EsdSip.dll

Description: Crypto SIP provider for signing and verifying .esd Electronic Software Distribution files

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: 08b6b2990071fc0b1d50c1430beb5387

File Size: 17.5 KB

Uploaded At: Dec. 1, 2025, 7:56 a.m.

Views: 4

Exported Functions

  • EsdSipCreateHash (Ordinal: 1, Address: 0x1fb0)
  • EsdSipDelSignature (Ordinal: 2, Address: 0x1e70)
  • EsdSipGetCaps (Ordinal: 3, Address: 0x17e0)
  • EsdSipGetSignature (Ordinal: 4, Address: 0x1ba0)
  • EsdSipIsMyFileType (Ordinal: 5, Address: 0x1840)
  • EsdSipPutSignature (Ordinal: 6, Address: 0x1d00)
  • EsdSipVerifyHash (Ordinal: 7, Address: 0x2380)
  • DllCanUnloadNow (Ordinal: 8, Address: 0x16d0)
  • DllMain (Ordinal: 9, Address: 0x16b0)
  • DllRegisterServer (Ordinal: 10, Address: 0x16e0)
  • DllUnregisterServer (Ordinal: 11, Address: 0x1820)

Imported DLLs & Functions

ADVAPI32.dll
  • CryptAcquireContextW (Address: 0x10005004)
  • CryptCreateHash (Address: 0x10005014)
  • CryptDestroyHash (Address: 0x1000500c)
  • CryptGetHashParam (Address: 0x10005008)
  • CryptHashData (Address: 0x10005010)
  • CryptReleaseContext (Address: 0x10005000)
CRYPT32.dll
  • CryptDecodeObject (Address: 0x1000502c)
  • CryptEncodeObject (Address: 0x10005020)
  • CryptFindOIDInfo (Address: 0x10005028)
  • CryptSIPAddProvider (Address: 0x10005024)
  • CryptSIPRemoveProvider (Address: 0x1000501c)
KERNEL32.dll
  • CloseHandle (Address: 0x10005070)
  • CreateFileW (Address: 0x1000506c)
  • DisableThreadLibraryCalls (Address: 0x10005048)
  • GetCurrentProcess (Address: 0x10005094)
  • GetCurrentProcessId (Address: 0x10005080)
  • GetCurrentThreadId (Address: 0x10005084)
  • GetFileAttributesW (Address: 0x100050a0)
  • GetFileSizeEx (Address: 0x10005058)
  • GetFullPathNameW (Address: 0x100050ac)
  • GetLastError (Address: 0x10005044)
  • GetModuleFileNameW (Address: 0x1000503c)
  • GetModuleHandleW (Address: 0x10005050)
  • GetProcessHeap (Address: 0x100050a8)
  • GetSystemTimeAsFileTime (Address: 0x10005088)
  • GetTickCount (Address: 0x1000508c)
  • HeapAlloc (Address: 0x100050a4)
  • HeapFree (Address: 0x1000509c)
  • LocalAlloc (Address: 0x10005040)
  • LocalFree (Address: 0x1000504c)
  • QueryPerformanceCounter (Address: 0x1000507c)
  • ReadFile (Address: 0x10005054)
  • SetEndOfFile (Address: 0x10005068)
  • SetFilePointerEx (Address: 0x10005074)
  • SetLastError (Address: 0x10005038)
  • SetUnhandledExceptionFilter (Address: 0x10005090)
  • Sleep (Address: 0x10005078)
  • TerminateProcess (Address: 0x10005098)
  • UnhandledExceptionFilter (Address: 0x10005034)
  • VirtualAlloc (Address: 0x10005064)
  • VirtualFree (Address: 0x1000505c)
  • WriteFile (Address: 0x10005060)
msvcrt.dll
  • _amsg_exit (Address: 0x100050c4)
  • _except_handler4_common (Address: 0x100050b4)
  • _initterm (Address: 0x100050b8)
  • _wcsicmp (Address: 0x100050e0)
  • _wcsnicmp (Address: 0x100050d4)
  • _XcptFilter (Address: 0x100050c8)
  • free (Address: 0x100050c0)
  • malloc (Address: 0x100050bc)
  • memcmp (Address: 0x100050d0)
  • memcpy (Address: 0x100050dc)
  • memset (Address: 0x100050e4)
  • wcschr (Address: 0x100050d8)
  • wcsrchr (Address: 0x100050cc)
ntdll.dll
  • RtlAllocateHeap (Address: 0x100050f0)
  • RtlFreeHeap (Address: 0x100050ec)