msoobeplugins.dll
Description: msoobeplugins
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6392
Architecture: 64-bit
Operating System: Windows NT
SHA256: 4bbdbacc8c64e0c2652e57b359ca521b
File Size: 1.0 MB
Uploaded At: Dec. 1, 2025, 7:50 a.m.
Views: 5
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x67c0)
- DllGetActivationFactory (Ordinal: 2, Address: 0x6400)
- DllGetClassObject (Ordinal: 3, Address: 0x65e0)
Imported DLLs & Functions
ADVAPI32.dll
- CheckTokenMembership (Address: 0x1800c6048)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800c6040)
- CreateWellKnownSid (Address: 0x1800c6058)
- DuplicateToken (Address: 0x1800c6030)
- LogonUserW (Address: 0x1800c6038)
- RegDeleteKeyExW (Address: 0x1800c6028)
- RegSetKeySecurity (Address: 0x1800c6020)
- TraceMessage (Address: 0x1800c6050)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x1800c6430)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
- CStdStubBuffer2_Connect (Address: 0x1800c6448)
- CStdStubBuffer2_CountRefs (Address: 0x1800c6490)
- CStdStubBuffer2_Disconnect (Address: 0x1800c64a8)
- CStdStubBuffer2_QueryInterface (Address: 0x1800c64c0)
- NdrProxyForwardingFunction3 (Address: 0x1800c6450)
- NdrProxyForwardingFunction4 (Address: 0x1800c64d0)
- NdrProxyForwardingFunction5 (Address: 0x1800c64d8)
- ObjectStublessClient10 (Address: 0x1800c6460)
- ObjectStublessClient11 (Address: 0x1800c6488)
- ObjectStublessClient12 (Address: 0x1800c6478)
- ObjectStublessClient13 (Address: 0x1800c64b8)
- ObjectStublessClient14 (Address: 0x1800c6480)
- ObjectStublessClient15 (Address: 0x1800c6440)
- ObjectStublessClient16 (Address: 0x1800c6458)
- ObjectStublessClient17 (Address: 0x1800c6470)
- ObjectStublessClient18 (Address: 0x1800c6498)
- ObjectStublessClient19 (Address: 0x1800c64c8)
- ObjectStublessClient20 (Address: 0x1800c64a0)
- ObjectStublessClient3 (Address: 0x1800c6468)
- ObjectStublessClient6 (Address: 0x1800c64e0)
- ObjectStublessClient7 (Address: 0x1800c64b0)
- ObjectStublessClient8 (Address: 0x1800c64e8)
- ObjectStublessClient9 (Address: 0x1800c64f0)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800c6508)
- IsDebuggerPresent (Address: 0x1800c6500)
- OutputDebugStringW (Address: 0x1800c6510)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800c6520)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800c6530)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800c6540)
- RaiseException (Address: 0x1800c6548)
- SetLastError (Address: 0x1800c6550)
- SetUnhandledExceptionFilter (Address: 0x1800c6560)
- UnhandledExceptionFilter (Address: 0x1800c6558)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x1800c6580)
- DeleteFileW (Address: 0x1800c65a8)
- FindFirstVolumeW (Address: 0x1800c6578)
- FindNextVolumeW (Address: 0x1800c65a0)
- GetDriveTypeW (Address: 0x1800c6598)
- GetFileSize (Address: 0x1800c6588)
- GetTempFileNameW (Address: 0x1800c6570)
- ReadFile (Address: 0x1800c65b0)
- WriteFile (Address: 0x1800c6590)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x1800c65c0)
- GetVolumePathNamesForVolumeNameW (Address: 0x1800c65c8)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800c65e0)
