wiarpc.dll
Description: Windows Image Acquisition RPC client DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: e8c3e75ba9670da771bedfee7ef7cf09
File Size: 109.5 KB
Uploaded At: Dec. 1, 2025, 7:42 a.m.
Views: 4
Exported Functions
- ??0BUFFER@@QEAA@I@Z (Ordinal: 1, Address: 0x1c40)
- ??0BUFFER_CHAIN@@QEAA@XZ (Ordinal: 2, Address: 0x1d90)
- ??0BUFFER_CHAIN_ITEM@@QEAA@I@Z (Ordinal: 3, Address: 0x1cd0)
- ??1BUFFER@@QEAA@XZ (Ordinal: 4, Address: 0x1c70)
- ??1BUFFER_CHAIN@@QEAA@XZ (Ordinal: 5, Address: 0x1db0)
- ??1BUFFER_CHAIN_ITEM@@QEAA@XZ (Ordinal: 6, Address: 0x1d10)
- ??_FBUFFER@@QEAAXXZ (Ordinal: 7, Address: 0x1cc0)
- ??_FBUFFER_CHAIN_ITEM@@QEAAXXZ (Ordinal: 8, Address: 0x1d70)
- ?QueryPtr@BUFFER@@QEBAPEAXXZ (Ordinal: 9, Address: 0x1ca0)
- ?QuerySize@BUFFER@@QEBAIXZ (Ordinal: 10, Address: 0x1cb0)
- ?QueryUsed@BUFFER_CHAIN_ITEM@@QEBAKXZ (Ordinal: 11, Address: 0x1d50)
- ServiceMain (Ordinal: 12, Address: 0x7350)
- ?SetUsed@BUFFER_CHAIN_ITEM@@QEAAXK@Z (Ordinal: 13, Address: 0x1d60)
Imported DLLs & Functions
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessAsUserW (Address: 0x180014048)
- GetCurrentProcess (Address: 0x180014050)
- GetCurrentProcessId (Address: 0x180014040)
- GetCurrentThreadId (Address: 0x180014038)
- TerminateProcess (Address: 0x180014058)
api-ms-win-core-processthreads-l1-1-1.dll
- SetProcessMitigationPolicy (Address: 0x180014068)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800140a0)
- RegCreateKeyExW (Address: 0x180014098)
- RegEnumKeyExW (Address: 0x180014088)
- RegEnumValueW (Address: 0x1800140a8)
- RegOpenKeyExW (Address: 0x180014080)
- RegQueryInfoKeyW (Address: 0x1800140b0)
- RegQueryValueExW (Address: 0x180014090)
- RegSetValueExW (Address: 0x180014078)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x1800140d8)
- EventSetInformation (Address: 0x1800140d0)
- EventUnregister (Address: 0x1800140c8)
- EventWriteTransfer (Address: 0x1800140c0)
api-ms-win-security-base-l1-1-0.dll
- DuplicateTokenEx (Address: 0x1800140e8)
api-ms-win-service-core-l1-1-0.dll
- RegisterServiceCtrlHandlerExW (Address: 0x180014100)
- SetServiceStatus (Address: 0x1800140f8)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x180013f10)
- AcquireSRWLockShared (Address: 0x180013eb8)
- CloseHandle (Address: 0x180013ef8)
- CloseThreadpoolTimer (Address: 0x180013f18)
- CompareStringW (Address: 0x180013e40)
- CreateDirectoryW (Address: 0x180013df8)
- CreateEventW (Address: 0x180013f40)
- CreateFileW (Address: 0x180013db8)
- CreateMutexExW (Address: 0x180013ec8)
- CreateMutexW (Address: 0x180013dc8)
- CreateSemaphoreExW (Address: 0x180013f68)
- CreateThreadpoolTimer (Address: 0x180013ee0)
- DebugBreak (Address: 0x180013e98)
- DelayLoadFailureHook (Address: 0x180013e00)
- DeleteCriticalSection (Address: 0x180013eb0)
- DeleteFileW (Address: 0x180013d88)
- DisableThreadLibraryCalls (Address: 0x180013e68)
- EnterCriticalSection (Address: 0x180013f80)
- ExpandEnvironmentStringsW (Address: 0x180013df0)
- FormatMessageW (Address: 0x180013f38)
- FreeLibrary (Address: 0x180013d70)
- GetFileInformationByHandle (Address: 0x180013da0)
- GetLastError (Address: 0x180013f30)
- GetLocalTime (Address: 0x180013d80)
- GetModuleFileNameA (Address: 0x180013f60)
- GetModuleHandleA (Address: 0x180013da8)
- GetModuleHandleExW (Address: 0x180013f90)
- GetModuleHandleW (Address: 0x180013ea0)
- GetProcAddress (Address: 0x180013ed0)
- GetProcessHeap (Address: 0x180013ea8)
- GetSystemDirectoryA (Address: 0x180013d90)
- GetSystemTimeAsFileTime (Address: 0x180013e18)
- GetTickCount (Address: 0x180013e10)
