vmcompute.dll

Description: Hyper-V Host Compute Service Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5129

Architecture: 64-bit

Operating System: Windows NT

SHA256: 6cb00235cca76e8df249126004d68d4b

File Size: 660.5 KB

Uploaded At: Dec. 1, 2025, 7:42 a.m.

Views: 8

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • HcsEnumerateVmWorkerProcesses (Ordinal: 1, Address: 0x280d0)
  • HcsFindVmWorkerProcesses (Ordinal: 2, Address: 0x28250)
  • HcsGetWorkerProcessJob (Ordinal: 3, Address: 0x28320)
  • HcsStartVmWorkerProcess (Ordinal: 4, Address: 0x27fd0)
  • ActivateLayer (Ordinal: 5, Address: 0x20300)
  • ApplyRegistryChangesToLayer (Ordinal: 6, Address: 0x208c0)
  • ComputeSystemExists (Ordinal: 7, Address: 0x181a0)
  • CreateBaseImageVHD (Ordinal: 8, Address: 0x21ee0)
  • CreateBaseImageVHDWithFolders (Ordinal: 9, Address: 0x22080)
  • CreateComputeSystem (Ordinal: 10, Address: 0x179a0)
  • CreateDifferencingVHD (Ordinal: 11, Address: 0x22060)
  • CreateLayer (Ordinal: 12, Address: 0x200d0)
  • CreateProcessInComputeSystem (Ordinal: 13, Address: 0x188d0)
  • CreateProcessWithStdHandlesInComputeSystem (Ordinal: 14, Address: 0x18330)
  • CreateSandboxLayer (Ordinal: 15, Address: 0x206f0)
  • DeactivateLayer (Ordinal: 16, Address: 0x20540)
  • DestroyLayer (Ordinal: 17, Address: 0x201d0)
  • DismountVhdByHandle (Ordinal: 18, Address: 0x238e0)
  • EnumerateComputeSystems (Ordinal: 19, Address: 0x17990)
  • ExpandSandboxSize (Ordinal: 20, Address: 0x20e50)
  • ExportLayer (Ordinal: 21, Address: 0x21720)
  • GetComputeSystemProperties (Ordinal: 22, Address: 0x18230)
  • GetHostProperties (Ordinal: 23, Address: 0x18e60)
  • GetLayerMountPath (Ordinal: 24, Address: 0x20610)
  • GrantVmAccess (Ordinal: 25, Address: 0x21d60)
  • GrantVmGroupAccess (Ordinal: 26, Address: 0x21d30)
  • HNSCall (Ordinal: 27, Address: 0x27e40)
  • HcsAddComputeSystemResource (Ordinal: 28, Address: 0xfc70)
  • HcsCloseComputeSystem (Ordinal: 29, Address: 0xdfa0)
  • HcsCloseProcess (Ordinal: 30, Address: 0x10590)
  • HcsCrashComputeSystem (Ordinal: 31, Address: 0xe980)
  • HcsCreateComputeSystem (Ordinal: 32, Address: 0xdc70)
  • HcsCreateProcess (Ordinal: 33, Address: 0xfff0)
  • HcsEnumerateComputeSystems (Ordinal: 34, Address: 0xda70)
  • HcsGetComputeSystemProperties (Ordinal: 35, Address: 0xf650)
  • HcsGetProcessInfo (Ordinal: 36, Address: 0x109c0)
  • HcsGetProcessProperties (Ordinal: 37, Address: 0x10d60)
  • HcsGetServiceProperties (Ordinal: 38, Address: 0x11640)
  • HcsModifyComputeSystem (Ordinal: 39, Address: 0xf8e0)
  • HcsModifyComputeSystemResource (Ordinal: 40, Address: 0xfc70)
  • HcsModifyComputeSystemWithUserToken (Ordinal: 41, Address: 0xf900)
  • HcsModifyProcess (Ordinal: 42, Address: 0x10fe0)
  • HcsModifyServiceSettings (Ordinal: 43, Address: 0x11860)
  • HcsOpenComputeSystem (Ordinal: 44, Address: 0xde60)
  • HcsOpenProcess (Ordinal: 45, Address: 0x103f0)
  • HcsPauseComputeSystem (Ordinal: 46, Address: 0xed20)
  • HcsRegisterComputeSystemCallback (Ordinal: 47, Address: 0xfc80)
  • HcsRegisterProcessCallback (Ordinal: 48, Address: 0x112e0)
  • HcsRemoveComputeSystemResource (Ordinal: 49, Address: 0xfc70)
