wecapi.dll

Description: Event Collector Configuration API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3996

Architecture: 64-bit

Operating System: Windows NT

SHA256: 1770dc8c10ff2b50d20d2474dc5b7e22

File Size: 79.5 KB

Uploaded At: Dec. 1, 2025, 7:42 a.m.

Views: 4

Exported Functions

  • EcIsConfigRequired (Ordinal: 1, Address: 0x38f0)
  • EcQuickConfig (Ordinal: 2, Address: 0x38a0)
  • EcClose (Ordinal: 3, Address: 0x3750)
  • EcDeleteSubscription (Ordinal: 4, Address: 0x2b00)
  • EcEnumNextSubscription (Ordinal: 5, Address: 0x2180)
  • EcGetObjectArrayProperty (Ordinal: 6, Address: 0x2f80)
  • EcGetObjectArraySize (Ordinal: 7, Address: 0x2c70)
  • EcGetSubscriptionProperty (Ordinal: 8, Address: 0x27b0)
  • EcGetSubscriptionRunTimeStatus (Ordinal: 9, Address: 0x3300)
  • EcInsertObjectArrayElement (Ordinal: 10, Address: 0x31c0)
  • EcOpenSubscription (Ordinal: 11, Address: 0x2360)
  • EcOpenSubscriptionEnum (Ordinal: 12, Address: 0x1ed0)
  • EcRemoveObjectArrayElement (Ordinal: 13, Address: 0x3260)
  • EcRetrySubscription (Ordinal: 14, Address: 0x35e0)
  • EcSaveSubscription (Ordinal: 15, Address: 0x29e0)
  • EcSetObjectArrayProperty (Ordinal: 16, Address: 0x2de0)
  • EcSetSubscriptionProperty (Ordinal: 17, Address: 0x2620)

Imported DLLs & Functions

api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18000e618)
  • SetLastError (Address: 0x18000e620)
  • SetUnhandledExceptionFilter (Address: 0x18000e628)
  • UnhandledExceptionFilter (Address: 0x18000e610)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18000e638)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18000e658)
  • HeapAlloc (Address: 0x18000e648)
  • HeapFree (Address: 0x18000e650)
api-ms-win-core-localization-l1-2-0.dll
  • LocaleNameToLCID (Address: 0x18000e668)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18000e678)
  • GetCurrentProcessId (Address: 0x18000e690)
  • GetCurrentThreadId (Address: 0x18000e680)
  • TerminateProcess (Address: 0x18000e688)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18000e6a0)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18000e6b0)
  • RtlLookupFunctionEntry (Address: 0x18000e6b8)
  • RtlVirtualUnwind (Address: 0x18000e6c0)
api-ms-win-core-synch-l1-1-0.dll
  • DeleteCriticalSection (Address: 0x18000e6e0)
  • EnterCriticalSection (Address: 0x18000e6d8)
  • InitializeCriticalSectionEx (Address: 0x18000e6d0)
  • LeaveCriticalSection (Address: 0x18000e6e8)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18000e6f8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18000e708)
  • GetTickCount (Address: 0x18000e710)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • TraceMessage (Address: 0x18000e720)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x18000e730)
  • OpenSCManagerW (Address: 0x18000e740)
  • OpenServiceW (Address: 0x18000e738)
  • StartServiceW (Address: 0x18000e748)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfig2W (Address: 0x18000e758)
  • ChangeServiceConfigW (Address: 0x18000e768)
  • QueryServiceConfigW (Address: 0x18000e760)
api-ms-win-service-winsvc-l1-1-0.dll
  • QueryServiceStatus (Address: 0x18000e778)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000e7f8)
  • __CxxFrameHandler3 (Address: 0x18000e788)
  • __dllonexit (Address: 0x18000e798)
  • _amsg_exit (Address: 0x18000e830)
  • _CxxThrowException (Address: 0x18000e7c0)
  • _initterm (Address: 0x18000e790)
  • _lock (Address: 0x18000e7a8)
  • _onexit (Address: 0x18000e7e0)
  • _purecall (Address: 0x18000e828)
  • _unlock (Address: 0x18000e7a0)
  • _XcptFilter (Address: 0x18000e7f0)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18000e800)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18000e7e8)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18000e7d8)
  • ??1exception@@UEAA@XZ (Address: 0x18000e7d0)
  • ??1type_info@@UEAA@XZ (Address: 0x18000e810)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18000e7c8)
  • free (Address: 0x18000e820)
  • iswalnum (Address: 0x18000e808)
  • iswspace (Address: 0x18000e838)
  • malloc (Address: 0x18000e818)
  • memcpy (Address: 0x18000e7b8)
  • memmove (Address: 0x18000e7b0)
  • memset (Address: 0x18000e840)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x18000e5e8)
  • RpcBindingFree (Address: 0x18000e5f8)
  • RpcBindingFromStringBindingW (Address: 0x18000e5d8)
  • RpcBindingSetAuthInfoW (Address: 0x18000e5e0)
  • RpcStringBindingComposeW (Address: 0x18000e600)
  • RpcStringFreeW (Address: 0x18000e5f0)
wevtapi.dll
  • EvtClose (Address: 0x18000e850)
  • EvtGetChannelConfigProperty (Address: 0x18000e860)
  • EvtOpenChannelConfig (Address: 0x18000e858)
  • EvtSaveChannelConfig (Address: 0x18000e870)
  • EvtSetChannelConfigProperty (Address: 0x18000e868)