sppnp.dll

Description: PnP module of SysPrep

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 3bc8b60a3f474904607321b9f30a0033

File Size: 269.5 KB

Uploaded At: Dec. 1, 2025, 7:39 a.m.

Views: 4

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • Sysprep_Generalize_Pnp (Ordinal: 1, Address: 0xb250)
  • Sysprep_Generalize_Pnp_Drivers (Ordinal: 2, Address: 0xb9b0)
  • Sysprep_Respecialize_Pnp (Ordinal: 3, Address: 0xbc10)
  • Sysprep_RunDll_PnpW (Ordinal: 4, Address: 0x16040)
  • Sysprep_Specialize_Offline_Pnp (Ordinal: 5, Address: 0x59d0)
  • Sysprep_Specialize_Pnp (Ordinal: 6, Address: 0x6a80)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x18002faf0)
  • CoInitializeEx (Address: 0x18002fae8)
  • CoUninitialize (Address: 0x18002faf8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18002fb08)
  • RaiseException (Address: 0x18002fb20)
  • SetErrorMode (Address: 0x18002fb28)
  • SetLastError (Address: 0x18002fb30)
  • SetUnhandledExceptionFilter (Address: 0x18002fb18)
  • UnhandledExceptionFilter (Address: 0x18002fb10)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18002fbb0)
  • CreateDirectoryW (Address: 0x18002fbc0)
  • CreateFileW (Address: 0x18002fb48)
  • DeleteFileW (Address: 0x18002fb90)
  • FileTimeToLocalFileTime (Address: 0x18002fb80)
  • FindClose (Address: 0x18002fbb8)
  • FindFirstFileW (Address: 0x18002fba8)
  • FindNextFileW (Address: 0x18002fba0)
  • FlushFileBuffers (Address: 0x18002fb68)
  • GetFileAttributesW (Address: 0x18002fb98)
  • GetFileInformationByHandle (Address: 0x18002fb58)
  • GetFileSize (Address: 0x18002fb70)
  • GetFullPathNameW (Address: 0x18002fb88)
  • SetEndOfFile (Address: 0x18002fb40)
  • SetFileAttributesW (Address: 0x18002fb50)
  • SetFilePointer (Address: 0x18002fb60)
  • WriteFile (Address: 0x18002fb78)
api-ms-win-core-file-l2-1-0.dll
  • CreateHardLinkW (Address: 0x18002fbd8)
  • MoveFileExW (Address: 0x18002fbd0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18002fbe8)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18002fc10)
  • HeapAlloc (Address: 0x18002fbf8)
  • HeapFree (Address: 0x18002fc08)
  • HeapReAlloc (Address: 0x18002fc00)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x18002fc20)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • FindResourceW (Address: 0x18002fc38)
  • LoadLibraryW (Address: 0x18002fc40)
  • MulDiv (Address: 0x18002fc30)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x18002fc68)
  • GetModuleFileNameA (Address: 0x18002fc80)
  • GetModuleFileNameW (Address: 0x18002fc78)
  • GetModuleHandleExW (Address: 0x18002fc58)
  • GetModuleHandleW (Address: 0x18002fc70)
  • GetProcAddress (Address: 0x18002fc60)
  • LoadLibraryExW (Address: 0x18002fc88)
  • LoadResource (Address: 0x18002fc50)
  • LockResource (Address: 0x18002fc98)
  • SizeofResource (Address: 0x18002fc90)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18002fcb0)
  • GetLocaleInfoEx (Address: 0x18002fca8)
  • GetLocaleInfoW (Address: 0x18002fcc0)
  • GetThreadLocale (Address: 0x18002fcc8)
  • LCMapStringW (Address: 0x18002fcb8)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x18002fce8)
  • MapViewOfFile (Address: 0x18002fcd8)
  • UnmapViewOfFile (Address: 0x18002fce0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18002fd08)
  • GetCommandLineA (Address: 0x18002fcf8)
