RDXTaskFactory.dll

Description: RDXTaskFactory

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6216

Architecture: 64-bit

Operating System: Windows NT

SHA256: 32af99845a847df0429eae71fca3e110

File Size: 415.5 KB

Uploaded At: Dec. 1, 2025, 7:37 a.m.

Views: 4

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x5c60)
  • DllGetClassObject (Ordinal: 2, Address: 0x5cd0)
  • GetProxyDllInfo (Ordinal: 3, Address: 0x2870)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x1800480d8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800480e8)
  • IsDebuggerPresent (Address: 0x1800480f0)
  • OutputDebugStringW (Address: 0x1800480f8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180048108)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180048118)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180048140)
  • RaiseException (Address: 0x180048130)
  • SetLastError (Address: 0x180048138)
  • SetUnhandledExceptionFilter (Address: 0x180048128)
  • UnhandledExceptionFilter (Address: 0x180048148)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x180048168)
  • FindClose (Address: 0x180048170)
  • FindFirstFileW (Address: 0x180048178)
  • FindNextFileW (Address: 0x180048160)
  • GetFullPathNameW (Address: 0x180048158)
api-ms-win-core-file-l2-1-2.dll
  • CopyFileW (Address: 0x180048188)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180048198)
  • DuplicateHandle (Address: 0x1800481a0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1800481b8)
  • HeapAlloc (Address: 0x1800481b0)
  • HeapFree (Address: 0x1800481c0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1800481d8)
  • LocalFree (Address: 0x1800481d0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1800481e8)
  • FreeLibrary (Address: 0x180048208)
  • GetModuleFileNameA (Address: 0x1800481f8)
  • GetModuleHandleExW (Address: 0x180048210)
  • GetModuleHandleW (Address: 0x180048218)
  • GetProcAddress (Address: 0x180048200)
  • LoadLibraryExW (Address: 0x1800481f0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180048228)
  • GetUserDefaultLCID (Address: 0x180048230)
api-ms-win-core-localization-obsolete-l1-2-0.dll
  • GetUserDefaultUILanguage (Address: 0x180048240)
api-ms-win-core-path-l1-1-0.dll
  • PathAllocCombine (Address: 0x180048250)
  • PathCchAppend (Address: 0x180048260)
  • PathCchCombine (Address: 0x180048258)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x180048270)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800482b0)
  • GetCurrentProcessId (Address: 0x180048280)
  • GetCurrentThread (Address: 0x1800482a0)
  • GetCurrentThreadId (Address: 0x180048298)
  • GetExitCodeProcess (Address: 0x1800482b8)
  • OpenProcessToken (Address: 0x1800482a8)
  • OpenThreadToken (Address: 0x180048290)
  • TerminateProcess (Address: 0x180048288)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x1800482c8)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800482d8)
api-ms-win-core-psapi-l1-1-0.dll
  • K32GetProcessImageFileNameW (Address: 0x1800482e8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180048318)
  • RegCreateKeyExW (Address: 0x180048330)
  • RegDeleteTreeW (Address: 0x180048300)
  • RegGetValueW (Address: 0x1800482f8)
  • RegOpenCurrentUser (Address: 0x180048308)
  • RegOpenKeyExW (Address: 0x180048328)
  • RegQueryValueExW (Address: 0x180048320)
