TpmTasks.dll

Description: TPM Maintenance Tasks

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6456

Architecture: 64-bit

Operating System: Windows NT

SHA256: a2813e27a7cb3b83010ddb07cb6f48ab

File Size: 720.5 KB

Uploaded At: Dec. 1, 2025, 7:40 a.m.

Views: 2

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x142a0)
  • DllGetClassObject (Ordinal: 2, Address: 0x142c0)
  • DllRegisterServer (Ordinal: 3, Address: 0xa9c0)
  • DllUnregisterServer (Ordinal: 4, Address: 0xa9c0)

Imported DLLs & Functions

ADVAPI32.dll
  • SetNamedSecurityInfoW (Address: 0x1800733d8)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x180073640)
  • CoInitializeEx (Address: 0x180073650)
  • CoInitializeSecurity (Address: 0x180073648)
  • CoSetProxyBlanket (Address: 0x180073670)
  • CoTaskMemAlloc (Address: 0x180073658)
  • CoTaskMemFree (Address: 0x180073660)
  • CoUninitialize (Address: 0x180073668)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180073690)
  • IsDebuggerPresent (Address: 0x180073680)
  • OutputDebugStringW (Address: 0x180073688)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800736a0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800736b0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800736c8)
  • RaiseException (Address: 0x1800736c0)
  • SetLastError (Address: 0x1800736d0)
  • SetUnhandledExceptionFilter (Address: 0x1800736d8)
  • UnhandledExceptionFilter (Address: 0x1800736e0)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x180073768)
  • CreateDirectoryW (Address: 0x180073778)
  • CreateFileA (Address: 0x180073708)
  • CreateFileW (Address: 0x180073750)
  • DeleteFileW (Address: 0x180073730)
  • FindClose (Address: 0x180073758)
  • FindFirstFileW (Address: 0x1800737b8)
  • FindFirstVolumeW (Address: 0x180073790)
  • FindNextFileW (Address: 0x180073798)
  • FindNextVolumeW (Address: 0x180073720)
  • FindVolumeClose (Address: 0x180073740)
  • FlushFileBuffers (Address: 0x180073728)
  • GetFileAttributesW (Address: 0x180073780)
  • GetFileInformationByHandle (Address: 0x1800737a8)
  • GetFileSize (Address: 0x180073710)
  • GetFileSizeEx (Address: 0x1800736f8)
  • GetFullPathNameW (Address: 0x180073700)
  • GetTempFileNameW (Address: 0x180073718)
  • GetVolumeInformationW (Address: 0x180073760)
  • GetVolumePathNameW (Address: 0x180073748)
  • QueryDosDeviceW (Address: 0x1800737b0)
  • ReadFile (Address: 0x1800736f0)
  • SetFileAttributesW (Address: 0x180073770)
  • SetFileInformationByHandle (Address: 0x1800737a0)
  • SetFilePointer (Address: 0x180073738)
  • WriteFile (Address: 0x180073788)
api-ms-win-core-file-l1-2-0.dll
  • GetVolumeNameForVolumeMountPointW (Address: 0x1800737c8)
api-ms-win-core-file-l1-2-3.dll
  • GetTempPath2W (Address: 0x1800737d8)
api-ms-win-core-file-l2-1-0.dll
  • CopyFileExW (Address: 0x1800737f8)
  • GetFileInformationByHandleEx (Address: 0x1800737f0)
  • MoveFileExW (Address: 0x1800737e8)
api-ms-win-core-file-l2-1-2.dll
  • CopyFileW (Address: 0x180073808)
api-ms-win-core-firmware-l1-1-0.dll
  • GetFirmwareEnvironmentVariableW (Address: 0x180073820)
  • SetFirmwareEnvironmentVariableExW (Address: 0x180073818)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180073830)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180073840)
  • HeapAlloc (Address: 0x180073848)
  • HeapFree (Address: 0x180073850)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180073860)