  • GetEnvironmentVariableW (Address: 0x18002fd00)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x18002fd50)
  • CreateThread (Address: 0x18002fd60)
  • ExitProcess (Address: 0x18002fd70)
  • GetCurrentProcess (Address: 0x18002fd28)
  • GetCurrentProcessId (Address: 0x18002fd80)
  • GetCurrentThread (Address: 0x18002fd20)
  • GetCurrentThreadId (Address: 0x18002fd78)
  • GetExitCodeProcess (Address: 0x18002fd48)
  • GetExitCodeThread (Address: 0x18002fd58)
  • OpenProcessToken (Address: 0x18002fd30)
  • OpenThreadToken (Address: 0x18002fd38)
  • QueueUserAPC (Address: 0x18002fd68)
  • SetThreadToken (Address: 0x18002fd40)
  • TerminateProcess (Address: 0x18002fd18)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18002fd90)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18002fda0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18002fe00)
  • RegCreateKeyExW (Address: 0x18002fdc8)
  • RegDeleteKeyExW (Address: 0x18002fde8)
  • RegDeleteTreeW (Address: 0x18002fdd0)
  • RegDeleteValueW (Address: 0x18002fdb8)
  • RegEnumKeyExW (Address: 0x18002fdd8)
  • RegLoadKeyW (Address: 0x18002fdf8)
  • RegNotifyChangeKeyValue (Address: 0x18002fe08)
  • RegOpenKeyExW (Address: 0x18002fdc0)
  • RegQueryValueExW (Address: 0x18002fde0)
  • RegSetValueExW (Address: 0x18002fdf0)
  • RegUnLoadKeyW (Address: 0x18002fdb0)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x18002fe20)
  • CompareStringW (Address: 0x18002fe18)
  • WideCharToMultiByte (Address: 0x18002fe28)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18002fea8)
  • CreateEventW (Address: 0x18002fe88)
  • CreateMutexW (Address: 0x18002fe48)
  • DeleteCriticalSection (Address: 0x18002fe60)
  • EnterCriticalSection (Address: 0x18002fe50)
  • InitializeCriticalSection (Address: 0x18002fe58)
  • LeaveCriticalSection (Address: 0x18002fe98)
  • OpenEventW (Address: 0x18002fe80)
  • ReleaseMutex (Address: 0x18002fe40)
  • ReleaseSRWLockExclusive (Address: 0x18002fea0)
  • ResetEvent (Address: 0x18002fe68)
  • SetEvent (Address: 0x18002fe78)
  • SleepEx (Address: 0x18002feb0)
  • WaitForMultipleObjectsEx (Address: 0x18002fe38)
  • WaitForSingleObject (Address: 0x18002fe90)
  • WaitForSingleObjectEx (Address: 0x18002fe70)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18002fed0)
  • SleepConditionVariableSRW (Address: 0x18002fec0)
  • WakeAllConditionVariable (Address: 0x18002fec8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x18002ff08)
  • GetSystemTimeAsFileTime (Address: 0x18002fef8)
  • GetSystemWindowsDirectoryW (Address: 0x18002fee0)
  • GetTickCount (Address: 0x18002fef0)
  • GetTickCount64 (Address: 0x18002fee8)
  • GetVersionExW (Address: 0x18002ff00)
api-ms-win-devices-query-l1-1-0.dll
  • DevFreeObjects (Address: 0x18002ff18)
  • DevGetObjects (Address: 0x18002ff20)
  • DevSetObjectProperties (Address: 0x18002ff28)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x18002ff40)
  • GetTraceEnableLevel (Address: 0x18002ff48)
  • GetTraceLoggerHandle (Address: 0x18002ff38)
  • RegisterTraceGuidsW (Address: 0x18002ff50)
  • TraceEvent (Address: 0x18002ff60)
  • UnregisterTraceGuids (Address: 0x18002ff58)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x18002ff78)
  • EventUnregister (Address: 0x18002ff80)
  • EventWriteTransfer (Address: 0x18002ff70)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x18002ff98)
