WpdMtpDr.dll
Description: Windows Portable Device Media Transfer Protocol Driver
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 64-bit
Operating System: Windows NT
SHA256: 83bd62d9144a08111c6abe5f8115a6e9
File Size: 910.0 KB
Uploaded At: Dec. 1, 2025, 7:47 a.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x10bc0)
- DllGetClassObject (Ordinal: 2, Address: 0x10c00)
- DllRegisterServer (Ordinal: 3, Address: 0x10d40)
- DllUnregisterServer (Ordinal: 4, Address: 0x10e70)
- DriverEntry (Ordinal: 5, Address: 0x1260)
- Microsoft_WDF_UMDF_Version (Ordinal: 6, Address: 0xd7340)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x1800b2110)
- AuditFree (Address: 0x1800b20e0)
- AuditQueryPerUserPolicy (Address: 0x1800b20d8)
- AuditQuerySystemPolicy (Address: 0x1800b20e8)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800b2108)
- CopySid (Address: 0x1800b20f0)
- EventActivityIdControl (Address: 0x1800b2098)
- EventRegister (Address: 0x1800b20a8)
- EventUnregister (Address: 0x1800b20a0)
- EventWriteTransfer (Address: 0x1800b2100)
- GetTokenInformation (Address: 0x1800b20f8)
- GetTraceEnableFlags (Address: 0x1800b20c0)
- GetTraceEnableLevel (Address: 0x1800b20c8)
- GetTraceLoggerHandle (Address: 0x1800b20d0)
- LookupPrivilegeValueW (Address: 0x1800b2118)
- OpenProcessToken (Address: 0x1800b2120)
- RegCloseKey (Address: 0x1800b2160)
- RegCreateKeyExW (Address: 0x1800b2138)
- RegDeleteValueW (Address: 0x1800b2130)
- RegEnumKeyExW (Address: 0x1800b2150)
- RegisterTraceGuidsW (Address: 0x1800b20b8)
- RegOpenKeyExW (Address: 0x1800b2148)
- RegQueryInfoKeyW (Address: 0x1800b2158)
- RegQueryValueExW (Address: 0x1800b2090)
- RegSetValueExW (Address: 0x1800b2140)
- TraceEvent (Address: 0x1800b2128)
- TraceMessage (Address: 0x1800b2168)
- UnregisterTraceGuids (Address: 0x1800b20b0)
api-ms-win-core-winrt-l1-1-0.dll
- RoGetActivationFactory (Address: 0x1800b2440)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateStringReference (Address: 0x1800b2458)
- WindowsDeleteString (Address: 0x1800b2450)
- WindowsGetStringRawBuffer (Address: 0x1800b2460)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x1800b2338)
- AcquireSRWLockShared (Address: 0x1800b2348)
- CloseHandle (Address: 0x1800b2318)
- CompareStringW (Address: 0x1800b21e0)
- CreateEventW (Address: 0x1800b2278)
- CreateSemaphoreW (Address: 0x1800b21b0)
- CreateThread (Address: 0x1800b2320)
- DelayLoadFailureHook (Address: 0x1800b2380)
- DeleteCriticalSection (Address: 0x1800b2300)
- DisableThreadLibraryCalls (Address: 0x1800b2378)
- EnterCriticalSection (Address: 0x1800b22c8)
- FileTimeToSystemTime (Address: 0x1800b21d8)
- FindResourceExW (Address: 0x1800b22e8)
- FreeLibrary (Address: 0x1800b2288)
- GetCurrentProcess (Address: 0x1800b2310)
- GetCurrentProcessId (Address: 0x1800b2358)
- GetCurrentThreadId (Address: 0x1800b2250)
- GetLastError (Address: 0x1800b2290)
- GetModuleFileNameW (Address: 0x1800b22f0)
- GetModuleHandleW (Address: 0x1800b22a8)
- GetProcAddress (Address: 0x1800b2298)
- GetProcessHeap (Address: 0x1800b2210)
- GetSystemTimeAsFileTime (Address: 0x1800b2258)
- GetThreadLocale (Address: 0x1800b21c8)
- GetTickCount (Address: 0x1800b2260)
- GetVersion (Address: 0x1800b21e8)
- HeapAlloc (Address: 0x1800b2208)
- HeapDestroy (Address: 0x1800b2218)
- HeapFree (Address: 0x1800b2200)
- HeapReAlloc (Address: 0x1800b21f8)
- HeapSize (Address: 0x1800b21f0)
- InitializeCriticalSection (Address: 0x1800b22f8)
- InitializeSRWLock (Address: 0x1800b2280)
- InitOnceExecuteOnce (Address: 0x1800b21a0)
- LeaveCriticalSection (Address: 0x1800b22b8)
- LoadLibraryExW (Address: 0x1800b22a0)
- LoadResource (Address: 0x1800b22e0)
