cloudAP.dll

Description: Cloud AP Security Package

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6456

Architecture: 64-bit

Operating System: Windows NT

SHA256: 8fb8bb80da8e63162750d123d2693fef

File Size: 603.5 KB

Uploaded At: Dec. 1, 2025, 7:24 a.m.

Views: 18

Exported Functions

  • SpLsaModeInitialize (Ordinal: 1, Address: 0xc1c0)
  • SpUserModeInitialize (Ordinal: 2, Address: 0x47500)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18007ebc8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18007ebe8)
  • IsDebuggerPresent (Address: 0x18007ebe0)
  • OutputDebugStringW (Address: 0x18007ebd8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18007ebf8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18007ec08)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18007ec18)
  • SetLastError (Address: 0x18007ec30)
  • SetUnhandledExceptionFilter (Address: 0x18007ec28)
  • UnhandledExceptionFilter (Address: 0x18007ec20)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18007eca8)
  • CreateDirectoryW (Address: 0x18007ec88)
  • CreateFileW (Address: 0x18007ec90)
  • DeleteFileW (Address: 0x18007ecb0)
  • FindClose (Address: 0x18007ec58)
  • FindFirstFileExW (Address: 0x18007ec80)
  • FindFirstFileW (Address: 0x18007ec40)
  • FindNextFileW (Address: 0x18007eca0)
  • GetFileAttributesW (Address: 0x18007ec70)
  • GetFileSizeEx (Address: 0x18007ec50)
  • GetFileTime (Address: 0x18007ec48)
  • ReadFile (Address: 0x18007ec98)
  • RemoveDirectoryW (Address: 0x18007ec68)
  • SetFileAttributesW (Address: 0x18007ec78)
  • WriteFile (Address: 0x18007ec60)
api-ms-win-core-file-l2-1-2.dll
  • CopyFileW (Address: 0x18007ecc0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18007ecd0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18007ecf0)
  • HeapAlloc (Address: 0x18007ece8)
  • HeapFree (Address: 0x18007ece0)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18007ed00)
  • LocalFree (Address: 0x18007ed08)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x18007ed18)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x18007ed30)
  • MoveFileW (Address: 0x18007ed28)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18007ed40)
  • FreeLibrary (Address: 0x18007ed68)
  • GetModuleFileNameA (Address: 0x18007ed60)
  • GetModuleHandleExW (Address: 0x18007ed58)
  • GetModuleHandleW (Address: 0x18007ed50)
  • GetProcAddress (Address: 0x18007ed48)
  • LoadLibraryExW (Address: 0x18007ed70)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18007ed88)
  • GetACP (Address: 0x18007ed90)
  • LCMapStringEx (Address: 0x18007ed80)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x18007edb0)
  • VirtualProtect (Address: 0x18007eda8)
  • VirtualQuery (Address: 0x18007eda0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18007edc0)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18007ede8)
  • GetCurrentProcessId (Address: 0x18007ee08)
  • GetCurrentThreadId (Address: 0x18007ee10)
  • SetThreadStackGuarantee (Address: 0x18007ee00)
  • SetThreadToken (Address: 0x18007edf8)
  • TerminateProcess (Address: 0x18007edd0)
  • TlsAlloc (Address: 0x18007edd8)
  • TlsFree (Address: 0x18007ede0)
  • TlsGetValue (Address: 0x18007ee18)
