rdpserverbase.dll

Description: Rdp Server OneCore Base Services

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6216

Architecture: 64-bit

Operating System: Windows NT

SHA256: 97b03b507d837b449938661311876e29

File Size: 1.8 MB

Uploaded At: Dec. 1, 2025, 7:37 a.m.

Views: 8

Exported Functions

  • ?GetEncodingPixelMap@RdpSurface@@QEAAJPEAPEAVPixelMap@@@Z (Ordinal: 1, Address: 0x7f30)
  • ?GetGfxPipeSettingBOOL@@YAJPEAGHPEAH@Z (Ordinal: 2, Address: 0x76700)
  • ?GetGfxPipeSettingUINT@@YAJPEAGIPEAI@Z (Ordinal: 3, Address: 0x767b0)
  • ?GetGraphicsSourceContext@RdpSurface@@QEAAJPEAPEAUIRdpGFXSourceUpdateContext@@@Z (Ordinal: 4, Address: 0x6a550)
  • ?GetTileFirst@Tiler@@QEAAJPEBURdpRect@@PEAU2@@Z (Ordinal: 5, Address: 0x21f60)
  • ?GetTileNext@Tiler@@QEAAJPEAURdpRect@@@Z (Ordinal: 6, Address: 0x33140)
  • ?Initialize@Tiler@@QEAAJPEBURdpRect@@0@Z (Ordinal: 7, Address: 0x61bb0)
  • ?LogRDPGraphicsError@RDPGraphicsTraceLogging@@YAXU_GUID@@IIJ@Z (Ordinal: 8, Address: 0xb6b0)
  • ?LogRDPGraphicsFirstNonBlackFrame@RDPGraphicsTraceLogging@@YAX_K@Z (Ordinal: 9, Address: 0x107f10)
  • ?LogRDPGraphicsFirstNonBlackFramePostLogon@RDPGraphicsTraceLogging@@YAXI@Z (Ordinal: 10, Address: 0x107ff0)
  • ?LogRDPGraphicsSubsampleAdapter@RDPGraphicsTraceLogging@@YAXPEBGII@Z (Ordinal: 11, Address: 0x108790)
  • ?LogRDPGraphicsSubsampleFailure@RDPGraphicsTraceLogging@@YAXJI@Z (Ordinal: 12, Address: 0x108870)
  • ?LogRDPGraphicsVOBRHint@RDPGraphicsTraceLogging@@YAXI_KII@Z (Ordinal: 13, Address: 0x108a80)
  • ?RDPGraphicsTraceLogging_Register@RDPGraphicsTraceLogging@@YAJXZ (Ordinal: 14, Address: 0x108b70)
  • ?RDPGraphicsTraceLogging_Unregister@RDPGraphicsTraceLogging@@YAXXZ (Ordinal: 15, Address: 0x108b90)
  • ?RDPServerStackQOE_Register@@YAJXZ (Ordinal: 16, Address: 0xc38a0)
  • ?RDPServerStackQOE_Unregister@@YAXXZ (Ordinal: 17, Address: 0xc38e0)
  • CCompressedUpdateContext_CreateInstance (Ordinal: 18, Address: 0xc7230)
  • CUpdateContext_CreateInstance (Ordinal: 19, Address: 0xc72a0)
  • CUpdateDataAccumulator_CreateInstance (Ordinal: 20, Address: 0xc7310)
  • RDPEncryptionTraceLogging_Register (Ordinal: 21, Address: 0x1078b0)
  • RDPEncryptionTraceLogging_Unregister (Ordinal: 22, Address: 0x1078d0)
  • RDPSERVERBASE_CreateInstance (Ordinal: 23, Address: 0x3dde0)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x180140c18)
  • CoCreateGuid (Address: 0x180140c08)
  • CoTaskMemFree (Address: 0x180140c10)
  • StringFromGUID2 (Address: 0x180140c20)
  • StringFromIID (Address: 0x180140c00)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180140c40)
  • IsDebuggerPresent (Address: 0x180140c38)
  • OutputDebugStringW (Address: 0x180140c30)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180140c50)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180140c60)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180140c78)
  • RaiseException (Address: 0x180140c88)
