UserDeviceRegistration.dll
Description: AAD User Device Registration WinRT
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: ae1abfc934027c1096c4554f79c2a370
File Size: 233.0 KB
Uploaded At: Dec. 1, 2025, 7:41 a.m.
Views: 3
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x1f20)
- DllGetActivationFactory (Ordinal: 2, Address: 0x1c10)
- DllGetClassObject (Ordinal: 3, Address: 0x1df0)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateFreeThreadedMarshaler (Address: 0x180027158)
- CoCreateInstance (Address: 0x180027148)
- CoGetCallContext (Address: 0x180027128)
- CoGetInterfaceAndReleaseStream (Address: 0x180027130)
- CoImpersonateClient (Address: 0x180027138)
- CoMarshalInterface (Address: 0x180027178)
- CoReleaseMarshalData (Address: 0x180027168)
- CoRevertToSelf (Address: 0x180027140)
- CoTaskMemAlloc (Address: 0x180027160)
- CoTaskMemFree (Address: 0x180027150)
- CreateStreamOnHGlobal (Address: 0x180027170)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x180027188)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
- CStdStubBuffer2_Connect (Address: 0x1800271f8)
- CStdStubBuffer2_CountRefs (Address: 0x180027210)
- CStdStubBuffer2_Disconnect (Address: 0x1800271e0)
- CStdStubBuffer2_QueryInterface (Address: 0x180027200)
- NdrProxyForwardingFunction3 (Address: 0x180027218)
- NdrProxyForwardingFunction4 (Address: 0x180027220)
- NdrProxyForwardingFunction5 (Address: 0x180027228)
- ObjectStublessClient10 (Address: 0x180027260)
- ObjectStublessClient11 (Address: 0x1800271e8)
- ObjectStublessClient12 (Address: 0x1800271c0)
- ObjectStublessClient13 (Address: 0x1800271f0)
- ObjectStublessClient14 (Address: 0x180027250)
- ObjectStublessClient15 (Address: 0x1800271d0)
- ObjectStublessClient16 (Address: 0x180027268)
- ObjectStublessClient17 (Address: 0x180027258)
- ObjectStublessClient18 (Address: 0x1800271b8)
- ObjectStublessClient19 (Address: 0x180027208)
- ObjectStublessClient20 (Address: 0x1800271c8)
- ObjectStublessClient21 (Address: 0x180027240)
- ObjectStublessClient22 (Address: 0x1800271a8)
- ObjectStublessClient23 (Address: 0x1800271d8)
- ObjectStublessClient24 (Address: 0x180027198)
- ObjectStublessClient25 (Address: 0x1800271a0)
- ObjectStublessClient3 (Address: 0x1800271b0)
- ObjectStublessClient6 (Address: 0x180027230)
- ObjectStublessClient7 (Address: 0x180027248)
- ObjectStublessClient8 (Address: 0x180027238)
- ObjectStublessClient9 (Address: 0x180027270)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180027290)
- IsDebuggerPresent (Address: 0x180027288)
- OutputDebugStringA (Address: 0x180027298)
- OutputDebugStringW (Address: 0x180027280)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800272a8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800272b8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800272d8)
- RaiseException (Address: 0x1800272e0)
- SetLastError (Address: 0x1800272c8)
- SetUnhandledExceptionFilter (Address: 0x1800272e8)
- UnhandledExceptionFilter (Address: 0x1800272d0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800272f8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180027310)
- HeapAlloc (Address: 0x180027308)
- HeapFree (Address: 0x180027318)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180027328)
- LocalFree (Address: 0x180027330)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x180027360)
- GetModuleFileNameA (Address: 0x180027350)
- GetModuleHandleExW (Address: 0x180027348)
- GetModuleHandleW (Address: 0x180027358)
- GetProcAddress (Address: 0x180027340)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x180027370)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x180027388)
- GetCurrentProcessId (Address: 0x180027390)
- GetCurrentThread (Address: 0x1800273a0)
- GetCurrentThreadId (Address: 0x1800273a8)
- OpenProcessToken (Address: 0x1800273b0)
- OpenThreadToken (Address: 0x180027398)
- TerminateProcess (Address: 0x180027380)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x1800273c0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800273d0)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800273e8)
- RtlLookupFunctionEntry (Address: 0x1800273f0)
- RtlVirtualUnwind (Address: 0x1800273e0)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x180027400)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180027478)
- AcquireSRWLockShared (Address: 0x180027470)
- CreateEventExW (Address: 0x180027420)
- CreateMutexExW (Address: 0x180027490)
- CreateSemaphoreExW (Address: 0x180027448)
- DeleteCriticalSection (Address: 0x180027480)
- EnterCriticalSection (Address: 0x180027430)
- InitializeCriticalSectionEx (Address: 0x180027418)
- InitializeSRWLock (Address: 0x180027440)
- LeaveCriticalSection (Address: 0x180027488)
- OpenSemaphoreW (Address: 0x180027468)
- ReleaseMutex (Address: 0x180027438)
- ReleaseSemaphore (Address: 0x180027410)
- ReleaseSRWLockExclusive (Address: 0x180027458)
- ReleaseSRWLockShared (Address: 0x180027498)