  • HcsResumeComputeSystem (Ordinal: 50, Address: 0xf030)
  • HcsSaveComputeSystem (Ordinal: 51, Address: 0xf340)
  • HcsShutdownComputeSystem (Ordinal: 52, Address: 0xe380)
  • HcsSignalProcess (Ordinal: 53, Address: 0x106d0)
  • HcsStartComputeSystem (Ordinal: 54, Address: 0xe070)
  • HcsSubmitWerReport (Ordinal: 55, Address: 0x119d0)
  • HcsTerminateComputeSystem (Ordinal: 56, Address: 0xe720)
  • HcsTerminateProcess (Ordinal: 57, Address: 0x109b0)
  • HcsUnregisterComputeSystemCallback (Ordinal: 58, Address: 0xfe60)
  • HcsUnregisterProcessCallback (Ordinal: 59, Address: 0x114c0)
  • ImportLayer (Ordinal: 60, Address: 0x21ac0)
  • LayerExists (Ordinal: 61, Address: 0x20070)
  • ModifyComputeSystemResource (Ordinal: 62, Address: 0x182b0)
  • MountVhdForSetup (Ordinal: 63, Address: 0x23830)
  • NameToGuid (Ordinal: 64, Address: 0x21c80)
  • PrepareLayer (Ordinal: 65, Address: 0x212c0)
  • PrepareLayerEx (Ordinal: 66, Address: 0x212e0)
  • ProcessBaseImage (Ordinal: 67, Address: 0x23770)
  • ProcessHostImage (Ordinal: 68, Address: 0x237a0)
  • ProcessImage (Ordinal: 69, Address: 0x22870)
  • ProcessImageEx (Ordinal: 70, Address: 0x22890)
  • ProcessUtilityHostImage (Ordinal: 71, Address: 0x23800)
  • ProcessUtilityImage (Ordinal: 72, Address: 0x237d0)
  • ResizeConsoleInComputeSystem (Ordinal: 73, Address: 0x18900)
  • RevokeVmAccess (Ordinal: 74, Address: 0x21e20)
  • ShutdownComputeSystem (Ordinal: 75, Address: 0x17d70)
  • StartComputeSystem (Ordinal: 76, Address: 0x17b80)
  • TerminateComputeSystem (Ordinal: 77, Address: 0x17fb0)
  • TerminateProcessInComputeSystem (Ordinal: 78, Address: 0x18da0)
  • UnprepareLayer (Ordinal: 79, Address: 0x21590)
  • UnprepareLayerEx (Ordinal: 80, Address: 0x215a0)
  • WaitForProcessInComputeSystem (Ordinal: 81, Address: 0x18a70)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCancelCall (Address: 0x180079780)
  • CoCreateInstance (Address: 0x1800797a0)
  • CoDisableCallCancellation (Address: 0x180079788)
  • CoEnableCallCancellation (Address: 0x180079790)
  • CoGetObjectContext (Address: 0x1800797b8)
  • CoInitializeEx (Address: 0x180079798)
  • CoTaskMemAlloc (Address: 0x1800797a8)
  • CoTaskMemFree (Address: 0x1800797c0)
  • CoUninitialize (Address: 0x1800797b0)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800797e0)
  • IsDebuggerPresent (Address: 0x1800797d8)
  • OutputDebugStringW (Address: 0x1800797d0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800797f0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180079800)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180079810)
  • RaiseException (Address: 0x180079830)
  • SetLastError (Address: 0x180079820)
  • SetUnhandledExceptionFilter (Address: 0x180079828)
  • UnhandledExceptionFilter (Address: 0x180079818)
api-ms-win-core-errorhandling-l1-1-2.dll
  • RaiseFailFastException (Address: 0x180079840)
api-ms-win-core-featurestaging-l1-1-0.dll
  • RecordFeatureUsage (Address: 0x180079860)
  • SubscribeFeatureStateChangeNotification (Address: 0x180079850)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x180079858)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x1800798e0)
