rdpbase.dll
Description: Rdp OneCore Base Services
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6216
Architecture: 64-bit
Operating System: Windows NT
SHA256: 7ce2ca3817ff22ef074dca68032003f0
File Size: 1.5 MB
Uploaded At: Dec. 1, 2025, 7:37 a.m.
Views: 8
Exported Functions
- ??0CRDPCache@@QEAA@XZ (Ordinal: 1, Address: 0x106b0)
- ??0CRDPENCONResolver@@QEAA@XZ (Ordinal: 2, Address: 0xacab0)
- ??0NSCodecDecompressor@@QEAA@_N@Z (Ordinal: 3, Address: 0x543f0)
- ??0PipeETWEvents@@QEAA@XZ (Ordinal: 4, Address: 0x87450)
- ??0RdpEncodeBuffer@@QEAA@PEAVITSObjectPool@@@Z (Ordinal: 5, Address: 0x44970)
- ??0RdpGfxProtocolBaseDecoder@@IEAA@XZ (Ordinal: 6, Address: 0x44f30)
- ??0SSECBCHash2@@QEAA@XZ (Ordinal: 7, Address: 0x26260)
- ??1CRDPCache@@UEAA@XZ (Ordinal: 8, Address: 0x8d810)
- ??1CRDPENCONResolver@@QEAA@XZ (Ordinal: 9, Address: 0xacbe0)
- ??1Evict@@QEAA@XZ (Ordinal: 10, Address: 0x8aa50)
- ??1RdpGfxProtocolBaseDecoder@@IEAA@XZ (Ordinal: 11, Address: 0x44f60)
- ?AddConnection@CRDPENCONResolver@@QEAAJPEAGKH@Z (Ordinal: 12, Address: 0xacd20)
- ?AddPortMapping@CRDPENCConnectorStringSerializer@@UEAAJPEAGK@Z (Ordinal: 13, Address: 0xaee00)
- ?AlphaCompressor__CreateInstance@@YAJPEAPEAUIRdpImageCompressor@@@Z (Ordinal: 14, Address: 0x53b70)
- ?ClearCache@CRDPCache@@UEAAJXZ (Ordinal: 15, Address: 0x8d8f0)
- ?Compress@NSCodecCompressor@@QEAA_NAEBVPixelMap@@_NPEAEIAEAI@Z (Ordinal: 16, Address: 0x17010)
- ?CompressRdp8__CreateInstance@@YAJPEAPEAVIRdpPipeCompress@@I@Z (Ordinal: 17, Address: 0x70f50)
- ?CreateInstance@CRDPENCONPort@@SAJPEAUaddrinfo@@HPEAXPEAPEAV1@@Z (Ordinal: 18, Address: 0xafc30)
- ?CreateInstance@CRdpGfxCapsSet@@SAJPEAXKPEAPEAUIRdpGfxCapsSet@@@Z (Ordinal: 19, Address: 0x453c0)
- ?CreateInstance@Evict@@SAJKKKKKPEAPEAV1@@Z (Ordinal: 20, Address: 0x8abf0)
- ?CreateInstance@HashTable@@SAJKKPEAPEAUIHashBucket@@@Z (Ordinal: 21, Address: 0x8b370)
- ?CreateInstance@NSCodecCompressor@@SA_N_N00EAEAV?$TCntPtr@VNSCodecCompressor@@@@@Z (Ordinal: 22, Address: 0x54ec0)
- ?CreateInstance@PlanarCompressor@@SAJGGEHHHPEAPEAUIRdpImageCompressor@@@Z (Ordinal: 23, Address: 0x56af0)
- ?CreateInstance@RdpEncodeBuffer@@SAJPEAVRdpEncodeBufferPool@@KPEAPEAV1@@Z (Ordinal: 24, Address: 0x44ab0)
- ?Decompress@NSCodecDecompressor@@QEAA_NPEBEIAEAVPixelMap@@@Z (Ordinal: 25, Address: 0x54f40)
- ?DecompressRdp8__CreateInstance@@YAJPEAPEAVIRdpPipeDecompress@@@Z (Ordinal: 26, Address: 0x71740)
- ?Enable@PipeETWEvents@@UEAAJKK@Z (Ordinal: 27, Address: 0x87b20)
- ?EvictEntry@Evict@@QEAAPEAU_SCORE_ENTRY@@XZ (Ordinal: 28, Address: 0x2d1c0)
- ?FakeSleep@PipelineClock@@QEAAX_K@Z (Ordinal: 29, Address: 0x8b9a0)
- ?GetFreeEntry@Evict@@QEAAPEAU_SCORE_ENTRY@@XZ (Ordinal: 30, Address: 0x8ad80)
- ?GetInstance@PipelineClock@@SAAEAV1@XZ (Ordinal: 31, Address: 0x1fe80)
- ?GetMillisecondCount64@PipelineClock@@QEAA_KXZ (Ordinal: 32, Address: 0x8b9f0)
- ?GetMillisecondCount@PipelineClock@@QEAAIXZ (Ordinal: 33, Address: 0x24d40)
- ?GetNext@CRDPENCONIPHelper@@QEAAPEAU_SOCKET_ADDRESS@@XZ (Ordinal: 34, Address: 0xb0b70)
- ?GetNext@CRDPENCONResolver@@QEAAHPEAPEAUsockaddr@@PEA_K@Z (Ordinal: 35, Address: 0xad970)
- ?GetPortMapping@CRDPENCConnectorStringDeserializer@@QEAAJKPEAPEAGPEAK@Z (Ordinal: 36, Address: 0xaf170)
- ?GetTickCount@PipelineClock@@QEAAIXZ (Ordinal: 37, Address: 0x1fc00)
- ?GetTimeHNS@PipelineClock@@QEAA_JXZ (Ordinal: 38, Address: 0x32d60)
- ?HintCoconet__CreateInstance@@YAJPEAPEAVIRdpPipeCompressHintProvider@@@Z (Ordinal: 39, Address: 0x71af0)
- ?Initialize@CRDPENCONIPHelper@@QEAAJKHPEAG@Z (Ordinal: 40, Address: 0xb0be0)
- ?Initialize@PipeETWEvents@@UEAAJPEAUIUnknown@@@Z (Ordinal: 41, Address: 0x88c50)
- ?InitializeInstance@CRDPENCConnectorStringSerializer@@UEAAJXZ (Ordinal: 42, Address: 0xaf340)
- ?InsertEntry@Evict@@QEAAXPEAU_SCORE_ENTRY@@K@Z (Ordinal: 43, Address: 0x30e20)
- ?IsSupportedVersion@CRdpGfxCaps@@SAHK@Z (Ordinal: 44, Address: 0x45e80)
- ?IsTestMode@PipelineClock@@QEAA_NXZ (Ordinal: 45, Address: 0x373a0)
- ?NSRunLengthDecode@@YAKPEBEKPEAEK@Z (Ordinal: 46, Address: 0x55580)
- ?PAL_System_Win32_IsRunningInAppContainer@@YAHXZ (Ordinal: 47, Address: 0xde3d0)
