efswrt.dll
Description: Storage Protection Windows Runtime DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5848
Architecture: 32-bit
Operating System: Windows NT
SHA256: 61fa70d82ac4a49070bd5f12546596c4
File Size: 604.0 KB
Uploaded At: Dec. 1, 2025, 7:56 a.m.
Views: 5
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- CdplGetFileProtectionLevel (Ordinal: 1, Address: 0x34300)
- CdplIsAppAllowedToRun (Ordinal: 2, Address: 0x345e0)
- CdplIsAppDataProtectionSupported (Ordinal: 3, Address: 0x2b460)
- CdplIsSupported (Ordinal: 4, Address: 0x34c90)
- CdplProtectFileToLevel (Ordinal: 5, Address: 0x34210)
- CdplProtectFileToLevelWithResult (Ordinal: 6, Address: 0x340f0)
- CdplProtectKnownUserFolders (Ordinal: 7, Address: 0x34350)
- CdplProtectSecretToLevel (Ordinal: 8, Address: 0x34550)
- CdplUnprotectSecret (Ordinal: 9, Address: 0x345c0)
- DllCanUnloadNow (Ordinal: 10, Address: 0x24940)
- DllGetActivationFactory (Ordinal: 11, Address: 0x24980)
- DllGetClassObject (Ordinal: 12, Address: 0x249a0)
- DpmBufferFree (Ordinal: 13, Address: 0x2b350)
- DpmProtectSecretToIdentity (Ordinal: 14, Address: 0x2b130)
- DpmStreamClose (Ordinal: 15, Address: 0x2b340)
- DpmStreamOpenToProtectToIdentity (Ordinal: 16, Address: 0x2b260)
- DpmStreamOpenToUnprotect (Ordinal: 17, Address: 0x2b300)
- DpmStreamUpdate (Ordinal: 18, Address: 0x2b320)
- DpmUnprotectSecret (Ordinal: 19, Address: 0x2b200)
- EnterpriseDataCopyProtection (Ordinal: 20, Address: 0x2a020)
- EnterpriseDataGetStatus (Ordinal: 21, Address: 0x2a6a0)
- EnterpriseDataProtect (Ordinal: 22, Address: 0x29be0)
- EnterpriseDataRevoke (Ordinal: 23, Address: 0x2a2e0)
- FreeIdentityProtectorList (Ordinal: 24, Address: 0x2b110)
- GetEnterpriseActionForCopy (Ordinal: 25, Address: 0x2ab30)
- GetEnterpriseIdForNetworkPath (Ordinal: 26, Address: 0x2a910)
- ProtectFileToEnterpriseIdentity (Ordinal: 27, Address: 0x2b360)
- ProtectFileToIdentity (Ordinal: 28, Address: 0x29f20)
- ProtectOrReprotectFileToIdentity (Ordinal: 29, Address: 0x2b3b0)
- QueryIdentityProtectors (Ordinal: 30, Address: 0x2afa0)
- UnprotectFile (Ordinal: 31, Address: 0x2b380)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-internal-l1-1-3.dll
- CouldMultiUserAppsBehaviorBePossibleForPackage (Address: 0x10089070)
api-ms-win-appmodel-runtime-l1-1-0.dll
- GetPackageFamilyName (Address: 0x10089080)
- GetPackageFullName (Address: 0x1008907c)
- GetPackagesByPackageFamily (Address: 0x10089088)
- PackageFamilyNameFromFullName (Address: 0x10089078)
- PackageNameAndPublisherIdFromFamilyName (Address: 0x10089084)
api-ms-win-appmodel-runtime-l1-1-1.dll
- GetPackageFullNameFromToken (Address: 0x10089090)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x10089098)
api-ms-win-core-com-l1-1-0.dll
- CoCreateFreeThreadedMarshaler (Address: 0x100890a8)
- CoCreateInstance (Address: 0x100890a4)
- CoDecrementMTAUsage (Address: 0x100890d0)
- CoGetApartmentType (Address: 0x100890a0)
- CoGetCallContext (Address: 0x100890b4)
- CoGetCallerTID (Address: 0x100890cc)
- CoGetInterfaceAndReleaseStream (Address: 0x100890d8)
- CoGetMalloc (Address: 0x100890c8)
- CoIncrementMTAUsage (Address: 0x100890c4)
- CoMarshalInterface (Address: 0x100890b0)
- CoMarshalInterThreadInterfaceInStream (Address: 0x100890c0)
- CoReleaseMarshalData (Address: 0x100890b8)
- CoTaskMemAlloc (Address: 0x100890d4)
- CoTaskMemFree (Address: 0x100890dc)
- CoTaskMemRealloc (Address: 0x100890e0)
- CoWaitForMultipleHandles (Address: 0x100890ac)
- CreateStreamOnHGlobal (Address: 0x100890bc)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x100890e8)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
