WinREAgent.dll
Description: Windows Recovery Environment Agent
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6033
Architecture: 64-bit
Operating System: Windows NT
SHA256: 26156f3cf7131bb76207193f94253de8
File Size: 529.9 KB
Uploaded At: Dec. 1, 2025, 7:44 a.m.
Views: 4
Exported Functions
- BackupWinRE (Ordinal: 1, Address: 0x11000)
- CreateWinREServicingManager (Ordinal: 2, Address: 0x10570)
- GetWinREAgentVersion (Ordinal: 3, Address: 0x10ac0)
- GetWinREPartitionFreeSpace (Ordinal: 4, Address: 0x11020)
- GetWinREVersion (Ordinal: 5, Address: 0x10af0)
- LoadWinREServicingManager (Ordinal: 6, Address: 0x10930)
- RestoreWinRE (Ordinal: 7, Address: 0x11010)
- SaveWinREServicingManager (Ordinal: 8, Address: 0x10770)
Imported DLLs & Functions
ADVAPI32.dll
- AddAccessAllowedAce (Address: 0x180050b40)
- AdjustTokenPrivileges (Address: 0x180050bb8)
- AllocateAndInitializeSid (Address: 0x180050bd8)
- ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x180050b08)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180050bb0)
- CopySid (Address: 0x180050b50)
- EventRegister (Address: 0x180050bc8)
- EventSetInformation (Address: 0x180050b70)
- EventUnregister (Address: 0x180050bd0)
- EventWriteTransfer (Address: 0x180050bc0)
- GetAce (Address: 0x180050b38)
- GetFileSecurityW (Address: 0x180050b00)
- GetLengthSid (Address: 0x180050b58)
- GetTokenInformation (Address: 0x180050b60)
- InitializeAcl (Address: 0x180050b48)
- InitializeSecurityDescriptor (Address: 0x180050b30)
- OpenProcessToken (Address: 0x180050be0)
- OpenThreadToken (Address: 0x180050b68)
- RegCreateKeyExW (Address: 0x180050b80)
- RegDeleteKeyExW (Address: 0x180050b78)
- RegDeleteKeyW (Address: 0x180050ae8)
- RegDeleteTreeW (Address: 0x180050b98)
- RegDeleteValueW (Address: 0x180050ba8)
- RegEnumKeyExW (Address: 0x180050b88)
- RegGetKeySecurity (Address: 0x180050af0)
- RegGetValueW (Address: 0x180050ae0)
- RegLoadKeyW (Address: 0x180050ad8)
- RegSetKeySecurity (Address: 0x180050b90)
- RegSetValueExW (Address: 0x180050ba0)
- SetFileSecurityW (Address: 0x180050af8)
- SetSecurityDescriptorControl (Address: 0x180050b10)
- SetSecurityDescriptorDacl (Address: 0x180050b18)
- SetSecurityDescriptorGroup (Address: 0x180050b20)
- SetSecurityDescriptorOwner (Address: 0x180050b28)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x180051048)
- FindClose (Address: 0x180051060)
- FindFirstFileW (Address: 0x180051070)
- FindNextFileW (Address: 0x180051050)
- GetFileAttributesW (Address: 0x180051058)
- QueryDosDeviceW (Address: 0x180051068)
api-ms-win-core-file-l2-1-0.dll
- MoveFileExW (Address: 0x180051080)
api-ms-win-core-libraryloader-l1-2-0.dll
- LoadLibraryExW (Address: 0x180051090)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800510b0)
- RegEnumValueW (Address: 0x1800510b8)
- RegOpenKeyExW (Address: 0x1800510a0)
- RegUnLoadKeyW (Address: 0x1800510a8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetWindowsDirectoryW (Address: 0x1800510c8)
api-ms-win-core-version-l1-1-0.dll
- GetFileVersionInfoExW (Address: 0x1800510e8)
- GetFileVersionInfoSizeExW (Address: 0x1800510e0)
- VerQueryValueW (Address: 0x1800510d8)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1800510f8)
CRYPT32.dll
- CertVerifyCertificateChainPolicy (Address: 0x180050bf0)
DismApi.DLL
- _DismCleanImage (Address: 0x180050c48)
- DismAddPackage (Address: 0x180050c38)
- DismCloseSession (Address: 0x180050c40)
- DismDelete (Address: 0x180050c30)
- DismGetImageInfo (Address: 0x180050c28)
- DismInitialize (Address: 0x180050c10)
- DismMountImage (Address: 0x180050c20)
- DismOpenSession (Address: 0x180050c00)
- DismShutdown (Address: 0x180050c08)
- DismUnmountImage (Address: 0x180050c18)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x180050f18)
