psapi.dll
Description: Process Status Helper
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: 8c91fa7e5ee1de667d3cd312d8a40cfd
File Size: 19.9 KB
Uploaded At: Dec. 1, 2025, 7:37 a.m.
Views: 12
Exported Functions
- EmptyWorkingSet (Ordinal: 1, Address: 0x13c0)
- EnumDeviceDrivers (Ordinal: 2, Address: 0x1090)
- EnumPageFilesA (Ordinal: 3, Address: 0x13e0)
- EnumPageFilesW (Ordinal: 4, Address: 0x1400)
- EnumProcessModules (Ordinal: 5, Address: 0x1010)
- EnumProcessModulesEx (Ordinal: 6, Address: 0x1420)
- EnumProcesses (Ordinal: 7, Address: 0x1030)
- GetDeviceDriverBaseNameA (Ordinal: 8, Address: 0x1440)
- GetDeviceDriverBaseNameW (Ordinal: 9, Address: 0x10b0)
- GetDeviceDriverFileNameA (Ordinal: 10, Address: 0x1460)
- GetDeviceDriverFileNameW (Ordinal: 11, Address: 0x1480)
- GetMappedFileNameA (Ordinal: 12, Address: 0x14a0)
- GetMappedFileNameW (Ordinal: 13, Address: 0x14c0)
- GetModuleBaseNameA (Ordinal: 14, Address: 0x14e0)
- GetModuleBaseNameW (Ordinal: 15, Address: 0x10d0)
- GetModuleFileNameExA (Ordinal: 16, Address: 0x1500)
- GetModuleFileNameExW (Ordinal: 17, Address: 0x1050)
- GetModuleInformation (Ordinal: 18, Address: 0x10f0)
- GetPerformanceInfo (Ordinal: 19, Address: 0x1520)
- GetProcessImageFileNameA (Ordinal: 20, Address: 0x1540)
- GetProcessImageFileNameW (Ordinal: 21, Address: 0x1070)
- GetProcessMemoryInfo (Ordinal: 22, Address: 0x1560)
- GetWsChanges (Ordinal: 23, Address: 0x15a0)
- GetWsChangesEx (Ordinal: 24, Address: 0x1580)
- InitializeProcessForWsWatch (Ordinal: 25, Address: 0x15c0)
- QueryWorkingSet (Ordinal: 26, Address: 0x1600)
- QueryWorkingSetEx (Ordinal: 27, Address: 0x15e0)
Imported DLLs & Functions
api-ms-win-core-errorhandling-l1-1-0.dll
- SetUnhandledExceptionFilter (Address: 0x180002128)
- UnhandledExceptionFilter (Address: 0x180002130)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x180002140)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x180002150)
- GetCurrentProcessId (Address: 0x180002160)
- GetCurrentThreadId (Address: 0x180002158)
- TerminateProcess (Address: 0x180002168)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180002178)
api-ms-win-core-psapi-ansi-l1-1-0.dll
- K32EnumPageFilesA (Address: 0x180002198)
- K32GetDeviceDriverBaseNameA (Address: 0x180002190)
- K32GetDeviceDriverFileNameA (Address: 0x1800021a8)
- K32GetMappedFileNameA (Address: 0x1800021a0)
- K32GetProcessImageFileNameA (Address: 0x180002188)
api-ms-win-core-psapi-l1-1-0.dll
- K32EmptyWorkingSet (Address: 0x180002248)
- K32EnumDeviceDrivers (Address: 0x180002208)
- K32EnumPageFilesW (Address: 0x1800021b8)
- K32EnumProcesses (Address: 0x1800021f0)
- K32EnumProcessModules (Address: 0x1800021c0)
- K32EnumProcessModulesEx (Address: 0x180002228)
- K32GetDeviceDriverBaseNameW (Address: 0x180002200)
- K32GetDeviceDriverFileNameW (Address: 0x180002210)
- K32GetMappedFileNameW (Address: 0x1800021c8)
- K32GetModuleBaseNameW (Address: 0x180002220)
- K32GetModuleFileNameExW (Address: 0x180002238)
- K32GetModuleInformation (Address: 0x1800021f8)
- K32GetPerformanceInfo (Address: 0x1800021e8)
- K32GetProcessImageFileNameW (Address: 0x180002240)
- K32GetProcessMemoryInfo (Address: 0x180002218)
- K32GetWsChanges (Address: 0x1800021d8)
- K32GetWsChangesEx (Address: 0x180002250)
- K32InitializeProcessForWsWatch (Address: 0x1800021e0)
- K32QueryWorkingSet (Address: 0x1800021d0)
- K32QueryWorkingSetEx (Address: 0x180002230)
api-ms-win-core-psapi-obsolete-l1-1-0.dll
- K32GetModuleBaseNameA (Address: 0x180002268)
- K32GetModuleFileNameExA (Address: 0x180002260)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x180002278)
- GetTickCount (Address: 0x180002280)
ntdll.dll
- RtlCaptureContext (Address: 0x1800022a0)
- RtlLookupFunctionEntry (Address: 0x180002298)
- RtlVirtualUnwind (Address: 0x180002290)