  • TlsSetValue (Address: 0x18007edf0)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x18007ee28)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18007ee38)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18007ee58)
  • RegCreateKeyExW (Address: 0x18007ee80)
  • RegDeleteKeyExW (Address: 0x18007ee60)
  • RegEnumKeyExW (Address: 0x18007ee78)
  • RegFlushKey (Address: 0x18007ee70)
  • RegGetValueW (Address: 0x18007ee50)
  • RegOpenKeyExW (Address: 0x18007ee48)
  • RegQueryInfoKeyW (Address: 0x18007ee88)
  • RegQueryValueExW (Address: 0x18007ee90)
  • RegSetValueExW (Address: 0x18007ee68)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueW (Address: 0x18007eea0)
api-ms-win-core-registry-l2-1-0.dll
  • RegDeleteKeyW (Address: 0x18007eeb0)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18007eec8)
  • RtlLookupFunctionEntry (Address: 0x18007eec0)
  • RtlVirtualUnwind (Address: 0x18007eed0)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFileExistsW (Address: 0x18007eee0)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x18007eef0)
  • WideCharToMultiByte (Address: 0x18007eef8)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrlenA (Address: 0x18007ef10)
  • lstrlenW (Address: 0x18007ef08)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18007efc8)
  • AcquireSRWLockShared (Address: 0x18007efa0)
  • CreateEventW (Address: 0x18007ef58)
  • CreateMutexExW (Address: 0x18007efa8)
  • CreateSemaphoreExW (Address: 0x18007ef78)
  • DeleteCriticalSection (Address: 0x18007ef98)
  • EnterCriticalSection (Address: 0x18007ef50)
  • InitializeCriticalSection (Address: 0x18007ef90)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18007ef70)
  • InitializeCriticalSectionEx (Address: 0x18007ef38)
  • InitializeSRWLock (Address: 0x18007ef48)
  • LeaveCriticalSection (Address: 0x18007ef30)
  • OpenSemaphoreW (Address: 0x18007efb8)
  • ReleaseMutex (Address: 0x18007ef80)
  • ReleaseSemaphore (Address: 0x18007ef28)
  • ReleaseSRWLockExclusive (Address: 0x18007ef88)
  • ReleaseSRWLockShared (Address: 0x18007efb0)
  • ResetEvent (Address: 0x18007ef60)
  • SetEvent (Address: 0x18007ef68)
  • TryAcquireSRWLockExclusive (Address: 0x18007ef20)
  • WaitForSingleObject (Address: 0x18007ef40)
  • WaitForSingleObjectEx (Address: 0x18007efc0)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x18007eff0)
  • InitOnceComplete (Address: 0x18007efe8)
  • InitOnceExecuteOnce (Address: 0x18007efd8)
  • Sleep (Address: 0x18007efe0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x18007f010)
  • GetSystemTimeAsFileTime (Address: 0x18007f000)
  • GetTickCount (Address: 0x18007f008)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18007f038)
  • CreateThreadpoolTimer (Address: 0x18007f028)
  • SetThreadpoolTimer (Address: 0x18007f030)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18007f020)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • QueueUserWorkItem (Address: 0x18007f048)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x18007f170)
  • __CxxFrameHandler3 (Address: 0x18007f0c8)
  • __CxxFrameHandler4 (Address: 0x18007f180)
  • __std_terminate (Address: 0x18007f178)
  • _CxxThrowException (Address: 0x18007f0d0)
  • _o___std_exception_copy (Address: 0x18007f150)
