rdpsharercom.dll

Description: RDPSRAPI Sharer COM Objects

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6093

Architecture: 64-bit

Operating System: Windows NT

SHA256: e5f6c446852460bf62d980468f7a032f

File Size: 1.4 MB

Uploaded At: Dec. 1, 2025, 7:37 a.m.

Views: 3

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0xb060)
  • DllGetClassObject (Ordinal: 2, Address: 0xb080)
  • DllRegisterServer (Ordinal: 3, Address: 0xb1b0)
  • DllUnregisterServer (Ordinal: 4, Address: 0xb2b0)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180131ce0)
api-ms-win-core-atoms-l1-1-0.dll
  • GlobalAddAtomW (Address: 0x180131cf0)
  • GlobalDeleteAtom (Address: 0x180131cf8)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x180131d20)
  • CoInitializeEx (Address: 0x180131d08)
  • CoTaskMemAlloc (Address: 0x180131d38)
  • CoTaskMemFree (Address: 0x180131d30)
  • CoTaskMemRealloc (Address: 0x180131d10)
  • CoUninitialize (Address: 0x180131d18)
  • StringFromGUID2 (Address: 0x180131d28)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180131d48)
  • IsDebuggerPresent (Address: 0x180131d58)
  • OutputDebugStringA (Address: 0x180131d60)
  • OutputDebugStringW (Address: 0x180131d50)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180131d70)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180131d80)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180131da8)
  • RaiseException (Address: 0x180131db0)
  • SetErrorMode (Address: 0x180131db8)
  • SetLastError (Address: 0x180131d98)
  • SetUnhandledExceptionFilter (Address: 0x180131da0)
  • UnhandledExceptionFilter (Address: 0x180131d90)
api-ms-win-core-featurestaging-l1-1-0.dll
  • GetFeatureEnabledState (Address: 0x180131de0)
  • RecordFeatureUsage (Address: 0x180131dd8)
  • SubscribeFeatureStateChangeNotification (Address: 0x180131dd0)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x180131dc8)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x180131e38)
  • CreateFileW (Address: 0x180131df8)
  • DeleteFileW (Address: 0x180131e40)
  • FindClose (Address: 0x180131df0)
  • FindFirstFileW (Address: 0x180131e08)
  • FindNextFileW (Address: 0x180131e00)
  • GetFileAttributesW (Address: 0x180131e20)
  • GetFileInformationByHandle (Address: 0x180131e48)
  • GetTempFileNameW (Address: 0x180131e10)
  • ReadFile (Address: 0x180131e28)
  • SetFilePointerEx (Address: 0x180131e18)
  • WriteFile (Address: 0x180131e30)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180131e58)
  • DuplicateHandle (Address: 0x180131e60)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180131e70)
  • HeapAlloc (Address: 0x180131e80)
  • HeapFree (Address: 0x180131e78)
api-ms-win-core-heap-l2-1-0.dll
  • GlobalAlloc (Address: 0x180131e98)
  • GlobalFree (Address: 0x180131e90)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • GlobalLock (Address: 0x180131ea8)
  • GlobalSize (Address: 0x180131eb0)
  • GlobalUnlock (Address: 0x180131eb8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • PulseEvent (Address: 0x180131ec8)
  • WTSGetActiveConsoleSessionId (Address: 0x180131ed0)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
  • VerifyVersionInfoW (Address: 0x180131ee0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180131f20)
  • FindResourceExW (Address: 0x180131ef8)
  • FreeLibrary (Address: 0x180131f30)
  • GetModuleFileNameA (Address: 0x180131f40)