  • CreateFileW (Address: 0x1800798e8)
  • DeleteFileW (Address: 0x180079870)
  • FindClose (Address: 0x180079898)
  • FindFirstFileW (Address: 0x180079888)
  • FindFirstVolumeW (Address: 0x1800798c0)
  • FindNextFileW (Address: 0x180079890)
  • FindNextVolumeW (Address: 0x1800798d0)
  • FindVolumeClose (Address: 0x1800798c8)
  • FlushFileBuffers (Address: 0x1800798d8)
  • GetFileAttributesW (Address: 0x1800798f0)
  • GetFileSizeEx (Address: 0x1800798b8)
  • GetFinalPathNameByHandleW (Address: 0x1800798a0)
  • GetVolumePathNameW (Address: 0x1800798a8)
  • ReadFile (Address: 0x1800798b0)
  • SetFileAttributesW (Address: 0x180079880)
  • WriteFile (Address: 0x180079878)
api-ms-win-core-file-l2-1-0.dll
  • CopyFile2 (Address: 0x180079908)
  • CreateHardLinkW (Address: 0x180079900)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180079918)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180079930)
  • HeapAlloc (Address: 0x180079928)
  • HeapFree (Address: 0x180079938)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x180079948)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180079958)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x180079968)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x180079990)
  • GetModuleFileNameA (Address: 0x180079978)
  • GetModuleFileNameW (Address: 0x180079980)
  • GetModuleHandleExW (Address: 0x180079988)
  • GetModuleHandleW (Address: 0x1800799a8)
  • GetProcAddress (Address: 0x1800799a0)
  • LoadLibraryExW (Address: 0x180079998)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800799b8)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x1800799d0)
  • MapViewOfFile (Address: 0x1800799d8)
  • UnmapViewOfFile (Address: 0x1800799c8)
api-ms-win-core-path-l1-1-0.dll
  • PathCchAddBackslash (Address: 0x1800799f0)
  • PathCchCombineEx (Address: 0x1800799f8)
  • PathCchFindExtension (Address: 0x180079a00)
  • PathCchRemoveFileSpec (Address: 0x1800799e8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180079a38)
  • GetCurrentProcessId (Address: 0x180079a20)
  • GetCurrentThread (Address: 0x180079a10)
  • GetCurrentThreadId (Address: 0x180079a18)
  • OpenThreadToken (Address: 0x180079a28)
  • TerminateProcess (Address: 0x180079a50)
  • TlsAlloc (Address: 0x180079a30)
  • TlsFree (Address: 0x180079a58)
  • TlsGetValue (Address: 0x180079a40)
  • TlsSetValue (Address: 0x180079a48)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180079a68)
  • OpenProcess (Address: 0x180079a70)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180079a88)
  • QueryPerformanceFrequency (Address: 0x180079a80)
api-ms-win-core-psapi-l1-1-0.dll
  • K32GetModuleInformation (Address: 0x180079a98)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180079aa8)
  • RegDeleteValueW (Address: 0x180079ad0)
  • RegEnumKeyExW (Address: 0x180079ac8)
  • RegGetValueW (Address: 0x180079ab0)
  • RegOpenKeyExW (Address: 0x180079ab8)
  • RegQueryInfoKeyW (Address: 0x180079ac0)
  • RegSetValueExW (Address: 0x180079ad8)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180079b08)
  • RtlCaptureStackBackTrace (Address: 0x180079af0)
