efsutil.dll

Description: EFS Utility Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1

Architecture: 32-bit

Operating System: Windows NT

SHA256: d64e237a51408d12d8af1b3a74aa6f1f

File Size: 35.0 KB

Uploaded At: Dec. 1, 2025, 7:56 a.m.

Views: 8

Exported Functions

  • EfsUtilApplyGroupPolicy (Ordinal: 1, Address: 0x5c20)
  • EfsUtilCheckCurrentKeyCapabilities (Ordinal: 2, Address: 0x3110)
  • EfsUtilCreateSelfSignedCertificate (Ordinal: 3, Address: 0x38d0)
  • EfsUtilFreeParsedRecoveryPolicy (Ordinal: 4, Address: 0x4a00)
  • EfsUtilGetCertContextFromCertHash (Ordinal: 5, Address: 0x3340)
  • EfsUtilGetCertDisplayInformation (Ordinal: 6, Address: 0x4bf0)
  • EfsUtilGetCertNameFromCertContext (Ordinal: 7, Address: 0x4ac0)
  • EfsUtilGetCurrentKey (Ordinal: 8, Address: 0x3150)
  • EfsUtilGetCurrentKey_Deprecated (Ordinal: 9, Address: 0x43c0)
  • EfsUtilGetCurrentUserInformation (Ordinal: 10, Address: 0x3f20)
  • EfsUtilGetProvider (Ordinal: 11, Address: 0x1fe0)
  • EfsUtilGetPublicKeyType (Ordinal: 12, Address: 0x5190)
  • EfsUtilGetSmartcardProviderName (Ordinal: 13, Address: 0x4100)
  • EfsUtilGetUserKey (Ordinal: 14, Address: 0x2a50)
  • EfsUtilIsSmartcardKey (Ordinal: 15, Address: 0x2b00)
  • EfsUtilIsSmartcardProvider (Ordinal: 16, Address: 0x2150)
  • EfsUtilParseDataRecoveryPolicy_1_1 (Ordinal: 17, Address: 0x43d0)
  • EfsUtilReleaseProvider (Ordinal: 18, Address: 0x2110)
  • EfsUtilReleaseUserKey (Ordinal: 19, Address: 0x2ba0)
  • EfsUtilSetCurrentKey (Ordinal: 20, Address: 0x3280)
  • EfsUtilSetSmartcardPin (Ordinal: 21, Address: 0x21d0)
  • EfsUtilSmartcardCredsNeededError (Ordinal: 22, Address: 0x1fa0)

