bisrv.dll

Description: Background Tasks Infrastructure Service

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 6fb105fe5b9704d1636ec1d499d6ba17

File Size: 827.5 KB

Uploaded At: Dec. 1, 2025, 7:23 a.m.

Views: 19

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • PsmBiExtInitialize (Ordinal: 1, Address: 0x37510)
  • PsmBiExtNotifyAppState (Ordinal: 2, Address: 0x3c860)
  • PsmBiExtNotifySessionStateChange (Ordinal: 3, Address: 0x2ce20)
  • PsmBiExtNotifySessionUserStateChange (Ordinal: 4, Address: 0x30500)
  • PsmBiExtNotifyWerReportProgress (Ordinal: 5, Address: 0x5b9a0)
  • PsmBiExtPrepareToSuspendPackage (Ordinal: 6, Address: 0x5b9b0)
  • PsmBiExtResumePackage (Ordinal: 7, Address: 0x5b9c0)

Imported DLLs & Functions

api-ms-win-appmodel-runtime-internal-l1-1-4.dll
  • GetPackageStatusForUserSid (Address: 0x180097d20)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180097d30)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x180097d68)
  • CoCreateInstance (Address: 0x180097d78)
  • CoDecrementMTAUsage (Address: 0x180097db8)
  • CoDisconnectObject (Address: 0x180097d48)
  • CoGetCallContext (Address: 0x180097db0)
  • CoGetClassObject (Address: 0x180097d90)
  • CoIncrementMTAUsage (Address: 0x180097d40)
  • CoInitializeEx (Address: 0x180097d88)
  • CoInitializeSecurity (Address: 0x180097da0)
  • CoMarshalInterface (Address: 0x180097d58)
  • CoRegisterClassObject (Address: 0x180097d70)
  • CoReleaseMarshalData (Address: 0x180097da8)
  • CoTaskMemAlloc (Address: 0x180097d80)
  • CoTaskMemFree (Address: 0x180097d50)
  • CoUninitialize (Address: 0x180097d98)
  • CoUnmarshalInterface (Address: 0x180097dc0)
  • CreateStreamOnHGlobal (Address: 0x180097d60)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180097dd0)
  • IsDebuggerPresent (Address: 0x180097de0)
  • OutputDebugStringW (Address: 0x180097dd8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180097df0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180097e00)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180097e10)
  • RaiseException (Address: 0x180097e20)
  • SetLastError (Address: 0x180097e28)
  • SetUnhandledExceptionFilter (Address: 0x180097e30)
  • UnhandledExceptionFilter (Address: 0x180097e18)
api-ms-win-core-errorhandling-l1-1-2.dll
  • RaiseFailFastException (Address: 0x180097e40)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180097e58)
  • DuplicateHandle (Address: 0x180097e50)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180097e78)
  • HeapAlloc (Address: 0x180097e70)
  • HeapFree (Address: 0x180097e68)
api-ms-win-core-heap-l2-1-0.dll
  • GlobalAlloc (Address: 0x180097ea0)
  • GlobalFree (Address: 0x180097e98)
  • LocalAlloc (Address: 0x180097e88)
  • LocalFree (Address: 0x180097ea8)
  • LocalReAlloc (Address: 0x180097e90)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x180097ec0)
  • GetModuleHandleExW (Address: 0x180097ec8)
  • GetModuleHandleW (Address: 0x180097eb8)
  • GetProcAddress (Address: 0x180097ed0)
  • LoadLibraryExW (Address: 0x180097ed8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180097ee8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180097f18)
  • GetCurrentProcessId (Address: 0x180097f08)
  • GetCurrentThread (Address: 0x180097f28)
  • GetCurrentThreadId (Address: 0x180097f10)
  • GetProcessId (Address: 0x180097f00)