  • RtlLookupFunctionEntry (Address: 0x180079b00)
  • RtlPcToFileHeader (Address: 0x180079ae8)
  • RtlVirtualUnwind (Address: 0x180079af8)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFileExistsW (Address: 0x180079b28)
  • PathIsRelativeW (Address: 0x180079b18)
  • PathIsUNCServerShareW (Address: 0x180079b20)
  • PathIsUNCServerW (Address: 0x180079b38)
  • PathSkipRootW (Address: 0x180079b30)
api-ms-win-core-string-l1-1-0.dll
  • WideCharToMultiByte (Address: 0x180079b48)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180079b88)
  • AcquireSRWLockShared (Address: 0x180079b78)
  • CreateEventExW (Address: 0x180079b90)
  • CreateEventW (Address: 0x180079bb8)
  • CreateMutexExW (Address: 0x180079ba0)
  • CreateSemaphoreExW (Address: 0x180079b60)
  • DeleteCriticalSection (Address: 0x180079b98)
  • EnterCriticalSection (Address: 0x180079ba8)
  • InitializeCriticalSection (Address: 0x180079b70)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180079bd8)
  • InitializeCriticalSectionEx (Address: 0x180079bc8)
  • InitializeSRWLock (Address: 0x180079be8)
  • LeaveCriticalSection (Address: 0x180079bd0)
  • OpenSemaphoreW (Address: 0x180079c08)
  • ReleaseMutex (Address: 0x180079bb0)
  • ReleaseSemaphore (Address: 0x180079b58)
  • ReleaseSRWLockExclusive (Address: 0x180079bf8)
  • ReleaseSRWLockShared (Address: 0x180079bf0)
  • ResetEvent (Address: 0x180079b80)
  • SetEvent (Address: 0x180079be0)
  • TryAcquireSRWLockExclusive (Address: 0x180079c00)
  • WaitForSingleObject (Address: 0x180079bc0)
  • WaitForSingleObjectEx (Address: 0x180079b68)
api-ms-win-core-synch-l1-2-0.dll
  • InitializeConditionVariable (Address: 0x180079c58)
  • InitOnceBeginInitialize (Address: 0x180079c28)
  • InitOnceComplete (Address: 0x180079c38)
  • InitOnceExecuteOnce (Address: 0x180079c18)
  • SleepConditionVariableSRW (Address: 0x180079c40)
  • WaitOnAddress (Address: 0x180079c48)
  • WakeAllConditionVariable (Address: 0x180079c20)
  • WakeByAddressAll (Address: 0x180079c30)
  • WakeConditionVariable (Address: 0x180079c50)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x180079c78)
  • GetSystemTimeAsFileTime (Address: 0x180079c68)
  • GetTickCount (Address: 0x180079c80)
  • GetTickCount64 (Address: 0x180079c70)
api-ms-win-core-threadpool-l1-2-0.dll
  • CallbackMayRunLong (Address: 0x180079cd8)
  • CloseThreadpoolTimer (Address: 0x180079ca8)
  • CloseThreadpoolWait (Address: 0x180079ca0)
  • CloseThreadpoolWork (Address: 0x180079c98)
  • CreateThreadpoolTimer (Address: 0x180079cf0)
  • CreateThreadpoolWait (Address: 0x180079c90)
  • CreateThreadpoolWork (Address: 0x180079cc0)
  • FreeLibraryWhenCallbackReturns (Address: 0x180079cb8)
  • SetThreadpoolTimer (Address: 0x180079cc8)
  • SetThreadpoolWait (Address: 0x180079cb0)
  • SubmitThreadpoolWork (Address: 0x180079cd0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180079ce8)
  • WaitForThreadpoolWaitCallbacks (Address: 0x180079ce0)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180079d00)
  • EncodePointer (Address: 0x180079d08)
api-ms-win-core-winrt-l1-1-0.dll
  • RoInitialize (Address: 0x180079d18)
