remoting_core.dll
Description: Biblioteca principal [File deleted after analysis due to size limit > 20MB]
Authors: Copyright 2026 Google LLC. Todos los derechos reservados.
Version: 148.0.7778.23
Architecture: 32-bit
Operating System: Windows
SHA256: ec0a1df075fde83b942c412d466723f6
File Size: 30.4 MB
Uploaded At: May 1, 2026, 12:09 a.m.
Views: 50
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- ?CrashUploaderMain@remoting@@YAHHPAPAD@Z (Ordinal: 1, Address: 0x260640)
- ?HostMain@remoting@@YAHHPAPAD@Z (Ordinal: 2, Address: 0x2527a0)
- ?It2MeNativeMessagingHostMain@remoting@@YAHHPAPAD@Z (Ordinal: 3, Address: 0x2590e0)
- ?Me2MeNativeMessagingHostMain@remoting@@YAHHPAPAD@Z (Ordinal: 4, Address: 0x259a50)
- ?RemoteOpenUrlMain@remoting@@YAHHPAPAD@Z (Ordinal: 5, Address: 0x260360)
- ?RemoteSecurityKeyMain@remoting@@YAHHPAPAD@Z (Ordinal: 6, Address: 0x260b90)
- ?RemoteWebAuthnMain@remoting@@YAHHPAPAD@Z (Ordinal: 7, Address: 0x25ff80)
- ?StartHostMain@remoting@@YAHHPAPAD@Z (Ordinal: 8, Address: 0x25c500)
- DllCanUnloadNow (Ordinal: 9, Address: 0x2683d0)
- DllGetClassObject (Ordinal: 10, Address: 0x268390)
- DllRegisterServer (Ordinal: 11, Address: 0x268420)
- DllUnregisterServer (Ordinal: 12, Address: 0x268450)
- GetHandleVerifier (Ordinal: 13, Address: 0x26cb80)
- sqlite3_dbdata_init (Ordinal: 14, Address: 0x106fc30)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x11c781e4)
- BuildTrusteeWithSidW (Address: 0x11c781e8)
- ChangeServiceConfigW (Address: 0x11c781ec)
- CheckTokenMembership (Address: 0x11c781f0)
- CloseServiceHandle (Address: 0x11c781f4)
- CloseTrace (Address: 0x11c781f8)
- ControlService (Address: 0x11c781fc)
- ControlTraceW (Address: 0x11c78200)
- ConvertSidToStringSidW (Address: 0x11c78204)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x11c78208)
- ConvertStringSidToSidW (Address: 0x11c7820c)
- CopySid (Address: 0x11c78210)
- CreateProcessAsUserW (Address: 0x11c78214)
- CreateRestrictedToken (Address: 0x11c78218)
- CryptCreateHash (Address: 0x11c7821c)
- CryptDestroyHash (Address: 0x11c78220)
- CryptGetHashParam (Address: 0x11c78224)
- CryptGetProvParam (Address: 0x11c78228)
- CryptReleaseContext (Address: 0x11c7822c)
- CryptSetHashParam (Address: 0x11c78230)
- CryptSignHashW (Address: 0x11c78234)
- DeregisterEventSource (Address: 0x11c78238)
- DuplicateTokenEx (Address: 0x11c7823c)
- EnableTrace (Address: 0x11c78240)
- GetLengthSid (Address: 0x11c78244)
- GetNamedSecurityInfoW (Address: 0x11c78248)
- GetSecurityDescriptorControl (Address: 0x11c7824c)
- GetSecurityDescriptorDacl (Address: 0x11c78250)
- GetSecurityDescriptorGroup (Address: 0x11c78254)
- GetSecurityDescriptorOwner (Address: 0x11c78258)
- GetSecurityDescriptorSacl (Address: 0x11c7825c)
- GetSecurityInfo (Address: 0x11c78260)
- GetSidSubAuthority (Address: 0x11c78264)
- GetSidSubAuthorityCount (Address: 0x11c78268)
- GetTokenInformation (Address: 0x11c7826c)
- GetTraceEnableFlags (Address: 0x11c78270)
- GetTraceEnableLevel (Address: 0x11c78274)
- GetTraceLoggerHandle (Address: 0x11c78278)
- ImpersonateAnonymousToken (Address: 0x11c7827c)
- ImpersonateLoggedOnUser (Address: 0x11c78280)
- InitializeAcl (Address: 0x11c78284)
- InitializeSecurityDescriptor (Address: 0x11c78288)
- IsValidAcl (Address: 0x11c7828c)
- IsValidSecurityDescriptor (Address: 0x11c78290)
- IsValidSid (Address: 0x11c78294)
- LogonUserW (Address: 0x11c78298)
- LookupPrivilegeValueW (Address: 0x11c7829c)
- MakeAbsoluteSD (Address: 0x11c782a0)
- OpenProcessToken (Address: 0x11c782a4)
- OpenSCManagerW (Address: 0x11c782a8)
- OpenServiceW (Address: 0x11c782ac)
- OpenThreadToken (Address: 0x11c782b0)
- OpenTraceW (Address: 0x11c782b4)
- ProcessTrace (Address: 0x11c782b8)
- QueryServiceStatus (Address: 0x11c782bc)
- RegCloseKey (Address: 0x11c782c0)
- RegCreateKeyExW (Address: 0x11c782c4)
- RegDeleteKeyW (Address: 0x11c782c8)
