SHCore.dll

Description: SHCORE

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 63257882eb0d0d08ccc275287e11e721

File Size: 686.1 KB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • (Ordinal: 1, Address: 0xa0a0)
  • CommandLineToArgvW (Ordinal: 2, Address: 0x1e030)
  • CreateRandomAccessStreamOnFile (Ordinal: 3, Address: 0x30d20)
  • CreateRandomAccessStreamOverStream (Ordinal: 4, Address: 0x234b0)
  • CreateStreamOverRandomAccessStream (Ordinal: 5, Address: 0x31440)
  • DllCanUnloadNow (Ordinal: 6, Address: 0x326e0)
  • DllGetActivationFactory (Ordinal: 7, Address: 0x567e0)
  • DllGetClassObject (Ordinal: 8, Address: 0x302d0)
  • GetCurrentProcessExplicitAppUserModelID (Ordinal: 9, Address: 0x72d50)
  • GetDpiForMonitor (Ordinal: 10, Address: 0xb5a0)
  • GetDpiForShellUIComponent (Ordinal: 11, Address: 0x30320)
  • GetFeatureEnabledState (Ordinal: 12, Address: 0x2b3f0)
  • GetFeatureVariant (Ordinal: 13, Address: 0x2b350)
  • GetProcessDpiAwareness (Ordinal: 14, Address: 0x37620)
  • GetProcessReference (Ordinal: 15, Address: 0x26390)
  • GetScaleFactorForDevice (Ordinal: 16, Address: 0x32630)
  • GetScaleFactorForMonitor (Ordinal: 17, Address: 0x2fac0)
  • IStream_Copy (Ordinal: 18, Address: 0x2070)
  • IStream_Read (Ordinal: 19, Address: 0xbd90)
  • IStream_ReadStr (Ordinal: 20, Address: 0xb360)
  • IStream_Reset (Ordinal: 21, Address: 0xedc0)
  • IStream_Size (Ordinal: 22, Address: 0x30bd0)
  • IStream_Write (Ordinal: 23, Address: 0x251e0)
  • IStream_WriteStr (Ordinal: 24, Address: 0x25260)
  • IUnknown_AtomicRelease (Ordinal: 25, Address: 0x568e0)
  • IUnknown_GetSite (Ordinal: 26, Address: 0x28080)
  • IUnknown_QueryService (Ordinal: 27, Address: 0x1f8f0)
  • IUnknown_Set (Ordinal: 28, Address: 0x1f7f0)
  • IUnknown_SetSite (Ordinal: 29, Address: 0x28110)
  • IsOS (Ordinal: 30, Address: 0x1d1c0)
  • IsProcessInIsolatedContainer (Ordinal: 31, Address: 0x31b60)
  • IsProcessInWDAGContainer (Ordinal: 32, Address: 0x31a60)
  • RecordFeatureError (Ordinal: 33, Address: 0x57210)
  • RecordFeatureUsage (Ordinal: 34, Address: 0x19550)
  • RegisterScaleChangeEvent (Ordinal: 35, Address: 0x384a0)
  • RegisterScaleChangeNotifications (Ordinal: 36, Address: 0x59500)
  • RevokeScaleChangeNotifications (Ordinal: 37, Address: 0x59840)
  • SHAnsiToAnsi (Ordinal: 38, Address: 0x73790)
  • SHAnsiToUnicode (Ordinal: 39, Address: 0x1faa0)
  • SHCopyKeyA (Ordinal: 40, Address: 0x58080)
  • SHCopyKeyW (Ordinal: 41, Address: 0x58100)
  • SHCreateMemStream (Ordinal: 42, Address: 0x107d0)
  • SHCreateStreamOnFileA (Ordinal: 43, Address: 0x6a2d0)
  • SHCreateStreamOnFileEx (Ordinal: 44, Address: 0x319d0)
  • SHCreateStreamOnFileW (Ordinal: 45, Address: 0x2a7d0)
  • SHCreateThread (Ordinal: 46, Address: 0x26080)
  • SHCreateThreadRef (Ordinal: 47, Address: 0x2bfc0)
  • SHCreateThreadWithHandle (Ordinal: 48, Address: 0x26060)
  • SHDeleteEmptyKeyA (Ordinal: 49, Address: 0x578e0)
  • SHDeleteEmptyKeyW (Ordinal: 50, Address: 0x57b60)
  • SHDeleteKeyA (Ordinal: 51, Address: 0x583d0)
