gpprefcl.dll

Description: Group Policy Preference Client

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 32-bit

Operating System: Windows NT

SHA256: b3c5e769724bd0108a3b6501bbd45f63

File Size: 602.0 KB

Uploaded At: Dec. 1, 2025, 7:56 a.m.

Views: 6

Exported Functions

  • ProcessGroupPolicyMitigationOptions (Ordinal: 1, Address: 0x54e10)
  • ProcessGroupPolicyProcessMitigationOptions (Ordinal: 2, Address: 0x550b0)
  • DllCanUnloadNow (Ordinal: 3, Address: 0x47080)
  • DllGetClassObject (Ordinal: 4, Address: 0x470a0)
  • DllRegisterServer (Ordinal: 5, Address: 0x470d0)
  • DllUnregisterServer (Ordinal: 6, Address: 0x470e0)
  • GenerateGroupPolicyApplications (Ordinal: 7, Address: 0x45410)
  • GenerateGroupPolicyDataSources (Ordinal: 8, Address: 0x45b90)
  • GenerateGroupPolicyDevices (Ordinal: 9, Address: 0x45d70)
  • GenerateGroupPolicyDrives (Ordinal: 10, Address: 0x44ab0)
  • GenerateGroupPolicyEnviron (Ordinal: 11, Address: 0x448d0)
  • GenerateGroupPolicyFiles (Ordinal: 12, Address: 0x44e70)
  • GenerateGroupPolicyFolderOptions (Ordinal: 13, Address: 0x45f50)
  • GenerateGroupPolicyFolders (Ordinal: 14, Address: 0x44c90)
  • GenerateGroupPolicyIniFile (Ordinal: 15, Address: 0x45050)
  • GenerateGroupPolicyInternet (Ordinal: 16, Address: 0x457d0)
  • GenerateGroupPolicyLocUsAndGroups (Ordinal: 17, Address: 0x46130)
  • GenerateGroupPolicyNetShares (Ordinal: 18, Address: 0x46e50)
  • GenerateGroupPolicyNetworkOptions (Ordinal: 19, Address: 0x46310)
  • GenerateGroupPolicyPowerOptions (Ordinal: 20, Address: 0x464f0)
  • GenerateGroupPolicyPrinters (Ordinal: 21, Address: 0x455f0)
  • GenerateGroupPolicyRegionOptions (Ordinal: 22, Address: 0x466d0)
  • GenerateGroupPolicyRegistry (Ordinal: 23, Address: 0x45230)
  • GenerateGroupPolicySchedTasks (Ordinal: 24, Address: 0x468b0)
  • GenerateGroupPolicyServices (Ordinal: 25, Address: 0x46a90)
  • GenerateGroupPolicyShortcuts (Ordinal: 26, Address: 0x459b0)
  • GenerateGroupPolicyStartMenu (Ordinal: 27, Address: 0x46c70)
  • ProcessGroupPolicyApplications (Ordinal: 28, Address: 0x454b0)
  • ProcessGroupPolicyDataSources (Ordinal: 29, Address: 0x45c30)
  • ProcessGroupPolicyDevices (Ordinal: 30, Address: 0x45e10)
  • ProcessGroupPolicyDrives (Ordinal: 31, Address: 0x44b50)
  • ProcessGroupPolicyEnviron (Ordinal: 32, Address: 0x44970)
  • ProcessGroupPolicyExApplications (Ordinal: 33, Address: 0x45550)
  • ProcessGroupPolicyExDataSources (Ordinal: 34, Address: 0x45cd0)
  • ProcessGroupPolicyExDevices (Ordinal: 35, Address: 0x45eb0)
  • ProcessGroupPolicyExDrives (Ordinal: 36, Address: 0x44bf0)
  • ProcessGroupPolicyExEnviron (Ordinal: 37, Address: 0x44a10)
  • ProcessGroupPolicyExFiles (Ordinal: 38, Address: 0x44fb0)
  • ProcessGroupPolicyExFolderOptions (Ordinal: 39, Address: 0x46090)
  • ProcessGroupPolicyExFolders (Ordinal: 40, Address: 0x44dd0)
  • ProcessGroupPolicyExIniFile (Ordinal: 41, Address: 0x45190)
  • ProcessGroupPolicyExInternet (Ordinal: 42, Address: 0x45910)