- DuplicateHandle (Address: 0x1800c65d8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800c65f8)
- HeapAlloc (Address: 0x1800c65f0)
- HeapDestroy (Address: 0x1800c6610)
- HeapFree (Address: 0x1800c6618)
- HeapReAlloc (Address: 0x1800c6608)
- HeapSize (Address: 0x1800c6600)
api-ms-win-core-heap-l2-1-0.dll
- GlobalAlloc (Address: 0x1800c6630)
- GlobalFree (Address: 0x1800c6638)
- LocalAlloc (Address: 0x1800c6628)
- LocalFree (Address: 0x1800c6648)
- LocalReAlloc (Address: 0x1800c6640)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- GlobalLock (Address: 0x1800c6668)
- GlobalSize (Address: 0x1800c6658)
- GlobalUnlock (Address: 0x1800c6660)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x1800c6678)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x1800c6688)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- DnsHostnameToComputerNameW (Address: 0x1800c66a0)
- GetComputerNameW (Address: 0x1800c66a8)
- GetSystemPowerStatus (Address: 0x1800c6698)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
- PowerClearRequest (Address: 0x1800c66c0)
- PowerCreateRequest (Address: 0x1800c66b8)
- PowerSetRequest (Address: 0x1800c66c8)
api-ms-win-core-kernel32-legacy-l1-1-5.dll
- SetThreadExecutionState (Address: 0x1800c66d8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1800c66e8)
- FindResourceExW (Address: 0x1800c66f8)
- FreeLibrary (Address: 0x1800c6738)
- GetModuleFileNameA (Address: 0x1800c6710)
- GetModuleHandleExW (Address: 0x1800c6708)
- GetModuleHandleW (Address: 0x1800c66f0)
- GetProcAddress (Address: 0x1800c6718)
- LoadLibraryExW (Address: 0x1800c6730)
- LoadResource (Address: 0x1800c6720)
- LoadStringW (Address: 0x1800c6700)
- LockResource (Address: 0x1800c6740)
- SizeofResource (Address: 0x1800c6728)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryW (Address: 0x1800c6750)
api-ms-win-core-localization-l1-2-0.dll
- EnumSystemGeoID (Address: 0x1800c6788)
- EnumSystemLocalesW (Address: 0x1800c6768)
- FormatMessageW (Address: 0x1800c6790)
- GetACP (Address: 0x1800c67c8)
- GetCPInfo (Address: 0x1800c67b8)
- GetFileMUIPath (Address: 0x1800c6798)
- GetGeoInfoW (Address: 0x1800c67f8)
- GetLocaleInfoEx (Address: 0x1800c6770)
- GetLocaleInfoW (Address: 0x1800c67c0)
- GetSystemPreferredUILanguages (Address: 0x1800c67e8)
- GetThreadPreferredUILanguages (Address: 0x1800c67d0)
- GetThreadUILanguage (Address: 0x1800c67a8)
- GetUserDefaultLCID (Address: 0x1800c6778)
- GetUserDefaultLocaleName (Address: 0x1800c67b0)
- GetUserGeoID (Address: 0x1800c6780)
- LCMapStringEx (Address: 0x1800c67f0)
- LocaleNameToLCID (Address: 0x1800c67e0)
- SetThreadPreferredUILanguages (Address: 0x1800c67d8)
- SetThreadUILanguage (Address: 0x1800c67a0)
- SetUserGeoID (Address: 0x1800c6760)
api-ms-win-core-localization-l1-2-2.dll
- GetSystemDefaultLocaleName (Address: 0x1800c6810)
- LCIDToLocaleName (Address: 0x1800c6808)
api-ms-win-core-localization-l1-2-3.dll
- GetUserDefaultGeoName (Address: 0x1800c6820)
api-ms-win-core-localization-private-l1-1-0.dll
- NlsUpdateLocale (Address: 0x1800c6830)
api-ms-win-core-path-l1-1-0.dll
- PathCchAppend (Address: 0x1800c6848)