  • _o___std_exception_destroy (Address: 0x18007f148)
  • _o___std_type_info_destroy_list (Address: 0x18007f140)
  • _o___stdio_common_vsnprintf_s (Address: 0x18007f138)
  • _o___stdio_common_vsnwprintf_s (Address: 0x18007f130)
  • _o___stdio_common_vsprintf (Address: 0x18007f128)
  • _o___stdio_common_vswprintf (Address: 0x18007f120)
  • _o__beginthreadex (Address: 0x18007f118)
  • _o__callnewh (Address: 0x18007f110)
  • _o__cexit (Address: 0x18007f108)
  • _o__configure_narrow_argv (Address: 0x18007f100)
  • _o__crt_atexit (Address: 0x18007f0f8)
  • _o__errno (Address: 0x18007f160)
  • _o__execute_onexit_table (Address: 0x18007f158)
  • _o__initialize_narrow_environment (Address: 0x18007f0f0)
  • _o__initialize_onexit_table (Address: 0x18007f0e8)
  • _o__invalid_parameter_noinfo (Address: 0x18007f0e0)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x18007f0d8)
  • _o__purecall (Address: 0x18007f058)
  • _o__register_onexit_function (Address: 0x18007f060)
  • _o__seh_filter_dll (Address: 0x18007f068)
  • _o__stricmp (Address: 0x18007f070)
  • _o__wcsicmp (Address: 0x18007f078)
  • _o_free (Address: 0x18007f088)
  • _o_iswascii (Address: 0x18007f090)
  • _o_iswprint (Address: 0x18007f098)
  • _o_malloc (Address: 0x18007f0a0)
  • _o_memcpy_s (Address: 0x18007f0a8)
  • _o_tolower (Address: 0x18007f0b0)
  • _o_toupper (Address: 0x18007f0b8)
  • _o_wcscpy_s (Address: 0x18007f0c0)
  • memcmp (Address: 0x18007f188)
  • memcpy (Address: 0x18007f190)
  • memmove (Address: 0x18007f080)
  • wcschr (Address: 0x18007f168)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x18007f1a0)
  • _initterm_e (Address: 0x18007f1a8)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x18007f1c0)
  • wcscmp (Address: 0x18007f1c8)
  • wcsnlen (Address: 0x18007f1b8)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x18007f1f0)
  • GetTraceEnableLevel (Address: 0x18007f1f8)
  • GetTraceLoggerHandle (Address: 0x18007f1e8)
  • RegisterTraceGuidsW (Address: 0x18007f1e0)
  • TraceMessage (Address: 0x18007f1d8)
  • UnregisterTraceGuids (Address: 0x18007f200)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x18007f220)
  • EventProviderEnabled (Address: 0x18007f238)
  • EventRegister (Address: 0x18007f210)
  • EventSetInformation (Address: 0x18007f228)
  • EventUnregister (Address: 0x18007f230)
  • EventWriteTransfer (Address: 0x18007f218)
api-ms-win-eventlog-legacy-l1-1-0.dll
  • DeregisterEventSource (Address: 0x18007f248)
  • RegisterEventSourceW (Address: 0x18007f250)
  • ReportEventW (Address: 0x18007f258)
api-ms-win-security-base-l1-1-0.dll
  • CheckTokenMembership (Address: 0x18007f268)
  • CopySid (Address: 0x18007f288)
  • CreateWellKnownSid (Address: 0x18007f270)
  • GetLengthSid (Address: 0x18007f278)
  • RevertToSelf (Address: 0x18007f280)
api-ms-win-security-credentials-l1-1-0.dll
  • CredIsProtectedW (Address: 0x18007f298)
api-ms-win-security-credentials-l2-1-1.dll
  • CredUnprotectEx (Address: 0x18007f2a8)
api-ms-win-security-cryptoapi-l1-1-0.dll
  • CryptAcquireContextW (Address: 0x18007f308)
  • CryptCreateHash (Address: 0x18007f2d0)
  • CryptDecrypt (Address: 0x18007f2e0)
  • CryptDeriveKey (Address: 0x18007f2c8)
