SHCore.dll
Description: SHCORE
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 63257882eb0d0d08ccc275287e11e721
File Size: 686.1 KB
Uploaded At: Dec. 1, 2025, 7:39 a.m.
Views: 9
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- (Ordinal: 1, Address: 0xa0a0)
- CommandLineToArgvW (Ordinal: 2, Address: 0x1e030)
- CreateRandomAccessStreamOnFile (Ordinal: 3, Address: 0x30d20)
- CreateRandomAccessStreamOverStream (Ordinal: 4, Address: 0x234b0)
- CreateStreamOverRandomAccessStream (Ordinal: 5, Address: 0x31440)
- DllCanUnloadNow (Ordinal: 6, Address: 0x326e0)
- DllGetActivationFactory (Ordinal: 7, Address: 0x567e0)
- DllGetClassObject (Ordinal: 8, Address: 0x302d0)
- GetCurrentProcessExplicitAppUserModelID (Ordinal: 9, Address: 0x72d50)
- GetDpiForMonitor (Ordinal: 10, Address: 0xb5a0)
- GetDpiForShellUIComponent (Ordinal: 11, Address: 0x30320)
- GetFeatureEnabledState (Ordinal: 12, Address: 0x2b3f0)
- GetFeatureVariant (Ordinal: 13, Address: 0x2b350)
- GetProcessDpiAwareness (Ordinal: 14, Address: 0x37620)
- GetProcessReference (Ordinal: 15, Address: 0x26390)
- GetScaleFactorForDevice (Ordinal: 16, Address: 0x32630)
- GetScaleFactorForMonitor (Ordinal: 17, Address: 0x2fac0)
- IStream_Copy (Ordinal: 18, Address: 0x2070)
- IStream_Read (Ordinal: 19, Address: 0xbd90)
- IStream_ReadStr (Ordinal: 20, Address: 0xb360)
- IStream_Reset (Ordinal: 21, Address: 0xedc0)
- IStream_Size (Ordinal: 22, Address: 0x30bd0)
- IStream_Write (Ordinal: 23, Address: 0x251e0)
- IStream_WriteStr (Ordinal: 24, Address: 0x25260)
- IUnknown_AtomicRelease (Ordinal: 25, Address: 0x568e0)
- IUnknown_GetSite (Ordinal: 26, Address: 0x28080)
- IUnknown_QueryService (Ordinal: 27, Address: 0x1f8f0)
- IUnknown_Set (Ordinal: 28, Address: 0x1f7f0)
- IUnknown_SetSite (Ordinal: 29, Address: 0x28110)
- IsOS (Ordinal: 30, Address: 0x1d1c0)
- IsProcessInIsolatedContainer (Ordinal: 31, Address: 0x31b60)
- IsProcessInWDAGContainer (Ordinal: 32, Address: 0x31a60)
- RecordFeatureError (Ordinal: 33, Address: 0x57210)
- RecordFeatureUsage (Ordinal: 34, Address: 0x19550)
- RegisterScaleChangeEvent (Ordinal: 35, Address: 0x384a0)
- RegisterScaleChangeNotifications (Ordinal: 36, Address: 0x59500)
- RevokeScaleChangeNotifications (Ordinal: 37, Address: 0x59840)
- SHAnsiToAnsi (Ordinal: 38, Address: 0x73790)
- SHAnsiToUnicode (Ordinal: 39, Address: 0x1faa0)
- SHCopyKeyA (Ordinal: 40, Address: 0x58080)
- SHCopyKeyW (Ordinal: 41, Address: 0x58100)
- SHCreateMemStream (Ordinal: 42, Address: 0x107d0)
- SHCreateStreamOnFileA (Ordinal: 43, Address: 0x6a2d0)
- SHCreateStreamOnFileEx (Ordinal: 44, Address: 0x319d0)
- SHCreateStreamOnFileW (Ordinal: 45, Address: 0x2a7d0)
- SHCreateThread (Ordinal: 46, Address: 0x26080)
- SHCreateThreadRef (Ordinal: 47, Address: 0x2bfc0)
- SHCreateThreadWithHandle (Ordinal: 48, Address: 0x26060)
- SHDeleteEmptyKeyA (Ordinal: 49, Address: 0x578e0)
- SHDeleteEmptyKeyW (Ordinal: 50, Address: 0x57b60)