  • OpenProcessToken (Address: 0x180097ef8)
  • OpenThreadToken (Address: 0x180097f30)
  • TerminateProcess (Address: 0x180097f20)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x180097f40)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180097f50)
  • QueryPerformanceFrequency (Address: 0x180097f58)
api-ms-win-core-psm-key-l1-1-0.dll
  • PsmCreateKey (Address: 0x180097f78)
  • PsmGetApplicationNameFromKey (Address: 0x180097f70)
  • PsmGetPackageFullNameFromKey (Address: 0x180097f68)
  • PsmIsDynamicKey (Address: 0x180097f88)
  • PsmIsValidKey (Address: 0x180097f80)
api-ms-win-core-quirks-l1-1-0.dll
  • QuirkIsEnabledForPackage (Address: 0x180097f98)
api-ms-win-core-quirks-l1-1-1.dll
  • QuirkIsEnabledForPackage3 (Address: 0x180097fa8)
api-ms-win-core-realtime-l1-1-0.dll
  • QueryUnbiasedInterruptTime (Address: 0x180097fb8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180097fd8)
  • RegCreateKeyExW (Address: 0x180098008)
  • RegDeleteValueA (Address: 0x180098010)
  • RegEnumKeyExW (Address: 0x180097fc8)
  • RegEnumValueA (Address: 0x180098000)
  • RegEnumValueW (Address: 0x180097fe0)
  • RegGetValueW (Address: 0x180097ff0)
  • RegOpenKeyExW (Address: 0x180097fd0)
  • RegQueryInfoKeyW (Address: 0x180097ff8)
  • RegQueryValueExW (Address: 0x180097fe8)
api-ms-win-core-registry-l2-1-0.dll
  • RegEnumKeyW (Address: 0x180098028)
  • RegOpenKeyW (Address: 0x180098020)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180098050)
  • RtlCompareMemory (Address: 0x180098040)
  • RtlLookupFunctionEntry (Address: 0x180098038)
  • RtlVirtualUnwind (Address: 0x180098048)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x180098068)
  • CompareStringW (Address: 0x180098060)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800980a0)
  • AcquireSRWLockShared (Address: 0x1800980f0)
  • CreateEventExW (Address: 0x180098080)
  • CreateMutexExW (Address: 0x1800980e8)
  • CreateSemaphoreExW (Address: 0x180098090)
  • DeleteCriticalSection (Address: 0x180098108)
  • EnterCriticalSection (Address: 0x1800980c0)
  • InitializeCriticalSection (Address: 0x1800980e0)
  • InitializeCriticalSectionEx (Address: 0x1800980a8)
  • InitializeSRWLock (Address: 0x180098110)
  • LeaveCriticalSection (Address: 0x1800980b8)
  • OpenEventW (Address: 0x1800980f8)
  • OpenSemaphoreW (Address: 0x1800980d8)
  • ReleaseMutex (Address: 0x180098100)
  • ReleaseSemaphore (Address: 0x180098088)
  • ReleaseSRWLockExclusive (Address: 0x180098098)
  • ReleaseSRWLockShared (Address: 0x1800980b0)
  • SetEvent (Address: 0x180098078)
  • TryAcquireSRWLockExclusive (Address: 0x180098118)
  • WaitForSingleObject (Address: 0x1800980d0)
  • WaitForSingleObjectEx (Address: 0x1800980c8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x180098130)
  • InitOnceComplete (Address: 0x180098128)
  • Sleep (Address: 0x180098138)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180098148)
  • GetTickCount (Address: 0x180098158)
  • GetTickCount64 (Address: 0x180098150)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpool (Address: 0x1800981b8)
  • CloseThreadpoolCleanupGroup (Address: 0x180098188)
  • CloseThreadpoolCleanupGroupMembers (Address: 0x1800981e0)
  • CloseThreadpoolTimer (Address: 0x1800981c0)
  • CloseThreadpoolWait (Address: 0x180098168)
  • CloseThreadpoolWork (Address: 0x180098198)