  • SetLastError (Address: 0x180140c80)
  • SetUnhandledExceptionFilter (Address: 0x180140c90)
  • UnhandledExceptionFilter (Address: 0x180140c70)
api-ms-win-core-featurestaging-l1-1-0.dll
  • GetFeatureEnabledState (Address: 0x180140cb0)
  • RecordFeatureUsage (Address: 0x180140ca0)
  • SubscribeFeatureStateChangeNotification (Address: 0x180140cb8)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x180140ca8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180140cc8)
  • DuplicateHandle (Address: 0x180140cd0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180140ce8)
  • HeapAlloc (Address: 0x180140cf0)
  • HeapFree (Address: 0x180140ce0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180140d08)
  • LocalFree (Address: 0x180140d00)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x180140d20)
  • RegisterWaitForSingleObject (Address: 0x180140d18)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
  • VerifyVersionInfoW (Address: 0x180140d30)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180140d58)
  • FreeLibrary (Address: 0x180140d40)
  • GetModuleFileNameA (Address: 0x180140d60)
  • GetModuleHandleExA (Address: 0x180140d70)
  • GetModuleHandleExW (Address: 0x180140d48)
  • GetModuleHandleW (Address: 0x180140d78)
  • GetProcAddress (Address: 0x180140d68)
  • LoadLibraryExW (Address: 0x180140d50)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryW (Address: 0x180140d88)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180140d98)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x180140db8)
  • MapViewOfFile (Address: 0x180140dd8)
  • MapViewOfFileEx (Address: 0x180140dd0)
  • OpenFileMappingW (Address: 0x180140dc0)
  • UnmapViewOfFile (Address: 0x180140dc8)
  • VirtualAlloc (Address: 0x180140db0)
  • VirtualFree (Address: 0x180140da8)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x180140e00)
  • GetCurrentProcess (Address: 0x180140e08)
  • GetCurrentProcessId (Address: 0x180140df0)
  • GetCurrentThreadId (Address: 0x180140de8)
  • ProcessIdToSessionId (Address: 0x180140e10)
  • SwitchToThread (Address: 0x180140df8)
  • TerminateProcess (Address: 0x180140e18)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180140e28)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180140e40)
  • QueryPerformanceFrequency (Address: 0x180140e38)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180140e78)
  • RegCreateKeyExW (Address: 0x180140e70)
  • RegGetValueW (Address: 0x180140e58)
  • RegOpenKeyExW (Address: 0x180140e50)
  • RegQueryValueExW (Address: 0x180140e68)
  • RegSetValueExW (Address: 0x180140e60)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180140e88)
  • RtlLookupFunctionEntry (Address: 0x180140e90)
  • RtlVirtualUnwind (Address: 0x180140e98)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x180140eb0)
  • WideCharToMultiByte (Address: 0x180140ea8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180140f60)
