PasswordEnrollmentManager.dll

Description: In-Proc WinRT server for PasswordEnrollmentManager

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.26100.7824

Architecture: 64-bit

Operating System: Windows NT

SHA256: 92b6468776a0387522c6e3607ea287a5

File Size: 220.0 KB

Uploaded At: March 8, 2026, 7:39 p.m.

Views: 12

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x8bf0)
  • DllGetActivationFactory (Ordinal: 2, Address: 0x8c20)
  • DllGetClassObject (Ordinal: 3, Address: 0x8c60)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180024960)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateFreeThreadedMarshaler (Address: 0x1800249a0)
  • CoCreateInstance (Address: 0x180024980)
  • CoGetInterfaceAndReleaseStream (Address: 0x180024998)
  • CoMarshalInterface (Address: 0x180024988)
  • CoReleaseMarshalData (Address: 0x1800249c0)
  • CoTaskMemAlloc (Address: 0x1800249b0)
  • CoTaskMemFree (Address: 0x1800249a8)
  • CoTaskMemRealloc (Address: 0x180024970)
  • CoWaitForMultipleHandles (Address: 0x180024990)
  • CreateStreamOnHGlobal (Address: 0x180024978)
  • PropVariantClear (Address: 0x1800249b8)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x1800249d0)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800249e0)
  • IsDebuggerPresent (Address: 0x1800249f0)
  • OutputDebugStringW (Address: 0x1800249e8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180024a00)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180024a10)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180024a40)
  • RaiseException (Address: 0x180024a30)
  • SetLastError (Address: 0x180024a38)
  • SetUnhandledExceptionFilter (Address: 0x180024a20)
  • UnhandledExceptionFilter (Address: 0x180024a28)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180024a50)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180024a68)
  • HeapAlloc (Address: 0x180024a70)
  • HeapFree (Address: 0x180024a60)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180024a88)
  • LocalFree (Address: 0x180024a80)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180024a98)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180024ac0)
  • FindResourceExW (Address: 0x180024ad8)
  • GetModuleFileNameA (Address: 0x180024aa8)
  • GetModuleHandleExW (Address: 0x180024ab0)
  • GetModuleHandleW (Address: 0x180024ab8)
  • GetProcAddress (Address: 0x180024ae0)
  • LoadResource (Address: 0x180024ad0)
  • LockResource (Address: 0x180024ac8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180024af0)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180024b28)
  • GetCurrentProcessId (Address: 0x180024b20)
  • GetCurrentThread (Address: 0x180024b10)
  • GetCurrentThreadId (Address: 0x180024b08)
  • OpenProcessToken (Address: 0x180024b18)
  • OpenThreadToken (Address: 0x180024b00)
  • TerminateProcess (Address: 0x180024b30)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180024b40)
  • OpenProcess (Address: 0x180024b48)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180024b58)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180024b78)
  • RegCreateKeyExW (Address: 0x180024b98)
  • RegEnumValueW (Address: 0x180024ba0)
  • RegGetValueW (Address: 0x180024b88)
  • RegOpenKeyExW (Address: 0x180024b70)
  • RegQueryInfoKeyW (Address: 0x180024b90)
  • RegQueryValueExW (Address: 0x180024b80)
  • RegSetValueExW (Address: 0x180024b68)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180024bc0)
  • RtlLookupFunctionEntry (Address: 0x180024bb0)
