pwrshplugin.dll

Description: pwrshplugin.dll

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1

Architecture: 64-bit

Operating System: Windows NT

SHA256: 25e8d298caf10390ff1c97bd1ed7ed7d

File Size: 96.0 KB

Uploaded At: Dec. 1, 2025, 7:37 a.m.

Views: 5

Exported Functions

  • GetCLRVersionForPSVersion (Ordinal: 1, Address: 0x3220)
  • PerformWSManPluginReportCompletion (Ordinal: 2, Address: 0x2f10)
  • WSManPluginCommand (Ordinal: 3, Address: 0x3740)
  • WSManPluginConnect (Ordinal: 4, Address: 0x39b0)
  • WSManPluginReceive (Ordinal: 5, Address: 0x38b0)
  • WSManPluginReleaseCommandContext (Ordinal: 6, Address: 0x37c0)
  • WSManPluginReleaseShellContext (Ordinal: 7, Address: 0x36f0)
  • WSManPluginSend (Ordinal: 8, Address: 0x3820)
  • WSManPluginShell (Ordinal: 9, Address: 0x35f0)
  • WSManPluginShutdown (Ordinal: 10, Address: 0x3500)
  • WSManPluginSignal (Ordinal: 11, Address: 0x3930)
  • WSManPluginStartup (Ordinal: 12, Address: 0x3430)

Imported DLLs & Functions

ADVAPI32.dll
  • RegCloseKey (Address: 0x18000e958)
  • RegEnumKeyExW (Address: 0x18000e968)
  • RegOpenKeyExW (Address: 0x18000e960)
  • RegQueryValueExW (Address: 0x18000e950)
ATL.DLL
  • (Address: 0x18000e978)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18000ea58)
  • CloseHandle (Address: 0x18000e998)
  • CreateFileMappingW (Address: 0x18000ea50)
  • CreateFileW (Address: 0x18000e9b0)
  • DeleteCriticalSection (Address: 0x18000eab0)
  • EnterCriticalSection (Address: 0x18000ea78)
  • ExpandEnvironmentStringsW (Address: 0x18000e9d8)
  • FindResourceExW (Address: 0x18000e990)
  • FormatMessageW (Address: 0x18000ea98)
  • FreeLibrary (Address: 0x18000eac8)
  • GetCurrentProcess (Address: 0x18000ea20)
  • GetCurrentProcessId (Address: 0x18000ea08)
  • GetCurrentThreadId (Address: 0x18000ea00)
  • GetLastError (Address: 0x18000ead0)
  • GetLocaleInfoW (Address: 0x18000e9b8)
  • GetModuleFileNameW (Address: 0x18000ea68)
  • GetModuleHandleExW (Address: 0x18000ea70)
  • GetModuleHandleW (Address: 0x18000eab8)
  • GetProcAddress (Address: 0x18000eaa0)
  • GetSystemDefaultUILanguage (Address: 0x18000e9d0)
  • GetSystemTimeAsFileTime (Address: 0x18000e9f8)
  • GetTickCount (Address: 0x18000e9f0)
  • GetUserDefaultUILanguage (Address: 0x18000e9c8)
  • GetVersionExW (Address: 0x18000e9a8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18000ea88)
  • LeaveCriticalSection (Address: 0x18000ea90)
  • LoadLibraryExW (Address: 0x18000e9c0)
  • LoadResource (Address: 0x18000e988)
  • LocalFree (Address: 0x18000eaa8)
  • MapViewOfFile (Address: 0x18000e9e0)
  • QueryPerformanceCounter (Address: 0x18000ea10)
  • ReleaseSRWLockExclusive (Address: 0x18000ea80)
  • SearchPathW (Address: 0x18000e9e8)
  • SetErrorMode (Address: 0x18000ea48)
  • SetLastError (Address: 0x18000ea60)
  • SetUnhandledExceptionFilter (Address: 0x18000ea28)
  • Sleep (Address: 0x18000eac0)
  • SleepConditionVariableSRW (Address: 0x18000ea38)
  • TerminateProcess (Address: 0x18000ea18)
  • UnhandledExceptionFilter (Address: 0x18000ea30)
  • UnmapViewOfFile (Address: 0x18000e9a0)
  • WakeAllConditionVariable (Address: 0x18000ea40)
mscoree.dll
  • CorBindToRuntimeEx (Address: 0x18000eb38)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000ec68)
  • __CxxFrameHandler3 (Address: 0x18000eb98)
  • __dllonexit (Address: 0x18000eb48)
  • __uncaught_exception (Address: 0x18000ebd0)
  • _amsg_exit (Address: 0x18000eb50)
  • _callnewh (Address: 0x18000ec18)
  • _CxxThrowException (Address: 0x18000ebe8)
  • _initterm (Address: 0x18000eb60)
  • _itow_s (Address: 0x18000ec50)
  • _lock (Address: 0x18000eb68)
  • _onexit (Address: 0x18000eb78)
  • _purecall (Address: 0x18000ec40)
  • _unlock (Address: 0x18000eb70)
  • _vsnwprintf (Address: 0x18000ec70)
  • _wcsicmp (Address: 0x18000ec58)
  • _wcsnicmp (Address: 0x18000ec28)
  • _wfopen (Address: 0x18000ebc8)
  • _XcptFilter (Address: 0x18000eb58)
  • ??_V@YAXPEAX@Z (Address: 0x18000ec60)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18000ec10)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18000ec08)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18000ec00)
  • ??1exception@@UEAA@XZ (Address: 0x18000ebf8)
  • ??1type_info@@UEAA@XZ (Address: 0x18000eb90)
  • ??3@YAXPEAX@Z (Address: 0x18000ec48)
  • ?terminate@@YAXXZ (Address: 0x18000eb80)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18000ebf0)
  • bsearch (Address: 0x18000eba8)
  • fclose (Address: 0x18000ebc0)
  • free (Address: 0x18000eb88)
  • isspace (Address: 0x18000ec30)
  • malloc (Address: 0x18000ec20)
  • memcpy (Address: 0x18000ebe0)
  • memmove (Address: 0x18000ebd8)
  • memset (Address: 0x18000ec78)
  • wcschr (Address: 0x18000ebb8)
  • wcsncmp (Address: 0x18000eba0)
  • wcsstr (Address: 0x18000ec38)
  • wcstoul (Address: 0x18000ebb0)
ntdll.dll
  • RtlCaptureContext (Address: 0x18000ec88)
  • RtlLookupFunctionEntry (Address: 0x18000ec90)
  • RtlVirtualUnwind (Address: 0x18000ec98)
OLE32.dll
  • CoInitializeEx (Address: 0x18000eae0)
  • CoUninitialize (Address: 0x18000eae8)
OLEAUT32.dll
  • SysAllocString (Address: 0x18000eb10)
  • SysFreeString (Address: 0x18000eb08)
  • VariantClear (Address: 0x18000eaf8)
  • VariantInit (Address: 0x18000eb00)
WsmSvc.DLL
  • WSManPluginOperationComplete (Address: 0x18000eb20)
  • WSManPluginReportCompletion (Address: 0x18000eb28)