remoting_core.dll

Description: Biblioteca principal [File deleted after analysis due to size limit > 20MB]

Authors: Copyright 2026 Google LLC. Todos los derechos reservados.

Version: 148.0.7778.23

Architecture: 32-bit

Operating System: Windows

SHA256: ec0a1df075fde83b942c412d466723f6

File Size: 30.4 MB

Uploaded At: May 1, 2026, 12:09 a.m.

Views: 50

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ?CrashUploaderMain@remoting@@YAHHPAPAD@Z (Ordinal: 1, Address: 0x260640)
  • ?HostMain@remoting@@YAHHPAPAD@Z (Ordinal: 2, Address: 0x2527a0)
  • ?It2MeNativeMessagingHostMain@remoting@@YAHHPAPAD@Z (Ordinal: 3, Address: 0x2590e0)
  • ?Me2MeNativeMessagingHostMain@remoting@@YAHHPAPAD@Z (Ordinal: 4, Address: 0x259a50)
  • ?RemoteOpenUrlMain@remoting@@YAHHPAPAD@Z (Ordinal: 5, Address: 0x260360)
  • ?RemoteSecurityKeyMain@remoting@@YAHHPAPAD@Z (Ordinal: 6, Address: 0x260b90)
  • ?RemoteWebAuthnMain@remoting@@YAHHPAPAD@Z (Ordinal: 7, Address: 0x25ff80)
  • ?StartHostMain@remoting@@YAHHPAPAD@Z (Ordinal: 8, Address: 0x25c500)
  • DllCanUnloadNow (Ordinal: 9, Address: 0x2683d0)
  • DllGetClassObject (Ordinal: 10, Address: 0x268390)
  • DllRegisterServer (Ordinal: 11, Address: 0x268420)
  • DllUnregisterServer (Ordinal: 12, Address: 0x268450)
  • GetHandleVerifier (Ordinal: 13, Address: 0x26cb80)
  • sqlite3_dbdata_init (Ordinal: 14, Address: 0x106fc30)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x11c781e4)
  • BuildTrusteeWithSidW (Address: 0x11c781e8)
  • ChangeServiceConfigW (Address: 0x11c781ec)
  • CheckTokenMembership (Address: 0x11c781f0)
  • CloseServiceHandle (Address: 0x11c781f4)
  • CloseTrace (Address: 0x11c781f8)
  • ControlService (Address: 0x11c781fc)
  • ControlTraceW (Address: 0x11c78200)
  • ConvertSidToStringSidW (Address: 0x11c78204)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x11c78208)
  • ConvertStringSidToSidW (Address: 0x11c7820c)
  • CopySid (Address: 0x11c78210)
  • CreateProcessAsUserW (Address: 0x11c78214)
  • CreateRestrictedToken (Address: 0x11c78218)
  • CryptCreateHash (Address: 0x11c7821c)
  • CryptDestroyHash (Address: 0x11c78220)
  • CryptGetHashParam (Address: 0x11c78224)
  • CryptGetProvParam (Address: 0x11c78228)
  • CryptReleaseContext (Address: 0x11c7822c)
  • CryptSetHashParam (Address: 0x11c78230)
  • CryptSignHashW (Address: 0x11c78234)
  • DeregisterEventSource (Address: 0x11c78238)
  • DuplicateTokenEx (Address: 0x11c7823c)
  • EnableTrace (Address: 0x11c78240)
  • GetLengthSid (Address: 0x11c78244)
  • GetNamedSecurityInfoW (Address: 0x11c78248)
  • GetSecurityDescriptorControl (Address: 0x11c7824c)
  • GetSecurityDescriptorDacl (Address: 0x11c78250)
  • GetSecurityDescriptorGroup (Address: 0x11c78254)
  • GetSecurityDescriptorOwner (Address: 0x11c78258)
  • GetSecurityDescriptorSacl (Address: 0x11c7825c)
  • GetSecurityInfo (Address: 0x11c78260)
  • GetSidSubAuthority (Address: 0x11c78264)
  • GetSidSubAuthorityCount (Address: 0x11c78268)
  • GetTokenInformation (Address: 0x11c7826c)
  • GetTraceEnableFlags (Address: 0x11c78270)
  • GetTraceEnableLevel (Address: 0x11c78274)
  • GetTraceLoggerHandle (Address: 0x11c78278)
  • ImpersonateAnonymousToken (Address: 0x11c7827c)
  • ImpersonateLoggedOnUser (Address: 0x11c78280)
  • InitializeAcl (Address: 0x11c78284)
  • InitializeSecurityDescriptor (Address: 0x11c78288)
  • IsValidAcl (Address: 0x11c7828c)
  • IsValidSecurityDescriptor (Address: 0x11c78290)
  • IsValidSid (Address: 0x11c78294)
  • LogonUserW (Address: 0x11c78298)
  • LookupPrivilegeValueW (Address: 0x11c7829c)
  • MakeAbsoluteSD (Address: 0x11c782a0)
  • OpenProcessToken (Address: 0x11c782a4)
  • OpenSCManagerW (Address: 0x11c782a8)
  • OpenServiceW (Address: 0x11c782ac)
  • OpenThreadToken (Address: 0x11c782b0)
  • OpenTraceW (Address: 0x11c782b4)
  • ProcessTrace (Address: 0x11c782b8)
  • QueryServiceStatus (Address: 0x11c782bc)
  • RegCloseKey (Address: 0x11c782c0)
  • RegCreateKeyExW (Address: 0x11c782c4)
  • RegDeleteKeyW (Address: 0x11c782c8)
  • RegDeleteValueW (Address: 0x11c782cc)