  • RtlVirtualUnwind (Address: 0x180024bb8)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • StrChrW (Address: 0x180024bd0)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringW (Address: 0x180024be0)
  • WideCharToMultiByte (Address: 0x180024be8)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x180024bf8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180024c10)
  • AcquireSRWLockShared (Address: 0x180024c48)
  • CreateEventExW (Address: 0x180024c30)
  • CreateEventW (Address: 0x180024c58)
  • CreateMutexExW (Address: 0x180024c40)
  • CreateSemaphoreExW (Address: 0x180024ca8)
  • DeleteCriticalSection (Address: 0x180024c20)
  • EnterCriticalSection (Address: 0x180024cb0)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180024c28)
  • InitializeCriticalSectionEx (Address: 0x180024ca0)
  • InitializeSRWLock (Address: 0x180024c90)
  • LeaveCriticalSection (Address: 0x180024c50)
  • OpenEventW (Address: 0x180024cb8)
  • OpenSemaphoreW (Address: 0x180024c60)
  • ReleaseMutex (Address: 0x180024c78)
  • ReleaseSemaphore (Address: 0x180024c98)
  • ReleaseSRWLockExclusive (Address: 0x180024c08)
  • ReleaseSRWLockShared (Address: 0x180024c18)
  • ResetEvent (Address: 0x180024c80)
  • SetEvent (Address: 0x180024c38)
  • TryAcquireSRWLockExclusive (Address: 0x180024c70)
  • WaitForSingleObject (Address: 0x180024c88)
  • WaitForSingleObjectEx (Address: 0x180024c68)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180024cd8)
  • InitOnceComplete (Address: 0x180024cd0)
  • InitOnceExecuteOnce (Address: 0x180024cc8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x180024cf8)
  • GetSystemTimeAsFileTime (Address: 0x180024ce8)
  • GetVersionExW (Address: 0x180024cf0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180024d08)
  • CreateThreadpoolTimer (Address: 0x180024d18)
  • SetThreadpoolTimer (Address: 0x180024d10)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180024d20)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180024d30)
  • EncodePointer (Address: 0x180024d38)
api-ms-win-core-winrt-error-l1-1-0.dll
  • GetRestrictedErrorInfo (Address: 0x180024d48)
  • RoOriginateError (Address: 0x180024d60)
  • RoOriginateErrorW (Address: 0x180024d50)
  • RoTransformError (Address: 0x180024d58)
  • SetRestrictedErrorInfo (Address: 0x180024d68)
api-ms-win-core-winrt-error-l1-1-1.dll
  • IsErrorPropagationEnabled (Address: 0x180024d78)
  • RoGetMatchingRestrictedErrorInfo (Address: 0x180024d88)
  • RoReportFailedDelegate (Address: 0x180024d80)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180024d98)
  • RoGetActivationFactory (Address: 0x180024da0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCompareStringOrdinal (Address: 0x180024db8)
  • WindowsCreateString (Address: 0x180024dd0)
  • WindowsCreateStringReference (Address: 0x180024db0)
  • WindowsDeleteString (Address: 0x180024dc0)
  • WindowsDuplicateString (Address: 0x180024dc8)
  • WindowsGetStringRawBuffer (Address: 0x180024dd8)
  • WindowsIsStringEmpty (Address: 0x180024de8)
  • WindowsStringHasEmbeddedNull (Address: 0x180024de0)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x180024e58)
  • __current_exception (Address: 0x180024e60)
  • __current_exception_context (Address: 0x180024e68)
  • __CxxFrameHandler3 (Address: 0x180024ec8)
  • __CxxFrameHandler4 (Address: 0x180024ee0)
  • __std_terminate (Address: 0x180024ed8)
  • _CxxThrowException (Address: 0x180024ed0)
  • _o___std_exception_copy (Address: 0x180024e90)
  • _o___std_exception_destroy (Address: 0x180024e88)
  • _o___std_type_info_destroy_list (Address: 0x180024e70)
  • _o___stdio_common_vswprintf (Address: 0x180024ea0)
