rdpbase.dll

Description: Rdp OneCore Base Services

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6216

Architecture: 32-bit

Operating System: Windows NT

SHA256: f7311cf87b49c9c6904cfe2ab54cfce9

File Size: 1.2 MB

Uploaded At: Dec. 1, 2025, 8:03 a.m.

Views: 5

Exported Functions

  • ??0CRDPCache@@QAE@XZ (Ordinal: 1, Address: 0x99ed0)
  • ??0CRDPENCONResolver@@QAE@XZ (Ordinal: 2, Address: 0xb4800)
  • ??0NSCodecDecompressor@@QAE@_N@Z (Ordinal: 3, Address: 0x64c90)
  • ??0PipeETWEvents@@QAE@XZ (Ordinal: 4, Address: 0x93540)
  • ??0RdpEncodeBuffer@@QAE@PAVITSObjectPool@@@Z (Ordinal: 5, Address: 0x56c00)
  • ??0RdpGfxProtocolBaseDecoder@@IAE@XZ (Ordinal: 6, Address: 0x57130)
  • ??0SSECBCHash2@@QAE@XZ (Ordinal: 7, Address: 0x88ad0)
  • ??1CRDPCache@@UAE@XZ (Ordinal: 8, Address: 0x99f40)
  • ??1CRDPENCONResolver@@QAE@XZ (Ordinal: 9, Address: 0xb48e0)
  • ??1Evict@@QAE@XZ (Ordinal: 10, Address: 0x96230)
  • ??1RdpGfxProtocolBaseDecoder@@IAE@XZ (Ordinal: 11, Address: 0x57150)
  • ?AddConnection@CRDPENCONResolver@@QAEJPAGKH@Z (Ordinal: 12, Address: 0xb49d0)
  • ?AddPortMapping@CRDPENCConnectorStringSerializer@@UAGJPAGK@Z (Ordinal: 13, Address: 0xb6380)
  • ?AlphaCompressor__CreateInstance@@YGJPAPAUIRdpImageCompressor@@@Z (Ordinal: 14, Address: 0x645a0)
  • ?ClearCache@CRDPCache@@UAGJXZ (Ordinal: 15, Address: 0x9a010)
  • ?Compress@NSCodecCompressor@@QAE_NABVPixelMap@@_NPAEIAAI@Z (Ordinal: 16, Address: 0x651d0)
  • ?CompressRdp8__CreateInstance@@YGJPAPAVIRdpPipeCompress@@I@Z (Ordinal: 17, Address: 0x7eef0)
  • ?CreateInstance@CRDPENCONPort@@SGJPAUaddrinfo@@HPAXPAPAV1@@Z (Ordinal: 18, Address: 0xb6f40)
  • ?CreateInstance@CRdpGfxCapsSet@@SGJPAXKPAPAUIRdpGfxCapsSet@@@Z (Ordinal: 19, Address: 0x57490)
  • ?CreateInstance@Evict@@SGJKKKKKPAPAV1@@Z (Ordinal: 20, Address: 0x96360)
  • ?CreateInstance@HashTable@@SGJKKPAPAUIHashBucket@@@Z (Ordinal: 21, Address: 0x96d40)
  • ?CreateInstance@NSCodecCompressor@@SG_N_N00EAAV?$TCntPtr@VNSCodecCompressor@@@@@Z (Ordinal: 22, Address: 0x65970)
  • ?CreateInstance@PlanarCompressor@@SGJGGEHHHPAPAUIRdpImageCompressor@@@Z (Ordinal: 23, Address: 0x67460)
  • ?CreateInstance@RdpEncodeBuffer@@SGJPAVRdpEncodeBufferPool@@KPAPAV1@@Z (Ordinal: 24, Address: 0x56d00)
  • ?Decompress@NSCodecDecompressor@@QAE_NPBEIAAVPixelMap@@@Z (Ordinal: 25, Address: 0x659c0)
  • ?DecompressRdp8__CreateInstance@@YGJPAPAVIRdpPipeDecompress@@@Z (Ordinal: 26, Address: 0x7f600)
  • ?Enable@PipeETWEvents@@UAEJKK@Z (Ordinal: 27, Address: 0x93af0)
  • ?EvictEntry@Evict@@QAEPAU_SCORE_ENTRY@@XZ (Ordinal: 28, Address: 0x96450)
  • ?GetFreeEntry@Evict@@QAEPAU_SCORE_ENTRY@@XZ (Ordinal: 29, Address: 0x96510)
  • ?GetInstance@PipelineClock@@SGAAV1@XZ (Ordinal: 30, Address: 0x42f40)
  • ?GetMillisecondCount64@PipelineClock@@QAE_KXZ (Ordinal: 31, Address: 0x97530)