- CStdStubBuffer2_Connect (Address: 0x10089148)
- CStdStubBuffer2_CountRefs (Address: 0x10089138)
- CStdStubBuffer2_Disconnect (Address: 0x10089124)
- CStdStubBuffer2_QueryInterface (Address: 0x10089118)
- NdrProxyForwardingFunction3 (Address: 0x100890f0)
- NdrProxyForwardingFunction4 (Address: 0x10089110)
- NdrProxyForwardingFunction5 (Address: 0x10089108)
- ObjectStublessClient10 (Address: 0x100890f8)
- ObjectStublessClient11 (Address: 0x1008913c)
- ObjectStublessClient12 (Address: 0x10089144)
- ObjectStublessClient13 (Address: 0x1008911c)
- ObjectStublessClient14 (Address: 0x10089140)
- ObjectStublessClient15 (Address: 0x10089128)
- ObjectStublessClient16 (Address: 0x100890f4)
- ObjectStublessClient17 (Address: 0x100890fc)
- ObjectStublessClient18 (Address: 0x10089130)
- ObjectStublessClient19 (Address: 0x10089114)
- ObjectStublessClient20 (Address: 0x1008912c)
- ObjectStublessClient3 (Address: 0x10089134)
- ObjectStublessClient6 (Address: 0x1008910c)
- ObjectStublessClient7 (Address: 0x10089120)
- ObjectStublessClient8 (Address: 0x10089104)
- ObjectStublessClient9 (Address: 0x10089100)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x10089158)
- IsDebuggerPresent (Address: 0x10089154)
- OutputDebugStringW (Address: 0x10089150)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x10089160)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x10089168)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x10089174)
- RaiseException (Address: 0x10089180)
- SetLastError (Address: 0x10089170)
- SetUnhandledExceptionFilter (Address: 0x1008917c)
- UnhandledExceptionFilter (Address: 0x10089178)
api-ms-win-core-file-l1-1-0.dll
- CreateFileW (Address: 0x100891a0)
- FindClose (Address: 0x10089190)
- FindFirstFileW (Address: 0x100891a4)
- FindNextFileW (Address: 0x1008918c)
- GetDriveTypeW (Address: 0x100891a8)
- GetFileAttributesW (Address: 0x1008919c)
- GetFullPathNameW (Address: 0x10089198)
- GetLongPathNameW (Address: 0x10089194)
- GetVolumePathNameW (Address: 0x10089188)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x100891b0)
- GetVolumeNameForVolumeMountPointW (Address: 0x100891b4)
api-ms-win-core-file-l2-1-0.dll
- GetFileInformationByHandleEx (Address: 0x100891bc)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x100891c4)
- DuplicateHandle (Address: 0x100891c8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x100891d0)
- HeapAlloc (Address: 0x100891d8)
- HeapFree (Address: 0x100891d4)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x100891e4)
- LocalFree (Address: 0x100891e0)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x100891f0)
- FindStringOrdinal (Address: 0x100891fc)
- FreeLibrary (Address: 0x100891f8)
- GetModuleFileNameA (Address: 0x10089208)
- GetModuleFileNameW (Address: 0x1008920c)
- GetModuleHandleExW (Address: 0x100891ec)
- GetModuleHandleW (Address: 0x10089204)
- GetProcAddress (Address: 0x100891f4)
- LoadLibraryExW (Address: 0x10089200)
- LoadStringW (Address: 0x10089210)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1008921c)
- IdnToAscii (Address: 0x10089218)
api-ms-win-core-marshal-l1-1-0.dll
- HWND_UserFree (Address: 0x10089224)
- HWND_UserMarshal (Address: 0x10089230)
- HWND_UserSize (Address: 0x1008922c)
- HWND_UserUnmarshal (Address: 0x10089228)
api-ms-win-core-path-l1-1-0.dll
- PathCchRemoveFileSpec (Address: 0x10089240)
- PathCchSkipRoot (Address: 0x1008923c)
- PathIsUNCEx (Address: 0x10089238)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x10089248)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x10089258)