  • AcquireSRWLockShared (Address: 0x180140f30)
  • CreateEventW (Address: 0x180140ec8)
  • CreateMutexExW (Address: 0x180140ef0)
  • CreateMutexW (Address: 0x180140ed8)
  • CreateSemaphoreExW (Address: 0x180140f58)
  • DeleteCriticalSection (Address: 0x180140ee8)
  • EnterCriticalSection (Address: 0x180140ed0)
  • InitializeCriticalSection (Address: 0x180140f10)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180140f28)
  • InitializeCriticalSectionEx (Address: 0x180140ee0)
  • InitializeSRWLock (Address: 0x180140f18)
  • LeaveCriticalSection (Address: 0x180140f40)
  • OpenSemaphoreW (Address: 0x180140ef8)
  • ReleaseMutex (Address: 0x180140f00)
  • ReleaseSemaphore (Address: 0x180140f08)
  • ReleaseSRWLockExclusive (Address: 0x180140f48)
  • ReleaseSRWLockShared (Address: 0x180140f20)
  • ResetEvent (Address: 0x180140f50)
  • SetEvent (Address: 0x180140f68)
  • WaitForSingleObject (Address: 0x180140f38)
  • WaitForSingleObjectEx (Address: 0x180140ec0)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x180140f90)
  • Sleep (Address: 0x180140f78)
  • SleepConditionVariableSRW (Address: 0x180140f88)
  • WakeAllConditionVariable (Address: 0x180140f80)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x180140fa0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x180140fb0)
  • GetSystemInfo (Address: 0x180140fd8)
  • GetSystemTime (Address: 0x180140fe0)
  • GetSystemTimeAsFileTime (Address: 0x180140fd0)
  • GetTickCount (Address: 0x180140fc0)
  • GetTickCount64 (Address: 0x180140fb8)
  • GetVersionExW (Address: 0x180140fc8)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetNativeSystemInfo (Address: 0x180140ff0)
  • VerSetConditionMask (Address: 0x180140ff8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CancelThreadpoolIo (Address: 0x180141030)
  • CloseThreadpoolIo (Address: 0x180141020)
  • CloseThreadpoolTimer (Address: 0x180141008)
  • CloseThreadpoolWork (Address: 0x180141028)
  • CreateThreadpoolIo (Address: 0x180141038)
  • CreateThreadpoolTimer (Address: 0x180141050)
  • CreateThreadpoolWork (Address: 0x180141040)
  • SetThreadpoolTimer (Address: 0x180141018)
  • StartThreadpoolIo (Address: 0x180141060)
  • SubmitThreadpoolWork (Address: 0x180141058)
  • WaitForThreadpoolIoCallbacks (Address: 0x180141048)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180141010)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x180141070)
  • DeleteTimerQueueTimer (Address: 0x180141080)
  • UnregisterWaitEx (Address: 0x180141078)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x180141098)
  • GetTimeZoneInformation (Address: 0x180141090)
  • SystemTimeToFileTime (Address: 0x1801410a0)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1801410b0)
  • RoGetActivationFactory (Address: 0x1801410b8)
  • RoInitialize (Address: 0x1801410c8)
