UserDataPlatformHelperUtil.dll

Description: Platform Utilities for data access

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 32791349776adabca7283cbad8318d7b

File Size: 63.0 KB

Uploaded At: Dec. 1, 2025, 7:41 a.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ??0CalculateSize@Comms@@QEAA@_N0@Z (Ordinal: 1, Address: 0x23e0)
  • ??0Deserializer@Comms@@QEAA@PEBE0_N1@Z (Ordinal: 2, Address: 0x1950)
  • ??0RpcClient@Comms@@QEAA@XZ (Ordinal: 3, Address: 0x1cc0)
  • ??0SecureRpcClient@Comms@@QEAA@XZ (Ordinal: 4, Address: 0x1e50)
  • ??0SerializeBuffer@Comms@@QEAA@AEBVCalculateSize@1@_N1@Z (Ordinal: 5, Address: 0x2460)
  • ??1Deserializer@Comms@@QEAA@XZ (Ordinal: 6, Address: 0x11e0)
  • ??1RpcClient@Comms@@QEAA@XZ (Ordinal: 7, Address: 0x1ce0)
  • ??1SecureRpcClient@Comms@@UEAA@XZ (Ordinal: 8, Address: 0x1e70)
  • ?CopyBytesIn@CalculateSize@Comms@@UEAAXPEBX_KAEBVtype_info@@@Z (Ordinal: 9, Address: 0x2410)
  • ?CopyBytesIn@SerializeBuffer@Comms@@UEAAXPEBX_KAEBVtype_info@@@Z (Ordinal: 10, Address: 0x2540)
  • ?CopyBytesOut@Deserializer@Comms@@QEAA_NPEAX_KAEBVtype_info@@@Z (Ordinal: 11, Address: 0x1980)
  • CreateKnownFolderPath (Ordinal: 12, Address: 0x3b20)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEAPEAD@Z (Ordinal: 13, Address: 0x1a80)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEAPEAG@Z (Ordinal: 14, Address: 0x1b40)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEAPEBD@Z (Ordinal: 15, Address: 0x1b30)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEAPEBG@Z (Ordinal: 16, Address: 0x1c00)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEAV?$basic_string@GU?$char_traits@G@utl@@V?$allocator@G@2@@utl@@@Z (Ordinal: 17, Address: 0x1390)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEAV?$vector@EV?$allocator@E@utl@@@utl@@@Z (Ordinal: 18, Address: 0x14c0)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEAVNullType@detail@1@@Z (Ordinal: 19, Address: 0x1c10)
  • ?DeserializeObject@Comms@@YA_NAEAVDeserializer@1@AEBVNullType@detail@1@@Z (Ordinal: 20, Address: 0x1c10)
  • ?GetBuffer@Deserializer@Comms@@QEAAPEAX_K@Z (Ordinal: 21, Address: 0x1240)
  • ?GetBuffer@SerializeBuffer@Comms@@QEAAXAEAV?$vector@EV?$allocator@E@utl@@@utl@@@Z (Ordinal: 22, Address: 0x1190)
  • ?GetBuffer@SerializeBuffer@Comms@@QEBAPEBV?$vector@EV?$allocator@E@utl@@@utl@@XZ (Ordinal: 23, Address: 0x1180)
  • GetRpcClientThreadToken (Ordinal: 24, Address: 0x4390)
  • GetSupportedImageFileExtensions (Ordinal: 25, Address: 0x4bf0)
  • GetTempFileNameWithExt (Ordinal: 26, Address: 0x37c0)
  • GetThreadIOPriority (Ordinal: 27, Address: 0x5ec0)
  • ?GetTotal@CalculateSize@Comms@@QEBA_KXZ (Ordinal: 28, Address: 0x1170)
  • ?Initialize@SerializeBuffer@Comms@@QEAA_NXZ (Ordinal: 29, Address: 0x2500)
  • ?InitializeBinding@RpcClient@Comms@@QEAAJPEBGAEAPEAX@Z (Ordinal: 30, Address: 0x1d30)
  • IsActiveDebugger (Ordinal: 31, Address: 0x1e10)
  • IsImageExtension (Ordinal: 32, Address: 0x4fe0)
  • ?ReleaseBuffer@Deserializer@Comms@@QEAAXPEBX@Z (Ordinal: 33, Address: 0x12e0)
  • ResizeImageBySizeInMemory (Ordinal: 34, Address: 0x5800)
  • ResizeImageBySizeToStream (Ordinal: 35, Address: 0x5be0)
  • ?SerializeObject@Comms@@YAXAEAVSerializeBase@1@AEBV?$basic_string@GU?$char_traits@G@utl@@V?$allocator@G@2@@utl@@@Z (Ordinal: 36, Address: 0x1310)
  • ?SerializeObject@Comms@@YAXAEAVSerializeBase@1@AEBV?$vector@EV?$allocator@E@utl@@@utl@@@Z (Ordinal: 37, Address: 0x1450)
