vmcompute.dll
Description: Hyper-V Host Compute Service Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5129
Architecture: 64-bit
Operating System: Windows NT
SHA256: 6cb00235cca76e8df249126004d68d4b
File Size: 660.5 KB
Uploaded At: Dec. 1, 2025, 7:42 a.m.
Views: 8
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- HcsEnumerateVmWorkerProcesses (Ordinal: 1, Address: 0x280d0)
- HcsFindVmWorkerProcesses (Ordinal: 2, Address: 0x28250)
- HcsGetWorkerProcessJob (Ordinal: 3, Address: 0x28320)
- HcsStartVmWorkerProcess (Ordinal: 4, Address: 0x27fd0)
- ActivateLayer (Ordinal: 5, Address: 0x20300)
- ApplyRegistryChangesToLayer (Ordinal: 6, Address: 0x208c0)
- ComputeSystemExists (Ordinal: 7, Address: 0x181a0)
- CreateBaseImageVHD (Ordinal: 8, Address: 0x21ee0)
- CreateBaseImageVHDWithFolders (Ordinal: 9, Address: 0x22080)
- CreateComputeSystem (Ordinal: 10, Address: 0x179a0)
- CreateDifferencingVHD (Ordinal: 11, Address: 0x22060)
- CreateLayer (Ordinal: 12, Address: 0x200d0)
- CreateProcessInComputeSystem (Ordinal: 13, Address: 0x188d0)
- CreateProcessWithStdHandlesInComputeSystem (Ordinal: 14, Address: 0x18330)
- CreateSandboxLayer (Ordinal: 15, Address: 0x206f0)
- DeactivateLayer (Ordinal: 16, Address: 0x20540)
- DestroyLayer (Ordinal: 17, Address: 0x201d0)
- DismountVhdByHandle (Ordinal: 18, Address: 0x238e0)
- EnumerateComputeSystems (Ordinal: 19, Address: 0x17990)
- ExpandSandboxSize (Ordinal: 20, Address: 0x20e50)
- ExportLayer (Ordinal: 21, Address: 0x21720)
- GetComputeSystemProperties (Ordinal: 22, Address: 0x18230)
- GetHostProperties (Ordinal: 23, Address: 0x18e60)
- GetLayerMountPath (Ordinal: 24, Address: 0x20610)
- GrantVmAccess (Ordinal: 25, Address: 0x21d60)
- GrantVmGroupAccess (Ordinal: 26, Address: 0x21d30)
- HNSCall (Ordinal: 27, Address: 0x27e40)
- HcsAddComputeSystemResource (Ordinal: 28, Address: 0xfc70)
- HcsCloseComputeSystem (Ordinal: 29, Address: 0xdfa0)
- HcsCloseProcess (Ordinal: 30, Address: 0x10590)
- HcsCrashComputeSystem (Ordinal: 31, Address: 0xe980)
- HcsCreateComputeSystem (Ordinal: 32, Address: 0xdc70)
- HcsCreateProcess (Ordinal: 33, Address: 0xfff0)
- HcsEnumerateComputeSystems (Ordinal: 34, Address: 0xda70)
- HcsGetComputeSystemProperties (Ordinal: 35, Address: 0xf650)
- HcsGetProcessInfo (Ordinal: 36, Address: 0x109c0)
- HcsGetProcessProperties (Ordinal: 37, Address: 0x10d60)
- HcsGetServiceProperties (Ordinal: 38, Address: 0x11640)
- HcsModifyComputeSystem (Ordinal: 39, Address: 0xf8e0)
- HcsModifyComputeSystemResource (Ordinal: 40, Address: 0xfc70)
- HcsModifyComputeSystemWithUserToken (Ordinal: 41, Address: 0xf900)
- HcsModifyProcess (Ordinal: 42, Address: 0x10fe0)
- HcsModifyServiceSettings (Ordinal: 43, Address: 0x11860)
- HcsOpenComputeSystem (Ordinal: 44, Address: 0xde60)
- HcsOpenProcess (Ordinal: 45, Address: 0x103f0)
- HcsPauseComputeSystem (Ordinal: 46, Address: 0xed20)
- HcsRegisterComputeSystemCallback (Ordinal: 47, Address: 0xfc80)
- HcsRegisterProcessCallback (Ordinal: 48, Address: 0x112e0)
- HcsRemoveComputeSystemResource (Ordinal: 49, Address: 0xfc70)
