ResourcePolicyServer.dll
Description: Resource Policy RM Service Extension
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 64-bit
Operating System: Windows NT
SHA256: bf8e6b764d6be58e673c8264627243a5
File Size: 146.5 KB
Uploaded At: Dec. 1, 2025, 7:38 a.m.
Views: 5
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- RmRpsInitialize (Ordinal: 1, Address: 0x33b0)
- RmRpsNotifyApplicationInterruptiveUIChange (Ordinal: 2, Address: 0x3500)
- RmRpsQueryResourceSetInfo (Ordinal: 3, Address: 0x35a0)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-l1-1-0.dll
- GetPackageFullName (Address: 0x18001a330)
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x18001a360)
- CoInitializeEx (Address: 0x18001a340)
- CoTaskMemAlloc (Address: 0x18001a350)
- CoTaskMemFree (Address: 0x18001a358)
- CoUninitialize (Address: 0x18001a348)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x18001a370)
- IsDebuggerPresent (Address: 0x18001a380)
- OutputDebugStringW (Address: 0x18001a378)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x18001a390)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x18001a3a0)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18001a3c8)
- RaiseException (Address: 0x18001a3c0)
- SetLastError (Address: 0x18001a3b8)
- SetUnhandledExceptionFilter (Address: 0x18001a3d0)
- UnhandledExceptionFilter (Address: 0x18001a3b0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18001a3e0)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18001a3f8)
- HeapAlloc (Address: 0x18001a3f0)
- HeapFree (Address: 0x18001a400)
api-ms-win-core-heap-l2-1-0.dll
- LocalFree (Address: 0x18001a410)
api-ms-win-core-libraryloader-l1-2-0.dll
- FindStringOrdinal (Address: 0x18001a438)
- GetModuleFileNameA (Address: 0x18001a420)
- GetModuleHandleExW (Address: 0x18001a430)
- GetModuleHandleW (Address: 0x18001a428)
- GetProcAddress (Address: 0x18001a440)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18001a450)
api-ms-win-core-memory-l1-1-0.dll
- ReadProcessMemory (Address: 0x18001a460)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18001a478)
- GetCurrentProcessId (Address: 0x18001a470)
- GetCurrentThread (Address: 0x18001a4a0)
- GetCurrentThreadId (Address: 0x18001a490)
- OpenProcessToken (Address: 0x18001a488)
- OpenThreadToken (Address: 0x18001a498)
- TerminateProcess (Address: 0x18001a480)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x18001a4b0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18001a4c0)
api-ms-win-core-psapi-l1-1-0.dll
- QueryFullProcessImageNameW (Address: 0x18001a4d0)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18001a4e0)
- RegCreateKeyExW (Address: 0x18001a510)
- RegDeleteValueW (Address: 0x18001a518)
- RegEnumKeyExW (Address: 0x18001a4f0)
- RegEnumValueW (Address: 0x18001a520)
- RegOpenKeyExW (Address: 0x18001a508)
- RegQueryInfoKeyW (Address: 0x18001a4e8)
- RegQueryValueExW (Address: 0x18001a4f8)
- RegSetValueExW (Address: 0x18001a500)
api-ms-win-core-registry-l2-1-0.dll
- RegCreateKeyTransactedW (Address: 0x18001a538)
- RegDeleteKeyTransactedW (Address: 0x18001a530)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18001a550)
- RtlLookupFunctionEntry (Address: 0x18001a558)
- RtlVirtualUnwind (Address: 0x18001a548)
api-ms-win-core-synch-l1-1-0.dll
- CreateMutexExW (Address: 0x18001a5a8)
- CreateSemaphoreExW (Address: 0x18001a5b0)
- DeleteCriticalSection (Address: 0x18001a578)
- EnterCriticalSection (Address: 0x18001a5b8)
- InitializeCriticalSectionEx (Address: 0x18001a580)
- LeaveCriticalSection (Address: 0x18001a570)
- OpenSemaphoreW (Address: 0x18001a590)
- ReleaseMutex (Address: 0x18001a568)
- ReleaseSemaphore (Address: 0x18001a5a0)
- WaitForSingleObject (Address: 0x18001a598)
- WaitForSingleObjectEx (Address: 0x18001a588)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x18001a5c8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x18001a5e8)
- GetTickCount (Address: 0x18001a5e0)
- GlobalMemoryStatusEx (Address: 0x18001a5d8)
api-ms-win-core-winrt-l1-1-0.dll
- RoGetActivationFactory (Address: 0x18001a5f8)
- RoInitialize (Address: 0x18001a600)
- RoUninitialize (Address: 0x18001a608)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateStringReference (Address: 0x18001a618)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x18001a630)
