WinREAgent.dll

Description: Windows Recovery Environment Agent

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6033

Architecture: 64-bit

Operating System: Windows NT

SHA256: 26156f3cf7131bb76207193f94253de8

File Size: 529.9 KB

Uploaded At: Dec. 1, 2025, 7:44 a.m.

Views: 4

Exported Functions

  • BackupWinRE (Ordinal: 1, Address: 0x11000)
  • CreateWinREServicingManager (Ordinal: 2, Address: 0x10570)
  • GetWinREAgentVersion (Ordinal: 3, Address: 0x10ac0)
  • GetWinREPartitionFreeSpace (Ordinal: 4, Address: 0x11020)
  • GetWinREVersion (Ordinal: 5, Address: 0x10af0)
  • LoadWinREServicingManager (Ordinal: 6, Address: 0x10930)
  • RestoreWinRE (Ordinal: 7, Address: 0x11010)
  • SaveWinREServicingManager (Ordinal: 8, Address: 0x10770)

Imported DLLs & Functions

ADVAPI32.dll
  • AddAccessAllowedAce (Address: 0x180050b40)
  • AdjustTokenPrivileges (Address: 0x180050bb8)
  • AllocateAndInitializeSid (Address: 0x180050bd8)
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x180050b08)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180050bb0)
  • CopySid (Address: 0x180050b50)
  • EventRegister (Address: 0x180050bc8)
  • EventSetInformation (Address: 0x180050b70)
  • EventUnregister (Address: 0x180050bd0)
  • EventWriteTransfer (Address: 0x180050bc0)
  • GetAce (Address: 0x180050b38)
  • GetFileSecurityW (Address: 0x180050b00)
  • GetLengthSid (Address: 0x180050b58)
  • GetTokenInformation (Address: 0x180050b60)
  • InitializeAcl (Address: 0x180050b48)
  • InitializeSecurityDescriptor (Address: 0x180050b30)
  • OpenProcessToken (Address: 0x180050be0)
  • OpenThreadToken (Address: 0x180050b68)
  • RegCreateKeyExW (Address: 0x180050b80)
  • RegDeleteKeyExW (Address: 0x180050b78)
  • RegDeleteKeyW (Address: 0x180050ae8)
  • RegDeleteTreeW (Address: 0x180050b98)
  • RegDeleteValueW (Address: 0x180050ba8)
  • RegEnumKeyExW (Address: 0x180050b88)
  • RegGetKeySecurity (Address: 0x180050af0)
  • RegGetValueW (Address: 0x180050ae0)
  • RegLoadKeyW (Address: 0x180050ad8)
  • RegSetKeySecurity (Address: 0x180050b90)
  • RegSetValueExW (Address: 0x180050ba0)
  • SetFileSecurityW (Address: 0x180050af8)
  • SetSecurityDescriptorControl (Address: 0x180050b10)
  • SetSecurityDescriptorDacl (Address: 0x180050b18)
  • SetSecurityDescriptorGroup (Address: 0x180050b20)
  • SetSecurityDescriptorOwner (Address: 0x180050b28)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x180051048)
  • FindClose (Address: 0x180051060)
  • FindFirstFileW (Address: 0x180051070)
  • FindNextFileW (Address: 0x180051050)
  • GetFileAttributesW (Address: 0x180051058)
  • QueryDosDeviceW (Address: 0x180051068)
api-ms-win-core-file-l2-1-0.dll
  • MoveFileExW (Address: 0x180051080)
api-ms-win-core-libraryloader-l1-2-0.dll
  • LoadLibraryExW (Address: 0x180051090)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800510b0)
  • RegEnumValueW (Address: 0x1800510b8)
  • RegOpenKeyExW (Address: 0x1800510a0)
  • RegUnLoadKeyW (Address: 0x1800510a8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetWindowsDirectoryW (Address: 0x1800510c8)
api-ms-win-core-version-l1-1-0.dll
  • GetFileVersionInfoExW (Address: 0x1800510e8)
  • GetFileVersionInfoSizeExW (Address: 0x1800510e0)
  • VerQueryValueW (Address: 0x1800510d8)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x1800510f8)
CRYPT32.dll
  • CertVerifyCertificateChainPolicy (Address: 0x180050bf0)
DismApi.DLL
  • _DismCleanImage (Address: 0x180050c48)
  • DismAddPackage (Address: 0x180050c38)
  • DismCloseSession (Address: 0x180050c40)
  • DismDelete (Address: 0x180050c30)
  • DismGetImageInfo (Address: 0x180050c28)
  • DismInitialize (Address: 0x180050c10)
  • DismMountImage (Address: 0x180050c20)
  • DismOpenSession (Address: 0x180050c00)
  • DismShutdown (Address: 0x180050c08)
  • DismUnmountImage (Address: 0x180050c18)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x180050f18)