  • DuplicateTokenEx (Address: 0x18002ffc8)
  • EqualSid (Address: 0x18002ff90)
  • GetKernelObjectSecurity (Address: 0x18002ffc0)
  • GetSecurityDescriptorDacl (Address: 0x18002ffb8)
  • GetSecurityDescriptorGroup (Address: 0x18002ffa0)
  • GetSecurityDescriptorOwner (Address: 0x18002ffa8)
  • GetSecurityDescriptorSacl (Address: 0x18002ffd0)
  • IsValidSecurityDescriptor (Address: 0x18002ffb0)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x18002ffe0)
api-ms-win-security-provider-l1-1-0.dll
  • GetNamedSecurityInfoW (Address: 0x18002fff8)
  • SetNamedSecurityInfoW (Address: 0x18002fff0)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180030010)
  • ConvertStringSidToSidW (Address: 0x180030008)
api-ms-win-service-core-l1-1-2.dll
  • GetServiceKeyNameW (Address: 0x180030020)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x180030048)
  • OpenSCManagerW (Address: 0x180030030)
  • OpenServiceW (Address: 0x180030038)
  • StartServiceW (Address: 0x180030040)
api-ms-win-service-winsvc-l1-1-0.dll
  • QueryServiceStatus (Address: 0x180030058)
CFGMGR32.dll
  • CM_Get_DevNode_Status (Address: 0x18002f700)
  • CM_MapCrToWin32Err (Address: 0x18002f718)
  • CM_Reenumerate_DevNode (Address: 0x18002f720)
  • CMP_GetServerSideDeviceInstallFlags (Address: 0x18002f708)
  • CMP_WaitNoPendingInstallEvents (Address: 0x18002f710)
drvstore.dll
  • DriverPackageClose (Address: 0x180030088)
  • DriverPackageGetVersionInfoW (Address: 0x180030070)
  • DriverPackageOpenW (Address: 0x180030090)
  • DriverStoreClose (Address: 0x1800300c0)
  • DriverStoreEnumDeviceDriversW (Address: 0x1800300a0)
  • DriverStoreEnumW (Address: 0x180030098)
  • DriverStoreFindW (Address: 0x180030080)
  • DriverStoreGetObjectPropertyW (Address: 0x1800300b8)
  • DriverStoreOpenW (Address: 0x1800300a8)
  • DriverStoreReflectCriticalW (Address: 0x180030068)
  • DriverStoreSetLogContext (Address: 0x180030078)
  • DriverStoreSetObjectPropertyW (Address: 0x1800300b0)
GDI32.dll
  • AddFontMemResourceEx (Address: 0x18002f7e8)
  • BitBlt (Address: 0x18002f758)
  • CreateCompatibleBitmap (Address: 0x18002f760)
  • CreateCompatibleDC (Address: 0x18002f770)
  • CreateDIBitmap (Address: 0x18002f7f0)
  • CreateFontIndirectW (Address: 0x18002f7d8)
  • CreateSolidBrush (Address: 0x18002f7d0)
  • DeleteDC (Address: 0x18002f818)
  • DeleteObject (Address: 0x18002f7c8)
  • GdiAlphaBlend (Address: 0x18002f7e0)
  • GetDeviceCaps (Address: 0x18002f788)
  • GetObjectW (Address: 0x18002f7b0)
  • GetStockObject (Address: 0x18002f780)
  • GetTextAlign (Address: 0x18002f790)
  • GetTextExtentPoint32W (Address: 0x18002f798)
  • GetTextMetricsW (Address: 0x18002f7f8)
  • RemoveFontMemResourceEx (Address: 0x18002f810)
  • SelectObject (Address: 0x18002f768)
  • SetBkColor (Address: 0x18002f7b8)
  • SetBkMode (Address: 0x18002f7a8)
  • SetBrushOrgEx (Address: 0x18002f750)
  • SetGraphicsMode (Address: 0x18002f800)
  • SetLayout (Address: 0x18002f808)
  • SetMapMode (Address: 0x18002f740)
  • SetStretchBltMode (Address: 0x18002f7c0)
  • SetTextAlign (Address: 0x18002f738)
  • SetTextCharacterExtra (Address: 0x18002f820)
  • SetTextColor (Address: 0x18002f7a0)
  • SetWorldTransform (Address: 0x18002f730)
  • StretchBlt (Address: 0x18002f778)
  • TextOutW (Address: 0x18002f748)
KERNEL32.dll
