UserOOBE.dll

Description: UserOOBE

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5848

Architecture: 64-bit

Operating System: Windows NT

SHA256: ae50a85b9c1c5df0022e74174084c84c

File Size: 427.5 KB

Uploaded At: Dec. 1, 2025, 7:50 a.m.

Views: 5

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x5b70)
  • DllGetClassObject (Ordinal: 2, Address: 0x5bc0)

Imported DLLs & Functions

api-ms-win-appmodel-runtime-l1-1-1.dll
  • FindPackagesByPackageFamily (Address: 0x18004f7c8)
api-ms-win-appmodel-state-l1-2-0.dll
  • CloseState (Address: 0x18004f7e8)
  • GetSystemAppDataKey (Address: 0x18004f7e0)
  • OpenStateExplicit (Address: 0x18004f7d8)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18004f7f8)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x18004f870)
  • CoCreateFreeThreadedMarshaler (Address: 0x18004f820)
  • CoCreateInstance (Address: 0x18004f890)
  • CoGetApartmentType (Address: 0x18004f858)
  • CoGetCallContext (Address: 0x18004f840)
  • CoGetMalloc (Address: 0x18004f860)
  • CoGetStdMarshalEx (Address: 0x18004f898)
  • CoImpersonateClient (Address: 0x18004f878)
  • CoRegisterClassObject (Address: 0x18004f828)
  • CoRevertToSelf (Address: 0x18004f880)
  • CoRevokeClassObject (Address: 0x18004f830)
  • CoSetProxyBlanket (Address: 0x18004f818)
  • CoTaskMemAlloc (Address: 0x18004f808)
  • CoTaskMemFree (Address: 0x18004f810)
  • CoTaskMemRealloc (Address: 0x18004f850)
  • CoWaitForMultipleHandles (Address: 0x18004f888)
  • StringFromCLSID (Address: 0x18004f848)
  • StringFromGUID2 (Address: 0x18004f868)
  • StringFromIID (Address: 0x18004f838)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x18004f8a8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18004f8b8)
  • IsDebuggerPresent (Address: 0x18004f8c8)
  • OutputDebugStringW (Address: 0x18004f8c0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18004f8d8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18004f8e8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18004f908)
  • RaiseException (Address: 0x18004f8f8)
  • SetLastError (Address: 0x18004f900)
  • SetUnhandledExceptionFilter (Address: 0x18004f918)
  • UnhandledExceptionFilter (Address: 0x18004f910)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x18004f960)
  • CreateFileW (Address: 0x18004f938)
  • DeleteFileW (Address: 0x18004f978)
  • FindClose (Address: 0x18004f930)
  • FindFirstFileW (Address: 0x18004f940)
  • FindNextFileW (Address: 0x18004f950)
  • FlushFileBuffers (Address: 0x18004f970)
  • GetFileAttributesW (Address: 0x18004f968)
  • GetFileInformationByHandle (Address: 0x18004f948)
  • GetFullPathNameW (Address: 0x18004f928)
  • SetFileInformationByHandle (Address: 0x18004f958)
api-ms-win-core-file-l2-1-0.dll
  • GetFileInformationByHandleEx (Address: 0x18004f988)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18004f9a0)
  • DuplicateHandle (Address: 0x18004f998)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18004f9b8)
  • HeapAlloc (Address: 0x18004f9b0)
  • HeapFree (Address: 0x18004f9c0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18004f9d8)
  • LocalFree (Address: 0x18004f9d0)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x18004f9e8)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x18004f9f8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • MulDiv (Address: 0x18004fa08)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18004fa38)
  • FindResourceExW (Address: 0x18004fa28)
  • FreeLibrary (Address: 0x18004fa20)
  • GetModuleFileNameA (Address: 0x18004fa68)
  • GetModuleFileNameW (Address: 0x18004fa48)
  • GetModuleHandleExW (Address: 0x18004fa58)
  • GetModuleHandleW (Address: 0x18004fa50)
  • GetProcAddress (Address: 0x18004fa30)
  • LoadLibraryExW (Address: 0x18004fa60)
  • LoadResource (Address: 0x18004fa18)