  • RegEnumKeyExW (Address: 0x11c782d0)
  • RegEnumValueW (Address: 0x11c782d4)
  • RegisterEventSourceA (Address: 0x11c782ec)
  • RegisterEventSourceW (Address: 0x11c782f0)
  • RegisterServiceCtrlHandlerExW (Address: 0x11c782f4)
  • RegisterTraceGuidsW (Address: 0x11c782f8)
  • RegNotifyChangeKeyValue (Address: 0x11c782d8)
  • RegOpenKeyExW (Address: 0x11c782dc)
  • RegQueryInfoKeyW (Address: 0x11c782e0)
  • RegQueryValueExW (Address: 0x11c782e4)
  • RegSetValueExW (Address: 0x11c782e8)
  • ReportEventA (Address: 0x11c782fc)
  • ReportEventW (Address: 0x11c78300)
  • RevertToSelf (Address: 0x11c78304)
  • SetEntriesInAclW (Address: 0x11c78308)
  • SetNamedSecurityInfoW (Address: 0x11c7830c)
  • SetSecurityDescriptorDacl (Address: 0x11c78310)
  • SetSecurityInfo (Address: 0x11c78314)
  • SetServiceStatus (Address: 0x11c78318)
  • SetTokenInformation (Address: 0x11c7831c)
  • StartServiceCtrlDispatcherW (Address: 0x11c78320)
  • StartServiceW (Address: 0x11c78324)
  • StartTraceW (Address: 0x11c78328)
  • TraceEvent (Address: 0x11c7832c)
  • UnregisterTraceGuids (Address: 0x11c78330)
api-ms-win-core-synch-l1-2-0.dll
  • WaitOnAddress (Address: 0x11c78684)
  • WakeByAddressAll (Address: 0x11c78688)
  • WakeByAddressSingle (Address: 0x11c7868c)
api-ms-win-core-winrt-l1-1-0.dll
  • RoInitialize (Address: 0x11c78624)
  • RoUninitialize (Address: 0x11c78628)
COMCTL32.dll
  • (Address: 0x11c7836c)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x11c78374)
  • CertAddStoreToCollection (Address: 0x11c78378)
  • CertCloseStore (Address: 0x11c7837c)
  • CertCompareCertificateName (Address: 0x11c78380)
  • CertControlStore (Address: 0x11c78384)
  • CertEnumCertificatesInStore (Address: 0x11c78388)
  • CertFindCertificateInStore (Address: 0x11c7838c)
  • CertFindChainInStore (Address: 0x11c78390)
  • CertFreeCertificateContext (Address: 0x11c78394)
  • CertGetCertificateContextProperty (Address: 0x11c78398)
  • CertGetEnhancedKeyUsage (Address: 0x11c7839c)
  • CertGetIntendedKeyUsage (Address: 0x11c783a0)
  • CertOpenStore (Address: 0x11c783a4)
  • CertOpenSystemStoreW (Address: 0x11c783a8)
  • CertVerifyTimeValidity (Address: 0x11c783ac)
  • CryptAcquireCertificatePrivateKey (Address: 0x11c783b0)
  • CryptProtectMemory (Address: 0x11c783b4)
  • CryptUnprotectData (Address: 0x11c783b8)
  • CryptUnprotectMemory (Address: 0x11c783bc)
  • CryptVerifyCertificateSignatureEx (Address: 0x11c783c0)
dbghelp.dll
  • SymCleanup (Address: 0x11c783c8)
  • SymFromAddr (Address: 0x11c783cc)
  • SymGetLineFromAddr64 (Address: 0x11c783d0)
  • SymGetModuleInfo64 (Address: 0x11c783d4)
  • SymGetSearchPathW (Address: 0x11c783d8)
  • SymInitialize (Address: 0x11c783dc)
  • SymSetOptions (Address: 0x11c783e0)
  • SymSetSearchPathW (Address: 0x11c783e4)
dwmapi.dll
  • DwmGetWindowAttribute (Address: 0x11c7867c)
dxgi.dll
  • CreateDXGIFactory1 (Address: 0x11c78514)
GDI32.dll
  • BitBlt (Address: 0x11c7855c)
  • CreateCompatibleBitmap (Address: 0x11c78560)
  • CreateCompatibleDC (Address: 0x11c78564)
  • CreateDIBSection (Address: 0x11c78568)
  • CreatePen (Address: 0x11c7856c)
  • CreateRoundRectRgn (Address: 0x11c78570)
  • CreateSolidBrush (Address: 0x11c78574)
  • DeleteDC (Address: 0x11c78578)
  • DeleteObject (Address: 0x11c7857c)
  • GetDeviceCaps (Address: 0x11c78584)
  • GetDIBits (Address: 0x11c78580)
  • GetObjectW (Address: 0x11c78588)
  • GetStockObject (Address: 0x11c7858c)
  • RoundRect (Address: 0x11c78590)
  • SelectObject (Address: 0x11c78594)
IPHLPAPI.DLL
  • CancelIPChangeNotify (Address: 0x11c784ac)
  • GetAdaptersAddresses (Address: 0x11c784b0)
  • if_indextoname (Address: 0x11c784b8)
  • NotifyAddrChange (Address: 0x11c784b4)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x11c77b24)
  • AcquireSRWLockShared (Address: 0x11c77b28)
  • AreFileApisANSI (Address: 0x11c77b2c)
  • AssignProcessToJobObject (Address: 0x11c77b30)
  • CancelIo (Address: 0x11c77b34)
  • CancelIoEx (Address: 0x11c77b38)
  • CancelSynchronousIo (Address: 0x11c77b3c)
  • CloseHandle (Address: 0x11c77b40)
