EmbeddedLockdownWmi.dll

Description: Embedded Lockdown Settings

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 64-bit

Operating System: Windows NT

SHA256: 660dfa28c22ac29063627450a1eede07

File Size: 114.9 KB

Uploaded At: Dec. 1, 2025, 7:51 a.m.

Views: 5

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x1fa0)
  • DllGetClassObject (Ordinal: 2, Address: 0x1fe0)
  • DllMain (Ordinal: 3, Address: 0x1c90)
  • DllRegisterServer (Ordinal: 4, Address: 0x1f00)
  • DllUnregisterServer (Ordinal: 5, Address: 0x1f50)
  • GetProviderClassID (Ordinal: 6, Address: 0x1cf0)
  • MI_Main (Ordinal: 7, Address: 0x1c30)

Imported DLLs & Functions

ADVAPI32.dll
  • CheckTokenMembership (Address: 0x180013df8)
  • ConvertStringSidToSidW (Address: 0x180013de0)
  • CreateWellKnownSid (Address: 0x180013dd8)
  • EventActivityIdControl (Address: 0x180013e18)
  • EventRegister (Address: 0x180013dd0)
  • EventSetInformation (Address: 0x180013de8)
  • EventUnregister (Address: 0x180013e08)
  • EventWrite (Address: 0x180013db8)
  • EventWriteTransfer (Address: 0x180013dc8)
  • ImpersonateLoggedOnUser (Address: 0x180013df0)
  • LookupAccountSidW (Address: 0x180013e10)
  • RegCloseKey (Address: 0x180013dc0)
  • RegOpenKeyExW (Address: 0x180013e00)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateGuid (Address: 0x180014020)
  • CoGetApartmentType (Address: 0x180014018)
  • CoImpersonateClient (Address: 0x180014028)
  • CoRevertToSelf (Address: 0x180014040)
  • CoTaskMemAlloc (Address: 0x180014030)
  • CoTaskMemFree (Address: 0x180014038)
  • CoTaskMemRealloc (Address: 0x180014010)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x180014050)
  • RoTransformError (Address: 0x180014058)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180014068)
  • RoGetActivationFactory (Address: 0x180014070)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x180014098)
  • WindowsCreateStringReference (Address: 0x180014090)
  • WindowsDeleteString (Address: 0x180014088)
  • WindowsGetStringRawBuffer (Address: 0x180014080)
DismApi.DLL
  • _DismGetProvisionedAppxPackages (Address: 0x180013e40)
  • DismCloseSession (Address: 0x180013e48)
  • DismDelete (Address: 0x180013e38)
  • DismInitialize (Address: 0x180013e30)
  • DismOpenSession (Address: 0x180013e28)
ext-ms-win-session-wtsapi32-l1-1-0.dll
  • WTSEnumerateSessionsW (Address: 0x1800140a8)
  • WTSFreeMemory (Address: 0x1800140b0)
  • WTSLogoffSession (Address: 0x1800140b8)
  • WTSQuerySessionInformationW (Address: 0x1800140c8)
  • WTSQueryUserToken (Address: 0x1800140c0)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x180013f70)
  • AcquireSRWLockShared (Address: 0x180013eb0)
  • CloseHandle (Address: 0x180013f88)
  • CompareStringEx (Address: 0x180013f90)
  • CompareStringOrdinal (Address: 0x180013f30)
  • CreateMutexExW (Address: 0x180013fa0)
  • CreateSemaphoreExW (Address: 0x180013f08)
  • DebugBreak (Address: 0x180013fd8)
  • DisableThreadLibraryCalls (Address: 0x180013ed8)
  • FormatMessageW (Address: 0x180013f50)
  • FreeLibrary (Address: 0x180013ee8)
  • GetComputerNameW (Address: 0x180013fb8)
  • GetCurrentProcess (Address: 0x180013e98)
  • GetCurrentProcessId (Address: 0x180013fc0)
  • GetCurrentThreadId (Address: 0x180013f40)
  • GetLastError (Address: 0x180013ed0)