  • LockResource (Address: 0x18004fa40)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18004fa78)
api-ms-win-core-path-l1-1-0.dll
  • PathCchCombine (Address: 0x18004fa88)
api-ms-win-core-privateprofile-l1-1-0.dll
  • WritePrivateProfileStringW (Address: 0x18004fa98)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18004faa8)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x18004fae0)
  • GetCurrentProcess (Address: 0x18004faf8)
  • GetCurrentProcessId (Address: 0x18004fae8)
  • GetCurrentThread (Address: 0x18004fac0)
  • GetCurrentThreadId (Address: 0x18004fad0)
  • GetProcessId (Address: 0x18004fab8)
  • OpenProcessToken (Address: 0x18004faf0)
  • OpenThreadToken (Address: 0x18004fb00)
  • ProcessIdToSessionId (Address: 0x18004fac8)
  • TerminateProcess (Address: 0x18004fad8)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x18004fb10)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18004fb20)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18004fb40)
  • RegCreateKeyExW (Address: 0x18004fb38)
  • RegDeleteKeyExW (Address: 0x18004fb70)
  • RegDeleteTreeW (Address: 0x18004fb88)
  • RegDeleteValueW (Address: 0x18004fb80)
  • RegEnumKeyExW (Address: 0x18004fb90)
  • RegEnumValueW (Address: 0x18004fb98)
  • RegFlushKey (Address: 0x18004fb60)
  • RegGetValueW (Address: 0x18004fb48)
  • RegOpenCurrentUser (Address: 0x18004fb30)
  • RegOpenKeyExW (Address: 0x18004fb68)
  • RegQueryInfoKeyW (Address: 0x18004fb78)
  • RegQueryValueExW (Address: 0x18004fb58)
  • RegSetValueExW (Address: 0x18004fb50)
api-ms-win-core-registryuserspecific-l1-1-0.dll
  • SHRegGetUSValueW (Address: 0x18004fba8)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18004fbc0)
  • RtlLookupFunctionEntry (Address: 0x18004fbc8)
  • RtlVirtualUnwind (Address: 0x18004fbb8)
api-ms-win-core-shutdown-l1-1-0.dll
  • InitiateSystemShutdownExW (Address: 0x18004fbd8)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x18004fbe8)
  • CompareStringW (Address: 0x18004fbf0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18004fc38)
  • AcquireSRWLockShared (Address: 0x18004fc50)
  • CreateEventExW (Address: 0x18004fc10)
  • CreateEventW (Address: 0x18004fc98)
  • CreateMutexExW (Address: 0x18004fc28)
  • CreateMutexW (Address: 0x18004fcb0)
  • CreateSemaphoreExW (Address: 0x18004fc18)
  • DeleteCriticalSection (Address: 0x18004fcb8)
  • EnterCriticalSection (Address: 0x18004fca0)
  • InitializeCriticalSection (Address: 0x18004fc20)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18004fc68)
  • InitializeCriticalSectionEx (Address: 0x18004fcc0)
  • InitializeSRWLock (Address: 0x18004fc30)
  • LeaveCriticalSection (Address: 0x18004fc80)
  • OpenEventW (Address: 0x18004fca8)
  • OpenSemaphoreW (Address: 0x18004fc40)
  • ReleaseMutex (Address: 0x18004fc88)
  • ReleaseSemaphore (Address: 0x18004fc70)
  • ReleaseSRWLockExclusive (Address: 0x18004fc00)
  • ReleaseSRWLockShared (Address: 0x18004fc48)
  • ResetEvent (Address: 0x18004fc90)
  • SetEvent (Address: 0x18004fc08)
  • WaitForMultipleObjectsEx (Address: 0x18004fc60)
  • WaitForSingleObject (Address: 0x18004fc78)
  • WaitForSingleObjectEx (Address: 0x18004fc58)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x18004fce0)
  • InitOnceComplete (Address: 0x18004fcd8)
  • InitOnceExecuteOnce (Address: 0x18004fcd0)
  • Sleep (Address: 0x18004fce8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x18004fd18)
  • GetSystemTimeAsFileTime (Address: 0x18004fd10)
  • GetTickCount (Address: 0x18004fd00)
  • GetTickCount64 (Address: 0x18004fcf8)
  • GetVersionExW (Address: 0x18004fd08)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetProductInfo (Address: 0x18004fd28)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18004fd50)
  • CreateThreadpoolTimer (Address: 0x18004fd48)