  • CompareStringW (Address: 0x11c77b44)
  • ConnectNamedPipe (Address: 0x11c77b48)
  • CopyFileW (Address: 0x11c77b4c)
  • CreateDirectoryW (Address: 0x11c77b50)
  • CreateEventW (Address: 0x11c77b54)
  • CreateFileA (Address: 0x11c77b58)
  • CreateFileMappingW (Address: 0x11c77b5c)
  • CreateFileW (Address: 0x11c77b60)
  • CreateIoCompletionPort (Address: 0x11c77b64)
  • CreateJobObjectW (Address: 0x11c77b68)
  • CreateMutexW (Address: 0x11c77b6c)
  • CreateNamedPipeW (Address: 0x11c77b70)
  • CreatePipe (Address: 0x11c77b74)
  • CreateProcessW (Address: 0x11c77b78)
  • CreateSemaphoreW (Address: 0x11c77b7c)
  • CreateSymbolicLinkW (Address: 0x11c77b80)
  • CreateThread (Address: 0x11c77b84)
  • DecodePointer (Address: 0x11c77b88)
  • DeleteCriticalSection (Address: 0x11c77b8c)
  • DeleteFileA (Address: 0x11c77b90)
  • DeleteFileW (Address: 0x11c77b94)
  • DeleteProcThreadAttributeList (Address: 0x11c77b98)
  • DeviceIoControl (Address: 0x11c77b9c)
  • DisableThreadLibraryCalls (Address: 0x11c77ba0)
  • DisconnectNamedPipe (Address: 0x11c77ba4)
  • DuplicateHandle (Address: 0x11c77ba8)
  • EncodePointer (Address: 0x11c77bac)
  • EnterCriticalSection (Address: 0x11c77bb0)
  • EnumSystemLocalesW (Address: 0x11c77bb4)
  • ExitProcess (Address: 0x11c77bb8)
  • ExitThread (Address: 0x11c77bbc)
  • ExpandEnvironmentStringsW (Address: 0x11c77bc0)
  • FileTimeToSystemTime (Address: 0x11c77bc4)
  • FindClose (Address: 0x11c77bc8)
  • FindFirstFileExW (Address: 0x11c77bcc)
  • FindNextFileW (Address: 0x11c77bd0)
  • FindResourceW (Address: 0x11c77bd4)
  • FlsAlloc (Address: 0x11c77bd8)
  • FlsFree (Address: 0x11c77bdc)
  • FlsGetValue (Address: 0x11c77be0)
  • FlsSetValue (Address: 0x11c77be4)
  • FlushFileBuffers (Address: 0x11c77be8)
  • FlushInstructionCache (Address: 0x11c77bec)
  • FlushViewOfFile (Address: 0x11c77bf0)
  • FormatMessageA (Address: 0x11c77bf4)
  • FormatMessageW (Address: 0x11c77bf8)
  • FreeEnvironmentStringsW (Address: 0x11c77bfc)
  • FreeLibrary (Address: 0x11c77c00)
  • FreeLibraryAndExitThread (Address: 0x11c77c04)
  • GetACP (Address: 0x11c77c08)
  • GetCommandLineA (Address: 0x11c77c10)
  • GetCommandLineW (Address: 0x11c77c14)
  • GetComputerNameExW (Address: 0x11c77c18)
  • GetConsoleMode (Address: 0x11c77c1c)
  • GetConsoleOutputCP (Address: 0x11c77c20)
  • GetCPInfo (Address: 0x11c77c0c)
  • GetCurrencyFormatEx (Address: 0x11c77c24)
  • GetCurrentDirectoryW (Address: 0x11c77c28)
  • GetCurrentProcess (Address: 0x11c77c2c)
  • GetCurrentProcessId (Address: 0x11c77c30)
  • GetCurrentThread (Address: 0x11c77c34)
  • GetCurrentThreadId (Address: 0x11c77c38)
  • GetDateFormatEx (Address: 0x11c77c3c)
  • GetDateFormatW (Address: 0x11c77c40)
  • GetDiskFreeSpaceA (Address: 0x11c77c44)
  • GetDiskFreeSpaceExW (Address: 0x11c77c48)
  • GetDiskFreeSpaceW (Address: 0x11c77c4c)
  • GetDriveTypeW (Address: 0x11c77c50)
  • GetDynamicTimeZoneInformation (Address: 0x11c77c54)
  • GetEnvironmentStringsW (Address: 0x11c77c58)
  • GetEnvironmentVariableW (Address: 0x11c77c5c)
  • GetExitCodeProcess (Address: 0x11c77c60)
  • GetFileAttributesA (Address: 0x11c77c64)
  • GetFileAttributesExW (Address: 0x11c77c68)
  • GetFileAttributesW (Address: 0x11c77c6c)
  • GetFileInformationByHandle (Address: 0x11c77c70)
  • GetFileSize (Address: 0x11c77c74)
  • GetFileSizeEx (Address: 0x11c77c78)
  • GetFileType (Address: 0x11c77c7c)
  • GetFullPathNameA (Address: 0x11c77c80)
  • GetFullPathNameW (Address: 0x11c77c84)
  • GetGeoInfoW (Address: 0x11c77c88)
  • GetHandleInformation (Address: 0x11c77c8c)
  • GetLastError (Address: 0x11c77c90)
  • GetLocaleInfoEx (Address: 0x11c77c98)
  • GetLocaleInfoW (Address: 0x11c77c9c)
  • GetLocalTime (Address: 0x11c77c94)
  • GetLogicalProcessorInformation (Address: 0x11c77ca0)
  • GetLogicalProcessorInformationEx (Address: 0x11c77ca4)
  • GetLongPathNameW (Address: 0x11c77ca8)
  • GetModuleFileNameW (Address: 0x11c77cac)
  • GetModuleHandleA (Address: 0x11c77cb0)
  • GetModuleHandleExW (Address: 0x11c77cb4)