- RegDeleteValueW (Address: 0x11c782cc)
- RegEnumKeyExW (Address: 0x11c782d0)
- RegEnumValueW (Address: 0x11c782d4)
- RegisterEventSourceA (Address: 0x11c782ec)
- RegisterEventSourceW (Address: 0x11c782f0)
- RegisterServiceCtrlHandlerExW (Address: 0x11c782f4)
- RegisterTraceGuidsW (Address: 0x11c782f8)
- RegNotifyChangeKeyValue (Address: 0x11c782d8)
- RegOpenKeyExW (Address: 0x11c782dc)
- RegQueryInfoKeyW (Address: 0x11c782e0)
- RegQueryValueExW (Address: 0x11c782e4)
- RegSetValueExW (Address: 0x11c782e8)
- ReportEventA (Address: 0x11c782fc)
- ReportEventW (Address: 0x11c78300)
- RevertToSelf (Address: 0x11c78304)
- SetEntriesInAclW (Address: 0x11c78308)
- SetNamedSecurityInfoW (Address: 0x11c7830c)
- SetSecurityDescriptorDacl (Address: 0x11c78310)
- SetSecurityInfo (Address: 0x11c78314)
- SetServiceStatus (Address: 0x11c78318)
- SetTokenInformation (Address: 0x11c7831c)
- StartServiceCtrlDispatcherW (Address: 0x11c78320)
- StartServiceW (Address: 0x11c78324)
- StartTraceW (Address: 0x11c78328)
- TraceEvent (Address: 0x11c7832c)
- UnregisterTraceGuids (Address: 0x11c78330)
api-ms-win-core-synch-l1-2-0.dll
- WaitOnAddress (Address: 0x11c78684)
- WakeByAddressAll (Address: 0x11c78688)
- WakeByAddressSingle (Address: 0x11c7868c)
api-ms-win-core-winrt-l1-1-0.dll
- RoInitialize (Address: 0x11c78624)
- RoUninitialize (Address: 0x11c78628)
COMCTL32.dll
- (Address: 0x11c7836c)
CRYPT32.dll
- CertAddCertificateContextToStore (Address: 0x11c78374)
- CertAddStoreToCollection (Address: 0x11c78378)
- CertCloseStore (Address: 0x11c7837c)
- CertCompareCertificateName (Address: 0x11c78380)
- CertControlStore (Address: 0x11c78384)
- CertEnumCertificatesInStore (Address: 0x11c78388)
- CertFindCertificateInStore (Address: 0x11c7838c)
- CertFindChainInStore (Address: 0x11c78390)
- CertFreeCertificateContext (Address: 0x11c78394)
- CertGetCertificateContextProperty (Address: 0x11c78398)
- CertGetEnhancedKeyUsage (Address: 0x11c7839c)
- CertGetIntendedKeyUsage (Address: 0x11c783a0)
- CertOpenStore (Address: 0x11c783a4)
- CertOpenSystemStoreW (Address: 0x11c783a8)
- CertVerifyTimeValidity (Address: 0x11c783ac)
- CryptAcquireCertificatePrivateKey (Address: 0x11c783b0)
- CryptProtectMemory (Address: 0x11c783b4)
- CryptUnprotectData (Address: 0x11c783b8)
- CryptUnprotectMemory (Address: 0x11c783bc)
- CryptVerifyCertificateSignatureEx (Address: 0x11c783c0)
dbghelp.dll
- SymCleanup (Address: 0x11c783c8)
- SymFromAddr (Address: 0x11c783cc)
- SymGetLineFromAddr64 (Address: 0x11c783d0)
- SymGetModuleInfo64 (Address: 0x11c783d4)
- SymGetSearchPathW (Address: 0x11c783d8)
- SymInitialize (Address: 0x11c783dc)
- SymSetOptions (Address: 0x11c783e0)
- SymSetSearchPathW (Address: 0x11c783e4)
dwmapi.dll
- DwmGetWindowAttribute (Address: 0x11c7867c)
dxgi.dll
- CreateDXGIFactory1 (Address: 0x11c78514)
GDI32.dll
- BitBlt (Address: 0x11c7855c)
- CreateCompatibleBitmap (Address: 0x11c78560)
- CreateCompatibleDC (Address: 0x11c78564)
- CreateDIBSection (Address: 0x11c78568)
- CreatePen (Address: 0x11c7856c)
- CreateRoundRectRgn (Address: 0x11c78570)
- CreateSolidBrush (Address: 0x11c78574)
- DeleteDC (Address: 0x11c78578)
- DeleteObject (Address: 0x11c7857c)
- GetDeviceCaps (Address: 0x11c78584)
- GetDIBits (Address: 0x11c78580)
- GetObjectW (Address: 0x11c78588)
- GetStockObject (Address: 0x11c7858c)
- RoundRect (Address: 0x11c78590)
- SelectObject (Address: 0x11c78594)
IPHLPAPI.DLL
- CancelIPChangeNotify (Address: 0x11c784ac)
- GetAdaptersAddresses (Address: 0x11c784b0)
- if_indextoname (Address: 0x11c784b8)
- NotifyAddrChange (Address: 0x11c784b4)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x11c77b24)
- AcquireSRWLockShared (Address: 0x11c77b28)
- AreFileApisANSI (Address: 0x11c77b2c)
- AssignProcessToJobObject (Address: 0x11c77b30)
- CancelIo (Address: 0x11c77b34)
- CancelIoEx (Address: 0x11c77b38)
- CancelSynchronousIo (Address: 0x11c77b3c)
