KrnlProv.dll

Description: WMI

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 624ea5c19fffc1634e387b1ea7ec1337

File Size: 73.0 KB

Uploaded At: Dec. 1, 2025, 7:51 a.m.

Views: 6

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x6050)
  • DllGetClassObject (Ordinal: 2, Address: 0x6070)
  • DllRegisterServer (Ordinal: 3, Address: 0x61a0)
  • DllUnregisterServer (Ordinal: 4, Address: 0x62a0)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x18000bff0)
  • CoImpersonateClient (Address: 0x18000c008)
  • CoRevertToSelf (Address: 0x18000bff8)
  • CoTaskMemAlloc (Address: 0x18000bfe8)
  • CoTaskMemFree (Address: 0x18000c010)
  • CoTaskMemRealloc (Address: 0x18000c000)
  • StringFromGUID2 (Address: 0x18000c018)
api-ms-win-core-debug-l1-1-0.dll
  • OutputDebugStringA (Address: 0x18000c028)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18000c048)
  • RaiseException (Address: 0x18000c038)
  • SetLastError (Address: 0x18000c040)
  • SetUnhandledExceptionFilter (Address: 0x18000c058)
  • UnhandledExceptionFilter (Address: 0x18000c050)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18000c068)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18000c078)
  • HeapAlloc (Address: 0x18000c080)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x18000c090)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18000c0a0)
  • FindResourceExW (Address: 0x18000c0d0)
  • FreeLibrary (Address: 0x18000c0b0)
  • GetModuleFileNameW (Address: 0x18000c0c0)
  • GetModuleHandleW (Address: 0x18000c0e8)
  • GetProcAddress (Address: 0x18000c0b8)
  • LoadLibraryExA (Address: 0x18000c0e0)
  • LoadLibraryExW (Address: 0x18000c0d8)
  • LoadResource (Address: 0x18000c0c8)
  • SizeofResource (Address: 0x18000c0a8)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualProtect (Address: 0x18000c100)
  • VirtualQuery (Address: 0x18000c0f8)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x18000c130)
  • GetCurrentProcess (Address: 0x18000c120)
  • GetCurrentProcessId (Address: 0x18000c110)
  • GetCurrentThread (Address: 0x18000c138)
  • GetCurrentThreadId (Address: 0x18000c118)
  • TerminateProcess (Address: 0x18000c128)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18000c148)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18000c158)
  • RegCreateKeyExW (Address: 0x18000c188)
  • RegDeleteValueW (Address: 0x18000c170)
  • RegEnumKeyExW (Address: 0x18000c168)
  • RegOpenKeyExW (Address: 0x18000c180)
  • RegQueryInfoKeyW (Address: 0x18000c178)
  • RegSetValueExW (Address: 0x18000c160)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18000c1b0)
  • RtlCompareMemory (Address: 0x18000c198)
  • RtlLookupFunctionEntry (Address: 0x18000c1a8)
  • RtlVirtualUnwind (Address: 0x18000c1a0)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x18000c1c0)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x18000c1d0)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x18000c1e8)
  • lstrlenA (Address: 0x18000c1e0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18000c210)
  • DeleteCriticalSection (Address: 0x18000c220)
  • EnterCriticalSection (Address: 0x18000c208)
  • InitializeCriticalSection (Address: 0x18000c200)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18000c1f8)
  • LeaveCriticalSection (Address: 0x18000c230)
  • ReleaseSRWLockExclusive (Address: 0x18000c228)
  • WaitForSingleObject (Address: 0x18000c218)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18000c240)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x18000c258)
  • GetSystemTimeAsFileTime (Address: 0x18000c250)
  • GetTickCount (Address: 0x18000c260)
api-ms-win-eventing-consumer-l1-1-0.dll
  • CloseTrace (Address: 0x18000c280)
  • OpenTraceW (Address: 0x18000c278)
  • ProcessTrace (Address: 0x18000c270)
api-ms-win-eventing-controller-l1-1-0.dll
  • StartTraceW (Address: 0x18000c298)
  • StopTraceW (Address: 0x18000c290)
api-ms-win-eventing-legacy-l1-1-0.dll
  • EnableTraceEx (Address: 0x18000c2b0)
  • QueryTraceW (Address: 0x18000c2a8)
api-ms-win-eventing-tdh-l1-1-0.dll
  • TdhGetProperty (Address: 0x18000c2c0)
esscli.dll
  • IsUserAdministrator (Address: 0x18000c2d0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000c3b0)
  • __CxxFrameHandler3 (Address: 0x18000c3b8)
  • __dllonexit (Address: 0x18000c348)
  • _amsg_exit (Address: 0x18000c320)
  • _callnewh (Address: 0x18000c3c8)
  • _CxxThrowException (Address: 0x18000c328)
  • _errno (Address: 0x18000c358)
  • _initterm (Address: 0x18000c3c0)
  • _lock (Address: 0x18000c398)
  • _onexit (Address: 0x18000c350)
  • _purecall (Address: 0x18000c300)
  • _unlock (Address: 0x18000c340)
  • _XcptFilter (Address: 0x18000c2f8)
  • ??_V@YAXPEAX@Z (Address: 0x18000c3a8)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18000c390)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18000c3d0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18000c388)
  • ??1exception@@UEAA@XZ (Address: 0x18000c380)
  • ??1type_info@@UEAA@XZ (Address: 0x18000c368)
  • ??3@YAXPEAX@Z (Address: 0x18000c310)
  • ?terminate@@YAXXZ (Address: 0x18000c330)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18000c378)
  • free (Address: 0x18000c2f0)
  • malloc (Address: 0x18000c2e8)
  • memcpy (Address: 0x18000c318)
  • memcpy_s (Address: 0x18000c3a0)
  • memmove (Address: 0x18000c338)
  • memset (Address: 0x18000c3d8)
  • realloc (Address: 0x18000c360)
  • wcscat_s (Address: 0x18000c308)
  • wcscpy_s (Address: 0x18000c370)
  • wcsncpy_s (Address: 0x18000c2e0)
ntdll.dll
  • RtlFreeSid (Address: 0x18000c3e8)
OLEAUT32.dll
  • LoadTypeLib (Address: 0x18000bfb0)
  • RegisterTypeLib (Address: 0x18000bfd8)
  • SysAllocString (Address: 0x18000bfa0)
  • SysFreeString (Address: 0x18000bfc0)
  • SysStringLen (Address: 0x18000bfa8)
  • UnRegisterTypeLib (Address: 0x18000bfb8)
  • VariantClear (Address: 0x18000bfc8)
  • VarUI4FromStr (Address: 0x18000bfd0)
wbemcomn.dll
  • _ThrowMemoryException_ (Address: 0x18000c3f8)
  • BreakOnDbgAndRenterLoop (Address: 0x18000c400)