  • ?SerializeObject@Comms@@YAXAEAVSerializeBase@1@AEBVNullType@detail@1@@Z (Ordinal: 38, Address: 0x23d0)
  • ?SerializeObject@Comms@@YAXAEAVSerializeBase@1@PEBD@Z (Ordinal: 39, Address: 0x22d0)
  • ?SerializeObject@Comms@@YAXAEAVSerializeBase@1@PEBG@Z (Ordinal: 40, Address: 0x2350)
  • SetPoolThreadBasePriority (Ordinal: 41, Address: 0x5fc0)
  • SetThreadIOPriority (Ordinal: 42, Address: 0x5f40)
  • ?_InitializeSecureRpcBinding@SecureRpcClient@Comms@@IEAAJPEBG0@Z (Ordinal: 43, Address: 0x1eb0)
  • ConvertHtmlStringToPlainTextStringOneCore (Ordinal: 44, Address: 0x6480)
  • ConvertPlainTextStringToHtmlStringOneCore (Ordinal: 45, Address: 0x65c0)
  • DefaultMakeHresultFromJetError (Ordinal: 46, Address: 0x7530)
  • DllCanUnloadNow (Ordinal: 47, Address: 0x29b0)
  • DllGetClassObject (Ordinal: 48, Address: 0x29f0)
  • FreeEnumColumn (Ordinal: 49, Address: 0x7140)
  • GenerateUserModeServiceName (Ordinal: 50, Address: 0x44f0)
  • GetCalendarColors (Ordinal: 51, Address: 0x6640)
  • GetCombinedTransientObjectSecurityDescriptor (Ordinal: 52, Address: 0x48c0)
  • GetContentTypeFromFilePath (Ordinal: 53, Address: 0x6b30)
  • GetFileExtensionFromContentType (Ordinal: 54, Address: 0x6e00)
  • GetNextNewCalendarColor (Ordinal: 55, Address: 0x66b0)
  • GetQueryProcessHandle (Ordinal: 56, Address: 0x4ad0)
  • GetUserContextFromHandle (Ordinal: 57, Address: 0x3e80)
  • GetUserTokenFromContext (Ordinal: 58, Address: 0x3e30)
  • IsCommsSystemService (Ordinal: 59, Address: 0x4450)
  • JetReallocMethod (Ordinal: 60, Address: 0x70b0)
  • PrependHtmlOneCore (Ordinal: 61, Address: 0x65e0)
  • RunServicesInProc (Ordinal: 62, Address: 0x3ed0)
  • SetCommsServiceJetGlobalSystemParameters (Ordinal: 63, Address: 0x74c0)
  • StartAndWaitForService (Ordinal: 64, Address: 0x3ef0)
  • StartAndWaitForServiceForUser (Ordinal: 65, Address: 0x3f30)
  • StopAndWaitForFullyNamedService (Ordinal: 66, Address: 0x41b0)
  • StopAndWaitForService (Ordinal: 67, Address: 0x4130)
  • UT_UninitializeTrident (Ordinal: 68, Address: 0x63f0)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18000b610)
api-ms-win-core-debug-l1-1-0.dll
  • IsDebuggerPresent (Address: 0x18000b620)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18000b630)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18000b640)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18000b650)
  • RaiseException (Address: 0x18000b658)
  • SetLastError (Address: 0x18000b660)
  • SetUnhandledExceptionFilter (Address: 0x18000b668)
  • UnhandledExceptionFilter (Address: 0x18000b670)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x18000b680)
  • GetFileAttributesW (Address: 0x18000b690)
  • GetTempFileNameW (Address: 0x18000b688)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18000b6a0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18000b6c0)
  • HeapAlloc (Address: 0x18000b6b8)
  • HeapFree (Address: 0x18000b6c8)
  • HeapReAlloc (Address: 0x18000b6b0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18000b6d8)
  • LocalFree (Address: 0x18000b6e0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18000b710)
  • FreeLibrary (Address: 0x18000b700)
  • GetModuleHandleW (Address: 0x18000b6f0)
  • GetProcAddress (Address: 0x18000b708)
  • LoadLibraryExW (Address: 0x18000b6f8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18000b748)
  • GetCurrentProcessId (Address: 0x18000b728)
  • GetCurrentThread (Address: 0x18000b740)