  • GetModuleFileNameW (Address: 0x180131f18)
  • GetModuleHandleExA (Address: 0x180131ef0)
  • GetModuleHandleExW (Address: 0x180131f10)
  • GetModuleHandleW (Address: 0x180131f48)
  • GetProcAddress (Address: 0x180131f08)
  • LoadLibraryExW (Address: 0x180131f28)
  • LoadResource (Address: 0x180131f00)
  • SizeofResource (Address: 0x180131f38)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryA (Address: 0x180131f60)
  • LoadLibraryW (Address: 0x180131f58)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180131f70)
  • GetCPInfo (Address: 0x180131f80)
  • IsDBCSLeadByte (Address: 0x180131f78)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualQuery (Address: 0x180131f90)
api-ms-win-core-path-l1-1-0.dll
  • PathCchCanonicalize (Address: 0x180131fa0)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x180131fd8)
  • GetCurrentProcess (Address: 0x180132008)
  • GetCurrentProcessId (Address: 0x180131fc8)
  • GetCurrentThread (Address: 0x180132010)
  • GetCurrentThreadId (Address: 0x180131fb8)
  • OpenProcessToken (Address: 0x180131fb0)
  • OpenThreadToken (Address: 0x180131ff8)
  • ProcessIdToSessionId (Address: 0x180131ff0)
  • TerminateProcess (Address: 0x180131fd0)
  • TlsAlloc (Address: 0x180131fe0)
  • TlsFree (Address: 0x180131fe8)
  • TlsGetValue (Address: 0x180131fc0)
  • TlsSetValue (Address: 0x180132000)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180132028)
  • OpenProcess (Address: 0x180132020)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180132038)
  • QueryPerformanceFrequency (Address: 0x180132040)
api-ms-win-core-psapi-l1-1-0.dll
  • K32EnumProcessModules (Address: 0x180132058)
  • K32GetModuleBaseNameW (Address: 0x180132050)
  • K32GetModuleFileNameExW (Address: 0x180132060)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180132098)
  • RegCreateKeyExW (Address: 0x180132070)
  • RegDeleteValueW (Address: 0x1801320a8)
  • RegEnumKeyExW (Address: 0x1801320b0)
  • RegEnumValueW (Address: 0x180132080)
  • RegOpenKeyExW (Address: 0x1801320a0)
  • RegQueryInfoKeyW (Address: 0x180132088)
  • RegQueryValueExW (Address: 0x180132090)
  • RegSetValueExW (Address: 0x180132078)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1801320c0)
  • RtlLookupFunctionEntry (Address: 0x1801320c8)
  • RtlVirtualUnwind (Address: 0x1801320d0)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFindFileNameW (Address: 0x1801320e0)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x1801320f8)
  • WideCharToMultiByte (Address: 0x1801320f0)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x180132108)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x180132120)
  • lstrcmpW (Address: 0x180132118)
api-ms-win-core-stringansi-l1-1-0.dll
  • CharNextA (Address: 0x180132130)
  • CharPrevA (Address: 0x180132138)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1801321c8)
  • AcquireSRWLockShared (Address: 0x1801321f0)
  • CreateEventW (Address: 0x1801321a0)
  • CreateMutexExW (Address: 0x180132160)
  • CreateSemaphoreExW (Address: 0x180132198)
  • CreateWaitableTimerExW (Address: 0x180132170)
  • DeleteCriticalSection (Address: 0x1801321d8)
  • EnterCriticalSection (Address: 0x180132158)
  • InitializeCriticalSection (Address: 0x180132188)
  • InitializeCriticalSectionEx (Address: 0x1801321d0)
  • InitializeSRWLock (Address: 0x180132180)
  • LeaveCriticalSection (Address: 0x180132148)
  • OpenEventW (Address: 0x1801321f8)