  • ProcessGroupPolicyExLocUsAndGroups (Ordinal: 43, Address: 0x46270)
  • ProcessGroupPolicyExNetShares (Ordinal: 44, Address: 0x46fa0)
  • ProcessGroupPolicyExNetworkOptions (Ordinal: 45, Address: 0x46450)
  • ProcessGroupPolicyExPowerOptions (Ordinal: 46, Address: 0x46630)
  • ProcessGroupPolicyExPrinters (Ordinal: 47, Address: 0x45730)
  • ProcessGroupPolicyExRegionOptions (Ordinal: 48, Address: 0x46810)
  • ProcessGroupPolicyExRegistry (Ordinal: 49, Address: 0x45370)
  • ProcessGroupPolicyExSchedTasks (Ordinal: 50, Address: 0x469f0)
  • ProcessGroupPolicyExServices (Ordinal: 51, Address: 0x46bd0)
  • ProcessGroupPolicyExShortcuts (Ordinal: 52, Address: 0x45af0)
  • ProcessGroupPolicyExStartMenu (Ordinal: 53, Address: 0x46db0)
  • ProcessGroupPolicyFiles (Ordinal: 54, Address: 0x44f10)
  • ProcessGroupPolicyFolderOptions (Ordinal: 55, Address: 0x45ff0)
  • ProcessGroupPolicyFolders (Ordinal: 56, Address: 0x44d30)
  • ProcessGroupPolicyIniFile (Ordinal: 57, Address: 0x450f0)
  • ProcessGroupPolicyInternet (Ordinal: 58, Address: 0x45870)
  • ProcessGroupPolicyLocUsAndGroups (Ordinal: 59, Address: 0x461d0)
  • ProcessGroupPolicyNetShares (Ordinal: 60, Address: 0x46ef0)
  • ProcessGroupPolicyNetworkOptions (Ordinal: 61, Address: 0x463b0)
  • ProcessGroupPolicyPowerOptions (Ordinal: 62, Address: 0x46590)
  • ProcessGroupPolicyPrinters (Ordinal: 63, Address: 0x45690)
  • ProcessGroupPolicyRegionOptions (Ordinal: 64, Address: 0x46770)
  • ProcessGroupPolicyRegistry (Ordinal: 65, Address: 0x452d0)
  • ProcessGroupPolicySchedTasks (Ordinal: 66, Address: 0x46950)
  • ProcessGroupPolicyServices (Ordinal: 67, Address: 0x46b30)
  • ProcessGroupPolicyShortcuts (Ordinal: 68, Address: 0x45a50)
  • ProcessGroupPolicyStartMenu (Ordinal: 69, Address: 0x46d10)

Imported DLLs & Functions

ACTIVEDS.dll
  • (Address: 0x10087000)
  • (Address: 0x10087004)
  • (Address: 0x10087008)
  • (Address: 0x1008700c)
  • (Address: 0x10087010)
  • (Address: 0x10087014)
ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x10087088)
  • ChangeServiceConfig2W (Address: 0x1008701c)
  • ChangeServiceConfigW (Address: 0x1008702c)
  • CheckTokenMembership (Address: 0x100870a4)
  • CloseEventLog (Address: 0x10087074)
  • CloseServiceHandle (Address: 0x10087038)
  • ControlService (Address: 0x10087024)
  • CryptAcquireContextW (Address: 0x100870d4)
  • CryptCreateHash (Address: 0x10087050)
  • CryptDecrypt (Address: 0x1008704c)
  • CryptDeriveKey (Address: 0x10087054)
  • CryptDestroyHash (Address: 0x1008705c)
  • CryptDestroyKey (Address: 0x10087048)
  • CryptHashData (Address: 0x10087058)
  • CryptReleaseContext (Address: 0x10087060)
  • DuplicateToken (Address: 0x100870a8)
  • EqualSid (Address: 0x1008708c)
  • GetAce (Address: 0x1008709c)
  • GetNamedSecurityInfoW (Address: 0x100870c4)
  • GetSidIdentifierAuthority (Address: 0x10087068)
  • LockServiceDatabase (Address: 0x10087020)
  • LookupAccountNameW (Address: 0x10087070)
  • LookupAccountSidW (Address: 0x1008706c)