  • FileTimeToSystemTime (Address: 0x18002f858)
  • GetSystemDefaultUILanguage (Address: 0x18002f850)
  • IsDebuggerPresent (Address: 0x18002f830)
  • K32EnumProcesses (Address: 0x18002f848)
  • LocalFree (Address: 0x18002f840)
  • QueryFullProcessImageNameW (Address: 0x18002f838)
msvcrt.dll
  • __C_specific_handler (Address: 0x180030190)
  • __CxxFrameHandler3 (Address: 0x1800300e0)
  • __dllonexit (Address: 0x180030140)
  • _amsg_exit (Address: 0x180030160)
  • _callnewh (Address: 0x180030178)
  • _initterm (Address: 0x180030158)
  • _lock (Address: 0x180030150)
  • _onexit (Address: 0x180030138)
  • _resetstkoflw (Address: 0x180030118)
  • _unlock (Address: 0x180030148)
  • _vsnprintf (Address: 0x180030110)
  • _vsnwprintf (Address: 0x1800300e8)
  • _vsnwprintf_s (Address: 0x1800300d0)
  • _wcsicmp (Address: 0x1800301c0)
  • _wcsnicmp (Address: 0x1800301a0)
  • _XcptFilter (Address: 0x180030168)
  • ?terminate@@YAXXZ (Address: 0x1800300f0)
  • free (Address: 0x180030170)
  • iswalpha (Address: 0x1800301a8)
  • malloc (Address: 0x180030180)
  • memcmp (Address: 0x180030120)
  • memcpy (Address: 0x180030128)
  • memmove (Address: 0x180030130)
  • memset (Address: 0x1800301d0)
  • qsort (Address: 0x1800301b0)
  • swprintf_s (Address: 0x1800300d8)
  • swscanf (Address: 0x180030188)
  • swscanf_s (Address: 0x1800301b8)
  • toupper (Address: 0x180030108)
  • wcschr (Address: 0x180030100)
  • wcscpy_s (Address: 0x1800300f8)
  • wcsncpy_s (Address: 0x1800301c8)
  • wcsrchr (Address: 0x180030198)
newdev.dll
  • DiInstallDevice (Address: 0x1800301e0)
  • DiInstallDriverW (Address: 0x1800301e8)
ntdll.dll
  • DbgPrint (Address: 0x180030208)
  • DbgPrintEx (Address: 0x180030290)
  • NtClose (Address: 0x1800302f0)
  • NtCreateKey (Address: 0x180030298)
  • NtDeleteKey (Address: 0x180030288)
  • NtDeleteValueKey (Address: 0x180030218)
  • NtOpenKey (Address: 0x180030238)
  • NtOpenKeyEx (Address: 0x1800302a0)
  • NtQueryInformationFile (Address: 0x180030278)
  • NtQuerySystemInformation (Address: 0x1800302d8)
  • NtQueryValueKey (Address: 0x180030228)
  • NtQueryWnfStateData (Address: 0x1800302f8)
  • NtSetInformationFile (Address: 0x180030270)
  • NtSetValueKey (Address: 0x180030220)
  • NtUnloadKeyEx (Address: 0x1800302d0)
  • RtlAdjustPrivilege (Address: 0x180030210)
  • RtlAllocateHeap (Address: 0x180030200)
  • RtlCaptureContext (Address: 0x1800302b8)
  • RtlFormatCurrentUserKeyPath (Address: 0x180030248)
  • RtlFreeHeap (Address: 0x1800301f8)
  • RtlFreeUnicodeString (Address: 0x180030240)
  • RtlGetVersion (Address: 0x180030280)
  • RtlInitUnicodeString (Address: 0x1800302c8)
  • RtlInitUnicodeStringEx (Address: 0x1800302e8)
  • RtlLookupFunctionEntry (Address: 0x1800302b0)
  • RtlMultiByteToUnicodeN (Address: 0x180030250)
  • RtlMultiByteToUnicodeSize (Address: 0x180030258)
  • RtlNtStatusToDosError (Address: 0x1800302c0)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x1800302e0)
  • RtlRaiseStatus (Address: 0x180030230)
  • RtlUnicodeToMultiByteN (Address: 0x180030260)
  • RtlUnicodeToMultiByteSize (Address: 0x180030268)
  • RtlVirtualUnwind (Address: 0x1800302a8)
OLEAUT32.dll
  • SysAllocString (Address: 0x18002f868)
  • SysFreeString (Address: 0x18002f870)
SETUPAPI.dll
  • PnpEnumDrpFile (Address: 0x18002f908)
  • PnpRepairWindowsProtectedDriver (Address: 0x18002f910)