  • SHDeleteKeyW (Ordinal: 52, Address: 0x38a20)
  • SHDeleteValueA (Ordinal: 53, Address: 0x579f0)
  • SHDeleteValueW (Ordinal: 54, Address: 0x374e0)
  • SHEnumKeyExA (Ordinal: 55, Address: 0x58450)
  • SHEnumKeyExW (Ordinal: 56, Address: 0x35d60)
  • SHEnumValueA (Ordinal: 57, Address: 0x58490)
  • SHEnumValueW (Ordinal: 58, Address: 0x36d00)
  • SHGetThreadRef (Ordinal: 59, Address: 0x266e0)
  • SHGetValueA (Ordinal: 60, Address: 0x36680)
  • SHGetValueW (Ordinal: 61, Address: 0x1b510)
  • SHOpenRegStream2A (Ordinal: 62, Address: 0x69890)
  • SHOpenRegStream2W (Ordinal: 63, Address: 0x2ca90)
  • SHOpenRegStreamA (Ordinal: 64, Address: 0x69990)
  • SHOpenRegStreamW (Ordinal: 65, Address: 0x699c0)
  • SHQueryInfoKeyA (Ordinal: 66, Address: 0x58560)
  • SHQueryInfoKeyW (Ordinal: 67, Address: 0x37d80)
  • SHQueryValueExA (Ordinal: 68, Address: 0x585c0)
  • SHQueryValueExW (Ordinal: 69, Address: 0x1b4c0)
  • SHRegDuplicateHKey (Ordinal: 70, Address: 0x58600)
  • SHRegGetIntW (Ordinal: 71, Address: 0x58640)
  • SHRegGetPathA (Ordinal: 72, Address: 0x586f0)
  • SHRegGetPathW (Ordinal: 73, Address: 0x58730)
  • SHRegGetValueA (Ordinal: 74, Address: 0x366c0)
  • SHRegGetValueW (Ordinal: 75, Address: 0x1ad60)
  • SHRegSetPathA (Ordinal: 76, Address: 0x58770)
  • SHRegSetPathW (Ordinal: 77, Address: 0x58820)
  • SHReleaseThreadRef (Ordinal: 78, Address: 0x2c060)
  • SHSetThreadRef (Ordinal: 79, Address: 0x2bf90)
  • SHSetValueA (Ordinal: 80, Address: 0x57a80)
  • SHSetValueW (Ordinal: 81, Address: 0x31350)
  • SHStrDupA (Ordinal: 82, Address: 0x39f30)
  • SHStrDupW (Ordinal: 83, Address: 0x150e0)
  • SHTaskPoolAllowThreadReuse (Ordinal: 84, Address: 0x2efd0)
  • SHTaskPoolDoNotWaitForMoreTasks (Ordinal: 85, Address: 0x573a0)
  • SHTaskPoolGetCurrentThreadLifetime (Ordinal: 86, Address: 0x18e80)
  • SHTaskPoolGetUniqueContext (Ordinal: 87, Address: 0x33c00)
  • SHTaskPoolQueueTask (Ordinal: 88, Address: 0x15a10)
  • SHTaskPoolSetThreadReuseAllowed (Ordinal: 89, Address: 0x573b0)
  • SHUnicodeToAnsi (Ordinal: 90, Address: 0x306c0)
  • SHUnicodeToUnicode (Ordinal: 91, Address: 0x73bc0)
  • SetCurrentProcessExplicitAppUserModelID (Ordinal: 92, Address: 0x20f40)
  • SetProcessDpiAwareness (Ordinal: 93, Address: 0x38c70)
  • SetProcessReference (Ordinal: 94, Address: 0x37d70)
  • SubscribeFeatureStateChangeNotification (Ordinal: 95, Address: 0x38c60)
  • UnregisterScaleChangeEvent (Ordinal: 96, Address: 0x38ca0)
  • UnsubscribeFeatureStateChangeNotification (Ordinal: 97, Address: 0x1df60)
  • (Ordinal: 100, Address: 0x141d0)
  • (Ordinal: 101, Address: 0xfa40)
  • (Ordinal: 102, Address: 0x37110)
  • (Ordinal: 103, Address: 0x2ad0)
  • (Ordinal: 104, Address: 0x13f70)
  • (Ordinal: 105, Address: 0x28830)
  • (Ordinal: 106, Address: 0x27690)
  • (Ordinal: 107, Address: 0x69780)
  • (Ordinal: 108, Address: 0x697f0)
  • (Ordinal: 109, Address: 0x2d3b0)
  • (Ordinal: 110, Address: 0x2d1b0)
  • (Ordinal: 111, Address: 0x695d0)
  • (Ordinal: 115, Address: 0x320e0)
  • (Ordinal: 116, Address: 0x6cb50)