- HcsResumeComputeSystem (Ordinal: 50, Address: 0xf030)
- HcsSaveComputeSystem (Ordinal: 51, Address: 0xf340)
- HcsShutdownComputeSystem (Ordinal: 52, Address: 0xe380)
- HcsSignalProcess (Ordinal: 53, Address: 0x106d0)
- HcsStartComputeSystem (Ordinal: 54, Address: 0xe070)
- HcsSubmitWerReport (Ordinal: 55, Address: 0x119d0)
- HcsTerminateComputeSystem (Ordinal: 56, Address: 0xe720)
- HcsTerminateProcess (Ordinal: 57, Address: 0x109b0)
- HcsUnregisterComputeSystemCallback (Ordinal: 58, Address: 0xfe60)
- HcsUnregisterProcessCallback (Ordinal: 59, Address: 0x114c0)
- ImportLayer (Ordinal: 60, Address: 0x21ac0)
- LayerExists (Ordinal: 61, Address: 0x20070)
- ModifyComputeSystemResource (Ordinal: 62, Address: 0x182b0)
- MountVhdForSetup (Ordinal: 63, Address: 0x23830)
- NameToGuid (Ordinal: 64, Address: 0x21c80)
- PrepareLayer (Ordinal: 65, Address: 0x212c0)
- PrepareLayerEx (Ordinal: 66, Address: 0x212e0)
- ProcessBaseImage (Ordinal: 67, Address: 0x23770)
- ProcessHostImage (Ordinal: 68, Address: 0x237a0)
- ProcessImage (Ordinal: 69, Address: 0x22870)
- ProcessImageEx (Ordinal: 70, Address: 0x22890)
- ProcessUtilityHostImage (Ordinal: 71, Address: 0x23800)
- ProcessUtilityImage (Ordinal: 72, Address: 0x237d0)
- ResizeConsoleInComputeSystem (Ordinal: 73, Address: 0x18900)
- RevokeVmAccess (Ordinal: 74, Address: 0x21e20)
- ShutdownComputeSystem (Ordinal: 75, Address: 0x17d70)
- StartComputeSystem (Ordinal: 76, Address: 0x17b80)
- TerminateComputeSystem (Ordinal: 77, Address: 0x17fb0)
- TerminateProcessInComputeSystem (Ordinal: 78, Address: 0x18da0)
- UnprepareLayer (Ordinal: 79, Address: 0x21590)
- UnprepareLayerEx (Ordinal: 80, Address: 0x215a0)
- WaitForProcessInComputeSystem (Ordinal: 81, Address: 0x18a70)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCancelCall (Address: 0x180079780)
- CoCreateInstance (Address: 0x1800797a0)
- CoDisableCallCancellation (Address: 0x180079788)
- CoEnableCallCancellation (Address: 0x180079790)
- CoGetObjectContext (Address: 0x1800797b8)
- CoInitializeEx (Address: 0x180079798)
- CoTaskMemAlloc (Address: 0x1800797a8)
- CoTaskMemFree (Address: 0x1800797c0)
- CoUninitialize (Address: 0x1800797b0)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800797e0)
- IsDebuggerPresent (Address: 0x1800797d8)
- OutputDebugStringW (Address: 0x1800797d0)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800797f0)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180079800)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180079810)
- RaiseException (Address: 0x180079830)
- SetLastError (Address: 0x180079820)
- SetUnhandledExceptionFilter (Address: 0x180079828)
- UnhandledExceptionFilter (Address: 0x180079818)
api-ms-win-core-errorhandling-l1-1-2.dll
- RaiseFailFastException (Address: 0x180079840)
api-ms-win-core-featurestaging-l1-1-0.dll
- RecordFeatureUsage (Address: 0x180079860)
- SubscribeFeatureStateChangeNotification (Address: 0x180079850)
- UnsubscribeFeatureStateChangeNotification (Address: 0x180079858)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x1800798e0)
