bisrv.dll
Description: Background Tasks Infrastructure Service
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 6fb105fe5b9704d1636ec1d499d6ba17
File Size: 827.5 KB
Uploaded At: Dec. 1, 2025, 7:23 a.m.
Views: 19
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- PsmBiExtInitialize (Ordinal: 1, Address: 0x37510)
- PsmBiExtNotifyAppState (Ordinal: 2, Address: 0x3c860)
- PsmBiExtNotifySessionStateChange (Ordinal: 3, Address: 0x2ce20)
- PsmBiExtNotifySessionUserStateChange (Ordinal: 4, Address: 0x30500)
- PsmBiExtNotifyWerReportProgress (Ordinal: 5, Address: 0x5b9a0)
- PsmBiExtPrepareToSuspendPackage (Ordinal: 6, Address: 0x5b9b0)
- PsmBiExtResumePackage (Ordinal: 7, Address: 0x5b9c0)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-internal-l1-1-4.dll
- GetPackageStatusForUserSid (Address: 0x180097d20)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180097d30)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x180097d68)
- CoCreateInstance (Address: 0x180097d78)
- CoDecrementMTAUsage (Address: 0x180097db8)
- CoDisconnectObject (Address: 0x180097d48)
- CoGetCallContext (Address: 0x180097db0)
- CoGetClassObject (Address: 0x180097d90)
- CoIncrementMTAUsage (Address: 0x180097d40)
- CoInitializeEx (Address: 0x180097d88)
- CoInitializeSecurity (Address: 0x180097da0)
- CoMarshalInterface (Address: 0x180097d58)
- CoRegisterClassObject (Address: 0x180097d70)
- CoReleaseMarshalData (Address: 0x180097da8)
- CoTaskMemAlloc (Address: 0x180097d80)
- CoTaskMemFree (Address: 0x180097d50)
- CoUninitialize (Address: 0x180097d98)
- CoUnmarshalInterface (Address: 0x180097dc0)
- CreateStreamOnHGlobal (Address: 0x180097d60)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180097dd0)
- IsDebuggerPresent (Address: 0x180097de0)
- OutputDebugStringW (Address: 0x180097dd8)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180097df0)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180097e00)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180097e10)
- RaiseException (Address: 0x180097e20)
- SetLastError (Address: 0x180097e28)
- SetUnhandledExceptionFilter (Address: 0x180097e30)
- UnhandledExceptionFilter (Address: 0x180097e18)
api-ms-win-core-errorhandling-l1-1-2.dll
- RaiseFailFastException (Address: 0x180097e40)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180097e58)
- DuplicateHandle (Address: 0x180097e50)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180097e78)
- HeapAlloc (Address: 0x180097e70)
- HeapFree (Address: 0x180097e68)
api-ms-win-core-heap-l2-1-0.dll
- GlobalAlloc (Address: 0x180097ea0)
- GlobalFree (Address: 0x180097e98)
- LocalAlloc (Address: 0x180097e88)
- LocalFree (Address: 0x180097ea8)
- LocalReAlloc (Address: 0x180097e90)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleFileNameA (Address: 0x180097ec0)
- GetModuleHandleExW (Address: 0x180097ec8)
- GetModuleHandleW (Address: 0x180097eb8)
- GetProcAddress (Address: 0x180097ed0)
- LoadLibraryExW (Address: 0x180097ed8)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x180097ee8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x180097f18)
- GetCurrentProcessId (Address: 0x180097f08)
- GetCurrentThread (Address: 0x180097f28)
- GetCurrentThreadId (Address: 0x180097f10)
