AudioSrvPolicyManager.dll

Description: Windows Audio Service Policy Manager

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 64-bit

Operating System: Windows NT

SHA256: 2b5a9890a8c8207c42b0418fc369ac4e

File Size: 341.0 KB

Uploaded At: Dec. 1, 2025, 7:23 a.m.

Views: 23

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • HHOSTEDAPPMANAGERCONTEXTRundown (Ordinal: 1, Address: 0x23f40)
  • TS_SessionChanged (Ordinal: 2, Address: 0x2a7f0)
  • ActivatePolicyManager (Ordinal: 3, Address: 0x59f0)
  • PbmAllowMediaPlaybackForApp (Ordinal: 4, Address: 0x232a0)
  • PbmCastingAppStateChanged (Ordinal: 5, Address: 0x23d90)
  • PbmGetSoundLevel (Ordinal: 6, Address: 0x23720)
  • PbmIsPlaying (Ordinal: 7, Address: 0x23860)
  • PbmLaunchBackgroundTask (Ordinal: 8, Address: 0x242e0)
  • PbmPlayToStreamStateChanged (Ordinal: 9, Address: 0x23c40)
  • PbmRegisterAppClosureNotification (Ordinal: 10, Address: 0x23ac0)
  • PbmRegisterAppManagerNotification (Ordinal: 11, Address: 0x23980)
  • PbmRegisterPlaybackManagerNotifications (Ordinal: 12, Address: 0x233a0)
  • PbmReportAppClosing (Ordinal: 13, Address: 0x23230)
  • PbmReportAppInteractivityChange (Ordinal: 14, Address: 0x230d0)
  • PbmReportApplicationState (Ordinal: 15, Address: 0x24200)
  • PbmReportHostedAppStateChange (Ordinal: 16, Address: 0x231a0)
  • PbmSetScreenReaderState (Ordinal: 17, Address: 0x240b0)
  • PbmSetSmtcSubscriptionState (Ordinal: 18, Address: 0x23590)
  • PbmSwitchSoftNonInteractiveAppsToHardNonInteractive (Ordinal: 19, Address: 0x23150)
  • PbmUnregisterAppClosureNotification (Ordinal: 20, Address: 0x23b60)
  • PbmUnregisterAppManagerNotification (Ordinal: 21, Address: 0x23a20)
  • PbmUnregisterPlaybackManagerNotifications (Ordinal: 22, Address: 0x23460)
  • TS_AudioProtocolNotifyRundown (Ordinal: 23, Address: 0x2ae20)
  • TS_RegisterAudioProtocolNotification (Ordinal: 24, Address: 0x2ad60)
  • TS_SessionGetAudioProtocol (Ordinal: 25, Address: 0x2acb0)
  • TS_UnregisterAudioProtocolNotification (Ordinal: 26, Address: 0x2adc0)