  • GetModuleHandleW (Address: 0x11c77cb8)
  • GetNamedPipeClientProcessId (Address: 0x11c77cbc)
  • GetNamedPipeServerProcessId (Address: 0x11c77cc0)
  • GetNamedPipeServerSessionId (Address: 0x11c77cc4)
  • GetNativeSystemInfo (Address: 0x11c77cc8)
  • GetNumberFormatEx (Address: 0x11c77ccc)
  • GetOEMCP (Address: 0x11c77cd0)
  • GetOverlappedResult (Address: 0x11c77cd4)
  • GetPriorityClass (Address: 0x11c77cd8)
  • GetProcAddress (Address: 0x11c77cdc)
  • GetProcessAffinityMask (Address: 0x11c77ce0)
  • GetProcessHeap (Address: 0x11c77ce4)
  • GetProcessId (Address: 0x11c77ce8)
  • GetProcessMitigationPolicy (Address: 0x11c77cec)
  • GetProcessTimes (Address: 0x11c77cf0)
  • GetProductInfo (Address: 0x11c77cf4)
  • GetQueuedCompletionStatus (Address: 0x11c77cf8)
  • GetStartupInfoW (Address: 0x11c77cfc)
  • GetStdHandle (Address: 0x11c77d00)
  • GetStringTypeW (Address: 0x11c77d04)
  • GetSystemDirectoryW (Address: 0x11c77d08)
  • GetSystemInfo (Address: 0x11c77d0c)
  • GetSystemTime (Address: 0x11c77d10)
  • GetSystemTimeAsFileTime (Address: 0x11c77d14)
  • GetSystemTimePreciseAsFileTime (Address: 0x11c77d18)
  • GetTempPathA (Address: 0x11c77d1c)
  • GetTempPathW (Address: 0x11c77d20)
  • GetThreadGroupAffinity (Address: 0x11c77d24)
  • GetThreadId (Address: 0x11c77d28)
  • GetThreadPriority (Address: 0x11c77d2c)
  • GetTickCount (Address: 0x11c77d30)
  • GetTimeFormatEx (Address: 0x11c77d34)
  • GetTimeFormatW (Address: 0x11c77d38)
  • GetTimeZoneInformation (Address: 0x11c77d3c)
  • GetUserDefaultLCID (Address: 0x11c77d40)
  • GetUserGeoID (Address: 0x11c77d44)
  • GetVersionExW (Address: 0x11c77d48)
  • GetWindowsDirectoryW (Address: 0x11c77d4c)
  • GlobalAlloc (Address: 0x11c77d50)
  • GlobalFree (Address: 0x11c77d54)
  • GlobalLock (Address: 0x11c77d58)
  • GlobalMemoryStatusEx (Address: 0x11c77d5c)
  • GlobalUnlock (Address: 0x11c77d60)
  • HeapAlloc (Address: 0x11c77d64)
  • HeapCompact (Address: 0x11c77d68)
  • HeapCreate (Address: 0x11c77d6c)
  • HeapDestroy (Address: 0x11c77d70)
  • HeapFree (Address: 0x11c77d74)
  • HeapReAlloc (Address: 0x11c77d78)
  • HeapSize (Address: 0x11c77d7c)
  • HeapValidate (Address: 0x11c77d80)
  • InitializeConditionVariable (Address: 0x11c77d90)
  • InitializeCriticalSection (Address: 0x11c77d94)
  • InitializeCriticalSectionEx (Address: 0x11c77d98)
  • InitializeProcThreadAttributeList (Address: 0x11c77d9c)
  • InitializeSListHead (Address: 0x11c77da0)
  • InitializeSRWLock (Address: 0x11c77da4)
  • InitOnceBeginInitialize (Address: 0x11c77d84)
  • InitOnceComplete (Address: 0x11c77d88)
  • InitOnceExecuteOnce (Address: 0x11c77d8c)
  • InterlockedFlushSList (Address: 0x11c77da8)
  • InterlockedPopEntrySList (Address: 0x11c77dac)
  • InterlockedPushEntrySList (Address: 0x11c77db0)
  • IsDebuggerPresent (Address: 0x11c77db4)
  • IsProcessorFeaturePresent (Address: 0x11c77db8)
  • IsValidCodePage (Address: 0x11c77dbc)
  • IsValidLocale (Address: 0x11c77dc0)
  • IsWow64Process (Address: 0x11c77dc4)
  • K32GetModuleInformation (Address: 0x11c77dc8)
  • K32QueryWorkingSetEx (Address: 0x11c77dcc)
  • LCMapStringW (Address: 0x11c77dd0)
  • LeaveCriticalSection (Address: 0x11c77dd4)
  • LoadLibraryA (Address: 0x11c77dd8)
  • LoadLibraryExA (Address: 0x11c77ddc)
  • LoadLibraryExW (Address: 0x11c77de0)
  • LoadLibraryW (Address: 0x11c77de4)
  • LoadResource (Address: 0x11c77de8)
  • LocalAlloc (Address: 0x11c77dec)
  • LocalFree (Address: 0x11c77df0)
  • LockFile (Address: 0x11c77df4)
  • LockFileEx (Address: 0x11c77df8)
  • lstrcmpiW (Address: 0x11c77f80)
  • lstrcmpW (Address: 0x11c77f7c)
  • MapViewOfFile (Address: 0x11c77dfc)
  • MoveFileExW (Address: 0x11c77e00)
  • MoveFileW (Address: 0x11c77e04)
  • MulDiv (Address: 0x11c77e08)
  • MultiByteToWideChar (Address: 0x11c77e0c)
  • OpenProcess (Address: 0x11c77e10)
  • OpenThread (Address: 0x11c77e14)
  • OutputDebugStringA (Address: 0x11c77e18)
  • OutputDebugStringW (Address: 0x11c77e1c)
  • PeekNamedPipe (Address: 0x11c77e20)
  • PostQueuedCompletionStatus (Address: 0x11c77e24)