  • LocalFree (Address: 0x180073868)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180073878)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x180073888)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1800738c8)
  • FindResourceExW (Address: 0x1800738e8)
  • FreeLibrary (Address: 0x1800738d8)
  • FreeLibraryAndExitThread (Address: 0x1800738a0)
  • GetModuleFileNameA (Address: 0x180073898)
  • GetModuleHandleExW (Address: 0x1800738a8)
  • GetModuleHandleW (Address: 0x1800738c0)
  • GetProcAddress (Address: 0x1800738d0)
  • LoadLibraryExW (Address: 0x1800738e0)
  • LoadResource (Address: 0x1800738b8)
  • SizeofResource (Address: 0x1800738b0)
api-ms-win-core-libraryloader-l1-2-1.dll
  • FindResourceW (Address: 0x180073900)
  • LoadLibraryW (Address: 0x1800738f8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180073910)
  • GetLocaleInfoW (Address: 0x180073918)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x180073928)
  • MapViewOfFile (Address: 0x180073938)
  • UnmapViewOfFile (Address: 0x180073930)
api-ms-win-core-processenvironment-l1-1-0.dll
  • SearchPathW (Address: 0x180073948)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x180073990)
  • GetCurrentProcess (Address: 0x180073978)
  • GetCurrentProcessId (Address: 0x180073970)
  • GetCurrentThread (Address: 0x180073988)
  • GetCurrentThreadId (Address: 0x180073958)
  • OpenProcessToken (Address: 0x180073968)
  • OpenThreadToken (Address: 0x1800739a0)
  • ResumeThread (Address: 0x180073960)
  • SetThreadToken (Address: 0x180073998)
  • TerminateProcess (Address: 0x180073980)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x1800739b0)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1800739c0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800739f0)
  • RegCreateKeyExW (Address: 0x1800739f8)
  • RegDeleteValueW (Address: 0x1800739e8)
  • RegGetValueW (Address: 0x1800739e0)
  • RegOpenKeyExW (Address: 0x1800739d8)
  • RegQueryInfoKeyW (Address: 0x180073a08)
  • RegQueryValueExW (Address: 0x180073a00)
  • RegSetValueExW (Address: 0x1800739d0)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueW (Address: 0x180073a18)
  • RegSetKeyValueW (Address: 0x180073a20)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCompareMemory (Address: 0x180073a30)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • StrStrIW (Address: 0x180073a40)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x180073a50)
  • WideCharToMultiByte (Address: 0x180073a58)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180073aa8)
  • AcquireSRWLockShared (Address: 0x180073a80)
  • CreateMutexExW (Address: 0x180073a90)
  • CreateMutexW (Address: 0x180073ac0)
  • CreateSemaphoreExW (Address: 0x180073af0)
  • DeleteCriticalSection (Address: 0x180073a68)
  • EnterCriticalSection (Address: 0x180073ae8)
  • InitializeCriticalSectionEx (Address: 0x180073ad0)
  • LeaveCriticalSection (Address: 0x180073ad8)
  • OpenMutexW (Address: 0x180073aa0)
  • OpenSemaphoreW (Address: 0x180073ae0)
  • ReleaseMutex (Address: 0x180073a88)
  • ReleaseSemaphore (Address: 0x180073a98)
  • ReleaseSRWLockExclusive (Address: 0x180073a78)
  • ReleaseSRWLockShared (Address: 0x180073a70)
  • TryAcquireSRWLockExclusive (Address: 0x180073ab0)
  • WaitForSingleObject (Address: 0x180073ab8)
  • WaitForSingleObjectEx (Address: 0x180073ac8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180073b08)
