userenv.dll

Description: Userenv

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: c515d413b083c785a0549a78fb0803b1

File Size: 174.1 KB

Uploaded At: Dec. 1, 2025, 7:41 a.m.

Views: 10

Exported Functions

  • (Ordinal: 104, Address: 0xf640)
  • RsopLoggingEnabled (Ordinal: 105, Address: 0x99f0)
  • AreThereVisibleLogoffScripts (Ordinal: 106, Address: 0x9a10)
  • AreThereVisibleShutdownScripts (Ordinal: 107, Address: 0x9a30)
  • CreateAppContainerProfile (Ordinal: 108, Address: 0x4750)
  • CreateEnvironmentBlock (Ordinal: 109, Address: 0x48c0)
  • CreateProfile (Ordinal: 110, Address: 0x12380)
  • DeleteAppContainerProfile (Ordinal: 111, Address: 0xf5e0)
  • DeleteProfileA (Ordinal: 112, Address: 0x129a0)
  • DeleteProfileW (Ordinal: 113, Address: 0x12500)
  • DeriveAppContainerSidFromAppContainerName (Ordinal: 114, Address: 0x4660)
  • DeriveRestrictedAppContainerSidFromAppContainerSidAndRestrictedName (Ordinal: 115, Address: 0x43a0)
  • DestroyEnvironmentBlock (Ordinal: 116, Address: 0x4890)
  • DllCanUnloadNow (Ordinal: 117, Address: 0x133a0)
  • DllGetClassObject (Ordinal: 118, Address: 0x133c0)
  • DllRegisterServer (Ordinal: 119, Address: 0x13410)
  • DllUnregisterServer (Ordinal: 120, Address: 0x13450)
  • EnterCriticalPolicySection (Ordinal: 121, Address: 0x4a60)
  • (Ordinal: 122, Address: 0xf680)
  • ExpandEnvironmentStringsForUserA (Ordinal: 123, Address: 0x12aa0)
  • ExpandEnvironmentStringsForUserW (Ordinal: 124, Address: 0x4200)
  • ForceSyncFgPolicy (Ordinal: 125, Address: 0x9a50)
  • FreeGPOListA (Ordinal: 126, Address: 0x9a70)
  • FreeGPOListW (Ordinal: 127, Address: 0x9a90)
  • GenerateGPNotification (Ordinal: 128, Address: 0x9ab0)
  • GetAllUsersProfileDirectoryA (Ordinal: 129, Address: 0x12ba0)
  • GetAllUsersProfileDirectoryW (Ordinal: 130, Address: 0x12cc0)
  • GetAppContainerFolderPath (Ordinal: 131, Address: 0x44e0)
  • GetAppContainerRegistryLocation (Ordinal: 132, Address: 0x4240)
  • GetAppliedGPOListA (Ordinal: 133, Address: 0x9ad0)
  • GetAppliedGPOListW (Ordinal: 134, Address: 0x49c0)
  • (Ordinal: 135, Address: 0x13be0)
  • GetDefaultUserProfileDirectoryA (Ordinal: 136, Address: 0x12ce0)
  • (Ordinal: 137, Address: 0xf4b0)
  • GetDefaultUserProfileDirectoryW (Ordinal: 138, Address: 0x1210)
  • (Ordinal: 139, Address: 0xf510)
  • GetGPOListA (Ordinal: 140, Address: 0x9af0)
  • GetGPOListW (Ordinal: 141, Address: 0x9b10)
  • GetNextFgPolicyRefreshInfo (Ordinal: 142, Address: 0x9b30)
  • GetPreviousFgPolicyRefreshInfo (Ordinal: 143, Address: 0x9b50)
  • GetProfileType (Ordinal: 144, Address: 0x3610)
  • GetProfilesDirectoryA (Ordinal: 145, Address: 0x12e00)
  • GetProfilesDirectoryW (Ordinal: 146, Address: 0x4ab0)
  • GetUserProfileDirectoryA (Ordinal: 147, Address: 0x12f20)
  • GetUserProfileDirectoryW (Ordinal: 148, Address: 0x28d0)
  • HasPolicyForegroundProcessingCompleted (Ordinal: 149, Address: 0x9b70)
  • LeaveCriticalPolicySection (Ordinal: 150, Address: 0x4a40)
  • LoadProfileExtender (Ordinal: 151, Address: 0x12540)
  • LoadUserProfileA (Ordinal: 152, Address: 0x13040)
  • LoadUserProfileW (Ordinal: 153, Address: 0x1530)
  • ProcessGroupPolicyCompleted (Ordinal: 154, Address: 0xf790)
  • ProcessGroupPolicyCompletedEx (Ordinal: 155, Address: 0xf7f0)
  • RefreshPolicy (Ordinal: 156, Address: 0x9b90)
  • RefreshPolicyEx (Ordinal: 157, Address: 0x9bb0)
  • RegisterGPNotification (Ordinal: 158, Address: 0x48f0)
  • RsopAccessCheckByType (Ordinal: 159, Address: 0xf860)
  • RsopFileAccessCheck (Ordinal: 160, Address: 0xf920)
  • RsopResetPolicySettingStatus (Ordinal: 161, Address: 0xf990)
  • RsopSetPolicySettingStatus (Ordinal: 162, Address: 0xf9f0)
  • UnloadProfileExtender (Ordinal: 163, Address: 0x127e0)