  • AcquireSRWLockShared (Address: 0x180050f08)
  • CloseHandle (Address: 0x180050ef0)
  • CloseThreadpoolTimer (Address: 0x180050ec8)
  • CompareStringW (Address: 0x180050c80)
  • CopyFile2 (Address: 0x180050d30)
  • CreateDirectoryW (Address: 0x180050e80)
  • CreateEventW (Address: 0x180050d58)
  • CreateMutexExW (Address: 0x180050d88)
  • CreateSemaphoreExW (Address: 0x180050d40)
  • CreateThreadpoolTimer (Address: 0x180050e88)
  • DebugBreak (Address: 0x180050e28)
  • DeleteCriticalSection (Address: 0x180050ea0)
  • DeleteFileW (Address: 0x180050dd0)
  • DeviceIoControl (Address: 0x180050de0)
  • EnterCriticalSection (Address: 0x180050eb0)
  • FindResourceExW (Address: 0x180050cf0)
  • FlushFileBuffers (Address: 0x180050d98)
  • FormatMessageW (Address: 0x180050e60)
  • FreeLibrary (Address: 0x180050db8)
  • GetCurrentDirectoryW (Address: 0x180050df0)
  • GetCurrentProcess (Address: 0x180050cb8)
  • GetCurrentProcessId (Address: 0x180050db0)
  • GetCurrentThread (Address: 0x180050d38)
  • GetCurrentThreadId (Address: 0x180050e58)
  • GetDiskFreeSpaceExW (Address: 0x180050dc0)
  • GetFileInformationByHandle (Address: 0x180050da8)
  • GetFileInformationByHandleEx (Address: 0x180050dc8)
  • GetFinalPathNameByHandleW (Address: 0x180050e08)
  • GetFullPathNameW (Address: 0x180050e78)
  • GetLastError (Address: 0x180050e10)
  • GetLongPathNameW (Address: 0x180050e70)
  • GetModuleFileNameA (Address: 0x180050e30)
  • GetModuleHandleExW (Address: 0x180050e38)
  • GetModuleHandleW (Address: 0x180050e20)
  • GetPrivateProfileSectionNamesW (Address: 0x180050d28)
  • GetPrivateProfileSectionW (Address: 0x180050d80)
  • GetProcAddress (Address: 0x180050e18)
  • GetProcessHeap (Address: 0x180050e48)
  • GetSystemDirectoryW (Address: 0x180050de8)
  • GetSystemTimeAsFileTime (Address: 0x180050cd0)
  • GetSystemWindowsDirectoryW (Address: 0x180050ce8)
  • GetTickCount (Address: 0x180050cd8)
  • GetVersionExW (Address: 0x180050e68)
  • GetVolumeNameForVolumeMountPointW (Address: 0x180050df8)
  • GetVolumePathNamesForVolumeNameW (Address: 0x180050d48)
  • GetVolumePathNameW (Address: 0x180050e00)
  • HeapAlloc (Address: 0x180050e50)
  • HeapDestroy (Address: 0x180050c68)
  • HeapFree (Address: 0x180050e40)
  • HeapReAlloc (Address: 0x180050c60)
  • HeapSize (Address: 0x180050c58)
  • InitializeCriticalSection (Address: 0x180050c70)
  • InitializeCriticalSectionEx (Address: 0x180050ea8)
  • IsDebuggerPresent (Address: 0x180050f28)
  • LeaveCriticalSection (Address: 0x180050d60)
  • LoadResource (Address: 0x180050cf8)
  • LocalFree (Address: 0x180050d68)
  • LockResource (Address: 0x180050d00)
  • MoveFileTransactedW (Address: 0x180050d50)
  • MultiByteToWideChar (Address: 0x180050eb8)
  • OpenSemaphoreW (Address: 0x180050e90)
  • OutputDebugStringW (Address: 0x180050f20)
  • QueryPerformanceCounter (Address: 0x180050cc8)
  • RaiseException (Address: 0x180050c78)
  • ReleaseMutex (Address: 0x180050ee0)
  • ReleaseSemaphore (Address: 0x180050ee8)
  • ReleaseSRWLockExclusive (Address: 0x180050f10)
  • ReleaseSRWLockShared (Address: 0x180050f00)
  • RtlCaptureContext (Address: 0x180050c90)
  • RtlLookupFunctionEntry (Address: 0x180050c98)
  • RtlVirtualUnwind (Address: 0x180050ca0)
  • SetEnvironmentVariableW (Address: 0x180050d78)
  • SetEvent (Address: 0x180050d70)
  • SetFileAttributesW (Address: 0x180050dd8)
  • SetFileInformationByHandle (Address: 0x180050da0)
  • SetLastError (Address: 0x180050ef8)
  • SetThreadpoolTimer (Address: 0x180050ed8)
  • SetUnhandledExceptionFilter (Address: 0x180050cb0)
  • SizeofResource (Address: 0x180050d08)
  • Sleep (Address: 0x180050c88)
  • TerminateProcess (Address: 0x180050cc0)
  • TlsAlloc (Address: 0x180050d20)
  • TlsGetValue (Address: 0x180050d18)
  • TlsSetValue (Address: 0x180050d10)
  • UnhandledExceptionFilter (Address: 0x180050ca8)
  • WaitForSingleObject (Address: 0x180050e98)
