feclient.dll

Description: Windows NT File Encryption Client Interfaces

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6328

Architecture: 32-bit

Operating System: Windows NT

SHA256: f5e6263c82712c8cb2e9af3b6cc81302

File Size: 191.5 KB

Uploaded At: Dec. 1, 2025, 7:56 a.m.

Views: 8

Exported Functions

  • EfsUtilGetCurrentKey (Ordinal: 1, Address: 0x2b0d6)
  • DpQueryUserProtectorDescriptor (Ordinal: 2, Address: 0x16cd0)
  • DpQueryUserProtectorDescriptorInfo (Ordinal: 3, Address: 0x16db0)
  • EdpAllowFileAccessForProcess (Ordinal: 4, Address: 0x167d0)
  • EdpContainerizeFile (Ordinal: 5, Address: 0x167a0)
  • EdpCredentialCreate (Ordinal: 6, Address: 0x15c90)
  • EdpCredentialDelete (Ordinal: 7, Address: 0x15fc0)
  • EdpCredentialExists (Ordinal: 8, Address: 0x15ed0)
  • EdpCredentialQuery (Ordinal: 9, Address: 0x15db0)
  • EdpDecontainerizeFile (Ordinal: 10, Address: 0x167c0)
  • EdpDplPolicyEnabledForUser (Ordinal: 11, Address: 0x16320)
  • EdpDplStartCredServiceIfDplEnabledForUser (Ordinal: 12, Address: 0x16340)
  • EdpDplUpgradePinInfo (Ordinal: 13, Address: 0x162d0)
  • EdpDplUpgradeVerifyUser (Ordinal: 14, Address: 0x162e0)
  • EdpDplUserCredentialsSet (Ordinal: 15, Address: 0x162f0)
  • EdpDplUserUnlockComplete (Ordinal: 16, Address: 0x16310)
  • EdpDplUserUnlockStart (Ordinal: 17, Address: 0x16300)
  • EdpFree (Ordinal: 18, Address: 0x15ff0)
  • EdpGetContainerIdentity (Ordinal: 19, Address: 0x167b0)
  • EdpGetCredServiceState (Ordinal: 20, Address: 0x162c0)
  • EdpIsConsumerDataProtectionEnforced (Ordinal: 21, Address: 0x168c0)
  • EdpIsConsumerDataProtectionSupported (Ordinal: 22, Address: 0x168a0)
  • EdpPurgeAppLearningEvents (Ordinal: 23, Address: 0x167f0)
  • EdpQueryCredServiceInfo (Ordinal: 24, Address: 0x16380)
  • EdpQueryDplEnforcedPolicyOwnerIds (Ordinal: 25, Address: 0x15fe0)
  • EdpQueryRevokedPolicyOwnerIds (Ordinal: 26, Address: 0x15fd0)
  • EdpRmsClearKeys (Ordinal: 27, Address: 0x16790)
  • EdpSetCredServiceInfo (Ordinal: 28, Address: 0x16580)
  • EdpUnprotectFile (Ordinal: 29, Address: 0x167e0)
  • EdpWriteLogSiteLearningEvents (Ordinal: 30, Address: 0x16800)
  • EfsClientCloseFileRaw (Ordinal: 31, Address: 0x151b0)
  • EfsClientCopyFileRaw (Ordinal: 32, Address: 0x16810)
  • EfsClientDecryptFile (Ordinal: 33, Address: 0x14f30)
  • EfsClientDuplicateEncryptionInfo (Ordinal: 34, Address: 0x15600)
  • EfsClientEncryptFileEx (Ordinal: 35, Address: 0x14e70)
  • EfsClientFileEncryptionStatus (Ordinal: 36, Address: 0x14fc0)
  • EfsClientFreeKeyInfo (Ordinal: 37, Address: 0x15840)
  • EfsClientFreeProtectorList (Ordinal: 38, Address: 0x15570)
  • EfsClientGetEncryptedFileVersion (Ordinal: 39, Address: 0x15880)
  • EfsClientGetKeyInfo (Ordinal: 40, Address: 0x157b0)
  • EfsClientOpenFileRaw (Ordinal: 41, Address: 0x15020)
  • EfsClientQueryProtectors (Ordinal: 42, Address: 0x15450)
  • EfsClientReadFileRaw (Ordinal: 43, Address: 0x15100)
  • EfsClientWriteFileRaw (Ordinal: 44, Address: 0x15130)
  • EfsClientWriteFileWithHeaderRaw (Ordinal: 45, Address: 0x15170)
  • EfsReprotectFile (Ordinal: 46, Address: 0x16840)
  • EfsValidateTokenForConsumer (Ordinal: 47, Address: 0x16a60)