  • SetThreadpoolTimer (Address: 0x18004fd40)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18004fd38)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x18004fd68)
  • DeleteTimerQueueTimer (Address: 0x18004fd60)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x18004fd78)
  • SystemTimeToFileTime (Address: 0x18004fd80)
api-ms-win-core-url-l1-1-0.dll
  • ParseURLW (Address: 0x18004fd90)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x18004fda8)
  • EncodePointer (Address: 0x18004fda0)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x18004fdb8)
  • RoTransformError (Address: 0x18004fdc0)
api-ms-win-core-winrt-error-l1-1-1.dll
  • IsErrorPropagationEnabled (Address: 0x18004fdd0)
  • RoGetMatchingRestrictedErrorInfo (Address: 0x18004fde0)
  • RoReportFailedDelegate (Address: 0x18004fdd8)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x18004fdf8)
  • RoGetActivationFactory (Address: 0x18004fdf0)
api-ms-win-core-winrt-propertysetprivate-l1-1-1.dll
  • RoCreatePropertySetSerializer (Address: 0x18004fe08)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x18004fe20)
  • WindowsCreateStringReference (Address: 0x18004fe38)
  • WindowsDeleteString (Address: 0x18004fe18)
  • WindowsDuplicateString (Address: 0x18004fe40)
  • WindowsGetStringRawBuffer (Address: 0x18004fe30)
  • WindowsSubstringWithSpecifiedLength (Address: 0x18004fe28)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x18004fe50)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x18004fed0)
  • __CxxFrameHandler3 (Address: 0x18004fed8)
  • __CxxFrameHandler4 (Address: 0x18004ff88)
  • __std_terminate (Address: 0x18004ff80)
  • _CxxThrowException (Address: 0x18004fee0)
  • _o___std_exception_copy (Address: 0x18004ff30)
  • _o___std_exception_destroy (Address: 0x18004ff28)
  • _o___std_type_info_destroy_list (Address: 0x18004ff20)
  • _o___stdio_common_vsnprintf_s (Address: 0x18004ff18)
  • _o___stdio_common_vsprintf (Address: 0x18004ff10)
  • _o___stdio_common_vswprintf (Address: 0x18004fee8)
  • _o__callnewh (Address: 0x18004ff68)
  • _o__cexit (Address: 0x18004ff60)
  • _o__configure_narrow_argv (Address: 0x18004ff58)
  • _o__crt_atexit (Address: 0x18004ff50)
  • _o__errno (Address: 0x18004ff48)
  • _o__execute_onexit_table (Address: 0x18004ff40)
  • _o__get_errno (Address: 0x18004ff38)
  • _o__initialize_narrow_environment (Address: 0x18004ff08)
  • _o__initialize_onexit_table (Address: 0x18004ff00)
  • _o__invalid_parameter_noinfo (Address: 0x18004fef8)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x18004fef0)
  • _o__purecall (Address: 0x18004fe60)
  • _o__register_onexit_function (Address: 0x18004fe68)
  • _o__seh_filter_dll (Address: 0x18004fe70)
  • _o__set_errno (Address: 0x18004fe78)
  • _o__wcsicmp (Address: 0x18004fe80)
  • _o__wcsnicmp (Address: 0x18004fe88)
  • _o_free (Address: 0x18004fe98)
  • _o_malloc (Address: 0x18004fea0)
  • _o_realloc (Address: 0x18004fea8)
  • _o_terminate (Address: 0x18004feb0)
  • _o_toupper (Address: 0x18004feb8)
  • _o_wcstok_s (Address: 0x18004fec0)
  • _o_wcstol (Address: 0x18004fec8)
  • memcmp (Address: 0x18004ff90)
  • memcpy (Address: 0x18004ff98)
  • memmove (Address: 0x18004fe90)
  • wcschr (Address: 0x18004ff78)
  • wcsrchr (Address: 0x18004ff70)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x18004ffa8)
  • _initterm_e (Address: 0x18004ffb0)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x18004ffc0)
  • wcscspn (Address: 0x18004ffc8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x18004fff0)
  • GetTraceEnableLevel (Address: 0x18004ffd8)
  • GetTraceLoggerHandle (Address: 0x18004fff8)
  • RegisterTraceGuidsW (Address: 0x18004ffe8)
  • TraceMessage (Address: 0x18004ffe0)
  • UnregisterTraceGuids (Address: 0x180050000)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x180050028)