- PathCchRenameExtension (Address: 0x1800c6840)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x1800c6858)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessW (Address: 0x1800c6888)
- GetCurrentProcess (Address: 0x1800c68a0)
- GetCurrentProcessId (Address: 0x1800c6890)
- GetCurrentThread (Address: 0x1800c6870)
- GetCurrentThreadId (Address: 0x1800c6880)
- OpenProcessToken (Address: 0x1800c6868)
- OpenThreadToken (Address: 0x1800c6878)
- TerminateProcess (Address: 0x1800c6898)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x1800c68b0)
- OpenProcess (Address: 0x1800c68b8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800c68c8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800c68d8)
- RegCreateKeyExW (Address: 0x1800c6908)
- RegDeleteTreeW (Address: 0x1800c6928)
- RegDeleteValueW (Address: 0x1800c6910)
- RegEnumKeyExW (Address: 0x1800c6920)
- RegEnumValueW (Address: 0x1800c68f0)
- RegGetValueW (Address: 0x1800c68e0)
- RegOpenKeyExW (Address: 0x1800c6900)
- RegQueryInfoKeyW (Address: 0x1800c68e8)
- RegQueryValueExW (Address: 0x1800c6918)
- RegSetValueExW (Address: 0x1800c68f8)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800c6948)
- RtlLookupFunctionEntry (Address: 0x1800c6940)
- RtlVirtualUnwind (Address: 0x1800c6938)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1800c6970)
- CompareStringW (Address: 0x1800c6958)
- MultiByteToWideChar (Address: 0x1800c6968)
- WideCharToMultiByte (Address: 0x1800c6960)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800c6980)
- AcquireSRWLockShared (Address: 0x1800c69c8)
- CreateEventExW (Address: 0x1800c6a28)
- CreateEventW (Address: 0x1800c69a0)
- CreateMutexExW (Address: 0x1800c69c0)
- CreateSemaphoreExW (Address: 0x1800c6a18)
- DeleteCriticalSection (Address: 0x1800c69f8)
- EnterCriticalSection (Address: 0x1800c6a00)
- InitializeCriticalSection (Address: 0x1800c6988)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800c69b8)
- InitializeCriticalSectionEx (Address: 0x1800c6a10)
- InitializeSRWLock (Address: 0x1800c6a30)
- LeaveCriticalSection (Address: 0x1800c6a08)
- OpenSemaphoreW (Address: 0x1800c69d0)
- ReleaseMutex (Address: 0x1800c69e0)
- ReleaseSemaphore (Address: 0x1800c69f0)
- ReleaseSRWLockExclusive (Address: 0x1800c6998)
- ReleaseSRWLockShared (Address: 0x1800c6990)
- ResetEvent (Address: 0x1800c69a8)
- SetEvent (Address: 0x1800c69b0)
- WaitForMultipleObjectsEx (Address: 0x1800c6a20)
- WaitForSingleObject (Address: 0x1800c69e8)
- WaitForSingleObjectEx (Address: 0x1800c69d8)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1800c6a40)
- InitOnceComplete (Address: 0x1800c6a48)
- InitOnceExecuteOnce (Address: 0x1800c6a50)
- Sleep (Address: 0x1800c6a58)
api-ms-win-core-synch-l1-2-1.dll
- WaitForMultipleObjects (Address: 0x1800c6a68)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x1800c6a90)
- GetSystemDirectoryW (Address: 0x1800c6a98)
- GetSystemTimeAsFileTime (Address: 0x1800c6a78)
- GetTickCount (Address: 0x1800c6a88)
- GetTickCount64 (Address: 0x1800c6a80)
api-ms-win-core-sysinfo-l1-2-0.dll
- SetComputerNameExW (Address: 0x1800c6aa8)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1800c6ad8)