  • PowerClearRequest (Address: 0x11c77e28)
  • PowerCreateRequest (Address: 0x11c77e2c)
  • PowerSetRequest (Address: 0x11c77e30)
  • PrefetchVirtualMemory (Address: 0x11c77e34)
  • ProcessIdToSessionId (Address: 0x11c77e38)
  • QueryFullProcessImageNameW (Address: 0x11c77e3c)
  • QueryPerformanceCounter (Address: 0x11c77e40)
  • QueryPerformanceFrequency (Address: 0x11c77e44)
  • QueryThreadCycleTime (Address: 0x11c77e48)
  • RaiseException (Address: 0x11c77e4c)
  • ReadConsoleW (Address: 0x11c77e50)
  • ReadDirectoryChangesW (Address: 0x11c77e54)
  • ReadFile (Address: 0x11c77e58)
  • ReadProcessMemory (Address: 0x11c77e5c)
  • RegisterWaitForSingleObject (Address: 0x11c77e60)
  • ReleaseMutex (Address: 0x11c77e64)
  • ReleaseSemaphore (Address: 0x11c77e70)
  • ReleaseSRWLockExclusive (Address: 0x11c77e68)
  • ReleaseSRWLockShared (Address: 0x11c77e6c)
  • RemoveDirectoryW (Address: 0x11c77e74)
  • ReplaceFileW (Address: 0x11c77e78)
  • ResetEvent (Address: 0x11c77e7c)
  • ResolveLocaleName (Address: 0x11c77e80)
  • ResumeThread (Address: 0x11c77e84)
  • RtlCaptureContext (Address: 0x11c77e88)
  • RtlCaptureStackBackTrace (Address: 0x11c77e8c)
  • RtlUnwind (Address: 0x11c77e90)
  • SetConsoleCtrlHandler (Address: 0x11c77e94)
  • SetConsoleMode (Address: 0x11c77e98)
  • SetCurrentDirectoryW (Address: 0x11c77e9c)
  • SetEndOfFile (Address: 0x11c77ea0)
  • SetEnvironmentVariableW (Address: 0x11c77ea4)
  • SetEvent (Address: 0x11c77ea8)
  • SetFileAttributesW (Address: 0x11c77eac)
  • SetFileCompletionNotificationModes (Address: 0x11c77eb0)
  • SetFileInformationByHandle (Address: 0x11c77eb4)
  • SetFilePointer (Address: 0x11c77eb8)
  • SetFilePointerEx (Address: 0x11c77ebc)
  • SetHandleInformation (Address: 0x11c77ec0)
  • SetInformationJobObject (Address: 0x11c77ec4)
  • SetLastError (Address: 0x11c77ec8)
  • SetNamedPipeHandleState (Address: 0x11c77ecc)
  • SetStdHandle (Address: 0x11c77ed0)
  • SetThreadExecutionState (Address: 0x11c77ed4)
  • SetThreadInformation (Address: 0x11c77ed8)
  • SetThreadPriority (Address: 0x11c77edc)
  • SetUnhandledExceptionFilter (Address: 0x11c77ee0)
  • SizeofResource (Address: 0x11c77ee4)
  • Sleep (Address: 0x11c77ee8)
  • SleepConditionVariableSRW (Address: 0x11c77eec)
  • SwitchToThread (Address: 0x11c77ef0)
  • SystemTimeToFileTime (Address: 0x11c77ef4)
  • SystemTimeToTzSpecificLocalTime (Address: 0x11c77ef8)
  • TerminateJobObject (Address: 0x11c77efc)
  • TerminateProcess (Address: 0x11c77f00)
  • TlsAlloc (Address: 0x11c77f04)
  • TlsFree (Address: 0x11c77f08)
  • TlsGetValue (Address: 0x11c77f0c)
  • TlsSetValue (Address: 0x11c77f10)
  • TransactNamedPipe (Address: 0x11c77f14)
  • TryAcquireSRWLockExclusive (Address: 0x11c77f18)
  • TryEnterCriticalSection (Address: 0x11c77f1c)
  • TzSpecificLocalTimeToSystemTime (Address: 0x11c77f20)
  • UnhandledExceptionFilter (Address: 0x11c77f24)
  • UnlockFile (Address: 0x11c77f28)
  • UnlockFileEx (Address: 0x11c77f2c)
  • UnmapViewOfFile (Address: 0x11c77f30)
  • UnregisterWait (Address: 0x11c77f34)
  • UnregisterWaitEx (Address: 0x11c77f38)
  • UpdateProcThreadAttribute (Address: 0x11c77f3c)
  • VirtualAlloc (Address: 0x11c77f40)
  • VirtualFree (Address: 0x11c77f44)
  • VirtualProtect (Address: 0x11c77f48)
  • VirtualQuery (Address: 0x11c77f4c)
  • VirtualQueryEx (Address: 0x11c77f50)
  • WaitForMultipleObjects (Address: 0x11c77f58)
  • WaitForSingleObject (Address: 0x11c77f5c)
  • WaitForSingleObjectEx (Address: 0x11c77f60)
  • WaitNamedPipeW (Address: 0x11c77f64)
  • WakeAllConditionVariable (Address: 0x11c77f68)
  • WakeConditionVariable (Address: 0x11c77f6c)
  • WideCharToMultiByte (Address: 0x11c77f70)
  • WriteConsoleW (Address: 0x11c77f74)
  • WriteFile (Address: 0x11c77f78)
  • WTSGetActiveConsoleSessionId (Address: 0x11c77f54)
ncrypt.dll
  • NCryptCreatePersistedKey (Address: 0x11c78630)
  • NCryptExportKey (Address: 0x11c78634)
  • NCryptFinalizeKey (Address: 0x11c78638)
  • NCryptFreeObject (Address: 0x11c7863c)
  • NCryptGetProperty (Address: 0x11c78640)
