cscobj.dll

Description: In-proc COM object used by clients of CSC API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5369

Architecture: 32-bit

Operating System: Windows NT

SHA256: ddb39684e66a949ea856a01fe6562c65

File Size: 198.0 KB

Uploaded At: Dec. 1, 2025, 7:54 a.m.

Views: 5

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ProcessGroupPolicy (Ordinal: 1, Address: 0x17290)
  • ProcessPolicy (Ordinal: 2, Address: 0x172b0)
  • DllCanUnloadNow (Ordinal: 3, Address: 0xc3a0)
  • DllGetClassObject (Ordinal: 4, Address: 0x14e00)
  • DllRegisterServer (Ordinal: 5, Address: 0x14ea0)
  • DllUnregisterServer (Ordinal: 6, Address: 0x14ed0)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x7374e094)
  • CoCreateInstanceEx (Address: 0x7374e07c)
  • CoGetCallContext (Address: 0x7374e078)
  • CoGetInterfaceAndReleaseStream (Address: 0x7374e088)
  • CoInitializeEx (Address: 0x7374e0a0)
  • CoMarshalInterface (Address: 0x7374e090)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x7374e08c)
  • CoQueryProxyBlanket (Address: 0x7374e098)
  • CoRevertToSelf (Address: 0x7374e074)
  • CoSetProxyBlanket (Address: 0x7374e080)
  • CoTaskMemAlloc (Address: 0x7374e070)
  • CoTaskMemFree (Address: 0x7374e06c)
  • CoUninitialize (Address: 0x7374e09c)
  • CoUnmarshalInterface (Address: 0x7374e084)
  • CoWaitForMultipleHandles (Address: 0x7374e0a8)
  • CreateStreamOnHGlobal (Address: 0x7374e0a4)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • CStdAsyncStubBuffer_AddRef (Address: 0x7374e0f0)
  • CStdAsyncStubBuffer_Connect (Address: 0x7374e10c)
  • CStdAsyncStubBuffer_Disconnect (Address: 0x7374e108)
  • CStdAsyncStubBuffer_Invoke (Address: 0x7374e0f4)
  • CStdAsyncStubBuffer_QueryInterface (Address: 0x7374e128)
  • CStdAsyncStubBuffer_Release (Address: 0x7374e144)
  • CStdStubBuffer2_Connect (Address: 0x7374e0c8)
  • CStdStubBuffer2_CountRefs (Address: 0x7374e100)
  • CStdStubBuffer2_Disconnect (Address: 0x7374e134)
  • CStdStubBuffer2_QueryInterface (Address: 0x7374e0ec)
  • NdrProxyForwardingFunction20 (Address: 0x7374e0f8)
  • NdrProxyForwardingFunction3 (Address: 0x7374e0dc)
  • NdrProxyForwardingFunction4 (Address: 0x7374e13c)
  • NdrProxyForwardingFunction5 (Address: 0x7374e140)
  • NdrProxyForwardingFunction6 (Address: 0x7374e14c)
  • NdrProxyForwardingFunction7 (Address: 0x7374e0d0)
  • ObjectStublessClient10 (Address: 0x7374e114)
  • ObjectStublessClient11 (Address: 0x7374e0fc)
  • ObjectStublessClient12 (Address: 0x7374e0b4)
  • ObjectStublessClient13 (Address: 0x7374e110)
  • ObjectStublessClient14 (Address: 0x7374e0c4)
  • ObjectStublessClient15 (Address: 0x7374e130)
  • ObjectStublessClient16 (Address: 0x7374e0e8)
  • ObjectStublessClient17 (Address: 0x7374e118)
  • ObjectStublessClient18 (Address: 0x7374e12c)
  • ObjectStublessClient19 (Address: 0x7374e104)
  • ObjectStublessClient20 (Address: 0x7374e138)
  • ObjectStublessClient21 (Address: 0x7374e0e0)
  • ObjectStublessClient22 (Address: 0x7374e0b8)
  • ObjectStublessClient23 (Address: 0x7374e0d8)
  • ObjectStublessClient24 (Address: 0x7374e0d4)
  • ObjectStublessClient25 (Address: 0x7374e0e4)
  • ObjectStublessClient26 (Address: 0x7374e0cc)
  • ObjectStublessClient27 (Address: 0x7374e0b0)
  • ObjectStublessClient3 (Address: 0x7374e11c)
  • ObjectStublessClient4 (Address: 0x7374e0bc)
  • ObjectStublessClient5 (Address: 0x7374e0c0)
  • ObjectStublessClient6 (Address: 0x7374e150)
  • ObjectStublessClient7 (Address: 0x7374e148)
  • ObjectStublessClient8 (Address: 0x7374e124)
