psapi.dll

Description: Process Status Helper

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: f901c48de42ecc015eaa99f61444cffa

File Size: 17.7 KB

Uploaded At: Dec. 1, 2025, 8:03 a.m.

Views: 13

Exported Functions

  • EmptyWorkingSet (Ordinal: 1, Address: 0x1590)
  • EnumDeviceDrivers (Ordinal: 2, Address: 0x1380)
  • EnumPageFilesA (Ordinal: 3, Address: 0x15b0)
  • EnumPageFilesW (Ordinal: 4, Address: 0x15d0)
  • EnumProcessModules (Ordinal: 5, Address: 0x13a0)
  • EnumProcessModulesEx (Ordinal: 6, Address: 0x15f0)
  • EnumProcesses (Ordinal: 7, Address: 0x13c0)
  • GetDeviceDriverBaseNameA (Ordinal: 8, Address: 0x1610)
  • GetDeviceDriverBaseNameW (Ordinal: 9, Address: 0x13e0)
  • GetDeviceDriverFileNameA (Ordinal: 10, Address: 0x1630)
  • GetDeviceDriverFileNameW (Ordinal: 11, Address: 0x1650)
  • GetMappedFileNameA (Ordinal: 12, Address: 0x1670)
  • GetMappedFileNameW (Ordinal: 13, Address: 0x1690)
  • GetModuleBaseNameA (Ordinal: 14, Address: 0x16b0)
  • GetModuleBaseNameW (Ordinal: 15, Address: 0x1400)
  • GetModuleFileNameExA (Ordinal: 16, Address: 0x16d0)
  • GetModuleFileNameExW (Ordinal: 17, Address: 0x1420)
  • GetModuleInformation (Ordinal: 18, Address: 0x1440)
  • GetPerformanceInfo (Ordinal: 19, Address: 0x1460)
  • GetProcessImageFileNameA (Ordinal: 20, Address: 0x16f0)
  • GetProcessImageFileNameW (Ordinal: 21, Address: 0x14c0)
  • GetProcessMemoryInfo (Ordinal: 22, Address: 0x1480)
  • GetWsChanges (Ordinal: 23, Address: 0x1730)
  • GetWsChangesEx (Ordinal: 24, Address: 0x1710)
  • InitializeProcessForWsWatch (Ordinal: 25, Address: 0x1750)
  • QueryWorkingSet (Ordinal: 26, Address: 0x14a0)
  • QueryWorkingSetEx (Ordinal: 27, Address: 0x1770)

Imported DLLs & Functions

api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x4fb83000)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcessId (Address: 0x4fb83008)
  • GetCurrentThreadId (Address: 0x4fb8300c)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x4fb83014)
api-ms-win-core-psapi-ansi-l1-1-0.dll
  • K32EnumPageFilesA (Address: 0x4fb8301c)
  • K32GetDeviceDriverBaseNameA (Address: 0x4fb83020)
  • K32GetDeviceDriverFileNameA (Address: 0x4fb83028)
  • K32GetMappedFileNameA (Address: 0x4fb83024)
  • K32GetProcessImageFileNameA (Address: 0x4fb8302c)
api-ms-win-core-psapi-l1-1-0.dll
  • K32EmptyWorkingSet (Address: 0x4fb8306c)
  • K32EnumDeviceDrivers (Address: 0x4fb83054)
  • K32EnumPageFilesW (Address: 0x4fb83048)
  • K32EnumProcesses (Address: 0x4fb83050)
  • K32EnumProcessModules (Address: 0x4fb83044)
  • K32EnumProcessModulesEx (Address: 0x4fb83070)
  • K32GetDeviceDriverBaseNameW (Address: 0x4fb83060)
  • K32GetDeviceDriverFileNameW (Address: 0x4fb83058)
  • K32GetMappedFileNameW (Address: 0x4fb83034)
  • K32GetModuleBaseNameW (Address: 0x4fb83068)
  • K32GetModuleFileNameExW (Address: 0x4fb8307c)
  • K32GetModuleInformation (Address: 0x4fb8305c)
  • K32GetPerformanceInfo (Address: 0x4fb8304c)
  • K32GetProcessImageFileNameW (Address: 0x4fb83078)
  • K32GetProcessMemoryInfo (Address: 0x4fb83064)
  • K32GetWsChanges (Address: 0x4fb8303c)
  • K32GetWsChangesEx (Address: 0x4fb83080)
  • K32InitializeProcessForWsWatch (Address: 0x4fb83040)
  • K32QueryWorkingSet (Address: 0x4fb83038)
  • K32QueryWorkingSetEx (Address: 0x4fb83074)
api-ms-win-core-psapi-obsolete-l1-1-0.dll
  • K32GetModuleBaseNameA (Address: 0x4fb8308c)
  • K32GetModuleFileNameExA (Address: 0x4fb83088)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x4fb83098)
  • GetTickCount (Address: 0x4fb83094)