  • EventRegister (Address: 0x180050030)
  • EventSetInformation (Address: 0x180050020)
  • EventUnregister (Address: 0x180050018)
  • EventWriteTransfer (Address: 0x180050010)
api-ms-win-ntuser-ie-message-l1-1-0.dll
  • DispatchMessageW (Address: 0x180050058)
  • MsgWaitForMultipleObjectsEx (Address: 0x180050048)
  • PeekMessageW (Address: 0x180050060)
  • PostQuitMessage (Address: 0x180050040)
  • TranslateMessage (Address: 0x180050050)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • GetMonitorInfoW (Address: 0x180050070)
  • GetSystemMetrics (Address: 0x180050078)
api-ms-win-oobe-notification-l1-1-0.dll
  • OOBEComplete (Address: 0x180050088)
api-ms-win-rtcore-ntuser-private-l1-1-0.dll
  • CreateWindowInBand (Address: 0x1800500a0)
  • GetWindowBand (Address: 0x180050098)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • CreateWindowExW (Address: 0x1800500b8)
  • DefWindowProcW (Address: 0x1800500f8)
  • DestroyWindow (Address: 0x1800500d8)
  • EnumWindows (Address: 0x1800500b0)
  • FindWindowW (Address: 0x1800500e0)
  • GetPropW (Address: 0x1800500d0)
  • GetWindowThreadProcessId (Address: 0x1800500c0)
  • IsWindowVisible (Address: 0x180050118)
  • RegisterClassExW (Address: 0x180050108)
  • SetForegroundWindow (Address: 0x1800500e8)
  • SetPropW (Address: 0x1800500c8)
  • SetWindowPos (Address: 0x1800500f0)
  • ShowWindow (Address: 0x180050110)
  • UnregisterClassW (Address: 0x180050100)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x180050170)
  • AllocateAndInitializeSid (Address: 0x180050158)
  • CopySid (Address: 0x180050178)
  • CreateWellKnownSid (Address: 0x180050148)
  • EqualSid (Address: 0x180050160)
  • GetLengthSid (Address: 0x180050168)
  • GetTokenInformation (Address: 0x180050128)
  • ImpersonateLoggedOnUser (Address: 0x180050138)
  • IsValidSid (Address: 0x180050140)
  • RevertToSelf (Address: 0x180050130)
  • SetTokenInformation (Address: 0x180050150)
api-ms-win-security-lsalookup-l1-1-2.dll
  • LsaLookupUserAccountType (Address: 0x180050188)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountNameW (Address: 0x180050198)
  • LookupAccountSidW (Address: 0x1800501a0)
  • LookupPrivilegeValueW (Address: 0x1800501a8)
api-ms-win-security-lsapolicy-l1-1-0.dll
  • LsaClose (Address: 0x1800501c8)
  • LsaFreeMemory (Address: 0x1800501d0)
  • LsaLookupNames2 (Address: 0x1800501c0)
  • LsaOpenPolicy (Address: 0x1800501e0)
  • LsaRetrievePrivateData (Address: 0x1800501d8)
  • LsaStorePrivateData (Address: 0x1800501b8)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x1800501f8)
  • ConvertStringSidToSidW (Address: 0x1800501f0)
api-ms-win-shcore-comhelpers-l1-1-0.dll
  • IUnknown_QueryService (Address: 0x180050208)
api-ms-win-shcore-obsolete-l1-1-0.dll
  • SHStrDupW (Address: 0x180050218)
api-ms-win-shcore-registry-l1-1-0.dll
  • SHDeleteKeyW (Address: 0x180050228)
  • SHDeleteValueW (Address: 0x180050230)
api-ms-win-shcore-scaling-l1-1-1.dll
  • GetDpiForMonitor (Address: 0x180050240)
api-ms-win-shcore-stream-l1-1-0.dll
  • IStream_Write (Address: 0x180050250)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolQueueTask (Address: 0x180050260)
api-ms-win-shcore-thread-l1-1-0.dll
  • SHCreateThreadWithHandle (Address: 0x180050278)
  • SHGetThreadRef (Address: 0x180050270)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x180050288)
credui.dll
  • CredUnPackAuthenticationBufferW (Address: 0x180050298)
CRYPT32.dll
  • CryptProtectData (Address: 0x18004f6e0)
DUI70.dll
  • ?Create@RichText@DirectUI@@SAJPEAVElement@2@PEAKPEAPEAV32@@Z (Address: 0x18004f6f8)
  • ?Destroy@Element@DirectUI@@QEAAJ_N@Z (Address: 0x18004f700)
  • ?SetAccessible@Element@DirectUI@@QEAAJ_N@Z (Address: 0x18004f718)