  • GetCurrentThreadId (Address: 0x18000b730)
  • OpenThreadToken (Address: 0x18000b720)
  • TerminateProcess (Address: 0x18000b738)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18000b758)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18000b768)
api-ms-win-core-quirks-l1-1-0.dll
  • QuirkIsEnabled (Address: 0x18000b778)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18000b790)
  • RegCreateKeyExW (Address: 0x18000b7a0)
  • RegGetValueW (Address: 0x18000b788)
  • RegSetValueExW (Address: 0x18000b798)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18000b7b8)
  • RtlLookupFunctionEntry (Address: 0x18000b7c0)
  • RtlVirtualUnwind (Address: 0x18000b7b0)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFindExtensionW (Address: 0x18000b7d0)
  • PathMatchSpecW (Address: 0x18000b7d8)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • StrStrIW (Address: 0x18000b7e8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18000b800)
  • DeleteCriticalSection (Address: 0x18000b808)
  • EnterCriticalSection (Address: 0x18000b820)
  • InitializeCriticalSection (Address: 0x18000b810)
  • InitializeCriticalSectionEx (Address: 0x18000b818)
  • LeaveCriticalSection (Address: 0x18000b828)
  • ReleaseSRWLockExclusive (Address: 0x18000b7f8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x18000b848)
  • InitOnceComplete (Address: 0x18000b850)
  • InitOnceExecuteOnce (Address: 0x18000b840)
  • Sleep (Address: 0x18000b858)
  • SleepConditionVariableSRW (Address: 0x18000b860)
  • WakeAllConditionVariable (Address: 0x18000b838)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18000b878)
  • GetTickCount (Address: 0x18000b880)
  • GetTickCount64 (Address: 0x18000b870)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x18000b898)
  • EventUnregister (Address: 0x18000b890)
api-ms-win-security-base-l1-1-0.dll
  • GetSecurityDescriptorDacl (Address: 0x18000b8b0)
  • MakeAbsoluteSD (Address: 0x18000b8c0)
  • MakeSelfRelativeSD (Address: 0x18000b8b8)
  • SetSecurityDescriptorDacl (Address: 0x18000b8a8)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x18000b8d0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000b970)
  • __CxxFrameHandler3 (Address: 0x18000b920)
  • __dllonexit (Address: 0x18000b928)
  • _amsg_exit (Address: 0x18000b998)
  • _callnewh (Address: 0x18000b940)
  • _initterm (Address: 0x18000b988)
  • _lock (Address: 0x18000b8f8)
  • _onexit (Address: 0x18000b930)
  • _purecall (Address: 0x18000b978)
  • _unlock (Address: 0x18000b900)
  • _vsnwprintf (Address: 0x18000b950)
  • _XcptFilter (Address: 0x18000b960)
  • ??1type_info@@UEAA@XZ (Address: 0x18000b8f0)
  • ?raw_name@type_info@@QEBAPEBDXZ (Address: 0x18000b980)
  • free (Address: 0x18000b908)
  • malloc (Address: 0x18000b990)
  • memcpy (Address: 0x18000b948)
  • memcpy_s (Address: 0x18000b938)
  • memmove (Address: 0x18000b918)
  • memset (Address: 0x18000b958)
  • rand (Address: 0x18000b910)
  • sqrtf (Address: 0x18000b9a0)
  • srand (Address: 0x18000b968)
ntdll.dll
  • NtQueryInformationThread (Address: 0x18000b9b0)
  • NtSetInformationThread (Address: 0x18000b9b8)
RPCRT4.dll
  • RpcBindingFree (Address: 0x18000b5e8)
  • RpcBindingFromStringBindingW (Address: 0x18000b5d0)
  • RpcBindingSetAuthInfoExW (Address: 0x18000b600)
  • RpcImpersonateClient (Address: 0x18000b5d8)
  • RpcRevertToSelf (Address: 0x18000b5e0)
  • RpcStringBindingComposeW (Address: 0x18000b5f8)
  • RpcStringFreeW (Address: 0x18000b5f0)