- SHDeleteKeyA (Ordinal: 51, Address: 0x583d0)
- SHDeleteKeyW (Ordinal: 52, Address: 0x38a20)
- SHDeleteValueA (Ordinal: 53, Address: 0x579f0)
- SHDeleteValueW (Ordinal: 54, Address: 0x374e0)
- SHEnumKeyExA (Ordinal: 55, Address: 0x58450)
- SHEnumKeyExW (Ordinal: 56, Address: 0x35d60)
- SHEnumValueA (Ordinal: 57, Address: 0x58490)
- SHEnumValueW (Ordinal: 58, Address: 0x36d00)
- SHGetThreadRef (Ordinal: 59, Address: 0x266e0)
- SHGetValueA (Ordinal: 60, Address: 0x36680)
- SHGetValueW (Ordinal: 61, Address: 0x1b510)
- SHOpenRegStream2A (Ordinal: 62, Address: 0x69890)
- SHOpenRegStream2W (Ordinal: 63, Address: 0x2ca90)
- SHOpenRegStreamA (Ordinal: 64, Address: 0x69990)
- SHOpenRegStreamW (Ordinal: 65, Address: 0x699c0)
- SHQueryInfoKeyA (Ordinal: 66, Address: 0x58560)
- SHQueryInfoKeyW (Ordinal: 67, Address: 0x37d80)
- SHQueryValueExA (Ordinal: 68, Address: 0x585c0)
- SHQueryValueExW (Ordinal: 69, Address: 0x1b4c0)
- SHRegDuplicateHKey (Ordinal: 70, Address: 0x58600)
- SHRegGetIntW (Ordinal: 71, Address: 0x58640)
- SHRegGetPathA (Ordinal: 72, Address: 0x586f0)
- SHRegGetPathW (Ordinal: 73, Address: 0x58730)
- SHRegGetValueA (Ordinal: 74, Address: 0x366c0)
- SHRegGetValueW (Ordinal: 75, Address: 0x1ad60)
- SHRegSetPathA (Ordinal: 76, Address: 0x58770)
- SHRegSetPathW (Ordinal: 77, Address: 0x58820)
- SHReleaseThreadRef (Ordinal: 78, Address: 0x2c060)
- SHSetThreadRef (Ordinal: 79, Address: 0x2bf90)
- SHSetValueA (Ordinal: 80, Address: 0x57a80)
- SHSetValueW (Ordinal: 81, Address: 0x31350)
- SHStrDupA (Ordinal: 82, Address: 0x39f30)
- SHStrDupW (Ordinal: 83, Address: 0x150e0)
- SHTaskPoolAllowThreadReuse (Ordinal: 84, Address: 0x2efd0)
- SHTaskPoolDoNotWaitForMoreTasks (Ordinal: 85, Address: 0x573a0)
- SHTaskPoolGetCurrentThreadLifetime (Ordinal: 86, Address: 0x18e80)
- SHTaskPoolGetUniqueContext (Ordinal: 87, Address: 0x33c00)
- SHTaskPoolQueueTask (Ordinal: 88, Address: 0x15a10)
- SHTaskPoolSetThreadReuseAllowed (Ordinal: 89, Address: 0x573b0)
- SHUnicodeToAnsi (Ordinal: 90, Address: 0x306c0)
- SHUnicodeToUnicode (Ordinal: 91, Address: 0x73bc0)
- SetCurrentProcessExplicitAppUserModelID (Ordinal: 92, Address: 0x20f40)
- SetProcessDpiAwareness (Ordinal: 93, Address: 0x38c70)
- SetProcessReference (Ordinal: 94, Address: 0x37d70)
- SubscribeFeatureStateChangeNotification (Ordinal: 95, Address: 0x38c60)
- UnregisterScaleChangeEvent (Ordinal: 96, Address: 0x38ca0)
- UnsubscribeFeatureStateChangeNotification (Ordinal: 97, Address: 0x1df60)
- (Ordinal: 100, Address: 0x141d0)
- (Ordinal: 101, Address: 0xfa40)
- (Ordinal: 102, Address: 0x37110)
- (Ordinal: 103, Address: 0x2ad0)
- (Ordinal: 104, Address: 0x13f70)
- (Ordinal: 105, Address: 0x28830)
- (Ordinal: 106, Address: 0x27690)
- (Ordinal: 107, Address: 0x69780)
- (Ordinal: 108, Address: 0x697f0)
- (Ordinal: 109, Address: 0x2d3b0)
- (Ordinal: 110, Address: 0x2d1b0)
- (Ordinal: 111, Address: 0x695d0)
- (Ordinal: 115, Address: 0x320e0)