- SetEvent (Address: 0x180027450)
- WaitForSingleObject (Address: 0x180027428)
- WaitForSingleObjectEx (Address: 0x180027460)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceExecuteOnce (Address: 0x1800274b0)
- Sleep (Address: 0x1800274a8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1800274d0)
- GetTickCount (Address: 0x1800274c8)
- GetTickCount64 (Address: 0x1800274c0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1800274e0)
- CreateThreadpoolTimer (Address: 0x1800274f8)
- SetThreadpoolTimer (Address: 0x1800274f0)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800274e8)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- QueueUserWorkItem (Address: 0x180027508)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x180027520)
- EncodePointer (Address: 0x180027518)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x180027538)
- RoOriginateError (Address: 0x180027530)
- RoOriginateErrorW (Address: 0x180027540)
- RoTransformError (Address: 0x180027550)
- SetRestrictedErrorInfo (Address: 0x180027548)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x180027568)
- RoGetMatchingRestrictedErrorInfo (Address: 0x180027560)
- RoReportFailedDelegate (Address: 0x180027570)
api-ms-win-core-winrt-l1-1-0.dll
- RoGetActivationFactory (Address: 0x180027588)
- RoInitialize (Address: 0x180027580)
- RoUninitialize (Address: 0x180027590)
api-ms-win-core-winrt-string-l1-1-0.dll
- HSTRING_UserFree (Address: 0x1800275d8)
- HSTRING_UserFree64 (Address: 0x1800275b8)
- HSTRING_UserMarshal (Address: 0x1800275c0)
- HSTRING_UserMarshal64 (Address: 0x180027608)
- HSTRING_UserSize (Address: 0x1800275c8)
- HSTRING_UserSize64 (Address: 0x1800275b0)
- HSTRING_UserUnmarshal (Address: 0x1800275a8)
- HSTRING_UserUnmarshal64 (Address: 0x1800275d0)
- WindowsCreateString (Address: 0x1800275e0)
- WindowsCreateStringReference (Address: 0x1800275a0)
- WindowsDeleteString (Address: 0x180027600)
- WindowsDuplicateString (Address: 0x180027610)
- WindowsGetStringRawBuffer (Address: 0x1800275e8)
- WindowsIsStringEmpty (Address: 0x1800275f0)
- WindowsStringHasEmbeddedNull (Address: 0x1800275f8)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x180027628)
- EventUnregister (Address: 0x180027630)
- EventWriteTransfer (Address: 0x180027620)
api-ms-win-security-base-l1-1-0.dll
- AllocateAndInitializeSid (Address: 0x180027650)
- CopySid (Address: 0x180027660)
- FreeSid (Address: 0x180027640)
- GetLengthSid (Address: 0x180027658)
- GetTokenInformation (Address: 0x180027648)
api-ms-win-security-base-l1-2-0.dll
- CheckTokenCapability (Address: 0x180027670)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x180027680)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolAllowThreadReuse (Address: 0x180027690)
- SHTaskPoolQueueTask (Address: 0x180027698)
CRYPT32.dll
- CertNameToStrW (Address: 0x180027060)
- CryptAcquireCertificatePrivateKey (Address: 0x180027068)
- CryptHashCertificate (Address: 0x180027070)
msvcrt.dll
- __C_specific_handler (Address: 0x180027710)
- __CxxFrameHandler3 (Address: 0x180027700)
- __dllonexit (Address: 0x1800276e8)
- _amsg_exit (Address: 0x180027728)
- _callnewh (Address: 0x1800276d0)
- _errno (Address: 0x1800276b0)
- _initterm (Address: 0x180027718)
- _lock (Address: 0x1800276f8)
- _onexit (Address: 0x1800276e0)
- _purecall (Address: 0x180027738)
- _unlock (Address: 0x1800276f0)
- _vsnwprintf (Address: 0x1800276a8)
- _XcptFilter (Address: 0x180027730)
- free (Address: 0x180027740)
- malloc (Address: 0x180027720)
- memcmp (Address: 0x1800276b8)
- memcpy (Address: 0x180027708)
- memmove (Address: 0x1800276d8)
- memmove_s (Address: 0x1800276c8)
- memset (Address: 0x180027748)
- realloc (Address: 0x1800276c0)
ncrypt.dll
- NCryptFreeObject (Address: 0x180027760)
- NCryptSignHash (Address: 0x180027758)
ntdll.dll
- LdrDisableThreadCalloutsForDll (Address: 0x180027778)
- RtlImageNtHeader (Address: 0x180027770)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x180027090)
- CStdStubBuffer_Connect (Address: 0x1800270b0)
- CStdStubBuffer_CountRefs (Address: 0x1800270b8)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800270d8)
- CStdStubBuffer_DebugServerRelease (Address: 0x180027080)
- CStdStubBuffer_Disconnect (Address: 0x180027108)
- CStdStubBuffer_Invoke (Address: 0x180027110)
- CStdStubBuffer_IsIIDSupported (Address: 0x1800270d0)
- CStdStubBuffer_QueryInterface (Address: 0x1800270c8)
- IUnknown_AddRef_Proxy (Address: 0x1800270a8)
- IUnknown_QueryInterface_Proxy (Address: 0x1800270f8)
- IUnknown_Release_Proxy (Address: 0x180027088)
- NdrCStdStubBuffer_Release (Address: 0x1800270e0)
- NdrCStdStubBuffer2_Release (Address: 0x180027118)
- NdrDllCanUnloadNow (Address: 0x1800270f0)
- NdrDllGetClassObject (Address: 0x180027100)
- NdrOleAllocate (Address: 0x1800270a0)
- NdrOleFree (Address: 0x180027098)
- NdrStubCall3 (Address: 0x1800270e8)
- NdrStubForwardingFunction (Address: 0x1800270c0)