- LocalFree (Address: 0x1800b2308)
- LockResource (Address: 0x1800b2360)
- lstrcmpiW (Address: 0x1800b22b0)
- MultiByteToWideChar (Address: 0x1800b22d0)
- OpenProcess (Address: 0x1800b2368)
- OutputDebugStringA (Address: 0x1800b2268)
- QueryFullProcessImageNameW (Address: 0x1800b2370)
- QueryPerformanceCounter (Address: 0x1800b2248)
- RaiseException (Address: 0x1800b22c0)
- ReleaseSemaphore (Address: 0x1800b2198)
- ReleaseSRWLockExclusive (Address: 0x1800b2340)
- ReleaseSRWLockShared (Address: 0x1800b2350)
- ResetEvent (Address: 0x1800b2188)
- ResolveDelayLoadedAPI (Address: 0x1800b2270)
- SetEvent (Address: 0x1800b21b8)
- SetThreadLocale (Address: 0x1800b21c0)
- SetUnhandledExceptionFilter (Address: 0x1800b2228)
- SizeofResource (Address: 0x1800b22d8)
- Sleep (Address: 0x1800b21a8)
- SleepConditionVariableSRW (Address: 0x1800b2240)
- TerminateProcess (Address: 0x1800b2230)
- TlsAlloc (Address: 0x1800b2330)
- TlsFree (Address: 0x1800b21d0)
- TlsGetValue (Address: 0x1800b2178)
- TlsSetValue (Address: 0x1800b2180)
- UnhandledExceptionFilter (Address: 0x1800b2220)
- WaitForMultipleObjects (Address: 0x1800b2190)
- WaitForSingleObject (Address: 0x1800b2328)
- WakeAllConditionVariable (Address: 0x1800b2238)
msvcrt.dll
- __C_specific_handler (Address: 0x1800b25a0)
- __CxxFrameHandler3 (Address: 0x1800b25a8)
- __dllonexit (Address: 0x1800b2568)
- _amsg_exit (Address: 0x1800b2528)
- _callnewh (Address: 0x1800b2518)
- _CxxThrowException (Address: 0x1800b2590)
- _errno (Address: 0x1800b2548)
- _initterm (Address: 0x1800b2530)
- _lock (Address: 0x1800b2558)
- _onexit (Address: 0x1800b2570)
- _purecall (Address: 0x1800b2478)
- _unlock (Address: 0x1800b2560)
- _vscwprintf (Address: 0x1800b24a0)
- _vsnwprintf (Address: 0x1800b24b0)
- _wcsicmp (Address: 0x1800b24d0)
- _wcslwr (Address: 0x1800b24e8)
- _XcptFilter (Address: 0x1800b2520)
- ??1type_info@@UEAA@XZ (Address: 0x1800b2540)
- ?terminate@@YAXXZ (Address: 0x1800b2538)
- calloc (Address: 0x1800b2500)
- free (Address: 0x1800b2598)
- iswspace (Address: 0x1800b24f8)
- malloc (Address: 0x1800b2480)
- memcpy (Address: 0x1800b2588)
- memcpy_s (Address: 0x1800b2470)
- memmove (Address: 0x1800b2580)
- memmove_s (Address: 0x1800b2490)
- memset (Address: 0x1800b2578)
- qsort_s (Address: 0x1800b2510)
- realloc (Address: 0x1800b2550)
- towupper (Address: 0x1800b24d8)
- vswprintf_s (Address: 0x1800b24a8)
- wcscat_s (Address: 0x1800b24c0)
- wcschr (Address: 0x1800b2498)
- wcscmp (Address: 0x1800b25b0)
- wcscpy_s (Address: 0x1800b24b8)
- wcsncpy_s (Address: 0x1800b2488)
- wcsstr (Address: 0x1800b24e0)
- wcstok (Address: 0x1800b2508)
- wcstol (Address: 0x1800b24f0)
- wcstoul (Address: 0x1800b24c8)
ntdll.dll
- RtlCaptureContext (Address: 0x1800b25c0)
- RtlLookupFunctionEntry (Address: 0x1800b25c8)
- RtlVirtualUnwind (Address: 0x1800b25d0)
OLEAUT32.dll
- LoadTypeLib (Address: 0x1800b23b8)
- RegisterTypeLib (Address: 0x1800b23c0)
- SysAllocString (Address: 0x1800b23b0)
- SysAllocStringByteLen (Address: 0x1800b23d0)
- SysFreeString (Address: 0x1800b2398)
- SysStringByteLen (Address: 0x1800b2390)
- SysStringLen (Address: 0x1800b23c8)
- SystemTimeToVariantTime (Address: 0x1800b23e8)
- UnRegisterTypeLib (Address: 0x1800b23a8)
- VarCmp (Address: 0x1800b23e0)
- VariantChangeType (Address: 0x1800b23d8)
- VariantTimeToSystemTime (Address: 0x1800b23f0)
- VarUI4FromStr (Address: 0x1800b23a0)
USER32.dll
- CharNextW (Address: 0x1800b2400)
- LoadStringW (Address: 0x1800b2408)
- UnregisterClassA (Address: 0x1800b2410)
VERSION.dll
- GetFileVersionInfoSizeW (Address: 0x1800b2430)
- GetFileVersionInfoW (Address: 0x1800b2420)
- VerQueryValueW (Address: 0x1800b2428)