OutputDebugStringW (Address: 0x180030828)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180030838)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180030848)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180030868)
  • RaiseException (Address: 0x180030878)
  • SetLastError (Address: 0x180030870)
  • SetUnhandledExceptionFilter (Address: 0x180030860)
  • UnhandledExceptionFilter (Address: 0x180030858)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180030888)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180030898)
  • HeapAlloc (Address: 0x1800308a8)
  • HeapFree (Address: 0x1800308a0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1800308b8)
  • LocalFree (Address: 0x1800308c0)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x1800308d0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1800308e8)
  • FindResourceExW (Address: 0x1800308f8)
  • GetModuleFileNameA (Address: 0x180030910)
  • GetModuleHandleExW (Address: 0x180030918)
  • GetModuleHandleW (Address: 0x1800308e0)
  • GetProcAddress (Address: 0x1800308f0)
  • LoadResource (Address: 0x180030900)
  • LockResource (Address: 0x180030908)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180030928)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180030940)
  • GetCurrentProcessId (Address: 0x180030938)
  • GetCurrentThread (Address: 0x180030960)
  • GetCurrentThreadId (Address: 0x180030950)
  • OpenProcessToken (Address: 0x180030958)
  • OpenThreadToken (Address: 0x180030968)
  • TerminateProcess (Address: 0x180030948)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180030978)
  • OpenProcess (Address: 0x180030980)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180030990)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800309c8)
  • RegCreateKeyExW (Address: 0x1800309b0)
  • RegEnumValueW (Address: 0x1800309a8)
  • RegGetValueW (Address: 0x1800309c0)
  • RegOpenKeyExW (Address: 0x1800309d8)
  • RegQueryInfoKeyW (Address: 0x1800309b8)
  • RegQueryValueExW (Address: 0x1800309d0)
  • RegSetValueExW (Address: 0x1800309a0)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800309e8)
  • RtlLookupFunctionEntry (Address: 0x1800309f0)
  • RtlVirtualUnwind (Address: 0x1800309f8)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • StrChrW (Address: 0x180030a08)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringW (Address: 0x180030a18)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x180030a28)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180030a98)
  • AcquireSRWLockShared (Address: 0x180030a88)
  • CreateEventExW (Address: 0x180030a70)
  • CreateEventW (Address: 0x180030a58)
  • CreateMutexExW (Address: 0x180030aa8)
  • CreateSemaphoreExW (Address: 0x180030ae0)
  • DeleteCriticalSection (Address: 0x180030a68)
  • EnterCriticalSection (Address: 0x180030a38)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180030a78)
  • InitializeCriticalSectionEx (Address: 0x180030a60)
  • InitializeSRWLock (Address: 0x180030a40)
  • LeaveCriticalSection (Address: 0x180030a50)
  • OpenEventW (Address: 0x180030ae8)
  • OpenSemaphoreW (Address: 0x180030ab0)
  • ReleaseMutex (Address: 0x180030ac0)
  • ReleaseSemaphore (Address: 0x180030ad8)
  • ReleaseSRWLockExclusive (Address: 0x180030aa0)
  • ReleaseSRWLockShared (Address: 0x180030a90)
  • ResetEvent (Address: 0x180030ac8)
  • SetEvent (Address: 0x180030a48)
  • TryAcquireSRWLockExclusive (Address: 0x180030a80)
  • WaitForSingleObject (Address: 0x180030ad0)
  • WaitForSingleObjectEx (Address: 0x180030ab8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180030b08)
  • InitOnceComplete (Address: 0x180030b00)
  • InitOnceExecuteOnce (Address: 0x180030af8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x180030b28)
  • GetSystemTimeAsFileTime (Address: 0x180030b18)
  • GetVersionExW (Address: 0x180030b20)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180030b38)
  • CreateThreadpoolTimer (Address: 0x180030b48)
  • SetThreadpoolTimer (Address: 0x180030b40)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180030b50)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180030b60)
  • EncodePointer (Address: 0x180030b68)
api-ms-win-core-winrt-error-l1-1-0.dll
  • GetRestrictedErrorInfo (Address: 0x180030b78)
  • RoOriginateError (Address: 0x180030b98)
  • RoOriginateErrorW (Address: 0x180030b80)
  • RoTransformError (Address: 0x180030b88)
  • SetRestrictedErrorInfo (Address: 0x180030b90)
api-ms-win-core-winrt-error-l1-1-1.dll
  • IsErrorPropagationEnabled (Address: 0x180030ba8)
  • RoGetMatchingRestrictedErrorInfo (Address: 0x180030bb0)
  • RoReportFailedDelegate (Address: 0x180030bb8)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180030bc8)
  • RoGetActivationFactory (Address: 0x180030bd0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCompareStringOrdinal (Address: 0x180030be8)
  • WindowsCreateString (Address: 0x180030c00)
