SettingSyncCore.dll

Description: Setting Synchronization Core

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: f92a198c27162b1715fa0abdfc216be4

File Size: 1.1 MB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 5

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x54cb0)
  • DllGetActivationFactory (Ordinal: 2, Address: 0x60c00)
  • DllGetClassObject (Ordinal: 3, Address: 0x8660)

Imported DLLs & Functions

api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800c07f8)
  • IsDebuggerPresent (Address: 0x1800c07e8)
  • OutputDebugStringW (Address: 0x1800c07f0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800c0808)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800c0818)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800c0828)
  • RaiseException (Address: 0x1800c0830)
  • SetLastError (Address: 0x1800c0840)
  • SetUnhandledExceptionFilter (Address: 0x1800c0848)
  • UnhandledExceptionFilter (Address: 0x1800c0838)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x1800c08b0)
  • CreateDirectoryW (Address: 0x1800c0890)
  • CreateFileW (Address: 0x1800c08c8)
  • DeleteFileW (Address: 0x1800c08a0)
  • FindClose (Address: 0x1800c0858)
  • FindFirstFileW (Address: 0x1800c0870)
  • FindNextFileW (Address: 0x1800c0860)
  • GetDriveTypeW (Address: 0x1800c0878)
  • GetFileAttributesExW (Address: 0x1800c0888)
  • GetFileAttributesW (Address: 0x1800c0880)
  • GetFileTime (Address: 0x1800c08a8)
  • GetFullPathNameW (Address: 0x1800c0868)
  • GetTempFileNameW (Address: 0x1800c08c0)
  • RemoveDirectoryW (Address: 0x1800c0898)
  • SetFileAttributesW (Address: 0x1800c08d0)
  • SetFileTime (Address: 0x1800c08b8)
api-ms-win-core-file-l1-2-0.dll
  • GetTempPathW (Address: 0x1800c08e0)
api-ms-win-core-file-l2-1-0.dll
  • CopyFileExW (Address: 0x1800c0910)
  • CreateHardLinkW (Address: 0x1800c08f8)
  • GetFileInformationByHandleEx (Address: 0x1800c0900)
  • MoveFileExW (Address: 0x1800c0908)
  • ReadDirectoryChangesW (Address: 0x1800c08f0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800c0920)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1800c0938)
  • HeapAlloc (Address: 0x1800c0930)
  • HeapFree (Address: 0x1800c0940)
  • HeapReAlloc (Address: 0x1800c0948)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1800c0960)
  • LocalFree (Address: 0x1800c0968)
  • LocalReAlloc (Address: 0x1800c0958)
api-ms-win-core-io-l1-1-0.dll
  • CancelIoEx (Address: 0x1800c0978)
  • DeviceIoControl (Address: 0x1800c0980)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
  • VerifyVersionInfoW (Address: 0x1800c0990)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1800c09a0)
  • FindStringOrdinal (Address: 0x1800c09c8)
  • GetModuleFileNameA (Address: 0x1800c09b0)
  • GetModuleHandleExW (Address: 0x1800c09c0)
  • GetModuleHandleW (Address: 0x1800c09a8)
  • GetProcAddress (Address: 0x1800c09b8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800c09d8)
  • LCMapStringEx (Address: 0x1800c09e0)
api-ms-win-core-path-l1-1-0.dll
  • PathAllocCanonicalize (Address: 0x1800c09f8)
  • PathAllocCombine (Address: 0x1800c0a10)
  • PathCchAppend (Address: 0x1800c0a08)
  • PathCchCombine (Address: 0x1800c0a00)
  • PathCchRemoveFileSpec (Address: 0x1800c09f0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800c0a20)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800c0a60)
  • GetCurrentProcessId (Address: 0x1800c0a50)
  • GetCurrentThread (Address: 0x1800c0a40)
  • GetCurrentThreadId (Address: 0x1800c0a48)
  • OpenProcessToken (Address: 0x1800c0a30)
  • OpenThreadToken (Address: 0x1800c0a68)
  • ProcessIdToSessionId (Address: 0x1800c0a58)