  • CryptDestroyHash (Address: 0x18007f2f8)
  • CryptDestroyKey (Address: 0x18007f328)
  • CryptEncrypt (Address: 0x18007f300)
  • CryptGetHashParam (Address: 0x18007f2b8)
  • CryptGetKeyParam (Address: 0x18007f310)
  • CryptGetProvParam (Address: 0x18007f2d8)
  • CryptGetUserKey (Address: 0x18007f318)
  • CryptHashData (Address: 0x18007f2c0)
  • CryptReleaseContext (Address: 0x18007f330)
  • CryptSetHashParam (Address: 0x18007f2e8)
  • CryptSetProvParam (Address: 0x18007f2f0)
  • CryptSignHashW (Address: 0x18007f320)
api-ms-win-security-lsalookup-l1-1-2.dll
  • LsaLookupUserAccountType (Address: 0x18007f340)
api-ms-win-security-provider-l1-1-0.dll
  • GetExplicitEntriesFromAclW (Address: 0x18007f360)
  • GetNamedSecurityInfoW (Address: 0x18007f368)
  • SetEntriesInAclW (Address: 0x18007f350)
  • SetNamedSecurityInfoW (Address: 0x18007f358)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x18007f388)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18007f378)
  • ConvertStringSidToSidW (Address: 0x18007f380)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x18007f398)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x18007f3a8)
  • BCryptCreateHash (Address: 0x18007f410)
  • BCryptDecrypt (Address: 0x18007f420)
  • BCryptDeriveKeyPBKDF2 (Address: 0x18007f3b8)
  • BCryptDestroyHash (Address: 0x18007f3b0)
  • BCryptDestroyKey (Address: 0x18007f418)
  • BCryptEncrypt (Address: 0x18007f3f8)
  • BCryptExportKey (Address: 0x18007f3d0)
  • BCryptFinalizeKeyPair (Address: 0x18007f3e0)
  • BCryptFinishHash (Address: 0x18007f400)
  • BCryptGenerateKeyPair (Address: 0x18007f3d8)
  • BCryptGenerateSymmetricKey (Address: 0x18007f438)
  • BCryptGenRandom (Address: 0x18007f3e8)
  • BCryptGetProperty (Address: 0x18007f440)
  • BCryptHashData (Address: 0x18007f408)
  • BCryptImportKeyPair (Address: 0x18007f3f0)
  • BCryptKeyDerivation (Address: 0x18007f430)
  • BCryptOpenAlgorithmProvider (Address: 0x18007f428)
  • BCryptSetProperty (Address: 0x18007f3c0)
  • BCryptVerifySignature (Address: 0x18007f3c8)
CRYPT32.dll
  • CertCloseStore (Address: 0x18007e848)
  • CertCompareCertificateName (Address: 0x18007e878)
  • CertComparePublicKeyInfo (Address: 0x18007e888)
  • CertCreateCertificateContext (Address: 0x18007e838)
  • CertFindCertificateInStore (Address: 0x18007e890)
  • CertFreeCertificateContext (Address: 0x18007e858)
  • CertGetCertificateContextProperty (Address: 0x18007e830)
  • CertGetNameStringW (Address: 0x18007e870)
  • CertGetPublicKeyLength (Address: 0x18007e840)
  • CertOpenStore (Address: 0x18007e898)
  • CertSetCertificateContextProperty (Address: 0x18007e850)
  • CryptAcquireCertificatePrivateKey (Address: 0x18007e860)
  • CryptExportPublicKeyInfoFromBCryptKeyHandle (Address: 0x18007e868)
  • CryptImportPublicKeyInfoEx2 (Address: 0x18007e880)
cryptdll.dll
  • CDGenerateRandomBits (Address: 0x18007f450)
  • CDLocateCSystem (Address: 0x18007f458)
LSASRV.dll
  • LsaIAddNamesToLogonSession (Address: 0x18007e8c8)
  • LsaICallPackage (Address: 0x18007e8a8)
  • LsaICheckRestrictedMode (Address: 0x18007e8d0)
  • LsaIFlushIdentityCacheForSid (Address: 0x18007e8b8)
  • LsaIFree_LSAPR_CR_CIPHER_VALUE (Address: 0x18007e928)
  • LsaIGetNameFromLuid (Address: 0x18007e8f0)
