cscobj.dll
Description: In-proc COM object used by clients of CSC API
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5369
Architecture: 32-bit
Operating System: Windows NT
SHA256: ddb39684e66a949ea856a01fe6562c65
File Size: 198.0 KB
Uploaded At: Dec. 1, 2025, 7:54 a.m.
Views: 5
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- ProcessGroupPolicy (Ordinal: 1, Address: 0x17290)
- ProcessPolicy (Ordinal: 2, Address: 0x172b0)
- DllCanUnloadNow (Ordinal: 3, Address: 0xc3a0)
- DllGetClassObject (Ordinal: 4, Address: 0x14e00)
- DllRegisterServer (Ordinal: 5, Address: 0x14ea0)
- DllUnregisterServer (Ordinal: 6, Address: 0x14ed0)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x7374e094)
- CoCreateInstanceEx (Address: 0x7374e07c)
- CoGetCallContext (Address: 0x7374e078)
- CoGetInterfaceAndReleaseStream (Address: 0x7374e088)
- CoInitializeEx (Address: 0x7374e0a0)
- CoMarshalInterface (Address: 0x7374e090)
- CoMarshalInterThreadInterfaceInStream (Address: 0x7374e08c)
- CoQueryProxyBlanket (Address: 0x7374e098)
- CoRevertToSelf (Address: 0x7374e074)
- CoSetProxyBlanket (Address: 0x7374e080)
- CoTaskMemAlloc (Address: 0x7374e070)
- CoTaskMemFree (Address: 0x7374e06c)
- CoUninitialize (Address: 0x7374e09c)
- CoUnmarshalInterface (Address: 0x7374e084)
- CoWaitForMultipleHandles (Address: 0x7374e0a8)
- CreateStreamOnHGlobal (Address: 0x7374e0a4)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
- CStdAsyncStubBuffer_AddRef (Address: 0x7374e0f0)
- CStdAsyncStubBuffer_Connect (Address: 0x7374e10c)
- CStdAsyncStubBuffer_Disconnect (Address: 0x7374e108)
- CStdAsyncStubBuffer_Invoke (Address: 0x7374e0f4)
- CStdAsyncStubBuffer_QueryInterface (Address: 0x7374e128)
- CStdAsyncStubBuffer_Release (Address: 0x7374e144)
- CStdStubBuffer2_Connect (Address: 0x7374e0c8)
- CStdStubBuffer2_CountRefs (Address: 0x7374e100)
- CStdStubBuffer2_Disconnect (Address: 0x7374e134)
- CStdStubBuffer2_QueryInterface (Address: 0x7374e0ec)
- NdrProxyForwardingFunction20 (Address: 0x7374e0f8)
- NdrProxyForwardingFunction3 (Address: 0x7374e0dc)
- NdrProxyForwardingFunction4 (Address: 0x7374e13c)
- NdrProxyForwardingFunction5 (Address: 0x7374e140)
- NdrProxyForwardingFunction6 (Address: 0x7374e14c)
- NdrProxyForwardingFunction7 (Address: 0x7374e0d0)
- ObjectStublessClient10 (Address: 0x7374e114)
- ObjectStublessClient11 (Address: 0x7374e0fc)
- ObjectStublessClient12 (Address: 0x7374e0b4)
- ObjectStublessClient13 (Address: 0x7374e110)
- ObjectStublessClient14 (Address: 0x7374e0c4)
- ObjectStublessClient15 (Address: 0x7374e130)
- ObjectStublessClient16 (Address: 0x7374e0e8)
- ObjectStublessClient17 (Address: 0x7374e118)
- ObjectStublessClient18 (Address: 0x7374e12c)
- ObjectStublessClient19 (Address: 0x7374e104)
- ObjectStublessClient20 (Address: 0x7374e138)
- ObjectStublessClient21 (Address: 0x7374e0e0)
- ObjectStublessClient22 (Address: 0x7374e0b8)
- ObjectStublessClient23 (Address: 0x7374e0d8)
- ObjectStublessClient24 (Address: 0x7374e0d4)
- ObjectStublessClient25 (Address: 0x7374e0e4)
- ObjectStublessClient26 (Address: 0x7374e0cc)
- ObjectStublessClient27 (Address: 0x7374e0b0)
- ObjectStublessClient3 (Address: 0x7374e11c)
- ObjectStublessClient4 (Address: 0x7374e0bc)
- ObjectStublessClient5 (Address: 0x7374e0c0)
- ObjectStublessClient6 (Address: 0x7374e150)
- ObjectStublessClient7 (Address: 0x7374e148)
- ObjectStublessClient8 (Address: 0x7374e124)