  • WaitForSingleObjectEx (Address: 0x180050ec0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180050ed0)
  • WideCharToMultiByte (Address: 0x180050ce0)
  • WritePrivateProfileStringW (Address: 0x180050d90)
ktmw32.dll
  • CommitTransaction (Address: 0x180051110)
  • CreateTransaction (Address: 0x180051108)
msvcrt.dll
  • __C_specific_handler (Address: 0x180051188)
  • __CxxFrameHandler3 (Address: 0x1800511d0)
  • __dllonexit (Address: 0x180051200)
  • __RTDynamicCast (Address: 0x180051120)
  • _amsg_exit (Address: 0x1800511c8)
  • _callnewh (Address: 0x1800511b0)
  • _CxxThrowException (Address: 0x1800511b8)
  • _errno (Address: 0x180051210)
  • _initterm (Address: 0x1800511d8)
  • _lock (Address: 0x1800511f0)
  • _onexit (Address: 0x180051208)
  • _purecall (Address: 0x180051180)
  • _set_errno (Address: 0x180051248)
  • _unlock (Address: 0x1800511f8)
  • _vscwprintf (Address: 0x180051170)
  • _vsnprintf_s (Address: 0x180051148)
  • _vsnwprintf (Address: 0x180051270)
  • _wcsicmp (Address: 0x180051160)
  • _wcsnicmp (Address: 0x180051278)
  • _wtoi (Address: 0x180051230)
  • _wtoi64 (Address: 0x180051228)
  • _wtol (Address: 0x180051220)
  • _XcptFilter (Address: 0x1800511c0)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800511a0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180051138)
  • ??0exception@@QEAA@XZ (Address: 0x180051150)
  • ??1exception@@UEAA@XZ (Address: 0x180051268)
  • ??1type_info@@UEAA@XZ (Address: 0x1800511e8)
  • ?terminate@@YAXXZ (Address: 0x1800511e0)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x1800511a8)
  • calloc (Address: 0x180051178)
  • free (Address: 0x180051168)
  • malloc (Address: 0x180051198)
  • memcmp (Address: 0x180051128)
  • memcpy (Address: 0x180051130)
  • memcpy_s (Address: 0x180051140)
  • memmove_s (Address: 0x180051158)
  • memset (Address: 0x180051218)
  • sprintf_s (Address: 0x180051238)
  • strchr (Address: 0x180051240)
  • strncpy_s (Address: 0x180051258)
  • strtol (Address: 0x180051250)
  • vswprintf_s (Address: 0x180051288)
  • wcschr (Address: 0x180051260)
  • wcscmp (Address: 0x180051290)
  • wcscpy_s (Address: 0x180051190)
  • wcsrchr (Address: 0x180051280)
ntdll.dll
  • NtSetInformationFile (Address: 0x1800512a8)
  • RtlAllocateHeap (Address: 0x1800512b8)
  • RtlFreeHeap (Address: 0x1800512b0)
  • RtlNtStatusToDosError (Address: 0x1800512c0)
  • RtlSetThreadErrorMode (Address: 0x1800512a0)
ole32.dll
  • CoCreateInstance (Address: 0x1800512d0)
  • CoTaskMemFree (Address: 0x1800512e0)
  • StringFromGUID2 (Address: 0x1800512d8)
OLEAUT32.dll
  • SysAllocString (Address: 0x180050f38)
  • SysFreeString (Address: 0x180050f40)
ReAgent.dll
  • WinReGetConfig (Address: 0x180050f68)
  • WinReHashWimFile (Address: 0x180050f70)
  • WinReInstallOnTargetOS (Address: 0x180050f60)
  • WinReSetupBackupWinRE (Address: 0x180050f78)
RPCRT4.dll
  • UuidCreate (Address: 0x180050f50)
USER32.dll
  • UnregisterClassA (Address: 0x180050f88)
WDSCORE.dll
  • ConstructPartialMsgVW (Address: 0x180050fb0)
  • CurrentIP (Address: 0x180050fb8)
  • WdsInitialize (Address: 0x180050f98)
  • WdsSetupLogMessageW (Address: 0x180050fa8)
  • WdsTerminate (Address: 0x180050fa0)
WIMGAPI.DLL
  • WIMCloseHandle (Address: 0x180050fd0)
  • WIMCreateFile (Address: 0x180051008)
  • WIMExportImage (Address: 0x180050fe8)
  • WIMGetAttributes (Address: 0x180051000)
  • WIMLoadImage (Address: 0x180050ff0)
  • WIMRegisterLogFile (Address: 0x180050fe0)
  • WIMRegisterMessageCallback (Address: 0x180050fc8)
  • WIMSetTemporaryPath (Address: 0x180050ff8)
  • WIMUnmountImage (Address: 0x180050fd8)
  • WIMUnregisterLogFile (Address: 0x180051018)
  • WIMUnregisterMessageCallback (Address: 0x180051010)
WINTRUST.dll
  • WinVerifyTrust (Address: 0x180051038)
  • WTHelperGetProvSignerFromChain (Address: 0x180051028)
  • WTHelperProvDataFromStateData (Address: 0x180051030)