  • (Ordinal: 117, Address: 0x64630)
  • (Ordinal: 120, Address: 0x14020)
  • (Ordinal: 121, Address: 0x37e10)
  • SHRegGetValueFromHKCUHKLM (Ordinal: 122, Address: 0x1a910)
  • (Ordinal: 123, Address: 0x1c2b0)
  • (Ordinal: 124, Address: 0x584e0)
  • (Ordinal: 125, Address: 0x58520)
  • (Ordinal: 126, Address: 0x1d520)
  • (Ordinal: 127, Address: 0x11270)
  • (Ordinal: 130, Address: 0x1a710)
  • (Ordinal: 131, Address: 0x37c90)
  • (Ordinal: 132, Address: 0x573d0)
  • (Ordinal: 133, Address: 0x57410)
  • (Ordinal: 140, Address: 0x1f850)
  • (Ordinal: 141, Address: 0x25380)
  • (Ordinal: 142, Address: 0x1dae0)
  • (Ordinal: 143, Address: 0x25b40)
  • (Ordinal: 144, Address: 0x2ed10)
  • (Ordinal: 145, Address: 0x21530)
  • (Ordinal: 150, Address: 0x737f0)
  • (Ordinal: 151, Address: 0x306e0)
  • (Ordinal: 152, Address: 0x73a90)
  • (Ordinal: 153, Address: 0x73970)
  • (Ordinal: 160, Address: 0x73770)
  • (Ordinal: 161, Address: 0x26300)
  • (Ordinal: 162, Address: 0x30080)
  • (Ordinal: 170, Address: 0x255c0)
  • (Ordinal: 171, Address: 0x57510)
  • (Ordinal: 172, Address: 0x2bb30)
  • (Ordinal: 173, Address: 0x25b80)
  • (Ordinal: 174, Address: 0x267c0)
  • (Ordinal: 175, Address: 0x57440)
  • (Ordinal: 181, Address: 0xef30)
  • (Ordinal: 182, Address: 0xb980)
  • (Ordinal: 183, Address: 0xd450)
  • (Ordinal: 184, Address: 0x38e30)
  • (Ordinal: 185, Address: 0x73de0)
  • (Ordinal: 186, Address: 0x30680)
  • (Ordinal: 187, Address: 0x2f530)
  • (Ordinal: 188, Address: 0x310b0)
  • (Ordinal: 189, Address: 0x2f3b0)
  • (Ordinal: 190, Address: 0x12710)
  • (Ordinal: 191, Address: 0x36520)
  • (Ordinal: 192, Address: 0x1cfc0)
  • (Ordinal: 193, Address: 0x1b1e0)
  • (Ordinal: 200, Address: 0x1e400)
  • (Ordinal: 210, Address: 0x1dfe0)
  • (Ordinal: 211, Address: 0x253f0)
  • (Ordinal: 212, Address: 0x73df0)
  • (Ordinal: 213, Address: 0x25680)
  • (Ordinal: 220, Address: 0x591e0)
  • (Ordinal: 222, Address: 0x325f0)
  • (Ordinal: 223, Address: 0x594c0)
  • (Ordinal: 224, Address: 0x59950)
  • (Ordinal: 225, Address: 0x59180)
  • (Ordinal: 226, Address: 0x59350)
  • (Ordinal: 227, Address: 0x595f0)
  • (Ordinal: 228, Address: 0x599a0)
  • (Ordinal: 229, Address: 0x59290)
  • (Ordinal: 230, Address: 0x3100)
  • (Ordinal: 231, Address: 0x72ab0)
  • (Ordinal: 232, Address: 0x72be0)
  • (Ordinal: 233, Address: 0x34c0)
  • (Ordinal: 234, Address: 0x31270)
  • (Ordinal: 240, Address: 0x32060)
  • (Ordinal: 241, Address: 0x598f0)
  • (Ordinal: 242, Address: 0x596b0)
  • (Ordinal: 244, Address: 0x123b0)
  • (Ordinal: 245, Address: 0x31fa0)
  • (Ordinal: 246, Address: 0x34eb0)
  • (Ordinal: 247, Address: 0x32440)
  • (Ordinal: 248, Address: 0x1d8c0)
  • (Ordinal: 249, Address: 0x5a560)
  • (Ordinal: 250, Address: 0x7f30)
  • (Ordinal: 251, Address: 0x6cb0)
  • (Ordinal: 252, Address: 0x743a0)
  • (Ordinal: 253, Address: 0x74840)
  • (Ordinal: 254, Address: 0x7040)
  • (Ordinal: 255, Address: 0x19460)
  • (Ordinal: 260, Address: 0x593a0)
  • (Ordinal: 261, Address: 0x59720)
