sppnp.dll
Description: PnP module of SysPrep
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: 3bc8b60a3f474904607321b9f30a0033
File Size: 269.5 KB
Uploaded At: Dec. 1, 2025, 7:39 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- Sysprep_Generalize_Pnp (Ordinal: 1, Address: 0xb250)
- Sysprep_Generalize_Pnp_Drivers (Ordinal: 2, Address: 0xb9b0)
- Sysprep_Respecialize_Pnp (Ordinal: 3, Address: 0xbc10)
- Sysprep_RunDll_PnpW (Ordinal: 4, Address: 0x16040)
- Sysprep_Specialize_Offline_Pnp (Ordinal: 5, Address: 0x59d0)
- Sysprep_Specialize_Pnp (Ordinal: 6, Address: 0x6a80)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x18002faf0)
- CoInitializeEx (Address: 0x18002fae8)
- CoUninitialize (Address: 0x18002faf8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18002fb08)
- RaiseException (Address: 0x18002fb20)
- SetErrorMode (Address: 0x18002fb28)
- SetLastError (Address: 0x18002fb30)
- SetUnhandledExceptionFilter (Address: 0x18002fb18)
- UnhandledExceptionFilter (Address: 0x18002fb10)
api-ms-win-core-file-l1-1-0.dll
- CompareFileTime (Address: 0x18002fbb0)
- CreateDirectoryW (Address: 0x18002fbc0)
- CreateFileW (Address: 0x18002fb48)
- DeleteFileW (Address: 0x18002fb90)
- FileTimeToLocalFileTime (Address: 0x18002fb80)
- FindClose (Address: 0x18002fbb8)
- FindFirstFileW (Address: 0x18002fba8)
- FindNextFileW (Address: 0x18002fba0)
- FlushFileBuffers (Address: 0x18002fb68)
- GetFileAttributesW (Address: 0x18002fb98)
- GetFileInformationByHandle (Address: 0x18002fb58)
- GetFileSize (Address: 0x18002fb70)
- GetFullPathNameW (Address: 0x18002fb88)
- SetEndOfFile (Address: 0x18002fb40)
- SetFileAttributesW (Address: 0x18002fb50)
- SetFilePointer (Address: 0x18002fb60)
- WriteFile (Address: 0x18002fb78)
api-ms-win-core-file-l2-1-0.dll
- CreateHardLinkW (Address: 0x18002fbd8)
- MoveFileExW (Address: 0x18002fbd0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18002fbe8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18002fc10)
- HeapAlloc (Address: 0x18002fbf8)
- HeapFree (Address: 0x18002fc08)
- HeapReAlloc (Address: 0x18002fc00)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x18002fc20)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- FindResourceW (Address: 0x18002fc38)
- LoadLibraryW (Address: 0x18002fc40)
- MulDiv (Address: 0x18002fc30)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x18002fc68)
- GetModuleFileNameA (Address: 0x18002fc80)
- GetModuleFileNameW (Address: 0x18002fc78)
- GetModuleHandleExW (Address: 0x18002fc58)
- GetModuleHandleW (Address: 0x18002fc70)
- GetProcAddress (Address: 0x18002fc60)
- LoadLibraryExW (Address: 0x18002fc88)
- LoadResource (Address: 0x18002fc50)
- LockResource (Address: 0x18002fc98)
- SizeofResource (Address: 0x18002fc90)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18002fcb0)
- GetLocaleInfoEx (Address: 0x18002fca8)
- GetLocaleInfoW (Address: 0x18002fcc0)
- GetThreadLocale (Address: 0x18002fcc8)
- LCMapStringW (Address: 0x18002fcb8)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x18002fce8)
- MapViewOfFile (Address: 0x18002fcd8)
- UnmapViewOfFile (Address: 0x18002fce0)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x18002fd08)
- GetCommandLineA (Address: 0x18002fcf8)