- ObjectStublessClient9 (Address: 0x7374e120)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x7374e158)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x7374e160)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x7374e178)
- RaiseException (Address: 0x7374e174)
- SetLastError (Address: 0x7374e170)
- SetUnhandledExceptionFilter (Address: 0x7374e16c)
- UnhandledExceptionFilter (Address: 0x7374e168)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x7374e180)
- DuplicateHandle (Address: 0x7374e184)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x7374e194)
- HeapAlloc (Address: 0x7374e18c)
- HeapDestroy (Address: 0x7374e198)
- HeapFree (Address: 0x7374e190)
- HeapReAlloc (Address: 0x7374e1a0)
- HeapSize (Address: 0x7374e19c)
api-ms-win-core-heap-l2-1-0.dll
- LocalFree (Address: 0x7374e1a8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x7374e1c4)
- FindResourceExW (Address: 0x7374e1c8)
- FreeLibrary (Address: 0x7374e1b8)
- FreeLibraryAndExitThread (Address: 0x7374e1d0)
- GetProcAddress (Address: 0x7374e1c0)
- LoadResource (Address: 0x7374e1bc)
- LoadStringW (Address: 0x7374e1cc)
- LockResource (Address: 0x7374e1b4)
- SizeofResource (Address: 0x7374e1b0)
api-ms-win-core-libraryloader-l1-2-1.dll
- FindResourceW (Address: 0x7374e1d8)
- LoadLibraryW (Address: 0x7374e1dc)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x7374e1e4)
api-ms-win-core-marshal-l1-1-0.dll
- HWND_UserFree (Address: 0x7374e1f8)
- HWND_UserMarshal (Address: 0x7374e1f4)
- HWND_UserSize (Address: 0x7374e1ec)
- HWND_UserUnmarshal (Address: 0x7374e1f0)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x7374e200)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x7374e224)
- GetCurrentProcess (Address: 0x7374e21c)
- GetCurrentProcessId (Address: 0x7374e208)
- GetCurrentThread (Address: 0x7374e214)
- GetCurrentThreadId (Address: 0x7374e210)
- OpenThreadToken (Address: 0x7374e220)
- SetThreadToken (Address: 0x7374e20c)
- TerminateProcess (Address: 0x7374e218)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x7374e22c)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x7374e234)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x7374e248)
- RegCreateKeyExW (Address: 0x7374e23c)
- RegDeleteKeyExW (Address: 0x7374e258)
- RegDeleteValueW (Address: 0x7374e244)
- RegEnumValueW (Address: 0x7374e240)
- RegOpenCurrentUser (Address: 0x7374e25c)
- RegOpenKeyExW (Address: 0x7374e254)
- RegQueryValueExW (Address: 0x7374e250)
- RegSetValueExW (Address: 0x7374e24c)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x7374e264)
- CompareStringW (Address: 0x7374e268)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x7374e270)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x7374e294)
- CreateEventW (Address: 0x7374e290)
- DeleteCriticalSection (Address: 0x7374e284)
- EnterCriticalSection (Address: 0x7374e280)
- InitializeCriticalSection (Address: 0x7374e28c)
- InitializeCriticalSectionAndSpinCount (Address: 0x7374e278)
- LeaveCriticalSection (Address: 0x7374e27c)
- ReleaseSRWLockExclusive (Address: 0x7374e298)
- SetEvent (Address: 0x7374e29c)
- WaitForSingleObject (Address: 0x7374e288)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x7374e2ac)
- SleepConditionVariableSRW (Address: 0x7374e2a8)
- WakeAllConditionVariable (Address: 0x7374e2a4)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x7374e2b8)
- GetSystemWindowsDirectoryW (Address: 0x7374e2bc)