- CreateFileW (Address: 0x1800798e8)
- DeleteFileW (Address: 0x180079870)
- FindClose (Address: 0x180079898)
- FindFirstFileW (Address: 0x180079888)
- FindFirstVolumeW (Address: 0x1800798c0)
- FindNextFileW (Address: 0x180079890)
- FindNextVolumeW (Address: 0x1800798d0)
- FindVolumeClose (Address: 0x1800798c8)
- FlushFileBuffers (Address: 0x1800798d8)
- GetFileAttributesW (Address: 0x1800798f0)
- GetFileSizeEx (Address: 0x1800798b8)
- GetFinalPathNameByHandleW (Address: 0x1800798a0)
- GetVolumePathNameW (Address: 0x1800798a8)
- ReadFile (Address: 0x1800798b0)
- SetFileAttributesW (Address: 0x180079880)
- WriteFile (Address: 0x180079878)
api-ms-win-core-file-l2-1-0.dll
- CopyFile2 (Address: 0x180079908)
- CreateHardLinkW (Address: 0x180079900)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180079918)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180079930)
- HeapAlloc (Address: 0x180079928)
- HeapFree (Address: 0x180079938)
api-ms-win-core-heap-l2-1-0.dll
- LocalFree (Address: 0x180079948)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x180079958)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x180079968)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x180079990)
- GetModuleFileNameA (Address: 0x180079978)
- GetModuleFileNameW (Address: 0x180079980)
- GetModuleHandleExW (Address: 0x180079988)
- GetModuleHandleW (Address: 0x1800799a8)
- GetProcAddress (Address: 0x1800799a0)
- LoadLibraryExW (Address: 0x180079998)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800799b8)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x1800799d0)
- MapViewOfFile (Address: 0x1800799d8)
- UnmapViewOfFile (Address: 0x1800799c8)
api-ms-win-core-path-l1-1-0.dll
- PathCchAddBackslash (Address: 0x1800799f0)
- PathCchCombineEx (Address: 0x1800799f8)
- PathCchFindExtension (Address: 0x180079a00)
- PathCchRemoveFileSpec (Address: 0x1800799e8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x180079a38)
- GetCurrentProcessId (Address: 0x180079a20)
- GetCurrentThread (Address: 0x180079a10)
- GetCurrentThreadId (Address: 0x180079a18)
- OpenThreadToken (Address: 0x180079a28)
- TerminateProcess (Address: 0x180079a50)
- TlsAlloc (Address: 0x180079a30)
- TlsFree (Address: 0x180079a58)
- TlsGetValue (Address: 0x180079a40)
- TlsSetValue (Address: 0x180079a48)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x180079a68)
- OpenProcess (Address: 0x180079a70)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180079a88)
- QueryPerformanceFrequency (Address: 0x180079a80)
api-ms-win-core-psapi-l1-1-0.dll
- K32GetModuleInformation (Address: 0x180079a98)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180079aa8)
- RegDeleteValueW (Address: 0x180079ad0)
- RegEnumKeyExW (Address: 0x180079ac8)
- RegGetValueW (Address: 0x180079ab0)
- RegOpenKeyExW (Address: 0x180079ab8)
- RegQueryInfoKeyW (Address: 0x180079ac0)
- RegSetValueExW (Address: 0x180079ad8)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x180079b08)
- RtlCaptureStackBackTrace (Address: 0x180079af0)