- GetEnvironmentVariableW (Address: 0x18002fd00)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessW (Address: 0x18002fd50)
- CreateThread (Address: 0x18002fd60)
- ExitProcess (Address: 0x18002fd70)
- GetCurrentProcess (Address: 0x18002fd28)
- GetCurrentProcessId (Address: 0x18002fd80)
- GetCurrentThread (Address: 0x18002fd20)
- GetCurrentThreadId (Address: 0x18002fd78)
- GetExitCodeProcess (Address: 0x18002fd48)
- GetExitCodeThread (Address: 0x18002fd58)
- OpenProcessToken (Address: 0x18002fd30)
- OpenThreadToken (Address: 0x18002fd38)
- QueueUserAPC (Address: 0x18002fd68)
- SetThreadToken (Address: 0x18002fd40)
- TerminateProcess (Address: 0x18002fd18)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x18002fd90)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18002fda0)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18002fe00)
- RegCreateKeyExW (Address: 0x18002fdc8)
- RegDeleteKeyExW (Address: 0x18002fde8)
- RegDeleteTreeW (Address: 0x18002fdd0)
- RegDeleteValueW (Address: 0x18002fdb8)
- RegEnumKeyExW (Address: 0x18002fdd8)
- RegLoadKeyW (Address: 0x18002fdf8)
- RegNotifyChangeKeyValue (Address: 0x18002fe08)
- RegOpenKeyExW (Address: 0x18002fdc0)
- RegQueryValueExW (Address: 0x18002fde0)
- RegSetValueExW (Address: 0x18002fdf0)
- RegUnLoadKeyW (Address: 0x18002fdb0)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x18002fe20)
- CompareStringW (Address: 0x18002fe18)
- WideCharToMultiByte (Address: 0x18002fe28)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18002fea8)
- CreateEventW (Address: 0x18002fe88)
- CreateMutexW (Address: 0x18002fe48)
- DeleteCriticalSection (Address: 0x18002fe60)
- EnterCriticalSection (Address: 0x18002fe50)
- InitializeCriticalSection (Address: 0x18002fe58)
- LeaveCriticalSection (Address: 0x18002fe98)
- OpenEventW (Address: 0x18002fe80)
- ReleaseMutex (Address: 0x18002fe40)
- ReleaseSRWLockExclusive (Address: 0x18002fea0)
- ResetEvent (Address: 0x18002fe68)
- SetEvent (Address: 0x18002fe78)
- SleepEx (Address: 0x18002feb0)
- WaitForMultipleObjectsEx (Address: 0x18002fe38)
- WaitForSingleObject (Address: 0x18002fe90)
- WaitForSingleObjectEx (Address: 0x18002fe70)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x18002fed0)
- SleepConditionVariableSRW (Address: 0x18002fec0)
- WakeAllConditionVariable (Address: 0x18002fec8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetLocalTime (Address: 0x18002ff08)
- GetSystemTimeAsFileTime (Address: 0x18002fef8)
- GetSystemWindowsDirectoryW (Address: 0x18002fee0)
- GetTickCount (Address: 0x18002fef0)
- GetTickCount64 (Address: 0x18002fee8)
- GetVersionExW (Address: 0x18002ff00)
api-ms-win-devices-query-l1-1-0.dll
- DevFreeObjects (Address: 0x18002ff18)
- DevGetObjects (Address: 0x18002ff20)
- DevSetObjectProperties (Address: 0x18002ff28)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x18002ff40)
- GetTraceEnableLevel (Address: 0x18002ff48)
- GetTraceLoggerHandle (Address: 0x18002ff38)
- RegisterTraceGuidsW (Address: 0x18002ff50)
- TraceEvent (Address: 0x18002ff60)
- UnregisterTraceGuids (Address: 0x18002ff58)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x18002ff78)
- EventUnregister (Address: 0x18002ff80)