  • LookupPrivilegeValueW (Address: 0x10087084)
  • LsaAddAccountRights (Address: 0x100870cc)
  • LsaClose (Address: 0x100870ac)
  • LsaEnumerateAccountRights (Address: 0x100870d0)
  • LsaFreeMemory (Address: 0x100870b0)
  • LsaNtStatusToWinError (Address: 0x100870b8)
  • LsaOpenPolicy (Address: 0x100870bc)
  • LsaQueryInformationPolicy (Address: 0x100870b4)
  • OpenEventLogW (Address: 0x10087078)
  • OpenProcessToken (Address: 0x100870a0)
  • OpenSCManagerW (Address: 0x1008703c)
  • OpenServiceW (Address: 0x10087044)
  • OpenThreadToken (Address: 0x10087064)
  • QueryServiceConfig2W (Address: 0x10087030)
  • QueryServiceConfigW (Address: 0x10087028)
  • QueryServiceStatus (Address: 0x10087034)
  • RegDeleteKeyW (Address: 0x10087090)
  • RegDeleteValueW (Address: 0x10087080)
  • RegEnumKeyExW (Address: 0x10087094)
  • RegSetValueExW (Address: 0x10087098)
  • ReportEventW (Address: 0x1008707c)
  • SetNamedSecurityInfoW (Address: 0x100870c0)
  • StartServiceW (Address: 0x10087040)
  • UnlockServiceDatabase (Address: 0x100870c8)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x1008740c)
  • CoCreateInstance (Address: 0x10087418)
  • CoInitializeEx (Address: 0x10087410)
  • CoSetProxyBlanket (Address: 0x10087414)
  • CoTaskMemFree (Address: 0x10087408)
  • CoUninitialize (Address: 0x10087420)
  • StringFromGUID2 (Address: 0x1008741c)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x10087430)
  • IsDebuggerPresent (Address: 0x10087434)
  • OutputDebugStringA (Address: 0x10087428)
  • OutputDebugStringW (Address: 0x1008742c)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x10087440)
  • RaiseException (Address: 0x1008743c)
  • SetLastError (Address: 0x10087448)
  • SetUnhandledExceptionFilter (Address: 0x1008744c)
  • UnhandledExceptionFilter (Address: 0x10087444)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x10087458)
  • FindClose (Address: 0x10087470)
  • FindFirstFileW (Address: 0x10087474)
  • FindNextFileW (Address: 0x10087478)
  • GetDiskFreeSpaceExW (Address: 0x10087454)
  • GetDiskFreeSpaceW (Address: 0x1008746c)
  • GetFileAttributesW (Address: 0x10087468)
  • GetFileSize (Address: 0x1008745c)
  • ReadFile (Address: 0x10087464)
  • SetFileAttributesW (Address: 0x10087460)
api-ms-win-core-file-l2-1-0.dll
  • MoveFileExW (Address: 0x10087480)
api-ms-win-core-file-l2-1-2.dll
  • CopyFileW (Address: 0x10087488)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x10087490)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x10087498)
  • HeapAlloc (Address: 0x1008749c)
  • HeapFree (Address: 0x100874a0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x100874a8)
  • LocalFree (Address: 0x100874ac)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x100874c8)
  • FindResourceExW (Address: 0x100874cc)
  • FreeLibrary (Address: 0x100874dc)
  • GetModuleFileNameA (Address: 0x100874d8)
  • GetModuleFileNameW (Address: 0x100874d0)
  • GetModuleHandleExW (Address: 0x100874d4)
  • GetModuleHandleW (Address: 0x100874bc)