- GetCurrentProcessId (Address: 0x10089264)
- GetCurrentThread (Address: 0x1008926c)
- GetCurrentThreadId (Address: 0x10089250)
- GetProcessId (Address: 0x1008925c)
- OpenProcessToken (Address: 0x10089260)
- OpenThreadToken (Address: 0x10089268)
- TerminateProcess (Address: 0x10089254)
api-ms-win-core-processthreads-l1-1-1.dll
- GetProcessMitigationPolicy (Address: 0x10089278)
- OpenProcess (Address: 0x10089274)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x10089280)
- QueryPerformanceFrequency (Address: 0x10089284)
api-ms-win-core-psapi-l1-1-0.dll
- QueryFullProcessImageNameW (Address: 0x1008928c)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x100892ac)
- RegCreateKeyExW (Address: 0x100892a4)
- RegGetValueW (Address: 0x1008929c)
- RegNotifyChangeKeyValue (Address: 0x100892a0)
- RegOpenCurrentUser (Address: 0x100892a8)
- RegOpenKeyExW (Address: 0x10089298)
- RegQueryValueExW (Address: 0x10089294)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFindExtensionW (Address: 0x100892b4)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- StrStrIW (Address: 0x100892bc)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x100892c4)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x100892dc)
- AcquireSRWLockShared (Address: 0x10089304)
- CreateEventExW (Address: 0x10089318)
- CreateMutexExW (Address: 0x10089300)
- CreateMutexW (Address: 0x100892e4)
- CreateSemaphoreExW (Address: 0x100892e0)
- DeleteCriticalSection (Address: 0x10089320)
- EnterCriticalSection (Address: 0x10089308)
- InitializeCriticalSection (Address: 0x100892ec)
- InitializeCriticalSectionEx (Address: 0x1008931c)
- InitializeSRWLock (Address: 0x1008930c)
- LeaveCriticalSection (Address: 0x10089314)
- OpenSemaphoreW (Address: 0x10089310)
- ReleaseMutex (Address: 0x100892d4)
- ReleaseSemaphore (Address: 0x100892cc)
- ReleaseSRWLockExclusive (Address: 0x100892d8)
- ReleaseSRWLockShared (Address: 0x100892fc)
- SetEvent (Address: 0x100892f8)
- TryAcquireSRWLockExclusive (Address: 0x100892e8)
- TryAcquireSRWLockShared (Address: 0x10089324)
- TryEnterCriticalSection (Address: 0x10089328)
- WaitForMultipleObjectsEx (Address: 0x100892f0)
- WaitForSingleObject (Address: 0x100892d0)
- WaitForSingleObjectEx (Address: 0x100892f4)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x10089330)
- InitOnceComplete (Address: 0x1008934c)
- InitOnceExecuteOnce (Address: 0x10089340)
- Sleep (Address: 0x10089338)
- SleepConditionVariableSRW (Address: 0x1008933c)
- WaitOnAddress (Address: 0x10089334)
- WakeAllConditionVariable (Address: 0x10089344)
- WakeByAddressAll (Address: 0x10089348)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x10089358)
- GetTickCount (Address: 0x10089354)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1008938c)
- CloseThreadpoolWait (Address: 0x10089384)
- CloseThreadpoolWork (Address: 0x10089374)
- CreateThreadpoolTimer (Address: 0x1008937c)
- CreateThreadpoolWait (Address: 0x10089368)
- CreateThreadpoolWork (Address: 0x10089364)
- FreeLibraryWhenCallbackReturns (Address: 0x10089378)
- SetThreadpoolTimer (Address: 0x10089388)
- SetThreadpoolWait (Address: 0x1008936c)
- SubmitThreadpoolWork (Address: 0x10089380)
- WaitForThreadpoolTimerCallbacks (Address: 0x10089370)
- WaitForThreadpoolWaitCallbacks (Address: 0x10089360)
api-ms-win-core-url-l1-1-0.dll
- UrlGetPartW (Address: 0x10089394)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1008939c)
- EncodePointer (Address: 0x100893a0)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x100893b8)
- RoOriginateError (Address: 0x100893a8)
