RDXService.dll
Description: RDXService
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 7681877d2492df2b3188b94d65c5e5de
File Size: 717.5 KB
Uploaded At: Dec. 1, 2025, 7:37 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- OpenRDXDocumentW (Ordinal: 1, Address: 0xb510)
- ServiceMain (Ordinal: 2, Address: 0xb310)
- DllCanUnloadNow (Ordinal: 3, Address: 0xb370)
- DllGetClassObject (Ordinal: 4, Address: 0xb3e0)
- GetProxyDllInfo (Ordinal: 5, Address: 0x3350)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-internal-l1-1-1.dll
- GetPackageStatusForUser (Address: 0x1800804d0)
api-ms-win-appmodel-runtime-l1-1-0.dll
- GetPackagesByPackageFamily (Address: 0x1800804e0)
- PackageFamilyNameFromFullName (Address: 0x1800804f0)
- PackageNameAndPublisherIdFromFamilyName (Address: 0x1800804e8)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180080500)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x180080570)
- CoAddRefServerProcess (Address: 0x180080520)
- CoCreateFreeThreadedMarshaler (Address: 0x180080578)
- CoCreateInstance (Address: 0x180080568)
- CoDisconnectObject (Address: 0x180080560)
- CoGetApartmentType (Address: 0x180080530)
- CoGetMalloc (Address: 0x180080590)
- CoInitializeEx (Address: 0x1800805b8)
- CoInitializeSecurity (Address: 0x180080540)
- CoRegisterClassObject (Address: 0x180080550)
- CoReleaseServerProcess (Address: 0x180080598)
- CoResumeClassObjects (Address: 0x180080580)
- CoRevokeClassObject (Address: 0x1800805b0)
- CoSetProxyBlanket (Address: 0x180080510)
- CoTaskMemAlloc (Address: 0x1800805a0)
- CoTaskMemFree (Address: 0x1800805a8)
- CoTaskMemRealloc (Address: 0x180080588)
- CoUninitialize (Address: 0x180080518)
- CoWaitForMultipleHandles (Address: 0x180080528)
- CreateStreamOnHGlobal (Address: 0x180080548)
- PropVariantClear (Address: 0x180080538)
- StringFromGUID2 (Address: 0x180080558)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
- ObjectStublessClient10 (Address: 0x1800805d8)
- ObjectStublessClient3 (Address: 0x1800805c8)
- ObjectStublessClient4 (Address: 0x1800805e8)
- ObjectStublessClient5 (Address: 0x1800805d0)
- ObjectStublessClient6 (Address: 0x1800805f8)
- ObjectStublessClient7 (Address: 0x1800805f0)
- ObjectStublessClient8 (Address: 0x180080600)
- ObjectStublessClient9 (Address: 0x1800805e0)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180080610)
- IsDebuggerPresent (Address: 0x180080618)
- OutputDebugStringW (Address: 0x180080620)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180080630)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180080640)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180080660)
- RaiseException (Address: 0x180080658)
- SetLastError (Address: 0x180080668)
- SetUnhandledExceptionFilter (Address: 0x180080670)
- UnhandledExceptionFilter (Address: 0x180080650)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x1800806c8)
- CreateDirectoryW (Address: 0x180080680)
- CreateFileW (Address: 0x1800806d8)
- DeleteFileW (Address: 0x1800806b8)
- FindClose (Address: 0x1800806a0)
- FindFirstFileW (Address: 0x180080688)
- FindNextFileW (Address: 0x1800806a8)
- GetDriveTypeW (Address: 0x1800806e0)
- GetFileSizeEx (Address: 0x180080698)
- ReadFile (Address: 0x180080690)
- RemoveDirectoryW (Address: 0x1800806c0)
- SetFileAttributesW (Address: 0x1800806b0)
- SetFilePointerEx (Address: 0x1800806d0)
api-ms-win-core-file-l2-1-2.dll
- CopyFileW (Address: 0x1800806f0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180080700)
- DuplicateHandle (Address: 0x180080708)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180080718)
- HeapAlloc (Address: 0x180080728)
- HeapFree (Address: 0x180080720)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180080740)