- RtlLookupFunctionEntry (Address: 0x180079b00)
- RtlPcToFileHeader (Address: 0x180079ae8)
- RtlVirtualUnwind (Address: 0x180079af8)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFileExistsW (Address: 0x180079b28)
- PathIsRelativeW (Address: 0x180079b18)
- PathIsUNCServerShareW (Address: 0x180079b20)
- PathIsUNCServerW (Address: 0x180079b38)
- PathSkipRootW (Address: 0x180079b30)
api-ms-win-core-string-l1-1-0.dll
- WideCharToMultiByte (Address: 0x180079b48)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180079b88)
- AcquireSRWLockShared (Address: 0x180079b78)
- CreateEventExW (Address: 0x180079b90)
- CreateEventW (Address: 0x180079bb8)
- CreateMutexExW (Address: 0x180079ba0)
- CreateSemaphoreExW (Address: 0x180079b60)
- DeleteCriticalSection (Address: 0x180079b98)
- EnterCriticalSection (Address: 0x180079ba8)
- InitializeCriticalSection (Address: 0x180079b70)
- InitializeCriticalSectionAndSpinCount (Address: 0x180079bd8)
- InitializeCriticalSectionEx (Address: 0x180079bc8)
- InitializeSRWLock (Address: 0x180079be8)
- LeaveCriticalSection (Address: 0x180079bd0)
- OpenSemaphoreW (Address: 0x180079c08)
- ReleaseMutex (Address: 0x180079bb0)
- ReleaseSemaphore (Address: 0x180079b58)
- ReleaseSRWLockExclusive (Address: 0x180079bf8)
- ReleaseSRWLockShared (Address: 0x180079bf0)
- ResetEvent (Address: 0x180079b80)
- SetEvent (Address: 0x180079be0)
- TryAcquireSRWLockExclusive (Address: 0x180079c00)
- WaitForSingleObject (Address: 0x180079bc0)
- WaitForSingleObjectEx (Address: 0x180079b68)
api-ms-win-core-synch-l1-2-0.dll
- InitializeConditionVariable (Address: 0x180079c58)
- InitOnceBeginInitialize (Address: 0x180079c28)
- InitOnceComplete (Address: 0x180079c38)
- InitOnceExecuteOnce (Address: 0x180079c18)
- SleepConditionVariableSRW (Address: 0x180079c40)
- WaitOnAddress (Address: 0x180079c48)
- WakeAllConditionVariable (Address: 0x180079c20)
- WakeByAddressAll (Address: 0x180079c30)
- WakeConditionVariable (Address: 0x180079c50)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemInfo (Address: 0x180079c78)
- GetSystemTimeAsFileTime (Address: 0x180079c68)
- GetTickCount (Address: 0x180079c80)
- GetTickCount64 (Address: 0x180079c70)
api-ms-win-core-threadpool-l1-2-0.dll
- CallbackMayRunLong (Address: 0x180079cd8)
- CloseThreadpoolTimer (Address: 0x180079ca8)
- CloseThreadpoolWait (Address: 0x180079ca0)
- CloseThreadpoolWork (Address: 0x180079c98)
- CreateThreadpoolTimer (Address: 0x180079cf0)
- CreateThreadpoolWait (Address: 0x180079c90)
- CreateThreadpoolWork (Address: 0x180079cc0)
- FreeLibraryWhenCallbackReturns (Address: 0x180079cb8)
- SetThreadpoolTimer (Address: 0x180079cc8)
- SetThreadpoolWait (Address: 0x180079cb0)
- SubmitThreadpoolWork (Address: 0x180079cd0)
- WaitForThreadpoolTimerCallbacks (Address: 0x180079ce8)
- WaitForThreadpoolWaitCallbacks (Address: 0x180079ce0)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x180079d00)
- EncodePointer (Address: 0x180079d08)
api-ms-win-core-winrt-l1-1-0.dll
- RoInitialize (Address: 0x180079d18)