- CloseHandle (Address: 0x11c77b40)
- CompareStringW (Address: 0x11c77b44)
- ConnectNamedPipe (Address: 0x11c77b48)
- CopyFileW (Address: 0x11c77b4c)
- CreateDirectoryW (Address: 0x11c77b50)
- CreateEventW (Address: 0x11c77b54)
- CreateFileA (Address: 0x11c77b58)
- CreateFileMappingW (Address: 0x11c77b5c)
- CreateFileW (Address: 0x11c77b60)
- CreateIoCompletionPort (Address: 0x11c77b64)
- CreateJobObjectW (Address: 0x11c77b68)
- CreateMutexW (Address: 0x11c77b6c)
- CreateNamedPipeW (Address: 0x11c77b70)
- CreatePipe (Address: 0x11c77b74)
- CreateProcessW (Address: 0x11c77b78)
- CreateSemaphoreW (Address: 0x11c77b7c)
- CreateSymbolicLinkW (Address: 0x11c77b80)
- CreateThread (Address: 0x11c77b84)
- DecodePointer (Address: 0x11c77b88)
- DeleteCriticalSection (Address: 0x11c77b8c)
- DeleteFileA (Address: 0x11c77b90)
- DeleteFileW (Address: 0x11c77b94)
- DeleteProcThreadAttributeList (Address: 0x11c77b98)
- DeviceIoControl (Address: 0x11c77b9c)
- DisableThreadLibraryCalls (Address: 0x11c77ba0)
- DisconnectNamedPipe (Address: 0x11c77ba4)
- DuplicateHandle (Address: 0x11c77ba8)
- EncodePointer (Address: 0x11c77bac)
- EnterCriticalSection (Address: 0x11c77bb0)
- EnumSystemLocalesW (Address: 0x11c77bb4)
- ExitProcess (Address: 0x11c77bb8)
- ExitThread (Address: 0x11c77bbc)
- ExpandEnvironmentStringsW (Address: 0x11c77bc0)
- FileTimeToSystemTime (Address: 0x11c77bc4)
- FindClose (Address: 0x11c77bc8)
- FindFirstFileExW (Address: 0x11c77bcc)
- FindNextFileW (Address: 0x11c77bd0)
- FindResourceW (Address: 0x11c77bd4)
- FlsAlloc (Address: 0x11c77bd8)
- FlsFree (Address: 0x11c77bdc)
- FlsGetValue (Address: 0x11c77be0)
- FlsSetValue (Address: 0x11c77be4)
- FlushFileBuffers (Address: 0x11c77be8)
- FlushInstructionCache (Address: 0x11c77bec)
- FlushViewOfFile (Address: 0x11c77bf0)
- FormatMessageA (Address: 0x11c77bf4)
- FormatMessageW (Address: 0x11c77bf8)
- FreeEnvironmentStringsW (Address: 0x11c77bfc)
- FreeLibrary (Address: 0x11c77c00)
- FreeLibraryAndExitThread (Address: 0x11c77c04)
- GetACP (Address: 0x11c77c08)
- GetCommandLineA (Address: 0x11c77c10)
- GetCommandLineW (Address: 0x11c77c14)
- GetComputerNameExW (Address: 0x11c77c18)
- GetConsoleMode (Address: 0x11c77c1c)
- GetConsoleOutputCP (Address: 0x11c77c20)
- GetCPInfo (Address: 0x11c77c0c)
- GetCurrencyFormatEx (Address: 0x11c77c24)
- GetCurrentDirectoryW (Address: 0x11c77c28)
- GetCurrentProcess (Address: 0x11c77c2c)
- GetCurrentProcessId (Address: 0x11c77c30)
- GetCurrentThread (Address: 0x11c77c34)
- GetCurrentThreadId (Address: 0x11c77c38)
- GetDateFormatEx (Address: 0x11c77c3c)
- GetDateFormatW (Address: 0x11c77c40)
- GetDiskFreeSpaceA (Address: 0x11c77c44)
- GetDiskFreeSpaceExW (Address: 0x11c77c48)
- GetDiskFreeSpaceW (Address: 0x11c77c4c)
- GetDriveTypeW (Address: 0x11c77c50)
- GetDynamicTimeZoneInformation (Address: 0x11c77c54)
- GetEnvironmentStringsW (Address: 0x11c77c58)
- GetEnvironmentVariableW (Address: 0x11c77c5c)
- GetExitCodeProcess (Address: 0x11c77c60)
- GetFileAttributesA (Address: 0x11c77c64)
- GetFileAttributesExW (Address: 0x11c77c68)
- GetFileAttributesW (Address: 0x11c77c6c)
- GetFileInformationByHandle (Address: 0x11c77c70)
- GetFileSize (Address: 0x11c77c74)
- GetFileSizeEx (Address: 0x11c77c78)
- GetFileType (Address: 0x11c77c7c)
- GetFullPathNameA (Address: 0x11c77c80)
- GetFullPathNameW (Address: 0x11c77c84)
- GetGeoInfoW (Address: 0x11c77c88)
- GetHandleInformation (Address: 0x11c77c8c)
- GetLastError (Address: 0x11c77c90)
- GetLocaleInfoEx (Address: 0x11c77c98)
- GetLocaleInfoW (Address: 0x11c77c9c)
- GetLocalTime (Address: 0x11c77c94)
- GetLogicalProcessorInformation (Address: 0x11c77ca0)
- GetLogicalProcessorInformationEx (Address: 0x11c77ca4)
- GetLongPathNameW (Address: 0x11c77ca8)
- GetModuleFileNameW (Address: 0x11c77cac)
- GetModuleHandleA (Address: 0x11c77cb0)
- GetModuleHandleExW (Address: 0x11c77cb4)