- AcquireSRWLockShared (Address: 0x180050f08)
- CloseHandle (Address: 0x180050ef0)
- CloseThreadpoolTimer (Address: 0x180050ec8)
- CompareStringW (Address: 0x180050c80)
- CopyFile2 (Address: 0x180050d30)
- CreateDirectoryW (Address: 0x180050e80)
- CreateEventW (Address: 0x180050d58)
- CreateMutexExW (Address: 0x180050d88)
- CreateSemaphoreExW (Address: 0x180050d40)
- CreateThreadpoolTimer (Address: 0x180050e88)
- DebugBreak (Address: 0x180050e28)
- DeleteCriticalSection (Address: 0x180050ea0)
- DeleteFileW (Address: 0x180050dd0)
- DeviceIoControl (Address: 0x180050de0)
- EnterCriticalSection (Address: 0x180050eb0)
- FindResourceExW (Address: 0x180050cf0)
- FlushFileBuffers (Address: 0x180050d98)
- FormatMessageW (Address: 0x180050e60)
- FreeLibrary (Address: 0x180050db8)
- GetCurrentDirectoryW (Address: 0x180050df0)
- GetCurrentProcess (Address: 0x180050cb8)
- GetCurrentProcessId (Address: 0x180050db0)
- GetCurrentThread (Address: 0x180050d38)
- GetCurrentThreadId (Address: 0x180050e58)
- GetDiskFreeSpaceExW (Address: 0x180050dc0)
- GetFileInformationByHandle (Address: 0x180050da8)
- GetFileInformationByHandleEx (Address: 0x180050dc8)
- GetFinalPathNameByHandleW (Address: 0x180050e08)
- GetFullPathNameW (Address: 0x180050e78)
- GetLastError (Address: 0x180050e10)
- GetLongPathNameW (Address: 0x180050e70)
- GetModuleFileNameA (Address: 0x180050e30)
- GetModuleHandleExW (Address: 0x180050e38)
- GetModuleHandleW (Address: 0x180050e20)
- GetPrivateProfileSectionNamesW (Address: 0x180050d28)
- GetPrivateProfileSectionW (Address: 0x180050d80)
- GetProcAddress (Address: 0x180050e18)
- GetProcessHeap (Address: 0x180050e48)
- GetSystemDirectoryW (Address: 0x180050de8)
- GetSystemTimeAsFileTime (Address: 0x180050cd0)
- GetSystemWindowsDirectoryW (Address: 0x180050ce8)
- GetTickCount (Address: 0x180050cd8)
- GetVersionExW (Address: 0x180050e68)
- GetVolumeNameForVolumeMountPointW (Address: 0x180050df8)
- GetVolumePathNamesForVolumeNameW (Address: 0x180050d48)
- GetVolumePathNameW (Address: 0x180050e00)
- HeapAlloc (Address: 0x180050e50)
- HeapDestroy (Address: 0x180050c68)
- HeapFree (Address: 0x180050e40)
- HeapReAlloc (Address: 0x180050c60)
- HeapSize (Address: 0x180050c58)
- InitializeCriticalSection (Address: 0x180050c70)
- InitializeCriticalSectionEx (Address: 0x180050ea8)
- IsDebuggerPresent (Address: 0x180050f28)
- LeaveCriticalSection (Address: 0x180050d60)
- LoadResource (Address: 0x180050cf8)
- LocalFree (Address: 0x180050d68)
- LockResource (Address: 0x180050d00)
- MoveFileTransactedW (Address: 0x180050d50)
- MultiByteToWideChar (Address: 0x180050eb8)
- OpenSemaphoreW (Address: 0x180050e90)
- OutputDebugStringW (Address: 0x180050f20)
- QueryPerformanceCounter (Address: 0x180050cc8)
- RaiseException (Address: 0x180050c78)
- ReleaseMutex (Address: 0x180050ee0)
- ReleaseSemaphore (Address: 0x180050ee8)
- ReleaseSRWLockExclusive (Address: 0x180050f10)
- ReleaseSRWLockShared (Address: 0x180050f00)
- RtlCaptureContext (Address: 0x180050c90)
- RtlLookupFunctionEntry (Address: 0x180050c98)
- RtlVirtualUnwind (Address: 0x180050ca0)
- SetEnvironmentVariableW (Address: 0x180050d78)
- SetEvent (Address: 0x180050d70)
- SetFileAttributesW (Address: 0x180050dd8)
- SetFileInformationByHandle (Address: 0x180050da0)
- SetLastError (Address: 0x180050ef8)
- SetThreadpoolTimer (Address: 0x180050ed8)
- SetUnhandledExceptionFilter (Address: 0x180050cb0)
- SizeofResource (Address: 0x180050d08)
- Sleep (Address: 0x180050c88)
- TerminateProcess (Address: 0x180050cc0)
- TlsAlloc (Address: 0x180050d20)
- TlsGetValue (Address: 0x180050d18)
- TlsSetValue (Address: 0x180050d10)
- UnhandledExceptionFilter (Address: 0x180050ca8)