  • GetProcAddress (Address: 0x100874e0)
  • LoadLibraryExW (Address: 0x100874c0)
  • LoadResource (Address: 0x100874c4)
  • LockResource (Address: 0x100874b8)
  • SizeofResource (Address: 0x100874b4)
api-ms-win-core-localization-l1-2-0.dll
  • EnumSystemLocalesW (Address: 0x100874f0)
  • FormatMessageW (Address: 0x100874fc)
  • GetACP (Address: 0x100874f4)
  • GetLocaleInfoW (Address: 0x10087504)
  • GetSystemDefaultLangID (Address: 0x100874ec)
  • GetUserDefaultLangID (Address: 0x100874e8)
  • GetUserDefaultLCID (Address: 0x1008750c)
  • IsValidLocale (Address: 0x10087508)
  • SetCalendarInfoW (Address: 0x100874f8)
  • SetLocaleInfoW (Address: 0x10087500)
api-ms-win-core-path-l1-1-0.dll
  • PathCchRemoveBackslash (Address: 0x10087518)
  • PathCchStripToRoot (Address: 0x10087514)
api-ms-win-core-processenvironment-l1-1-0.dll
  • GetEnvironmentVariableW (Address: 0x10087520)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x10087538)
  • GetCurrentProcessId (Address: 0x10087530)
  • GetCurrentThread (Address: 0x1008753c)
  • GetCurrentThreadId (Address: 0x10087534)
  • SetThreadPriority (Address: 0x10087528)
  • TerminateProcess (Address: 0x1008752c)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x10087544)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x10087554)
  • RegCreateKeyExW (Address: 0x10087564)
  • RegEnumValueW (Address: 0x1008755c)
  • RegOpenCurrentUser (Address: 0x10087558)
  • RegOpenKeyExW (Address: 0x10087550)
  • RegQueryInfoKeyW (Address: 0x1008754c)
  • RegQueryValueExW (Address: 0x10087560)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringW (Address: 0x10087570)
  • MultiByteToWideChar (Address: 0x1008756c)
  • WideCharToMultiByte (Address: 0x10087574)
api-ms-win-core-string-l2-1-0.dll
  • CharLowerW (Address: 0x10087580)
  • CharNextW (Address: 0x10087584)
  • CharUpperW (Address: 0x1008757c)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x100875a0)
  • AcquireSRWLockShared (Address: 0x100875a4)
  • CreateMutexExW (Address: 0x100875bc)
  • CreateSemaphoreExW (Address: 0x100875c4)
  • DeleteCriticalSection (Address: 0x10087594)
  • EnterCriticalSection (Address: 0x1008759c)
  • InitializeCriticalSection (Address: 0x10087598)
  • InitializeCriticalSectionEx (Address: 0x100875b0)
  • LeaveCriticalSection (Address: 0x1008758c)
  • OpenSemaphoreW (Address: 0x100875c8)
  • ReleaseMutex (Address: 0x100875b8)
  • ReleaseSemaphore (Address: 0x100875b4)
  • ReleaseSRWLockExclusive (Address: 0x10087590)
  • ReleaseSRWLockShared (Address: 0x100875ac)
  • WaitForSingleObject (Address: 0x100875a8)
  • WaitForSingleObjectEx (Address: 0x100875c0)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x100875d0)
  • SleepConditionVariableSRW (Address: 0x100875d4)
  • WakeAllConditionVariable (Address: 0x100875d8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x100875e8)
  • GetSystemInfo (Address: 0x100875f4)
  • GetSystemTime (Address: 0x100875e4)
  • GetSystemTimeAsFileTime (Address: 0x100875ec)
  • GetTickCount (Address: 0x100875e0)