  • (Ordinal: 270, Address: 0x2b640)
  • (Ordinal: 280, Address: 0x2b050)
  • (Ordinal: 281, Address: 0x2b210)
  • (Ordinal: 282, Address: 0x74990)
  • (Ordinal: 283, Address: 0x748e0)
  • (Ordinal: 284, Address: 0x2b270)
  • (Ordinal: 290, Address: 0x2b030)
  • (Ordinal: 291, Address: 0x74910)
  • (Ordinal: 292, Address: 0x2b010)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180082e70)
api-ms-win-core-atoms-l1-1-0.dll
  • GlobalAddAtomExW (Address: 0x180082e80)
  • GlobalDeleteAtom (Address: 0x180082e90)
  • GlobalGetAtomNameW (Address: 0x180082e88)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180082ea8)
  • IsDebuggerPresent (Address: 0x180082ea0)
  • OutputDebugStringW (Address: 0x180082eb0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180082ec0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180082ed0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180082ee8)
  • RaiseException (Address: 0x180082ee0)
  • SetLastError (Address: 0x180082ef8)
  • SetUnhandledExceptionFilter (Address: 0x180082f00)
  • UnhandledExceptionFilter (Address: 0x180082ef0)
api-ms-win-core-errorhandling-l1-1-2.dll
  • RaiseFailFastException (Address: 0x180082f10)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x180082f40)
  • CreateFileW (Address: 0x180082f90)
  • DeleteFileW (Address: 0x180082f58)
  • FlushFileBuffers (Address: 0x180082f20)
  • GetDriveTypeW (Address: 0x180082f50)
  • GetFileAttributesExW (Address: 0x180082fa8)
  • GetFileAttributesW (Address: 0x180082f68)
  • GetFileInformationByHandle (Address: 0x180082f88)
  • GetFileSizeEx (Address: 0x180082fa0)
  • GetVolumeInformationByHandleW (Address: 0x180082f30)
  • LockFileEx (Address: 0x180082f38)
  • ReadFile (Address: 0x180082f28)
  • SetEndOfFile (Address: 0x180082f78)
  • SetFileInformationByHandle (Address: 0x180082f98)
  • SetFilePointer (Address: 0x180082f80)
  • SetFilePointerEx (Address: 0x180082f48)
  • UnlockFileEx (Address: 0x180082f70)
  • WriteFile (Address: 0x180082f60)
api-ms-win-core-file-l1-2-0.dll
  • CreateFile2 (Address: 0x180082fb8)
api-ms-win-core-file-l2-1-0.dll
  • GetFileInformationByHandleEx (Address: 0x180082fd0)
  • ReplaceFileW (Address: 0x180082fc8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180082fe8)
  • DuplicateHandle (Address: 0x180082fe0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180083008)
  • HeapAlloc (Address: 0x180082ff8)
  • HeapFree (Address: 0x180083000)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180083020)
  • LocalFree (Address: 0x180083018)
  • LocalReAlloc (Address: 0x180083028)
api-ms-win-core-io-l1-1-0.dll
  • CancelIoEx (Address: 0x180083048)
  • DeviceIoControl (Address: 0x180083038)
  • GetOverlappedResult (Address: 0x180083040)
api-ms-win-core-largeinteger-l1-1-0.dll
  • MulDiv (Address: 0x180083058)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180083078)
  • FindResourceExW (Address: 0x1800830b0)
  • FreeLibrary (Address: 0x1800830b8)
  • FreeLibraryAndExitThread (Address: 0x180083098)
  • GetModuleFileNameA (Address: 0x1800830c8)