  • RoUninitialize (Address: 0x1801410c0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x1801410d8)
  • WindowsDeleteString (Address: 0x1801410e0)
  • WindowsGetStringRawBuffer (Address: 0x1801410e8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x1801410f8)
  • GetTraceEnableLevel (Address: 0x180141118)
  • GetTraceLoggerHandle (Address: 0x180141108)
  • RegisterTraceGuidsW (Address: 0x180141110)
  • TraceMessage (Address: 0x180141120)
  • UnregisterTraceGuids (Address: 0x180141100)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x180141150)
  • EventProviderEnabled (Address: 0x180141138)
  • EventRegister (Address: 0x180141130)
  • EventSetInformation (Address: 0x180141148)
  • EventUnregister (Address: 0x180141140)
  • EventWriteTransfer (Address: 0x180141158)
api-ms-win-security-base-l1-1-0.dll
  • AddAce (Address: 0x180141178)
  • CopySid (Address: 0x180141180)
  • GetLengthSid (Address: 0x180141168)
  • IsValidSid (Address: 0x180141170)
api-ms-win-security-cryptoapi-l1-1-0.dll
  • CryptAcquireContextW (Address: 0x1801411b8)
  • CryptDestroyKey (Address: 0x1801411a0)
  • CryptGenKey (Address: 0x1801411a8)
  • CryptGenRandom (Address: 0x1801411b0)
  • CryptGetProvParam (Address: 0x180141198)
  • CryptReleaseContext (Address: 0x180141190)
api-ms-win-security-provider-l1-1-0.dll
  • GetSecurityInfo (Address: 0x1801411c8)
  • SetSecurityInfo (Address: 0x1801411d0)
CRYPT32.dll
  • CertCreateSelfSignCertificate (Address: 0x1801407a8)
  • CertFreeCertificateContext (Address: 0x1801407b0)
  • CertStrToNameW (Address: 0x1801407c8)
  • CryptEncodeObject (Address: 0x1801407d0)
  • CryptProtectData (Address: 0x1801407e0)
  • CryptProtectMemory (Address: 0x1801407b8)
  • CryptStringToBinaryW (Address: 0x1801407d8)
  • CryptUnprotectData (Address: 0x1801407a0)
  • CryptUnprotectMemory (Address: 0x1801407c0)
msvcrt.dll
  • __C_specific_handler (Address: 0x1801412e0)
  • __CxxFrameHandler3 (Address: 0x180141238)
  • __dllonexit (Address: 0x1801412c8)
  • __RTDynamicCast (Address: 0x180141290)
  • _aligned_free (Address: 0x180141268)
  • _aligned_malloc (Address: 0x180141270)
  • _amsg_exit (Address: 0x180141308)
  • _callnewh (Address: 0x1801411e8)
  • _initterm (Address: 0x1801412f0)
  • _lock (Address: 0x1801412d8)
  • _onexit (Address: 0x1801412c0)
  • _purecall (Address: 0x180141278)
  • _snwprintf_s (Address: 0x1801412e8)
  • _stricmp (Address: 0x180141200)
  • _strlwr (Address: 0x180141218)
  • _strnicmp (Address: 0x1801411f8)
  • _unlock (Address: 0x1801412d0)
  • _vsnwprintf (Address: 0x180141260)
  • _wcsicmp (Address: 0x180141250)
  • _wcsnicmp (Address: 0x180141258)
  • _XcptFilter (Address: 0x180141310)
  • ??1type_info@@UEAA@XZ (Address: 0x180141280)
  • ?terminate@@YAXXZ (Address: 0x1801411e0)
  • free (Address: 0x180141300)
  • malloc (Address: 0x1801412f8)
  • memcmp (Address: 0x180141298)
  • memcpy (Address: 0x1801412a0)
  • memcpy_s (Address: 0x180141248)