  • InitOnceComplete (Address: 0x180073b00)
  • Sleep (Address: 0x180073b10)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x180073b40)
  • GetSystemDirectoryW (Address: 0x180073b38)
  • GetSystemInfo (Address: 0x180073b50)
  • GetSystemTime (Address: 0x180073b48)
  • GetSystemTimeAsFileTime (Address: 0x180073b28)
  • GetVersionExW (Address: 0x180073b20)
  • GetWindowsDirectoryW (Address: 0x180073b30)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180073b60)
  • CreateThreadpoolTimer (Address: 0x180073b70)
  • SetThreadpoolTimer (Address: 0x180073b68)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180073b78)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x180073b88)
  • SystemTimeToFileTime (Address: 0x180073b90)
api-ms-win-core-winrt-l1-1-0.dll
  • RoGetActivationFactory (Address: 0x180073ba8)
  • RoInitialize (Address: 0x180073bb0)
  • RoUninitialize (Address: 0x180073ba0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x180073bc8)
  • WindowsDeleteString (Address: 0x180073bc0)
  • WindowsGetStringRawBuffer (Address: 0x180073bd0)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x180073cc0)
  • __CxxFrameHandler3 (Address: 0x180073cc8)
  • __CxxFrameHandler4 (Address: 0x180073d80)
  • __std_terminate (Address: 0x180073d78)
  • _CxxThrowException (Address: 0x180073cd0)
  • _o___acrt_iob_func (Address: 0x180073d68)
  • _o___std_exception_copy (Address: 0x180073d60)
  • _o___std_exception_destroy (Address: 0x180073d58)
  • _o___std_type_info_destroy_list (Address: 0x180073d50)
  • _o___stdio_common_vfwprintf (Address: 0x180073d48)
  • _o___stdio_common_vsnprintf_s (Address: 0x180073d40)
  • _o___stdio_common_vsnwprintf_s (Address: 0x180073d38)
  • _o___stdio_common_vsprintf_s (Address: 0x180073d30)
  • _o___stdio_common_vswprintf (Address: 0x180073d28)
  • _o___stdio_common_vswprintf_s (Address: 0x180073d20)
  • _o___stdio_common_vswscanf (Address: 0x180073d18)
  • _o__callnewh (Address: 0x180073d10)
  • _o__cexit (Address: 0x180073d08)
  • _o__configure_narrow_argv (Address: 0x180073d00)
  • _o__crt_atexit (Address: 0x180073cf8)
  • _o__errno (Address: 0x180073ce8)
  • _o__execute_onexit_table (Address: 0x180073ce0)
  • _o__initialize_narrow_environment (Address: 0x180073be0)
  • _o__initialize_onexit_table (Address: 0x180073be8)
  • _o__invalid_parameter_noinfo (Address: 0x180073bf0)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x180073bf8)
  • _o__purecall (Address: 0x180073c00)
  • _o__register_onexit_function (Address: 0x180073c08)
  • _o__seh_filter_dll (Address: 0x180073c10)
  • _o__wcsdup (Address: 0x180073c18)
  • _o__wcsicmp (Address: 0x180073c20)
  • _o__wcsnicmp (Address: 0x180073c28)
  • _o__wcsupr (Address: 0x180073c30)
  • _o__wfopen_s (Address: 0x180073c38)
  • _o_bsearch (Address: 0x180073c48)
  • _o_fclose (Address: 0x180073c50)
  • _o_fflush (Address: 0x180073c58)
  • _o_free (Address: 0x180073c60)
  • _o_iswspace (Address: 0x180073c68)
  • _o_malloc (Address: 0x180073c70)
  • _o_qsort (Address: 0x180073c78)
  • _o_strtod (Address: 0x180073c80)
  • _o_strtoul (Address: 0x180073c88)
  • _o_terminate (Address: 0x180073c90)
  • _o_tolower (Address: 0x180073c98)
  • _o_towupper (Address: 0x180073ca0)
  • _o_wcscat_s (Address: 0x180073ca8)
  • _o_wcscpy_s (Address: 0x180073cb0)
  • _o_wcstol (Address: 0x180073cb8)
  • memcmp (Address: 0x180073d88)
  • memcpy (Address: 0x180073d90)
  • memmove (Address: 0x180073c40)