- GetProcessId (Address: 0x180097f00)
- OpenProcessToken (Address: 0x180097ef8)
- OpenThreadToken (Address: 0x180097f30)
- TerminateProcess (Address: 0x180097f20)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x180097f40)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180097f50)
- QueryPerformanceFrequency (Address: 0x180097f58)
api-ms-win-core-psm-key-l1-1-0.dll
- PsmCreateKey (Address: 0x180097f78)
- PsmGetApplicationNameFromKey (Address: 0x180097f70)
- PsmGetPackageFullNameFromKey (Address: 0x180097f68)
- PsmIsDynamicKey (Address: 0x180097f88)
- PsmIsValidKey (Address: 0x180097f80)
api-ms-win-core-quirks-l1-1-0.dll
- QuirkIsEnabledForPackage (Address: 0x180097f98)
api-ms-win-core-quirks-l1-1-1.dll
- QuirkIsEnabledForPackage3 (Address: 0x180097fa8)
api-ms-win-core-realtime-l1-1-0.dll
- QueryUnbiasedInterruptTime (Address: 0x180097fb8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180097fd8)
- RegCreateKeyExW (Address: 0x180098008)
- RegDeleteValueA (Address: 0x180098010)
- RegEnumKeyExW (Address: 0x180097fc8)
- RegEnumValueA (Address: 0x180098000)
- RegEnumValueW (Address: 0x180097fe0)
- RegGetValueW (Address: 0x180097ff0)
- RegOpenKeyExW (Address: 0x180097fd0)
- RegQueryInfoKeyW (Address: 0x180097ff8)
- RegQueryValueExW (Address: 0x180097fe8)
api-ms-win-core-registry-l2-1-0.dll
- RegEnumKeyW (Address: 0x180098028)
- RegOpenKeyW (Address: 0x180098020)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x180098050)
- RtlCompareMemory (Address: 0x180098040)
- RtlLookupFunctionEntry (Address: 0x180098038)
- RtlVirtualUnwind (Address: 0x180098048)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x180098068)
- CompareStringW (Address: 0x180098060)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800980a0)
- AcquireSRWLockShared (Address: 0x1800980f0)
- CreateEventExW (Address: 0x180098080)
- CreateMutexExW (Address: 0x1800980e8)
- CreateSemaphoreExW (Address: 0x180098090)
- DeleteCriticalSection (Address: 0x180098108)
- EnterCriticalSection (Address: 0x1800980c0)
- InitializeCriticalSection (Address: 0x1800980e0)
- InitializeCriticalSectionEx (Address: 0x1800980a8)
- InitializeSRWLock (Address: 0x180098110)
- LeaveCriticalSection (Address: 0x1800980b8)
- OpenEventW (Address: 0x1800980f8)
- OpenSemaphoreW (Address: 0x1800980d8)
- ReleaseMutex (Address: 0x180098100)
- ReleaseSemaphore (Address: 0x180098088)
- ReleaseSRWLockExclusive (Address: 0x180098098)
- ReleaseSRWLockShared (Address: 0x1800980b0)
- SetEvent (Address: 0x180098078)
- TryAcquireSRWLockExclusive (Address: 0x180098118)
- WaitForSingleObject (Address: 0x1800980d0)
- WaitForSingleObjectEx (Address: 0x1800980c8)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x180098130)
- InitOnceComplete (Address: 0x180098128)
- Sleep (Address: 0x180098138)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x180098148)
- GetTickCount (Address: 0x180098158)
- GetTickCount64 (Address: 0x180098150)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpool (Address: 0x1800981b8)
- CloseThreadpoolCleanupGroup (Address: 0x180098188)
- CloseThreadpoolCleanupGroupMembers (Address: 0x1800981e0)
- CloseThreadpoolTimer (Address: 0x1800981c0)
- CloseThreadpoolWait (Address: 0x180098168)