- CloseThreadpoolWait (Address: 0x1800c6ac0)
- CreateThreadpoolTimer (Address: 0x1800c6af0)
- CreateThreadpoolWait (Address: 0x1800c6ae0)
- SetThreadpoolTimer (Address: 0x1800c6ac8)
- SetThreadpoolWait (Address: 0x1800c6ad0)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800c6ae8)
- WaitForThreadpoolWaitCallbacks (Address: 0x1800c6ab8)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- QueueUserWorkItem (Address: 0x1800c6b00)
api-ms-win-core-timezone-l1-1-0.dll
- GetDynamicTimeZoneInformation (Address: 0x1800c6b18)
- SetDynamicTimeZoneInformation (Address: 0x1800c6b10)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1800c6b30)
- EncodePointer (Address: 0x1800c6b28)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x1800c6b60)
- RoOriginateError (Address: 0x1800c6b48)
- RoOriginateErrorW (Address: 0x1800c6b50)
- RoTransformError (Address: 0x1800c6b58)
- SetRestrictedErrorInfo (Address: 0x1800c6b40)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x1800c6b80)
- RoGetMatchingRestrictedErrorInfo (Address: 0x1800c6b70)
- RoReportFailedDelegate (Address: 0x1800c6b78)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x1800c6ba8)
- RoGetActivationFactory (Address: 0x1800c6b90)
- RoInitialize (Address: 0x1800c6b98)
- RoUninitialize (Address: 0x1800c6ba0)
api-ms-win-core-winrt-string-l1-1-0.dll
- HSTRING_UserFree (Address: 0x1800c6c28)
- HSTRING_UserFree64 (Address: 0x1800c6c18)
- HSTRING_UserMarshal (Address: 0x1800c6c10)
- HSTRING_UserMarshal64 (Address: 0x1800c6c30)
- HSTRING_UserSize (Address: 0x1800c6c08)
- HSTRING_UserSize64 (Address: 0x1800c6c20)
- HSTRING_UserUnmarshal (Address: 0x1800c6c00)
- HSTRING_UserUnmarshal64 (Address: 0x1800c6be0)
- WindowsConcatString (Address: 0x1800c6bd0)
- WindowsCreateString (Address: 0x1800c6bd8)
- WindowsCreateStringReference (Address: 0x1800c6bf8)
- WindowsDeleteString (Address: 0x1800c6bc8)
- WindowsDuplicateString (Address: 0x1800c6be8)
- WindowsGetStringRawBuffer (Address: 0x1800c6bf0)
- WindowsIsStringEmpty (Address: 0x1800c6bb8)
- WindowsStringHasEmbeddedNull (Address: 0x1800c6bc0)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x1800c6da8)
- __CxxFrameHandler3 (Address: 0x1800c6ce0)
- __CxxFrameHandler4 (Address: 0x1800c6db8)
- __std_terminate (Address: 0x1800c6db0)
- _CxxThrowException (Address: 0x1800c6ce8)
- _o___std_exception_copy (Address: 0x1800c6da0)
- _o___std_exception_destroy (Address: 0x1800c6d98)
- _o___std_type_info_destroy_list (Address: 0x1800c6d90)
- _o___stdio_common_vsnprintf_s (Address: 0x1800c6d78)
- _o___stdio_common_vsprintf (Address: 0x1800c6d70)
- _o___stdio_common_vswprintf (Address: 0x1800c6d68)
- _o__callnewh (Address: 0x1800c6d60)
- _o__cexit (Address: 0x1800c6d58)
- _o__configure_narrow_argv (Address: 0x1800c6d50)
- _o__crt_atexit (Address: 0x1800c6d48)
- _o__errno (Address: 0x1800c6d40)
- _o__execute_onexit_table (Address: 0x1800c6d38)
- _o__get_errno (Address: 0x1800c6d30)
- _o__initialize_narrow_environment (Address: 0x1800c6d08)
- _o__initialize_onexit_table (Address: 0x1800c6d00)
- _o__invalid_parameter_noinfo (Address: 0x1800c6cf8)