  • TerminateProcess (Address: 0x1800c0a38)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x1800c0a78)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800c0a88)
api-ms-win-core-psapi-l1-1-0.dll
  • QueryFullProcessImageNameW (Address: 0x1800c0a98)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800c0ac0)
  • RegCreateKeyExW (Address: 0x1800c0b08)
  • RegDeleteTreeW (Address: 0x1800c0ac8)
  • RegDeleteValueW (Address: 0x1800c0ad8)
  • RegEnumKeyExW (Address: 0x1800c0ae0)
  • RegEnumValueW (Address: 0x1800c0aa8)
  • RegGetValueW (Address: 0x1800c0ab0)
  • RegNotifyChangeKeyValue (Address: 0x1800c0b00)
  • RegOpenCurrentUser (Address: 0x1800c0af8)
  • RegOpenKeyExW (Address: 0x1800c0af0)
  • RegQueryInfoKeyW (Address: 0x1800c0ad0)
  • RegQueryValueExW (Address: 0x1800c0ab8)
  • RegSetValueExW (Address: 0x1800c0ae8)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueW (Address: 0x1800c0b18)
api-ms-win-core-registry-l2-1-0.dll
  • RegDeleteKeyW (Address: 0x1800c0b28)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800c0b40)
  • RtlLookupFunctionEntry (Address: 0x1800c0b48)
  • RtlVirtualUnwind (Address: 0x1800c0b38)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFileExistsW (Address: 0x1800c0b70)
  • PathFindExtensionW (Address: 0x1800c0b90)
  • PathFindFileNameW (Address: 0x1800c0b88)
  • PathGetCharTypeW (Address: 0x1800c0b68)
  • PathGetDriveNumberW (Address: 0x1800c0b60)
  • PathIsUNCW (Address: 0x1800c0b78)
  • PathRemoveFileSpecW (Address: 0x1800c0b80)
  • PathStripPathW (Address: 0x1800c0b58)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • QISearch (Address: 0x1800c0ba8)
  • StrRChrW (Address: 0x1800c0ba0)
  • StrToIntExW (Address: 0x1800c0bb0)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1800c0bc0)
api-ms-win-core-string-l2-1-0.dll
  • CharLowerBuffW (Address: 0x1800c0bd0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800c0c60)
  • AcquireSRWLockShared (Address: 0x1800c0be8)
  • CreateEventExW (Address: 0x1800c0c18)
  • CreateMutexExW (Address: 0x1800c0c70)
  • CreateSemaphoreExW (Address: 0x1800c0c28)
  • DeleteCriticalSection (Address: 0x1800c0bf0)
  • EnterCriticalSection (Address: 0x1800c0c20)
  • InitializeCriticalSectionEx (Address: 0x1800c0c00)
  • InitializeSRWLock (Address: 0x1800c0c08)
  • LeaveCriticalSection (Address: 0x1800c0c30)
  • OpenEventW (Address: 0x1800c0c10)
  • OpenSemaphoreW (Address: 0x1800c0c78)
  • ReleaseMutex (Address: 0x1800c0c50)
  • ReleaseSemaphore (Address: 0x1800c0c40)
  • ReleaseSRWLockExclusive (Address: 0x1800c0c68)
  • ReleaseSRWLockShared (Address: 0x1800c0bf8)
  • SetEvent (Address: 0x1800c0c38)
  • TryAcquireSRWLockExclusive (Address: 0x1800c0be0)
  • WaitForSingleObject (Address: 0x1800c0c48)
  • WaitForSingleObjectEx (Address: 0x1800c0c58)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x1800c0ca0)
  • InitOnceComplete (Address: 0x1800c0c98)
  • InitOnceExecuteOnce (Address: 0x1800c0c88)
  • Sleep (Address: 0x1800c0c90)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTime (Address: 0x1800c0cb0)
  • GetSystemTimeAsFileTime (Address: 0x1800c0cc0)
  • GetTickCount (Address: 0x1800c0cb8)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetOsSafeBootMode (Address: 0x1800c0cd0)
  • VerSetConditionMask (Address: 0x1800c0cd8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CancelThreadpoolIo (Address: 0x1800c0d10)
  • CloseThreadpoolIo (Address: 0x1800c0d50)
  • CloseThreadpoolTimer (Address: 0x1800c0d18)
  • CloseThreadpoolWait (Address: 0x1800c0ce8)
  • CreateThreadpoolIo (Address: 0x1800c0cf8)
  • CreateThreadpoolTimer (Address: 0x1800c0d28)
  • CreateThreadpoolWait (Address: 0x1800c0d30)
  • DisassociateCurrentThreadFromCallback (Address: 0x1800c0d20)
  • SetThreadpoolTimer (Address: 0x1800c0d38)