- CloseThreadpoolWork (Address: 0x180098198)
- CreateThreadpool (Address: 0x1800981c8)
- CreateThreadpoolCleanupGroup (Address: 0x1800981d8)
- CreateThreadpoolTimer (Address: 0x180098180)
- CreateThreadpoolWork (Address: 0x180098178)
- IsThreadpoolTimerSet (Address: 0x1800981d0)
- SetThreadpoolThreadMaximum (Address: 0x1800981a8)
- SetThreadpoolThreadMinimum (Address: 0x180098190)
- SetThreadpoolTimer (Address: 0x1800981b0)
- SubmitThreadpoolWork (Address: 0x180098170)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800981a0)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueue (Address: 0x180098200)
- CreateTimerQueueTimer (Address: 0x1800981f0)
- DeleteTimerQueueEx (Address: 0x1800981f8)
api-ms-win-core-winrt-error-l1-1-0.dll
- RoOriginateError (Address: 0x180098218)
- SetRestrictedErrorInfo (Address: 0x180098210)
api-ms-win-core-winrt-error-l1-1-1.dll
- RoGetMatchingRestrictedErrorInfo (Address: 0x180098228)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x180098238)
- RoGetActivationFactory (Address: 0x180098240)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateString (Address: 0x180098260)
- WindowsCreateStringReference (Address: 0x180098258)
- WindowsDeleteString (Address: 0x180098270)
- WindowsGetStringRawBuffer (Address: 0x180098250)
- WindowsStringHasEmbeddedNull (Address: 0x180098268)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x1800982a0)
- GetTraceEnableLevel (Address: 0x180098298)
- GetTraceLoggerHandle (Address: 0x180098288)
- RegisterTraceGuidsW (Address: 0x180098280)
- TraceMessage (Address: 0x180098290)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1800982c0)
- EventProviderEnabled (Address: 0x1800982b8)
- EventRegister (Address: 0x1800982d0)
- EventSetInformation (Address: 0x1800982b0)
- EventUnregister (Address: 0x1800982d8)
- EventWriteTransfer (Address: 0x1800982c8)
api-ms-win-power-setting-l1-1-0.dll
- PowerSettingRegisterNotification (Address: 0x1800982e8)
- PowerSettingUnregisterNotification (Address: 0x1800982f0)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x180098310)
- CopySid (Address: 0x180098348)
- CreateWellKnownSid (Address: 0x180098360)
- GetLengthSid (Address: 0x180098308)
- GetSecurityDescriptorDacl (Address: 0x180098340)
- GetTokenInformation (Address: 0x180098300)
- ImpersonateLoggedOnUser (Address: 0x180098338)
- InitializeAcl (Address: 0x180098368)
- InitializeSecurityDescriptor (Address: 0x180098330)
- IsValidSid (Address: 0x180098370)
- IsWellKnownSid (Address: 0x180098350)
- RevertToSelf (Address: 0x180098318)
- SetSecurityDescriptorDacl (Address: 0x180098320)
- SetSecurityDescriptorGroup (Address: 0x180098358)
- SetSecurityDescriptorOwner (Address: 0x180098328)
api-ms-win-security-lsalookup-l1-1-0.dll
- LookupAccountSidLocalW (Address: 0x180098388)
- LsaLookupClose (Address: 0x1800983a0)
- LsaLookupFreeMemory (Address: 0x180098380)
- LsaLookupGetDomainInfo (Address: 0x180098390)
- LsaLookupOpenLocalPolicy (Address: 0x180098398)
api-ms-win-security-provider-l1-1-0.dll
- SetNamedSecurityInfoW (Address: 0x1800983b0)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1800983d0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800983c8)
- ConvertStringSidToSidW (Address: 0x1800983c0)