  • EfsValidateUserForConsumer (Ordinal: 48, Address: 0x16900)
  • FeClClearCaches (Ordinal: 49, Address: 0x16780)
  • FeClQueryInfo (Ordinal: 50, Address: 0x16720)
  • FeClientInitialize (Ordinal: 51, Address: 0x14de0)
  • GetLockSessionUnwrappedKey (Ordinal: 52, Address: 0x161d0)
  • GetLockSessionWrappedKey (Ordinal: 53, Address: 0x160e0)
  • OefsCheckSupport (Ordinal: 54, Address: 0x16830)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoTaskMemAlloc (Address: 0x5ad2d03c)
  • CoTaskMemFree (Address: 0x5ad2d040)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x5ad2d048)
  • IsDebuggerPresent (Address: 0x5ad2d050)
  • OutputDebugStringW (Address: 0x5ad2d04c)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x5ad2d058)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x5ad2d060)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x5ad2d074)
  • RaiseException (Address: 0x5ad2d068)
  • SetLastError (Address: 0x5ad2d070)
  • SetUnhandledExceptionFilter (Address: 0x5ad2d078)
  • UnhandledExceptionFilter (Address: 0x5ad2d06c)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x5ad2d098)
  • DeleteFileW (Address: 0x5ad2d08c)
  • GetDriveTypeW (Address: 0x5ad2d09c)
  • GetFileAttributesW (Address: 0x5ad2d080)
  • GetFinalPathNameByHandleW (Address: 0x5ad2d090)
  • GetVolumePathNameW (Address: 0x5ad2d094)
  • RemoveDirectoryW (Address: 0x5ad2d088)
  • SetFileAttributesW (Address: 0x5ad2d084)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x5ad2d0a4)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x5ad2d0b0)
  • HeapAlloc (Address: 0x5ad2d0ac)
  • HeapCreate (Address: 0x5ad2d0b8)
  • HeapDestroy (Address: 0x5ad2d0c0)
  • HeapFree (Address: 0x5ad2d0b4)
  • HeapSetInformation (Address: 0x5ad2d0bc)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x5ad2d0c8)
  • LocalFree (Address: 0x5ad2d0cc)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x5ad2d0d4)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x5ad2d0f4)
  • GetModuleFileNameA (Address: 0x5ad2d0e4)
  • GetModuleFileNameW (Address: 0x5ad2d0ec)
  • GetModuleHandleExW (Address: 0x5ad2d0dc)
  • GetModuleHandleW (Address: 0x5ad2d0e8)
  • GetProcAddress (Address: 0x5ad2d0f0)
  • LoadLibraryExW (Address: 0x5ad2d0e0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x5ad2d100)
  • IdnToAscii (Address: 0x5ad2d0fc)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x5ad2d108)
  • VirtualFree (Address: 0x5ad2d10c)
api-ms-win-core-memory-l1-1-1.dll
  • GetProcessWorkingSetSizeEx (Address: 0x5ad2d11c)
  • SetProcessWorkingSetSizeEx (Address: 0x5ad2d114)
  • VirtualLock (Address: 0x5ad2d120)
  • VirtualUnlock (Address: 0x5ad2d118)
api-ms-win-core-privateprofile-l1-1-0.dll
  • GetPrivateProfileStringW (Address: 0x5ad2d128)
  • WritePrivateProfileStringW (Address: 0x5ad2d12c)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x5ad2d134)
  • GetCurrentProcess (Address: 0x5ad2d150)
  • GetCurrentProcessId (Address: 0x5ad2d14c)
  • GetCurrentThread (Address: 0x5ad2d138)
  • GetCurrentThreadId (Address: 0x5ad2d13c)
  • OpenThreadToken (Address: 0x5ad2d148)
  • ProcessIdToSessionId (Address: 0x5ad2d140)
  • SetThreadToken (Address: 0x5ad2d144)
  • TerminateProcess (Address: 0x5ad2d154)