- (Ordinal: 116, Address: 0x6cb50)
- (Ordinal: 117, Address: 0x64630)
- (Ordinal: 120, Address: 0x14020)
- (Ordinal: 121, Address: 0x37e10)
- SHRegGetValueFromHKCUHKLM (Ordinal: 122, Address: 0x1a910)
- (Ordinal: 123, Address: 0x1c2b0)
- (Ordinal: 124, Address: 0x584e0)
- (Ordinal: 125, Address: 0x58520)
- (Ordinal: 126, Address: 0x1d520)
- (Ordinal: 127, Address: 0x11270)
- (Ordinal: 130, Address: 0x1a710)
- (Ordinal: 131, Address: 0x37c90)
- (Ordinal: 132, Address: 0x573d0)
- (Ordinal: 133, Address: 0x57410)
- (Ordinal: 140, Address: 0x1f850)
- (Ordinal: 141, Address: 0x25380)
- (Ordinal: 142, Address: 0x1dae0)
- (Ordinal: 143, Address: 0x25b40)
- (Ordinal: 144, Address: 0x2ed10)
- (Ordinal: 145, Address: 0x21530)
- (Ordinal: 150, Address: 0x737f0)
- (Ordinal: 151, Address: 0x306e0)
- (Ordinal: 152, Address: 0x73a90)
- (Ordinal: 153, Address: 0x73970)
- (Ordinal: 160, Address: 0x73770)
- (Ordinal: 161, Address: 0x26300)
- (Ordinal: 162, Address: 0x30080)
- (Ordinal: 170, Address: 0x255c0)
- (Ordinal: 171, Address: 0x57510)
- (Ordinal: 172, Address: 0x2bb30)
- (Ordinal: 173, Address: 0x25b80)
- (Ordinal: 174, Address: 0x267c0)
- (Ordinal: 175, Address: 0x57440)
- (Ordinal: 181, Address: 0xef30)
- (Ordinal: 182, Address: 0xb980)
- (Ordinal: 183, Address: 0xd450)
- (Ordinal: 184, Address: 0x38e30)
- (Ordinal: 185, Address: 0x73de0)
- (Ordinal: 186, Address: 0x30680)
- (Ordinal: 187, Address: 0x2f530)
- (Ordinal: 188, Address: 0x310b0)
- (Ordinal: 189, Address: 0x2f3b0)
- (Ordinal: 190, Address: 0x12710)
- (Ordinal: 191, Address: 0x36520)
- (Ordinal: 192, Address: 0x1cfc0)
- (Ordinal: 193, Address: 0x1b1e0)
- (Ordinal: 200, Address: 0x1e400)
- (Ordinal: 210, Address: 0x1dfe0)
- (Ordinal: 211, Address: 0x253f0)
- (Ordinal: 212, Address: 0x73df0)
- (Ordinal: 213, Address: 0x25680)
- (Ordinal: 220, Address: 0x591e0)
- (Ordinal: 222, Address: 0x325f0)
- (Ordinal: 223, Address: 0x594c0)
- (Ordinal: 224, Address: 0x59950)
- (Ordinal: 225, Address: 0x59180)
- (Ordinal: 226, Address: 0x59350)
- (Ordinal: 227, Address: 0x595f0)
- (Ordinal: 228, Address: 0x599a0)
- (Ordinal: 229, Address: 0x59290)
- (Ordinal: 230, Address: 0x3100)
- (Ordinal: 231, Address: 0x72ab0)
- (Ordinal: 232, Address: 0x72be0)
- (Ordinal: 233, Address: 0x34c0)
- (Ordinal: 234, Address: 0x31270)
- (Ordinal: 240, Address: 0x32060)
- (Ordinal: 241, Address: 0x598f0)
- (Ordinal: 242, Address: 0x596b0)
- (Ordinal: 244, Address: 0x123b0)
- (Ordinal: 245, Address: 0x31fa0)
- (Ordinal: 246, Address: 0x34eb0)
- (Ordinal: 247, Address: 0x32440)
- (Ordinal: 248, Address: 0x1d8c0)
- (Ordinal: 249, Address: 0x5a560)
- (Ordinal: 250, Address: 0x7f30)
- (Ordinal: 251, Address: 0x6cb0)
- (Ordinal: 252, Address: 0x743a0)
- (Ordinal: 253, Address: 0x74840)
- (Ordinal: 254, Address: 0x7040)
- (Ordinal: 255, Address: 0x19460)
- (Ordinal: 260, Address: 0x593a0)
- (Ordinal: 261, Address: 0x59720)
- (Ordinal: 270, Address: 0x2b640)