  • GetModuleFileNameA (Address: 0x180013ef8)
  • GetModuleHandleExW (Address: 0x180013f28)
  • GetModuleHandleW (Address: 0x180013fd0)
  • GetProcAddress (Address: 0x180013ee0)
  • GetProcessHeap (Address: 0x180013fc8)
  • GetSystemDirectoryW (Address: 0x180013ec8)
  • GetSystemTimeAsFileTime (Address: 0x180013e70)
  • GetTickCount (Address: 0x180013e78)
  • HeapAlloc (Address: 0x180013f98)
  • HeapDestroy (Address: 0x180014000)
  • HeapFree (Address: 0x180013f10)
  • HeapReAlloc (Address: 0x180013ff8)
  • HeapSize (Address: 0x180013ff0)
  • InitializeSRWLock (Address: 0x180013ea8)
  • InitOnceBeginInitialize (Address: 0x180013f00)
  • InitOnceComplete (Address: 0x180013f68)
  • IsDebuggerPresent (Address: 0x180013fe0)
  • LoadLibraryExW (Address: 0x180013ef0)
  • LocalFree (Address: 0x180013fa8)
  • OpenSemaphoreW (Address: 0x180013f80)
  • OutputDebugStringW (Address: 0x180013f60)
  • QueryPerformanceCounter (Address: 0x180013e68)
  • RaiseException (Address: 0x180013fe8)
  • ReleaseMutex (Address: 0x180013f48)
  • ReleaseSemaphore (Address: 0x180013f20)
  • ReleaseSRWLockExclusive (Address: 0x180013f58)
  • ReleaseSRWLockShared (Address: 0x180013eb8)
  • RtlCaptureContext (Address: 0x180013e58)
  • RtlLookupFunctionEntry (Address: 0x180013ec0)
  • RtlVirtualUnwind (Address: 0x180013e80)
  • SetLastError (Address: 0x180013f18)
  • SetUnhandledExceptionFilter (Address: 0x180013e90)
  • Sleep (Address: 0x180013e60)
  • TerminateProcess (Address: 0x180013ea0)
  • UnhandledExceptionFilter (Address: 0x180013e88)
  • WaitForSingleObject (Address: 0x180013f38)
  • WaitForSingleObjectEx (Address: 0x180013f78)
  • WTSGetActiveConsoleSessionId (Address: 0x180013fb0)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800140d8)
  • __CxxFrameHandler3 (Address: 0x1800141b8)
  • __dllonexit (Address: 0x180014170)
  • _amsg_exit (Address: 0x180014140)
  • _callnewh (Address: 0x180014128)
  • _CxxThrowException (Address: 0x180014130)
  • _initterm (Address: 0x180014148)
  • _lock (Address: 0x180014160)
  • _onexit (Address: 0x180014178)
  • _purecall (Address: 0x180014108)
  • _unlock (Address: 0x180014168)
  • _vscwprintf (Address: 0x1800140e8)
  • _vsnprintf_s (Address: 0x180014120)
  • _vsnwprintf (Address: 0x1800141b0)
  • _wcsicmp (Address: 0x1800141a0)
  • _XcptFilter (Address: 0x180014138)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180014110)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800140e0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800140f0)
  • ??0exception@@QEAA@XZ (Address: 0x1800140f8)
  • ??1exception@@UEAA@XZ (Address: 0x180014100)
  • ??1type_info@@UEAA@XZ (Address: 0x180014180)
  • ??3@YAXPEAX@Z (Address: 0x1800141c0)
  • ?terminate@@YAXXZ (Address: 0x180014150)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180014158)
  • free (Address: 0x1800141d0)
  • malloc (Address: 0x1800141c8)
  • memcpy (Address: 0x180014118)
  • memcpy_s (Address: 0x1800141a8)
  • memmove (Address: 0x1800141e0)
  • memmove_s (Address: 0x180014190)
  • memset (Address: 0x1800141e8)
  • realloc (Address: 0x1800141d8)
  • swprintf_s (Address: 0x180014188)
  • vswprintf_s (Address: 0x180014198)
ntdll.dll
  • NtDuplicateToken (Address: 0x180014200)
  • NtQueryInformationToken (Address: 0x1800141f8)