  • CreateThreadpool (Address: 0x1800981c8)
  • CreateThreadpoolCleanupGroup (Address: 0x1800981d8)
  • CreateThreadpoolTimer (Address: 0x180098180)
  • CreateThreadpoolWork (Address: 0x180098178)
  • IsThreadpoolTimerSet (Address: 0x1800981d0)
  • SetThreadpoolThreadMaximum (Address: 0x1800981a8)
  • SetThreadpoolThreadMinimum (Address: 0x180098190)
  • SetThreadpoolTimer (Address: 0x1800981b0)
  • SubmitThreadpoolWork (Address: 0x180098170)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800981a0)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueue (Address: 0x180098200)
  • CreateTimerQueueTimer (Address: 0x1800981f0)
  • DeleteTimerQueueEx (Address: 0x1800981f8)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x180098218)
  • SetRestrictedErrorInfo (Address: 0x180098210)
api-ms-win-core-winrt-error-l1-1-1.dll
  • RoGetMatchingRestrictedErrorInfo (Address: 0x180098228)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x180098238)
  • RoGetActivationFactory (Address: 0x180098240)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x180098260)
  • WindowsCreateStringReference (Address: 0x180098258)
  • WindowsDeleteString (Address: 0x180098270)
  • WindowsGetStringRawBuffer (Address: 0x180098250)
  • WindowsStringHasEmbeddedNull (Address: 0x180098268)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x1800982a0)
  • GetTraceEnableLevel (Address: 0x180098298)
  • GetTraceLoggerHandle (Address: 0x180098288)
  • RegisterTraceGuidsW (Address: 0x180098280)
  • TraceMessage (Address: 0x180098290)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x1800982c0)
  • EventProviderEnabled (Address: 0x1800982b8)
  • EventRegister (Address: 0x1800982d0)
  • EventSetInformation (Address: 0x1800982b0)
  • EventUnregister (Address: 0x1800982d8)
  • EventWriteTransfer (Address: 0x1800982c8)
api-ms-win-power-setting-l1-1-0.dll
  • PowerSettingRegisterNotification (Address: 0x1800982e8)
  • PowerSettingUnregisterNotification (Address: 0x1800982f0)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x180098310)
  • CopySid (Address: 0x180098348)
  • CreateWellKnownSid (Address: 0x180098360)
  • GetLengthSid (Address: 0x180098308)
  • GetSecurityDescriptorDacl (Address: 0x180098340)
  • GetTokenInformation (Address: 0x180098300)
  • ImpersonateLoggedOnUser (Address: 0x180098338)
  • InitializeAcl (Address: 0x180098368)
  • InitializeSecurityDescriptor (Address: 0x180098330)
  • IsValidSid (Address: 0x180098370)
  • IsWellKnownSid (Address: 0x180098350)
  • RevertToSelf (Address: 0x180098318)
  • SetSecurityDescriptorDacl (Address: 0x180098320)
  • SetSecurityDescriptorGroup (Address: 0x180098358)
  • SetSecurityDescriptorOwner (Address: 0x180098328)
api-ms-win-security-lsalookup-l1-1-0.dll
  • LookupAccountSidLocalW (Address: 0x180098388)
  • LsaLookupClose (Address: 0x1800983a0)
  • LsaLookupFreeMemory (Address: 0x180098380)
  • LsaLookupGetDomainInfo (Address: 0x180098390)
  • LsaLookupOpenLocalPolicy (Address: 0x180098398)
api-ms-win-security-provider-l1-1-0.dll
  • SetNamedSecurityInfoW (Address: 0x1800983b0)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x1800983d0)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800983c8)
  • ConvertStringSidToSidW (Address: 0x1800983c0)
EventAggregation.dll
  • BriCreateBrokeredEventEx (Address: 0x180097b30)