- EventWriteTransfer (Address: 0x18002ff70)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x18002ff98)
- DuplicateTokenEx (Address: 0x18002ffc8)
- EqualSid (Address: 0x18002ff90)
- GetKernelObjectSecurity (Address: 0x18002ffc0)
- GetSecurityDescriptorDacl (Address: 0x18002ffb8)
- GetSecurityDescriptorGroup (Address: 0x18002ffa0)
- GetSecurityDescriptorOwner (Address: 0x18002ffa8)
- GetSecurityDescriptorSacl (Address: 0x18002ffd0)
- IsValidSecurityDescriptor (Address: 0x18002ffb0)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x18002ffe0)
api-ms-win-security-provider-l1-1-0.dll
- GetNamedSecurityInfoW (Address: 0x18002fff8)
- SetNamedSecurityInfoW (Address: 0x18002fff0)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180030010)
- ConvertStringSidToSidW (Address: 0x180030008)
api-ms-win-service-core-l1-1-2.dll
- GetServiceKeyNameW (Address: 0x180030020)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x180030048)
- OpenSCManagerW (Address: 0x180030030)
- OpenServiceW (Address: 0x180030038)
- StartServiceW (Address: 0x180030040)
api-ms-win-service-winsvc-l1-1-0.dll
- QueryServiceStatus (Address: 0x180030058)
CFGMGR32.dll
- CM_Get_DevNode_Status (Address: 0x18002f700)
- CM_MapCrToWin32Err (Address: 0x18002f718)
- CM_Reenumerate_DevNode (Address: 0x18002f720)
- CMP_GetServerSideDeviceInstallFlags (Address: 0x18002f708)
- CMP_WaitNoPendingInstallEvents (Address: 0x18002f710)
drvstore.dll
- DriverPackageClose (Address: 0x180030088)
- DriverPackageGetVersionInfoW (Address: 0x180030070)
- DriverPackageOpenW (Address: 0x180030090)
- DriverStoreClose (Address: 0x1800300c0)
- DriverStoreEnumDeviceDriversW (Address: 0x1800300a0)
- DriverStoreEnumW (Address: 0x180030098)
- DriverStoreFindW (Address: 0x180030080)
- DriverStoreGetObjectPropertyW (Address: 0x1800300b8)
- DriverStoreOpenW (Address: 0x1800300a8)
- DriverStoreReflectCriticalW (Address: 0x180030068)
- DriverStoreSetLogContext (Address: 0x180030078)
- DriverStoreSetObjectPropertyW (Address: 0x1800300b0)
GDI32.dll
- AddFontMemResourceEx (Address: 0x18002f7e8)
- BitBlt (Address: 0x18002f758)
- CreateCompatibleBitmap (Address: 0x18002f760)
- CreateCompatibleDC (Address: 0x18002f770)
- CreateDIBitmap (Address: 0x18002f7f0)
- CreateFontIndirectW (Address: 0x18002f7d8)
- CreateSolidBrush (Address: 0x18002f7d0)
- DeleteDC (Address: 0x18002f818)
- DeleteObject (Address: 0x18002f7c8)
- GdiAlphaBlend (Address: 0x18002f7e0)
- GetDeviceCaps (Address: 0x18002f788)
- GetObjectW (Address: 0x18002f7b0)
- GetStockObject (Address: 0x18002f780)
- GetTextAlign (Address: 0x18002f790)
- GetTextExtentPoint32W (Address: 0x18002f798)
- GetTextMetricsW (Address: 0x18002f7f8)
- RemoveFontMemResourceEx (Address: 0x18002f810)
- SelectObject (Address: 0x18002f768)
- SetBkColor (Address: 0x18002f7b8)
- SetBkMode (Address: 0x18002f7a8)
- SetBrushOrgEx (Address: 0x18002f750)
- SetGraphicsMode (Address: 0x18002f800)
- SetLayout (Address: 0x18002f808)
- SetMapMode (Address: 0x18002f740)
- SetStretchBltMode (Address: 0x18002f7c0)
- SetTextAlign (Address: 0x18002f738)
- SetTextCharacterExtra (Address: 0x18002f820)
- SetTextColor (Address: 0x18002f7a0)
- SetWorldTransform (Address: 0x18002f730)
- StretchBlt (Address: 0x18002f778)