Imported DLLs & Functions

api-ms-win-appmodel-runtime-l1-1-1.dll
  • ParseApplicationUserModelId (Address: 0x1800409c0)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x1800409d0)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x1800409f8)
  • CoInitializeEx (Address: 0x1800409f0)
  • CoTaskMemAlloc (Address: 0x1800409e0)
  • CoTaskMemFree (Address: 0x180040a00)
  • CoTaskMemRealloc (Address: 0x180040a08)
  • CoUninitialize (Address: 0x1800409e8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180040a20)
  • IsDebuggerPresent (Address: 0x180040a28)
  • OutputDebugStringW (Address: 0x180040a18)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180040a38)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180040a48)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180040a60)
  • RaiseException (Address: 0x180040a58)
  • SetLastError (Address: 0x180040a68)
  • SetUnhandledExceptionFilter (Address: 0x180040a78)
  • UnhandledExceptionFilter (Address: 0x180040a70)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180040a90)
  • DuplicateHandle (Address: 0x180040a88)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180040ac8)
  • HeapAlloc (Address: 0x180040aa8)
  • HeapDestroy (Address: 0x180040ab8)
  • HeapFree (Address: 0x180040aa0)
  • HeapReAlloc (Address: 0x180040ac0)
  • HeapSize (Address: 0x180040ab0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180040ad8)
  • LocalFree (Address: 0x180040ae0)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180040af0)
api-ms-win-core-io-l1-1-0.dll
  • CreateIoCompletionPort (Address: 0x180040b10)
  • GetQueuedCompletionStatus (Address: 0x180040b08)
  • PostQueuedCompletionStatus (Address: 0x180040b00)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180040b38)
  • FindResourceExW (Address: 0x180040b60)
  • FreeLibrary (Address: 0x180040b68)
  • GetModuleFileNameA (Address: 0x180040b50)
  • GetModuleHandleExW (Address: 0x180040b48)
  • GetModuleHandleW (Address: 0x180040b58)
  • GetProcAddress (Address: 0x180040b28)
  • LoadLibraryExW (Address: 0x180040b70)
  • LoadResource (Address: 0x180040b30)
  • LockResource (Address: 0x180040b20)
  • SizeofResource (Address: 0x180040b40)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180040b80)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x180040ba0)
  • GetCurrentProcess (Address: 0x180040bb0)
  • GetCurrentProcessId (Address: 0x180040ba8)
  • GetCurrentThread (Address: 0x180040bc8)
  • GetCurrentThreadId (Address: 0x180040bc0)
  • OpenProcessToken (Address: 0x180040b98)
  • OpenThreadToken (Address: 0x180040b90)
  • TerminateProcess (Address: 0x180040bb8)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180040be0)
  • OpenProcess (Address: 0x180040bd8)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180040bf0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180040c60)
  • RegCreateKeyExW (Address: 0x180040c18)
  • RegDeleteTreeW (Address: 0x180040c58)
  • RegDeleteValueW (Address: 0x180040c48)
  • RegEnumValueW (Address: 0x180040c38)
  • RegGetKeySecurity (Address: 0x180040c28)
  • RegGetValueW (Address: 0x180040c20)
  • RegOpenCurrentUser (Address: 0x180040c08)
  • RegOpenKeyExW (Address: 0x180040c00)
  • RegQueryInfoKeyW (Address: 0x180040c40)
  • RegQueryValueExW (Address: 0x180040c10)
  • RegSetKeySecurity (Address: 0x180040c50)
  • RegSetValueExW (Address: 0x180040c30)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180040c78)
  • RtlLookupFunctionEntry (Address: 0x180040c70)
  • RtlVirtualUnwind (Address: 0x180040c80)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x180040c90)
  • CompareStringW (Address: 0x180040c98)
api-ms-win-core-string-l2-1-0.dll
  • IsCharAlphaNumericW (Address: 0x180040cb0)
  • IsCharAlphaW (Address: 0x180040ca8)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180040d50)
  • AcquireSRWLockShared (Address: 0x180040d40)
  • CreateEventW (Address: 0x180040d20)
  • CreateMutexExW (Address: 0x180040d10)
  • CreateSemaphoreExW (Address: 0x180040d08)
  • DeleteCriticalSection (Address: 0x180040cc8)
  • EnterCriticalSection (Address: 0x180040ce8)
  • InitializeCriticalSection (Address: 0x180040cc0)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180040cf8)