  • RegSetValueExW (Address: 0x180048310)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueW (Address: 0x180048340)
  • RegSetKeyValueW (Address: 0x180048348)
api-ms-win-core-registry-l2-1-0.dll
  • RegCreateKeyW (Address: 0x180048358)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180048378)
  • RtlLookupFunctionEntry (Address: 0x180048370)
  • RtlVirtualUnwind (Address: 0x180048368)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x180048388)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180048410)
  • AcquireSRWLockShared (Address: 0x180048428)
  • CreateEventExW (Address: 0x180048398)
  • CreateMutexExW (Address: 0x1800483d8)
  • CreateSemaphoreExW (Address: 0x1800483e8)
  • DeleteCriticalSection (Address: 0x180048418)
  • EnterCriticalSection (Address: 0x180048408)
  • InitializeCriticalSectionEx (Address: 0x1800483f8)
  • LeaveCriticalSection (Address: 0x1800483e0)
  • OpenEventW (Address: 0x1800483b8)
  • OpenSemaphoreW (Address: 0x180048420)
  • ReleaseMutex (Address: 0x1800483f0)
  • ReleaseSemaphore (Address: 0x1800483c8)
  • ReleaseSRWLockExclusive (Address: 0x1800483d0)
  • ReleaseSRWLockShared (Address: 0x180048400)
  • SetEvent (Address: 0x1800483b0)
  • WaitForMultipleObjectsEx (Address: 0x1800483a0)
  • WaitForSingleObject (Address: 0x1800483c0)
  • WaitForSingleObjectEx (Address: 0x1800483a8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180048448)
  • InitOnceComplete (Address: 0x180048460)
  • InitOnceExecuteOnce (Address: 0x180048440)
  • Sleep (Address: 0x180048450)
  • SleepConditionVariableSRW (Address: 0x180048458)
  • WakeAllConditionVariable (Address: 0x180048438)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x180048480)
  • GetSystemTimeAsFileTime (Address: 0x180048470)
  • GetTickCount (Address: 0x180048478)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180048498)
  • CreateThreadpoolTimer (Address: 0x1800484a8)
  • SetThreadpoolTimer (Address: 0x1800484a0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180048490)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x1800484c0)
  • DeleteTimerQueueTimer (Address: 0x1800484b8)
api-ms-win-core-timezone-l1-1-0.dll
  • GetTimeZoneInformation (Address: 0x1800484d8)
  • SystemTimeToFileTime (Address: 0x1800484d0)
api-ms-win-core-toolhelp-l1-1-0.dll
  • CreateToolhelp32Snapshot (Address: 0x1800484f0)
  • Process32NextW (Address: 0x1800484e8)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180048500)
  • EncodePointer (Address: 0x180048508)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180048520)
  • RoGetActivationFactory (Address: 0x180048518)
api-ms-win-core-winrt-propertysetprivate-l1-1-1.dll
  • RoCreatePropertySetSerializer (Address: 0x180048530)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x180048568)
  • WindowsCreateStringReference (Address: 0x180048550)
  • WindowsDeleteString (Address: 0x180048548)
  • WindowsDuplicateString (Address: 0x180048540)
  • WindowsGetStringRawBuffer (Address: 0x180048560)
  • WindowsSubstringWithSpecifiedLength (Address: 0x180048558)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x180048578)
  • EventProviderEnabled (Address: 0x180048598)
  • EventRegister (Address: 0x180048590)
  • EventSetInformation (Address: 0x1800485a0)
  • EventUnregister (Address: 0x180048580)
  • EventWriteTransfer (Address: 0x180048588)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • GetDisplayConfigBufferSizes (Address: 0x1800485b8)