  • GetModuleFileNameW (Address: 0x1800830c0)
  • GetModuleHandleExW (Address: 0x180083090)
  • GetModuleHandleW (Address: 0x1800830a0)
  • GetProcAddress (Address: 0x180083070)
  • LoadLibraryExW (Address: 0x180083088)
  • LoadResource (Address: 0x180083080)
  • LockResource (Address: 0x1800830a8)
  • SizeofResource (Address: 0x180083068)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800830e0)
  • GetLocaleInfoW (Address: 0x1800830d8)
api-ms-win-core-localization-obsolete-l1-2-0.dll
  • GetUserDefaultUILanguage (Address: 0x1800830f0)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x180083100)
  • MapViewOfFile (Address: 0x180083118)
  • OpenFileMappingW (Address: 0x180083110)
  • UnmapViewOfFile (Address: 0x180083108)
api-ms-win-core-path-l1-1-0.dll
  • PathCchAddBackslashEx (Address: 0x180083128)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsA (Address: 0x180083138)
  • ExpandEnvironmentStringsW (Address: 0x180083140)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x180083178)
  • GetCurrentProcess (Address: 0x1800831c8)
  • GetCurrentProcessId (Address: 0x1800831a0)
  • GetCurrentThread (Address: 0x180083168)
  • GetCurrentThreadId (Address: 0x180083188)
  • GetProcessId (Address: 0x180083170)
  • GetStartupInfoW (Address: 0x1800831b0)
  • GetThreadPriority (Address: 0x1800831a8)
  • OpenProcessToken (Address: 0x1800831d0)
  • OpenThreadToken (Address: 0x180083160)
  • ResumeThread (Address: 0x180083150)
  • SetThreadPriority (Address: 0x1800831b8)
  • TerminateProcess (Address: 0x180083180)
  • TlsAlloc (Address: 0x180083158)
  • TlsFree (Address: 0x1800831c0)
  • TlsGetValue (Address: 0x180083198)
  • TlsSetValue (Address: 0x180083190)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x1800831e0)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800831f0)
api-ms-win-core-quirks-l1-1-0.dll
  • QuirkIsEnabled (Address: 0x180083200)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180083270)
  • RegCreateKeyExA (Address: 0x1800832a0)
  • RegCreateKeyExW (Address: 0x180083248)
  • RegDeleteKeyExA (Address: 0x1800832a8)
  • RegDeleteKeyExW (Address: 0x180083218)
  • RegDeleteValueA (Address: 0x180083220)
  • RegDeleteValueW (Address: 0x180083250)
  • RegEnumKeyExA (Address: 0x180083258)
  • RegEnumKeyExW (Address: 0x180083240)
  • RegEnumValueA (Address: 0x180083260)
  • RegEnumValueW (Address: 0x180083228)
  • RegGetValueW (Address: 0x180083230)
  • RegOpenKeyExA (Address: 0x180083288)
  • RegOpenKeyExW (Address: 0x180083290)
  • RegQueryInfoKeyA (Address: 0x180083238)
  • RegQueryInfoKeyW (Address: 0x180083210)
  • RegQueryValueExA (Address: 0x180083268)
  • RegQueryValueExW (Address: 0x180083280)
  • RegSetValueExA (Address: 0x180083298)
  • RegSetValueExW (Address: 0x180083278)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800832c8)
  • RtlLookupFunctionEntry (Address: 0x1800832c0)
  • RtlVirtualUnwind (Address: 0x1800832b8)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathCombineW (Address: 0x1800832f8)