  • RoUninitialize (Address: 0x180079d20)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x180079d30)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x180079d40)
api-ms-win-crt-private-l1-1-0.dll
  • __AdjustPointer (Address: 0x180079e68)
  • __C_specific_handler (Address: 0x180079ed0)
  • __current_exception (Address: 0x180079e60)
  • __CxxFrameHandler3 (Address: 0x180079e28)
  • __CxxFrameHandler4 (Address: 0x180079ed8)
  • __processing_throw (Address: 0x180079e70)
  • __std_terminate (Address: 0x180079ec8)
  • _CxxThrowException (Address: 0x180079e30)
  • _o___std_exception_copy (Address: 0x180079eb0)
  • _o___std_exception_destroy (Address: 0x180079ea8)
  • _o___std_type_info_destroy_list (Address: 0x180079e98)
  • _o___stdio_common_vsnprintf_s (Address: 0x180079e90)
  • _o___stdio_common_vsnwprintf_s (Address: 0x180079e88)
  • _o___stdio_common_vswprintf (Address: 0x180079e80)
  • _o___stdio_common_vswprintf_s (Address: 0x180079e78)
  • _o__aligned_free (Address: 0x180079e58)
  • _o__aligned_malloc (Address: 0x180079e50)
  • _o__callnewh (Address: 0x180079e40)
  • _o__cexit (Address: 0x180079e38)
  • _o__configure_narrow_argv (Address: 0x180079ee0)
  • _o__crt_atexit (Address: 0x180079ec0)
  • _o__errno (Address: 0x180079eb8)
  • _o__execute_onexit_table (Address: 0x180079ea0)
  • _o__initialize_narrow_environment (Address: 0x180079d50)
  • _o__initialize_onexit_table (Address: 0x180079d58)
  • _o__invalid_parameter_noinfo (Address: 0x180079d60)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x180079d68)
  • _o__purecall (Address: 0x180079d70)
  • _o__register_onexit_function (Address: 0x180079d78)
  • _o__resetstkoflw (Address: 0x180079d80)
  • _o__seh_filter_dll (Address: 0x180079d88)
  • _o__wcsicmp (Address: 0x180079d90)
  • _o__wcsnicmp (Address: 0x180079d98)
  • _o__wcstoi64 (Address: 0x180079da0)
  • _o__wcstoui64 (Address: 0x180079da8)
  • _o_abort (Address: 0x180079db8)
  • _o_calloc (Address: 0x180079dc0)
  • _o_free (Address: 0x180079dc8)
  • _o_malloc (Address: 0x180079dd0)
  • _o_strcpy_s (Address: 0x180079dd8)
  • _o_terminate (Address: 0x180079de0)
  • _o_toupper (Address: 0x180079de8)
  • _o_towupper (Address: 0x180079df0)
  • _o_wcscat_s (Address: 0x180079df8)
  • _o_wcscpy_s (Address: 0x180079e00)
  • _o_wcsncpy_s (Address: 0x180079e08)
  • _o_wcstod (Address: 0x180079e10)
  • _o_wcstoul (Address: 0x180079e18)
  • _o_wcstoull (Address: 0x180079e20)
  • memcmp (Address: 0x180079ee8)
  • memcpy (Address: 0x180079ef0)
  • memmove (Address: 0x180079db0)
  • wcsrchr (Address: 0x180079e48)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180079f08)
  • _initterm_e (Address: 0x180079f00)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180079f28)
  • strcmp (Address: 0x180079f30)
  • wcsncmp (Address: 0x180079f20)
  • wcsnlen (Address: 0x180079f18)
api-ms-win-devices-config-l1-1-1.dll
  • CM_MapCrToWin32Err (Address: 0x180079f48)
  • CM_Register_Notification (Address: 0x180079f40)
  • CM_Unregister_Notification (Address: 0x180079f50)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x180079f68)
  • EventEnabled (Address: 0x180079f90)
  • EventProviderEnabled (Address: 0x180079f70)
  • EventRegister (Address: 0x180079f88)