  • ObjectStublessClient9 (Address: 0x7374e120)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x7374e158)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x7374e160)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x7374e178)
  • RaiseException (Address: 0x7374e174)
  • SetLastError (Address: 0x7374e170)
  • SetUnhandledExceptionFilter (Address: 0x7374e16c)
  • UnhandledExceptionFilter (Address: 0x7374e168)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x7374e180)
  • DuplicateHandle (Address: 0x7374e184)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x7374e194)
  • HeapAlloc (Address: 0x7374e18c)
  • HeapDestroy (Address: 0x7374e198)
  • HeapFree (Address: 0x7374e190)
  • HeapReAlloc (Address: 0x7374e1a0)
  • HeapSize (Address: 0x7374e19c)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x7374e1a8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x7374e1c4)
  • FindResourceExW (Address: 0x7374e1c8)
  • FreeLibrary (Address: 0x7374e1b8)
  • FreeLibraryAndExitThread (Address: 0x7374e1d0)
  • GetProcAddress (Address: 0x7374e1c0)
  • LoadResource (Address: 0x7374e1bc)
  • LoadStringW (Address: 0x7374e1cc)
  • LockResource (Address: 0x7374e1b4)
  • SizeofResource (Address: 0x7374e1b0)
api-ms-win-core-libraryloader-l1-2-1.dll
  • FindResourceW (Address: 0x7374e1d8)
  • LoadLibraryW (Address: 0x7374e1dc)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x7374e1e4)
api-ms-win-core-marshal-l1-1-0.dll
  • HWND_UserFree (Address: 0x7374e1f8)
  • HWND_UserMarshal (Address: 0x7374e1f4)
  • HWND_UserSize (Address: 0x7374e1ec)
  • HWND_UserUnmarshal (Address: 0x7374e1f0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x7374e200)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x7374e224)
  • GetCurrentProcess (Address: 0x7374e21c)
  • GetCurrentProcessId (Address: 0x7374e208)
  • GetCurrentThread (Address: 0x7374e214)
  • GetCurrentThreadId (Address: 0x7374e210)
  • OpenThreadToken (Address: 0x7374e220)
  • SetThreadToken (Address: 0x7374e20c)
  • TerminateProcess (Address: 0x7374e218)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x7374e22c)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x7374e234)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x7374e248)
  • RegCreateKeyExW (Address: 0x7374e23c)
  • RegDeleteKeyExW (Address: 0x7374e258)
  • RegDeleteValueW (Address: 0x7374e244)
  • RegEnumValueW (Address: 0x7374e240)
  • RegOpenCurrentUser (Address: 0x7374e25c)
  • RegOpenKeyExW (Address: 0x7374e254)
  • RegQueryValueExW (Address: 0x7374e250)
  • RegSetValueExW (Address: 0x7374e24c)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x7374e264)
  • CompareStringW (Address: 0x7374e268)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x7374e270)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x7374e294)
  • CreateEventW (Address: 0x7374e290)
  • DeleteCriticalSection (Address: 0x7374e284)
  • EnterCriticalSection (Address: 0x7374e280)
  • InitializeCriticalSection (Address: 0x7374e28c)
  • InitializeCriticalSectionAndSpinCount (Address: 0x7374e278)
  • LeaveCriticalSection (Address: 0x7374e27c)
  • ReleaseSRWLockExclusive (Address: 0x7374e298)
  • SetEvent (Address: 0x7374e29c)
  • WaitForSingleObject (Address: 0x7374e288)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x7374e2ac)
  • SleepConditionVariableSRW (Address: 0x7374e2a8)
  • WakeAllConditionVariable (Address: 0x7374e2a4)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x7374e2b8)
  • GetSystemWindowsDirectoryW (Address: 0x7374e2bc)