  • ?GetMillisecondCount@PipelineClock@@QAEIXZ (Ordinal: 32, Address: 0x97560)
  • ?GetNext@CRDPENCONIPHelper@@QAEPAU_SOCKET_ADDRESS@@XZ (Ordinal: 33, Address: 0xb7b00)
  • ?GetNext@CRDPENCONResolver@@QAEHPAPAUsockaddr@@PAI@Z (Ordinal: 34, Address: 0xb53e0)
  • ?GetPortMapping@CRDPENCConnectorStringDeserializer@@QAEJKPAPAGPAK@Z (Ordinal: 35, Address: 0xb6640)
  • ?GetTickCount@PipelineClock@@QAEIXZ (Ordinal: 36, Address: 0x44cb0)
  • ?GetTimeHNS@PipelineClock@@QAE_JXZ (Ordinal: 37, Address: 0x97590)
  • ?HintCoconet__CreateInstance@@YGJPAPAVIRdpPipeCompressHintProvider@@@Z (Ordinal: 38, Address: 0x7f960)
  • ?Initialize@CRDPENCONIPHelper@@QAEJKHPAG@Z (Ordinal: 39, Address: 0xb7b50)
  • ?Initialize@PipeETWEvents@@UAEJPAUIUnknown@@@Z (Ordinal: 40, Address: 0x94990)
  • ?InitializeInstance@CRDPENCConnectorStringSerializer@@UAGJXZ (Ordinal: 41, Address: 0xb67e0)
  • ?InsertEntry@Evict@@QAEXPAU_SCORE_ENTRY@@K@Z (Ordinal: 42, Address: 0x96930)
  • ?IsSupportedVersion@CRdpGfxCaps@@SGHK@Z (Ordinal: 43, Address: 0x57d50)
  • ?NSRunLengthDecode@@YGKPBEKPAEK@Z (Ordinal: 44, Address: 0x65fc0)
  • ?PAL_System_Win32_IsRunningInAppContainer@@YGHXZ (Ordinal: 45, Address: 0xde680)
  • ?ParkEntry@Evict@@QAEXPAU_SCORE_ENTRY@@@Z (Ordinal: 46, Address: 0x96a00)
  • ?ProcessAlignedData_AVX@SSECBCHash2@@AAEXPBIIII@Z (Ordinal: 47, Address: 0x88860)
  • ?ProcessAlignedData_SSE2@SSECBCHash2@@AAEXPBIIII@Z (Ordinal: 48, Address: 0x88d40)
  • ?ProcessAlignedData_SSE41@SSECBCHash2@@AAEXPBIIII@Z (Ordinal: 49, Address: 0x44420)
  • ?ProcessUnalignedData_REG@SSECBCHash2@@AAEXPBIIII@Z (Ordinal: 50, Address: 0x88fd0)
  • ?PromoteEntry@Evict@@QAEXKK@Z (Ordinal: 51, Address: 0x96a30)
  • ?RdpGfxProtocolServerEncoder_CreateInstance@@YGJPAVIRdpEncoderIO@@PAPAVIRdpPipeProtocolEncoderEx@@@Z (Ordinal: 52, Address: 0x99440)
  • ?RdpPerfLoggerStaticInitialize@@YGXXZ (Ordinal: 53, Address: 0xdd3d0)
  • ?RdpPerfLoggerStaticTerminate@@YGXXZ (Ordinal: 54, Address: 0xdd3e0)
  • ?Reset@CRDPCache@@UAGJI@Z (Ordinal: 55, Address: 0x9a210)
  • ?SearchCache@CRDPCache@@UAGJIIPAPAUIUnknown@@PAI@Z (Ordinal: 56, Address: 0x9a3f0)
  • ?SetCacheEntry@CRDPCache@@UAGJIIPAUIUnknown@@PAI@Z (Ordinal: 57, Address: 0x9a4f0)
  • ?SetConnectorId@CRDPENCConnectorStringSerializer@@UAGJK@Z (Ordinal: 58, Address: 0xb6910)
  • ?SetDecodeBuffer@RdpGfxProtocolBaseDecoder@@IAEXPBEI@Z (Ordinal: 59, Address: 0x57170)
  • ?SetSessionId@CRDPENCConnectorStringSerializer@@UAGJI@Z (Ordinal: 60, Address: 0xb6980)
  • ?SortAddresses@CRDPENCONResolver@@QAEJXZ (Ordinal: 61, Address: 0xb5df0)
  • ?StartEnum@CRDPENCONIPHelper@@QAEHXZ (Ordinal: 62, Address: 0xb7d30)
  • ?StartEnum@CRDPENCONResolver@@QAEIXZ (Ordinal: 63, Address: 0xb6210)
  • TSFree (Ordinal: 64, Address: 0x49fe0)
  • ?Terminate@CRDPENCONIPHelper@@QAEJXZ (Ordinal: 65, Address: 0xb7d60)