  • OpenSemaphoreW (Address: 0x1801321a8)
  • ReleaseMutex (Address: 0x180132200)
  • ReleaseSemaphore (Address: 0x180132150)
  • ReleaseSRWLockExclusive (Address: 0x1801321e0)
  • ReleaseSRWLockShared (Address: 0x1801321e8)
  • ResetEvent (Address: 0x180132190)
  • SetEvent (Address: 0x1801321c0)
  • SetWaitableTimer (Address: 0x180132178)
  • WaitForMultipleObjectsEx (Address: 0x1801321b8)
  • WaitForSingleObject (Address: 0x180132168)
  • WaitForSingleObjectEx (Address: 0x1801321b0)
api-ms-win-core-synch-l1-2-0.dll
  • InitializeConditionVariable (Address: 0x180132220)
  • InitOnceExecuteOnce (Address: 0x180132218)
  • Sleep (Address: 0x180132210)
  • SleepConditionVariableCS (Address: 0x180132228)
  • SleepConditionVariableSRW (Address: 0x180132230)
  • WakeAllConditionVariable (Address: 0x180132238)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x180132248)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x180132270)
  • GetSystemTime (Address: 0x180132278)
  • GetSystemTimeAsFileTime (Address: 0x180132260)
  • GetTickCount (Address: 0x180132258)
  • GetVersionExW (Address: 0x180132268)
api-ms-win-core-sysinfo-l1-2-0.dll
  • VerSetConditionMask (Address: 0x180132288)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180132298)
  • CreateThreadpoolTimer (Address: 0x1801322a8)
  • SetThreadpoolTimer (Address: 0x1801322b0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1801322a0)
api-ms-win-core-timezone-l1-1-0.dll
  • SystemTimeToFileTime (Address: 0x1801322c0)
api-ms-win-core-version-l1-1-0.dll
  • GetFileVersionInfoExW (Address: 0x1801322d8)
  • GetFileVersionInfoSizeExW (Address: 0x1801322e0)
  • VerQueryValueW (Address: 0x1801322d0)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1801322f0)
  • RoGetActivationFactory (Address: 0x1801322f8)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x180132308)
  • WindowsDeleteString (Address: 0x180132310)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180132338)
  • GetTraceEnableLevel (Address: 0x180132330)
  • GetTraceLoggerHandle (Address: 0x180132340)
  • RegisterTraceGuidsW (Address: 0x180132328)
  • TraceMessage (Address: 0x180132320)
  • UnregisterTraceGuids (Address: 0x180132348)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x180132360)
  • EventRegister (Address: 0x180132358)
  • EventUnregister (Address: 0x180132370)
  • EventWriteTransfer (Address: 0x180132368)
api-ms-win-ntuser-rectangle-l1-1-0.dll
  • CopyRect (Address: 0x1801323b8)
  • EqualRect (Address: 0x1801323c8)
  • InflateRect (Address: 0x180132390)
  • IntersectRect (Address: 0x1801323c0)
  • IsRectEmpty (Address: 0x1801323b0)
  • OffsetRect (Address: 0x180132388)
  • PtInRect (Address: 0x1801323a8)
  • SetRect (Address: 0x180132398)
  • SetRectEmpty (Address: 0x180132380)
  • UnionRect (Address: 0x1801323a0)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • EnumDisplayDevicesW (Address: 0x1801323f8)
  • EnumDisplayMonitors (Address: 0x180132400)
  • EnumDisplaySettingsExW (Address: 0x1801323e8)
  • EnumDisplaySettingsW (Address: 0x180132408)
  • GetMonitorInfoW (Address: 0x1801323e0)
  • GetSystemMetrics (Address: 0x1801323f0)
  • SystemParametersInfoW (Address: 0x1801323d8)
api-ms-win-rtcore-ole32-clipboard-l1-1-0.dll
  • OleGetClipboard (Address: 0x180132428)
  • OleIsCurrentClipboard (Address: 0x180132420)
  • OleSetClipboard (Address: 0x180132418)