- GetModuleHandleW (Address: 0x11c77cb8)
- GetNamedPipeClientProcessId (Address: 0x11c77cbc)
- GetNamedPipeServerProcessId (Address: 0x11c77cc0)
- GetNamedPipeServerSessionId (Address: 0x11c77cc4)
- GetNativeSystemInfo (Address: 0x11c77cc8)
- GetNumberFormatEx (Address: 0x11c77ccc)
- GetOEMCP (Address: 0x11c77cd0)
- GetOverlappedResult (Address: 0x11c77cd4)
- GetPriorityClass (Address: 0x11c77cd8)
- GetProcAddress (Address: 0x11c77cdc)
- GetProcessAffinityMask (Address: 0x11c77ce0)
- GetProcessHeap (Address: 0x11c77ce4)
- GetProcessId (Address: 0x11c77ce8)
- GetProcessMitigationPolicy (Address: 0x11c77cec)
- GetProcessTimes (Address: 0x11c77cf0)
- GetProductInfo (Address: 0x11c77cf4)
- GetQueuedCompletionStatus (Address: 0x11c77cf8)
- GetStartupInfoW (Address: 0x11c77cfc)
- GetStdHandle (Address: 0x11c77d00)
- GetStringTypeW (Address: 0x11c77d04)
- GetSystemDirectoryW (Address: 0x11c77d08)
- GetSystemInfo (Address: 0x11c77d0c)
- GetSystemTime (Address: 0x11c77d10)
- GetSystemTimeAsFileTime (Address: 0x11c77d14)
- GetSystemTimePreciseAsFileTime (Address: 0x11c77d18)
- GetTempPathA (Address: 0x11c77d1c)
- GetTempPathW (Address: 0x11c77d20)
- GetThreadGroupAffinity (Address: 0x11c77d24)
- GetThreadId (Address: 0x11c77d28)
- GetThreadPriority (Address: 0x11c77d2c)
- GetTickCount (Address: 0x11c77d30)
- GetTimeFormatEx (Address: 0x11c77d34)
- GetTimeFormatW (Address: 0x11c77d38)
- GetTimeZoneInformation (Address: 0x11c77d3c)
- GetUserDefaultLCID (Address: 0x11c77d40)
- GetUserGeoID (Address: 0x11c77d44)
- GetVersionExW (Address: 0x11c77d48)
- GetWindowsDirectoryW (Address: 0x11c77d4c)
- GlobalAlloc (Address: 0x11c77d50)
- GlobalFree (Address: 0x11c77d54)
- GlobalLock (Address: 0x11c77d58)
- GlobalMemoryStatusEx (Address: 0x11c77d5c)
- GlobalUnlock (Address: 0x11c77d60)
- HeapAlloc (Address: 0x11c77d64)
- HeapCompact (Address: 0x11c77d68)
- HeapCreate (Address: 0x11c77d6c)
- HeapDestroy (Address: 0x11c77d70)
- HeapFree (Address: 0x11c77d74)
- HeapReAlloc (Address: 0x11c77d78)
- HeapSize (Address: 0x11c77d7c)
- HeapValidate (Address: 0x11c77d80)
- InitializeConditionVariable (Address: 0x11c77d90)
- InitializeCriticalSection (Address: 0x11c77d94)
- InitializeCriticalSectionEx (Address: 0x11c77d98)
- InitializeProcThreadAttributeList (Address: 0x11c77d9c)
- InitializeSListHead (Address: 0x11c77da0)
- InitializeSRWLock (Address: 0x11c77da4)
- InitOnceBeginInitialize (Address: 0x11c77d84)
- InitOnceComplete (Address: 0x11c77d88)
- InitOnceExecuteOnce (Address: 0x11c77d8c)
- InterlockedFlushSList (Address: 0x11c77da8)
- InterlockedPopEntrySList (Address: 0x11c77dac)
- InterlockedPushEntrySList (Address: 0x11c77db0)
- IsDebuggerPresent (Address: 0x11c77db4)
- IsProcessorFeaturePresent (Address: 0x11c77db8)
- IsValidCodePage (Address: 0x11c77dbc)
- IsValidLocale (Address: 0x11c77dc0)
- IsWow64Process (Address: 0x11c77dc4)
- K32GetModuleInformation (Address: 0x11c77dc8)
- K32QueryWorkingSetEx (Address: 0x11c77dcc)
- LCMapStringW (Address: 0x11c77dd0)
- LeaveCriticalSection (Address: 0x11c77dd4)
- LoadLibraryA (Address: 0x11c77dd8)
- LoadLibraryExA (Address: 0x11c77ddc)
- LoadLibraryExW (Address: 0x11c77de0)
- LoadLibraryW (Address: 0x11c77de4)
- LoadResource (Address: 0x11c77de8)
- LocalAlloc (Address: 0x11c77dec)
- LocalFree (Address: 0x11c77df0)
- LockFile (Address: 0x11c77df4)
- LockFileEx (Address: 0x11c77df8)
- lstrcmpiW (Address: 0x11c77f80)
- lstrcmpW (Address: 0x11c77f7c)
- MapViewOfFile (Address: 0x11c77dfc)
- MoveFileExW (Address: 0x11c77e00)
- MoveFileW (Address: 0x11c77e04)
- MulDiv (Address: 0x11c77e08)
- MultiByteToWideChar (Address: 0x11c77e0c)
- OpenProcess (Address: 0x11c77e10)
- OpenThread (Address: 0x11c77e14)
- OutputDebugStringA (Address: 0x11c77e18)
- OutputDebugStringW (Address: 0x11c77e1c)
- PeekNamedPipe (Address: 0x11c77e20)
- PostQueuedCompletionStatus (Address: 0x11c77e24)