  • ?UnevictEntry@Evict@@QAEXPAU_SCORE_ENTRY@@@Z (Ordinal: 66, Address: 0x96c50)
  • ?UpdateKeys@SSECBCHash2@@ABEXXZ (Ordinal: 67, Address: 0x890b0)
  • ?XMLDeserialize@CRDPENCConnectorStringDeserializer@@QAEJPAG@Z (Ordinal: 68, Address: 0xb69f0)
  • ?XMLSerialize@CRDPENCConnectorStringSerializer@@UAGJPAPAG@Z (Ordinal: 69, Address: 0xb6d50)
  • ?XObjectId_RdpXHttpSession_CreateObject@@YG?AW4_XResult32@@PAURdpXInterface@@IW4_XInterfaceId32@@PAPAX@Z (Ordinal: 70, Address: 0x5f340)
  • ?XObjectId_RdpXInterfaceUriComponents_CreateObject@@YG?AW4_XResult32@@PAURdpXInterface@@IW4_XInterfaceId32@@PAPAX@Z (Ordinal: 71, Address: 0x5f3d0)
  • ApplyLuminanceFilter (Ordinal: 72, Address: 0x890f0)
  • ApplySobelFilterOnLum (Ordinal: 73, Address: 0x89130)
  • BitmapCombinePlanes (Ordinal: 74, Address: 0x68a50)
  • CAPAPI_AddCapSet (Ordinal: 75, Address: 0x7ac40)
  • CAPAPI_GetCapSet (Ordinal: 76, Address: 0x7ac70)
  • CAPAPI_InitializeCombinedCaps (Ordinal: 77, Address: 0x4a180)
  • CAPAPI_MergeCombinedCaps (Ordinal: 78, Address: 0x7acb0)
  • CRDPBitmapRecorder_CreateInstance (Ordinal: 79, Address: 0x9b3a0)
  • CRDPCacCodecEncoder_CreateInstance (Ordinal: 80, Address: 0x4ca20)
  • CRDPCacCodec_CreateInstance (Ordinal: 81, Address: 0x4cab0)
  • CRDPCacVideoCodecForHardwareClient_CreateInstance (Ordinal: 82, Address: 0x4cb90)
  • CRDPCacVideoCodec_CreateInstance (Ordinal: 83, Address: 0x4cbf0)
  • CRDPCaps_CreateInstance (Ordinal: 84, Address: 0x496f0)
  • CRDPENCGfxEncoder_CreateInstance (Ordinal: 85, Address: 0x9ce40)
  • CRDPNsCodec_CreateInstance (Ordinal: 86, Address: 0x66eb0)
  • CRDPPlanarCompressor_CreateInstance (Ordinal: 87, Address: 0x67ce0)
  • CRdpFIPSEncryption_CreateInstance (Ordinal: 88, Address: 0x90f20)
  • DecryptData (Ordinal: 89, Address: 0x109ad0)
  • DecryptDataEx (Ordinal: 90, Address: 0x109b40)
  • DrawBox (Ordinal: 91, Address: 0x89740)
  • DrawHLine (Ordinal: 92, Address: 0x897a0)
  • DrawIconToPixelMap (Ordinal: 93, Address: 0x89830)
  • DrawVLine (Ordinal: 94, Address: 0x89890)
  • EncryptClientRandom (Ordinal: 95, Address: 0x109c10)
  • EncryptData (Ordinal: 96, Address: 0x109bd0)
  • ExpandRectForSSE (Ordinal: 97, Address: 0x89c80)
  • GetSupportedSSELevel_SSE (Ordinal: 98, Address: 0x89f10)
  • GridBA_CreateInstance (Ordinal: 99, Address: 0x8bfd0)
  • MakeSessionKeys (Ordinal: 100, Address: 0x10a110)
  • MemCopyAligned_SSE (Ordinal: 101, Address: 0x49810)
  • MemEqual (Ordinal: 102, Address: 0x454c0)
  • MemMoveReverseAligned_SSE (Ordinal: 103, Address: 0x89f20)
  • PAL_System_AtomicCompareAndExchange (Ordinal: 104, Address: 0x38c30)
  • PAL_System_AtomicCompareAndExchangePointer (Ordinal: 105, Address: 0x920b0)
  • PAL_System_AtomicDecrement (Ordinal: 106, Address: 0x377f0)
  • PAL_System_AtomicExchange (Ordinal: 107, Address: 0x920e0)