  • NCryptImportKey (Address: 0x11c78644)
  • NCryptIsAlgSupported (Address: 0x11c78648)
  • NCryptOpenKey (Address: 0x11c7864c)
  • NCryptOpenStorageProvider (Address: 0x11c78650)
  • NCryptSignHash (Address: 0x11c78654)
netutils.dll
  • NetApiBufferFree (Address: 0x11c784e8)
ntdll.dll
  • NtQueryInformationProcess (Address: 0x11c78604)
  • NtQueryObject (Address: 0x11c78608)
  • RtlGetLastNtStatus (Address: 0x11c7860c)
ole32.dll
  • CLSIDFromProgID (Address: 0x11c77f88)
  • CLSIDFromString (Address: 0x11c77f8c)
  • CoCreateInstance (Address: 0x11c77f90)
  • CoGetClassObject (Address: 0x11c77f94)
  • CoInitializeEx (Address: 0x11c77f98)
  • CoInitializeSecurity (Address: 0x11c77f9c)
  • CoRegisterClassObject (Address: 0x11c77fa0)
  • CoRegisterInitializeSpy (Address: 0x11c77fa4)
  • CoResumeClassObjects (Address: 0x11c77fa8)
  • CoRevokeClassObject (Address: 0x11c77fac)
  • CoRevokeInitializeSpy (Address: 0x11c77fb0)
  • CoSuspendClassObjects (Address: 0x11c77fb4)
  • CoTaskMemAlloc (Address: 0x11c77fb8)
  • CoTaskMemFree (Address: 0x11c77fbc)
  • CoTaskMemRealloc (Address: 0x11c77fc0)
  • CoUninitialize (Address: 0x11c77fc4)
  • CreateStreamOnHGlobal (Address: 0x11c77fc8)
  • OleInitialize (Address: 0x11c77fcc)
  • OleLockRunning (Address: 0x11c77fd0)
  • OleUninitialize (Address: 0x11c77fd4)
  • StringFromGUID2 (Address: 0x11c77fd8)
OLEAUT32.dll
  • BSTR_UserFree (Address: 0x11c7851c)
  • BSTR_UserMarshal (Address: 0x11c78520)
  • BSTR_UserSize (Address: 0x11c78524)
  • BSTR_UserUnmarshal (Address: 0x11c78528)
  • DispCallFunc (Address: 0x11c7852c)
  • LoadRegTypeLib (Address: 0x11c78530)
  • LoadTypeLib (Address: 0x11c78534)
  • OleCreateFontIndirect (Address: 0x11c78538)
  • SysAllocString (Address: 0x11c7853c)
  • SysAllocStringLen (Address: 0x11c78540)
  • SysFreeString (Address: 0x11c78544)
  • SysStringLen (Address: 0x11c78548)
  • VariantClear (Address: 0x11c78550)
  • VariantInit (Address: 0x11c78554)
  • VarUI4FromStr (Address: 0x11c7854c)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x11c785b4)
  • CStdStubBuffer_Connect (Address: 0x11c785b8)
  • CStdStubBuffer_CountRefs (Address: 0x11c785bc)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x11c785c0)
  • CStdStubBuffer_DebugServerRelease (Address: 0x11c785c4)
  • CStdStubBuffer_Disconnect (Address: 0x11c785c8)
  • CStdStubBuffer_Invoke (Address: 0x11c785cc)
  • CStdStubBuffer_IsIIDSupported (Address: 0x11c785d0)
  • CStdStubBuffer_QueryInterface (Address: 0x11c785d4)
  • IUnknown_AddRef_Proxy (Address: 0x11c785d8)
  • IUnknown_QueryInterface_Proxy (Address: 0x11c785dc)
  • IUnknown_Release_Proxy (Address: 0x11c785e0)
  • NdrCStdStubBuffer_Release (Address: 0x11c785e4)
  • NdrDllCanUnloadNow (Address: 0x11c785e8)
  • NdrDllGetClassObject (Address: 0x11c785ec)
  • NdrDllRegisterProxy (Address: 0x11c785f0)
  • NdrDllUnregisterProxy (Address: 0x11c785f4)
  • NdrOleAllocate (Address: 0x11c785f8)
  • NdrOleFree (Address: 0x11c785fc)
Secur32.dll
  • AcquireCredentialsHandleW (Address: 0x11c784f0)
  • DeleteSecurityContext (Address: 0x11c784f4)
  • FreeContextBuffer (Address: 0x11c784f8)
  • FreeCredentialsHandle (Address: 0x11c784fc)
  • GetUserNameExW (Address: 0x11c78500)
  • InitializeSecurityContextW (Address: 0x11c78504)
  • QueryContextAttributesW (Address: 0x11c78508)
  • QuerySecurityPackageInfoW (Address: 0x11c7850c)
SHELL32.dll
  • CommandLineToArgvW (Address: 0x11c78354)
  • SHChangeNotify (Address: 0x11c78358)
  • ShellExecuteExW (Address: 0x11c78364)
  • SHGetFolderPathW (Address: 0x11c7835c)
  • SHGetKnownFolderPath (Address: 0x11c78360)
SHLWAPI.dll
  • (Address: 0x11c785a8)
  • AssocQueryStringW (Address: 0x11c785a4)
  • PathMatchSpecW (Address: 0x11c785ac)
urlmon.dll
  • CoInternetCreateSecurityManager (Address: 0x11c78674)
USER32.dll
  • AddClipboardFormatListener (Address: 0x11c77fe0)
  • AllowSetForegroundWindow (Address: 0x11c77fe4)
  • AnimateWindow (Address: 0x11c77fe8)
  • BeginPaint (Address: 0x11c77fec)
  • BringWindowToTop (Address: 0x11c77ff0)
  • CallNextHookEx (Address: 0x11c77ff4)