api-ms-win-core-processthreads-l1-1-1.dll
  • GetProcessMitigationPolicy (Address: 0x5ad2d15c)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x5ad2d164)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x5ad2d174)
  • RegGetValueW (Address: 0x5ad2d178)
  • RegOpenKeyExW (Address: 0x5ad2d16c)
  • RegQueryValueExW (Address: 0x5ad2d170)
api-ms-win-core-rtlsupport-l1-2-0.dll
  • RtlCompareMemory (Address: 0x5ad2d180)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x5ad2d188)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x5ad2d1cc)
  • AcquireSRWLockShared (Address: 0x5ad2d1e0)
  • CreateEventW (Address: 0x5ad2d1b8)
  • CreateMutexExW (Address: 0x5ad2d1d4)
  • CreateSemaphoreExW (Address: 0x5ad2d1d8)
  • DeleteCriticalSection (Address: 0x5ad2d1d0)
  • EnterCriticalSection (Address: 0x5ad2d1b0)
  • InitializeCriticalSection (Address: 0x5ad2d1dc)
  • InitializeCriticalSectionEx (Address: 0x5ad2d1c4)
  • InitializeSRWLock (Address: 0x5ad2d19c)
  • LeaveCriticalSection (Address: 0x5ad2d1ac)
  • OpenSemaphoreW (Address: 0x5ad2d1a4)
  • ReleaseMutex (Address: 0x5ad2d1bc)
  • ReleaseSemaphore (Address: 0x5ad2d1c0)
  • ReleaseSRWLockExclusive (Address: 0x5ad2d194)
  • ReleaseSRWLockShared (Address: 0x5ad2d1c8)
  • ResetEvent (Address: 0x5ad2d1a0)
  • SetEvent (Address: 0x5ad2d1b4)
  • SleepEx (Address: 0x5ad2d190)
  • WaitForSingleObject (Address: 0x5ad2d1a8)
  • WaitForSingleObjectEx (Address: 0x5ad2d198)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x5ad2d1ec)
  • InitOnceComplete (Address: 0x5ad2d1f0)
  • Sleep (Address: 0x5ad2d1e8)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x5ad2d1f8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x5ad2d204)
  • GetSystemInfo (Address: 0x5ad2d208)
  • GetSystemTimeAsFileTime (Address: 0x5ad2d20c)
  • GetSystemWindowsDirectoryW (Address: 0x5ad2d210)
  • GetTickCount (Address: 0x5ad2d200)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x5ad2d21c)
  • CreateThreadpoolTimer (Address: 0x5ad2d218)
  • SetThreadpoolTimer (Address: 0x5ad2d224)
  • WaitForThreadpoolTimerCallbacks (Address: 0x5ad2d220)
api-ms-win-core-winrt-l1-1-0.dll
  • RoGetActivationFactory (Address: 0x5ad2d22c)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x5ad2d234)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x5ad2d244)
  • EventRegister (Address: 0x5ad2d240)
  • EventSetInformation (Address: 0x5ad2d23c)
  • EventUnregister (Address: 0x5ad2d248)
  • EventWriteTransfer (Address: 0x5ad2d24c)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x5ad2d260)
  • GetTokenInformation (Address: 0x5ad2d258)
  • ImpersonateSelf (Address: 0x5ad2d25c)
  • RevertToSelf (Address: 0x5ad2d254)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x5ad2d26c)
  • ConvertStringSidToSidW (Address: 0x5ad2d268)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x5ad2d274)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x5ad2d280)
  • BCryptDecrypt (Address: 0x5ad2d284)
  • BCryptDestroyKey (Address: 0x5ad2d294)
  • BCryptEncrypt (Address: 0x5ad2d298)
  • BCryptGenerateSymmetricKey (Address: 0x5ad2d288)
  • BCryptGenRandom (Address: 0x5ad2d29c)
  • BCryptGetProperty (Address: 0x5ad2d27c)