- _o__invalid_parameter_noinfo_noreturn (Address: 0x1800c6cf0)
- _o__purecall (Address: 0x1800c6d28)
- _o__register_onexit_function (Address: 0x1800c6d20)
- _o__seh_filter_dll (Address: 0x1800c6d18)
- _o__set_errno (Address: 0x1800c6d10)
- _o__wcsicmp (Address: 0x1800c6c40)
- _o__wcsnicmp (Address: 0x1800c6c48)
- _o__wtoi (Address: 0x1800c6c50)
- _o__wtol (Address: 0x1800c6c58)
- _o_bsearch (Address: 0x1800c6c60)
- _o_free (Address: 0x1800c6c68)
- _o_iswascii (Address: 0x1800c6c70)
- _o_iswspace (Address: 0x1800c6c80)
- _o_iswupper (Address: 0x1800c6c88)
- _o_malloc (Address: 0x1800c6c90)
- _o_memcpy_s (Address: 0x1800c6c98)
- _o_rand (Address: 0x1800c6ca0)
- _o_realloc (Address: 0x1800c6ca8)
- _o_terminate (Address: 0x1800c6cb0)
- _o_toupper (Address: 0x1800c6cb8)
- _o_towlower (Address: 0x1800c6cc0)
- _o_wcscpy_s (Address: 0x1800c6cc8)
- _o_wcstok_s (Address: 0x1800c6cd0)
- _o_wcstol (Address: 0x1800c6cd8)
- memcmp (Address: 0x1800c6dc0)
- memcpy (Address: 0x1800c6dc8)
- memmove (Address: 0x1800c6c78)
- wcschr (Address: 0x1800c6d88)
- wcsrchr (Address: 0x1800c6d80)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x1800c6de0)
- _initterm_e (Address: 0x1800c6dd8)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x1800c6df8)
- wcscmp (Address: 0x1800c6e00)
- wcscspn (Address: 0x1800c6df0)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1800c6e28)
- EventRegister (Address: 0x1800c6e20)
- EventSetInformation (Address: 0x1800c6e10)
- EventUnregister (Address: 0x1800c6e18)
- EventWriteTransfer (Address: 0x1800c6e30)
api-ms-win-security-base-l1-1-0.dll
- AdjustTokenPrivileges (Address: 0x1800c6e40)
- CopySid (Address: 0x1800c6e60)
- DuplicateTokenEx (Address: 0x1800c6e78)
- GetSidLengthRequired (Address: 0x1800c6e58)
- GetSidSubAuthority (Address: 0x1800c6e50)
- GetSidSubAuthorityCount (Address: 0x1800c6e48)
- GetTokenInformation (Address: 0x1800c6e68)
- IsWellKnownSid (Address: 0x1800c6e70)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x1800c6e88)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupAccountNameW (Address: 0x1800c6e98)
- LookupPrivilegeValueW (Address: 0x1800c6ea0)
api-ms-win-security-lsapolicy-l1-1-0.dll
- LsaClose (Address: 0x1800c6ee0)
- LsaFreeMemory (Address: 0x1800c6ed8)
- LsaOpenPolicy (Address: 0x1800c6ec0)
- LsaQueryInformationPolicy (Address: 0x1800c6ec8)
- LsaRetrievePrivateData (Address: 0x1800c6eb8)
- LsaSetInformationPolicy (Address: 0x1800c6ed0)
- LsaStorePrivateData (Address: 0x1800c6eb0)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1800c6ef0)
- ConvertStringSidToSidW (Address: 0x1800c6ef8)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x1800c6f18)
- OpenSCManagerW (Address: 0x1800c6f20)
- OpenServiceW (Address: 0x1800c6f08)
- StartServiceW (Address: 0x1800c6f10)
api-ms-win-service-management-l2-1-0.dll
- ChangeServiceConfigW (Address: 0x1800c6f30)
- QueryServiceConfigW (Address: 0x1800c6f40)
- QueryServiceStatusEx (Address: 0x1800c6f38)
api-ms-win-service-winsvc-l1-1-0.dll
- ControlService (Address: 0x1800c6f50)
- QueryServiceStatus (Address: 0x1800c6f58)
api-ms-win-stateseparation-helpers-l1-1-0.dll