api-ms-win-security-base-l1-1-0.dll
  • GetTokenInformation (Address: 0x180132440)
  • SetTokenInformation (Address: 0x180132438)
api-ms-win-security-cryptoapi-l1-1-0.dll
  • CryptAcquireContextW (Address: 0x180132470)
  • CryptCreateHash (Address: 0x180132458)
  • CryptDestroyHash (Address: 0x180132480)
  • CryptGenRandom (Address: 0x180132468)
  • CryptGetHashParam (Address: 0x180132450)
  • CryptHashData (Address: 0x180132478)
  • CryptReleaseContext (Address: 0x180132460)
api-ms-win-security-isolatedcontainer-l1-1-1.dll
  • IsProcessInWDAGContainer (Address: 0x180132490)
AVRT.dll
  • AvRevertMmThreadCharacteristics (Address: 0x180131a48)
  • AvSetMmThreadCharacteristicsW (Address: 0x180131a40)
CRYPT32.dll
  • CryptBinaryToStringW (Address: 0x180131a58)
d3d11.dll
  • D3D11CreateDevice (Address: 0x1801324a0)
dxgi.dll
  • CreateDXGIFactory1 (Address: 0x1801324b0)
MSACM32.dll
  • acmDriverClose (Address: 0x180131a78)
  • acmDriverEnum (Address: 0x180131ab8)
  • acmDriverOpen (Address: 0x180131a80)
  • acmFormatSuggest (Address: 0x180131ab0)
  • acmFormatTagDetailsW (Address: 0x180131a88)
  • acmStreamClose (Address: 0x180131a70)
  • acmStreamConvert (Address: 0x180131aa0)
  • acmStreamOpen (Address: 0x180131a68)
  • acmStreamPrepareHeader (Address: 0x180131a98)
  • acmStreamSize (Address: 0x180131a90)
  • acmStreamUnprepareHeader (Address: 0x180131aa8)
msvcrt.dll
  • __C_specific_handler (Address: 0x1801325c8)
  • __CxxFrameHandler3 (Address: 0x180132520)
  • __dllonexit (Address: 0x180132530)
  • _aligned_free (Address: 0x1801324d8)
  • _aligned_malloc (Address: 0x1801324d0)
  • _amsg_exit (Address: 0x180132580)
  • _callnewh (Address: 0x180132598)
  • _errno (Address: 0x180132570)
  • _ftime64 (Address: 0x1801324e0)
  • _initterm (Address: 0x180132578)
  • _lock (Address: 0x180132540)
  • _onexit (Address: 0x180132528)
  • _purecall (Address: 0x1801325f8)
  • _resetstkoflw (Address: 0x180132620)
  • _strnicmp (Address: 0x180132640)
  • _unlock (Address: 0x180132538)
  • _vsnwprintf (Address: 0x180132618)
  • _wcsicmp (Address: 0x1801324c8)
  • _wcsicoll (Address: 0x180132628)
  • _wcsnicmp (Address: 0x180132630)
  • _wfopen_s (Address: 0x180132560)
  • _XcptFilter (Address: 0x180132588)
  • ?terminate@@YAXXZ (Address: 0x180132648)
  • calloc (Address: 0x180132610)
  • fclose (Address: 0x180132568)
  • fprintf (Address: 0x1801325b0)
  • free (Address: 0x1801325f0)
  • fwrite (Address: 0x1801325a8)
  • isalpha (Address: 0x180132638)
  • log (Address: 0x180132650)
  • malloc (Address: 0x1801325d0)
  • memcmp (Address: 0x180132658)
  • memcpy (Address: 0x180132660)
  • memcpy_s (Address: 0x180132608)
  • memmove (Address: 0x180132668)
  • memmove_s (Address: 0x1801325d8)
  • memset (Address: 0x180132670)
  • pow (Address: 0x180132678)
  • printf (Address: 0x180132518)
  • qsort (Address: 0x180132510)
  • rand (Address: 0x180132558)
  • realloc (Address: 0x180132548)
  • sprintf_s (Address: 0x180132508)
  • sqrt (Address: 0x180132680)
  • sqrtf (Address: 0x1801324e8)
  • strncpy_s (Address: 0x1801324f8)
  • strnlen (Address: 0x180132500)
  • swprintf_s (Address: 0x180132550)
  • vswprintf_s (Address: 0x1801325a0)
  • wcscat_s (Address: 0x1801325e8)
  • wcschr (Address: 0x1801324f0)
  • wcscmp (Address: 0x180132688)
  • wcscpy_s (Address: 0x180132590)
  • wcsncpy_s (Address: 0x1801325c0)
  • wcsnlen (Address: 0x1801325e0)