- PowerClearRequest (Address: 0x11c77e28)
- PowerCreateRequest (Address: 0x11c77e2c)
- PowerSetRequest (Address: 0x11c77e30)
- PrefetchVirtualMemory (Address: 0x11c77e34)
- ProcessIdToSessionId (Address: 0x11c77e38)
- QueryFullProcessImageNameW (Address: 0x11c77e3c)
- QueryPerformanceCounter (Address: 0x11c77e40)
- QueryPerformanceFrequency (Address: 0x11c77e44)
- QueryThreadCycleTime (Address: 0x11c77e48)
- RaiseException (Address: 0x11c77e4c)
- ReadConsoleW (Address: 0x11c77e50)
- ReadDirectoryChangesW (Address: 0x11c77e54)
- ReadFile (Address: 0x11c77e58)
- ReadProcessMemory (Address: 0x11c77e5c)
- RegisterWaitForSingleObject (Address: 0x11c77e60)
- ReleaseMutex (Address: 0x11c77e64)
- ReleaseSemaphore (Address: 0x11c77e70)
- ReleaseSRWLockExclusive (Address: 0x11c77e68)
- ReleaseSRWLockShared (Address: 0x11c77e6c)
- RemoveDirectoryW (Address: 0x11c77e74)
- ReplaceFileW (Address: 0x11c77e78)
- ResetEvent (Address: 0x11c77e7c)
- ResolveLocaleName (Address: 0x11c77e80)
- ResumeThread (Address: 0x11c77e84)
- RtlCaptureContext (Address: 0x11c77e88)
- RtlCaptureStackBackTrace (Address: 0x11c77e8c)
- RtlUnwind (Address: 0x11c77e90)
- SetConsoleCtrlHandler (Address: 0x11c77e94)
- SetConsoleMode (Address: 0x11c77e98)
- SetCurrentDirectoryW (Address: 0x11c77e9c)
- SetEndOfFile (Address: 0x11c77ea0)
- SetEnvironmentVariableW (Address: 0x11c77ea4)
- SetEvent (Address: 0x11c77ea8)
- SetFileAttributesW (Address: 0x11c77eac)
- SetFileCompletionNotificationModes (Address: 0x11c77eb0)
- SetFileInformationByHandle (Address: 0x11c77eb4)
- SetFilePointer (Address: 0x11c77eb8)
- SetFilePointerEx (Address: 0x11c77ebc)
- SetHandleInformation (Address: 0x11c77ec0)
- SetInformationJobObject (Address: 0x11c77ec4)
- SetLastError (Address: 0x11c77ec8)
- SetNamedPipeHandleState (Address: 0x11c77ecc)
- SetStdHandle (Address: 0x11c77ed0)
- SetThreadExecutionState (Address: 0x11c77ed4)
- SetThreadInformation (Address: 0x11c77ed8)
- SetThreadPriority (Address: 0x11c77edc)
- SetUnhandledExceptionFilter (Address: 0x11c77ee0)
- SizeofResource (Address: 0x11c77ee4)
- Sleep (Address: 0x11c77ee8)
- SleepConditionVariableSRW (Address: 0x11c77eec)
- SwitchToThread (Address: 0x11c77ef0)
- SystemTimeToFileTime (Address: 0x11c77ef4)
- SystemTimeToTzSpecificLocalTime (Address: 0x11c77ef8)
- TerminateJobObject (Address: 0x11c77efc)
- TerminateProcess (Address: 0x11c77f00)
- TlsAlloc (Address: 0x11c77f04)
- TlsFree (Address: 0x11c77f08)
- TlsGetValue (Address: 0x11c77f0c)
- TlsSetValue (Address: 0x11c77f10)
- TransactNamedPipe (Address: 0x11c77f14)
- TryAcquireSRWLockExclusive (Address: 0x11c77f18)
- TryEnterCriticalSection (Address: 0x11c77f1c)
- TzSpecificLocalTimeToSystemTime (Address: 0x11c77f20)
- UnhandledExceptionFilter (Address: 0x11c77f24)
- UnlockFile (Address: 0x11c77f28)
- UnlockFileEx (Address: 0x11c77f2c)
- UnmapViewOfFile (Address: 0x11c77f30)
- UnregisterWait (Address: 0x11c77f34)
- UnregisterWaitEx (Address: 0x11c77f38)
- UpdateProcThreadAttribute (Address: 0x11c77f3c)
- VirtualAlloc (Address: 0x11c77f40)
- VirtualFree (Address: 0x11c77f44)
- VirtualProtect (Address: 0x11c77f48)
- VirtualQuery (Address: 0x11c77f4c)
- VirtualQueryEx (Address: 0x11c77f50)
- WaitForMultipleObjects (Address: 0x11c77f58)
- WaitForSingleObject (Address: 0x11c77f5c)
- WaitForSingleObjectEx (Address: 0x11c77f60)
- WaitNamedPipeW (Address: 0x11c77f64)
- WakeAllConditionVariable (Address: 0x11c77f68)
- WakeConditionVariable (Address: 0x11c77f6c)
- WideCharToMultiByte (Address: 0x11c77f70)
- WriteConsoleW (Address: 0x11c77f74)
- WriteFile (Address: 0x11c77f78)
- WTSGetActiveConsoleSessionId (Address: 0x11c77f54)
ncrypt.dll
- NCryptCreatePersistedKey (Address: 0x11c78630)
- NCryptExportKey (Address: 0x11c78634)
- NCryptFinalizeKey (Address: 0x11c78638)
- NCryptFreeObject (Address: 0x11c7863c)
- NCryptGetProperty (Address: 0x11c78640)