  • UnloadUserProfile (Ordinal: 164, Address: 0x1230)
  • UnregisterGPNotification (Ordinal: 165, Address: 0x4980)
  • WaitForMachinePolicyForegroundProcessing (Ordinal: 166, Address: 0x9bd0)
  • WaitForUserPolicyForegroundProcessing (Ordinal: 167, Address: 0x9bf0)
  • (Ordinal: 175, Address: 0x13a00)
  • (Ordinal: 202, Address: 0x13390)
  • (Ordinal: 203, Address: 0x13370)
  • (Ordinal: 206, Address: 0xf440)
  • (Ordinal: 207, Address: 0xf470)
  • (Ordinal: 208, Address: 0x12670)
  • (Ordinal: 209, Address: 0x13380)
  • (Ordinal: 210, Address: 0xfa60)
  • (Ordinal: 211, Address: 0xf740)
  • (Ordinal: 212, Address: 0x4780)
  • (Ordinal: 213, Address: 0xf5f0)
  • (Ordinal: 214, Address: 0x13490)
  • (Ordinal: 217, Address: 0x4ad0)
  • (Ordinal: 218, Address: 0xf6e0)
  • (Ordinal: 219, Address: 0x7aa0)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18001cd08)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18001cd28)
  • IsDebuggerPresent (Address: 0x18001cd20)
  • OutputDebugStringW (Address: 0x18001cd18)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18001cd38)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18001cd48)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18001cd58)
  • SetLastError (Address: 0x18001cd68)
  • SetUnhandledExceptionFilter (Address: 0x18001cd60)
  • UnhandledExceptionFilter (Address: 0x18001cd70)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18001cd80)
  • CreateDirectoryW (Address: 0x18001cdb8)
  • CreateFileW (Address: 0x18001cde8)
  • DeleteFileW (Address: 0x18001cdd0)
  • FindClose (Address: 0x18001cd98)
  • FindFirstFileW (Address: 0x18001cde0)
  • FindNextFileW (Address: 0x18001cdc8)
  • FlushFileBuffers (Address: 0x18001cd90)
  • GetDiskFreeSpaceExW (Address: 0x18001cdb0)
  • GetFileAttributesExW (Address: 0x18001cd88)
  • GetFileAttributesW (Address: 0x18001cda8)
  • RemoveDirectoryW (Address: 0x18001cdd8)
  • SetFileAttributesW (Address: 0x18001cda0)
  • SetFileTime (Address: 0x18001cdc0)
api-ms-win-core-file-l2-1-0.dll
  • GetFileInformationByHandleEx (Address: 0x18001ce00)
  • MoveFileExW (Address: 0x18001cdf8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18001ce10)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18001ce20)
  • HeapAlloc (Address: 0x18001ce28)
  • HeapFree (Address: 0x18001ce30)
  • HeapReAlloc (Address: 0x18001ce38)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18001ce48)
  • LocalFree (Address: 0x18001ce50)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x18001ce60)
api-ms-win-core-kernel32-private-l1-1-1.dll
  • PrivCopyFileExW (Address: 0x18001ce70)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18001ce98)
  • FindResourceExW (Address: 0x18001ceb8)
  • GetModuleFileNameA (Address: 0x18001ce90)
  • GetModuleHandleExW (Address: 0x18001ceb0)
  • GetModuleHandleW (Address: 0x18001ce80)
  • GetProcAddress (Address: 0x18001ce88)
  • LoadResource (Address: 0x18001cea8)
  • LockResource (Address: 0x18001cea0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18001cec8)
api-ms-win-core-path-l1-1-0.dll
  • PathCchAddBackslashEx (Address: 0x18001ced8)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18001cee8)
  • GetCommandLineW (Address: 0x18001cef0)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x18001cf10)
  • GetCurrentProcess (Address: 0x18001cf40)
  • GetCurrentProcessId (Address: 0x18001cf18)
  • GetCurrentThread (Address: 0x18001cf00)
  • GetCurrentThreadId (Address: 0x18001cf08)
  • OpenProcessToken (Address: 0x18001cf30)
  • OpenThreadToken (Address: 0x18001cf38)
  • SetThreadToken (Address: 0x18001cf20)
  • TerminateProcess (Address: 0x18001cf28)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x18001cf50)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18001cf60)