- LocalFree (Address: 0x180080738)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x180080750)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- MoveFileW (Address: 0x180080760)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x180080770)
- FindResourceExW (Address: 0x1800807a8)
- FreeLibrary (Address: 0x180080788)
- GetModuleFileNameA (Address: 0x1800807a0)
- GetModuleHandleExW (Address: 0x180080790)
- GetModuleHandleW (Address: 0x180080778)
- GetProcAddress (Address: 0x180080798)
- LoadLibraryExW (Address: 0x180080780)
- LoadResource (Address: 0x1800807b8)
- LockResource (Address: 0x1800807b0)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryW (Address: 0x1800807c8)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800807f8)
- GetGeoInfoW (Address: 0x1800807d8)
- GetLocaleInfoW (Address: 0x1800807e8)
- GetThreadUILanguage (Address: 0x1800807f0)
- GetUserGeoID (Address: 0x1800807e0)
api-ms-win-core-path-l1-1-0.dll
- PathCchAppend (Address: 0x180080808)
- PathCchCombine (Address: 0x180080810)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x180080820)
- GetStdHandle (Address: 0x180080828)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessW (Address: 0x180080850)
- CreateThread (Address: 0x180080860)
- GetCurrentProcess (Address: 0x180080848)
- GetCurrentProcessId (Address: 0x180080838)
- GetCurrentThread (Address: 0x180080840)
- GetCurrentThreadId (Address: 0x180080878)
- OpenProcessToken (Address: 0x180080868)
- OpenThreadToken (Address: 0x180080858)
- ResumeThread (Address: 0x180080880)
- TerminateProcess (Address: 0x180080870)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x180080890)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800808a0)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800808e0)
- RegCopyTreeW (Address: 0x1800808b0)
- RegCreateKeyExW (Address: 0x1800808e8)
- RegDeleteTreeW (Address: 0x1800808b8)
- RegDeleteValueW (Address: 0x1800808c8)
- RegEnumKeyExW (Address: 0x180080908)
- RegEnumValueW (Address: 0x1800808c0)
- RegGetValueW (Address: 0x1800808d8)
- RegOpenCurrentUser (Address: 0x1800808d0)
- RegOpenKeyExW (Address: 0x180080900)
- RegQueryInfoKeyW (Address: 0x1800808f8)
- RegSetValueExW (Address: 0x1800808f0)
api-ms-win-core-registry-l1-1-1.dll
- RegDeleteKeyValueW (Address: 0x180080918)
- RegSetKeyValueW (Address: 0x180080920)
api-ms-win-core-registry-l2-1-0.dll
- RegCreateKeyW (Address: 0x180080930)
api-ms-win-core-registryuserspecific-l1-1-0.dll
- SHRegGetUSValueW (Address: 0x180080940)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x180080960)
- RtlLookupFunctionEntry (Address: 0x180080958)
- RtlVirtualUnwind (Address: 0x180080950)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFileExistsW (Address: 0x180080990)
- PathFindExtensionW (Address: 0x180080998)
- PathFindFileNameW (Address: 0x180080970)
- PathRemoveBackslashW (Address: 0x180080988)
- PathRemoveFileSpecW (Address: 0x180080980)
- PathStripPathW (Address: 0x180080978)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- QISearch (Address: 0x1800809b8)
- StrCmpW (Address: 0x1800809b0)
- StrRChrW (Address: 0x1800809a8)
api-ms-win-core-shutdown-l1-1-0.dll
- InitiateSystemShutdownExW (Address: 0x1800809c8)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1800809e0)
- GetStringTypeW (Address: 0x1800809f0)
- MultiByteToWideChar (Address: 0x1800809e8)
- WideCharToMultiByte (Address: 0x1800809d8)
api-ms-win-core-string-l2-1-0.dll
- CharLowerBuffW (Address: 0x180080a00)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180080a58)
- AcquireSRWLockShared (Address: 0x180080a98)
- CreateEventExW (Address: 0x180080a70)
- CreateEventW (Address: 0x180080a60)
- CreateMutexExW (Address: 0x180080a38)