  • memmove (Address: 0x1801412a8)
  • memmove_s (Address: 0x180141240)
  • memset (Address: 0x1801412b0)
  • qsort (Address: 0x180141230)
  • strcmp (Address: 0x1801412b8)
  • strncmp (Address: 0x180141210)
  • strtok_s (Address: 0x180141208)
  • toupper (Address: 0x1801411f0)
  • vswprintf_s (Address: 0x180141228)
  • wcscmp (Address: 0x180141288)
  • wcstombs (Address: 0x180141220)
ncrypt.dll
  • NCryptCreatePersistedKey (Address: 0x180141328)
  • NCryptDeleteKey (Address: 0x180141338)
  • NCryptFinalizeKey (Address: 0x180141340)
  • NCryptFreeObject (Address: 0x180141320)
  • NCryptIsKeyHandle (Address: 0x180141348)
  • NCryptOpenStorageProvider (Address: 0x180141330)
  • NCryptSetProperty (Address: 0x180141350)
ntdll.dll
  • NtQuerySystemInformation (Address: 0x180141370)
  • NtSetInformationThread (Address: 0x180141378)
  • RtlIpv6StringToAddressW (Address: 0x180141368)
  • RtlVerifyVersionInfo (Address: 0x180141360)
OLEAUT32.dll
  • SysAllocString (Address: 0x1801407f0)
  • SysAllocStringByteLen (Address: 0x180140800)
  • SysFreeString (Address: 0x1801407f8)
  • SysStringLen (Address: 0x180140818)
  • VariantClear (Address: 0x180140810)
  • VariantCopy (Address: 0x180140808)
  • VariantInit (Address: 0x180140820)
RDPBASE.dll
  • ??0CRDPCache@@QEAA@XZ (Address: 0x1801408e0)
  • ??0RdpEncodeBuffer@@QEAA@PEAVITSObjectPool@@@Z (Address: 0x1801409c8)
  • ??0RdpGfxProtocolBaseDecoder@@IEAA@XZ (Address: 0x180140b30)
  • ??0SSECBCHash2@@QEAA@XZ (Address: 0x180140988)
  • ??1CRDPCache@@UEAA@XZ (Address: 0x1801408d0)
  • ??1Evict@@QEAA@XZ (Address: 0x180140950)
  • ??1RdpGfxProtocolBaseDecoder@@IEAA@XZ (Address: 0x180140b38)
  • ?AlphaCompressor__CreateInstance@@YAJPEAPEAUIRdpImageCompressor@@@Z (Address: 0x180140a38)
  • ?ClearCache@CRDPCache@@UEAAJXZ (Address: 0x1801408b0)
  • ?Compress@NSCodecCompressor@@QEAA_NAEBVPixelMap@@_NPEAEIAEAI@Z (Address: 0x180140b68)
  • ?CompressRdp8__CreateInstance@@YAJPEAPEAVIRdpPipeCompress@@I@Z (Address: 0x1801409a8)
  • ?CreateInstance@CRdpGfxCapsSet@@SAJPEAXKPEAPEAUIRdpGfxCapsSet@@@Z (Address: 0x180140b48)
  • ?CreateInstance@Evict@@SAJKKKKKPEAPEAV1@@Z (Address: 0x180140ad8)
  • ?CreateInstance@HashTable@@SAJKKPEAPEAUIHashBucket@@@Z (Address: 0x180140ad0)
  • ?CreateInstance@NSCodecCompressor@@SA_N_N00EAEAV?$TCntPtr@VNSCodecCompressor@@@@@Z (Address: 0x180140af8)
  • ?CreateInstance@PlanarCompressor@@SAJGGEHHHPEAPEAUIRdpImageCompressor@@@Z (Address: 0x180140a30)
  • ?CreateInstance@RdpEncodeBuffer@@SAJPEAVRdpEncodeBufferPool@@KPEAPEAV1@@Z (Address: 0x1801409c0)
  • ?DecompressRdp8__CreateInstance@@YAJPEAPEAVIRdpPipeDecompress@@@Z (Address: 0x180140b58)
  • ?EvictEntry@Evict@@QEAAPEAU_SCORE_ENTRY@@XZ (Address: 0x180140960)
  • ?GetFreeEntry@Evict@@QEAAPEAU_SCORE_ENTRY@@XZ (Address: 0x180140b00)
  • ?GetInstance@PipelineClock@@SAAEAV1@XZ (Address: 0x180140838)
  • ?GetMillisecondCount@PipelineClock@@QEAAIXZ (Address: 0x180140840)