  • BCryptOpenAlgorithmProvider (Address: 0x5ad2d290)
  • BCryptSetProperty (Address: 0x5ad2d28c)
iertutil.dll
  • CreateUri (Address: 0x5ad2d2a4)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x5ad2d314)
  • __dllonexit (Address: 0x5ad2d318)
  • _amsg_exit (Address: 0x5ad2d2c0)
  • _callnewh (Address: 0x5ad2d2dc)
  • _CxxThrowException (Address: 0x5ad2d2ec)
  • _except_handler4_common (Address: 0x5ad2d310)
  • _initterm (Address: 0x5ad2d2f8)
  • _lock (Address: 0x5ad2d304)
  • _onexit (Address: 0x5ad2d328)
  • _purecall (Address: 0x5ad2d2ac)
  • _unlock (Address: 0x5ad2d308)
  • _vsnprintf_s (Address: 0x5ad2d320)
  • _vsnwprintf (Address: 0x5ad2d330)
  • _wcsicmp (Address: 0x5ad2d2cc)
  • _wcsnicmp (Address: 0x5ad2d2b8)
  • _XcptFilter (Address: 0x5ad2d33c)
  • ??0exception@@QAE@ABQBD@Z (Address: 0x5ad2d2e0)
  • ??0exception@@QAE@ABQBDH@Z (Address: 0x5ad2d2e4)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x5ad2d2b4)
  • ??0exception@@QAE@XZ (Address: 0x5ad2d31c)
  • ??1exception@@UAE@XZ (Address: 0x5ad2d338)
  • ??1type_info@@UAE@XZ (Address: 0x5ad2d300)
  • ??3@YAXPAX@Z (Address: 0x5ad2d334)
  • ?terminate@@YAXXZ (Address: 0x5ad2d2fc)
  • ?what@exception@@UBEPBDXZ (Address: 0x5ad2d2e8)
  • free (Address: 0x5ad2d2bc)
  • malloc (Address: 0x5ad2d2c8)
  • memcmp (Address: 0x5ad2d30c)
  • memcpy (Address: 0x5ad2d2f0)
  • memcpy_s (Address: 0x5ad2d32c)
  • memmove (Address: 0x5ad2d2f4)
  • memmove_s (Address: 0x5ad2d2b0)
  • memset (Address: 0x5ad2d340)
  • toupper (Address: 0x5ad2d2d8)
  • wcschr (Address: 0x5ad2d2d4)
  • wcsncmp (Address: 0x5ad2d2c4)
  • wcsnlen (Address: 0x5ad2d2d0)
  • wcstoul (Address: 0x5ad2d324)
ntdll.dll
  • NtCreateFile (Address: 0x5ad2d380)
  • NtFsControlFile (Address: 0x5ad2d354)
  • NtQueryInformationFile (Address: 0x5ad2d384)
  • NtQuerySecurityAttributesToken (Address: 0x5ad2d38c)
  • NtQueryWnfStateData (Address: 0x5ad2d350)
  • RtlAllocateHeap (Address: 0x5ad2d370)
  • RtlCompareUnicodeString (Address: 0x5ad2d388)
  • RtlDosPathNameToNtPathName_U (Address: 0x5ad2d37c)
  • RtlFreeHeap (Address: 0x5ad2d374)
  • RtlGetFullPathName_U (Address: 0x5ad2d368)
  • RtlInitUnicodeString (Address: 0x5ad2d390)
  • RtlLengthSecurityDescriptor (Address: 0x5ad2d35c)
  • RtlMakeSelfRelativeSD (Address: 0x5ad2d358)
  • RtlNtStatusToDosError (Address: 0x5ad2d364)
  • RtlQueryPackageClaims (Address: 0x5ad2d378)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x5ad2d34c)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x5ad2d348)
  • RtlValidSecurityDescriptor (Address: 0x5ad2d360)
  • ZwQueryWnfStateData (Address: 0x5ad2d36c)
OLEAUT32.dll
  • SysFreeString (Address: 0x5ad2d000)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x5ad2d024)
  • NdrClientCall4 (Address: 0x5ad2d018)
  • RpcBindingBind (Address: 0x5ad2d030)
  • RpcBindingCreateW (Address: 0x5ad2d02c)
  • RpcBindingFree (Address: 0x5ad2d034)
  • RpcBindingFromStringBindingW (Address: 0x5ad2d008)
  • RpcBindingSetAuthInfoW (Address: 0x5ad2d028)
  • RpcBindingUnbind (Address: 0x5ad2d01c)
  • RpcExceptionFilter (Address: 0x5ad2d020)
  • RpcStringBindingComposeW (Address: 0x5ad2d00c)
  • RpcStringFreeW (Address: 0x5ad2d014)
  • UuidFromStringW (Address: 0x5ad2d010)