  • LsaINotifyNewPassword (Address: 0x18007e8e8)
  • LsaIOpenPolicyTrusted (Address: 0x18007e930)
  • LsaISanitizeSAMName (Address: 0x18007e8c0)
  • LsaISetLogonInfo (Address: 0x18007e8e0)
  • LsaIWasLogonNotifiedOfProfileLoad (Address: 0x18007e8d8)
  • LsapDbLookupGetDomainInfo (Address: 0x18007e8b0)
  • LsarClose (Address: 0x18007e8f8)
  • LsarCreateSecret (Address: 0x18007e908)
  • LsarDeleteObject (Address: 0x18007e918)
  • LsarOpenSecret (Address: 0x18007e900)
  • LsarQuerySecret (Address: 0x18007e920)
  • LsarSetSecret (Address: 0x18007e910)
MSASN1.dll
  • ASN1_CloseDecoder (Address: 0x18007e950)
  • ASN1_CreateDecoder (Address: 0x18007ea78)
  • ASN1_CreateModule (Address: 0x18007e9a8)
  • ASN1_Decode (Address: 0x18007e948)
  • ASN1BERDecBitString (Address: 0x18007ea88)
  • ASN1BERDecBool (Address: 0x18007ea20)
  • ASN1BERDecCharString (Address: 0x18007e9b0)
  • ASN1BERDecEndOfContents (Address: 0x18007ea18)
  • ASN1BERDecExplicitTag (Address: 0x18007e998)
  • ASN1BERDecGeneralizedTime (Address: 0x18007e9c8)
  • ASN1BERDecNotEndOfContents (Address: 0x18007ea08)
  • ASN1BERDecObjectIdentifier (Address: 0x18007ea70)
  • ASN1BERDecOctetString (Address: 0x18007ea00)
  • ASN1BERDecOpenType2 (Address: 0x18007e958)
  • ASN1BERDecPeekTag (Address: 0x18007e9f0)
  • ASN1BERDecS32Val (Address: 0x18007e9b8)
  • ASN1BERDecSkip (Address: 0x18007ea58)
  • ASN1BERDecSXVal (Address: 0x18007e960)
  • ASN1BERDecU32Val (Address: 0x18007e980)
  • ASN1BERDecZeroCharString (Address: 0x18007e9e0)
  • ASN1BEREncBool (Address: 0x18007ea50)
  • ASN1BEREncEndOfContents (Address: 0x18007ea48)
  • ASN1BEREncExplicitTag (Address: 0x18007ea10)
  • ASN1BEREncObjectIdentifier (Address: 0x18007e9e8)
  • ASN1BEREncOpenType (Address: 0x18007e9d0)
  • ASN1BEREncS32 (Address: 0x18007ea38)
  • ASN1BEREncSX (Address: 0x18007ea80)
  • ASN1BEREncU32 (Address: 0x18007e9f8)
  • ASN1bitstring_free (Address: 0x18007e9c0)
  • ASN1charstring_free (Address: 0x18007e968)
  • ASN1DecAlloc (Address: 0x18007ea68)
  • ASN1DecSetError (Address: 0x18007e990)
  • ASN1DEREncBitString (Address: 0x18007e978)
  • ASN1DEREncCharString (Address: 0x18007ea40)
  • ASN1DEREncGeneralizedTime (Address: 0x18007e9a0)
  • ASN1DEREncOctetString (Address: 0x18007e970)
  • ASN1EncSetError (Address: 0x18007ea30)
  • ASN1Free (Address: 0x18007ea60)
  • ASN1intx_free (Address: 0x18007e940)
  • ASN1objectidentifier_free (Address: 0x18007ea28)
  • ASN1octetstring_free (Address: 0x18007e988)
  • ASN1ztcharstring_free (Address: 0x18007e9d8)
msvcp_win.dll
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x18007f468)
ncrypt.dll
  • NCryptDeleteKey (Address: 0x18007f498)
  • NCryptDeriveKey (Address: 0x18007f480)
  • NCryptExportKey (Address: 0x18007f488)
  • NCryptFreeObject (Address: 0x18007f4b8)
  • NCryptGetProperty (Address: 0x18007f4b0)
  • NCryptImportKey (Address: 0x18007f478)
  • NCryptOpenKey (Address: 0x18007f4a8)
  • NCryptOpenStorageProvider (Address: 0x18007f4c0)
  • NCryptSecretAgreement (Address: 0x18007f490)
  • NCryptSetProperty (Address: 0x18007f4c8)
  • NCryptSignHash (Address: 0x18007f4a0)
ntdll.dll
  • NtAllocateLocallyUniqueId (Address: 0x18007f580)
  • NtClose (Address: 0x18007f588)