- TextOutW (Address: 0x18002f748)
KERNEL32.dll
- FileTimeToSystemTime (Address: 0x18002f858)
- GetSystemDefaultUILanguage (Address: 0x18002f850)
- IsDebuggerPresent (Address: 0x18002f830)
- K32EnumProcesses (Address: 0x18002f848)
- LocalFree (Address: 0x18002f840)
- QueryFullProcessImageNameW (Address: 0x18002f838)
msvcrt.dll
- __C_specific_handler (Address: 0x180030190)
- __CxxFrameHandler3 (Address: 0x1800300e0)
- __dllonexit (Address: 0x180030140)
- _amsg_exit (Address: 0x180030160)
- _callnewh (Address: 0x180030178)
- _initterm (Address: 0x180030158)
- _lock (Address: 0x180030150)
- _onexit (Address: 0x180030138)
- _resetstkoflw (Address: 0x180030118)
- _unlock (Address: 0x180030148)
- _vsnprintf (Address: 0x180030110)
- _vsnwprintf (Address: 0x1800300e8)
- _vsnwprintf_s (Address: 0x1800300d0)
- _wcsicmp (Address: 0x1800301c0)
- _wcsnicmp (Address: 0x1800301a0)
- _XcptFilter (Address: 0x180030168)
- ?terminate@@YAXXZ (Address: 0x1800300f0)
- free (Address: 0x180030170)
- iswalpha (Address: 0x1800301a8)
- malloc (Address: 0x180030180)
- memcmp (Address: 0x180030120)
- memcpy (Address: 0x180030128)
- memmove (Address: 0x180030130)
- memset (Address: 0x1800301d0)
- qsort (Address: 0x1800301b0)
- swprintf_s (Address: 0x1800300d8)
- swscanf (Address: 0x180030188)
- swscanf_s (Address: 0x1800301b8)
- toupper (Address: 0x180030108)
- wcschr (Address: 0x180030100)
- wcscpy_s (Address: 0x1800300f8)
- wcsncpy_s (Address: 0x1800301c8)
- wcsrchr (Address: 0x180030198)
newdev.dll
- DiInstallDevice (Address: 0x1800301e0)
- DiInstallDriverW (Address: 0x1800301e8)
ntdll.dll
- DbgPrint (Address: 0x180030208)
- DbgPrintEx (Address: 0x180030290)
- NtClose (Address: 0x1800302f0)
- NtCreateKey (Address: 0x180030298)
- NtDeleteKey (Address: 0x180030288)
- NtDeleteValueKey (Address: 0x180030218)
- NtOpenKey (Address: 0x180030238)
- NtOpenKeyEx (Address: 0x1800302a0)
- NtQueryInformationFile (Address: 0x180030278)
- NtQuerySystemInformation (Address: 0x1800302d8)
- NtQueryValueKey (Address: 0x180030228)
- NtQueryWnfStateData (Address: 0x1800302f8)
- NtSetInformationFile (Address: 0x180030270)
- NtSetValueKey (Address: 0x180030220)
- NtUnloadKeyEx (Address: 0x1800302d0)
- RtlAdjustPrivilege (Address: 0x180030210)
- RtlAllocateHeap (Address: 0x180030200)
- RtlCaptureContext (Address: 0x1800302b8)
- RtlFormatCurrentUserKeyPath (Address: 0x180030248)
- RtlFreeHeap (Address: 0x1800301f8)
- RtlFreeUnicodeString (Address: 0x180030240)
- RtlGetVersion (Address: 0x180030280)
- RtlInitUnicodeString (Address: 0x1800302c8)
- RtlInitUnicodeStringEx (Address: 0x1800302e8)
- RtlLookupFunctionEntry (Address: 0x1800302b0)
- RtlMultiByteToUnicodeN (Address: 0x180030250)
- RtlMultiByteToUnicodeSize (Address: 0x180030258)
- RtlNtStatusToDosError (Address: 0x1800302c0)
- RtlNtStatusToDosErrorNoTeb (Address: 0x1800302e0)
- RtlRaiseStatus (Address: 0x180030230)
- RtlUnicodeToMultiByteN (Address: 0x180030260)
- RtlUnicodeToMultiByteSize (Address: 0x180030268)
- RtlVirtualUnwind (Address: 0x1800302a8)
OLEAUT32.dll
- SysAllocString (Address: 0x18002f868)
- SysFreeString (Address: 0x18002f870)
SETUPAPI.dll
- PnpEnumDrpFile (Address: 0x18002f908)
- PnpRepairWindowsProtectedDriver (Address: 0x18002f910)