  • BriDeleteBrokeredEvent (Address: 0x180097b10)
  • BriGetBrokerAvailabilityChangeStamp (Address: 0x180097b18)
  • BriIsBrokerRegistered (Address: 0x180097b08)
  • BriRegisterToBrokerAvailability (Address: 0x180097b00)
  • BriUnregisterFromBrokerAvailability (Address: 0x180097af0)
  • EaCreateAggregation (Address: 0x180097b20)
  • EaDeleteAggregation (Address: 0x180097b28)
  • EaSignalAggregatedEvent (Address: 0x180097af8)
msvcrt.dll
  • __C_specific_handler (Address: 0x180098498)
  • __CxxFrameHandler3 (Address: 0x1800984b0)
  • __dllonexit (Address: 0x180098488)
  • _amsg_exit (Address: 0x1800983f0)
  • _callnewh (Address: 0x180098490)
  • _errno (Address: 0x1800983e8)
  • _get_errno (Address: 0x1800984a8)
  • _initterm (Address: 0x180098478)
  • _lock (Address: 0x1800984d0)
  • _onexit (Address: 0x180098408)
  • _purecall (Address: 0x180098448)
  • _set_errno (Address: 0x1800984c0)
  • _ui64tow_s (Address: 0x180098438)
  • _unlock (Address: 0x1800984e0)
  • _vsnwprintf (Address: 0x180098440)
  • _wcsdup (Address: 0x1800984c8)
  • _wcsicmp (Address: 0x1800984a0)
  • _wcsnicmp (Address: 0x180098468)
  • _XcptFilter (Address: 0x1800983f8)
  • free (Address: 0x180098400)
  • malloc (Address: 0x180098460)
  • memcmp (Address: 0x180098450)
  • memcpy (Address: 0x180098420)
  • memcpy_s (Address: 0x180098470)
  • memmove (Address: 0x180098418)
  • memmove_s (Address: 0x1800984b8)
  • memset (Address: 0x1800984f0)
  • qsort (Address: 0x1800984d8)
  • strtoul (Address: 0x180098430)
  • swscanf_s (Address: 0x180098458)
  • toupper (Address: 0x180098428)
  • wcscpy_s (Address: 0x1800983e0)
  • wcsnlen (Address: 0x180098410)
  • wcstok_s (Address: 0x180098480)
  • wcstoul (Address: 0x1800984e8)
ntdll.dll
  • NtClearEvent (Address: 0x1800985f0)
  • NtClose (Address: 0x180098898)
  • NtCreateEvent (Address: 0x1800986c0)
  • NtCreateFile (Address: 0x180098530)
  • NtCreateIRTimer (Address: 0x180098890)
  • NtCreateKey (Address: 0x180098540)
  • NtCreateWnfStateName (Address: 0x180098788)
  • NtDeleteFile (Address: 0x180098560)
  • NtDeleteKey (Address: 0x180098598)
  • NtDeleteValueKey (Address: 0x180098550)
  • NtDeleteWnfStateName (Address: 0x180098790)
  • NtDuplicateObject (Address: 0x1800986a8)
  • NtEnumerateKey (Address: 0x180098588)
  • NtLoadKeyEx (Address: 0x180098548)
  • NtOpenKey (Address: 0x180098570)
  • NtOpenProcess (Address: 0x1800986c8)
  • NtOpenProcessToken (Address: 0x180098800)
  • NtOpenThreadToken (Address: 0x1800987c8)
  • NtPowerInformation (Address: 0x180098848)
  • NtQueryAttributesFile (Address: 0x180098510)
  • NtQueryInformationProcess (Address: 0x180098670)
  • NtQueryInformationToken (Address: 0x1800987f0)
  • NtQuerySystemInformation (Address: 0x180098678)
  • NtQueryValueKey (Address: 0x1800986f8)
  • NtQueryWnfStateData (Address: 0x180098850)
  • NtReadVirtualMemory (Address: 0x180098628)
  • NtSaveKeyEx (Address: 0x180098538)
  • NtSetEvent (Address: 0x180098610)
  • NtSetIRTimer (Address: 0x1800988a0)
  • NtSetValueKey (Address: 0x180098528)
  • NtWriteVirtualMemory (Address: 0x1800985f8)
  • RtlAcquirePrivilege (Address: 0x180098558)
  • RtlAcquireSRWLockExclusive (Address: 0x180098630)
  • RtlAcquireSRWLockShared (Address: 0x180098688)
  • RtlAddAccessAllowedAceEx (Address: 0x180098758)
  • RtlAllocateHeap (Address: 0x180098798)