- ?ParkEntry@Evict@@QEAAXPEAU_SCORE_ENTRY@@@Z (Ordinal: 48, Address: 0x8b1f0)
- ?ProcessAlignedData_AVX@SSECBCHash2@@AEAAXPEBIIII@Z (Ordinal: 49, Address: 0x108b0)
- ?ProcessAlignedData_SSE2@SSECBCHash2@@AEAAXPEBIIII@Z (Ordinal: 50, Address: 0x7c7e0)
- ?ProcessAlignedData_SSE41@SSECBCHash2@@AEAAXPEBIIII@Z (Ordinal: 51, Address: 0x7cb20)
- ?ProcessUnalignedData_REG@SSECBCHash2@@AEAAXPEBIIII@Z (Ordinal: 52, Address: 0x203f0)
- ?PromoteEntry@Evict@@QEAAXKK@Z (Ordinal: 53, Address: 0x26510)
- ?RdpGfxProtocolServerEncoder_CreateInstance@@YAJPEAVIRdpEncoderIO@@PEAPEAVIRdpPipeProtocolEncoderEx@@@Z (Ordinal: 54, Address: 0x8d330)
- ?RdpPerfLoggerStaticInitialize@@YAXXZ (Ordinal: 55, Address: 0xdcee0)
- ?RdpPerfLoggerStaticTerminate@@YAXXZ (Ordinal: 56, Address: 0xdcf00)
- ?Reset@CRDPCache@@UEAAJI@Z (Ordinal: 57, Address: 0x8dbe0)
- ?SearchCache@CRDPCache@@UEAAJIIPEAPEAUIUnknown@@PEAI@Z (Ordinal: 58, Address: 0x8de20)
- ?SetCacheEntry@CRDPCache@@UEAAJIIPEAUIUnknown@@PEAI@Z (Ordinal: 59, Address: 0x8dfa0)
- ?SetConnectorId@CRDPENCConnectorStringSerializer@@UEAAJK@Z (Ordinal: 60, Address: 0xaf4e0)
- ?SetDecodeBuffer@RdpGfxProtocolBaseDecoder@@IEAAXPEBEI@Z (Ordinal: 61, Address: 0x35a60)
- ?SetSessionId@CRDPENCConnectorStringSerializer@@UEAAJI@Z (Ordinal: 62, Address: 0xaf570)
- ?SortAddresses@CRDPENCONResolver@@QEAAJXZ (Ordinal: 63, Address: 0xae680)
- ?StartEnum@CRDPENCONIPHelper@@QEAAHXZ (Ordinal: 64, Address: 0xb0e10)
- ?StartEnum@CRDPENCONResolver@@QEAAIXZ (Ordinal: 65, Address: 0xaebe0)
- TSFree (Ordinal: 66, Address: 0x341c0)
- ?Terminate@CRDPENCONIPHelper@@QEAAJXZ (Ordinal: 67, Address: 0xb0e40)
- ?UnevictEntry@Evict@@QEAAXPEAU_SCORE_ENTRY@@@Z (Ordinal: 68, Address: 0x8b270)
- ?UpdateKeys@SSECBCHash2@@AEBAXXZ (Ordinal: 69, Address: 0x1f7c0)
- ?XMLDeserialize@CRDPENCConnectorStringDeserializer@@QEAAJPEAG@Z (Ordinal: 70, Address: 0xaf600)
- ?XMLSerialize@CRDPENCConnectorStringSerializer@@UEAAJPEAPEAG@Z (Ordinal: 71, Address: 0xaf9b0)
- ?XObjectId_RdpXHttpSession_CreateObject@@YA?AW4_XResult32@@PEAURdpXInterface@@IW4_XInterfaceId32@@PEAPEAX@Z (Ordinal: 72, Address: 0x4f130)
- ?XObjectId_RdpXInterfaceUriComponents_CreateObject@@YA?AW4_XResult32@@PEAURdpXInterface@@IW4_XInterfaceId32@@PEAPEAX@Z (Ordinal: 73, Address: 0x4f1e0)
- ?XObjectId_RdpXSecFilterServer_CreateObject@@YA?AW4_XResult32@@PEAURdpXInterface@@IW4_XInterfaceId32@@PEAPEAX@Z (Ordinal: 74, Address: 0x1dbc0)
- ApplyLuminanceFilter (Ordinal: 75, Address: 0x185e0)
- ApplySobelFilterOnLum (Ordinal: 76, Address: 0x7ce50)
- BitmapCombinePlanes (Ordinal: 77, Address: 0x58690)
- CAPAPI_AddCapSet (Ordinal: 78, Address: 0x6c5f0)
- CAPAPI_GetCapSet (Ordinal: 79, Address: 0x6c610)
- CAPAPI_InitializeCombinedCaps (Ordinal: 80, Address: 0x36e50)
- CAPAPI_MergeCombinedCaps (Ordinal: 81, Address: 0x6c660)
- CRDPBitmapRecorder_CreateInstance (Ordinal: 82, Address: 0x8f410)
- CRDPCacCodecEncoder_CreateInstance (Ordinal: 83, Address: 0x39900)
- CRDPCacCodec_CreateInstance (Ordinal: 84, Address: 0x399f0)
- CRDPCacVideoCodecForHardwareClient_CreateInstance (Ordinal: 85, Address: 0x39b10)
- CRDPCacVideoCodec_CreateInstance (Ordinal: 86, Address: 0x36670)
- CRDPCaps_CreateInstance (Ordinal: 87, Address: 0x37380)
- CRDPENCGfxEncoder_CreateInstance (Ordinal: 88, Address: 0x91870)
- CRDPNsCodec_CreateInstance (Ordinal: 89, Address: 0x562c0)
- CRDPPlanarCompressor_CreateInstance (Ordinal: 90, Address: 0x57630)
- CRdpFIPSEncryption_CreateInstance (Ordinal: 91, Address: 0x84fb0)
- DecryptData (Ordinal: 92, Address: 0x113500)
- DecryptDataEx (Ordinal: 93, Address: 0x1135c0)
- DrawBox (Ordinal: 94, Address: 0x7d270)
- DrawHLine (Ordinal: 95, Address: 0x7d300)
- DrawIconToPixelMap (Ordinal: 96, Address: 0x18c30)
- DrawVLine (Ordinal: 97, Address: 0x7d3b0)
- EncryptClientRandom (Ordinal: 98, Address: 0x113700)
- EncryptData (Ordinal: 99, Address: 0x113690)
- ExpandRectForSSE (Ordinal: 100, Address: 0x315f0)
- GetSupportedSSELevel_SSE (Ordinal: 101, Address: 0x1b590)
- GridBA_CreateInstance (Ordinal: 102, Address: 0x7fd00)
- MakeSessionKeys (Ordinal: 103, Address: 0x113cf0)
- MemCopyAligned_SSE (Ordinal: 104, Address: 0x13560)