  • InitializeCriticalSectionEx (Address: 0x180040d30)
  • InitializeSRWLock (Address: 0x180040d28)
  • LeaveCriticalSection (Address: 0x180040d38)
  • OpenSemaphoreW (Address: 0x180040cd8)
  • ReleaseMutex (Address: 0x180040cd0)
  • ReleaseSemaphore (Address: 0x180040cf0)
  • ReleaseSRWLockExclusive (Address: 0x180040d60)
  • ReleaseSRWLockShared (Address: 0x180040d58)
  • ResetEvent (Address: 0x180040d18)
  • SetEvent (Address: 0x180040d00)
  • WaitForSingleObject (Address: 0x180040ce0)
  • WaitForSingleObjectEx (Address: 0x180040d48)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180040d80)
  • InitOnceComplete (Address: 0x180040d70)
  • Sleep (Address: 0x180040d78)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180040d98)
  • GetTickCount64 (Address: 0x180040d90)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpool (Address: 0x180040e10)
  • CloseThreadpoolTimer (Address: 0x180040db8)
  • CloseThreadpoolWait (Address: 0x180040e20)
  • CloseThreadpoolWork (Address: 0x180040df8)
  • CreateThreadpool (Address: 0x180040dd8)
  • CreateThreadpoolCleanupGroup (Address: 0x180040da8)
  • CreateThreadpoolTimer (Address: 0x180040dd0)
  • CreateThreadpoolWait (Address: 0x180040e18)
  • CreateThreadpoolWork (Address: 0x180040df0)
  • SetThreadpoolThreadMaximum (Address: 0x180040de8)
  • SetThreadpoolThreadMinimum (Address: 0x180040de0)
  • SetThreadpoolTimer (Address: 0x180040dc8)
  • SetThreadpoolWait (Address: 0x180040e28)
  • SubmitThreadpoolWork (Address: 0x180040e00)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180040db0)
  • WaitForThreadpoolWaitCallbacks (Address: 0x180040e08)
  • WaitForThreadpoolWorkCallbacks (Address: 0x180040dc0)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180040e38)
  • RoGetActivationFactory (Address: 0x180040e40)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x180040e60)
  • WindowsDeleteString (Address: 0x180040e50)
  • WindowsGetStringRawBuffer (Address: 0x180040e58)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x180040e70)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x180040fa8)
  • __CxxFrameHandler3 (Address: 0x180040f48)
  • __CxxFrameHandler4 (Address: 0x180040fb8)
  • __std_terminate (Address: 0x180040fb0)
  • __std_type_info_compare (Address: 0x180040fa0)
  • _CxxThrowException (Address: 0x180040fc0)
  • _o___std_exception_copy (Address: 0x180040f98)
  • _o___std_exception_destroy (Address: 0x180040f90)
  • _o___std_type_info_destroy_list (Address: 0x180040f88)
  • _o___stdio_common_vsnprintf_s (Address: 0x180040f80)
  • _o___stdio_common_vswprintf (Address: 0x180040f78)
  • _o__cexit (Address: 0x180040f70)
  • _o__configure_narrow_argv (Address: 0x180040f68)
  • _o__crt_atexit (Address: 0x180040f60)
  • _o__errno (Address: 0x180040f58)
  • _o__execute_onexit_table (Address: 0x180040f50)
  • _o__get_errno (Address: 0x180040e80)
  • _o__initialize_narrow_environment (Address: 0x180040e88)
  • _o__initialize_onexit_table (Address: 0x180040e90)
  • _o__invalid_parameter_noinfo (Address: 0x180040e98)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x180040ea0)
  • _o__purecall (Address: 0x180040ea8)
  • _o__recalloc (Address: 0x180040eb0)
  • _o__register_onexit_function (Address: 0x180040eb8)
  • _o__resetstkoflw (Address: 0x180040ec0)
  • _o__seh_filter_dll (Address: 0x180040ec8)
  • _o__set_errno (Address: 0x180040ed0)
  • _o__wcsicmp (Address: 0x180040ee0)
  • _o__wcsicoll (Address: 0x180040ee8)
  • _o__wtoi (Address: 0x180040ef0)
  • _o_calloc (Address: 0x180040ef8)
  • _o_free (Address: 0x180040f00)
  • _o_log10 (Address: 0x180040f08)
  • _o_malloc (Address: 0x180040f10)
  • _o_pow (Address: 0x180040f18)
  • _o_terminate (Address: 0x180040f20)
  • _o_wcsncpy_s (Address: 0x180040f28)
  • _o_wmemcpy_s (Address: 0x180040f30)
  • memcpy (Address: 0x180040fc8)
  • memmove (Address: 0x180040ed8)
  • wcschr (Address: 0x180040f40)
  • wcsstr (Address: 0x180040f38)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180040fe0)
  • _initterm_e (Address: 0x180040fd8)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180040ff0)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x180041028)
  • GetTraceEnableLevel (Address: 0x180041020)
  • GetTraceLoggerHandle (Address: 0x180041018)