- NCryptImportKey (Address: 0x11c78644)
- NCryptIsAlgSupported (Address: 0x11c78648)
- NCryptOpenKey (Address: 0x11c7864c)
- NCryptOpenStorageProvider (Address: 0x11c78650)
- NCryptSignHash (Address: 0x11c78654)
netutils.dll
- NetApiBufferFree (Address: 0x11c784e8)
ntdll.dll
- NtQueryInformationProcess (Address: 0x11c78604)
- NtQueryObject (Address: 0x11c78608)
- RtlGetLastNtStatus (Address: 0x11c7860c)
ole32.dll
- CLSIDFromProgID (Address: 0x11c77f88)
- CLSIDFromString (Address: 0x11c77f8c)
- CoCreateInstance (Address: 0x11c77f90)
- CoGetClassObject (Address: 0x11c77f94)
- CoInitializeEx (Address: 0x11c77f98)
- CoInitializeSecurity (Address: 0x11c77f9c)
- CoRegisterClassObject (Address: 0x11c77fa0)
- CoRegisterInitializeSpy (Address: 0x11c77fa4)
- CoResumeClassObjects (Address: 0x11c77fa8)
- CoRevokeClassObject (Address: 0x11c77fac)
- CoRevokeInitializeSpy (Address: 0x11c77fb0)
- CoSuspendClassObjects (Address: 0x11c77fb4)
- CoTaskMemAlloc (Address: 0x11c77fb8)
- CoTaskMemFree (Address: 0x11c77fbc)
- CoTaskMemRealloc (Address: 0x11c77fc0)
- CoUninitialize (Address: 0x11c77fc4)
- CreateStreamOnHGlobal (Address: 0x11c77fc8)
- OleInitialize (Address: 0x11c77fcc)
- OleLockRunning (Address: 0x11c77fd0)
- OleUninitialize (Address: 0x11c77fd4)
- StringFromGUID2 (Address: 0x11c77fd8)
OLEAUT32.dll
- BSTR_UserFree (Address: 0x11c7851c)
- BSTR_UserMarshal (Address: 0x11c78520)
- BSTR_UserSize (Address: 0x11c78524)
- BSTR_UserUnmarshal (Address: 0x11c78528)
- DispCallFunc (Address: 0x11c7852c)
- LoadRegTypeLib (Address: 0x11c78530)
- LoadTypeLib (Address: 0x11c78534)
- OleCreateFontIndirect (Address: 0x11c78538)
- SysAllocString (Address: 0x11c7853c)
- SysAllocStringLen (Address: 0x11c78540)
- SysFreeString (Address: 0x11c78544)
- SysStringLen (Address: 0x11c78548)
- VariantClear (Address: 0x11c78550)
- VariantInit (Address: 0x11c78554)
- VarUI4FromStr (Address: 0x11c7854c)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x11c785b4)
- CStdStubBuffer_Connect (Address: 0x11c785b8)
- CStdStubBuffer_CountRefs (Address: 0x11c785bc)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x11c785c0)
- CStdStubBuffer_DebugServerRelease (Address: 0x11c785c4)
- CStdStubBuffer_Disconnect (Address: 0x11c785c8)
- CStdStubBuffer_Invoke (Address: 0x11c785cc)
- CStdStubBuffer_IsIIDSupported (Address: 0x11c785d0)
- CStdStubBuffer_QueryInterface (Address: 0x11c785d4)
- IUnknown_AddRef_Proxy (Address: 0x11c785d8)
- IUnknown_QueryInterface_Proxy (Address: 0x11c785dc)
- IUnknown_Release_Proxy (Address: 0x11c785e0)
- NdrCStdStubBuffer_Release (Address: 0x11c785e4)
- NdrDllCanUnloadNow (Address: 0x11c785e8)
- NdrDllGetClassObject (Address: 0x11c785ec)
- NdrDllRegisterProxy (Address: 0x11c785f0)
- NdrDllUnregisterProxy (Address: 0x11c785f4)
- NdrOleAllocate (Address: 0x11c785f8)
- NdrOleFree (Address: 0x11c785fc)
Secur32.dll
- AcquireCredentialsHandleW (Address: 0x11c784f0)
- DeleteSecurityContext (Address: 0x11c784f4)
- FreeContextBuffer (Address: 0x11c784f8)
- FreeCredentialsHandle (Address: 0x11c784fc)
- GetUserNameExW (Address: 0x11c78500)
- InitializeSecurityContextW (Address: 0x11c78504)
- QueryContextAttributesW (Address: 0x11c78508)
- QuerySecurityPackageInfoW (Address: 0x11c7850c)
SHELL32.dll
- CommandLineToArgvW (Address: 0x11c78354)
- SHChangeNotify (Address: 0x11c78358)
- ShellExecuteExW (Address: 0x11c78364)
- SHGetFolderPathW (Address: 0x11c7835c)
- SHGetKnownFolderPath (Address: 0x11c78360)
SHLWAPI.dll
- (Address: 0x11c785a8)
- AssocQueryStringW (Address: 0x11c785a4)
- PathMatchSpecW (Address: 0x11c785ac)
urlmon.dll
- CoInternetCreateSecurityManager (Address: 0x11c78674)
USER32.dll
- AddClipboardFormatListener (Address: 0x11c77fe0)
- AllowSetForegroundWindow (Address: 0x11c77fe4)
- AnimateWindow (Address: 0x11c77fe8)
- BeginPaint (Address: 0x11c77fec)
- BringWindowToTop (Address: 0x11c77ff0)