- RoOriginateErrorW (Address: 0x100893b4)
- RoTransformError (Address: 0x100893b0)
- SetRestrictedErrorInfo (Address: 0x100893ac)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x100893c4)
- RoGetMatchingRestrictedErrorInfo (Address: 0x100893c8)
- RoReportFailedDelegate (Address: 0x100893c0)
api-ms-win-core-winrt-l1-1-0.dll
- RoGetActivationFactory (Address: 0x100893d0)
api-ms-win-core-winrt-robuffer-l1-1-0.dll
- RoGetBufferMarshaler (Address: 0x100893d8)
api-ms-win-core-winrt-string-l1-1-0.dll
- HSTRING_UserFree (Address: 0x100893e8)
- HSTRING_UserMarshal (Address: 0x10089408)
- HSTRING_UserSize (Address: 0x1008940c)
- HSTRING_UserUnmarshal (Address: 0x100893fc)
- WindowsCreateString (Address: 0x100893ec)
- WindowsCreateStringReference (Address: 0x100893e4)
- WindowsDeleteString (Address: 0x100893f8)
- WindowsDuplicateString (Address: 0x10089400)
- WindowsGetStringLen (Address: 0x10089404)
- WindowsGetStringRawBuffer (Address: 0x100893e0)
- WindowsIsStringEmpty (Address: 0x100893f0)
- WindowsStringHasEmbeddedNull (Address: 0x100893f4)
api-ms-win-eventing-classicprovider-l1-1-0.dll
- GetTraceEnableFlags (Address: 0x10089428)
- GetTraceEnableLevel (Address: 0x10089424)
- GetTraceLoggerHandle (Address: 0x1008941c)
- RegisterTraceGuidsW (Address: 0x10089420)
- TraceMessage (Address: 0x10089418)
- UnregisterTraceGuids (Address: 0x10089414)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1008943c)
- EventProviderEnabled (Address: 0x10089430)
- EventRegister (Address: 0x10089444)
- EventSetInformation (Address: 0x10089434)
- EventUnregister (Address: 0x10089438)
- EventWriteTransfer (Address: 0x10089440)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x10089454)
- EqualSid (Address: 0x10089464)
- GetAce (Address: 0x1008946c)
- GetLengthSid (Address: 0x1008944c)
- GetSidSubAuthority (Address: 0x10089450)
- GetSidSubAuthorityCount (Address: 0x10089458)
- GetTokenInformation (Address: 0x1008945c)
- ImpersonateLoggedOnUser (Address: 0x10089468)
- RevertToSelf (Address: 0x10089460)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x10089474)
- ConvertStringSidToSidW (Address: 0x10089478)
api-ms-win-service-private-l1-1-0.dll
- I_QueryTagInformation (Address: 0x10089480)
combase.dll
- (Address: 0x10089490)
- (Address: 0x10089488)
- (Address: 0x1008948c)
MPR.dll
- WNetGetUniversalNameW (Address: 0x10089000)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x1008954c)
- __dllonexit (Address: 0x100894f4)
- _amsg_exit (Address: 0x100894bc)
- _callnewh (Address: 0x100894b8)
- _CxxThrowException (Address: 0x100894a8)
- _except_handler4_common (Address: 0x10089540)
- _initterm (Address: 0x100894c4)
- _lock (Address: 0x100894ec)
- _onexit (Address: 0x10089500)
- _purecall (Address: 0x100894d8)
- _ui64tow_s (Address: 0x100894d4)
- _unlock (Address: 0x100894f0)
- _vsnprintf_s (Address: 0x100894e8)
- _vsnwprintf (Address: 0x10089548)
- _wcsicmp (Address: 0x100894e4)
- _wcsnicmp (Address: 0x10089524)
- _XcptFilter (Address: 0x10089498)
- ??_V@YAXPAX@Z (Address: 0x10089510)
- ??0exception@@QAE@ABQBD@Z (Address: 0x100894b4)
- ??0exception@@QAE@ABQBDH@Z (Address: 0x100894b0)
- ??0exception@@QAE@ABV0@@Z (Address: 0x100894f8)
- ??0exception@@QAE@XZ (Address: 0x100894fc)
- ??1exception@@UAE@XZ (Address: 0x10089504)
- ??1type_info@@UAE@XZ (Address: 0x10089508)
- ??3@YAXPAX@Z (Address: 0x1008950c)
- ?terminate@@YAXXZ (Address: 0x100894dc)
- ?what@exception@@UBEPBDXZ (Address: 0x100894ac)
- free (Address: 0x100894c0)
- iswalpha (Address: 0x10089520)
- malloc (Address: 0x100894c8)
- memcmp (Address: 0x100894a4)