  • ?SetAccRole@Element@DirectUI@@QEAAJH@Z (Address: 0x18004f710)
  • ?SetConstrainLayout@RichText@DirectUI@@QEAAJH@Z (Address: 0x18004f708)
  • ?SetContentAlign@Element@DirectUI@@QEAAJH@Z (Address: 0x18004f6f0)
  • ?SetContentString@Element@DirectUI@@QEAAJPEBG@Z (Address: 0x18004f728)
  • ?SetID@Element@DirectUI@@QEAAJPEBG@Z (Address: 0x18004f720)
msvcp_win.dll
  • _Cnd_broadcast (Address: 0x1800502f8)
  • _Cnd_destroy_in_situ (Address: 0x180050320)
  • _Cnd_init_in_situ (Address: 0x180050388)
  • _Cnd_register_at_thread_exit (Address: 0x180050368)
  • _Cnd_timedwait (Address: 0x180050360)
  • _Cnd_unregister_at_thread_exit (Address: 0x180050370)
  • _Cnd_wait (Address: 0x180050328)
  • _Mtx_current_owns (Address: 0x180050358)
  • _Mtx_destroy_in_situ (Address: 0x180050308)
  • _Mtx_init_in_situ (Address: 0x1800502b0)
  • _Mtx_lock (Address: 0x1800502b8)
  • _Mtx_unlock (Address: 0x1800502d0)
  • _Query_perf_counter (Address: 0x1800502e8)
  • _Query_perf_frequency (Address: 0x180050338)
  • _Xtime_get_ticks (Address: 0x180050340)
  • ?__ExceptionPtrAssign@@YAXPEAXPEBX@Z (Address: 0x1800502a8)
  • ?__ExceptionPtrCopy@@YAXPEAXPEBX@Z (Address: 0x180050378)
  • ?__ExceptionPtrCopyException@@YAXPEAXPEBX1@Z (Address: 0x1800502c8)
  • ?__ExceptionPtrCreate@@YAXPEAX@Z (Address: 0x180050390)
  • ?__ExceptionPtrDestroy@@YAXPEAX@Z (Address: 0x180050380)
  • ?__ExceptionPtrToBool@@YA_NPEBX@Z (Address: 0x180050310)
  • ?_Execute_once@std@@YAHAEAUonce_flag@1@P6AHPEAX1PEAPEAX@Z1@Z (Address: 0x1800502d8)
  • ?_Rethrow_future_exception@std@@YAXVexception_ptr@1@@Z (Address: 0x180050300)
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x1800502e0)
  • ?_Throw_C_error@std@@YAXH@Z (Address: 0x1800502c0)
  • ?_Throw_Cpp_error@std@@YAXH@Z (Address: 0x1800502f0)
  • ?_Throw_future_error@std@@YAXAEBVerror_code@1@@Z (Address: 0x180050318)
  • ?_Xinvalid_argument@std@@YAXPEBD@Z (Address: 0x180050350)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x180050330)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180050348)
netutils.dll
  • NetApiBufferFree (Address: 0x1800503a0)
ntdll.dll
  • NtQueryInformationToken (Address: 0x1800503f8)
  • NtQueryWnfStateData (Address: 0x1800503d0)
  • NtSetInformationFile (Address: 0x1800503c8)
  • RtlAllocateHeap (Address: 0x180050410)
  • RtlCompareUnicodeString (Address: 0x180050400)
  • RtlFreeHeap (Address: 0x1800503b0)
  • RtlInitString (Address: 0x1800503d8)
  • RtlInitUnicodeString (Address: 0x1800503b8)
  • RtlNtStatusToDosError (Address: 0x1800503c0)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x180050408)
  • RtlPublishWnfStateData (Address: 0x1800503e8)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x1800503f0)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1800503e0)
ole32.dll
  • CoAllowSetForegroundWindow (Address: 0x180050420)
OLEAUT32.dll
  • SysAllocString (Address: 0x18004f738)
  • SysFreeString (Address: 0x18004f740)
policymanager.dll
  • PolicyManager_FreeGetPolicyData (Address: 0x180050430)
  • PolicyManager_GetPolicy (Address: 0x180050438)
samcli.dll
  • NetLocalGroupDelMembers (Address: 0x180050458)
  • NetUserDel (Address: 0x180050448)
  • NetUserGetInfo (Address: 0x180050450)
  • NetUserSetInfo (Address: 0x180050460)
SHCORE.dll
  • (Address: 0x18004f750)
SLC.dll
  • SLGetWindowsInformationDWORD (Address: 0x18004f760)
USER32.dll
  • CallNextHookEx (Address: 0x18004f7a0)
  • GetAsyncKeyState (Address: 0x18004f7a8)
  • LoadCursorW (Address: 0x18004f780)
  • MonitorFromPoint (Address: 0x18004f788)
  • MonitorFromWindow (Address: 0x18004f770)
  • SetCursor (Address: 0x18004f778)
  • SetWindowsHookExW (Address: 0x18004f790)
  • UnhookWindowsHookEx (Address: 0x18004f798)
USERENV.dll
  • DeleteProfileW (Address: 0x18004f7b8)
wkscli.dll
  • NetGetJoinInformation (Address: 0x180050470)