  • PAL_System_AtomicExchangeAdd (Ordinal: 108, Address: 0x92100)
  • PAL_System_AtomicExchangePointer (Ordinal: 109, Address: 0x92130)
  • PAL_System_AtomicIncrement (Ordinal: 110, Address: 0x2bef0)
  • PAL_System_Beep (Ordinal: 111, Address: 0xe0280)
  • PAL_System_CondAlloc (Ordinal: 112, Address: 0x92150)
  • PAL_System_CondReset (Ordinal: 113, Address: 0x92190)
  • PAL_System_CondSignal (Ordinal: 114, Address: 0x4a470)
  • PAL_System_CondWait (Ordinal: 115, Address: 0x3bc20)
  • PAL_System_ConvertToAndFromWideChar (Ordinal: 116, Address: 0xe1520)
  • PAL_System_CreateGuid (Ordinal: 117, Address: 0xe1570)
  • PAL_System_CredProtect (Ordinal: 118, Address: 0xe02a0)
  • PAL_System_CredUnprotect (Ordinal: 119, Address: 0xe02c0)
  • PAL_System_CritSecEnter (Ordinal: 120, Address: 0x2d830)
  • PAL_System_CritSecInit (Ordinal: 121, Address: 0x34d90)
  • PAL_System_CritSecIsLockedByCurrentThread (Ordinal: 122, Address: 0x921c0)
  • PAL_System_CritSecLeave (Ordinal: 123, Address: 0x2fc00)
  • PAL_System_CritSecTerminate (Ordinal: 124, Address: 0x408b0)
  • PAL_System_CritSecTryEnter (Ordinal: 125, Address: 0x921f0)
  • PAL_System_CryptDecryptLegacy (Ordinal: 126, Address: 0xe02e0)
  • PAL_System_CryptEncrypt (Ordinal: 127, Address: 0xe0300)
  • PAL_System_CryptFree (Ordinal: 128, Address: 0xe0320)
  • PAL_System_CryptZeroMemory (Ordinal: 129, Address: 0xe1590)
  • PAL_System_DebugBreak (Ordinal: 130, Address: 0x90070)
  • PAL_System_DebugOutput (Ordinal: 131, Address: 0x90080)
  • PAL_System_GetComputerName (Ordinal: 132, Address: 0xe0390)
  • PAL_System_GetFIPSAlgorithmEnabled (Ordinal: 133, Address: 0x900b0)
  • PAL_System_GetLocalSessionId (Ordinal: 134, Address: 0xe03b0)
  • PAL_System_GetModuleFilename (Ordinal: 135, Address: 0x901b0)
  • PAL_System_GetNetworkStatus (Ordinal: 136, Address: 0xe0420)
  • PAL_System_GetNumberOfProcessors (Ordinal: 137, Address: 0x4aaa0)
  • PAL_System_GetWindowsProductId (Ordinal: 138, Address: 0xe0830)
  • PAL_System_HandleFree (Ordinal: 139, Address: 0x44040)
  • PAL_System_MemAlloc (Ordinal: 140, Address: 0x4a3c0)
  • PAL_System_MemFree (Ordinal: 141, Address: 0x49fe0)
  • PAL_System_NetworkMonitorInit (Ordinal: 142, Address: 0xe08a0)
  • PAL_System_NetworkMonitorNotification (Ordinal: 143, Address: 0xe15c0)
  • PAL_System_NetworkMonitorTerminate (Ordinal: 144, Address: 0xe0c10)
  • PAL_System_SecureZeroMemory (Ordinal: 145, Address: 0xe15e0)
  • PAL_System_SemaphoreAcquire (Ordinal: 146, Address: 0x92430)
  • PAL_System_SemaphoreAlloc (Ordinal: 147, Address: 0x42fa0)
  • PAL_System_SemaphoreRelease (Ordinal: 148, Address: 0x2bf40)
  • PAL_System_SingleCondWait (Ordinal: 149, Address: 0x924c0)
  • PAL_System_Sleep (Ordinal: 150, Address: 0x902b0)
  • PAL_System_SwitchToThread (Ordinal: 151, Address: 0x902c0)
  • PAL_System_ThreadGetId (Ordinal: 152, Address: 0x41640)