  • GetVersionExW (Address: 0x100875f0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x10087600)
  • CreateThreadpoolTimer (Address: 0x10087608)
  • SetThreadpoolTimer (Address: 0x10087604)
  • WaitForThreadpoolTimerCallbacks (Address: 0x100875fc)
api-ms-win-core-wow64-l1-1-0.dll
  • IsWow64Process (Address: 0x10087610)
api-ms-win-power-setting-l1-1-0.dll
  • PowerGetActiveScheme (Address: 0x10087618)
  • PowerSetActiveScheme (Address: 0x10087624)
  • PowerWriteACValueIndex (Address: 0x1008761c)
  • PowerWriteDCValueIndex (Address: 0x10087620)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x10087634)
  • AllocateAndInitializeSid (Address: 0x10087660)
  • CopySid (Address: 0x10087650)
  • CreateWellKnownSid (Address: 0x10087630)
  • FreeSid (Address: 0x10087638)
  • GetLengthSid (Address: 0x10087654)
  • GetSidSubAuthority (Address: 0x10087658)
  • GetSidSubAuthorityCount (Address: 0x1008765c)
  • GetTokenInformation (Address: 0x10087648)
  • ImpersonateLoggedOnUser (Address: 0x10087664)
  • InitializeAcl (Address: 0x10087640)
  • InitializeSecurityDescriptor (Address: 0x1008762c)
  • IsValidSid (Address: 0x1008764c)
  • RevertToSelf (Address: 0x10087644)
  • SetSecurityDescriptorDacl (Address: 0x1008763c)
DSROLE.dll
  • DsRoleFreeMemory (Address: 0x100870dc)
  • DsRoleGetPrimaryDomainInformation (Address: 0x100870e0)
IPHLPAPI.DLL
  • GetIfTable (Address: 0x100870e8)
KERNEL32.dll
  • CompareFileTime (Address: 0x10087170)
  • CreateDirectoryW (Address: 0x10087184)
  • DeleteFileW (Address: 0x100870f0)
  • EnumResourceLanguagesW (Address: 0x1008711c)
  • ExpandEnvironmentStringsW (Address: 0x1008713c)
  • FileTimeToSystemTime (Address: 0x10087108)
  • GetComputerNameW (Address: 0x1008715c)
  • GetDriveTypeW (Address: 0x1008717c)
  • GetFileInformationByHandle (Address: 0x1008710c)
  • GetFileInformationByHandleEx (Address: 0x10087124)
  • GetFileSizeEx (Address: 0x10087118)
  • GetFinalPathNameByHandleW (Address: 0x10087104)
  • GetModuleHandleA (Address: 0x10087100)
  • GetSystemDirectoryW (Address: 0x10087148)
  • GetSystemPowerStatus (Address: 0x10087178)
  • GetSystemWindowsDirectoryW (Address: 0x10087168)
  • GetTimeZoneInformation (Address: 0x1008714c)
  • GetVolumeInformationW (Address: 0x10087174)
  • GetWindowsDirectoryW (Address: 0x10087154)
  • GlobalAlloc (Address: 0x10087134)
  • GlobalFree (Address: 0x10087150)
  • GlobalLock (Address: 0x1008716c)
  • GlobalMemoryStatus (Address: 0x10087120)
  • GlobalUnlock (Address: 0x10087144)
  • LoadLibraryA (Address: 0x10087180)
  • LoadLibraryW (Address: 0x10087138)
  • lstrcmpiW (Address: 0x1008712c)
  • lstrcmpW (Address: 0x10087130)
  • RemoveDirectoryW (Address: 0x100870f8)
  • SetDllDirectoryW (Address: 0x10087110)
  • SetEnvironmentVariableW (Address: 0x10087140)
  • SetFilePointer (Address: 0x100870f4)
  • SystemTimeToFileTime (Address: 0x10087160)
  • VerifyVersionInfoW (Address: 0x10087164)
  • VerSetConditionMask (Address: 0x10087158)
  • WriteFile (Address: 0x100870fc)