  • QueryDisplayConfig (Address: 0x1800485c0)
  • SystemParametersInfoW (Address: 0x1800485b0)
api-ms-win-power-setting-l1-1-0.dll
  • PowerGetActiveScheme (Address: 0x1800485d0)
  • PowerSetActiveScheme (Address: 0x1800485e8)
  • PowerWriteACValueIndex (Address: 0x1800485e0)
  • PowerWriteDCValueIndex (Address: 0x1800485d8)
api-ms-win-security-base-l1-1-0.dll
  • CreateWellKnownSid (Address: 0x180048600)
  • GetTokenInformation (Address: 0x180048610)
  • ImpersonateLoggedOnUser (Address: 0x180048608)
  • RevertToSelf (Address: 0x1800485f8)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountNameW (Address: 0x180048620)
  • LookupAccountSidW (Address: 0x180048628)
api-ms-win-security-provider-l1-1-0.dll
  • GetNamedSecurityInfoW (Address: 0x180048640)
  • SetEntriesInAclW (Address: 0x180048648)
  • SetNamedSecurityInfoW (Address: 0x180048638)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180048658)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x180048678)
  • OpenSCManagerW (Address: 0x180048668)
  • OpenServiceW (Address: 0x180048680)
  • StartServiceW (Address: 0x180048670)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfigW (Address: 0x180048690)
  • QueryServiceConfigW (Address: 0x180048698)
api-ms-win-service-private-l1-1-0.dll
  • WaitServiceState (Address: 0x1800486a8)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x1800486b8)
combase.dll
  • (Address: 0x1800486d8)
  • (Address: 0x1800486e0)
  • (Address: 0x1800486e8)
  • (Address: 0x1800486f8)
  • (Address: 0x180048708)
  • (Address: 0x180048718)
  • (Address: 0x180048728)
  • (Address: 0x180048730)
  • (Address: 0x180048740)
  • (Address: 0x180048750)
  • (Address: 0x180048758)
  • (Address: 0x180048760)
  • (Address: 0x180048768)
  • (Address: 0x180048770)
  • (Address: 0x180048780)
  • (Address: 0x180048788)
  • (Address: 0x180048790)
  • (Address: 0x180048798)
  • (Address: 0x1800487a8)
  • (Address: 0x1800487b8)
  • (Address: 0x1800487c8)
  • (Address: 0x1800487d0)
  • (Address: 0x1800487d8)
  • CStdStubBuffer_AddRef (Address: 0x1800486f0)
  • CStdStubBuffer_Connect (Address: 0x180048738)
  • CStdStubBuffer_CountRefs (Address: 0x180048720)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800487c0)
  • CStdStubBuffer_DebugServerRelease (Address: 0x1800487b0)
  • CStdStubBuffer_Disconnect (Address: 0x180048710)
  • CStdStubBuffer_Invoke (Address: 0x1800487a0)
  • CStdStubBuffer_IsIIDSupported (Address: 0x180048700)
  • CStdStubBuffer_QueryInterface (Address: 0x180048778)
  • NdrCStdStubBuffer_Release (Address: 0x180048748)
CRYPT32.dll
  • CryptUnprotectData (Address: 0x180047f00)
msvcrt.dll
  • __C_specific_handler (Address: 0x180048838)
  • __CxxFrameHandler3 (Address: 0x1800487e8)
  • __dllonexit (Address: 0x180048818)
  • _amsg_exit (Address: 0x180048850)
  • _callnewh (Address: 0x180048890)
  • _CxxThrowException (Address: 0x180048870)
  • _get_errno (Address: 0x1800488a8)
  • _initterm (Address: 0x180048840)
  • _lock (Address: 0x180048828)
  • _onexit (Address: 0x180048810)
  • _purecall (Address: 0x1800488f0)
  • _set_errno (Address: 0x1800488a0)
  • _unlock (Address: 0x180048820)
  • _vsnprintf_s (Address: 0x1800488d0)
  • _vsnwprintf (Address: 0x180048908)
  • _wcsicmp (Address: 0x1800488b0)
  • _wcsnicmp (Address: 0x1800488b8)