  • _o__callnewh (Address: 0x180024eb8)
  • _o__cexit (Address: 0x180024eb0)
  • _o__configure_narrow_argv (Address: 0x180024ea8)
  • _o__crt_atexit (Address: 0x180024e98)
  • _o__errno (Address: 0x180024e80)
  • _o__execute_onexit_table (Address: 0x180024e78)
  • _o__initialize_narrow_environment (Address: 0x180024df8)
  • _o__initialize_onexit_table (Address: 0x180024e00)
  • _o__invalid_parameter_noinfo (Address: 0x180024e08)
  • _o__purecall (Address: 0x180024e10)
  • _o__register_onexit_function (Address: 0x180024e18)
  • _o__seh_filter_dll (Address: 0x180024e20)
  • _o__wtoi (Address: 0x180024e38)
  • _o_free (Address: 0x180024e40)
  • _o_malloc (Address: 0x180024e48)
  • _o_terminate (Address: 0x180024e50)
  • memcmp (Address: 0x180024e28)
  • memcpy (Address: 0x180024ee8)
  • memmove (Address: 0x180024e30)
  • wcschr (Address: 0x180024ec0)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180024f00)
  • _initterm_e (Address: 0x180024ef8)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180024f10)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x180024f38)
  • EventRegister (Address: 0x180024f40)
  • EventSetInformation (Address: 0x180024f20)
  • EventUnregister (Address: 0x180024f30)
  • EventWriteTransfer (Address: 0x180024f28)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • EnumDisplayDevicesW (Address: 0x180024f50)
  • GetSystemMetrics (Address: 0x180024f58)
api-ms-win-power-base-l1-1-0.dll
  • PowerDeterminePlatformRoleEx (Address: 0x180024f68)
api-ms-win-security-base-l1-1-0.dll
  • CheckTokenMembership (Address: 0x180024f88)
  • CopySid (Address: 0x180024f80)
  • GetSidSubAuthority (Address: 0x180024f90)
  • GetSidSubAuthorityCount (Address: 0x180024f78)
  • GetTokenInformation (Address: 0x180024f98)
  • IsValidSid (Address: 0x180024fa0)
api-ms-win-security-lsalookup-l1-1-2.dll
  • LsaLookupUserAccountType (Address: 0x180024fb0)
api-ms-win-security-lsapolicy-l1-1-0.dll
  • LsaClose (Address: 0x180024fc0)
  • LsaFreeMemory (Address: 0x180024fd0)
  • LsaLookupSids (Address: 0x180024fd8)
  • LsaOpenPolicy (Address: 0x180024fc8)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180024fe8)
  • ConvertStringSidToSidW (Address: 0x180024ff0)
api-ms-win-shcore-sysinfo-l1-1-0.dll
  • IsOS (Address: 0x180025000)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolAllowThreadReuse (Address: 0x180025018)
  • SHTaskPoolQueueTask (Address: 0x180025010)
netutils.dll
  • NetApiBufferFree (Address: 0x180025028)
ntdll.dll
  • RtlAcquireResourceExclusive (Address: 0x180025050)
  • RtlDeleteResource (Address: 0x180025070)
  • RtlInitializeResource (Address: 0x180025038)
  • RtlInitString (Address: 0x180025060)
  • RtlIsMultiSessionSku (Address: 0x180025040)
  • RtlIsMultiUsersInSessionSku (Address: 0x180025068)
  • RtlNtStatusToDosError (Address: 0x180025048)
  • RtlReleaseResource (Address: 0x180025058)
OLEAUT32.dll
  • SysAllocString (Address: 0x1800248e8)
  • SysFreeString (Address: 0x1800248e0)
  • VariantClear (Address: 0x1800248f0)
PROPSYS.dll
  • PropVariantToBoolean (Address: 0x180024908)
  • PropVariantToUInt32 (Address: 0x180024900)
samcli.dll
  • NetUserGetInfo (Address: 0x180025080)
SHCORE.dll
  • (Address: 0x180024918)
SspiCli.dll
  • GetUserNameExW (Address: 0x180024938)
  • LsaCallAuthenticationPackage (Address: 0x180024940)
  • LsaConnectUntrusted (Address: 0x180024950)
  • LsaDeregisterLogonProcess (Address: 0x180024948)
  • LsaFreeReturnBuffer (Address: 0x180024930)
  • LsaLookupAuthenticationPackage (Address: 0x180024928)