- MemEqual (Ordinal: 105, Address: 0x2830)
- MemMoveReverseAligned_SSE (Ordinal: 106, Address: 0x7da40)
- PAL_System_AtomicCompareAndExchange (Ordinal: 107, Address: 0x25560)
- PAL_System_AtomicCompareAndExchangePointer (Ordinal: 108, Address: 0x86690)
- PAL_System_AtomicDecrement (Ordinal: 109, Address: 0x4040)
- PAL_System_AtomicExchange (Ordinal: 110, Address: 0x866b0)
- PAL_System_AtomicExchangeAdd (Ordinal: 111, Address: 0x866d0)
- PAL_System_AtomicExchangePointer (Ordinal: 112, Address: 0x866f0)
- PAL_System_AtomicIncrement (Ordinal: 113, Address: 0x3f40)
- PAL_System_Beep (Ordinal: 114, Address: 0xe0680)
- PAL_System_CondAlloc (Ordinal: 115, Address: 0x86710)
- PAL_System_CondReset (Ordinal: 116, Address: 0x86770)
- PAL_System_CondSignal (Ordinal: 117, Address: 0xdec0)
- PAL_System_CondWait (Ordinal: 118, Address: 0x25990)
- PAL_System_ConvertToAndFromWideChar (Ordinal: 119, Address: 0xe1da0)
- PAL_System_CreateGuid (Ordinal: 120, Address: 0xe1e10)
- PAL_System_CredProtect (Ordinal: 121, Address: 0xe06a0)
- PAL_System_CredUnprotect (Ordinal: 122, Address: 0xe06b0)
- PAL_System_CritSecEnter (Ordinal: 123, Address: 0xd020)
- PAL_System_CritSecInit (Ordinal: 124, Address: 0xfda0)
- PAL_System_CritSecIsLockedByCurrentThread (Ordinal: 125, Address: 0x35250)
- PAL_System_CritSecLeave (Ordinal: 126, Address: 0xcc10)
- PAL_System_CritSecTerminate (Ordinal: 127, Address: 0x2ca0)
- PAL_System_CritSecTryEnter (Ordinal: 128, Address: 0x867a0)
- PAL_System_CryptDecryptLegacy (Ordinal: 129, Address: 0xe06c0)
- PAL_System_CryptEncrypt (Ordinal: 130, Address: 0xe06e0)
- PAL_System_CryptFree (Ordinal: 131, Address: 0xe0700)
- PAL_System_CryptZeroMemory (Ordinal: 132, Address: 0xe1e30)
- PAL_System_DebugBreak (Ordinal: 133, Address: 0x83d20)
- PAL_System_DebugOutput (Ordinal: 134, Address: 0x83d40)
- PAL_System_GetComputerName (Ordinal: 135, Address: 0xe0780)
- PAL_System_GetFIPSAlgorithmEnabled (Ordinal: 136, Address: 0x83d80)
- PAL_System_GetLocalSessionId (Ordinal: 137, Address: 0xe07b0)
- PAL_System_GetModuleFilename (Ordinal: 138, Address: 0x83f00)
- PAL_System_GetNetworkStatus (Ordinal: 139, Address: 0xe0870)
- PAL_System_GetNumberOfProcessors (Ordinal: 140, Address: 0x324a0)
- PAL_System_GetWindowsProductId (Ordinal: 141, Address: 0xe0d50)
- PAL_System_HandleFree (Ordinal: 142, Address: 0x2ce0)
- PAL_System_MemAlloc (Ordinal: 143, Address: 0x2fba0)
- PAL_System_MemFree (Ordinal: 144, Address: 0x341c0)
- PAL_System_NetworkMonitorInit (Ordinal: 145, Address: 0xe0e00)
- PAL_System_NetworkMonitorNotification (Ordinal: 146, Address: 0xe1e60)
- PAL_System_NetworkMonitorTerminate (Ordinal: 147, Address: 0xe1220)
- PAL_System_SecureZeroMemory (Ordinal: 148, Address: 0xe1e90)
- PAL_System_SemaphoreAcquire (Ordinal: 149, Address: 0x86a50)
- PAL_System_SemaphoreAlloc (Ordinal: 150, Address: 0x30270)
- PAL_System_SemaphoreRelease (Ordinal: 151, Address: 0x1f440)
- PAL_System_SingleCondWait (Ordinal: 152, Address: 0x86b00)
- PAL_System_Sleep (Ordinal: 153, Address: 0x84050)
- PAL_System_SwitchToThread (Ordinal: 154, Address: 0x84070)
- PAL_System_ThreadGetId (Ordinal: 155, Address: 0x2d180)
- PAL_System_TimeGetCurrent (Ordinal: 156, Address: 0x86b50)
- PAL_System_TimeGetDynamicTimeZoneInformation (Ordinal: 157, Address: 0xe12e0)
- PAL_System_TimeGetTickCount (Ordinal: 158, Address: 0x32cd0)
- PAL_System_TimeGetTickCount64 (Ordinal: 159, Address: 0x86bc0)
- PAL_System_TimeGetTimeZoneInformation (Ordinal: 160, Address: 0xe1eb0)
- PAL_System_TimerCancel (Ordinal: 161, Address: 0xe1550)
- PAL_System_TimerDelete (Ordinal: 162, Address: 0xe1750)
- PAL_System_TimerInit (Ordinal: 163, Address: 0xe17d0)
- PAL_System_TimerIsSet (Ordinal: 164, Address: 0xe1940)
- PAL_System_TimerSet (Ordinal: 165, Address: 0xe19b0)
- PAL_System_WideCharToUnicode16 (Ordinal: 166, Address: 0xe2010)
- RDPAPI_GetGenericCounter (Ordinal: 167, Address: 0x213e0)
- RDPAPI_GetGlobalObject (Ordinal: 168, Address: 0x260a0)
- RDPAPI_GetLongCounter (Ordinal: 169, Address: 0x9ea60)
- RDPBASE_CreateInstance (Ordinal: 170, Address: 0x36660)
- RDPCompress (Ordinal: 171, Address: 0x50990)