- RoUninitialize (Address: 0x180079d20)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateStringReference (Address: 0x180079d30)
api-ms-win-crt-math-l1-1-0.dll
- ceilf (Address: 0x180079d40)
api-ms-win-crt-private-l1-1-0.dll
- __AdjustPointer (Address: 0x180079e68)
- __C_specific_handler (Address: 0x180079ed0)
- __current_exception (Address: 0x180079e60)
- __CxxFrameHandler3 (Address: 0x180079e28)
- __CxxFrameHandler4 (Address: 0x180079ed8)
- __processing_throw (Address: 0x180079e70)
- __std_terminate (Address: 0x180079ec8)
- _CxxThrowException (Address: 0x180079e30)
- _o___std_exception_copy (Address: 0x180079eb0)
- _o___std_exception_destroy (Address: 0x180079ea8)
- _o___std_type_info_destroy_list (Address: 0x180079e98)
- _o___stdio_common_vsnprintf_s (Address: 0x180079e90)
- _o___stdio_common_vsnwprintf_s (Address: 0x180079e88)
- _o___stdio_common_vswprintf (Address: 0x180079e80)
- _o___stdio_common_vswprintf_s (Address: 0x180079e78)
- _o__aligned_free (Address: 0x180079e58)
- _o__aligned_malloc (Address: 0x180079e50)
- _o__callnewh (Address: 0x180079e40)
- _o__cexit (Address: 0x180079e38)
- _o__configure_narrow_argv (Address: 0x180079ee0)
- _o__crt_atexit (Address: 0x180079ec0)
- _o__errno (Address: 0x180079eb8)
- _o__execute_onexit_table (Address: 0x180079ea0)
- _o__initialize_narrow_environment (Address: 0x180079d50)
- _o__initialize_onexit_table (Address: 0x180079d58)
- _o__invalid_parameter_noinfo (Address: 0x180079d60)
- _o__invalid_parameter_noinfo_noreturn (Address: 0x180079d68)
- _o__purecall (Address: 0x180079d70)
- _o__register_onexit_function (Address: 0x180079d78)
- _o__resetstkoflw (Address: 0x180079d80)
- _o__seh_filter_dll (Address: 0x180079d88)
- _o__wcsicmp (Address: 0x180079d90)
- _o__wcsnicmp (Address: 0x180079d98)
- _o__wcstoi64 (Address: 0x180079da0)
- _o__wcstoui64 (Address: 0x180079da8)
- _o_abort (Address: 0x180079db8)
- _o_calloc (Address: 0x180079dc0)
- _o_free (Address: 0x180079dc8)
- _o_malloc (Address: 0x180079dd0)
- _o_strcpy_s (Address: 0x180079dd8)
- _o_terminate (Address: 0x180079de0)
- _o_toupper (Address: 0x180079de8)
- _o_towupper (Address: 0x180079df0)
- _o_wcscat_s (Address: 0x180079df8)
- _o_wcscpy_s (Address: 0x180079e00)
- _o_wcsncpy_s (Address: 0x180079e08)
- _o_wcstod (Address: 0x180079e10)
- _o_wcstoul (Address: 0x180079e18)
- _o_wcstoull (Address: 0x180079e20)
- memcmp (Address: 0x180079ee8)
- memcpy (Address: 0x180079ef0)
- memmove (Address: 0x180079db0)
- wcsrchr (Address: 0x180079e48)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x180079f08)
- _initterm_e (Address: 0x180079f00)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x180079f28)
- strcmp (Address: 0x180079f30)
- wcsncmp (Address: 0x180079f20)
- wcsnlen (Address: 0x180079f18)
api-ms-win-devices-config-l1-1-1.dll
- CM_MapCrToWin32Err (Address: 0x180079f48)
- CM_Register_Notification (Address: 0x180079f40)
- CM_Unregister_Notification (Address: 0x180079f50)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x180079f68)
- EventEnabled (Address: 0x180079f90)
- EventProviderEnabled (Address: 0x180079f70)