- (Ordinal: 280, Address: 0x2b050)
- (Ordinal: 281, Address: 0x2b210)
- (Ordinal: 282, Address: 0x74990)
- (Ordinal: 283, Address: 0x748e0)
- (Ordinal: 284, Address: 0x2b270)
- (Ordinal: 290, Address: 0x2b030)
- (Ordinal: 291, Address: 0x74910)
- (Ordinal: 292, Address: 0x2b010)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180082e70)
api-ms-win-core-atoms-l1-1-0.dll
- GlobalAddAtomExW (Address: 0x180082e80)
- GlobalDeleteAtom (Address: 0x180082e90)
- GlobalGetAtomNameW (Address: 0x180082e88)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180082ea8)
- IsDebuggerPresent (Address: 0x180082ea0)
- OutputDebugStringW (Address: 0x180082eb0)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180082ec0)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180082ed0)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180082ee8)
- RaiseException (Address: 0x180082ee0)
- SetLastError (Address: 0x180082ef8)
- SetUnhandledExceptionFilter (Address: 0x180082f00)
- UnhandledExceptionFilter (Address: 0x180082ef0)
api-ms-win-core-errorhandling-l1-1-2.dll
- RaiseFailFastException (Address: 0x180082f10)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x180082f40)
- CreateFileW (Address: 0x180082f90)
- DeleteFileW (Address: 0x180082f58)
- FlushFileBuffers (Address: 0x180082f20)
- GetDriveTypeW (Address: 0x180082f50)
- GetFileAttributesExW (Address: 0x180082fa8)
- GetFileAttributesW (Address: 0x180082f68)
- GetFileInformationByHandle (Address: 0x180082f88)
- GetFileSizeEx (Address: 0x180082fa0)
- GetVolumeInformationByHandleW (Address: 0x180082f30)
- LockFileEx (Address: 0x180082f38)
- ReadFile (Address: 0x180082f28)
- SetEndOfFile (Address: 0x180082f78)
- SetFileInformationByHandle (Address: 0x180082f98)
- SetFilePointer (Address: 0x180082f80)
- SetFilePointerEx (Address: 0x180082f48)
- UnlockFileEx (Address: 0x180082f70)
- WriteFile (Address: 0x180082f60)
api-ms-win-core-file-l1-2-0.dll
- CreateFile2 (Address: 0x180082fb8)
api-ms-win-core-file-l2-1-0.dll
- GetFileInformationByHandleEx (Address: 0x180082fd0)
- ReplaceFileW (Address: 0x180082fc8)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180082fe8)
- DuplicateHandle (Address: 0x180082fe0)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180083008)
- HeapAlloc (Address: 0x180082ff8)
- HeapFree (Address: 0x180083000)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180083020)
- LocalFree (Address: 0x180083018)
- LocalReAlloc (Address: 0x180083028)
api-ms-win-core-io-l1-1-0.dll
- CancelIoEx (Address: 0x180083048)
- DeviceIoControl (Address: 0x180083038)
- GetOverlappedResult (Address: 0x180083040)
api-ms-win-core-largeinteger-l1-1-0.dll
- MulDiv (Address: 0x180083058)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x180083078)
- FindResourceExW (Address: 0x1800830b0)
- FreeLibrary (Address: 0x1800830b8)
- FreeLibraryAndExitThread (Address: 0x180083098)
- GetModuleFileNameA (Address: 0x1800830c8)