  • PathFileExistsW (Address: 0x1800832d8)
  • PathFindExtensionW (Address: 0x180083310)
  • PathFindFileNameW (Address: 0x180083308)
  • PathGetDriveNumberW (Address: 0x180083320)
  • PathIsRelativeW (Address: 0x1800832e8)
  • PathIsUNCW (Address: 0x180083318)
  • PathRemoveFileSpecW (Address: 0x1800832f0)
  • PathUnExpandEnvStringsA (Address: 0x1800832e0)
  • PathUnExpandEnvStringsW (Address: 0x180083300)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • QISearch (Address: 0x180083340)
  • StrChrW (Address: 0x180083348)
  • StrCmpICW (Address: 0x180083350)
  • StrCmpNICW (Address: 0x180083360)
  • StrCmpNIW (Address: 0x180083330)
  • StrDupA (Address: 0x180083368)
  • StrDupW (Address: 0x180083358)
  • StrToIntW (Address: 0x180083338)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x180083378)
  • WideCharToMultiByte (Address: 0x180083380)
api-ms-win-core-string-l2-1-1.dll
  • SHLoadIndirectString (Address: 0x180083390)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x1800833a8)
  • lstrcmpW (Address: 0x1800833a0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800833d0)
  • AcquireSRWLockShared (Address: 0x180083400)
  • CreateEventExW (Address: 0x1800833c0)
  • CreateEventW (Address: 0x180083420)
  • CreateMutexExW (Address: 0x1800833f0)
  • CreateMutexW (Address: 0x180083458)
  • CreateSemaphoreExW (Address: 0x180083440)
  • DeleteCriticalSection (Address: 0x1800833f8)
  • EnterCriticalSection (Address: 0x180083448)
  • InitializeCriticalSection (Address: 0x180083460)
  • InitializeCriticalSectionEx (Address: 0x180083428)
  • InitializeSRWLock (Address: 0x180083470)
  • LeaveCriticalSection (Address: 0x180083438)
  • OpenEventW (Address: 0x180083418)
  • OpenSemaphoreW (Address: 0x1800833e0)
  • ReleaseMutex (Address: 0x1800833b8)
  • ReleaseSemaphore (Address: 0x180083430)
  • ReleaseSRWLockExclusive (Address: 0x180083410)
  • ReleaseSRWLockShared (Address: 0x1800833e8)
  • SetEvent (Address: 0x180083408)
  • TryAcquireSRWLockExclusive (Address: 0x180083468)
  • WaitForMultipleObjectsEx (Address: 0x180083450)
  • WaitForSingleObject (Address: 0x1800833c8)
  • WaitForSingleObjectEx (Address: 0x1800833d8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180083498)
  • InitOnceComplete (Address: 0x180083480)
  • InitOnceExecuteOnce (Address: 0x180083490)
  • Sleep (Address: 0x180083488)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1800834c0)
  • GetTickCount (Address: 0x1800834a8)
  • GetTickCount64 (Address: 0x1800834b0)
  • GetVersionExW (Address: 0x1800834b8)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetOsSafeBootMode (Address: 0x1800834d0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CallbackMayRunLong (Address: 0x1800834e0)
  • CloseThreadpoolTimer (Address: 0x1800834e8)
  • CloseThreadpoolWait (Address: 0x180083510)
  • CreateThreadpoolTimer (Address: 0x180083520)
  • CreateThreadpoolWait (Address: 0x180083500)
  • DisassociateCurrentThreadFromCallback (Address: 0x180083518)
  • FreeLibraryWhenCallbackReturns (Address: 0x180083528)