- CreateSemaphoreExW (Address: 0x180080a40)
- DeleteCriticalSection (Address: 0x180080a18)
- EnterCriticalSection (Address: 0x180080a20)
- InitializeCriticalSectionEx (Address: 0x180080a88)
- InitializeSRWLock (Address: 0x180080a78)
- LeaveCriticalSection (Address: 0x180080a80)
- OpenEventW (Address: 0x180080aa0)
- OpenSemaphoreW (Address: 0x180080a10)
- ReleaseMutex (Address: 0x180080a68)
- ReleaseSemaphore (Address: 0x180080a28)
- ReleaseSRWLockExclusive (Address: 0x180080a30)
- ReleaseSRWLockShared (Address: 0x180080a48)
- ResetEvent (Address: 0x180080a90)
- SetEvent (Address: 0x180080aa8)
- WaitForMultipleObjectsEx (Address: 0x180080ab8)
- WaitForSingleObject (Address: 0x180080ab0)
- WaitForSingleObjectEx (Address: 0x180080a50)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x180080ae0)
- InitOnceComplete (Address: 0x180080ae8)
- InitOnceExecuteOnce (Address: 0x180080ad8)
- Sleep (Address: 0x180080af0)
- SleepConditionVariableSRW (Address: 0x180080ac8)
- WakeAllConditionVariable (Address: 0x180080ad0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetLocalTime (Address: 0x180080b10)
- GetSystemTimeAsFileTime (Address: 0x180080b08)
- GetSystemWindowsDirectoryW (Address: 0x180080b00)
- GetTickCount (Address: 0x180080b18)
- GetWindowsDirectoryW (Address: 0x180080b20)
- GlobalMemoryStatusEx (Address: 0x180080b28)
api-ms-win-core-sysinfo-l1-2-1.dll
- GetPhysicallyInstalledSystemMemory (Address: 0x180080b38)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x180080b60)
- CreateThreadpoolTimer (Address: 0x180080b48)
- SetThreadpoolTimer (Address: 0x180080b50)
- WaitForThreadpoolTimerCallbacks (Address: 0x180080b58)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x180080b70)
- SystemTimeToFileTime (Address: 0x180080b78)
api-ms-win-core-url-l1-1-0.dll
- ParseURLW (Address: 0x180080b88)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x180080b98)
- EncodePointer (Address: 0x180080ba0)
api-ms-win-core-winrt-error-l1-1-0.dll
- RoOriginateError (Address: 0x180080bc0)
- RoOriginateErrorW (Address: 0x180080bb0)
- RoTransformError (Address: 0x180080bb8)
- SetRestrictedErrorInfo (Address: 0x180080bc8)
api-ms-win-core-winrt-error-l1-1-1.dll
- RoGetMatchingRestrictedErrorInfo (Address: 0x180080bd8)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x180080bf0)
- RoGetActivationFactory (Address: 0x180080be8)
- RoRegisterActivationFactories (Address: 0x180080bf8)
- RoRevokeActivationFactories (Address: 0x180080c00)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateString (Address: 0x180080c30)
- WindowsCreateStringReference (Address: 0x180080c28)
- WindowsDeleteString (Address: 0x180080c10)
- WindowsGetStringRawBuffer (Address: 0x180080c20)
- WindowsIsStringEmpty (Address: 0x180080c18)
- WindowsStringHasEmbeddedNull (Address: 0x180080c38)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x180080c60)
- EventProviderEnabled (Address: 0x180080c68)
- EventRegister (Address: 0x180080c48)
- EventSetInformation (Address: 0x180080c70)
- EventUnregister (Address: 0x180080c58)
- EventWriteTransfer (Address: 0x180080c50)
api-ms-win-ntuser-sysparams-l1-1-0.dll
- GetSystemMetrics (Address: 0x180080c80)
api-ms-win-rtcore-ntuser-synch-l1-1-0.dll
- MsgWaitForMultipleObjectsEx (Address: 0x180080c90)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
- CreateWindowExW (Address: 0x180080cd8)
- DefWindowProcW (Address: 0x180080ca8)
- DestroyWindow (Address: 0x180080cb0)
- DispatchMessageW (Address: 0x180080ce8)
- GetMessageW (Address: 0x180080cf8)
- GetWindowLongPtrW (Address: 0x180080cc0)
- KillTimer (Address: 0x180080ce0)
- PeekMessageW (Address: 0x180080d08)
- PostQuitMessage (Address: 0x180080cd0)
- RegisterClassExW (Address: 0x180080cf0)