  • RtlAppendUnicodeStringToString (Address: 0x180098590)
  • RtlAppendUnicodeToString (Address: 0x180098580)
  • RtlClearBit (Address: 0x180098838)
  • RtlCompareUnicodeString (Address: 0x1800985a8)
  • RtlCompareUnicodeStrings (Address: 0x1800986d8)
  • RtlConvertSidToUnicodeString (Address: 0x180098888)
  • RtlCopySid (Address: 0x1800987d8)
  • RtlCopyUnicodeString (Address: 0x180098638)
  • RtlCreateAcl (Address: 0x180098718)
  • RtlCreateHashTable (Address: 0x1800986a0)
  • RtlCreateSecurityDescriptor (Address: 0x180098710)
  • RtlDeleteHashTable (Address: 0x180098700)
  • RtlDuplicateUnicodeString (Address: 0x180098708)
  • RtlEndEnumerationHashTable (Address: 0x180098780)
  • RtlEnumerateEntryHashTable (Address: 0x1800987a8)
  • RtlEqualSid (Address: 0x1800987b8)
  • RtlFreeHeap (Address: 0x180098720)
  • RtlFreeSid (Address: 0x180098730)
  • RtlFreeUnicodeString (Address: 0x1800986e0)
  • RtlGetDeviceFamilyInfoEnum (Address: 0x180098768)
  • RtlGetNextEntryHashTable (Address: 0x180098690)
  • RtlGUIDFromString (Address: 0x1800987a0)
  • RtlInitEnumerationHashTable (Address: 0x180098738)
  • RtlInitializeBitMap (Address: 0x180098818)
  • RtlInitializeSRWLock (Address: 0x180098648)
  • RtlInitUnicodeString (Address: 0x180098760)
  • RtlInsertEntryHashTable (Address: 0x1800986b8)
  • RtlIsMultiSessionSku (Address: 0x180098728)
  • RtlLengthSid (Address: 0x1800986d0)
  • RtlLookupEntryHashTable (Address: 0x180098698)
  • RtlNtStatusToDosError (Address: 0x180098518)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x180098658)
  • RtlPublishWnfStateData (Address: 0x180098668)
  • RtlQueryPackageClaims (Address: 0x1800987e8)
  • RtlQueryPackageIdentityEx (Address: 0x1800987c0)
  • RtlQueryUnbiasedInterruptTime (Address: 0x1800986f0)
  • RtlQueryWnfMetaNotification (Address: 0x180098748)
  • RtlQueryWnfStateData (Address: 0x180098520)
  • RtlRbInsertNodeEx (Address: 0x1800985c0)
  • RtlRbRemoveNode (Address: 0x180098500)
  • RtlReAllocateHeap (Address: 0x180098750)
  • RtlRegisterForWnfMetaNotification (Address: 0x180098618)
  • RtlReleasePrivilege (Address: 0x180098578)
  • RtlReleaseSRWLockExclusive (Address: 0x180098640)
  • RtlReleaseSRWLockShared (Address: 0x180098680)
  • RtlRemoveEntryHashTable (Address: 0x180098740)
  • RtlRunOnceBeginInitialize (Address: 0x1800985d0)
  • RtlRunOnceComplete (Address: 0x1800985a0)
  • RtlRunOnceExecuteOnce (Address: 0x180098840)
  • RtlSetBit (Address: 0x180098858)
  • RtlSetDaclSecurityDescriptor (Address: 0x180098778)
  • RtlSetOwnerSecurityDescriptor (Address: 0x1800987b0)
  • RtlStringFromGUID (Address: 0x1800986e8)
  • RtlStringFromGUIDEx (Address: 0x180098600)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x180098878)
  • RtlTestBit (Address: 0x180098810)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1800985e8)
  • RtlUnsubscribeWnfStateChangeNotification (Address: 0x180098650)
  • RtlUpcaseUnicodeChar (Address: 0x180098770)
  • RtlValidSid (Address: 0x180098808)
  • RtlWaitForWnfMetaNotification (Address: 0x180098660)
  • RtlWaitOnAddress (Address: 0x1800987e0)
  • RtlWakeAddressAll (Address: 0x1800986b0)
  • TpAllocPool (Address: 0x1800985e0)
  • TpAllocTimer (Address: 0x180098870)
  • TpAllocWait (Address: 0x1800985b8)
  • TpAllocWork (Address: 0x180098860)
  • TpPostWork (Address: 0x180098830)
  • TpReleasePool (Address: 0x1800985d8)