- WaitForSingleObject (Address: 0x180050e98)
- WaitForSingleObjectEx (Address: 0x180050ec0)
- WaitForThreadpoolTimerCallbacks (Address: 0x180050ed0)
- WideCharToMultiByte (Address: 0x180050ce0)
- WritePrivateProfileStringW (Address: 0x180050d90)
ktmw32.dll
- CommitTransaction (Address: 0x180051110)
- CreateTransaction (Address: 0x180051108)
msvcrt.dll
- __C_specific_handler (Address: 0x180051188)
- __CxxFrameHandler3 (Address: 0x1800511d0)
- __dllonexit (Address: 0x180051200)
- __RTDynamicCast (Address: 0x180051120)
- _amsg_exit (Address: 0x1800511c8)
- _callnewh (Address: 0x1800511b0)
- _CxxThrowException (Address: 0x1800511b8)
- _errno (Address: 0x180051210)
- _initterm (Address: 0x1800511d8)
- _lock (Address: 0x1800511f0)
- _onexit (Address: 0x180051208)
- _purecall (Address: 0x180051180)
- _set_errno (Address: 0x180051248)
- _unlock (Address: 0x1800511f8)
- _vscwprintf (Address: 0x180051170)
- _vsnprintf_s (Address: 0x180051148)
- _vsnwprintf (Address: 0x180051270)
- _wcsicmp (Address: 0x180051160)
- _wcsnicmp (Address: 0x180051278)
- _wtoi (Address: 0x180051230)
- _wtoi64 (Address: 0x180051228)
- _wtol (Address: 0x180051220)
- _XcptFilter (Address: 0x1800511c0)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800511a0)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x180051138)
- ??0exception@@QEAA@XZ (Address: 0x180051150)
- ??1exception@@UEAA@XZ (Address: 0x180051268)
- ??1type_info@@UEAA@XZ (Address: 0x1800511e8)
- ?terminate@@YAXXZ (Address: 0x1800511e0)
- ?what@exception@@UEBAPEBDXZ (Address: 0x1800511a8)
- calloc (Address: 0x180051178)
- free (Address: 0x180051168)
- malloc (Address: 0x180051198)
- memcmp (Address: 0x180051128)
- memcpy (Address: 0x180051130)
- memcpy_s (Address: 0x180051140)
- memmove_s (Address: 0x180051158)
- memset (Address: 0x180051218)
- sprintf_s (Address: 0x180051238)
- strchr (Address: 0x180051240)
- strncpy_s (Address: 0x180051258)
- strtol (Address: 0x180051250)
- vswprintf_s (Address: 0x180051288)
- wcschr (Address: 0x180051260)
- wcscmp (Address: 0x180051290)
- wcscpy_s (Address: 0x180051190)
- wcsrchr (Address: 0x180051280)
ntdll.dll
- NtSetInformationFile (Address: 0x1800512a8)
- RtlAllocateHeap (Address: 0x1800512b8)
- RtlFreeHeap (Address: 0x1800512b0)
- RtlNtStatusToDosError (Address: 0x1800512c0)
- RtlSetThreadErrorMode (Address: 0x1800512a0)
ole32.dll
- CoCreateInstance (Address: 0x1800512d0)
- CoTaskMemFree (Address: 0x1800512e0)
- StringFromGUID2 (Address: 0x1800512d8)
OLEAUT32.dll
- SysAllocString (Address: 0x180050f38)
- SysFreeString (Address: 0x180050f40)
ReAgent.dll
- WinReGetConfig (Address: 0x180050f68)
- WinReHashWimFile (Address: 0x180050f70)
- WinReInstallOnTargetOS (Address: 0x180050f60)
- WinReSetupBackupWinRE (Address: 0x180050f78)
RPCRT4.dll
- UuidCreate (Address: 0x180050f50)
USER32.dll
- UnregisterClassA (Address: 0x180050f88)
WDSCORE.dll
- ConstructPartialMsgVW (Address: 0x180050fb0)
- CurrentIP (Address: 0x180050fb8)
- WdsInitialize (Address: 0x180050f98)
- WdsSetupLogMessageW (Address: 0x180050fa8)
- WdsTerminate (Address: 0x180050fa0)
WIMGAPI.DLL
- WIMCloseHandle (Address: 0x180050fd0)
- WIMCreateFile (Address: 0x180051008)
- WIMExportImage (Address: 0x180050fe8)
- WIMGetAttributes (Address: 0x180051000)
- WIMLoadImage (Address: 0x180050ff0)
- WIMRegisterLogFile (Address: 0x180050fe0)
- WIMRegisterMessageCallback (Address: 0x180050fc8)
- WIMSetTemporaryPath (Address: 0x180050ff8)
- WIMUnmountImage (Address: 0x180050fd8)
- WIMUnregisterLogFile (Address: 0x180051018)
- WIMUnregisterMessageCallback (Address: 0x180051010)
WINTRUST.dll
- WinVerifyTrust (Address: 0x180051038)
- WTHelperGetProvSignerFromChain (Address: 0x180051028)
- WTHelperProvDataFromStateData (Address: 0x180051030)