- CallNextHookEx (Address: 0x11c77ff4)
- CallWindowProcW (Address: 0x11c77ff8)
- ChangeDisplaySettingsW (Address: 0x11c77ffc)
- CharNextW (Address: 0x11c78000)
- CharUpperW (Address: 0x11c78004)
- ClientToScreen (Address: 0x11c78008)
- CloseClipboard (Address: 0x11c7800c)
- CloseDesktop (Address: 0x11c78010)
- CloseWindowStation (Address: 0x11c78014)
- CreateAcceleratorTableW (Address: 0x11c78018)
- CreateDesktopW (Address: 0x11c7801c)
- CreateDialogParamW (Address: 0x11c78020)
- CreateWindowExW (Address: 0x11c78024)
- CreateWindowStationW (Address: 0x11c78028)
- DefRawInputProc (Address: 0x11c7802c)
- DefWindowProcW (Address: 0x11c78030)
- DestroyAcceleratorTable (Address: 0x11c78034)
- DestroyWindow (Address: 0x11c78038)
- DispatchMessageW (Address: 0x11c7803c)
- DisplayConfigGetDeviceInfo (Address: 0x11c78040)
- DrawTextW (Address: 0x11c78044)
- EmptyClipboard (Address: 0x11c78048)
- EndDialog (Address: 0x11c7804c)
- EndPaint (Address: 0x11c78050)
- EnumDisplayDevicesW (Address: 0x11c78054)
- EnumDisplaySettingsExW (Address: 0x11c78058)
- EqualRect (Address: 0x11c7805c)
- FillRect (Address: 0x11c78060)
- FindWindowExW (Address: 0x11c78064)
- FindWindowW (Address: 0x11c78068)
- GetActiveWindow (Address: 0x11c7806c)
- GetAncestor (Address: 0x11c78070)
- GetClassInfoExW (Address: 0x11c78074)
- GetClassNameW (Address: 0x11c78078)
- GetClientRect (Address: 0x11c7807c)
- GetClipboardData (Address: 0x11c78080)
- GetCursorInfo (Address: 0x11c78084)
- GetCursorPos (Address: 0x11c78088)
- GetDC (Address: 0x11c7808c)
- GetDesktopWindow (Address: 0x11c78090)
- GetDisplayConfigBufferSizes (Address: 0x11c78094)
- GetDlgItem (Address: 0x11c78098)
- GetFocus (Address: 0x11c7809c)
- GetForegroundWindow (Address: 0x11c780a0)
- GetIconInfo (Address: 0x11c780a4)
- GetKeyboardLayout (Address: 0x11c780ac)
- GetKeyboardState (Address: 0x11c780b0)
- GetKeyState (Address: 0x11c780a8)
- GetMonitorInfoA (Address: 0x11c780b4)
- GetMonitorInfoW (Address: 0x11c780b8)
- GetParent (Address: 0x11c780bc)
- GetProcessWindowStation (Address: 0x11c780c0)
- GetQueueStatus (Address: 0x11c780c4)
- GetRawInputData (Address: 0x11c780c8)
- GetSysColor (Address: 0x11c780cc)
- GetSystemMetrics (Address: 0x11c780d0)
- GetThreadDesktop (Address: 0x11c780d4)
- GetUserObjectInformationW (Address: 0x11c780d8)
- GetWindow (Address: 0x11c780dc)
- GetWindowLongW (Address: 0x11c780e0)
- GetWindowPlacement (Address: 0x11c780e4)
- GetWindowRect (Address: 0x11c780e8)
- GetWindowTextLengthW (Address: 0x11c780ec)
- GetWindowTextW (Address: 0x11c780f0)
- GetWindowThreadProcessId (Address: 0x11c780f4)
- InvalidateRect (Address: 0x11c780f8)
- InvalidateRgn (Address: 0x11c780fc)
- IsChild (Address: 0x11c78100)
- IsClipboardFormatAvailable (Address: 0x11c78104)
- IsWindow (Address: 0x11c78108)
- IsWindowVisible (Address: 0x11c7810c)
- KillTimer (Address: 0x11c78110)
- LoadCursorW (Address: 0x11c78114)
- LoadStringW (Address: 0x11c78118)
- LockWorkStation (Address: 0x11c7811c)
- MapDialogRect (Address: 0x11c78120)
- MapVirtualKeyExW (Address: 0x11c78124)
- MapVirtualKeyW (Address: 0x11c78128)
- MapWindowPoints (Address: 0x11c7812c)
- MonitorFromPoint (Address: 0x11c78130)
- MonitorFromRect (Address: 0x11c78134)
- MonitorFromWindow (Address: 0x11c78138)
- MoveWindow (Address: 0x11c7813c)
- MsgWaitForMultipleObjectsEx (Address: 0x11c78140)
- OpenClipboard (Address: 0x11c78144)
- OpenInputDesktop (Address: 0x11c78148)
- PeekMessageW (Address: 0x11c7814c)
- PostMessageW (Address: 0x11c78150)
- PostQuitMessage (Address: 0x11c78154)
- QueryDisplayConfig (Address: 0x11c78158)
- RedrawWindow (Address: 0x11c7815c)
- RegisterClassExW (Address: 0x11c78160)
- RegisterHotKey (Address: 0x11c78164)
- RegisterRawInputDevices (Address: 0x11c78168)
- RegisterWindowMessageW (Address: 0x11c7816c)
- ReleaseCapture (Address: 0x11c78170)
- ReleaseDC (Address: 0x11c78174)