  • CallWindowProcW (Address: 0x11c77ff8)
  • ChangeDisplaySettingsW (Address: 0x11c77ffc)
  • CharNextW (Address: 0x11c78000)
  • CharUpperW (Address: 0x11c78004)
  • ClientToScreen (Address: 0x11c78008)
  • CloseClipboard (Address: 0x11c7800c)
  • CloseDesktop (Address: 0x11c78010)
  • CloseWindowStation (Address: 0x11c78014)
  • CreateAcceleratorTableW (Address: 0x11c78018)
  • CreateDesktopW (Address: 0x11c7801c)
  • CreateDialogParamW (Address: 0x11c78020)
  • CreateWindowExW (Address: 0x11c78024)
  • CreateWindowStationW (Address: 0x11c78028)
  • DefRawInputProc (Address: 0x11c7802c)
  • DefWindowProcW (Address: 0x11c78030)
  • DestroyAcceleratorTable (Address: 0x11c78034)
  • DestroyWindow (Address: 0x11c78038)
  • DispatchMessageW (Address: 0x11c7803c)
  • DisplayConfigGetDeviceInfo (Address: 0x11c78040)
  • DrawTextW (Address: 0x11c78044)
  • EmptyClipboard (Address: 0x11c78048)
  • EndDialog (Address: 0x11c7804c)
  • EndPaint (Address: 0x11c78050)
  • EnumDisplayDevicesW (Address: 0x11c78054)
  • EnumDisplaySettingsExW (Address: 0x11c78058)
  • EqualRect (Address: 0x11c7805c)
  • FillRect (Address: 0x11c78060)
  • FindWindowExW (Address: 0x11c78064)
  • FindWindowW (Address: 0x11c78068)
  • GetActiveWindow (Address: 0x11c7806c)
  • GetAncestor (Address: 0x11c78070)
  • GetClassInfoExW (Address: 0x11c78074)
  • GetClassNameW (Address: 0x11c78078)
  • GetClientRect (Address: 0x11c7807c)
  • GetClipboardData (Address: 0x11c78080)
  • GetCursorInfo (Address: 0x11c78084)
  • GetCursorPos (Address: 0x11c78088)
  • GetDC (Address: 0x11c7808c)
  • GetDesktopWindow (Address: 0x11c78090)
  • GetDisplayConfigBufferSizes (Address: 0x11c78094)
  • GetDlgItem (Address: 0x11c78098)
  • GetFocus (Address: 0x11c7809c)
  • GetForegroundWindow (Address: 0x11c780a0)
  • GetIconInfo (Address: 0x11c780a4)
  • GetKeyboardLayout (Address: 0x11c780ac)
  • GetKeyboardState (Address: 0x11c780b0)
  • GetKeyState (Address: 0x11c780a8)
  • GetMonitorInfoA (Address: 0x11c780b4)
  • GetMonitorInfoW (Address: 0x11c780b8)
  • GetParent (Address: 0x11c780bc)
  • GetProcessWindowStation (Address: 0x11c780c0)
  • GetQueueStatus (Address: 0x11c780c4)
  • GetRawInputData (Address: 0x11c780c8)
  • GetSysColor (Address: 0x11c780cc)
  • GetSystemMetrics (Address: 0x11c780d0)
  • GetThreadDesktop (Address: 0x11c780d4)
  • GetUserObjectInformationW (Address: 0x11c780d8)
  • GetWindow (Address: 0x11c780dc)
  • GetWindowLongW (Address: 0x11c780e0)
  • GetWindowPlacement (Address: 0x11c780e4)
  • GetWindowRect (Address: 0x11c780e8)
  • GetWindowTextLengthW (Address: 0x11c780ec)
  • GetWindowTextW (Address: 0x11c780f0)
  • GetWindowThreadProcessId (Address: 0x11c780f4)
  • InvalidateRect (Address: 0x11c780f8)
  • InvalidateRgn (Address: 0x11c780fc)
  • IsChild (Address: 0x11c78100)
  • IsClipboardFormatAvailable (Address: 0x11c78104)
  • IsWindow (Address: 0x11c78108)
  • IsWindowVisible (Address: 0x11c7810c)
  • KillTimer (Address: 0x11c78110)
  • LoadCursorW (Address: 0x11c78114)
  • LoadStringW (Address: 0x11c78118)
  • LockWorkStation (Address: 0x11c7811c)
  • MapDialogRect (Address: 0x11c78120)
  • MapVirtualKeyExW (Address: 0x11c78124)
  • MapVirtualKeyW (Address: 0x11c78128)
  • MapWindowPoints (Address: 0x11c7812c)
  • MonitorFromPoint (Address: 0x11c78130)
  • MonitorFromRect (Address: 0x11c78134)
  • MonitorFromWindow (Address: 0x11c78138)
  • MoveWindow (Address: 0x11c7813c)
  • MsgWaitForMultipleObjectsEx (Address: 0x11c78140)
  • OpenClipboard (Address: 0x11c78144)
  • OpenInputDesktop (Address: 0x11c78148)
  • PeekMessageW (Address: 0x11c7814c)
  • PostMessageW (Address: 0x11c78150)
  • PostQuitMessage (Address: 0x11c78154)
  • QueryDisplayConfig (Address: 0x11c78158)
  • RedrawWindow (Address: 0x11c7815c)
  • RegisterClassExW (Address: 0x11c78160)
  • RegisterHotKey (Address: 0x11c78164)
  • RegisterRawInputDevices (Address: 0x11c78168)
  • RegisterWindowMessageW (Address: 0x11c7816c)
  • ReleaseCapture (Address: 0x11c78170)
  • ReleaseDC (Address: 0x11c78174)