  • WritePrivateProfileStringW (Address: 0x10087114)
  • WTSGetActiveConsoleSessionId (Address: 0x10087128)
logoncli.dll
  • DsGetSiteNameW (Address: 0x1008766c)
MPR.dll
  • WNetCancelConnection2W (Address: 0x10087190)
  • WNetGetConnectionW (Address: 0x1008718c)
  • WNetUseConnectionW (Address: 0x10087194)
msi.dll
  • (Address: 0x10087674)
  • (Address: 0x10087678)
  • (Address: 0x1008767c)
  • (Address: 0x10087680)
  • (Address: 0x10087684)
  • (Address: 0x10087688)
  • (Address: 0x1008768c)
  • (Address: 0x10087690)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x100876e4)
  • __dllonexit (Address: 0x10087708)
  • _amsg_exit (Address: 0x100876f0)
  • _callnewh (Address: 0x100876e8)
  • _CxxThrowException (Address: 0x10087728)
  • _errno (Address: 0x10087718)
  • _except_handler4_common (Address: 0x100876fc)
  • _initterm (Address: 0x100876f4)
  • _lock (Address: 0x10087700)
  • _onexit (Address: 0x1008770c)
  • _purecall (Address: 0x100876a0)
  • _unlock (Address: 0x10087704)
  • _vsnprintf_s (Address: 0x10087730)
  • _vsnwprintf (Address: 0x10087738)
  • _vsnwprintf_s (Address: 0x100876c0)
  • _wcsnicmp (Address: 0x1008772c)
  • _wtof (Address: 0x100876d8)
  • _wtoi (Address: 0x100876c4)
  • _wtol (Address: 0x100876dc)
  • _XcptFilter (Address: 0x100876ec)
  • ?_set_se_translator@@YAP6AXIPAU_EXCEPTION_POINTERS@@@ZP6AXI0@Z@Z (Address: 0x100876c8)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x100876b8)
  • ??0exception@@QAE@XZ (Address: 0x100876bc)
  • ??1exception@@UAE@XZ (Address: 0x100876b4)
  • ??1type_info@@UAE@XZ (Address: 0x10087714)
  • ?terminate@@YAXXZ (Address: 0x100876f8)
  • calloc (Address: 0x100876ac)
  • free (Address: 0x1008769c)
  • malloc (Address: 0x100876e0)
  • memcmp (Address: 0x10087724)
  • memcpy (Address: 0x10087710)
  • memcpy_s (Address: 0x100876a8)
  • memmove (Address: 0x10087720)
  • memmove_s (Address: 0x100876b0)
  • memset (Address: 0x1008773c)
  • realloc (Address: 0x1008771c)
  • swscanf (Address: 0x10087698)
  • wcscat_s (Address: 0x100876d0)
  • wcscpy_s (Address: 0x100876cc)
  • wcsncmp (Address: 0x100876a4)
  • wcsncpy_s (Address: 0x100876d4)
  • wcsnlen (Address: 0x10087734)
NETAPI32.dll
  • Netbios (Address: 0x1008719c)
  • NetLocalGroupAdd (Address: 0x100871cc)
  • NetLocalGroupAddMembers (Address: 0x100871ac)
  • NetLocalGroupDel (Address: 0x100871a8)
  • NetLocalGroupDelMembers (Address: 0x100871c0)
  • NetLocalGroupGetInfo (Address: 0x100871b4)
  • NetLocalGroupGetMembers (Address: 0x100871c4)
  • NetLocalGroupSetInfo (Address: 0x100871a4)
  • NetUserAdd (Address: 0x100871bc)
  • NetUserDel (Address: 0x100871b8)
  • NetUserGetInfo (Address: 0x100871b0)
  • NetUserSetInfo (Address: 0x100871c8)
  • NetWkstaGetInfo (Address: 0x100871a0)
netutils.dll
  • NetApiBufferFree (Address: 0x10087744)
ntdll.dll
  • NtClose (Address: 0x1008774c)
  • NtCreateFile (Address: 0x10087754)
  • NtFsControlFile (Address: 0x1008775c)
  • NtQueryInformationToken (Address: 0x10087750)