  • GetTickCount (Address: 0x7374e2b4)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • QueueUserWorkItem (Address: 0x7374e2c4)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x7374e2cc)
api-ms-win-security-base-l1-1-0.dll
  • CopySid (Address: 0x7374e2d8)
  • DuplicateTokenEx (Address: 0x7374e2dc)
  • GetLengthSid (Address: 0x7374e2ec)
  • GetTokenInformation (Address: 0x7374e2d4)
  • ImpersonateLoggedOnUser (Address: 0x7374e2e8)
  • IsValidSid (Address: 0x7374e2e0)
  • RevertToSelf (Address: 0x7374e2e4)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountSidW (Address: 0x7374e2f4)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x7374e300)
  • ConvertStringSidToSidW (Address: 0x7374e2fc)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x7374e32c)
  • __dllonexit (Address: 0x7374e324)
  • _amsg_exit (Address: 0x7374e308)
  • _callnewh (Address: 0x7374e358)
  • _except_handler4_common (Address: 0x7374e330)
  • _ftol2 (Address: 0x7374e318)
  • _i64tow_s (Address: 0x7374e34c)
  • _initterm (Address: 0x7374e310)
  • _lock (Address: 0x7374e31c)
  • _onexit (Address: 0x7374e328)
  • _purecall (Address: 0x7374e334)
  • _unlock (Address: 0x7374e320)
  • _vsnwprintf (Address: 0x7374e348)
  • _XcptFilter (Address: 0x7374e35c)
  • ?terminate@@YAXXZ (Address: 0x7374e314)
  • free (Address: 0x7374e350)
  • malloc (Address: 0x7374e354)
  • memcmp (Address: 0x7374e364)
  • memcpy_s (Address: 0x7374e30c)
  • memmove (Address: 0x7374e338)
  • memmove_s (Address: 0x7374e344)
  • memset (Address: 0x7374e368)
  • wcschr (Address: 0x7374e340)
  • wcscspn (Address: 0x7374e33c)
  • wcsspn (Address: 0x7374e360)
ntdll.dll
  • EtwGetTraceEnableFlags (Address: 0x7374e390)
  • EtwGetTraceEnableLevel (Address: 0x7374e394)
  • EtwGetTraceLoggerHandle (Address: 0x7374e398)
  • EtwRegisterTraceGuidsW (Address: 0x7374e3a4)
  • EtwTraceMessage (Address: 0x7374e3a0)
  • EtwUnregisterTraceGuids (Address: 0x7374e388)
  • RtlAppendPathElement (Address: 0x7374e378)
  • RtlFreeUnicodeString (Address: 0x7374e384)
  • RtlGetLengthWithoutLastFullDosOrNtPathElement (Address: 0x7374e370)
  • RtlGetLengthWithoutTrailingPathSeperators (Address: 0x7374e38c)
  • RtlInitUnicodeString (Address: 0x7374e380)
  • RtlNtStatusToDosError (Address: 0x7374e39c)
  • RtlpApplyLengthFunction (Address: 0x7374e374)
  • RtlpEnsureBufferSize (Address: 0x7374e37c)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x7374e028)
  • CStdStubBuffer_Connect (Address: 0x7374e048)
  • CStdStubBuffer_CountRefs (Address: 0x7374e024)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x7374e054)
  • CStdStubBuffer_DebugServerRelease (Address: 0x7374e038)
  • CStdStubBuffer_Disconnect (Address: 0x7374e040)
  • CStdStubBuffer_Invoke (Address: 0x7374e004)
  • CStdStubBuffer_IsIIDSupported (Address: 0x7374e044)
  • CStdStubBuffer_QueryInterface (Address: 0x7374e02c)
  • IUnknown_AddRef_Proxy (Address: 0x7374e050)
  • IUnknown_QueryInterface_Proxy (Address: 0x7374e000)
  • IUnknown_Release_Proxy (Address: 0x7374e010)
  • NdrCStdStubBuffer_Release (Address: 0x7374e008)
  • NdrCStdStubBuffer2_Release (Address: 0x7374e020)
  • NdrDllCanUnloadNow (Address: 0x7374e00c)
  • NdrDllGetClassObject (Address: 0x7374e014)
  • NdrDllRegisterProxy (Address: 0x7374e018)
  • NdrDllUnregisterProxy (Address: 0x7374e01c)
  • NdrOleAllocate (Address: 0x7374e030)
  • NdrOleFree (Address: 0x7374e03c)
  • NdrStubCall2 (Address: 0x7374e034)
  • NdrStubForwardingFunction (Address: 0x7374e04c)
USERENV.dll
  • ProcessGroupPolicyCompleted (Address: 0x7374e05c)
WTSAPI32.dll
  • WTSQueryUserToken (Address: 0x7374e064)