api-ms-win-core-psapi-l1-1-0.dll
  • QueryFullProcessImageNameW (Address: 0x18001cf70)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18001cf90)
  • RegGetValueW (Address: 0x18001cf88)
  • RegOpenKeyExW (Address: 0x18001cf80)
  • RegQueryValueExW (Address: 0x18001cf98)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18001cfa8)
  • RtlLookupFunctionEntry (Address: 0x18001cfb8)
  • RtlVirtualUnwind (Address: 0x18001cfb0)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x18001cfd0)
  • CompareStringW (Address: 0x18001cfc8)
  • MultiByteToWideChar (Address: 0x18001cfe0)
  • WideCharToMultiByte (Address: 0x18001cfd8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18001d070)
  • AcquireSRWLockShared (Address: 0x18001d050)
  • CreateEventW (Address: 0x18001d008)
  • CreateMutexExW (Address: 0x18001d058)
  • CreateSemaphoreExW (Address: 0x18001d068)
  • DeleteCriticalSection (Address: 0x18001d048)
  • EnterCriticalSection (Address: 0x18001cff8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18001d030)
  • InitializeCriticalSectionEx (Address: 0x18001d028)
  • LeaveCriticalSection (Address: 0x18001d018)
  • OpenSemaphoreW (Address: 0x18001d078)
  • ReleaseMutex (Address: 0x18001d040)
  • ReleaseSemaphore (Address: 0x18001d010)
  • ReleaseSRWLockExclusive (Address: 0x18001d060)
  • ReleaseSRWLockShared (Address: 0x18001cff0)
  • SetEvent (Address: 0x18001d020)
  • WaitForMultipleObjectsEx (Address: 0x18001d000)
  • WaitForSingleObject (Address: 0x18001d038)
  • WaitForSingleObjectEx (Address: 0x18001d080)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x18001d098)
  • InitOnceComplete (Address: 0x18001d090)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x18001d0b0)
  • GetSystemTimeAsFileTime (Address: 0x18001d0a8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18001d0c0)
  • CreateThreadpoolTimer (Address: 0x18001d0d0)
  • SetThreadpoolTimer (Address: 0x18001d0d8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18001d0c8)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x18001d0e8)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x18001d1a0)
  • __CxxFrameHandler4 (Address: 0x18001d1b0)
  • __std_terminate (Address: 0x18001d1a8)
  • _CxxThrowException (Address: 0x18001d1b8)
  • _o___std_exception_copy (Address: 0x18001d198)
  • _o___std_exception_destroy (Address: 0x18001d190)
  • _o___std_type_info_destroy_list (Address: 0x18001d188)
  • _o___stdio_common_vsnprintf_s (Address: 0x18001d180)
  • _o___stdio_common_vswprintf (Address: 0x18001d178)
  • _o__cexit (Address: 0x18001d168)
  • _o__configure_narrow_argv (Address: 0x18001d160)
  • _o__crt_atexit (Address: 0x18001d150)
  • _o__errno (Address: 0x18001d170)
  • _o__execute_onexit_table (Address: 0x18001d158)
  • _o__get_errno (Address: 0x18001d0f8)
  • _o__initialize_narrow_environment (Address: 0x18001d100)
  • _o__initialize_onexit_table (Address: 0x18001d108)
  • _o__invalid_parameter_noinfo (Address: 0x18001d110)
  • _o__purecall (Address: 0x18001d118)
  • _o__register_onexit_function (Address: 0x18001d120)
  • _o__seh_filter_dll (Address: 0x18001d128)
  • _o__set_errno (Address: 0x18001d130)
  • _o_free (Address: 0x18001d140)
  • _o_malloc (Address: 0x18001d148)
  • memcmp (Address: 0x18001d1c0)
  • memcpy (Address: 0x18001d1c8)
  • memmove (Address: 0x18001d138)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x18001d1e0)
  • _initterm_e (Address: 0x18001d1d8)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x18001d1f0)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x18001d200)
  • EventWriteTransfer (Address: 0x18001d208)
api-ms-win-security-base-l1-1-0.dll