- pSetupFree (Address: 0x18002f930)
- pSetupInfGetDigitalSignatureInfo (Address: 0x18002f918)
- pSetupInfIsInbox (Address: 0x18002f928)
- pSetupInfSetDigitalSignatureInfo (Address: 0x18002f920)
- SetupDiCallClassInstaller (Address: 0x18002f8d0)
- SetupDiCreateDeviceInfoList (Address: 0x18002f8f0)
- SetupDiDestroyDeviceInfoList (Address: 0x18002f958)
- SetupDiEnumDeviceInfo (Address: 0x18002f8e0)
- SetupDiGetClassDevsExW (Address: 0x18002f8f8)
- SetupDiGetClassDevsW (Address: 0x18002f960)
- SetupDiGetDeviceInfoListDetailW (Address: 0x18002f8d8)
- SetupDiGetDeviceInstallParamsW (Address: 0x18002f900)
- SetupDiGetDeviceInstanceIdW (Address: 0x18002f8e8)
- SetupDiGetDevicePropertyW (Address: 0x18002f8c8)
- SetupDiGetDeviceRegistryPropertyW (Address: 0x18002f888)
- SetupDiOpenDeviceInfoW (Address: 0x18002f8a8)
- SetupDiRemoveDevice (Address: 0x18002f8b8)
- SetupDiSetDeviceInstallParamsW (Address: 0x18002f8c0)
- SetupDiSetDeviceRegistryPropertyW (Address: 0x18002f880)
- SetupGetInfDriverStoreLocationW (Address: 0x18002f8a0)
- SetupGetInfPublishedNameW (Address: 0x18002f898)
- SetupGetThreadLogToken (Address: 0x18002f968)
- SetupSetNonInteractiveMode (Address: 0x18002f948)
- SetupSetThreadLogToken (Address: 0x18002f950)
- SetupUninstallOEMInfW (Address: 0x18002f890)
- SetupVerifyInfFileW (Address: 0x18002f8b0)
- SetupWriteTextLog (Address: 0x18002f940)
- SetupWriteTextLogError (Address: 0x18002f938)
USER32.dll
- BeginPaint (Address: 0x18002fa60)
- CreateWindowExW (Address: 0x18002f9d8)
- DefWindowProcW (Address: 0x18002f9a8)
- DestroyWindow (Address: 0x18002f998)
- DispatchMessageW (Address: 0x18002fa20)
- DrawTextW (Address: 0x18002fa98)
- EndPaint (Address: 0x18002fa58)
- FillRect (Address: 0x18002f9c0)
- FindWindowExW (Address: 0x18002f9a0)
- GetClientRect (Address: 0x18002faa0)
- GetDC (Address: 0x18002f990)
- GetMessageW (Address: 0x18002f9b0)
- GetPropW (Address: 0x18002f978)
- GetSystemMetrics (Address: 0x18002f9e8)
- GetWindowLongW (Address: 0x18002f9b8)
- GetWindowTextW (Address: 0x18002fa50)
- InvalidateRect (Address: 0x18002fa70)
- IsWindowVisible (Address: 0x18002f988)
- KillTimer (Address: 0x18002fa90)
- LoadBitmapW (Address: 0x18002f9c8)
- LoadImageW (Address: 0x18002fa78)
- LoadStringW (Address: 0x18002f9e0)
- MapWindowPoints (Address: 0x18002fa30)
- NotifyWinEvent (Address: 0x18002fa00)
- PostQuitMessage (Address: 0x18002fa88)
- RegisterClassExW (Address: 0x18002fa08)
- ReleaseDC (Address: 0x18002fa68)
- SendMessageW (Address: 0x18002f9d0)
- SetClassLongPtrW (Address: 0x18002f9f8)
- SetCursor (Address: 0x18002faa8)
- SetFocus (Address: 0x18002fa38)
- SetPropW (Address: 0x18002fa40)
- SetThreadDesktop (Address: 0x18002fa10)
- SetTimer (Address: 0x18002fa28)
- SetWindowPos (Address: 0x18002f980)
- SetWindowTextW (Address: 0x18002f9f0)
- ShowWindow (Address: 0x18002fa18)
- TranslateMessage (Address: 0x18002fa48)
- UpdateWindow (Address: 0x18002fa80)
WDSCORE.dll
- ConstructPartialMsgVW (Address: 0x18002fad0)
- CurrentIP (Address: 0x18002fad8)
- WdsInitialize (Address: 0x18002fab8)
- WdsSetupLogMessageW (Address: 0x18002fac8)
- WdsTerminate (Address: 0x18002fac0)
wevtapi.dll
- EvtClearLog (Address: 0x180030308)