  • strstr (Address: 0x180073d70)
  • wcschr (Address: 0x180073cd8)
  • wcsrchr (Address: 0x180073cf0)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180073da8)
  • _initterm_e (Address: 0x180073da0)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180073dc0)
  • strcmp (Address: 0x180073dd0)
  • wcscmp (Address: 0x180073db8)
  • wcsncmp (Address: 0x180073dd8)
  • wcsncpy (Address: 0x180073dc8)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x180073df0)
  • EventUnregister (Address: 0x180073df8)
  • EventWriteTransfer (Address: 0x180073de8)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x180073e40)
  • DuplicateTokenEx (Address: 0x180073e10)
  • GetSecurityDescriptorControl (Address: 0x180073e20)
  • GetSecurityDescriptorDacl (Address: 0x180073e38)
  • GetSecurityDescriptorGroup (Address: 0x180073e08)
  • GetSecurityDescriptorOwner (Address: 0x180073e30)
  • GetSecurityDescriptorSacl (Address: 0x180073e18)
  • GetTokenInformation (Address: 0x180073e28)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupPrivilegeValueW (Address: 0x180073e50)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180073e60)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180073e68)
bcd.dll
  • BcdCloseObject (Address: 0x180073f20)
  • BcdCloseStore (Address: 0x180073f28)
  • BcdCopyObjectEx (Address: 0x180073f00)
  • BcdCopyObjects (Address: 0x180073ed8)
  • BcdCreateStore (Address: 0x180073ee0)
  • BcdDeleteElement (Address: 0x180073eb0)
  • BcdDeleteObject (Address: 0x180073ec8)
  • BcdEnumerateObjects (Address: 0x180073ee8)
  • BcdFlushStore (Address: 0x180073ec0)
  • BcdForciblyUnloadStore (Address: 0x180073e98)
  • BcdGetElementData (Address: 0x180073ea8)
  • BcdGetSystemStorePath (Address: 0x180073ef0)
  • BcdMarkAsSystemStore (Address: 0x180073ef8)
  • BcdOpenObject (Address: 0x180073f10)
  • BcdOpenStore (Address: 0x180073e88)
  • BcdOpenStoreFromFile (Address: 0x180073ed0)
  • BcdQueryObject (Address: 0x180073ea0)
  • BcdSetElementData (Address: 0x180073eb8)
  • BcdSetElementDataWithFlags (Address: 0x180073e78)
  • BcdSetLogging (Address: 0x180073f08)
  • SyspartGetPhysicalPartitions (Address: 0x180073e90)
  • SyspartGetSystemPartition (Address: 0x180073e80)
  • SyspartIsSpace (Address: 0x180073f18)
Cabinet.dll
  • (Address: 0x180073458)
  • (Address: 0x180073460)
  • (Address: 0x180073468)
CRYPT32.dll
  • CertCloseStore (Address: 0x180073410)
  • CertComparePublicKeyInfo (Address: 0x180073420)
  • CertCreateCertificateContext (Address: 0x1800733e8)
  • CertEnumCertificatesInStore (Address: 0x180073400)
  • CertFindCertificateInStore (Address: 0x180073430)
  • CertFreeCertificateContext (Address: 0x1800733f8)
  • CertGetCertificateContextProperty (Address: 0x180073428)
  • CertGetNameStringW (Address: 0x180073440)
  • CertNameToStrW (Address: 0x180073438)
  • CryptBinaryToStringW (Address: 0x180073448)
  • CryptMsgClose (Address: 0x1800733f0)
  • CryptMsgGetParam (Address: 0x180073418)
  • CryptQueryObject (Address: 0x180073408)
imagehlp.dll
  • CheckSumMappedFile (Address: 0x180073f38)
KERNEL32.dll
  • GetPrivateProfileSectionW (Address: 0x180073478)
  • GetSystemDefaultUILanguage (Address: 0x180073490)
  • GetUserDefaultUILanguage (Address: 0x180073488)
  • lstrlenW (Address: 0x180073480)
msvcp_win.dll
  • _Xtime_get_ticks (Address: 0x180073f58)
  • ?_Ipfx@?$basic_istream@DU?$char_traits@D@std@@@std@@QEAA_N_N@Z (Address: 0x180073f70)