  • SetThreadpoolTimer (Address: 0x1800834f8)
  • SetThreadpoolWait (Address: 0x180083538)
  • TrySubmitThreadpoolCallback (Address: 0x180083530)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800834f0)
  • WaitForThreadpoolWaitCallbacks (Address: 0x180083508)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x180083548)
  • DeleteTimerQueueTimer (Address: 0x180083558)
  • QueueUserWorkItem (Address: 0x180083550)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180083568)
  • EncodePointer (Address: 0x180083570)
api-ms-win-core-version-l1-1-0.dll
  • GetFileVersionInfoExW (Address: 0x180083590)
  • GetFileVersionInfoSizeExW (Address: 0x180083588)
  • VerQueryValueW (Address: 0x180083580)
api-ms-win-core-wow64-l1-1-1.dll
  • Wow64SetThreadDefaultGuestMachine (Address: 0x1800835a0)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x1800835c8)
  • EventRegister (Address: 0x1800835b8)
  • EventSetInformation (Address: 0x1800835d0)
  • EventUnregister (Address: 0x1800835c0)
  • EventWriteTransfer (Address: 0x1800835b0)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x1800835e8)
  • CheckTokenMembership (Address: 0x1800835f8)
  • GetTokenInformation (Address: 0x180083600)
  • ImpersonateLoggedOnUser (Address: 0x1800835f0)
  • RevertToSelf (Address: 0x1800835e0)
combase.dll
  • (Address: 0x180083610)
msvcrt.dll
  • __C_specific_handler (Address: 0x180083670)
  • __CxxFrameHandler3 (Address: 0x180083650)
  • __dllonexit (Address: 0x180083658)
  • _amsg_exit (Address: 0x180083628)
  • _callnewh (Address: 0x180083648)
  • _initterm (Address: 0x1800836b0)
  • _lock (Address: 0x1800836a8)
  • _onexit (Address: 0x180083660)
  • _purecall (Address: 0x180083688)
  • _unlock (Address: 0x180083690)
  • _vsnwprintf (Address: 0x1800836a0)
  • _XcptFilter (Address: 0x180083678)
  • floor (Address: 0x180083620)
  • free (Address: 0x180083680)
  • malloc (Address: 0x180083630)
  • memcmp (Address: 0x180083638)
  • memcpy (Address: 0x180083640)
  • memcpy_s (Address: 0x180083698)
  • memmove (Address: 0x180083668)
  • memset (Address: 0x1800836b8)
ntdll.dll
  • _vsnprintf_s (Address: 0x1800836d0)
  • memmove_s (Address: 0x1800836c8)
  • NtCreateFile (Address: 0x180083730)
  • NtQueryInformationProcess (Address: 0x180083728)
  • NtQuerySystemInformation (Address: 0x180083710)
  • NtQuerySystemInformationEx (Address: 0x180083760)
  • RtlAcquireSRWLockExclusive (Address: 0x180083720)
  • RtlAreLongPathsEnabled (Address: 0x1800836f0)
  • RtlInitUnicodeString (Address: 0x180083738)
  • RtlNtStatusToDosError (Address: 0x180083740)
  • RtlQueryWnfStateData (Address: 0x180083750)
  • RtlReleaseSRWLockExclusive (Address: 0x180083718)
  • RtlSleepConditionVariableSRW (Address: 0x180083708)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x180083758)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x180083748)
  • RtlWakeAllConditionVariable (Address: 0x180083700)
  • toupper (Address: 0x1800836f8)
  • wcschr (Address: 0x1800836e0)
  • wcsncmp (Address: 0x1800836d8)
  • wcsrchr (Address: 0x1800836e8)