- GetPersistedRegistryLocationW (Address: 0x1800c6f68)
Bcp47Langs.dll
- AppendUserLanguageInternal (Address: 0x1800c6078)
- Bcp47FromLcid (Address: 0x1800c6068)
- GetUserLanguageInputMethods (Address: 0x1800c6070)
COMCTL32.dll
- (Address: 0x1800c6090)
- (Address: 0x1800c6098)
- (Address: 0x1800c60a0)
- (Address: 0x1800c60a8)
- (Address: 0x1800c60b0)
- (Address: 0x1800c60b8)
- (Address: 0x1800c6088)
credui.dll
- CredPackAuthenticationBufferW (Address: 0x1800c6f80)
- CredUnPackAuthenticationBufferW (Address: 0x1800c6f78)
CRYPTSP.dll
- CryptAcquireContextW (Address: 0x1800c60d0)
- CryptDestroyKey (Address: 0x1800c60f8)
- CryptEncrypt (Address: 0x1800c60e0)
- CryptExportKey (Address: 0x1800c60e8)
- CryptGenKey (Address: 0x1800c60c8)
- CryptImportKey (Address: 0x1800c60d8)
- CryptReleaseContext (Address: 0x1800c60f0)
Input.dll
- (Address: 0x1800c6128)
- (Address: 0x1800c6120)
- (Address: 0x1800c6118)
- (Address: 0x1800c6110)
- (Address: 0x1800c6108)
KERNEL32.dll
- CreateDirectoryW (Address: 0x1800c6158)
- EnumUILanguagesW (Address: 0x1800c6148)
- FindClose (Address: 0x1800c6178)
- FindFirstFileW (Address: 0x1800c6188)
- FindNextFileW (Address: 0x1800c6168)
- GetFileAttributesW (Address: 0x1800c6180)
- GetFullPathNameW (Address: 0x1800c6160)
- GetModuleFileNameW (Address: 0x1800c6138)
- GetPrivateProfileSectionW (Address: 0x1800c6140)
- GetSystemDefaultUILanguage (Address: 0x1800c6150)
- ResolveLocaleName (Address: 0x1800c6170)
msvcp_win.dll
- ?_Xbad_function_call@std@@YAXXZ (Address: 0x1800c6f98)
- ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800c6f90)
- ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800c6fa0)
ntdll.dll
- NtClose (Address: 0x1800c6ff0)
- NtDeviceIoControlFile (Address: 0x1800c6fe8)
- NtOpenFile (Address: 0x1800c6ff8)
- NtQueryInformationToken (Address: 0x1800c7080)
- NtQueryLicenseValue (Address: 0x1800c6fe0)
- NtQueryWnfStateData (Address: 0x1800c7010)
- NtUpdateWnfStateData (Address: 0x1800c6fb8)
- RtlAllocateHeap (Address: 0x1800c7070)
- RtlCanonicalizeDomainName (Address: 0x1800c7058)
- RtlConvertSidToUnicodeString (Address: 0x1800c7060)
- RtlEqualUnicodeString (Address: 0x1800c7078)
- RtlFreeHeap (Address: 0x1800c6fd8)
- RtlFreeUnicodeString (Address: 0x1800c7088)
- RtlGetDeviceFamilyInfoEnum (Address: 0x1800c7040)
- RtlGetUILanguageInfo (Address: 0x1800c6fb0)
- RtlInitUnicodeString (Address: 0x1800c7048)
- RtlIsMultiSessionSku (Address: 0x1800c7068)
- RtlNtStatusToDosError (Address: 0x1800c6fc8)
- RtlpSetPreferredUILanguages (Address: 0x1800c6fd0)
- RtlPublishWnfStateData (Address: 0x1800c7000)
- RtlpVerifyAndCommitUILanguageSettings (Address: 0x1800c6fc0)
- RtlSubscribeWnfStateChangeNotification (Address: 0x1800c7050)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1800c7008)
- WinSqmAddToStream (Address: 0x1800c7038)
- WinSqmEndSession (Address: 0x1800c7020)
- WinSqmIncrementDWORD (Address: 0x1800c7030)
- WinSqmSetDWORD (Address: 0x1800c7028)
- WinSqmStartSession (Address: 0x1800c7018)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x1800c61f0)
- CStdStubBuffer_Connect (Address: 0x1800c6248)