  • PAL_System_TimeGetCurrent (Ordinal: 153, Address: 0x92510)
  • PAL_System_TimeGetDynamicTimeZoneInformation (Ordinal: 154, Address: 0xe0c80)
  • PAL_System_TimeGetTickCount64 (Ordinal: 155, Address: 0x92570)
  • PAL_System_TimeGetTickCount (Ordinal: 156, Address: 0x4a970)
  • PAL_System_TimeGetTimeZoneInformation (Ordinal: 157, Address: 0xe1610)
  • PAL_System_TimerCancel (Ordinal: 158, Address: 0xe0e40)
  • PAL_System_TimerDelete (Ordinal: 159, Address: 0xe1000)
  • PAL_System_TimerInit (Ordinal: 160, Address: 0xe1060)
  • PAL_System_TimerIsSet (Ordinal: 161, Address: 0xe1180)
  • PAL_System_TimerSet (Ordinal: 162, Address: 0xe11e0)
  • PAL_System_WideCharToUnicode16 (Ordinal: 163, Address: 0xe1720)
  • RDPAPI_GetGenericCounter (Ordinal: 164, Address: 0x370d0)
  • RDPAPI_GetGlobalObject (Ordinal: 165, Address: 0x3b280)
  • RDPAPI_GetLongCounter (Ordinal: 166, Address: 0xa95d0)
  • RDPBASE_CreateInstance (Ordinal: 167, Address: 0x334a0)
  • RDPCompress (Ordinal: 168, Address: 0x607d0)
  • RDPCompressEx (Ordinal: 169, Address: 0x60840)
  • RDPCompress_GetContextSize (Ordinal: 170, Address: 0x608b0)
  • RDPCompress_InitRecvContext (Ordinal: 171, Address: 0x608f0)
  • RDPCompress_InitSendContext (Ordinal: 172, Address: 0x60950)
  • RDPDeCompress_GetContextSize (Ordinal: 173, Address: 0x609a0)
  • RDPDecompress (Ordinal: 174, Address: 0x609f0)
  • RDPENCDirectConnector_CreateInstance (Ordinal: 175, Address: 0xb9750)
  • RDPENCGDIHLP_FlipBitmapBits (Ordinal: 176, Address: 0xa9840)
  • RDPENCGDIHLP_FlipBitmapBitsInPlace (Ordinal: 177, Address: 0xa98e0)
  • RDPENCGDIHLP_ValidatePointerParams (Ordinal: 178, Address: 0xa9af0)
  • RDPENCHLPREG_ReadValueDWORD (Ordinal: 179, Address: 0x3c450)
  • RDPENCHLPWSErr2Hr (Ordinal: 180, Address: 0x2d860)
  • RDPENCHLPWS_GetIPFromAddr (Ordinal: 181, Address: 0x49a00)
  • RDPENCHLPWS_GetPortFromAddr (Ordinal: 182, Address: 0x43fb0)
  • RDPENCHLP_GetInputDesktopName (Ordinal: 183, Address: 0xa9eb0)
  • RDPENCHLP_IsGreaterThanOrEqWin8 (Ordinal: 184, Address: 0xa9fa0)
  • RDPENCHLP_IsSessionActive (Ordinal: 185, Address: 0xaa050)
  • RDPENCHLP_IsSessionRemote (Ordinal: 186, Address: 0xaa160)
  • RDPENCHLP_TraceWindowInfo (Ordinal: 187, Address: 0xaa230)
  • RDPENCORE_AddGlobalObject (Ordinal: 188, Address: 0xaab20)
  • RDPServerStackDiagnostics_LogCheckpoint (Ordinal: 189, Address: 0xdd9e0)
  • RDPServerStackDiagnostics_LogDisconnect (Ordinal: 190, Address: 0xdda50)
  • RDPServerStackDiagnostics_LogFailure (Ordinal: 191, Address: 0xddaf0)
  • RDPServerStackDiagnostics_Register (Ordinal: 192, Address: 0xddbc0)
  • RDPServerStackDiagnostics_Unregister (Ordinal: 193, Address: 0xddbf0)
  • RDPWSStreamConnector_CreateInstance (Ordinal: 194, Address: 0xdd000)
  • RDP_HMACMD5Final (Ordinal: 195, Address: 0x10a440)