  • RtlInitUnicodeString (Address: 0x10087760)
  • RtlIpv6StringToAddressW (Address: 0x10087758)
NTDSAPI.dll
  • DsBindW (Address: 0x100871d4)
  • DsCrackNamesW (Address: 0x100871d8)
  • DsFreeNameResultW (Address: 0x100871e0)
  • DsUnBindW (Address: 0x100871dc)
OLEAUT32.dll
  • LoadTypeLib (Address: 0x100871e8)
  • RegisterTypeLib (Address: 0x1008723c)
  • SafeArrayAccessData (Address: 0x100871fc)
  • SafeArrayCopy (Address: 0x10087228)
  • SafeArrayCreate (Address: 0x100871ec)
  • SafeArrayDestroy (Address: 0x10087218)
  • SafeArrayGetLBound (Address: 0x10087224)
  • SafeArrayGetUBound (Address: 0x10087220)
  • SafeArrayGetVartype (Address: 0x1008722c)
  • SafeArrayLock (Address: 0x1008721c)
  • SafeArrayRedim (Address: 0x100871f0)
  • SafeArrayUnaccessData (Address: 0x10087200)
  • SafeArrayUnlock (Address: 0x10087214)
  • SysAllocString (Address: 0x10087234)
  • SysAllocStringLen (Address: 0x10087238)
  • SysFreeString (Address: 0x10087230)
  • SysStringLen (Address: 0x10087240)
  • UnRegisterTypeLib (Address: 0x100871f8)
  • VarBstrCat (Address: 0x10087204)
  • VariantChangeType (Address: 0x100871f4)
  • VariantClear (Address: 0x1008720c)
  • VariantCopy (Address: 0x10087208)
  • VariantInit (Address: 0x10087210)
POWRPROF.dll
  • CallNtPowerInformation (Address: 0x10087270)
  • DeletePwrScheme (Address: 0x10087280)
  • EnumPwrSchemes (Address: 0x10087274)
  • GetActivePwrScheme (Address: 0x1008724c)
  • GetPwrCapabilities (Address: 0x10087248)
  • PowerDeleteScheme (Address: 0x10087260)
  • PowerDeterminePlatformRole (Address: 0x1008726c)
  • PowerDuplicateScheme (Address: 0x10087254)
  • PowerEnumerate (Address: 0x10087264)
  • PowerReadFriendlyName (Address: 0x10087268)
  • PowerWriteFriendlyName (Address: 0x1008725c)
  • ReadGlobalPwrPolicy (Address: 0x1008727c)
  • ReadPwrScheme (Address: 0x10087258)
  • SetActivePwrScheme (Address: 0x10087250)
  • WriteGlobalPwrPolicy (Address: 0x10087278)
  • WritePwrScheme (Address: 0x10087284)
RPCRT4.dll
  • RpcStringFreeW (Address: 0x1008728c)
  • UuidCreate (Address: 0x10087298)
  • UuidEqual (Address: 0x10087290)
  • UuidToStringW (Address: 0x10087294)
samcli.dll
  • NetUserGetGroups (Address: 0x1008776c)
  • NetUserGetLocalGroups (Address: 0x10087768)
Secur32.dll
  • AcceptSecurityContext (Address: 0x100872ec)
  • AcquireCredentialsHandleW (Address: 0x100872f8)
  • DeleteSecurityContext (Address: 0x100872f4)
  • FreeContextBuffer (Address: 0x100872e0)
  • FreeCredentialsHandle (Address: 0x100872fc)
  • InitializeSecurityContextW (Address: 0x10087300)
  • QuerySecurityContextToken (Address: 0x100872e8)
  • QuerySecurityPackageInfoW (Address: 0x100872f0)
  • SeciAllocateAndSetIPAddress (Address: 0x100872dc)
  • SeciFreeCallContext (Address: 0x100872e4)
SETUPAPI.dll
  • SetupDiCallClassInstaller (Address: 0x100872a8)
  • SetupDiDestroyDeviceInfoList (Address: 0x100872a0)
  • SetupDiEnumDeviceInfo (Address: 0x100872ac)
  • SetupDiGetDeviceInstanceIdW (Address: 0x100872b0)
  • SetupDiGetDevicePropertyW (Address: 0x100872b4)