- RDPCompressEx (Ordinal: 172, Address: 0x509f0)
- RDPCompress_GetContextSize (Ordinal: 173, Address: 0x50a90)
- RDPCompress_InitRecvContext (Ordinal: 174, Address: 0x50ac0)
- RDPCompress_InitSendContext (Ordinal: 175, Address: 0x50b10)
- RDPDeCompress_GetContextSize (Ordinal: 176, Address: 0x50b60)
- RDPDecompress (Ordinal: 177, Address: 0x50ba0)
- RDPENCDirectConnector_CreateInstance (Ordinal: 178, Address: 0xb2eb0)
- RDPENCGDIHLP_FlipBitmapBits (Ordinal: 179, Address: 0x9eeb0)
- RDPENCGDIHLP_FlipBitmapBitsInPlace (Ordinal: 180, Address: 0x9ef80)
- RDPENCGDIHLP_ValidatePointerParams (Ordinal: 181, Address: 0x9f1e0)
- RDPENCHLPREG_ReadValueDWORD (Ordinal: 182, Address: 0x25f70)
- RDPENCHLPWSErr2Hr (Ordinal: 183, Address: 0x9f480)
- RDPENCHLPWS_GetIPFromAddr (Ordinal: 184, Address: 0x2b820)
- RDPENCHLPWS_GetPortFromAddr (Ordinal: 185, Address: 0x341e0)
- RDPENCHLP_GetInputDesktopName (Ordinal: 186, Address: 0x9f5e0)
- RDPENCHLP_IsGreaterThanOrEqWin8 (Ordinal: 187, Address: 0x9f740)
- RDPENCHLP_IsSessionActive (Ordinal: 188, Address: 0x9f820)
- RDPENCHLP_IsSessionRemote (Ordinal: 189, Address: 0x9f980)
- RDPENCHLP_TraceWindowInfo (Ordinal: 190, Address: 0x9fa90)
- RDPENCORE_AddGlobalObject (Ordinal: 191, Address: 0xa06a0)
- RDPServerStackDiagnostics_LogCheckpoint (Ordinal: 192, Address: 0xdd520)
- RDPServerStackDiagnostics_LogDisconnect (Ordinal: 193, Address: 0xdd5a0)
- RDPServerStackDiagnostics_LogFailure (Ordinal: 194, Address: 0x36be0)
- RDPServerStackDiagnostics_Register (Ordinal: 195, Address: 0xdd650)
- RDPServerStackDiagnostics_Unregister (Ordinal: 196, Address: 0xdd690)
- RDPWSStreamConnector_CreateInstance (Ordinal: 197, Address: 0xdc9d0)
- RDP_HMACMD5Final (Ordinal: 198, Address: 0x114070)
- RDP_HMACMD5Init (Ordinal: 199, Address: 0x1140c0)
- RDP_HMACMD5Update (Ordinal: 200, Address: 0x114180)
- RDP_MD5Final (Ordinal: 201, Address: 0x1141d0)
- RDP_MD5Init (Ordinal: 202, Address: 0x114220)
- RDP_MD5Update (Ordinal: 203, Address: 0x114180)
- RDP_RC4 (Ordinal: 204, Address: 0x1142d0)
- RDP_RC4AllocKey (Ordinal: 205, Address: 0x114320)
- RDP_RC4FreeKey (Ordinal: 206, Address: 0x114380)
- RDP_RC4SetKey (Ordinal: 207, Address: 0x1143c0)
- RDP_RC4ZeroKey (Ordinal: 208, Address: 0x114490)
- RDP_RsaBCryptDecryptPrivate (Ordinal: 209, Address: 0x1144b0)
- RDP_RsaBCryptGenerateRsaKeyPair (Ordinal: 210, Address: 0x114610)
- RDP_RsaBCryptPubKeyToBSafePubKey (Ordinal: 211, Address: 0x114830)
- RDP_RsaBSafeEncPublic (Ordinal: 212, Address: 0x114950)
- RDP_RsaGetPublicKeyDataLength (Ordinal: 213, Address: 0x114b10)
- RDP_RsaGetPublicKeyLength (Ordinal: 214, Address: 0x114b30)
- RDP_SHAFinal (Ordinal: 215, Address: 0x114b50)
- RDP_SHAInit (Ordinal: 216, Address: 0x114ba0)
- RDP_SHAUpdate (Ordinal: 217, Address: 0x114180)
- RdpIntersectRect (Ordinal: 218, Address: 0x7d7f0)
- RdpTiledSurface_CreateInstance (Ordinal: 219, Address: 0x93930)
- RdpUnionRect (Ordinal: 220, Address: 0x7d850)
- RdpX_AtomicDecrement32 (Ordinal: 221, Address: 0x35330)
- RdpX_AtomicIncrement32 (Ordinal: 222, Address: 0x34cb0)
- RdpX_DateTime_GetHighResolutionTimeSinceReboot (Ordinal: 223, Address: 0x32830)
- RdpX_DebugBreak (Ordinal: 224, Address: 0x44800)
- RdpX_GetActivityIdPrefix (Ordinal: 225, Address: 0x13470)
- RdpX_Threading_CreateCriticalSection (Ordinal: 226, Address: 0x373c0)
- RgnlibBA_CreateInstance (Ordinal: 227, Address: 0x2bd00)
- SaveImageToFile (Ordinal: 228, Address: 0x7d470)
- SubtractRects (Ordinal: 229, Address: 0x7d8b0)
- TRC_TraceBufferW (Ordinal: 230, Address: 0x53960)
- TSAlloc (Ordinal: 231, Address: 0x7c7d0)
- TSCreateBaseServices (Ordinal: 232, Address: 0x73f00)
- TSCreateCoreEvents (Ordinal: 233, Address: 0x77530)
- TSCreatePlatform (Ordinal: 234, Address: 0x79030)
- TSDbgAssertThread (Ordinal: 235, Address: 0x370e0)
- TSRNG_GenerateRandomBits (Ordinal: 236, Address: 0x113f50)
- TsAddRectsToRegion (Ordinal: 237, Address: 0x12140)
- TsCreateRegion (Ordinal: 238, Address: 0x2c040)
- TsDestroyRegion (Ordinal: 239, Address: 0x316f0)
- TsGetRegionBoundingBox (Ordinal: 240, Address: 0x34630)
- TsGetRegionRectCount (Ordinal: 241, Address: 0x23ae0)
- TsGetRegionRects (Ordinal: 242, Address: 0x11a90)