  • ?_Lock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x180073ff8)
  • ?_Pninc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ (Address: 0x180074018)
  • ?_Unlock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x180073ff0)
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x180073f60)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x180073f50)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180073f48)
  • ??0?$basic_ios@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x180074028)
  • ??0?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@_N@Z (Address: 0x180074010)
  • ??0?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x180074030)
  • ??1?$basic_ios@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x180074008)
  • ??1?$basic_ostream@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x180073fb0)
  • ??1?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x180074000)
  • ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@H@Z (Address: 0x180073fa0)
  • ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@P6AAEAVios_base@1@AEAV21@@Z@Z (Address: 0x180073fa8)
  • ?gbump@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXH@Z (Address: 0x180074020)
  • ?imbue@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAXAEBVlocale@2@@Z (Address: 0x180073fb8)
  • ?sbumpc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ (Address: 0x180073f90)
  • ?setbuf@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAPEAV12@PEAG_J@Z (Address: 0x180073fc8)
  • ?setstate@?$basic_ios@DU?$char_traits@D@std@@@std@@QEAAXH_N@Z (Address: 0x180073f88)
  • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z (Address: 0x180073f68)
  • ?sgetc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ (Address: 0x180073f98)
  • ?showmanyc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JXZ (Address: 0x180073fe8)
  • ?snextc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QEAAHXZ (Address: 0x180073f78)
  • ?sync@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAHXZ (Address: 0x180073fc0)
  • ?uflow@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAGXZ (Address: 0x180073fe0)
  • ?widen@?$basic_ios@DU?$char_traits@D@std@@@std@@QEBADD@Z (Address: 0x180073f80)
  • ?xsgetn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEAG_J@Z (Address: 0x180073fd8)
  • ?xsputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEBG_J@Z (Address: 0x180073fd0)
ncrypt.dll
  • NCryptCreateClaim (Address: 0x180074058)
  • NCryptFreeObject (Address: 0x180074050)
  • NCryptGetProperty (Address: 0x180074048)
  • NCryptOpenStorageProvider (Address: 0x180074040)
ntdll.dll
  • LdrAccessResource (Address: 0x180074108)
  • LdrFindResource_U (Address: 0x180074110)
  • NtClose (Address: 0x180074098)
  • NtCreateEvent (Address: 0x1800740e0)
  • NtCreateFile (Address: 0x180074190)
  • NtDeviceIoControlFile (Address: 0x180074068)
  • NtOpenFile (Address: 0x180074138)
  • NtOpenProcess (Address: 0x180074168)
  • NtQueryInformationFile (Address: 0x180074148)
  • NtQueryInformationProcess (Address: 0x180074170)
  • NtQueryInformationThread (Address: 0x180074140)
  • NtQuerySystemEnvironmentValueEx (Address: 0x1800740f0)
  • NtQuerySystemInformation (Address: 0x180074070)
  • NtQueryWnfStateData (Address: 0x1800740b8)
  • NtReadFile (Address: 0x180074160)
  • NtSetInformationFile (Address: 0x180074128)
  • NtSetInformationThread (Address: 0x180074158)