- RemoveClipboardFormatListener (Address: 0x11c78178)
- ScreenToClient (Address: 0x11c7817c)
- SendInput (Address: 0x11c78180)
- SendMessageW (Address: 0x11c78184)
- SetCapture (Address: 0x11c78188)
- SetClipboardData (Address: 0x11c7818c)
- SetFocus (Address: 0x11c78190)
- SetForegroundWindow (Address: 0x11c78194)
- SetKeyboardState (Address: 0x11c78198)
- SetProcessWindowStation (Address: 0x11c7819c)
- SetThreadDesktop (Address: 0x11c781a0)
- SetTimer (Address: 0x11c781a4)
- SetWindowLongW (Address: 0x11c781ac)
- SetWindowPos (Address: 0x11c781b0)
- SetWindowRgn (Address: 0x11c781b4)
- SetWindowsHookExW (Address: 0x11c781bc)
- SetWindowTextW (Address: 0x11c781b8)
- SetWinEventHook (Address: 0x11c781a8)
- ShowWindow (Address: 0x11c781c0)
- ToUnicodeEx (Address: 0x11c781c4)
- TranslateMessage (Address: 0x11c781c8)
- UnhookWindowsHookEx (Address: 0x11c781d0)
- UnhookWinEvent (Address: 0x11c781cc)
- UnregisterClassW (Address: 0x11c781d4)
- UnregisterHotKey (Address: 0x11c781d8)
- WindowFromPoint (Address: 0x11c781dc)
USERENV.dll
- CreateEnvironmentBlock (Address: 0x11c784c0)
- DestroyEnvironmentBlock (Address: 0x11c784c4)
- EnterCriticalPolicySection (Address: 0x11c784c8)
- GetProfileType (Address: 0x11c784cc)
- LeaveCriticalPolicySection (Address: 0x11c784d0)
- RegisterGPNotification (Address: 0x11c784d4)
- UnregisterGPNotification (Address: 0x11c784d8)
WINHTTP.dll
- WinHttpCloseHandle (Address: 0x11c7865c)
- WinHttpGetIEProxyConfigForCurrentUser (Address: 0x11c78660)
- WinHttpGetProxyForUrl (Address: 0x11c78664)
- WinHttpOpen (Address: 0x11c78668)
- WinHttpSetTimeouts (Address: 0x11c7866c)
WINMM.dll
- timeBeginPeriod (Address: 0x11c78614)
- timeEndPeriod (Address: 0x11c78618)
- timeGetTime (Address: 0x11c7861c)
WINTRUST.dll
- WinVerifyTrust (Address: 0x11c7859c)
wkscli.dll
- NetGetJoinInformation (Address: 0x11c784e0)
WS2_32.dll
- accept (Address: 0x11c78448)
- bind (Address: 0x11c7844c)
- closesocket (Address: 0x11c78450)
- connect (Address: 0x11c78454)
- freeaddrinfo (Address: 0x11c78458)
- FreeAddrInfoExW (Address: 0x11c783ec)
- getaddrinfo (Address: 0x11c7845c)
- GetAddrInfoExCancel (Address: 0x11c783f0)
- GetAddrInfoExW (Address: 0x11c783f4)
- gethostname (Address: 0x11c78460)
- getpeername (Address: 0x11c78464)
- getsockname (Address: 0x11c78468)
- getsockopt (Address: 0x11c7846c)
- htonl (Address: 0x11c78470)
- htons (Address: 0x11c78474)
- inet_ntop (Address: 0x11c78478)
- ioctlsocket (Address: 0x11c7847c)
- listen (Address: 0x11c78480)
- ntohl (Address: 0x11c78484)
- ntohs (Address: 0x11c78488)
- recv (Address: 0x11c7848c)
- recvfrom (Address: 0x11c78490)
- send (Address: 0x11c78494)
- sendto (Address: 0x11c78498)
- setsockopt (Address: 0x11c7849c)
- shutdown (Address: 0x11c784a0)
- socket (Address: 0x11c784a4)
- WSACloseEvent (Address: 0x11c783f8)
- WSACreateEvent (Address: 0x11c783fc)
- WSAEnumNetworkEvents (Address: 0x11c78400)
- WSAEnumProtocolsW (Address: 0x11c78404)
- WSAEventSelect (Address: 0x11c78408)
- WSAGetLastError (Address: 0x11c7840c)
- WSAGetOverlappedResult (Address: 0x11c78410)
- WSAIoctl (Address: 0x11c78414)
- WSALookupServiceBeginW (Address: 0x11c78418)
- WSALookupServiceEnd (Address: 0x11c7841c)
- WSALookupServiceNextW (Address: 0x11c78420)
- WSARecv (Address: 0x11c78424)
- WSARecvFrom (Address: 0x11c78428)
- WSAResetEvent (Address: 0x11c7842c)
- WSASend (Address: 0x11c78430)
- WSASendTo (Address: 0x11c78434)
- WSASetEvent (Address: 0x11c78438)
- WSASocketW (Address: 0x11c7843c)
- WSAStartup (Address: 0x11c78440)
- WSAWaitForMultipleEvents (Address: 0x11c78444)
WTSAPI32.dll
- WTSEnumerateSessionsW (Address: 0x11c78338)
- WTSFreeMemory (Address: 0x11c7833c)
- WTSQuerySessionInformationW (Address: 0x11c78340)
- WTSQueryUserToken (Address: 0x11c78344)
- WTSRegisterSessionNotification (Address: 0x11c78348)
- WTSUnRegisterSessionNotification (Address: 0x11c7834c)