EventAggregation.dll
- BriCreateBrokeredEventEx (Address: 0x180097b30)
- BriDeleteBrokeredEvent (Address: 0x180097b10)
- BriGetBrokerAvailabilityChangeStamp (Address: 0x180097b18)
- BriIsBrokerRegistered (Address: 0x180097b08)
- BriRegisterToBrokerAvailability (Address: 0x180097b00)
- BriUnregisterFromBrokerAvailability (Address: 0x180097af0)
- EaCreateAggregation (Address: 0x180097b20)
- EaDeleteAggregation (Address: 0x180097b28)
- EaSignalAggregatedEvent (Address: 0x180097af8)
msvcrt.dll
- __C_specific_handler (Address: 0x180098498)
- __CxxFrameHandler3 (Address: 0x1800984b0)
- __dllonexit (Address: 0x180098488)
- _amsg_exit (Address: 0x1800983f0)
- _callnewh (Address: 0x180098490)
- _errno (Address: 0x1800983e8)
- _get_errno (Address: 0x1800984a8)
- _initterm (Address: 0x180098478)
- _lock (Address: 0x1800984d0)
- _onexit (Address: 0x180098408)
- _purecall (Address: 0x180098448)
- _set_errno (Address: 0x1800984c0)
- _ui64tow_s (Address: 0x180098438)
- _unlock (Address: 0x1800984e0)
- _vsnwprintf (Address: 0x180098440)
- _wcsdup (Address: 0x1800984c8)
- _wcsicmp (Address: 0x1800984a0)
- _wcsnicmp (Address: 0x180098468)
- _XcptFilter (Address: 0x1800983f8)
- free (Address: 0x180098400)
- malloc (Address: 0x180098460)
- memcmp (Address: 0x180098450)
- memcpy (Address: 0x180098420)
- memcpy_s (Address: 0x180098470)
- memmove (Address: 0x180098418)
- memmove_s (Address: 0x1800984b8)
- memset (Address: 0x1800984f0)
- qsort (Address: 0x1800984d8)
- strtoul (Address: 0x180098430)
- swscanf_s (Address: 0x180098458)
- toupper (Address: 0x180098428)
- wcscpy_s (Address: 0x1800983e0)
- wcsnlen (Address: 0x180098410)
- wcstok_s (Address: 0x180098480)
- wcstoul (Address: 0x1800984e8)
ntdll.dll
- NtClearEvent (Address: 0x1800985f0)
- NtClose (Address: 0x180098898)
- NtCreateEvent (Address: 0x1800986c0)
- NtCreateFile (Address: 0x180098530)
- NtCreateIRTimer (Address: 0x180098890)
- NtCreateKey (Address: 0x180098540)
- NtCreateWnfStateName (Address: 0x180098788)
- NtDeleteFile (Address: 0x180098560)
- NtDeleteKey (Address: 0x180098598)
- NtDeleteValueKey (Address: 0x180098550)
- NtDeleteWnfStateName (Address: 0x180098790)
- NtDuplicateObject (Address: 0x1800986a8)
- NtEnumerateKey (Address: 0x180098588)
- NtLoadKeyEx (Address: 0x180098548)
- NtOpenKey (Address: 0x180098570)
- NtOpenProcess (Address: 0x1800986c8)
- NtOpenProcessToken (Address: 0x180098800)
- NtOpenThreadToken (Address: 0x1800987c8)
- NtPowerInformation (Address: 0x180098848)
- NtQueryAttributesFile (Address: 0x180098510)
- NtQueryInformationProcess (Address: 0x180098670)
- NtQueryInformationToken (Address: 0x1800987f0)
- NtQuerySystemInformation (Address: 0x180098678)
- NtQueryValueKey (Address: 0x1800986f8)
- NtQueryWnfStateData (Address: 0x180098850)
- NtReadVirtualMemory (Address: 0x180098628)
- NtSaveKeyEx (Address: 0x180098538)
- NtSetEvent (Address: 0x180098610)
- NtSetIRTimer (Address: 0x1800988a0)
- NtSetValueKey (Address: 0x180098528)
- NtWriteVirtualMemory (Address: 0x1800985f8)
- RtlAcquirePrivilege (Address: 0x180098558)
- RtlAcquireSRWLockExclusive (Address: 0x180098630)
- RtlAcquireSRWLockShared (Address: 0x180098688)
- RtlAddAccessAllowedAceEx (Address: 0x180098758)