  • NtSetSystemEnvironmentValueEx (Address: 0x1800740a0)
  • NtWaitForSingleObject (Address: 0x1800740f8)
  • NtWriteFile (Address: 0x180074188)
  • RtlAcquirePrivilege (Address: 0x180074180)
  • RtlAllocateHeap (Address: 0x180074100)
  • RtlCaptureContext (Address: 0x1800740c8)
  • RtlCheckPortableOperatingSystem (Address: 0x180074088)
  • RtlComputeCrc32 (Address: 0x1800740e8)
  • RtlFreeHeap (Address: 0x180074118)
  • RtlFreeUnicodeString (Address: 0x180074130)
  • RtlGetPersistedStateLocation (Address: 0x1800740b0)
  • RtlImageNtHeader (Address: 0x180074150)
  • RtlImageNtHeaderEx (Address: 0x180074090)
  • RtlInitUnicodeString (Address: 0x1800740a8)
  • RtlLookupFunctionEntry (Address: 0x1800740d0)
  • RtlNtStatusToDosError (Address: 0x1800740c0)
  • RtlPublishWnfStateData (Address: 0x180074078)
  • RtlReleasePrivilege (Address: 0x180074178)
  • RtlStringFromGUID (Address: 0x180074120)
  • RtlVirtualUnwind (Address: 0x1800740d8)
  • ZwQueryWnfStateData (Address: 0x180074080)
OLEAUT32.dll
  • SafeArrayGetElement (Address: 0x1800734d8)
  • SafeArrayGetLBound (Address: 0x1800734c8)
  • SafeArrayGetUBound (Address: 0x1800734d0)
  • SysAllocString (Address: 0x1800734a0)
  • SysFreeString (Address: 0x1800734b0)
  • SysStringLen (Address: 0x1800734b8)
  • VariantClear (Address: 0x1800734a8)
  • VariantInit (Address: 0x1800734c0)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x1800734f0)
  • RpcBindingFree (Address: 0x180073518)
  • RpcBindingFromStringBindingW (Address: 0x180073508)
  • RpcExceptionFilter (Address: 0x1800734f8)
  • RpcStringBindingComposeW (Address: 0x180073510)
  • RpcStringFreeW (Address: 0x180073500)
  • UuidCreate (Address: 0x1800734e8)
SHLWAPI.dll
  • PathRemoveBackslashW (Address: 0x180073530)
  • StrCmpIW (Address: 0x180073528)
TpmCoreProvisioning.DLL
  • TpmCertDeleteHealthCert (Address: 0x180073588)
  • TpmCertGetWindowsAik (Address: 0x1800735b0)
  • TpmCertInstallNvEkCerts (Address: 0x180073598)
  • TpmCertSetEkAttestationOverride (Address: 0x180073570)
  • TpmCertSetPreferredMaximumProtocolVersion (Address: 0x180073578)
  • TpmCheckCreateWindowsAIK (Address: 0x180073560)
  • TpmEKCertValidateAndCleanup (Address: 0x1800735c8)
  • TpmEnableAutoProvisioning (Address: 0x1800735f8)
  • TpmGatherTpmData (Address: 0x1800735d8)
  • TpmGet_IsTpmPresent (Address: 0x1800735f0)
  • TpmGet_IsTpmVersion20 (Address: 0x180073550)
  • TpmGet_ManufacturerId (Address: 0x180073580)
  • TpmGet_ManufacturerVersion (Address: 0x1800735a8)
  • TpmGetCapLockoutInfo (Address: 0x180073600)
  • TpmGetOrderlyShutdownInfo (Address: 0x1800735a0)
  • TpmGetTpmVersion (Address: 0x180073608)
  • TpmIsOwned (Address: 0x180073548)
  • TpmIsReadyInformation (Address: 0x1800735c0)
  • TpmIsUseLegacyDictionaryAttackParametersPolicySet (Address: 0x1800735e0)
  • TpmPrepForNgc (Address: 0x180073540)
  • TpmProvision (Address: 0x180073590)
  • TpmRemoveRegisteredWindowsAIK (Address: 0x1800735e8)
  • TpmRetrieveEkCertOrReschedule (Address: 0x180073558)
  • TpmRetrieveHealthCertOrReschedule (Address: 0x1800735d0)
  • TpmSetToLegacyDictionaryAttackParameters (Address: 0x180073568)
  • TpmVerifyDeviceHealth (Address: 0x1800735b8)
WINTRUST.dll
  • WinVerifyTrust (Address: 0x180073628)
  • WTGetSignatureInfo (Address: 0x180073620)
  • WTHelperGetProvSignerFromChain (Address: 0x180073618)
  • WTHelperProvDataFromStateData (Address: 0x180073630)