  • ?GetMillisecondCount64@PipelineClock@@QEAA_KXZ (Address: 0x180140a88)
  • ?GetTickCount@PipelineClock@@QEAAIXZ (Address: 0x180140af0)
  • ?GetTimeHNS@PipelineClock@@QEAA_JXZ (Address: 0x180140a40)
  • ?HintCoconet__CreateInstance@@YAJPEAPEAVIRdpPipeCompressHintProvider@@@Z (Address: 0x1801409b0)
  • ?InsertEntry@Evict@@QEAAXPEAU_SCORE_ENTRY@@K@Z (Address: 0x180140980)
  • ?IsSupportedVersion@CRdpGfxCaps@@SAHK@Z (Address: 0x180140a78)
  • ?ParkEntry@Evict@@QEAAXPEAU_SCORE_ENTRY@@@Z (Address: 0x180140970)
  • ?ProcessAlignedData_AVX@SSECBCHash2@@AEAAXPEBIIII@Z (Address: 0x180140ab0)
  • ?ProcessAlignedData_SSE2@SSECBCHash2@@AEAAXPEBIIII@Z (Address: 0x180140ac8)
  • ?ProcessAlignedData_SSE41@SSECBCHash2@@AEAAXPEBIIII@Z (Address: 0x180140ab8)
  • ?ProcessUnalignedData_REG@SSECBCHash2@@AEAAXPEBIIII@Z (Address: 0x180140aa8)
  • ?PromoteEntry@Evict@@QEAAXKK@Z (Address: 0x180140958)
  • ?RdpGfxProtocolServerEncoder_CreateInstance@@YAJPEAVIRdpEncoderIO@@PEAPEAVIRdpPipeProtocolEncoderEx@@@Z (Address: 0x1801409b8)
  • ?Reset@CRDPCache@@UEAAJI@Z (Address: 0x1801408b8)
  • ?SearchCache@CRDPCache@@UEAAJIIPEAPEAUIUnknown@@PEAI@Z (Address: 0x180140900)
  • ?SetCacheEntry@CRDPCache@@UEAAJIIPEAUIUnknown@@PEAI@Z (Address: 0x180140898)
  • ?SetDecodeBuffer@RdpGfxProtocolBaseDecoder@@IEAAXPEBEI@Z (Address: 0x180140b40)
  • ?UnevictEntry@Evict@@QEAAXPEAU_SCORE_ENTRY@@@Z (Address: 0x180140968)
  • ?UpdateKeys@SSECBCHash2@@AEBAXXZ (Address: 0x180140aa0)
  • ApplyLuminanceFilter (Address: 0x180140a28)
  • ApplySobelFilterOnLum (Address: 0x1801409d0)
  • CAPAPI_AddCapSet (Address: 0x180140b18)
  • CAPAPI_GetCapSet (Address: 0x180140b08)
  • CAPAPI_InitializeCombinedCaps (Address: 0x180140b28)
  • CAPAPI_MergeCombinedCaps (Address: 0x180140b20)
  • CRDPCacCodecEncoder_CreateInstance (Address: 0x180140940)
  • CRDPCacVideoCodecForHardwareClient_CreateInstance (Address: 0x180140a20)
  • CRdpFIPSEncryption_CreateInstance (Address: 0x180140860)
  • CRDPNsCodec_CreateInstance (Address: 0x180140b60)
  • DecryptData (Address: 0x180140b10)
  • DrawBox (Address: 0x180140990)
  • DrawHLine (Address: 0x1801409a0)
  • DrawVLine (Address: 0x180140998)
  • EncryptData (Address: 0x180140ac0)
  • ExpandRectForSSE (Address: 0x180140830)
  • GetSupportedSSELevel_SSE (Address: 0x1801408f0)
  • GridBA_CreateInstance (Address: 0x180140928)
  • MakeSessionKeys (Address: 0x180140a60)
  • MemCopyAligned_SSE (Address: 0x1801408d8)
  • MemEqual (Address: 0x180140a90)
  • MemMoveReverseAligned_SSE (Address: 0x1801408e8)
  • PAL_System_AtomicCompareAndExchange (Address: 0x1801408a8)
  • PAL_System_AtomicCompareAndExchangePointer (Address: 0x180140a50)
  • PAL_System_AtomicDecrement (Address: 0x180140920)
  • PAL_System_AtomicIncrement (Address: 0x180140918)
  • PAL_System_CritSecEnter (Address: 0x180140910)
  • PAL_System_CritSecInit (Address: 0x1801408c0)