  • SetupDiSetClassInstallParamsW (Address: 0x100872a4)
SHELL32.dll
  • SHChangeNotify (Address: 0x100872c4)
  • Shell_NotifyIconW (Address: 0x100872cc)
  • SHGetFolderPathW (Address: 0x100872c0)
  • SHGetKnownFolderPath (Address: 0x100872bc)
  • SHGetMalloc (Address: 0x100872c8)
SHLWAPI.dll
  • (Address: 0x100872d4)
srvcli.dll
  • NetShareAdd (Address: 0x1008777c)
  • NetShareDel (Address: 0x10087780)
  • NetShareEnum (Address: 0x10087784)
  • NetShareGetInfo (Address: 0x10087778)
  • NetShareSetInfo (Address: 0x10087774)
USER32.dll
  • CharPrevW (Address: 0x10087340)
  • CharUpperBuffW (Address: 0x1008733c)
  • CreateWindowExW (Address: 0x10087318)
  • DefWindowProcW (Address: 0x10087330)
  • DestroyWindow (Address: 0x10087308)
  • ExitWindowsEx (Address: 0x10087334)
  • GetSystemMetrics (Address: 0x1008730c)
  • GetWindowLongW (Address: 0x1008732c)
  • LoadIconW (Address: 0x10087310)
  • MessageBoxW (Address: 0x10087348)
  • RegisterClassExW (Address: 0x10087314)
  • SendMessageW (Address: 0x10087324)
  • SendNotifyMessageW (Address: 0x10087344)
  • SetWindowLongW (Address: 0x1008731c)
  • SetWindowPos (Address: 0x10087320)
  • UnregisterClassA (Address: 0x10087338)
  • UnregisterClassW (Address: 0x10087328)
USERENV.dll
  • CreateEnvironmentBlock (Address: 0x10087364)
  • DestroyEnvironmentBlock (Address: 0x10087354)
  • ProcessGroupPolicyCompleted (Address: 0x10087358)
  • ProcessGroupPolicyCompletedEx (Address: 0x1008735c)
  • RsopResetPolicySettingStatus (Address: 0x10087360)
  • RsopSetPolicySettingStatus (Address: 0x10087350)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x10087374)
  • GetFileVersionInfoW (Address: 0x10087370)
  • VerQueryValueW (Address: 0x1008736c)
WINSPOOL.DRV
  • (Address: 0x100873b0)
  • AddPrinterConnectionW (Address: 0x100873ac)
  • AddPrinterDriverW (Address: 0x100873b8)
  • AddPrinterW (Address: 0x1008737c)
  • ClosePrinter (Address: 0x10087394)
  • DeletePrinter (Address: 0x10087390)
  • DeletePrinterConnectionW (Address: 0x100873a8)
  • EnumMonitorsW (Address: 0x10087388)
  • EnumPortsW (Address: 0x10087398)
  • EnumPrinterDriversW (Address: 0x10087380)
  • EnumPrintersW (Address: 0x1008739c)
  • GetPrinterDriverDirectoryW (Address: 0x100873a4)
  • GetPrinterDriverW (Address: 0x100873b4)
  • GetPrinterW (Address: 0x1008738c)
  • OpenPrinterW (Address: 0x100873a0)
  • XcvDataW (Address: 0x10087384)
WINSTA.dll
  • WinStationBroadcastSystemMessage (Address: 0x100873c0)
  • WinStationSendWindowMessage (Address: 0x100873c4)
WLDAP32.dll
  • (Address: 0x100873d0)
  • (Address: 0x100873cc)
WS2_32.dll
  • FreeAddrInfoW (Address: 0x100873d8)
  • GetAddrInfoW (Address: 0x100873e8)
  • ntohl (Address: 0x100873ec)
  • WSACleanup (Address: 0x100873e4)
  • WSAGetLastError (Address: 0x100873e0)
  • WSAStartup (Address: 0x100873dc)
WTSAPI32.dll
  • WTSFreeMemory (Address: 0x100873f4)
  • WTSQuerySessionInformationW (Address: 0x100873f8)
XmlLite.dll
  • CreateXmlReader (Address: 0x10087400)