ksuser.dll

Description: User CSA Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.1

Architecture: 32-bit

Operating System: Windows NT

SHA256: dd28805fc6f5fd70ddc8c87fe1f5561d

File Size: 19.9 KB

Uploaded At: Dec. 1, 2025, 7:59 a.m.

Views: 7

Exported Functions

  • KsCreateAllocator2 (Ordinal: 1, Address: 0x18c0)
  • KsCreateAllocator (Ordinal: 2, Address: 0x16e0)
  • KsCreateClock2 (Ordinal: 3, Address: 0x18f0)
  • KsCreateClock (Ordinal: 4, Address: 0x1710)
  • KsCreatePin2 (Ordinal: 5, Address: 0x1920)
  • KsCreatePin (Ordinal: 6, Address: 0x1740)
  • KsCreateTopologyNode2 (Ordinal: 7, Address: 0x1960)
  • KsCreateTopologyNode (Ordinal: 8, Address: 0x1780)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x5ef84000)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x5ef84010)
  • SetUnhandledExceptionFilter (Address: 0x5ef84008)
  • UnhandledExceptionFilter (Address: 0x5ef8400c)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x5ef84018)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x5ef84020)
  • HeapAlloc (Address: 0x5ef84024)
  • HeapFree (Address: 0x5ef84028)
api-ms-win-core-processenvironment-l1-1-0.dll
  • GetEnvironmentVariableW (Address: 0x5ef84030)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x5ef84038)
  • GetCurrentProcessId (Address: 0x5ef84044)
  • GetCurrentThreadId (Address: 0x5ef8403c)
  • OpenProcessToken (Address: 0x5ef84040)
  • TerminateProcess (Address: 0x5ef84048)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x5ef84050)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x5ef84058)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x5ef84064)
  • GetTickCount (Address: 0x5ef84060)
api-ms-win-security-base-l1-1-0.dll
  • AllocateAndInitializeSid (Address: 0x5ef84074)
  • EqualSid (Address: 0x5ef84078)
  • FreeSid (Address: 0x5ef84070)
  • GetTokenInformation (Address: 0x5ef8406c)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertStringSidToSidW (Address: 0x5ef84080)
msvcrt.dll
  • _amsg_exit (Address: 0x5ef840a0)
  • _except_handler4_common (Address: 0x5ef84088)
  • _initterm (Address: 0x5ef8408c)
  • _XcptFilter (Address: 0x5ef8409c)
  • free (Address: 0x5ef84098)
  • malloc (Address: 0x5ef84094)
  • memcpy (Address: 0x5ef84090)
  • memset (Address: 0x5ef840a4)
ntdll.dll
  • NtCreateFile (Address: 0x5ef840ac)
  • RtlNtStatusToDosError (Address: 0x5ef840b0)