  • EventSetInformation (Address: 0x180079f80)
  • EventUnregister (Address: 0x180079fa0)
  • EventWrite (Address: 0x180079f98)
  • EventWriteEx (Address: 0x180079f78)
  • EventWriteTransfer (Address: 0x180079f60)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x180079fe8)
  • AdjustTokenPrivileges (Address: 0x18007a020)
  • CheckTokenMembership (Address: 0x18007a000)
  • CopySid (Address: 0x180079ff8)
  • CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x18007a058)
  • CreateWellKnownSid (Address: 0x180079ff0)
  • DestroyPrivateObjectSecurity (Address: 0x18007a018)
  • GetAce (Address: 0x18007a068)
  • GetLengthSid (Address: 0x180079fe0)
  • GetSecurityDescriptorControl (Address: 0x18007a040)
  • GetSecurityDescriptorDacl (Address: 0x180079fc0)
  • GetSecurityDescriptorLength (Address: 0x18007a010)
  • GetSidLengthRequired (Address: 0x18007a070)
  • GetSidSubAuthority (Address: 0x180079fc8)
  • ImpersonateSelf (Address: 0x18007a030)
  • InitializeAcl (Address: 0x18007a038)
  • InitializeSecurityDescriptor (Address: 0x180079fb8)
  • InitializeSid (Address: 0x180079fd0)
  • IsValidSecurityDescriptor (Address: 0x18007a048)
  • IsValidSid (Address: 0x18007a050)
  • MakeSelfRelativeSD (Address: 0x180079fd8)
  • RevertToSelf (Address: 0x18007a028)
  • SetSecurityDescriptorDacl (Address: 0x18007a060)
  • SetSecurityDescriptorGroup (Address: 0x18007a008)
  • SetSecurityDescriptorOwner (Address: 0x180079fb0)
combase.dll
  • (Address: 0x18007a080)
KERNELBASE.dll
  • GetVolumeNameForVolumeMountPointW (Address: 0x180079728)
  • LocalAlloc (Address: 0x180079720)
  • Sleep (Address: 0x180079730)
ntdll.dll
  • NtClose (Address: 0x18007a0a8)
  • NtCreateFile (Address: 0x18007a140)
  • NtOpenJobObject (Address: 0x18007a0d0)
  • NtQueryEaFile (Address: 0x18007a0f0)
  • NtQueryVolumeInformationFile (Address: 0x18007a100)
  • NtSetCachedSigningLevel2 (Address: 0x18007a0f8)
  • NtSetEaFile (Address: 0x18007a090)
  • NtWaitForSingleObject (Address: 0x18007a0b0)
  • RtlAcquireSRWLockExclusive (Address: 0x18007a130)
  • RtlAllocateHeap (Address: 0x18007a098)
  • RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x18007a0d8)
  • RtlDosPathNameToRelativeNtPathName_U_WithStatus (Address: 0x18007a108)
  • RtlFindNextForwardRunClear (Address: 0x18007a110)
  • RtlFreeHeap (Address: 0x18007a148)
  • RtlFreeUnicodeString (Address: 0x18007a0e8)
  • RtlInitializeSRWLock (Address: 0x18007a120)
  • RtlInitUnicodeString (Address: 0x18007a0c0)
  • RtlNtStatusToDosError (Address: 0x18007a138)
  • RtlNumberOfSetBits (Address: 0x18007a118)
  • RtlReleaseRelativeName (Address: 0x18007a0a0)
  • RtlReleaseSRWLockExclusive (Address: 0x18007a128)
  • RtlRunOnceBeginInitialize (Address: 0x18007a0e0)
  • RtlRunOnceComplete (Address: 0x18007a0c8)
  • RtlUpcaseUnicodeChar (Address: 0x18007a0b8)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x180079758)
  • RpcBindingBind (Address: 0x180079768)
  • RpcBindingCreateW (Address: 0x180079748)
  • RpcBindingFree (Address: 0x180079770)
  • RpcExceptionFilter (Address: 0x180079760)
  • UuidCreate (Address: 0x180079750)
  • UuidFromStringW (Address: 0x180079740)