  • NtDuplicateToken (Address: 0x18007f5a8)
  • NtOpenThreadToken (Address: 0x18007f590)
  • NtQueryInformationToken (Address: 0x18007f500)
  • NtSetInformationThread (Address: 0x18007f5a0)
  • RtlAcquireResourceExclusive (Address: 0x18007f4e8)
  • RtlAcquireResourceShared (Address: 0x18007f538)
  • RtlAllocateHeap (Address: 0x18007f5d8)
  • RtlAvlInsertNodeEx (Address: 0x18007f548)
  • RtlAvlRemoveNode (Address: 0x18007f540)
  • RtlCompareUnicodeString (Address: 0x18007f5c0)
  • RtlConvertExclusiveToShared (Address: 0x18007f578)
  • RtlConvertSharedToExclusive (Address: 0x18007f570)
  • RtlCopySid (Address: 0x18007f510)
  • RtlDeleteCriticalSection (Address: 0x18007f560)
  • RtlDeleteResource (Address: 0x18007f4e0)
  • RtlEnterCriticalSection (Address: 0x18007f550)
  • RtlEqualSid (Address: 0x18007f518)
  • RtlEqualUnicodeString (Address: 0x18007f530)
  • RtlFreeHeap (Address: 0x18007f5c8)
  • RtlGetDeviceFamilyInfoEnum (Address: 0x18007f4d8)
  • RtlImageNtHeader (Address: 0x18007f5d0)
  • RtlInitializeCriticalSection (Address: 0x18007f568)
  • RtlInitializeResource (Address: 0x18007f4f8)
  • RtlInitString (Address: 0x18007f598)
  • RtlInitUnicodeString (Address: 0x18007f528)
  • RtlIsMultiSessionSku (Address: 0x18007f5b0)
  • RtlIsMultiUsersInSessionSku (Address: 0x18007f5e0)
  • RtlLeaveCriticalSection (Address: 0x18007f558)
  • RtlLengthSid (Address: 0x18007f508)
  • RtlNtStatusToDosError (Address: 0x18007f5b8)
  • RtlReleaseResource (Address: 0x18007f4f0)
  • RtlValidSid (Address: 0x18007f520)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x18007eac8)
  • I_RpcMapWin32Status (Address: 0x18007ea98)
  • MesBufferHandleReset (Address: 0x18007eac0)
  • MesDecodeBufferHandleCreate (Address: 0x18007eb18)
  • MesEncodeFixedBufferHandleCreate (Address: 0x18007eab8)
  • MesHandleFree (Address: 0x18007ead0)
  • NdrClientCall3 (Address: 0x18007eb28)
  • NdrMesTypeAlignSize3 (Address: 0x18007eb08)
  • NdrMesTypeDecode3 (Address: 0x18007eae0)
  • NdrMesTypeEncode3 (Address: 0x18007eae8)
  • RpcBindingFree (Address: 0x18007eab0)
  • RpcBindingFromStringBindingW (Address: 0x18007eaa0)
  • RpcExceptionFilter (Address: 0x18007eaa8)
  • RpcStringBindingComposeW (Address: 0x18007ead8)
  • RpcStringFreeW (Address: 0x18007eaf0)
  • UuidCreate (Address: 0x18007eb00)
  • UuidEqual (Address: 0x18007eb10)
  • UuidFromStringW (Address: 0x18007eb20)
  • UuidToStringW (Address: 0x18007eaf8)
SspiCli.dll
  • LsaCallAuthenticationPackage (Address: 0x18007eb80)
  • LsaConnectUntrusted (Address: 0x18007eb58)
  • LsaDeregisterLogonProcess (Address: 0x18007eb70)
  • LsaFreeReturnBuffer (Address: 0x18007eb40)
  • LsaLogonUser (Address: 0x18007eb68)
  • LsaLookupAuthenticationPackage (Address: 0x18007eb60)
  • SeciAllocateAndSetCallFlags (Address: 0x18007eb98)
  • SeciFreeCallContext (Address: 0x18007eb88)
  • SspiCopyAuthIdentity (Address: 0x18007eb90)
  • SspiDecryptAuthIdentityEx (Address: 0x18007eb38)
  • SspiFreeAuthIdentity (Address: 0x18007eb48)
  • SspiIsAuthIdentityEncrypted (Address: 0x18007eb50)
  • SspiUnmarshalAuthIdentity (Address: 0x18007eb78)
USERENV.dll
  • (Address: 0x18007eba8)
  • GetProfileType (Address: 0x18007ebb8)
  • GetUserProfileDirectoryW (Address: 0x18007ebb0)