- HeapAlloc (Address: 0x180013ed8)
- HeapFree (Address: 0x180013f70)
- InitializeCriticalSection (Address: 0x180013dd0)
- InitializeCriticalSectionAndSpinCount (Address: 0x180013e70)
- InitializeCriticalSectionEx (Address: 0x180013fa0)
- InitOnceBeginInitialize (Address: 0x180013e88)
- InitOnceComplete (Address: 0x180013e60)
- IsDebuggerPresent (Address: 0x180013e90)
- LeaveCriticalSection (Address: 0x180013f98)
- LoadLibraryExA (Address: 0x180013de0)
- LoadLibraryExW (Address: 0x180013d68)
- LocalAlloc (Address: 0x180013e08)
- LocalFree (Address: 0x180013ec0)
- lstrcmpA (Address: 0x180013db0)
- lstrlenA (Address: 0x180013dc0)
- lstrlenW (Address: 0x180013e80)
- OpenSemaphoreW (Address: 0x180013f00)
- OutputDebugStringW (Address: 0x180013f28)
- QueryPerformanceCounter (Address: 0x180013e20)
- RegCreateKeyExA (Address: 0x180013d98)
- RegisterWaitForSingleObject (Address: 0x180013e78)
- RegOpenKeyExA (Address: 0x180013dd8)
- RegQueryValueExA (Address: 0x180013d78)
- ReleaseMutex (Address: 0x180013f48)
- ReleaseSemaphore (Address: 0x180013f88)
- ReleaseSRWLockExclusive (Address: 0x180013d58)
- ReleaseSRWLockShared (Address: 0x180013ee8)
- RemoveDirectoryW (Address: 0x180013de8)
- ResetEvent (Address: 0x180013e58)
- ResolveDelayLoadedAPI (Address: 0x180013d60)
- SetEvent (Address: 0x180013f20)
- SetLastError (Address: 0x180013f78)
- SetThreadpoolTimer (Address: 0x180013ef0)
- SetUnhandledExceptionFilter (Address: 0x180013e28)
- Sleep (Address: 0x180013e38)
- UnhandledExceptionFilter (Address: 0x180013e30)
- UnregisterWaitEx (Address: 0x180013e50)
- WaitForSingleObject (Address: 0x180013f50)
- WaitForSingleObjectEx (Address: 0x180013f08)
- WaitForThreadpoolTimerCallbacks (Address: 0x180013f58)
- WTSGetActiveConsoleSessionId (Address: 0x180013e48)
msvcrt.dll
- __C_specific_handler (Address: 0x180014160)
- __CxxFrameHandler3 (Address: 0x1800141a0)
- __dllonexit (Address: 0x180014118)
- _amsg_exit (Address: 0x180014138)
- _callnewh (Address: 0x180014148)
- _initterm (Address: 0x180014130)
- _lock (Address: 0x180014128)
- _onexit (Address: 0x180014110)
- _purecall (Address: 0x180014180)
- _splitpath_s (Address: 0x180014190)
- _unlock (Address: 0x1800141c0)
- _vscwprintf (Address: 0x180014158)
- _vsnprintf (Address: 0x180014188)
- _vsnwprintf (Address: 0x1800141b8)
- _XcptFilter (Address: 0x180014140)
- ??1type_info@@UEAA@XZ (Address: 0x180014168)
- free (Address: 0x180014178)
- malloc (Address: 0x1800141a8)
- memcmp (Address: 0x180014120)
- memcpy (Address: 0x1800141b0)
- memcpy_s (Address: 0x180014198)
- memmove_s (Address: 0x180014170)
- memset (Address: 0x1800141c8)
- wcschr (Address: 0x180014150)
ntdll.dll
- NtClose (Address: 0x1800141e0)
- NtDuplicateToken (Address: 0x1800141d8)
- RtlCaptureContext (Address: 0x1800141f8)
- RtlLookupFunctionEntry (Address: 0x1800141f0)
- RtlVirtualUnwind (Address: 0x1800141e8)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x180013ff8)
- Ndr64AsyncClientCall (Address: 0x180013fb8)
- RpcAsyncCancelCall (Address: 0x180013fd8)
- RpcAsyncCompleteCall (Address: 0x180013fe8)
- RpcAsyncGetCallStatus (Address: 0x180013ff0)
- RpcAsyncInitializeHandle (Address: 0x180013fc0)
- RpcBindingFree (Address: 0x180013fc8)
- RpcBindingFromStringBindingW (Address: 0x180014008)
- RpcBindingSetAuthInfoExW (Address: 0x180013fb0)
- RpcStringBindingComposeW (Address: 0x180014000)
- RpcStringFreeW (Address: 0x180013fe0)
- UuidToStringW (Address: 0x180013fd0)
USER32.dll
- CharNextA (Address: 0x180014028)
- CharNextW (Address: 0x180014018)
- CharUpperA (Address: 0x180014020)