- GetModuleFileNameW (Address: 0x1800830c0)
- GetModuleHandleExW (Address: 0x180083090)
- GetModuleHandleW (Address: 0x1800830a0)
- GetProcAddress (Address: 0x180083070)
- LoadLibraryExW (Address: 0x180083088)
- LoadResource (Address: 0x180083080)
- LockResource (Address: 0x1800830a8)
- SizeofResource (Address: 0x180083068)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800830e0)
- GetLocaleInfoW (Address: 0x1800830d8)
api-ms-win-core-localization-obsolete-l1-2-0.dll
- GetUserDefaultUILanguage (Address: 0x1800830f0)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x180083100)
- MapViewOfFile (Address: 0x180083118)
- OpenFileMappingW (Address: 0x180083110)
- UnmapViewOfFile (Address: 0x180083108)
api-ms-win-core-path-l1-1-0.dll
- PathCchAddBackslashEx (Address: 0x180083128)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsA (Address: 0x180083138)
- ExpandEnvironmentStringsW (Address: 0x180083140)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x180083178)
- GetCurrentProcess (Address: 0x1800831c8)
- GetCurrentProcessId (Address: 0x1800831a0)
- GetCurrentThread (Address: 0x180083168)
- GetCurrentThreadId (Address: 0x180083188)
- GetProcessId (Address: 0x180083170)
- GetStartupInfoW (Address: 0x1800831b0)
- GetThreadPriority (Address: 0x1800831a8)
- OpenProcessToken (Address: 0x1800831d0)
- OpenThreadToken (Address: 0x180083160)
- ResumeThread (Address: 0x180083150)
- SetThreadPriority (Address: 0x1800831b8)
- TerminateProcess (Address: 0x180083180)
- TlsAlloc (Address: 0x180083158)
- TlsFree (Address: 0x1800831c0)
- TlsGetValue (Address: 0x180083198)
- TlsSetValue (Address: 0x180083190)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x1800831e0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800831f0)
api-ms-win-core-quirks-l1-1-0.dll
- QuirkIsEnabled (Address: 0x180083200)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180083270)
- RegCreateKeyExA (Address: 0x1800832a0)
- RegCreateKeyExW (Address: 0x180083248)
- RegDeleteKeyExA (Address: 0x1800832a8)
- RegDeleteKeyExW (Address: 0x180083218)
- RegDeleteValueA (Address: 0x180083220)
- RegDeleteValueW (Address: 0x180083250)
- RegEnumKeyExA (Address: 0x180083258)
- RegEnumKeyExW (Address: 0x180083240)
- RegEnumValueA (Address: 0x180083260)
- RegEnumValueW (Address: 0x180083228)
- RegGetValueW (Address: 0x180083230)
- RegOpenKeyExA (Address: 0x180083288)
- RegOpenKeyExW (Address: 0x180083290)
- RegQueryInfoKeyA (Address: 0x180083238)
- RegQueryInfoKeyW (Address: 0x180083210)
- RegQueryValueExA (Address: 0x180083268)
- RegQueryValueExW (Address: 0x180083280)
- RegSetValueExA (Address: 0x180083298)
- RegSetValueExW (Address: 0x180083278)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800832c8)
- RtlLookupFunctionEntry (Address: 0x1800832c0)
- RtlVirtualUnwind (Address: 0x1800832b8)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathCombineW (Address: 0x1800832f8)
- PathFileExistsW (Address: 0x1800832d8)