Imported DLLs & Functions

api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x10009064)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1000906c)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x10009080)
  • SetLastError (Address: 0x10009074)
  • SetUnhandledExceptionFilter (Address: 0x1000907c)
  • UnhandledExceptionFilter (Address: 0x10009078)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x10009088)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x10009094)
  • HeapAlloc (Address: 0x10009098)
  • HeapFree (Address: 0x10009090)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x100090a4)
  • LocalFree (Address: 0x100090a0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x100090ac)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x100090bc)
  • VirtualProtect (Address: 0x100090b8)
  • VirtualQuery (Address: 0x100090b4)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x100090dc)
  • GetCurrentProcessId (Address: 0x100090cc)
  • GetCurrentThread (Address: 0x100090d4)
  • GetCurrentThreadId (Address: 0x100090e0)
  • OpenProcessToken (Address: 0x100090d8)
  • OpenThreadToken (Address: 0x100090d0)
  • SetThreadStackGuarantee (Address: 0x100090c4)
  • TerminateProcess (Address: 0x100090c8)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x100090e8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x100090f8)
  • RegCreateKeyExW (Address: 0x100090f0)
  • RegGetValueW (Address: 0x100090fc)
  • RegOpenKeyExW (Address: 0x10009100)
  • RegQueryValueExW (Address: 0x10009104)
  • RegSetValueExW (Address: 0x100090f4)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1000910c)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x10009118)
  • ReleaseSRWLockExclusive (Address: 0x10009114)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x10009120)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x10009128)
  • GetSystemTime (Address: 0x1000912c)
  • GetSystemTimeAsFileTime (Address: 0x10009134)
  • GetTickCount (Address: 0x10009130)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x1000913c)
  • SystemTimeToFileTime (Address: 0x10009140)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x10009150)
  • EventRegister (Address: 0x10009148)
  • EventSetInformation (Address: 0x10009154)
  • EventUnregister (Address: 0x10009158)
  • EventWriteTransfer (Address: 0x1000914c)
api-ms-win-security-base-l1-1-0.dll
  • DuplicateToken (Address: 0x10009164)
  • GetLengthSid (Address: 0x10009160)
  • GetTokenInformation (Address: 0x1000916c)
  • IsValidSid (Address: 0x10009168)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x10009174)
bcrypt.dll
  • BCryptDestroyKey (Address: 0x10009180)
  • BCryptGetProperty (Address: 0x1000917c)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x10009038)
  • CertCloseStore (Address: 0x10009044)
  • CertCompareCertificateName (Address: 0x1000901c)
  • CertCreateCertificateContext (Address: 0x10009010)
  • CertCreateSelfSignCertificate (Address: 0x1000900c)
  • CertDeleteCertificateFromStore (Address: 0x10009004)
  • CertFindCertificateInStore (Address: 0x10009048)
  • CertFindExtension (Address: 0x10009000)
  • CertFreeCertificateContext (Address: 0x10009034)
  • CertGetCertificateContextProperty (Address: 0x1000904c)
  • CertGetEnhancedKeyUsage (Address: 0x10009028)
  • CertGetIntendedKeyUsage (Address: 0x10009018)
  • CertGetNameStringW (Address: 0x10009030)
  • CertOpenStore (Address: 0x1000903c)
  • CertSetCertificateContextProperty (Address: 0x10009008)
  • CertStrToNameW (Address: 0x1000902c)
  • CertVerifyTimeValidity (Address: 0x10009014)
  • CryptAcquireCertificatePrivateKey (Address: 0x10009050)
  • CryptDecodeObject (Address: 0x10009024)
  • CryptEncodeObject (Address: 0x10009040)
  • CryptImportPublicKeyInfoEx2 (Address: 0x10009020)
DSROLE.dll
  • DsRoleFreeMemory (Address: 0x1000905c)
  • DsRoleGetPrimaryDomainInformation (Address: 0x10009058)
msvcrt.dll
  • _amsg_exit (Address: 0x100091a0)
  • _except_handler4_common (Address: 0x10009188)
  • _initterm (Address: 0x100091a8)
  • _XcptFilter (Address: 0x100091a4)
  • free (Address: 0x1000919c)
  • malloc (Address: 0x10009194)
  • memcmp (Address: 0x10009198)
  • memcpy (Address: 0x10009190)
  • memmove (Address: 0x1000918c)
  • memset (Address: 0x100091b0)
  • toupper (Address: 0x100091ac)
ncrypt.dll
  • NCryptCreatePersistedKey (Address: 0x100091cc)
  • NCryptDeleteKey (Address: 0x100091c4)
  • NCryptFinalizeKey (Address: 0x100091c8)
  • NCryptFreeObject (Address: 0x100091bc)
  • NCryptGetProperty (Address: 0x100091c0)
  • NCryptOpenStorageProvider (Address: 0x100091b8)
  • NCryptSetProperty (Address: 0x100091d0)
ntdll.dll
  • EtwEventEnabled (Address: 0x100091dc)
  • EtwEventWrite (Address: 0x100091e0)
  • RtlImageNtHeader (Address: 0x100091e4)
  • RtlInitUnicodeString (Address: 0x100091d8)
  • RtlNtStatusToDosError (Address: 0x100091e8)
  • RtlUnicodeStringToAnsiString (Address: 0x100091ec)