- EventRegister (Address: 0x18001a638)
- EventSetInformation (Address: 0x18001a628)
- EventWriteTransfer (Address: 0x18001a640)
api-ms-win-security-accesshlpr-l1-1-0.dll
- FreeTransientObjectSecurityDescriptor (Address: 0x18001a650)
- QueryTransientObjectSecurityDescriptor (Address: 0x18001a658)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x18001a668)
- EqualSid (Address: 0x18001a678)
- GetLengthSid (Address: 0x18001a680)
- GetTokenInformation (Address: 0x18001a688)
- IsValidSid (Address: 0x18001a670)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x18001a698)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x18001a6a8)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18001a6b0)
CRYPT32.dll
- CryptProtectData (Address: 0x18001a268)
- CryptUnprotectData (Address: 0x18001a270)
CRYPTSP.dll
- CryptAcquireContextW (Address: 0x18001a290)
- CryptCreateHash (Address: 0x18001a298)
- CryptDestroyHash (Address: 0x18001a280)
- CryptGetHashParam (Address: 0x18001a2a8)
- CryptHashData (Address: 0x18001a2a0)
- CryptReleaseContext (Address: 0x18001a288)
msvcrt.dll
- __C_specific_handler (Address: 0x18001a750)
- __CxxFrameHandler3 (Address: 0x18001a710)
- __dllonexit (Address: 0x18001a738)
- _amsg_exit (Address: 0x18001a768)
- _callnewh (Address: 0x18001a700)
- _initterm (Address: 0x18001a758)
- _lock (Address: 0x18001a748)
- _onexit (Address: 0x18001a730)
- _purecall (Address: 0x18001a6c0)
- _snprintf_s (Address: 0x18001a6c8)
- _unlock (Address: 0x18001a740)
- _vsnwprintf (Address: 0x18001a708)
- _wcsicmp (Address: 0x18001a6d8)
- _wcslwr (Address: 0x18001a6e0)
- _XcptFilter (Address: 0x18001a770)
- free (Address: 0x18001a778)
- iswupper (Address: 0x18001a6f8)
- malloc (Address: 0x18001a760)
- memcpy (Address: 0x18001a720)
- memcpy_s (Address: 0x18001a780)
- memmove (Address: 0x18001a728)
- memset (Address: 0x18001a790)
- realloc (Address: 0x18001a718)
- towlower (Address: 0x18001a6f0)
- wcschr (Address: 0x18001a6d0)
- wcsrchr (Address: 0x18001a6e8)
- wcstombs (Address: 0x18001a788)
ntdll.dll
- NtCommitRegistryTransaction (Address: 0x18001a810)
- NtCreateRegistryTransaction (Address: 0x18001a880)
- NtCreateWnfStateName (Address: 0x18001a7f0)
- NtDeleteWnfStateName (Address: 0x18001a7f8)
- NtQueryInformationProcess (Address: 0x18001a888)
- NtQueryInformationToken (Address: 0x18001a7c0)
- NtQuerySystemInformation (Address: 0x18001a808)
- NtRollbackRegistryTransaction (Address: 0x18001a8a0)
- RtlAcquireSRWLockExclusive (Address: 0x18001a7c8)
- RtlAllocateHeap (Address: 0x18001a898)
- RtlCompareUnicodeString (Address: 0x18001a818)
- RtlCopySid (Address: 0x18001a800)
- RtlDeleteCriticalSection (Address: 0x18001a830)
- RtlEnterCriticalSection (Address: 0x18001a858)
- RtlFreeHeap (Address: 0x18001a890)
- RtlInitializeCriticalSection (Address: 0x18001a868)
- RtlInitializeSRWLock (Address: 0x18001a7e0)
- RtlInitUnicodeString (Address: 0x18001a828)
- RtlLeaveCriticalSection (Address: 0x18001a870)
- RtlNtStatusToDosError (Address: 0x18001a878)
- RtlNtStatusToDosErrorNoTeb (Address: 0x18001a820)
- RtlPublishWnfStateData (Address: 0x18001a7e8)
- RtlQueryWnfMetaNotification (Address: 0x18001a7b8)
- RtlReleaseSRWLockExclusive (Address: 0x18001a7d0)
- RtlWaitForWnfMetaNotification (Address: 0x18001a7a8)
- TpAllocTimer (Address: 0x18001a840)
- TpAllocWork (Address: 0x18001a7d8)
- TpPostWork (Address: 0x18001a7b0)
- TpReleaseTimer (Address: 0x18001a850)
- TpReleaseWork (Address: 0x18001a7a0)
- TpSetTimer (Address: 0x18001a838)
- TpWaitForTimer (Address: 0x18001a848)
- TpWaitForWork (Address: 0x18001a860)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x18001a308)
- NdrServerCall2 (Address: 0x18001a2f0)
- NdrServerCallAll (Address: 0x18001a2f8)
- RpcBindingVectorFree (Address: 0x18001a2d0)
- RpcEpRegisterW (Address: 0x18001a2d8)
- RpcEpUnregister (Address: 0x18001a310)
- RpcImpersonateClient (Address: 0x18001a318)
- RpcRevertToSelfEx (Address: 0x18001a320)
- RpcServerInqBindings (Address: 0x18001a2e0)
- RpcServerInqCallAttributesW (Address: 0x18001a2e8)
- RpcServerRegisterIf3 (Address: 0x18001a2c8)
- RpcServerUnregisterIfEx (Address: 0x18001a2b8)
- RpcServerUseProtseqW (Address: 0x18001a2c0)
- UuidCreate (Address: 0x18001a300)