- SetTimer (Address: 0x180080ca0)
- SetWindowLongPtrW (Address: 0x180080cb8)
- TranslateMessage (Address: 0x180080cc8)
- UnregisterClassW (Address: 0x180080d00)
api-ms-win-security-base-l1-1-0.dll
- AddAce (Address: 0x180080d60)
- AdjustTokenPrivileges (Address: 0x180080d28)
- DeleteAce (Address: 0x180080d70)
- DestroyPrivateObjectSecurity (Address: 0x180080d58)
- EqualSid (Address: 0x180080d38)
- GetAce (Address: 0x180080d68)
- GetAclInformation (Address: 0x180080d50)
- GetLengthSid (Address: 0x180080d20)
- GetTokenInformation (Address: 0x180080d30)
- ImpersonateLoggedOnUser (Address: 0x180080d48)
- InitializeAcl (Address: 0x180080d18)
- RevertToSelf (Address: 0x180080d40)
api-ms-win-security-cryptoapi-l1-1-0.dll
- CryptAcquireContextW (Address: 0x180080d88)
- CryptCreateHash (Address: 0x180080da8)
- CryptDestroyHash (Address: 0x180080da0)
- CryptGetHashParam (Address: 0x180080d80)
- CryptHashData (Address: 0x180080d90)
- CryptReleaseContext (Address: 0x180080d98)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x180080db8)
api-ms-win-security-provider-l1-1-0.dll
- GetSecurityInfo (Address: 0x180080dd0)
- SetSecurityInfo (Address: 0x180080dc8)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x180080de8)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180080de0)
api-ms-win-service-core-l1-1-0.dll
- RegisterServiceCtrlHandlerExW (Address: 0x180080e00)
- SetServiceStatus (Address: 0x180080df8)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x180080e28)
- OpenSCManagerW (Address: 0x180080e20)
- OpenServiceW (Address: 0x180080e18)
- StartServiceW (Address: 0x180080e10)
api-ms-win-service-management-l2-1-0.dll
- ChangeServiceConfigW (Address: 0x180080e38)
- QueryServiceConfigW (Address: 0x180080e40)
api-ms-win-shcore-registry-l1-1-0.dll
- SHDeleteKeyW (Address: 0x180080e50)
- SHDeleteValueW (Address: 0x180080e60)
- SHSetValueW (Address: 0x180080e58)
api-ms-win-shcore-stream-l1-1-0.dll
- IStream_Reset (Address: 0x180080e80)
- IStream_Size (Address: 0x180080e70)
- IStream_Write (Address: 0x180080e88)
- SHCreateStreamOnFileEx (Address: 0x180080e78)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolQueueTask (Address: 0x180080e98)
api-ms-win-shell-changenotify-l1-1-0.dll
- SHChangeNotify (Address: 0x180080ea8)
api-ms-win-shell-namespace-l1-1-0.dll
- ILFree (Address: 0x180080eb8)
- SHParseDisplayName (Address: 0x180080ec0)
api-ms-win-shlwapi-winrt-storage-l1-1-1.dll
- (Address: 0x180080ed8)
- PathIsDirectoryEmptyW (Address: 0x180080ee0)
- StrFormatByteSizeEx (Address: 0x180080ed0)
AppXAllUserStore.dll
- DeleteAllPackagesFromMainPackageArray (Address: 0x180080368)
- GetAllPackagesToBeInstalledForUser (Address: 0x180080360)
dmEnrollEngine.DLL
- EnrollEngineInitialize (Address: 0x180080ef0)
msvcrt.dll
- ___lc_codepage_func (Address: 0x180080f60)
- ___lc_handle_func (Address: 0x180080f68)
- ___mb_cur_max_func (Address: 0x180080f70)
- __C_specific_handler (Address: 0x180081058)
- __crtLCMapStringA (Address: 0x180080f08)
- __crtLCMapStringW (Address: 0x180080f10)
- __CxxFrameHandler3 (Address: 0x180080f18)
- __dllonexit (Address: 0x180081038)
- __pctype_func (Address: 0x180080f50)
- _amsg_exit (Address: 0x180081070)
- _callnewh (Address: 0x1800810b0)
- _CxxThrowException (Address: 0x180081090)
- _errno (Address: 0x180080f78)
- _get_errno (Address: 0x180081008)
- _initterm (Address: 0x180081060)
- _ismbblead (Address: 0x180080f58)
- _itow_s (Address: 0x180080fa0)
- _lock (Address: 0x180081048)
- _onexit (Address: 0x180081030)
- _purecall (Address: 0x1800810f0)
- _set_errno (Address: 0x180081010)
- _unlock (Address: 0x180081040)
- _vsnprintf_s (Address: 0x1800810d0)
- _vsnwprintf (Address: 0x180081108)
- _wcsdup (Address: 0x180080f20)