- TsSetRegionFromRects (Ordinal: 243, Address: 0x2d330)
- UnpackServerCert (Ordinal: 244, Address: 0x113810)
- UpdateSessionKey (Ordinal: 245, Address: 0x113ec0)
- ValidateServerCert (Ordinal: 246, Address: 0x1138d0)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180139e90)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x180139ea0)
- CoCreateGuid (Address: 0x180139ec0)
- CoCreateInstance (Address: 0x180139eb0)
- IIDFromString (Address: 0x180139eb8)
- StringFromGUID2 (Address: 0x180139ea8)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180139ed8)
- IsDebuggerPresent (Address: 0x180139ee0)
- OutputDebugStringW (Address: 0x180139ed0)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180139ef0)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180139f00)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180139f10)
- RaiseException (Address: 0x180139f20)
- SetLastError (Address: 0x180139f18)
- SetUnhandledExceptionFilter (Address: 0x180139f28)
- UnhandledExceptionFilter (Address: 0x180139f30)
api-ms-win-core-featurestaging-l1-1-0.dll
- GetFeatureEnabledState (Address: 0x180139f40)
- RecordFeatureUsage (Address: 0x180139f50)
- SubscribeFeatureStateChangeNotification (Address: 0x180139f58)
- UnsubscribeFeatureStateChangeNotification (Address: 0x180139f48)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x180139f70)
- ReadFile (Address: 0x180139f68)
- WriteFile (Address: 0x180139f78)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180139f90)
- DuplicateHandle (Address: 0x180139f88)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180139fb0)
- HeapAlloc (Address: 0x180139fa8)
- HeapFree (Address: 0x180139fa0)
api-ms-win-core-heap-l2-1-0.dll
- GlobalFree (Address: 0x180139fc0)
- LocalAlloc (Address: 0x180139fd0)
- LocalFree (Address: 0x180139fc8)
api-ms-win-core-io-l1-1-0.dll
- GetOverlappedResult (Address: 0x180139fe0)
api-ms-win-core-io-l1-1-1.dll
- CancelIo (Address: 0x180139ff0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- GetComputerNameW (Address: 0x18013a000)
- WTSGetActiveConsoleSessionId (Address: 0x18013a008)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
- VerifyVersionInfoW (Address: 0x18013a018)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x18013a028)
- FreeLibrary (Address: 0x18013a058)
- FreeLibraryAndExitThread (Address: 0x18013a040)
- GetModuleFileNameA (Address: 0x18013a038)
- GetModuleFileNameW (Address: 0x18013a070)
- GetModuleHandleA (Address: 0x18013a078)
- GetModuleHandleExA (Address: 0x18013a050)
- GetModuleHandleExW (Address: 0x18013a060)
- GetModuleHandleW (Address: 0x18013a030)
- GetProcAddress (Address: 0x18013a048)
- LoadLibraryExW (Address: 0x18013a068)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryW (Address: 0x18013a088)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18013a098)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x18013a0c8)
- MapViewOfFileEx (Address: 0x18013a0b0)
- UnmapViewOfFile (Address: 0x18013a0b8)
- VirtualAlloc (Address: 0x18013a0c0)
- VirtualFree (Address: 0x18013a0a8)
api-ms-win-core-namedpipe-l1-1-0.dll
- ConnectNamedPipe (Address: 0x18013a0e8)
- CreateNamedPipeW (Address: 0x18013a0d8)
- DisconnectNamedPipe (Address: 0x18013a0e0)
- WaitNamedPipeW (Address: 0x18013a0f0)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x18013a168)
- GetCurrentProcess (Address: 0x18013a140)
- GetCurrentProcessId (Address: 0x18013a148)
- GetCurrentThread (Address: 0x18013a110)
- GetCurrentThreadId (Address: 0x18013a100)
- GetExitCodeThread (Address: 0x18013a160)
- OpenProcessToken (Address: 0x18013a130)
- OpenThread (Address: 0x18013a138)
- OpenThreadToken (Address: 0x18013a108)
- ProcessIdToSessionId (Address: 0x18013a120)
- SetThreadPriority (Address: 0x18013a170)
- SwitchToThread (Address: 0x18013a150)
- TerminateProcess (Address: 0x18013a178)
- TlsAlloc (Address: 0x18013a118)
- TlsFree (Address: 0x18013a128)
- TlsGetValue (Address: 0x18013a158)
- TlsSetValue (Address: 0x18013a180)
api-ms-win-core-processthreads-l1-1-1.dll
- GetProcessMitigationPolicy (Address: 0x18013a198)
- IsProcessorFeaturePresent (Address: 0x18013a190)