  • TpReleaseTimer (Address: 0x1800987f8)
  • TpReleaseWait (Address: 0x180098568)
  • TpReleaseWork (Address: 0x180098820)
  • TpSetPoolMaxThreads (Address: 0x180098608)
  • TpSetTimer (Address: 0x180098880)
  • TpSetTimerEx (Address: 0x1800987d0)
  • TpSetWait (Address: 0x1800985c8)
  • TpSetWaitEx (Address: 0x180098620)
  • TpWaitForTimer (Address: 0x180098868)
  • TpWaitForWait (Address: 0x1800985b0)
  • TpWaitForWork (Address: 0x180098828)
  • ZwUpdateWnfStateData (Address: 0x180098508)
OLEAUT32.dll
  • SysAllocString (Address: 0x180097b50)
  • SysAllocStringLen (Address: 0x180097b40)
  • SysFreeString (Address: 0x180097b58)
  • SysStringLen (Address: 0x180097b48)
ResourcePolicyClient.dll
  • CreateResourcePolicyEngineClient (Address: 0x180097cd8)
  • CreateResourcePolicyStoreClient (Address: 0x180097cc8)
  • InterruptiveUIStateChanged_Subscribe (Address: 0x180097cc0)
  • InterruptiveUIStateChanged_Unsubscribe (Address: 0x180097cd0)
  • QueryApplicationInterruptiveUIStateByPsmKey (Address: 0x180097cb8)
RMCLIENT.dll
  • CrmActivityAllocate (Address: 0x180097b70)
  • CrmActivityFree (Address: 0x180097b68)
  • CrmActivityRequest (Address: 0x180097b78)
  • CrmActivityStart (Address: 0x180097b88)
  • CrmActivityStop (Address: 0x180097b80)
  • CrmRegister (Address: 0x180097be0)
  • HamCloseActivity (Address: 0x180097bd0)
  • HamConnectToServer (Address: 0x180097ba8)
  • HamCreateActivityEx (Address: 0x180097bc0)
  • HamDisconnectFromServer (Address: 0x180097ba0)
  • HamIsHostBeingDebugged (Address: 0x180097bb0)
  • HamPopulateActivityProperties (Address: 0x180097bb8)
  • HamResetExternalResourcePriority (Address: 0x180097b90)
  • HamSetExternalResourcePriority (Address: 0x180097b98)
  • HamStartActivityAsync (Address: 0x180097bc8)
  • HamTerminateActivityHost (Address: 0x180097bd8)
RPCRT4.dll
  • I_RpcBindingInqLocalClientPID (Address: 0x180097bf0)
  • I_RpcExceptionFilter (Address: 0x180097c48)
  • I_RpcMapWin32Status (Address: 0x180097c28)
  • Ndr64AsyncServerCallAll (Address: 0x180097c40)
  • NdrAsyncServerCall (Address: 0x180097c38)
  • NdrClientCall3 (Address: 0x180097c20)
  • NdrServerCall2 (Address: 0x180097c50)
  • NdrServerCallAll (Address: 0x180097c30)
  • RpcAsyncCompleteCall (Address: 0x180097c08)
  • RpcBindingBind (Address: 0x180097c10)
  • RpcBindingCreateW (Address: 0x180097c58)
  • RpcBindingFree (Address: 0x180097c00)
  • RpcBindingVectorFree (Address: 0x180097c70)
  • RpcEpRegisterW (Address: 0x180097c78)
  • RpcEpUnregister (Address: 0x180097c68)
  • RpcImpersonateClient (Address: 0x180097c60)
  • RpcRaiseException (Address: 0x180097bf8)
  • RpcRevertToSelf (Address: 0x180097ca8)
  • RpcServerInqBindings (Address: 0x180097c88)
  • RpcServerInqCallAttributesW (Address: 0x180097ca0)
  • RpcServerRegisterIf3 (Address: 0x180097c90)
  • RpcServerUnregisterIf (Address: 0x180097c80)
  • RpcServerUseProtseqW (Address: 0x180097c98)
  • UuidCreate (Address: 0x180097c18)
UMPDC.dll
  • Pdcv2ActivationClientActivate (Address: 0x180097d00)
  • Pdcv2ActivationClientDeactivate (Address: 0x180097d08)
  • Pdcv2ActivationClientRegister (Address: 0x180097d10)
  • Pdcv2ActivationClientRenewActivation (Address: 0x180097ce8)
  • Pdcv2ActivationClientSetBrokeredProcessId (Address: 0x180097cf0)
  • Pdcv2ActivationClientUnregister (Address: 0x180097cf8)