- _wcsicmp (Address: 0x180080fb0)
- _wcsnicmp (Address: 0x180080fa8)
- _wsetlocale (Address: 0x180081118)
- _wtof (Address: 0x180080ff0)
- _XcptFilter (Address: 0x180081078)
- ??_V@YAXPEAX@Z (Address: 0x180081110)
- ??0bad_cast@@QEAA@AEBV0@@Z (Address: 0x180080fe0)
- ??0bad_cast@@QEAA@PEBD@Z (Address: 0x180080fd0)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800810a8)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800810a0)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800810d8)
- ??0exception@@QEAA@XZ (Address: 0x1800810e0)
- ??1bad_cast@@UEAA@XZ (Address: 0x180080fd8)
- ??1exception@@UEAA@XZ (Address: 0x1800810e8)
- ??1type_info@@UEAA@XZ (Address: 0x180081028)
- ??3@YAXPEAX@Z (Address: 0x1800810f8)
- ?terminate@@YAXXZ (Address: 0x180081050)
- ?what@exception@@UEBAPEBDXZ (Address: 0x180081098)
- abort (Address: 0x180080f30)
- calloc (Address: 0x180080f40)
- free (Address: 0x180081068)
- islower (Address: 0x180080f38)
- isupper (Address: 0x180080f48)
- ldiv (Address: 0x180081020)
- localeconv (Address: 0x180080fc8)
- malloc (Address: 0x1800810c0)
- memcmp (Address: 0x180080f00)
- memcpy (Address: 0x180081088)
- memcpy_s (Address: 0x180081100)
- memmove (Address: 0x180081080)
- memmove_s (Address: 0x1800810c8)
- memset (Address: 0x180080f28)
- realloc (Address: 0x180080fb8)
- setlocale (Address: 0x180080f80)
- sprintf_s (Address: 0x180080fe8)
- sqrtf (Address: 0x180081120)
- strcspn (Address: 0x180080fc0)
- swprintf_s (Address: 0x180081000)
- toupper (Address: 0x180080f88)
- wcschr (Address: 0x180080f90)
- wcsncmp (Address: 0x1800810b8)
- wcsrchr (Address: 0x180080f98)
- wcsstr (Address: 0x180081018)
- wcstok_s (Address: 0x180080ff8)
ntdll.dll
- RtlGetDeviceFamilyInfoEnum (Address: 0x180081130)
- RtlGetVersion (Address: 0x180081138)
OLEAUT32.dll
- SysAllocString (Address: 0x180080380)
- SysFreeString (Address: 0x180080378)
- VariantClear (Address: 0x180080388)
PROPSYS.dll
- PropVariantToBoolean (Address: 0x1800803a8)
- PSCreateMemoryPropertyStore (Address: 0x180080398)
- VariantToInt32 (Address: 0x1800803b0)
- VariantToStringAlloc (Address: 0x1800803a0)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x180080400)
- CStdStubBuffer_Connect (Address: 0x180080440)
- CStdStubBuffer_CountRefs (Address: 0x1800803e8)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x180080428)
- CStdStubBuffer_DebugServerRelease (Address: 0x180080420)
- CStdStubBuffer_Disconnect (Address: 0x1800803f0)
- CStdStubBuffer_Invoke (Address: 0x180080438)
- CStdStubBuffer_IsIIDSupported (Address: 0x1800803d8)
- CStdStubBuffer_QueryInterface (Address: 0x180080410)
- IUnknown_AddRef_Proxy (Address: 0x180080430)
- IUnknown_QueryInterface_Proxy (Address: 0x1800803e0)
- IUnknown_Release_Proxy (Address: 0x180080408)
- NdrCStdStubBuffer_Release (Address: 0x1800803d0)
- NdrDllCanUnloadNow (Address: 0x1800803c8)
- NdrDllGetClassObject (Address: 0x1800803c0)
- NdrOleAllocate (Address: 0x180080418)
- NdrOleFree (Address: 0x1800803f8)
SHCORE.dll
- (Address: 0x180080450)
SspiCli.dll
- LsaEnumerateLogonSessions (Address: 0x180080460)
- LsaFreeReturnBuffer (Address: 0x180080470)
- LsaGetLogonSessionData (Address: 0x180080468)
Windows.Storage.dll
- (Address: 0x180080498)
- ILClone (Address: 0x180080488)
- SHCreateItemFromParsingName (Address: 0x180080490)
- ShellExecuteExW (Address: 0x1800804a8)
- SHGetKnownFolderPath (Address: 0x1800804a0)
- SHGetNameFromIDList (Address: 0x180080480)
wlanapi.dll
- WlanCloseHandle (Address: 0x180081158)
- WlanFreeMemory (Address: 0x180081148)
- WlanGetProfile (Address: 0x180081150)
- WlanOpenHandle (Address: 0x180081160)
XmlLite.dll
- CreateXmlReader (Address: 0x1800804b8)
- CreateXmlWriter (Address: 0x1800804c0)