  • WindowsCreateStringReference (Address: 0x180030be0)
  • WindowsDeleteString (Address: 0x180030bf0)
  • WindowsDuplicateString (Address: 0x180030bf8)
  • WindowsGetStringRawBuffer (Address: 0x180030c08)
  • WindowsIsStringEmpty (Address: 0x180030c18)
  • WindowsStringHasEmbeddedNull (Address: 0x180030c10)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x180030c88)
  • __CxxFrameHandler3 (Address: 0x180030cd0)
  • __CxxFrameHandler4 (Address: 0x180030d00)
  • __std_terminate (Address: 0x180030cf8)
  • _CxxThrowException (Address: 0x180030cd8)
  • _o___std_exception_copy (Address: 0x180030cf0)
  • _o___std_exception_destroy (Address: 0x180030ce8)
  • _o___std_type_info_destroy_list (Address: 0x180030ce0)
  • _o___stdio_common_vsnprintf_s (Address: 0x180030cc0)
  • _o___stdio_common_vswprintf (Address: 0x180030cb8)
  • _o__callnewh (Address: 0x180030ca0)
  • _o__cexit (Address: 0x180030c98)
  • _o__configure_narrow_argv (Address: 0x180030c90)
  • _o__crt_atexit (Address: 0x180030d08)
  • _o__errno (Address: 0x180030cb0)
  • _o__execute_onexit_table (Address: 0x180030ca8)
  • _o__initialize_narrow_environment (Address: 0x180030c28)
  • _o__initialize_onexit_table (Address: 0x180030c30)
  • _o__invalid_parameter_noinfo (Address: 0x180030c38)
  • _o__purecall (Address: 0x180030c40)
  • _o__register_onexit_function (Address: 0x180030c48)
  • _o__seh_filter_dll (Address: 0x180030c50)
  • _o__wcsnicmp (Address: 0x180030c58)
  • _o__wtoi (Address: 0x180030c68)
  • _o_free (Address: 0x180030c70)
  • _o_malloc (Address: 0x180030c78)
  • _o_terminate (Address: 0x180030c80)
  • memcmp (Address: 0x180030d10)
  • memcpy (Address: 0x180030d18)
  • memmove (Address: 0x180030c60)
  • wcschr (Address: 0x180030cc8)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180030d30)
  • _initterm_e (Address: 0x180030d28)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180030d40)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x180030d60)
  • EventRegister (Address: 0x180030d50)
  • EventSetInformation (Address: 0x180030d70)
  • EventUnregister (Address: 0x180030d68)
  • EventWriteTransfer (Address: 0x180030d58)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • EnumDisplayDevicesW (Address: 0x180030d80)
  • GetSystemMetrics (Address: 0x180030d88)
api-ms-win-power-base-l1-1-0.dll
  • PowerDeterminePlatformRoleEx (Address: 0x180030d98)
api-ms-win-security-base-l1-1-0.dll
  • AllocateAndInitializeSid (Address: 0x180030dd8)
  • CheckTokenMembership (Address: 0x180030de0)
  • CopySid (Address: 0x180030df0)
  • CreateWellKnownSid (Address: 0x180030da8)
  • DuplicateToken (Address: 0x180030db8)
  • FreeSid (Address: 0x180030de8)
  • GetSidSubAuthority (Address: 0x180030dc8)
  • GetSidSubAuthorityCount (Address: 0x180030dc0)
  • GetTokenInformation (Address: 0x180030dd0)
  • IsValidSid (Address: 0x180030db0)
api-ms-win-security-lsalookup-l1-1-2.dll
  • LsaLookupUserAccountType (Address: 0x180030e00)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180030e18)
  • ConvertStringSidToSidW (Address: 0x180030e10)
api-ms-win-shcore-sysinfo-l1-1-0.dll
  • IsOS (Address: 0x180030e28)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolAllowThreadReuse (Address: 0x180030e38)
  • SHTaskPoolQueueTask (Address: 0x180030e40)
netutils.dll
  • NetApiBufferFree (Address: 0x180030e50)
ntdll.dll
  • NtQueryInformationToken (Address: 0x180030e60)
  • RtlAcquireResourceExclusive (Address: 0x180030e88)
  • RtlDeleteResource (Address: 0x180030e98)
  • RtlInitializeResource (Address: 0x180030e80)
  • RtlInitString (Address: 0x180030e68)
  • RtlIsMultiSessionSku (Address: 0x180030e70)
  • RtlIsMultiUsersInSessionSku (Address: 0x180030e78)
  • RtlNtStatusToDosError (Address: 0x180030ea0)
  • RtlReleaseResource (Address: 0x180030e90)
OLEAUT32.dll
  • SysAllocString (Address: 0x1800306c0)
  • SysFreeString (Address: 0x1800306d0)
  • VariantClear (Address: 0x1800306c8)
PROPSYS.dll
  • PropVariantToBoolean (Address: 0x1800306e8)
  • PropVariantToUInt32 (Address: 0x1800306e0)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x180030740)
  • I_RpcMapWin32Status (Address: 0x180030720)
  • NdrClientCall3 (Address: 0x180030718)
  • RpcBindingBind (Address: 0x180030730)
  • RpcBindingCreateW (Address: 0x180030708)
  • RpcBindingFree (Address: 0x180030728)
  • RpcBindingFromStringBindingW (Address: 0x180030700)
  • RpcSsDestroyClientContext (Address: 0x180030710)
  • RpcStringBindingComposeW (Address: 0x1800306f8)
  • RpcStringFreeW (Address: 0x180030738)
samcli.dll
  • NetUserGetInfo (Address: 0x180030eb0)
SHCORE.dll
  • (Address: 0x180030750)
SspiCli.dll
  • GetUserNameExW (Address: 0x180030788)
  • LsaCallAuthenticationPackage (Address: 0x180030780)
  • LsaConnectUntrusted (Address: 0x180030778)
  • LsaDeregisterLogonProcess (Address: 0x180030770)
  • LsaFreeReturnBuffer (Address: 0x180030760)
  • LsaLookupAuthenticationPackage (Address: 0x180030768)