api-ms-win-core-processtopology-obsolete-l1-1-0.dll
- SetThreadAffinityMask (Address: 0x18013a1a8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18013a1b8)
- QueryPerformanceFrequency (Address: 0x18013a1c0)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18013a1d0)
- RegEnumKeyExW (Address: 0x18013a1f8)
- RegGetValueW (Address: 0x18013a1e0)
- RegOpenKeyExW (Address: 0x18013a1d8)
- RegQueryInfoKeyW (Address: 0x18013a1f0)
- RegQueryValueExW (Address: 0x18013a1e8)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18013a218)
- RtlLookupFunctionEntry (Address: 0x18013a210)
- RtlVirtualUnwind (Address: 0x18013a208)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x18013a228)
- WideCharToMultiByte (Address: 0x18013a230)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18013a278)
- AcquireSRWLockShared (Address: 0x18013a250)
- CancelWaitableTimer (Address: 0x18013a2b8)
- CreateEventW (Address: 0x18013a298)
- CreateMutexExW (Address: 0x18013a258)
- CreateSemaphoreExW (Address: 0x18013a2e8)
- CreateWaitableTimerExW (Address: 0x18013a308)
- DeleteCriticalSection (Address: 0x18013a2f0)
- EnterCriticalSection (Address: 0x18013a248)
- InitializeCriticalSection (Address: 0x18013a2c8)
- InitializeCriticalSectionAndSpinCount (Address: 0x18013a280)
- InitializeCriticalSectionEx (Address: 0x18013a2f8)
- InitializeSRWLock (Address: 0x18013a2c0)
- LeaveCriticalSection (Address: 0x18013a290)
- OpenEventW (Address: 0x18013a2e0)
- OpenSemaphoreW (Address: 0x18013a300)
- ReleaseMutex (Address: 0x18013a2a8)
- ReleaseSemaphore (Address: 0x18013a2d0)
- ReleaseSRWLockExclusive (Address: 0x18013a288)
- ReleaseSRWLockShared (Address: 0x18013a260)
- ResetEvent (Address: 0x18013a310)
- SetEvent (Address: 0x18013a2a0)
- SetWaitableTimer (Address: 0x18013a2d8)
- TryEnterCriticalSection (Address: 0x18013a240)
- WaitForMultipleObjectsEx (Address: 0x18013a268)
- WaitForSingleObject (Address: 0x18013a2b0)
- WaitForSingleObjectEx (Address: 0x18013a270)
api-ms-win-core-synch-l1-2-0.dll
- InitializeConditionVariable (Address: 0x18013a328)
- Sleep (Address: 0x18013a348)
- SleepConditionVariableCS (Address: 0x18013a330)
- SleepConditionVariableSRW (Address: 0x18013a340)
- WakeAllConditionVariable (Address: 0x18013a320)
- WakeConditionVariable (Address: 0x18013a338)
api-ms-win-core-synch-l1-2-1.dll
- CreateSemaphoreW (Address: 0x18013a358)
- CreateWaitableTimerW (Address: 0x18013a360)
- WaitForMultipleObjects (Address: 0x18013a368)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetLocalTime (Address: 0x18013a398)
- GetSystemDirectoryW (Address: 0x18013a378)
- GetSystemInfo (Address: 0x18013a390)
- GetSystemTime (Address: 0x18013a3b0)
- GetSystemTimeAsFileTime (Address: 0x18013a3b8)
- GetTickCount (Address: 0x18013a388)
- GetTickCount64 (Address: 0x18013a3a8)
- GetVersion (Address: 0x18013a3a0)
- GetVersionExW (Address: 0x18013a380)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetNativeSystemInfo (Address: 0x18013a3d0)
- VerSetConditionMask (Address: 0x18013a3c8)
api-ms-win-core-threadpool-l1-2-0.dll
- CancelThreadpoolIo (Address: 0x18013a420)
- CloseThreadpoolIo (Address: 0x18013a3e0)
- CloseThreadpoolTimer (Address: 0x18013a430)
- CloseThreadpoolWork (Address: 0x18013a400)
- CreateThreadpoolIo (Address: 0x18013a428)
- CreateThreadpoolTimer (Address: 0x18013a438)
- CreateThreadpoolWork (Address: 0x18013a410)
- SetThreadpoolTimer (Address: 0x18013a408)
- StartThreadpoolIo (Address: 0x18013a3f8)
- SubmitThreadpoolWork (Address: 0x18013a3e8)
- WaitForThreadpoolIoCallbacks (Address: 0x18013a418)
- WaitForThreadpoolTimerCallbacks (Address: 0x18013a3f0)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueueTimer (Address: 0x18013a458)
- DeleteTimerQueueTimer (Address: 0x18013a450)
- QueueUserWorkItem (Address: 0x18013a448)
api-ms-win-core-timezone-l1-1-0.dll
- GetTimeZoneInformation (Address: 0x18013a468)
- SystemTimeToFileTime (Address: 0x18013a470)
api-ms-win-core-util-l1-1-0.dll
- Beep (Address: 0x18013a480)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x18013a498)
- RoGetActivationFactory (Address: 0x18013a4a8)
- RoInitialize (Address: 0x18013a490)