- RtlAllocateHeap (Address: 0x180098798)
- RtlAppendUnicodeStringToString (Address: 0x180098590)
- RtlAppendUnicodeToString (Address: 0x180098580)
- RtlClearBit (Address: 0x180098838)
- RtlCompareUnicodeString (Address: 0x1800985a8)
- RtlCompareUnicodeStrings (Address: 0x1800986d8)
- RtlConvertSidToUnicodeString (Address: 0x180098888)
- RtlCopySid (Address: 0x1800987d8)
- RtlCopyUnicodeString (Address: 0x180098638)
- RtlCreateAcl (Address: 0x180098718)
- RtlCreateHashTable (Address: 0x1800986a0)
- RtlCreateSecurityDescriptor (Address: 0x180098710)
- RtlDeleteHashTable (Address: 0x180098700)
- RtlDuplicateUnicodeString (Address: 0x180098708)
- RtlEndEnumerationHashTable (Address: 0x180098780)
- RtlEnumerateEntryHashTable (Address: 0x1800987a8)
- RtlEqualSid (Address: 0x1800987b8)
- RtlFreeHeap (Address: 0x180098720)
- RtlFreeSid (Address: 0x180098730)
- RtlFreeUnicodeString (Address: 0x1800986e0)
- RtlGetDeviceFamilyInfoEnum (Address: 0x180098768)
- RtlGetNextEntryHashTable (Address: 0x180098690)
- RtlGUIDFromString (Address: 0x1800987a0)
- RtlInitEnumerationHashTable (Address: 0x180098738)
- RtlInitializeBitMap (Address: 0x180098818)
- RtlInitializeSRWLock (Address: 0x180098648)
- RtlInitUnicodeString (Address: 0x180098760)
- RtlInsertEntryHashTable (Address: 0x1800986b8)
- RtlIsMultiSessionSku (Address: 0x180098728)
- RtlLengthSid (Address: 0x1800986d0)
- RtlLookupEntryHashTable (Address: 0x180098698)
- RtlNtStatusToDosError (Address: 0x180098518)
- RtlNtStatusToDosErrorNoTeb (Address: 0x180098658)
- RtlPublishWnfStateData (Address: 0x180098668)
- RtlQueryPackageClaims (Address: 0x1800987e8)
- RtlQueryPackageIdentityEx (Address: 0x1800987c0)
- RtlQueryUnbiasedInterruptTime (Address: 0x1800986f0)
- RtlQueryWnfMetaNotification (Address: 0x180098748)
- RtlQueryWnfStateData (Address: 0x180098520)
- RtlRbInsertNodeEx (Address: 0x1800985c0)
- RtlRbRemoveNode (Address: 0x180098500)
- RtlReAllocateHeap (Address: 0x180098750)
- RtlRegisterForWnfMetaNotification (Address: 0x180098618)
- RtlReleasePrivilege (Address: 0x180098578)
- RtlReleaseSRWLockExclusive (Address: 0x180098640)
- RtlReleaseSRWLockShared (Address: 0x180098680)
- RtlRemoveEntryHashTable (Address: 0x180098740)
- RtlRunOnceBeginInitialize (Address: 0x1800985d0)
- RtlRunOnceComplete (Address: 0x1800985a0)
- RtlRunOnceExecuteOnce (Address: 0x180098840)
- RtlSetBit (Address: 0x180098858)
- RtlSetDaclSecurityDescriptor (Address: 0x180098778)
- RtlSetOwnerSecurityDescriptor (Address: 0x1800987b0)
- RtlStringFromGUID (Address: 0x1800986e8)
- RtlStringFromGUIDEx (Address: 0x180098600)
- RtlSubscribeWnfStateChangeNotification (Address: 0x180098878)
- RtlTestBit (Address: 0x180098810)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1800985e8)
- RtlUnsubscribeWnfStateChangeNotification (Address: 0x180098650)
- RtlUpcaseUnicodeChar (Address: 0x180098770)
- RtlValidSid (Address: 0x180098808)
- RtlWaitForWnfMetaNotification (Address: 0x180098660)
- RtlWaitOnAddress (Address: 0x1800987e0)
- RtlWakeAddressAll (Address: 0x1800986b0)
- TpAllocPool (Address: 0x1800985e0)
- TpAllocTimer (Address: 0x180098870)
- TpAllocWait (Address: 0x1800985b8)
- TpAllocWork (Address: 0x180098860)
- TpPostWork (Address: 0x180098830)