  • pSetupFree (Address: 0x18002f930)
  • pSetupInfGetDigitalSignatureInfo (Address: 0x18002f918)
  • pSetupInfIsInbox (Address: 0x18002f928)
  • pSetupInfSetDigitalSignatureInfo (Address: 0x18002f920)
  • SetupDiCallClassInstaller (Address: 0x18002f8d0)
  • SetupDiCreateDeviceInfoList (Address: 0x18002f8f0)
  • SetupDiDestroyDeviceInfoList (Address: 0x18002f958)
  • SetupDiEnumDeviceInfo (Address: 0x18002f8e0)
  • SetupDiGetClassDevsExW (Address: 0x18002f8f8)
  • SetupDiGetClassDevsW (Address: 0x18002f960)
  • SetupDiGetDeviceInfoListDetailW (Address: 0x18002f8d8)
  • SetupDiGetDeviceInstallParamsW (Address: 0x18002f900)
  • SetupDiGetDeviceInstanceIdW (Address: 0x18002f8e8)
  • SetupDiGetDevicePropertyW (Address: 0x18002f8c8)
  • SetupDiGetDeviceRegistryPropertyW (Address: 0x18002f888)
  • SetupDiOpenDeviceInfoW (Address: 0x18002f8a8)
  • SetupDiRemoveDevice (Address: 0x18002f8b8)
  • SetupDiSetDeviceInstallParamsW (Address: 0x18002f8c0)
  • SetupDiSetDeviceRegistryPropertyW (Address: 0x18002f880)
  • SetupGetInfDriverStoreLocationW (Address: 0x18002f8a0)
  • SetupGetInfPublishedNameW (Address: 0x18002f898)
  • SetupGetThreadLogToken (Address: 0x18002f968)
  • SetupSetNonInteractiveMode (Address: 0x18002f948)
  • SetupSetThreadLogToken (Address: 0x18002f950)
  • SetupUninstallOEMInfW (Address: 0x18002f890)
  • SetupVerifyInfFileW (Address: 0x18002f8b0)
  • SetupWriteTextLog (Address: 0x18002f940)
  • SetupWriteTextLogError (Address: 0x18002f938)
USER32.dll
  • BeginPaint (Address: 0x18002fa60)
  • CreateWindowExW (Address: 0x18002f9d8)
  • DefWindowProcW (Address: 0x18002f9a8)
  • DestroyWindow (Address: 0x18002f998)
  • DispatchMessageW (Address: 0x18002fa20)
  • DrawTextW (Address: 0x18002fa98)
  • EndPaint (Address: 0x18002fa58)
  • FillRect (Address: 0x18002f9c0)
  • FindWindowExW (Address: 0x18002f9a0)
  • GetClientRect (Address: 0x18002faa0)
  • GetDC (Address: 0x18002f990)
  • GetMessageW (Address: 0x18002f9b0)
  • GetPropW (Address: 0x18002f978)
  • GetSystemMetrics (Address: 0x18002f9e8)
  • GetWindowLongW (Address: 0x18002f9b8)
  • GetWindowTextW (Address: 0x18002fa50)
  • InvalidateRect (Address: 0x18002fa70)
  • IsWindowVisible (Address: 0x18002f988)
  • KillTimer (Address: 0x18002fa90)
  • LoadBitmapW (Address: 0x18002f9c8)
  • LoadImageW (Address: 0x18002fa78)
  • LoadStringW (Address: 0x18002f9e0)
  • MapWindowPoints (Address: 0x18002fa30)
  • NotifyWinEvent (Address: 0x18002fa00)
  • PostQuitMessage (Address: 0x18002fa88)
  • RegisterClassExW (Address: 0x18002fa08)
  • ReleaseDC (Address: 0x18002fa68)
  • SendMessageW (Address: 0x18002f9d0)
  • SetClassLongPtrW (Address: 0x18002f9f8)
  • SetCursor (Address: 0x18002faa8)
  • SetFocus (Address: 0x18002fa38)
  • SetPropW (Address: 0x18002fa40)
  • SetThreadDesktop (Address: 0x18002fa10)
  • SetTimer (Address: 0x18002fa28)
  • SetWindowPos (Address: 0x18002f980)
  • SetWindowTextW (Address: 0x18002f9f0)
  • ShowWindow (Address: 0x18002fa18)
  • TranslateMessage (Address: 0x18002fa48)
  • UpdateWindow (Address: 0x18002fa80)
WDSCORE.dll
  • ConstructPartialMsgVW (Address: 0x18002fad0)
  • CurrentIP (Address: 0x18002fad8)
  • WdsInitialize (Address: 0x18002fab8)
  • WdsSetupLogMessageW (Address: 0x18002fac8)
  • WdsTerminate (Address: 0x18002fac0)
wevtapi.dll
  • EvtClearLog (Address: 0x180030308)