- RoUninitialize (Address: 0x18013a4a0)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateStringReference (Address: 0x18013a4b8)
- WindowsDeleteString (Address: 0x18013a4c0)
- WindowsGetStringRawBuffer (Address: 0x18013a4c8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x18013a500)
- GetTraceEnableLevel (Address: 0x18013a4f0)
- GetTraceLoggerHandle (Address: 0x18013a4f8)
- RegisterTraceGuidsW (Address: 0x18013a4e8)
- TraceMessage (Address: 0x18013a4d8)
- UnregisterTraceGuids (Address: 0x18013a4e0)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x18013a520)
- EventRegister (Address: 0x18013a528)
- EventUnregister (Address: 0x18013a510)
- EventWriteTransfer (Address: 0x18013a518)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x18013a578)
- AllocateAndInitializeSid (Address: 0x18013a588)
- CopySid (Address: 0x18013a580)
- DuplicateToken (Address: 0x18013a558)
- FreeSid (Address: 0x18013a540)
- GetLengthSid (Address: 0x18013a560)
- GetSecurityDescriptorLength (Address: 0x18013a590)
- GetTokenInformation (Address: 0x18013a568)
- InitializeAcl (Address: 0x18013a570)
- InitializeSecurityDescriptor (Address: 0x18013a550)
- MakeSelfRelativeSD (Address: 0x18013a538)
- SetSecurityDescriptorDacl (Address: 0x18013a548)
api-ms-win-security-credentials-l1-1-0.dll
- CredProtectW (Address: 0x18013a5a8)
- CredUnprotectW (Address: 0x18013a5a0)
api-ms-win-security-cryptoapi-l1-1-0.dll
- CryptAcquireContextW (Address: 0x18013a5f0)
- CryptCreateHash (Address: 0x18013a5f8)
- CryptDecrypt (Address: 0x18013a600)
- CryptDestroyHash (Address: 0x18013a5d0)
- CryptDestroyKey (Address: 0x18013a5e0)
- CryptGenRandom (Address: 0x18013a5b8)
- CryptGetHashParam (Address: 0x18013a5c8)
- CryptGetUserKey (Address: 0x18013a5e8)
- CryptHashData (Address: 0x18013a5d8)
- CryptReleaseContext (Address: 0x18013a5c0)
api-ms-win-security-provider-l1-1-0.dll
- SetEntriesInAclW (Address: 0x18013a610)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertStringSidToSidW (Address: 0x18013a620)
api-ms-win-security-systemfunctions-l1-1-0.dll
- SystemFunction036 (Address: 0x18013a630)
AUTHZ.dll
- AuthziSourceAudit (Address: 0x180139bd0)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x18013a658)
- BCryptCreateHash (Address: 0x18013a648)
- BCryptDecrypt (Address: 0x18013a6a0)
- BCryptDestroyHash (Address: 0x18013a688)
- BCryptDestroyKey (Address: 0x18013a668)
- BCryptEncrypt (Address: 0x18013a670)
- BCryptExportKey (Address: 0x18013a640)
- BCryptFinalizeKeyPair (Address: 0x18013a698)
- BCryptFinishHash (Address: 0x18013a660)
- BCryptGenerateKeyPair (Address: 0x18013a6b8)
- BCryptGenerateSymmetricKey (Address: 0x18013a680)
- BCryptGetFipsAlgorithmMode (Address: 0x18013a678)
- BCryptGetProperty (Address: 0x18013a6b0)
- BCryptHashData (Address: 0x18013a6c0)
- BCryptImportKey (Address: 0x18013a6a8)
- BCryptImportKeyPair (Address: 0x18013a690)
- BCryptOpenAlgorithmProvider (Address: 0x18013a650)
CRYPT32.dll
- CertCloseStore (Address: 0x180139bf8)
- CertDuplicateCertificateContext (Address: 0x180139c08)
- CertFindCertificateInStore (Address: 0x180139bf0)
- CertFreeCertificateContext (Address: 0x180139c00)
- CertGetCertificateContextProperty (Address: 0x180139c38)
- CertGetIssuerCertificateFromStore (Address: 0x180139c28)
- CertGetNameStringW (Address: 0x180139c18)
- CertOpenStore (Address: 0x180139be8)
- CryptAcquireCertificatePrivateKey (Address: 0x180139c20)
- CryptProtectMemory (Address: 0x180139c30)
- CryptStringToBinaryW (Address: 0x180139c10)
- CryptUnprotectData (Address: 0x180139be0)
IPHLPAPI.DLL
- CreateSortedAddressPairs (Address: 0x180139c48)
- FreeMibTable (Address: 0x180139c50)
msvcrt.dll
- __C_specific_handler (Address: 0x18013a7e8)
- __CxxFrameHandler3 (Address: 0x18013a770)
- __dllonexit (Address: 0x18013a7c0)
- __RTDynamicCast (Address: 0x18013a7b8)
- _aligned_free (Address: 0x18013a790)
- _aligned_malloc (Address: 0x18013a788)
- _amsg_exit (Address: 0x18013a7f8)
- _callnewh (Address: 0x18013a810)
- _initterm (Address: 0x18013a7f0)
- _itoa_s (Address: 0x18013a750)
- _lock (Address: 0x18013a7e0)
- _ltow_s (Address: 0x18013a6d0)
- _onexit (Address: 0x18013a7b0)