  • AllocateAndInitializeSid (Address: 0x18001d230)
  • CopySid (Address: 0x18001d268)
  • EqualSid (Address: 0x18001d220)
  • FreeSid (Address: 0x18001d228)
  • GetFileSecurityW (Address: 0x18001d238)
  • GetLengthSid (Address: 0x18001d250)
  • GetSecurityDescriptorOwner (Address: 0x18001d218)
  • GetTokenInformation (Address: 0x18001d248)
  • ImpersonateLoggedOnUser (Address: 0x18001d258)
  • ImpersonateSelf (Address: 0x18001d260)
  • PrivilegeCheck (Address: 0x18001d270)
  • RevertToSelf (Address: 0x18001d240)
api-ms-win-security-grouppolicy-l1-1-0.dll
  • AreThereVisibleLogoffScriptsInternal (Address: 0x18001d2f8)
  • AreThereVisibleShutdownScriptsInternal (Address: 0x18001d2c0)
  • EnterCriticalPolicySectionInternal (Address: 0x18001d2b0)
  • ForceSyncFgPolicyInternal (Address: 0x18001d288)
  • FreeGPOListInternalA (Address: 0x18001d308)
  • FreeGPOListInternalW (Address: 0x18001d2d0)
  • GenerateGPNotificationInternal (Address: 0x18001d2b8)
  • GetAppliedGPOListInternalA (Address: 0x18001d2a8)
  • GetAppliedGPOListInternalW (Address: 0x18001d2a0)
  • GetGPOListInternalA (Address: 0x18001d2f0)
  • GetGPOListInternalW (Address: 0x18001d328)
  • GetNextFgPolicyRefreshInfoInternal (Address: 0x18001d2e8)
  • GetPreviousFgPolicyRefreshInfoInternal (Address: 0x18001d280)
  • HasPolicyForegroundProcessingCompletedInternal (Address: 0x18001d298)
  • LeaveCriticalPolicySectionInternal (Address: 0x18001d2c8)
  • RefreshPolicyExInternal (Address: 0x18001d2d8)
  • RefreshPolicyInternal (Address: 0x18001d320)
  • RegisterGPNotificationInternal (Address: 0x18001d290)
  • RsopLoggingEnabledInternal (Address: 0x18001d318)
  • UnregisterGPNotificationInternal (Address: 0x18001d310)
  • WaitForMachinePolicyForegroundProcessingInternal (Address: 0x18001d2e0)
  • WaitForUserPolicyForegroundProcessingInternal (Address: 0x18001d300)
ntdll.dll
  • EtwEventActivityIdControl (Address: 0x18001d378)
  • EtwEventRegister (Address: 0x18001d350)
  • EtwEventSetInformation (Address: 0x18001d368)
  • EtwEventUnregister (Address: 0x18001d360)
  • EtwEventWriteTransfer (Address: 0x18001d380)
  • NtClose (Address: 0x18001d340)
  • RtlAdjustPrivilege (Address: 0x18001d370)
  • RtlFreeUnicodeString (Address: 0x18001d348)
  • RtlNtStatusToDosError (Address: 0x18001d358)
  • RtlStringFromGUID (Address: 0x18001d338)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x18001cc68)
  • CStdStubBuffer_Connect (Address: 0x18001ccb0)
  • CStdStubBuffer_CountRefs (Address: 0x18001cce8)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x18001cc28)
  • CStdStubBuffer_DebugServerRelease (Address: 0x18001ccd0)
  • CStdStubBuffer_Disconnect (Address: 0x18001ccc8)
  • CStdStubBuffer_Invoke (Address: 0x18001cca8)
  • CStdStubBuffer_IsIIDSupported (Address: 0x18001ccb8)
  • CStdStubBuffer_QueryInterface (Address: 0x18001cce0)
  • I_RpcExceptionFilter (Address: 0x18001cc38)
  • IUnknown_AddRef_Proxy (Address: 0x18001ccf8)
  • IUnknown_QueryInterface_Proxy (Address: 0x18001ccc0)
  • IUnknown_Release_Proxy (Address: 0x18001ccf0)
  • NdrClientCall3 (Address: 0x18001cc70)
  • NdrCStdStubBuffer_Release (Address: 0x18001cca0)
  • NdrDllCanUnloadNow (Address: 0x18001cc98)
  • NdrDllGetClassObject (Address: 0x18001cc90)
  • NdrDllRegisterProxy (Address: 0x18001cc88)
  • NdrDllUnregisterProxy (Address: 0x18001cc80)
  • NdrOleAllocate (Address: 0x18001ccd8)
  • NdrOleFree (Address: 0x18001cc48)
  • RpcBindingFree (Address: 0x18001cc50)
  • RpcBindingFromStringBindingW (Address: 0x18001cc60)
  • RpcBindingSetAuthInfoExW (Address: 0x18001cc20)
  • RpcRevertToSelf (Address: 0x18001cc40)
  • RpcStringBindingComposeW (Address: 0x18001cc58)
  • RpcStringFreeW (Address: 0x18001cc30)
  • UuidCreate (Address: 0x18001cc78)