- TpReleasePool (Address: 0x1800985d8)
- TpReleaseTimer (Address: 0x1800987f8)
- TpReleaseWait (Address: 0x180098568)
- TpReleaseWork (Address: 0x180098820)
- TpSetPoolMaxThreads (Address: 0x180098608)
- TpSetTimer (Address: 0x180098880)
- TpSetTimerEx (Address: 0x1800987d0)
- TpSetWait (Address: 0x1800985c8)
- TpSetWaitEx (Address: 0x180098620)
- TpWaitForTimer (Address: 0x180098868)
- TpWaitForWait (Address: 0x1800985b0)
- TpWaitForWork (Address: 0x180098828)
- ZwUpdateWnfStateData (Address: 0x180098508)
OLEAUT32.dll
- SysAllocString (Address: 0x180097b50)
- SysAllocStringLen (Address: 0x180097b40)
- SysFreeString (Address: 0x180097b58)
- SysStringLen (Address: 0x180097b48)
ResourcePolicyClient.dll
- CreateResourcePolicyEngineClient (Address: 0x180097cd8)
- CreateResourcePolicyStoreClient (Address: 0x180097cc8)
- InterruptiveUIStateChanged_Subscribe (Address: 0x180097cc0)
- InterruptiveUIStateChanged_Unsubscribe (Address: 0x180097cd0)
- QueryApplicationInterruptiveUIStateByPsmKey (Address: 0x180097cb8)
RMCLIENT.dll
- CrmActivityAllocate (Address: 0x180097b70)
- CrmActivityFree (Address: 0x180097b68)
- CrmActivityRequest (Address: 0x180097b78)
- CrmActivityStart (Address: 0x180097b88)
- CrmActivityStop (Address: 0x180097b80)
- CrmRegister (Address: 0x180097be0)
- HamCloseActivity (Address: 0x180097bd0)
- HamConnectToServer (Address: 0x180097ba8)
- HamCreateActivityEx (Address: 0x180097bc0)
- HamDisconnectFromServer (Address: 0x180097ba0)
- HamIsHostBeingDebugged (Address: 0x180097bb0)
- HamPopulateActivityProperties (Address: 0x180097bb8)
- HamResetExternalResourcePriority (Address: 0x180097b90)
- HamSetExternalResourcePriority (Address: 0x180097b98)
- HamStartActivityAsync (Address: 0x180097bc8)
- HamTerminateActivityHost (Address: 0x180097bd8)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x180097bf0)
- I_RpcExceptionFilter (Address: 0x180097c48)
- I_RpcMapWin32Status (Address: 0x180097c28)
- Ndr64AsyncServerCallAll (Address: 0x180097c40)
- NdrAsyncServerCall (Address: 0x180097c38)
- NdrClientCall3 (Address: 0x180097c20)
- NdrServerCall2 (Address: 0x180097c50)
- NdrServerCallAll (Address: 0x180097c30)
- RpcAsyncCompleteCall (Address: 0x180097c08)
- RpcBindingBind (Address: 0x180097c10)
- RpcBindingCreateW (Address: 0x180097c58)
- RpcBindingFree (Address: 0x180097c00)
- RpcBindingVectorFree (Address: 0x180097c70)
- RpcEpRegisterW (Address: 0x180097c78)
- RpcEpUnregister (Address: 0x180097c68)
- RpcImpersonateClient (Address: 0x180097c60)
- RpcRaiseException (Address: 0x180097bf8)
- RpcRevertToSelf (Address: 0x180097ca8)
- RpcServerInqBindings (Address: 0x180097c88)
- RpcServerInqCallAttributesW (Address: 0x180097ca0)
- RpcServerRegisterIf3 (Address: 0x180097c90)
- RpcServerUnregisterIf (Address: 0x180097c80)
- RpcServerUseProtseqW (Address: 0x180097c98)
- UuidCreate (Address: 0x180097c18)
UMPDC.dll
- Pdcv2ActivationClientActivate (Address: 0x180097d00)
- Pdcv2ActivationClientDeactivate (Address: 0x180097d08)
- Pdcv2ActivationClientRegister (Address: 0x180097d10)
- Pdcv2ActivationClientRenewActivation (Address: 0x180097ce8)
- Pdcv2ActivationClientSetBrokeredProcessId (Address: 0x180097cf0)
- Pdcv2ActivationClientUnregister (Address: 0x180097cf8)