- EventRegister (Address: 0x180079f88)
- EventSetInformation (Address: 0x180079f80)
- EventUnregister (Address: 0x180079fa0)
- EventWrite (Address: 0x180079f98)
- EventWriteEx (Address: 0x180079f78)
- EventWriteTransfer (Address: 0x180079f60)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x180079fe8)
- AdjustTokenPrivileges (Address: 0x18007a020)
- CheckTokenMembership (Address: 0x18007a000)
- CopySid (Address: 0x180079ff8)
- CreatePrivateObjectSecurityWithMultipleInheritance (Address: 0x18007a058)
- CreateWellKnownSid (Address: 0x180079ff0)
- DestroyPrivateObjectSecurity (Address: 0x18007a018)
- GetAce (Address: 0x18007a068)
- GetLengthSid (Address: 0x180079fe0)
- GetSecurityDescriptorControl (Address: 0x18007a040)
- GetSecurityDescriptorDacl (Address: 0x180079fc0)
- GetSecurityDescriptorLength (Address: 0x18007a010)
- GetSidLengthRequired (Address: 0x18007a070)
- GetSidSubAuthority (Address: 0x180079fc8)
- ImpersonateSelf (Address: 0x18007a030)
- InitializeAcl (Address: 0x18007a038)
- InitializeSecurityDescriptor (Address: 0x180079fb8)
- InitializeSid (Address: 0x180079fd0)
- IsValidSecurityDescriptor (Address: 0x18007a048)
- IsValidSid (Address: 0x18007a050)
- MakeSelfRelativeSD (Address: 0x180079fd8)
- RevertToSelf (Address: 0x18007a028)
- SetSecurityDescriptorDacl (Address: 0x18007a060)
- SetSecurityDescriptorGroup (Address: 0x18007a008)
- SetSecurityDescriptorOwner (Address: 0x180079fb0)
combase.dll
- (Address: 0x18007a080)
KERNELBASE.dll
- GetVolumeNameForVolumeMountPointW (Address: 0x180079728)
- LocalAlloc (Address: 0x180079720)
- Sleep (Address: 0x180079730)
ntdll.dll
- NtClose (Address: 0x18007a0a8)
- NtCreateFile (Address: 0x18007a140)
- NtOpenJobObject (Address: 0x18007a0d0)
- NtQueryEaFile (Address: 0x18007a0f0)
- NtQueryVolumeInformationFile (Address: 0x18007a100)
- NtSetCachedSigningLevel2 (Address: 0x18007a0f8)
- NtSetEaFile (Address: 0x18007a090)
- NtWaitForSingleObject (Address: 0x18007a0b0)
- RtlAcquireSRWLockExclusive (Address: 0x18007a130)
- RtlAllocateHeap (Address: 0x18007a098)
- RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x18007a0d8)
- RtlDosPathNameToRelativeNtPathName_U_WithStatus (Address: 0x18007a108)
- RtlFindNextForwardRunClear (Address: 0x18007a110)
- RtlFreeHeap (Address: 0x18007a148)
- RtlFreeUnicodeString (Address: 0x18007a0e8)
- RtlInitializeSRWLock (Address: 0x18007a120)
- RtlInitUnicodeString (Address: 0x18007a0c0)
- RtlNtStatusToDosError (Address: 0x18007a138)
- RtlNumberOfSetBits (Address: 0x18007a118)
- RtlReleaseRelativeName (Address: 0x18007a0a0)
- RtlReleaseSRWLockExclusive (Address: 0x18007a128)
- RtlRunOnceBeginInitialize (Address: 0x18007a0e0)
- RtlRunOnceComplete (Address: 0x18007a0c8)
- RtlUpcaseUnicodeChar (Address: 0x18007a0b8)
RPCRT4.dll
- NdrClientCall3 (Address: 0x180079758)
- RpcBindingBind (Address: 0x180079768)
- RpcBindingCreateW (Address: 0x180079748)
- RpcBindingFree (Address: 0x180079770)
- RpcExceptionFilter (Address: 0x180079760)
- UuidCreate (Address: 0x180079750)
- UuidFromStringW (Address: 0x180079740)