  • SetThreadpoolWait (Address: 0x1800c0d40)
  • StartThreadpoolIo (Address: 0x1800c0d00)
  • WaitForThreadpoolIoCallbacks (Address: 0x1800c0d48)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800c0d08)
  • WaitForThreadpoolWaitCallbacks (Address: 0x1800c0cf0)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x1800c0d60)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x1800c0d78)
  • EncodePointer (Address: 0x1800c0d70)
api-ms-win-core-version-l1-1-0.dll
  • GetFileVersionInfoExW (Address: 0x1800c0d90)
  • GetFileVersionInfoSizeExW (Address: 0x1800c0d88)
  • VerQueryValueW (Address: 0x1800c0d98)
api-ms-win-core-winrt-error-l1-1-0.dll
  • GetRestrictedErrorInfo (Address: 0x1800c0dc0)
  • RoOriginateError (Address: 0x1800c0db8)
  • RoOriginateErrorW (Address: 0x1800c0db0)
  • RoTransformError (Address: 0x1800c0da8)
  • SetRestrictedErrorInfo (Address: 0x1800c0dc8)
api-ms-win-core-winrt-error-l1-1-1.dll
  • IsErrorPropagationEnabled (Address: 0x1800c0de8)
  • RoGetMatchingRestrictedErrorInfo (Address: 0x1800c0dd8)
  • RoReportFailedDelegate (Address: 0x1800c0de0)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1800c0df8)
  • RoGetActivationFactory (Address: 0x1800c0e00)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCompareStringOrdinal (Address: 0x1800c0e10)
  • WindowsCreateString (Address: 0x1800c0e18)
  • WindowsCreateStringReference (Address: 0x1800c0e30)
  • WindowsDeleteString (Address: 0x1800c0e38)
  • WindowsDuplicateString (Address: 0x1800c0e40)
  • WindowsGetStringRawBuffer (Address: 0x1800c0e28)
  • WindowsIsStringEmpty (Address: 0x1800c0e48)
  • WindowsStringHasEmbeddedNull (Address: 0x1800c0e20)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x1800c0e58)
  • GetTraceEnableLevel (Address: 0x1800c0e80)
  • GetTraceLoggerHandle (Address: 0x1800c0e60)
  • RegisterTraceGuidsW (Address: 0x1800c0e68)
  • TraceMessage (Address: 0x1800c0e78)
  • UnregisterTraceGuids (Address: 0x1800c0e70)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x1800c0ea8)
  • EventRegister (Address: 0x1800c0eb0)
  • EventSetInformation (Address: 0x1800c0e90)
  • EventUnregister (Address: 0x1800c0e98)
  • EventWriteTransfer (Address: 0x1800c0ea0)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAceEx (Address: 0x1800c0ed0)
  • AddAccessDeniedAceEx (Address: 0x1800c0ec0)
  • AddAce (Address: 0x1800c0f18)
  • CopySid (Address: 0x1800c0ef8)
  • DeleteAce (Address: 0x1800c0f28)
  • EqualSid (Address: 0x1800c0f00)
  • GetAce (Address: 0x1800c0f08)
  • GetAclInformation (Address: 0x1800c0f10)
  • GetLengthSid (Address: 0x1800c0ee8)
  • GetSecurityDescriptorControl (Address: 0x1800c0ed8)
  • GetSecurityDescriptorSacl (Address: 0x1800c0ef0)
  • GetTokenInformation (Address: 0x1800c0ee0)
  • InitializeAcl (Address: 0x1800c0f20)
  • IsValidSid (Address: 0x1800c0ec8)
api-ms-win-security-cryptoapi-l1-1-0.dll
  • CryptAcquireContextW (Address: 0x1800c0f60)
  • CryptCreateHash (Address: 0x1800c0f50)
  • CryptDestroyHash (Address: 0x1800c0f48)
  • CryptGetHashParam (Address: 0x1800c0f38)
  • CryptHashData (Address: 0x1800c0f58)
  • CryptReleaseContext (Address: 0x1800c0f40)
api-ms-win-shcore-obsolete-l1-1-0.dll
  • SHStrDupW (Address: 0x1800c0f70)
api-ms-win-shcore-registry-l1-1-0.dll
  • SHDeleteValueW (Address: 0x1800c0f80)
  • SHGetValueW (Address: 0x1800c0f98)
  • SHRegGetValueW (Address: 0x1800c0f90)
  • SHSetValueW (Address: 0x1800c0f88)
api-ms-win-shcore-stream-l1-1-0.dll
  • IStream_Copy (Address: 0x1800c0fd0)
  • IStream_Read (Address: 0x1800c0fa8)
  • IStream_Reset (Address: 0x1800c0fc8)
  • IStream_Size (Address: 0x1800c0fc0)
  • IStream_Write (Address: 0x1800c0fd8)
  • SHCreateMemStream (Address: 0x1800c0fb0)