- PathFindExtensionW (Address: 0x180083310)
- PathFindFileNameW (Address: 0x180083308)
- PathGetDriveNumberW (Address: 0x180083320)
- PathIsRelativeW (Address: 0x1800832e8)
- PathIsUNCW (Address: 0x180083318)
- PathRemoveFileSpecW (Address: 0x1800832f0)
- PathUnExpandEnvStringsA (Address: 0x1800832e0)
- PathUnExpandEnvStringsW (Address: 0x180083300)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- QISearch (Address: 0x180083340)
- StrChrW (Address: 0x180083348)
- StrCmpICW (Address: 0x180083350)
- StrCmpNICW (Address: 0x180083360)
- StrCmpNIW (Address: 0x180083330)
- StrDupA (Address: 0x180083368)
- StrDupW (Address: 0x180083358)
- StrToIntW (Address: 0x180083338)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x180083378)
- WideCharToMultiByte (Address: 0x180083380)
api-ms-win-core-string-l2-1-1.dll
- SHLoadIndirectString (Address: 0x180083390)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x1800833a8)
- lstrcmpW (Address: 0x1800833a0)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800833d0)
- AcquireSRWLockShared (Address: 0x180083400)
- CreateEventExW (Address: 0x1800833c0)
- CreateEventW (Address: 0x180083420)
- CreateMutexExW (Address: 0x1800833f0)
- CreateMutexW (Address: 0x180083458)
- CreateSemaphoreExW (Address: 0x180083440)
- DeleteCriticalSection (Address: 0x1800833f8)
- EnterCriticalSection (Address: 0x180083448)
- InitializeCriticalSection (Address: 0x180083460)
- InitializeCriticalSectionEx (Address: 0x180083428)
- InitializeSRWLock (Address: 0x180083470)
- LeaveCriticalSection (Address: 0x180083438)
- OpenEventW (Address: 0x180083418)
- OpenSemaphoreW (Address: 0x1800833e0)
- ReleaseMutex (Address: 0x1800833b8)
- ReleaseSemaphore (Address: 0x180083430)
- ReleaseSRWLockExclusive (Address: 0x180083410)
- ReleaseSRWLockShared (Address: 0x1800833e8)
- SetEvent (Address: 0x180083408)
- TryAcquireSRWLockExclusive (Address: 0x180083468)
- WaitForMultipleObjectsEx (Address: 0x180083450)
- WaitForSingleObject (Address: 0x1800833c8)
- WaitForSingleObjectEx (Address: 0x1800833d8)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x180083498)
- InitOnceComplete (Address: 0x180083480)
- InitOnceExecuteOnce (Address: 0x180083490)
- Sleep (Address: 0x180083488)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1800834c0)
- GetTickCount (Address: 0x1800834a8)
- GetTickCount64 (Address: 0x1800834b0)
- GetVersionExW (Address: 0x1800834b8)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetOsSafeBootMode (Address: 0x1800834d0)
api-ms-win-core-threadpool-l1-2-0.dll
- CallbackMayRunLong (Address: 0x1800834e0)
- CloseThreadpoolTimer (Address: 0x1800834e8)
- CloseThreadpoolWait (Address: 0x180083510)
- CreateThreadpoolTimer (Address: 0x180083520)
- CreateThreadpoolWait (Address: 0x180083500)
- DisassociateCurrentThreadFromCallback (Address: 0x180083518)
- FreeLibraryWhenCallbackReturns (Address: 0x180083528)
- SetThreadpoolTimer (Address: 0x1800834f8)