  • wcsrchr (Address: 0x180132600)
  • wcstombs (Address: 0x1801325b8)
  • wcstoul (Address: 0x1801324c0)
OLEAUT32.dll
  • LoadRegTypeLib (Address: 0x180131b10)
  • LoadTypeLib (Address: 0x180131b38)
  • RegisterTypeLib (Address: 0x180131ae8)
  • SafeArrayAccessData (Address: 0x180131b48)
  • SafeArrayCreate (Address: 0x180131ad0)
  • SafeArrayDestroy (Address: 0x180131b70)
  • SafeArrayLock (Address: 0x180131b68)
  • SafeArrayUnaccessData (Address: 0x180131b58)
  • SafeArrayUnlock (Address: 0x180131b60)
  • SysAllocString (Address: 0x180131b00)
  • SysAllocStringByteLen (Address: 0x180131b08)
  • SysAllocStringLen (Address: 0x180131af8)
  • SysFreeString (Address: 0x180131b18)
  • SysStringByteLen (Address: 0x180131ad8)
  • SysStringLen (Address: 0x180131b50)
  • UnRegisterTypeLib (Address: 0x180131af0)
  • VarBstrCat (Address: 0x180131b20)
  • VarBstrCmp (Address: 0x180131b78)
  • VariantChangeType (Address: 0x180131b30)
  • VariantClear (Address: 0x180131ac8)
  • VariantCopy (Address: 0x180131b28)
  • VariantInit (Address: 0x180131b40)
  • VarUI4FromStr (Address: 0x180131ae0)
RDPBASE.dll
  • ?RdpPerfLoggerStaticTerminate@@YAXXZ (Address: 0x180131be8)
  • DrawBox (Address: 0x180131bd8)
  • GetSupportedSSELevel_SSE (Address: 0x180131ba0)
  • GridBA_CreateInstance (Address: 0x180131bc8)
  • MemCopyAligned_SSE (Address: 0x180131c18)
  • MemMoveReverseAligned_SSE (Address: 0x180131c08)
  • PAL_System_AtomicCompareAndExchange (Address: 0x180131c48)
  • PAL_System_AtomicDecrement (Address: 0x180131bb0)
  • PAL_System_AtomicIncrement (Address: 0x180131bb8)
  • PAL_System_CritSecEnter (Address: 0x180131c60)
  • PAL_System_CritSecInit (Address: 0x180131c00)
  • PAL_System_CritSecLeave (Address: 0x180131c50)
  • PAL_System_CritSecTerminate (Address: 0x180131c58)
  • PAL_System_GetNumberOfProcessors (Address: 0x180131c20)
  • PAL_System_HandleFree (Address: 0x180131bd0)
  • PAL_System_SemaphoreAcquire (Address: 0x180131b98)
  • PAL_System_SemaphoreAlloc (Address: 0x180131bc0)
  • PAL_System_SemaphoreRelease (Address: 0x180131c68)
  • PAL_System_Sleep (Address: 0x180131c28)
  • PAL_System_SwitchToThread (Address: 0x180131c40)
  • PAL_System_ThreadGetId (Address: 0x180131be0)
  • RDPAPI_GetGenericCounter (Address: 0x180131c10)
  • RDPAPI_GetLongCounter (Address: 0x180131b90)
  • RDPBASE_CreateInstance (Address: 0x180131ba8)
  • RdpTiledSurface_CreateInstance (Address: 0x180131b88)
  • RgnlibBA_CreateInstance (Address: 0x180131bf0)
  • TSAlloc (Address: 0x180131c30)
  • TSCreateCoreEvents (Address: 0x180131bf8)
  • TSFree (Address: 0x180131c38)
RDPSERVERBASE.dll
  • ?GetEncodingPixelMap@RdpSurface@@QEAAJPEAPEAVPixelMap@@@Z (Address: 0x180131c80)
  • ?GetGfxPipeSettingBOOL@@YAJPEAGHPEAH@Z (Address: 0x180131cb0)
  • ?GetGfxPipeSettingUINT@@YAJPEAGIPEAI@Z (Address: 0x180131ca8)
  • ?GetGraphicsSourceContext@RdpSurface@@QEAAJPEAPEAUIRdpGFXSourceUpdateContext@@@Z (Address: 0x180131cb8)
  • ?GetTileFirst@Tiler@@QEAAJPEBURdpRect@@PEAU2@@Z (Address: 0x180131c78)
  • ?GetTileNext@Tiler@@QEAAJPEAURdpRect@@@Z (Address: 0x180131c88)
  • ?Initialize@Tiler@@QEAAJPEBURdpRect@@0@Z (Address: 0x180131ca0)
  • CCompressedUpdateContext_CreateInstance (Address: 0x180131c90)
  • CUpdateContext_CreateInstance (Address: 0x180131c98)
  • RDPSERVERBASE_CreateInstance (Address: 0x180131cc0)
WS2_32.dll
  • GetHostNameW (Address: 0x180131cd0)