  • RemoveClipboardFormatListener (Address: 0x11c78178)
  • ScreenToClient (Address: 0x11c7817c)
  • SendInput (Address: 0x11c78180)
  • SendMessageW (Address: 0x11c78184)
  • SetCapture (Address: 0x11c78188)
  • SetClipboardData (Address: 0x11c7818c)
  • SetFocus (Address: 0x11c78190)
  • SetForegroundWindow (Address: 0x11c78194)
  • SetKeyboardState (Address: 0x11c78198)
  • SetProcessWindowStation (Address: 0x11c7819c)
  • SetThreadDesktop (Address: 0x11c781a0)
  • SetTimer (Address: 0x11c781a4)
  • SetWindowLongW (Address: 0x11c781ac)
  • SetWindowPos (Address: 0x11c781b0)
  • SetWindowRgn (Address: 0x11c781b4)
  • SetWindowsHookExW (Address: 0x11c781bc)
  • SetWindowTextW (Address: 0x11c781b8)
  • SetWinEventHook (Address: 0x11c781a8)
  • ShowWindow (Address: 0x11c781c0)
  • ToUnicodeEx (Address: 0x11c781c4)
  • TranslateMessage (Address: 0x11c781c8)
  • UnhookWindowsHookEx (Address: 0x11c781d0)
  • UnhookWinEvent (Address: 0x11c781cc)
  • UnregisterClassW (Address: 0x11c781d4)
  • UnregisterHotKey (Address: 0x11c781d8)
  • WindowFromPoint (Address: 0x11c781dc)
USERENV.dll
  • CreateEnvironmentBlock (Address: 0x11c784c0)
  • DestroyEnvironmentBlock (Address: 0x11c784c4)
  • EnterCriticalPolicySection (Address: 0x11c784c8)
  • GetProfileType (Address: 0x11c784cc)
  • LeaveCriticalPolicySection (Address: 0x11c784d0)
  • RegisterGPNotification (Address: 0x11c784d4)
  • UnregisterGPNotification (Address: 0x11c784d8)
WINHTTP.dll
  • WinHttpCloseHandle (Address: 0x11c7865c)
  • WinHttpGetIEProxyConfigForCurrentUser (Address: 0x11c78660)
  • WinHttpGetProxyForUrl (Address: 0x11c78664)
  • WinHttpOpen (Address: 0x11c78668)
  • WinHttpSetTimeouts (Address: 0x11c7866c)
WINMM.dll
  • timeBeginPeriod (Address: 0x11c78614)
  • timeEndPeriod (Address: 0x11c78618)
  • timeGetTime (Address: 0x11c7861c)
WINTRUST.dll
  • WinVerifyTrust (Address: 0x11c7859c)
wkscli.dll
  • NetGetJoinInformation (Address: 0x11c784e0)
WS2_32.dll
  • accept (Address: 0x11c78448)
  • bind (Address: 0x11c7844c)
  • closesocket (Address: 0x11c78450)
  • connect (Address: 0x11c78454)
  • freeaddrinfo (Address: 0x11c78458)
  • FreeAddrInfoExW (Address: 0x11c783ec)
  • getaddrinfo (Address: 0x11c7845c)
  • GetAddrInfoExCancel (Address: 0x11c783f0)
  • GetAddrInfoExW (Address: 0x11c783f4)
  • gethostname (Address: 0x11c78460)
  • getpeername (Address: 0x11c78464)
  • getsockname (Address: 0x11c78468)
  • getsockopt (Address: 0x11c7846c)
  • htonl (Address: 0x11c78470)
  • htons (Address: 0x11c78474)
  • inet_ntop (Address: 0x11c78478)
  • ioctlsocket (Address: 0x11c7847c)
  • listen (Address: 0x11c78480)
  • ntohl (Address: 0x11c78484)
  • ntohs (Address: 0x11c78488)
  • recv (Address: 0x11c7848c)
  • recvfrom (Address: 0x11c78490)
  • send (Address: 0x11c78494)
  • sendto (Address: 0x11c78498)
  • setsockopt (Address: 0x11c7849c)
  • shutdown (Address: 0x11c784a0)
  • socket (Address: 0x11c784a4)
  • WSACloseEvent (Address: 0x11c783f8)
  • WSACreateEvent (Address: 0x11c783fc)
  • WSAEnumNetworkEvents (Address: 0x11c78400)
  • WSAEnumProtocolsW (Address: 0x11c78404)
  • WSAEventSelect (Address: 0x11c78408)
  • WSAGetLastError (Address: 0x11c7840c)
  • WSAGetOverlappedResult (Address: 0x11c78410)
  • WSAIoctl (Address: 0x11c78414)
  • WSALookupServiceBeginW (Address: 0x11c78418)
  • WSALookupServiceEnd (Address: 0x11c7841c)
  • WSALookupServiceNextW (Address: 0x11c78420)
  • WSARecv (Address: 0x11c78424)
  • WSARecvFrom (Address: 0x11c78428)
  • WSAResetEvent (Address: 0x11c7842c)
  • WSASend (Address: 0x11c78430)
  • WSASendTo (Address: 0x11c78434)
  • WSASetEvent (Address: 0x11c78438)
  • WSASocketW (Address: 0x11c7843c)
  • WSAStartup (Address: 0x11c78440)
  • WSAWaitForMultipleEvents (Address: 0x11c78444)
WTSAPI32.dll
  • WTSEnumerateSessionsW (Address: 0x11c78338)
  • WTSFreeMemory (Address: 0x11c7833c)
  • WTSQuerySessionInformationW (Address: 0x11c78340)
  • WTSQueryUserToken (Address: 0x11c78344)
  • WTSRegisterSessionNotification (Address: 0x11c78348)
  • WTSUnRegisterSessionNotification (Address: 0x11c7834c)