- memcpy (Address: 0x100894a0)
- memcpy_s (Address: 0x10089544)
- memmove (Address: 0x1008949c)
- memmove_s (Address: 0x100894cc)
- memset (Address: 0x10089550)
- qsort (Address: 0x100894e0)
- realloc (Address: 0x10089514)
- toupper (Address: 0x1008953c)
- wcschr (Address: 0x10089534)
- wcscpy_s (Address: 0x1008951c)
- wcsncmp (Address: 0x10089528)
- wcsnlen (Address: 0x10089530)
- wcsrchr (Address: 0x100894d0)
- wcsstr (Address: 0x1008952c)
- wcstok_s (Address: 0x10089518)
- wcstoul (Address: 0x10089538)
ntdll.dll
- NtClose (Address: 0x10089564)
- NtDeviceIoControlFile (Address: 0x10089568)
- NtDuplicateObject (Address: 0x10089560)
- NtDuplicateToken (Address: 0x10089570)
- NtFsControlFile (Address: 0x1008959c)
- NtOpenFile (Address: 0x10089558)
- NtOpenProcessToken (Address: 0x10089574)
- NtOpenThreadToken (Address: 0x1008955c)
- NtQuerySecurityAttributesToken (Address: 0x1008957c)
- NtQuerySecurityObject (Address: 0x100895a4)
- NtQueryWnfStateData (Address: 0x100895d8)
- NtSetInformationThread (Address: 0x1008956c)
- NtSetSecurityObject (Address: 0x100895bc)
- RtlAddAccessAllowedAce (Address: 0x100895b0)
- RtlAddAce (Address: 0x100895b8)
- RtlAllocateHeap (Address: 0x10089588)
- RtlCompareMemory (Address: 0x10089578)
- RtlCompareUnicodeString (Address: 0x1008958c)
- RtlConvertSidToUnicodeString (Address: 0x100895e4)
- RtlCopyUnicodeString (Address: 0x10089584)
- RtlCreateAcl (Address: 0x100895ac)
- RtlCreateSecurityDescriptor (Address: 0x100895fc)
- RtlFreeHeap (Address: 0x10089580)
- RtlFreeUnicodeString (Address: 0x100895f8)
- RtlGetAce (Address: 0x100895c4)
- RtlGetDaclSecurityDescriptor (Address: 0x100895a0)
- RtlInitUnicodeString (Address: 0x100895cc)
- RtlIsMultiSessionSku (Address: 0x10089598)
- RtlLengthSid (Address: 0x100895b4)
- RtlNtStatusToDosError (Address: 0x10089594)
- RtlPublishWnfStateData (Address: 0x100895d0)
- RtlQueryInformationAcl (Address: 0x100895c0)
- RtlQueryPackageClaims (Address: 0x10089590)
- RtlSetDaclSecurityDescriptor (Address: 0x100895c8)
- RtlSubscribeWnfStateChangeNotification (Address: 0x100895dc)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x100895d4)
- ZwClose (Address: 0x100895ec)
- ZwOpenProcessTokenEx (Address: 0x100895f0)
- ZwOpenThreadTokenEx (Address: 0x100895e8)
- ZwQueryInformationProcess (Address: 0x100895f4)
- ZwQueryInformationToken (Address: 0x100895e0)
- ZwQueryWnfStateData (Address: 0x100895a8)
OLEAUT32.dll
- SysFreeString (Address: 0x10089008)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x10089044)
- CStdStubBuffer_Connect (Address: 0x10089058)
- CStdStubBuffer_CountRefs (Address: 0x1008905c)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x10089048)
- CStdStubBuffer_DebugServerRelease (Address: 0x10089060)
- CStdStubBuffer_Disconnect (Address: 0x10089064)
- CStdStubBuffer_Invoke (Address: 0x1008902c)
- CStdStubBuffer_IsIIDSupported (Address: 0x10089054)
- CStdStubBuffer_QueryInterface (Address: 0x10089028)
- I_RpcBindingInqLocalClientPID (Address: 0x1008904c)
- IUnknown_AddRef_Proxy (Address: 0x1008903c)
- IUnknown_QueryInterface_Proxy (Address: 0x10089068)
- IUnknown_Release_Proxy (Address: 0x10089034)
- NdrCStdStubBuffer_Release (Address: 0x10089018)
- NdrCStdStubBuffer2_Release (Address: 0x10089024)
- NdrDllCanUnloadNow (Address: 0x10089010)
- NdrDllGetClassObject (Address: 0x1008901c)
- NdrOleAllocate (Address: 0x10089040)
- NdrOleFree (Address: 0x10089050)
- NdrStubCall2 (Address: 0x10089038)
- NdrStubForwardingFunction (Address: 0x10089030)
- UuidCreateNil (Address: 0x10089020)
- UuidFromStringW (Address: 0x10089014)