- SetThreadpoolWait (Address: 0x180083538)
- TrySubmitThreadpoolCallback (Address: 0x180083530)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800834f0)
- WaitForThreadpoolWaitCallbacks (Address: 0x180083508)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueueTimer (Address: 0x180083548)
- DeleteTimerQueueTimer (Address: 0x180083558)
- QueueUserWorkItem (Address: 0x180083550)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x180083568)
- EncodePointer (Address: 0x180083570)
api-ms-win-core-version-l1-1-0.dll
- GetFileVersionInfoExW (Address: 0x180083590)
- GetFileVersionInfoSizeExW (Address: 0x180083588)
- VerQueryValueW (Address: 0x180083580)
api-ms-win-core-wow64-l1-1-1.dll
- Wow64SetThreadDefaultGuestMachine (Address: 0x1800835a0)
api-ms-win-eventing-provider-l1-1-0.dll
- EventProviderEnabled (Address: 0x1800835c8)
- EventRegister (Address: 0x1800835b8)
- EventSetInformation (Address: 0x1800835d0)
- EventUnregister (Address: 0x1800835c0)
- EventWriteTransfer (Address: 0x1800835b0)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x1800835e8)
- CheckTokenMembership (Address: 0x1800835f8)
- GetTokenInformation (Address: 0x180083600)
- ImpersonateLoggedOnUser (Address: 0x1800835f0)
- RevertToSelf (Address: 0x1800835e0)
combase.dll
- (Address: 0x180083610)
msvcrt.dll
- __C_specific_handler (Address: 0x180083670)
- __CxxFrameHandler3 (Address: 0x180083650)
- __dllonexit (Address: 0x180083658)
- _amsg_exit (Address: 0x180083628)
- _callnewh (Address: 0x180083648)
- _initterm (Address: 0x1800836b0)
- _lock (Address: 0x1800836a8)
- _onexit (Address: 0x180083660)
- _purecall (Address: 0x180083688)
- _unlock (Address: 0x180083690)
- _vsnwprintf (Address: 0x1800836a0)
- _XcptFilter (Address: 0x180083678)
- floor (Address: 0x180083620)
- free (Address: 0x180083680)
- malloc (Address: 0x180083630)
- memcmp (Address: 0x180083638)
- memcpy (Address: 0x180083640)
- memcpy_s (Address: 0x180083698)
- memmove (Address: 0x180083668)
- memset (Address: 0x1800836b8)
ntdll.dll
- _vsnprintf_s (Address: 0x1800836d0)
- memmove_s (Address: 0x1800836c8)
- NtCreateFile (Address: 0x180083730)
- NtQueryInformationProcess (Address: 0x180083728)
- NtQuerySystemInformation (Address: 0x180083710)
- NtQuerySystemInformationEx (Address: 0x180083760)
- RtlAcquireSRWLockExclusive (Address: 0x180083720)
- RtlAreLongPathsEnabled (Address: 0x1800836f0)
- RtlInitUnicodeString (Address: 0x180083738)
- RtlNtStatusToDosError (Address: 0x180083740)
- RtlQueryWnfStateData (Address: 0x180083750)
- RtlReleaseSRWLockExclusive (Address: 0x180083718)
- RtlSleepConditionVariableSRW (Address: 0x180083708)
- RtlSubscribeWnfStateChangeNotification (Address: 0x180083758)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x180083748)
- RtlWakeAllConditionVariable (Address: 0x180083700)
- toupper (Address: 0x1800836f8)
- wcschr (Address: 0x1800836e0)
- wcsncmp (Address: 0x1800836d8)
- wcsrchr (Address: 0x1800836e8)