  • _XcptFilter (Address: 0x180048858)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180048888)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180048880)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800488d8)
  • ??0exception@@QEAA@XZ (Address: 0x1800488e0)
  • ??1exception@@UEAA@XZ (Address: 0x1800488e8)
  • ??1type_info@@UEAA@XZ (Address: 0x180048808)
  • ??3@YAXPEAX@Z (Address: 0x1800488f8)
  • ?terminate@@YAXXZ (Address: 0x180048830)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180048878)
  • free (Address: 0x180048848)
  • malloc (Address: 0x1800488c8)
  • memcmp (Address: 0x180048910)
  • memcpy (Address: 0x180048868)
  • memcpy_s (Address: 0x180048900)
  • memmove (Address: 0x180048860)
  • memmove_s (Address: 0x180048898)
  • memset (Address: 0x180048800)
  • sqrtf (Address: 0x180048918)
  • toupper (Address: 0x1800487f8)
  • wcscspn (Address: 0x1800487f0)
  • wcsrchr (Address: 0x1800488c0)
netutils.dll
  • NetApiBufferFree (Address: 0x180048928)
ntdll.dll
  • NtQueryWnfStateData (Address: 0x180048950)
  • RtlGetVersion (Address: 0x180048940)
  • RtlNtStatusToDosError (Address: 0x180048938)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x180048948)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x180048958)
OLEAUT32.dll
  • SysAllocString (Address: 0x180047f18)
  • SysFreeString (Address: 0x180047f10)
  • VariantClear (Address: 0x180047f20)
POWRPROF.dll
  • PowerReadACDefaultIndex (Address: 0x180047f30)
  • PowerReadDCDefaultIndex (Address: 0x180047f38)
RPCRT4.dll
  • IUnknown_AddRef_Proxy (Address: 0x180047f58)
  • IUnknown_QueryInterface_Proxy (Address: 0x180047f68)
  • IUnknown_Release_Proxy (Address: 0x180047f60)
  • NdrDllCanUnloadNow (Address: 0x180047f48)
  • NdrDllGetClassObject (Address: 0x180047f50)
  • NdrOleAllocate (Address: 0x180047f70)
  • NdrOleFree (Address: 0x180047f78)
SHCORE.dll
  • (Address: 0x180047fa0)
  • (Address: 0x180047fa8)
  • IUnknown_GetSite (Address: 0x180047f88)
  • IUnknown_QueryService (Address: 0x180047fc0)
  • IUnknown_SetSite (Address: 0x180047f98)
  • SHCreateStreamOnFileW (Address: 0x180047fb0)
  • SHDeleteKeyW (Address: 0x180047fd0)
  • SHDeleteValueW (Address: 0x180047fc8)
  • SHGetThreadRef (Address: 0x180047f90)
  • SHTaskPoolQueueTask (Address: 0x180047fb8)
SHELL32.dll
  • SHGetKnownFolderIDList (Address: 0x180047fe0)
  • SHQueryRecycleBinW (Address: 0x180047fe8)
SHLWAPI.dll
  • PathFileExistsW (Address: 0x180048000)
  • PathStripPathW (Address: 0x180048010)
  • SHRegGetUSValueW (Address: 0x180048018)
  • StrRChrW (Address: 0x180048008)
  • StrStrIW (Address: 0x180047ff8)
SspiCli.dll
  • LsaEnumerateLogonSessions (Address: 0x180048030)
  • LsaFreeReturnBuffer (Address: 0x180048038)
  • LsaGetLogonSessionData (Address: 0x180048028)
USER32.dll
  • (Address: 0x180048058)
  • CallNextHookEx (Address: 0x180048078)
  • EnumWindows (Address: 0x1800480a0)
  • GetCursorPos (Address: 0x1800480a8)
  • GetKeyState (Address: 0x180048090)
  • GetWindowInfo (Address: 0x180048080)
  • GetWindowThreadProcessId (Address: 0x180048070)
  • IsWindowVisible (Address: 0x180048088)
  • LoadCursorW (Address: 0x180048068)
  • PtInRect (Address: 0x1800480c0)
  • SetCursor (Address: 0x180048048)
  • SetCursorPos (Address: 0x1800480b8)
  • SetDisplayConfig (Address: 0x1800480b0)
  • SetWindowPlacement (Address: 0x1800480c8)
  • SetWindowPos (Address: 0x180048098)
  • SetWindowsHookExW (Address: 0x180048050)
  • UnhookWindowsHookEx (Address: 0x180048060)