  • PAL_System_CritSecIsLockedByCurrentThread (Address: 0x1801409d8)
  • PAL_System_CritSecLeave (Address: 0x180140908)
  • PAL_System_CritSecTerminate (Address: 0x1801408c8)
  • PAL_System_HandleFree (Address: 0x180140890)
  • PAL_System_MemAlloc (Address: 0x180140978)
  • PAL_System_MemFree (Address: 0x180140850)
  • PAL_System_SemaphoreAcquire (Address: 0x180140880)
  • PAL_System_SemaphoreAlloc (Address: 0x180140878)
  • PAL_System_SemaphoreRelease (Address: 0x180140888)
  • PAL_System_ThreadGetId (Address: 0x1801408a0)
  • RDP_MD5Final (Address: 0x180140a00)
  • RDP_MD5Init (Address: 0x180140a08)
  • RDP_MD5Update (Address: 0x1801409f0)
  • RDP_RC4AllocKey (Address: 0x180140a68)
  • RDP_RC4FreeKey (Address: 0x180140a18)
  • RDP_RsaBCryptDecryptPrivate (Address: 0x1801409f8)
  • RDP_RsaBCryptGenerateRsaKeyPair (Address: 0x180140a58)
  • RDP_RsaBCryptPubKeyToBSafePubKey (Address: 0x180140b50)
  • RDPAPI_GetGenericCounter (Address: 0x180140870)
  • RDPAPI_GetGlobalObject (Address: 0x180140a48)
  • RDPAPI_GetLongCounter (Address: 0x180140930)
  • RDPBASE_CreateInstance (Address: 0x180140858)
  • RDPCompress_GetContextSize (Address: 0x180140938)
  • RDPCompress_InitRecvContext (Address: 0x180140ae8)
  • RDPCompress_InitSendContext (Address: 0x180140ae0)
  • RDPCompressEx (Address: 0x180140a10)
  • RDPDecompress (Address: 0x180140948)
  • RDPDeCompress_GetContextSize (Address: 0x180140b70)
  • RDPENCHLPREG_ReadValueDWORD (Address: 0x1801409e8)
  • RdpIntersectRect (Address: 0x1801409e0)
  • RdpUnionRect (Address: 0x180140a80)
  • RdpX_DateTime_GetHighResolutionTimeSinceReboot (Address: 0x180140868)
  • RdpX_GetActivityIdPrefix (Address: 0x1801408f8)
  • RgnlibBA_CreateInstance (Address: 0x180140848)
  • SubtractRects (Address: 0x180140a98)
  • UpdateSessionKey (Address: 0x180140a70)
RPCRT4.dll
  • RpcStringFreeW (Address: 0x180140b80)
  • UuidCreate (Address: 0x180140b88)
  • UuidToStringW (Address: 0x180140b90)
SspiCli.dll
  • GetUserNameExW (Address: 0x180140ba8)
  • LsaCallAuthenticationPackage (Address: 0x180140bd0)
  • LsaConnectUntrusted (Address: 0x180140bb8)
  • LsaDeregisterLogonProcess (Address: 0x180140bc8)
  • LsaFreeReturnBuffer (Address: 0x180140ba0)
  • LsaLogonUser (Address: 0x180140bc0)
  • LsaLookupAuthenticationPackage (Address: 0x180140bb0)
websocket.dll
  • WebSocketAbortHandle (Address: 0x1801413c0)
  • WebSocketBeginServerHandshake (Address: 0x1801413b0)
  • WebSocketCompleteAction (Address: 0x180141398)
  • WebSocketCreateServerHandle (Address: 0x1801413b8)
  • WebSocketDeleteHandle (Address: 0x180141390)
  • WebSocketEndServerHandshake (Address: 0x1801413a8)
  • WebSocketGetAction (Address: 0x180141388)
  • WebSocketReceive (Address: 0x1801413a0)
  • WebSocketSend (Address: 0x1801413c8)
WS2_32.dll
  • WSAAddressToStringW (Address: 0x180140be8)
  • WSACleanup (Address: 0x180140bf0)
  • WSAStartup (Address: 0x180140be0)