- GetTickCount (Address: 0x7374e2b4)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- QueueUserWorkItem (Address: 0x7374e2c4)
api-ms-win-core-timezone-l1-1-0.dll
- FileTimeToSystemTime (Address: 0x7374e2cc)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x7374e2d8)
- DuplicateTokenEx (Address: 0x7374e2dc)
- GetLengthSid (Address: 0x7374e2ec)
- GetTokenInformation (Address: 0x7374e2d4)
- ImpersonateLoggedOnUser (Address: 0x7374e2e8)
- IsValidSid (Address: 0x7374e2e0)
- RevertToSelf (Address: 0x7374e2e4)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupAccountSidW (Address: 0x7374e2f4)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x7374e300)
- ConvertStringSidToSidW (Address: 0x7374e2fc)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x7374e32c)
- __dllonexit (Address: 0x7374e324)
- _amsg_exit (Address: 0x7374e308)
- _callnewh (Address: 0x7374e358)
- _except_handler4_common (Address: 0x7374e330)
- _ftol2 (Address: 0x7374e318)
- _i64tow_s (Address: 0x7374e34c)
- _initterm (Address: 0x7374e310)
- _lock (Address: 0x7374e31c)
- _onexit (Address: 0x7374e328)
- _purecall (Address: 0x7374e334)
- _unlock (Address: 0x7374e320)
- _vsnwprintf (Address: 0x7374e348)
- _XcptFilter (Address: 0x7374e35c)
- ?terminate@@YAXXZ (Address: 0x7374e314)
- free (Address: 0x7374e350)
- malloc (Address: 0x7374e354)
- memcmp (Address: 0x7374e364)
- memcpy_s (Address: 0x7374e30c)
- memmove (Address: 0x7374e338)
- memmove_s (Address: 0x7374e344)
- memset (Address: 0x7374e368)
- wcschr (Address: 0x7374e340)
- wcscspn (Address: 0x7374e33c)
- wcsspn (Address: 0x7374e360)
ntdll.dll
- EtwGetTraceEnableFlags (Address: 0x7374e390)
- EtwGetTraceEnableLevel (Address: 0x7374e394)
- EtwGetTraceLoggerHandle (Address: 0x7374e398)
- EtwRegisterTraceGuidsW (Address: 0x7374e3a4)
- EtwTraceMessage (Address: 0x7374e3a0)
- EtwUnregisterTraceGuids (Address: 0x7374e388)
- RtlAppendPathElement (Address: 0x7374e378)
- RtlFreeUnicodeString (Address: 0x7374e384)
- RtlGetLengthWithoutLastFullDosOrNtPathElement (Address: 0x7374e370)
- RtlGetLengthWithoutTrailingPathSeperators (Address: 0x7374e38c)
- RtlInitUnicodeString (Address: 0x7374e380)
- RtlNtStatusToDosError (Address: 0x7374e39c)
- RtlpApplyLengthFunction (Address: 0x7374e374)
- RtlpEnsureBufferSize (Address: 0x7374e37c)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x7374e028)
- CStdStubBuffer_Connect (Address: 0x7374e048)
- CStdStubBuffer_CountRefs (Address: 0x7374e024)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x7374e054)
- CStdStubBuffer_DebugServerRelease (Address: 0x7374e038)
- CStdStubBuffer_Disconnect (Address: 0x7374e040)
- CStdStubBuffer_Invoke (Address: 0x7374e004)
- CStdStubBuffer_IsIIDSupported (Address: 0x7374e044)
- CStdStubBuffer_QueryInterface (Address: 0x7374e02c)
- IUnknown_AddRef_Proxy (Address: 0x7374e050)
- IUnknown_QueryInterface_Proxy (Address: 0x7374e000)
- IUnknown_Release_Proxy (Address: 0x7374e010)
- NdrCStdStubBuffer_Release (Address: 0x7374e008)
- NdrCStdStubBuffer2_Release (Address: 0x7374e020)
- NdrDllCanUnloadNow (Address: 0x7374e00c)
- NdrDllGetClassObject (Address: 0x7374e014)
- NdrDllRegisterProxy (Address: 0x7374e018)
- NdrDllUnregisterProxy (Address: 0x7374e01c)
- NdrOleAllocate (Address: 0x7374e030)
- NdrOleFree (Address: 0x7374e03c)
- NdrStubCall2 (Address: 0x7374e034)
- NdrStubForwardingFunction (Address: 0x7374e04c)
USERENV.dll
- ProcessGroupPolicyCompleted (Address: 0x7374e05c)
WTSAPI32.dll
- WTSQueryUserToken (Address: 0x7374e064)