  • SHCreateStreamOnFileEx (Address: 0x1800c0fb8)
api-ms-win-shcore-sysinfo-l1-1-0.dll
  • IsOS (Address: 0x1800c0fe8)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolAllowThreadReuse (Address: 0x1800c0ff8)
  • SHTaskPoolQueueTask (Address: 0x1800c1000)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x1800c1038)
  • BCryptCreateHash (Address: 0x1800c1028)
  • BCryptDestroyHash (Address: 0x1800c1040)
  • BCryptFinishHash (Address: 0x1800c1020)
  • BCryptGetProperty (Address: 0x1800c1048)
  • BCryptHashData (Address: 0x1800c1050)
  • BCryptOpenAlgorithmProvider (Address: 0x1800c1030)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800c10f0)
  • __CxxFrameHandler3 (Address: 0x1800c1198)
  • __dllonexit (Address: 0x1800c10a8)
  • _amsg_exit (Address: 0x1800c10e0)
  • _CxxThrowException (Address: 0x1800c1068)
  • _get_errno (Address: 0x1800c1160)
  • _initterm (Address: 0x1800c10c8)
  • _lock (Address: 0x1800c10c0)
  • _onexit (Address: 0x1800c10a0)
  • _purecall (Address: 0x1800c1120)
  • _set_errno (Address: 0x1800c1170)
  • _unlock (Address: 0x1800c10b8)
  • _vsnprintf_s (Address: 0x1800c1100)
  • _vsnwprintf (Address: 0x1800c1168)
  • _wcsicmp (Address: 0x1800c1188)
  • _XcptFilter (Address: 0x1800c10e8)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800c1090)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800c1078)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800c1108)
  • ??0exception@@QEAA@XZ (Address: 0x1800c1110)
  • ??1exception@@UEAA@XZ (Address: 0x1800c1118)
  • ??1type_info@@UEAA@XZ (Address: 0x1800c1088)
  • ?terminate@@YAXXZ (Address: 0x1800c1098)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x1800c1070)
  • free (Address: 0x1800c10d8)
  • iswalnum (Address: 0x1800c10f8)
  • malloc (Address: 0x1800c10d0)
  • memcmp (Address: 0x1800c1080)
  • memcpy (Address: 0x1800c1060)
  • memcpy_s (Address: 0x1800c1128)
  • memmove (Address: 0x1800c1180)
  • memmove_s (Address: 0x1800c1158)
  • memset (Address: 0x1800c11a0)
  • realloc (Address: 0x1800c1150)
  • swscanf_s (Address: 0x1800c10b0)
  • wcschr (Address: 0x1800c1140)
  • wcsncmp (Address: 0x1800c1190)
  • wcsncpy_s (Address: 0x1800c1130)
  • wcsrchr (Address: 0x1800c1138)
  • wcsstr (Address: 0x1800c1178)
  • wcstok_s (Address: 0x1800c1148)
ntdll.dll
  • EtwEventWriteTransfer (Address: 0x1800c1238)
  • NtCreateWnfStateName (Address: 0x1800c1210)
  • NtDeleteWnfStateName (Address: 0x1800c1200)
  • NtQueryWnfStateData (Address: 0x1800c11d8)
  • NtSetInformationFile (Address: 0x1800c11d0)
  • RtlAcquireResourceExclusive (Address: 0x1800c11c8)
  • RtlAcquireResourceShared (Address: 0x1800c11b0)
  • RtlAllocateHeap (Address: 0x1800c11e8)
  • RtlComputeCrc32 (Address: 0x1800c11f8)
  • RtlConvertSidToUnicodeString (Address: 0x1800c11e0)
  • RtlDeleteResource (Address: 0x1800c11b8)
  • RtlFreeHeap (Address: 0x1800c11f0)
  • RtlFreeUnicodeString (Address: 0x1800c1230)
  • RtlInitializeResource (Address: 0x1800c11c0)
  • RtlMapGenericMask (Address: 0x1800c1228)
  • RtlNtStatusToDosError (Address: 0x1800c1218)
  • RtlReleaseResource (Address: 0x1800c1240)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x1800c1208)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1800c1220)
policymanager.dll
  • PolicyManager_GetPolicyInt (Address: 0x1800c1250)
profapi.dll
  • (Address: 0x1800c1260)
SHCORE.dll
  • (Address: 0x1800c07a8)
  • (Address: 0x1800c07a0)
  • (Address: 0x1800c07b0)
UMPDC.dll
  • Pdcv2ActivationClientActivate (Address: 0x1800c07c8)
  • Pdcv2ActivationClientDeactivate (Address: 0x1800c07c0)
  • Pdcv2ActivationClientRegister (Address: 0x1800c07d8)
  • Pdcv2ActivationClientUnregister (Address: 0x1800c07d0)