- CStdStubBuffer_CountRefs (Address: 0x1800c6200)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800c61e0)
- CStdStubBuffer_DebugServerRelease (Address: 0x1800c6218)
- CStdStubBuffer_Disconnect (Address: 0x1800c6228)
- CStdStubBuffer_Invoke (Address: 0x1800c61d0)
- CStdStubBuffer_IsIIDSupported (Address: 0x1800c6240)
- CStdStubBuffer_QueryInterface (Address: 0x1800c6208)
- IUnknown_AddRef_Proxy (Address: 0x1800c61d8)
- IUnknown_QueryInterface_Proxy (Address: 0x1800c6230)
- IUnknown_Release_Proxy (Address: 0x1800c61f8)
- NdrClientCall3 (Address: 0x1800c6260)
- NdrCStdStubBuffer_Release (Address: 0x1800c61c8)
- NdrCStdStubBuffer2_Release (Address: 0x1800c61b8)
- NdrDllCanUnloadNow (Address: 0x1800c61c0)
- NdrDllGetClassObject (Address: 0x1800c6220)
- NdrOleAllocate (Address: 0x1800c6210)
- NdrOleFree (Address: 0x1800c61e8)
- NdrStubCall3 (Address: 0x1800c6258)
- NdrStubForwardingFunction (Address: 0x1800c6250)
- RpcBindingFree (Address: 0x1800c6268)
- RpcBindingFromStringBindingW (Address: 0x1800c61a0)
- RpcExceptionFilter (Address: 0x1800c61b0)
- RpcStringBindingComposeW (Address: 0x1800c6198)
- RpcStringFreeW (Address: 0x1800c61a8)
- UuidCreate (Address: 0x1800c6238)
SHELL32.dll
- (Address: 0x1800c6278)
- ShellExecuteExW (Address: 0x1800c6280)
- SHGetFolderPathEx (Address: 0x1800c6290)
- SHGetKnownFolderPath (Address: 0x1800c6288)
SHLWAPI.dll
- (Address: 0x1800c62a0)
- (Address: 0x1800c62c0)
- (Address: 0x1800c62e0)
- (Address: 0x1800c62e8)
- (Address: 0x1800c62f0)
- (Address: 0x1800c6300)
- (Address: 0x1800c6308)
- PathAppendW (Address: 0x1800c62b0)
- SHCreateStreamOnFileW (Address: 0x1800c62a8)
- SHDeleteValueW (Address: 0x1800c62d8)
- SHStrDupW (Address: 0x1800c62f8)
- StrChrW (Address: 0x1800c62c8)
- StrStrW (Address: 0x1800c62b8)
- StrTrimW (Address: 0x1800c62d0)
USER32.dll
- DefWindowProcW (Address: 0x1800c6348)
- DestroyWindow (Address: 0x1800c6320)
- DispatchMessageW (Address: 0x1800c63b8)
- ExitWindowsEx (Address: 0x1800c63c0)
- GetForegroundWindow (Address: 0x1800c6318)
- GetMessageW (Address: 0x1800c6358)
- GetPointerDevices (Address: 0x1800c6378)
- GetWindowLongPtrW (Address: 0x1800c6340)
- KillTimer (Address: 0x1800c6368)
- LoadCursorW (Address: 0x1800c63b0)
- MsgWaitForMultipleObjectsEx (Address: 0x1800c6388)
- PeekMessageW (Address: 0x1800c6390)
- PostMessageW (Address: 0x1800c6328)
- PostQuitMessage (Address: 0x1800c6398)
- RegisterDeviceNotificationW (Address: 0x1800c6360)
- RegisterWindowMessageW (Address: 0x1800c6330)
- SetCursor (Address: 0x1800c63a8)
- SetTimer (Address: 0x1800c6350)
- SetWindowLongPtrW (Address: 0x1800c6380)
- TranslateMessage (Address: 0x1800c63a0)
- UnregisterClassA (Address: 0x1800c6338)
- UnregisterDeviceNotification (Address: 0x1800c6370)
USERENV.dll
- (Address: 0x1800c63d8)
- DeleteProfileW (Address: 0x1800c63e0)
- LoadUserProfileW (Address: 0x1800c63e8)
- UnloadUserProfile (Address: 0x1800c63d0)
WINBRAND.dll
- EulaFreeBuffer (Address: 0x1800c6400)
- GetEULAFile (Address: 0x1800c6410)
- GetInstalledEULAPath (Address: 0x1800c63f8)
- InstallEULA (Address: 0x1800c6408)
WinLangdb.dll
- SetUserLanguages (Address: 0x1800c6420)