- _purecall (Address: 0x18013a700)
- _snwprintf_s (Address: 0x18013a730)
- _unlock (Address: 0x18013a7c8)
- _vsnprintf (Address: 0x18013a728)
- _vsnwprintf (Address: 0x18013a768)
- _wcsicmp (Address: 0x18013a780)
- _wcsnicmp (Address: 0x18013a748)
- _wfopen_s (Address: 0x18013a708)
- _XcptFilter (Address: 0x18013a800)
- ??1type_info@@UEAA@XZ (Address: 0x18013a738)
- ?terminate@@YAXXZ (Address: 0x18013a760)
- fclose (Address: 0x18013a6e8)
- free (Address: 0x18013a808)
- fwrite (Address: 0x18013a6f0)
- malloc (Address: 0x18013a818)
- memcmp (Address: 0x18013a7d0)
- memcpy (Address: 0x18013a778)
- memcpy_s (Address: 0x18013a798)
- memmove (Address: 0x18013a710)
- memmove_s (Address: 0x18013a7a0)
- memset (Address: 0x18013a718)
- printf (Address: 0x18013a6e0)
- rand_s (Address: 0x18013a6d8)
- realloc (Address: 0x18013a820)
- sprintf_s (Address: 0x18013a7d8)
- sqrt (Address: 0x18013a7a8)
- wcschr (Address: 0x18013a740)
- wcscmp (Address: 0x18013a828)
- wcsnlen (Address: 0x18013a720)
- wcsrchr (Address: 0x18013a6f8)
- wcstok_s (Address: 0x18013a758)
ncrypt.dll
- NCryptDecrypt (Address: 0x18013a838)
- NCryptFreeObject (Address: 0x18013a840)
- NCryptIsKeyHandle (Address: 0x18013a848)
ntdll.dll
- RtlGetLastNtStatus (Address: 0x18013a868)
- RtlIpv4StringToAddressW (Address: 0x18013a860)
- RtlIpv6StringToAddressW (Address: 0x18013a858)
- RtlVerifyVersionInfo (Address: 0x18013a870)
OLEAUT32.dll
- SysAllocString (Address: 0x180139c68)
- SysAllocStringByteLen (Address: 0x180139c60)
- SysAllocStringLen (Address: 0x180139c90)
- SysFreeString (Address: 0x180139ca8)
- SysStringLen (Address: 0x180139c98)
- VarBstrCat (Address: 0x180139c88)
- VariantChangeType (Address: 0x180139c70)
- VariantClear (Address: 0x180139c78)
- VariantCopy (Address: 0x180139ca0)
- VariantInit (Address: 0x180139c80)
SspiCli.dll
- AcceptSecurityContext (Address: 0x180139d08)
- AcquireCredentialsHandleW (Address: 0x180139d20)
- DecryptMessage (Address: 0x180139cf8)
- DeleteSecurityContext (Address: 0x180139d30)
- EncryptMessage (Address: 0x180139d50)
- FreeContextBuffer (Address: 0x180139d40)
- FreeCredentialsHandle (Address: 0x180139d00)
- InitializeSecurityContextW (Address: 0x180139cf0)
- InitSecurityInterfaceW (Address: 0x180139d48)
- LogonUserExExW (Address: 0x180139d10)
- LsaCallAuthenticationPackage (Address: 0x180139ce8)
- LsaConnectUntrusted (Address: 0x180139cc0)
- LsaDeregisterLogonProcess (Address: 0x180139cd8)
- LsaFreeReturnBuffer (Address: 0x180139ce0)
- LsaLogonUser (Address: 0x180139d58)
- LsaLookupAuthenticationPackage (Address: 0x180139cc8)
- QueryContextAttributesW (Address: 0x180139d28)
- QuerySecurityPackageInfoW (Address: 0x180139d38)
- SeciAllocateAndSetIPAddress (Address: 0x180139cb8)
- SeciFreeCallContext (Address: 0x180139cd0)
- SetContextAttributesW (Address: 0x180139d18)
WS2_32.dll
- accept (Address: 0x180139e80)
- bind (Address: 0x180139e60)
- closesocket (Address: 0x180139e18)
- connect (Address: 0x180139d90)
- FreeAddrInfoW (Address: 0x180139e20)
- GetAddrInfoW (Address: 0x180139e28)
- GetNameInfoW (Address: 0x180139d88)
- getpeername (Address: 0x180139dc8)
- getsockname (Address: 0x180139da8)
- getsockopt (Address: 0x180139da0)
- htonl (Address: 0x180139db0)
- htons (Address: 0x180139d80)
- listen (Address: 0x180139e68)
- ntohl (Address: 0x180139de8)
- ntohs (Address: 0x180139d98)
- recv (Address: 0x180139d70)
- select (Address: 0x180139e38)
- send (Address: 0x180139e30)
- setsockopt (Address: 0x180139e58)
- shutdown (Address: 0x180139e10)
- socket (Address: 0x180139de0)
- WSAAddressToStringW (Address: 0x180139e50)
- WSACleanup (Address: 0x180139dd8)
- WSAEnumNetworkEvents (Address: 0x180139d68)
- WSAEventSelect (Address: 0x180139e70)
- WSAGetLastError (Address: 0x180139d78)
- WSAIoctl (Address: 0x180139e48)
- WSALookupServiceBeginW (Address: 0x180139df8)
- WSALookupServiceEnd (Address: 0x180139dc0)
- WSALookupServiceNextW (Address: 0x180139db8)
- WSANSPIoctl (Address: 0x180139df0)
- WSARecv (Address: 0x180139e08)
- WSASend (Address: 0x180139e00)
- WSASocketW (Address: 0x180139e78)
- WSAStartup (Address: 0x180139dd0)
- WSAStringToAddressW (Address: 0x180139e40)