  • RegisterTraceGuidsW (Address: 0x180041010)
  • TraceMessage (Address: 0x180041008)
  • UnregisterTraceGuids (Address: 0x180041000)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x180041038)
  • EventSetInformation (Address: 0x180041040)
  • EventUnregister (Address: 0x180041050)
  • EventWriteTransfer (Address: 0x180041048)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAceEx (Address: 0x180041118)
  • AddAce (Address: 0x180041070)
  • AllocateAndInitializeSid (Address: 0x180041120)
  • CopySid (Address: 0x180041080)
  • EqualSid (Address: 0x1800410a0)
  • GetAce (Address: 0x1800410e0)
  • GetAclInformation (Address: 0x180041098)
  • GetLengthSid (Address: 0x1800410f8)
  • GetSecurityDescriptorControl (Address: 0x1800410c8)
  • GetSecurityDescriptorDacl (Address: 0x180041100)
  • GetSecurityDescriptorGroup (Address: 0x1800410f0)
  • GetSecurityDescriptorLength (Address: 0x1800410c0)
  • GetSecurityDescriptorOwner (Address: 0x1800410e8)
  • GetSecurityDescriptorSacl (Address: 0x180041060)
  • GetSidLengthRequired (Address: 0x180041090)
  • GetSidSubAuthority (Address: 0x1800410b0)
  • GetSidSubAuthorityCount (Address: 0x1800410b8)
  • GetTokenInformation (Address: 0x1800410d8)
  • InitializeAcl (Address: 0x180041130)
  • InitializeSecurityDescriptor (Address: 0x180041110)
  • InitializeSid (Address: 0x180041088)
  • IsValidSid (Address: 0x1800410a8)
  • MakeAbsoluteSD (Address: 0x180041108)
  • MakeSelfRelativeSD (Address: 0x180041078)
  • SetKernelObjectSecurity (Address: 0x180041128)
  • SetSecurityDescriptorDacl (Address: 0x1800410d0)
  • SetSecurityDescriptorSacl (Address: 0x180041068)
api-ms-win-security-base-l1-2-0.dll
  • CheckTokenCapability (Address: 0x180041140)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x180041150)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180041160)
  • ConvertStringSidToSidW (Address: 0x180041168)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolQueueTask (Address: 0x180041178)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x180041188)
MMDevAPI.DLL
  • (Address: 0x180040950)
  • (Address: 0x180040958)
  • (Address: 0x180040960)
msvcp_win.dll
  • _Mtx_destroy_in_situ (Address: 0x180041198)
  • _Mtx_init_in_situ (Address: 0x1800411d0)
  • _Mtx_lock (Address: 0x1800411b0)
  • _Mtx_unlock (Address: 0x1800411a0)
  • ?_Throw_C_error@std@@YAXH@Z (Address: 0x1800411a8)
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x1800411b8)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800411c8)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800411c0)
ntdll.dll
  • NtAcquireProcessActivityReference (Address: 0x180041248)
  • NtOpenThreadToken (Address: 0x180041208)
  • NtQueryInformationProcess (Address: 0x180041250)
  • NtQueryInformationToken (Address: 0x180041200)
  • RtlAllocateHeap (Address: 0x180041258)
  • RtlCompareUnicodeString (Address: 0x180041268)
  • RtlDllShutdownInProgress (Address: 0x1800411e0)
  • RtlEqualWnfChangeStamps (Address: 0x180041288)
  • RtlFreeHeap (Address: 0x1800411e8)
  • RtlFreeSid (Address: 0x180041230)
  • RtlGetActiveConsoleId (Address: 0x180041270)
  • RtlGetAppContainerParent (Address: 0x180041238)
  • RtlGetAppContainerSidType (Address: 0x180041240)
  • RtlGetCurrentServiceSessionId (Address: 0x180041278)
  • RtlInitUnicodeString (Address: 0x180041210)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x180041260)
  • RtlPublishWnfStateData (Address: 0x180041280)
  • RtlQueryPackageClaims (Address: 0x180041220)
  • RtlQueryTokenHostIdAsUlong64 (Address: 0x180041218)
  • RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x180041228)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x1800411f8)
  • RtlUnsubscribeWnfStateChangeNotification (Address: 0x1800411f0)
POWRPROF.dll
  • GetPwrCapabilities (Address: 0x180040988)
  • PowerSettingRegisterNotification (Address: 0x180040980)
  • PowerSettingRegisterNotificationEx (Address: 0x180040978)
  • PowerSettingUnregisterNotification (Address: 0x180040970)
RPCRT4.dll
  • I_RpcBindingInqLocalClientPID (Address: 0x1800409a0)
  • RpcImpersonateClient (Address: 0x180040998)
  • RpcRevertToSelf (Address: 0x1800409a8)
  • RpcServerInqCallAttributesW (Address: 0x1800409b0)