  • RDP_HMACMD5Init (Ordinal: 196, Address: 0x10a480)
  • RDP_HMACMD5Update (Ordinal: 197, Address: 0x10a4f0)
  • RDP_MD5Final (Ordinal: 198, Address: 0x10a530)
  • RDP_MD5Init (Ordinal: 199, Address: 0x10a570)
  • RDP_MD5Update (Ordinal: 200, Address: 0x10a4f0)
  • RDP_RC4 (Ordinal: 201, Address: 0x10a5f0)
  • RDP_RC4AllocKey (Ordinal: 202, Address: 0x10a630)
  • RDP_RC4FreeKey (Ordinal: 203, Address: 0x10a670)
  • RDP_RC4SetKey (Ordinal: 204, Address: 0x10a6a0)
  • RDP_RC4ZeroKey (Ordinal: 205, Address: 0x10a720)
  • RDP_RsaBCryptDecryptPrivate (Ordinal: 206, Address: 0x10a740)
  • RDP_RsaBCryptGenerateRsaKeyPair (Ordinal: 207, Address: 0x10a820)
  • RDP_RsaBCryptPubKeyToBSafePubKey (Ordinal: 208, Address: 0x10a990)
  • RDP_RsaBSafeEncPublic (Ordinal: 209, Address: 0x10aa60)
  • RDP_RsaGetPublicKeyDataLength (Ordinal: 210, Address: 0x10abe0)
  • RDP_RsaGetPublicKeyLength (Ordinal: 211, Address: 0x10ac10)
  • RDP_SHAFinal (Ordinal: 212, Address: 0x10ac40)
  • RDP_SHAInit (Ordinal: 213, Address: 0x10ac80)
  • RDP_SHAUpdate (Ordinal: 214, Address: 0x10a4f0)
  • RdpIntersectRect (Ordinal: 215, Address: 0x89ce0)
  • RdpTiledSurface_CreateInstance (Ordinal: 216, Address: 0x9e780)
  • RdpUnionRect (Ordinal: 217, Address: 0x89d30)
  • RdpX_AtomicDecrement32 (Ordinal: 218, Address: 0x496d0)
  • RdpX_AtomicIncrement32 (Ordinal: 219, Address: 0x45ab0)
  • RdpX_DateTime_GetHighResolutionTimeSinceReboot (Ordinal: 220, Address: 0x56a20)
  • RdpX_DebugBreak (Ordinal: 221, Address: 0x56a90)
  • RdpX_GetActivityIdPrefix (Ordinal: 222, Address: 0x56aa0)
  • RdpX_Threading_CreateCriticalSection (Ordinal: 223, Address: 0x4a0b0)
  • RgnlibBA_CreateInstance (Ordinal: 224, Address: 0x8dc60)
  • SaveImageToFile (Ordinal: 225, Address: 0x89930)
  • SubtractRects (Ordinal: 226, Address: 0x89d90)
  • TRC_TraceBufferW (Ordinal: 227, Address: 0x64430)
  • TSAlloc (Ordinal: 228, Address: 0x88840)
  • TSCreateBaseServices (Ordinal: 229, Address: 0x81fe0)
  • TSCreateCoreEvents (Ordinal: 230, Address: 0x84860)
  • TSCreatePlatform (Ordinal: 231, Address: 0x85c70)
  • TSDbgAssertThread (Ordinal: 232, Address: 0x85d00)
  • TSRNG_GenerateRandomBits (Ordinal: 233, Address: 0x10a360)
  • TsAddRectsToRegion (Ordinal: 234, Address: 0x92970)
  • TsCreateRegion (Ordinal: 235, Address: 0x92a40)
  • TsDestroyRegion (Ordinal: 236, Address: 0x92b40)
  • TsGetRegionBoundingBox (Ordinal: 237, Address: 0x92c60)
  • TsGetRegionRectCount (Ordinal: 238, Address: 0x92cd0)
  • TsGetRegionRects (Ordinal: 239, Address: 0x92d20)
  • TsSetRegionFromRects (Ordinal: 240, Address: 0x92dd0)
  • UnpackServerCert (Ordinal: 241, Address: 0x109d10)
  • UpdateSessionKey (Ordinal: 242, Address: 0x10a2f0)
  • ValidateServerCert (Ordinal: 243, Address: 0x109dd0)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x10130160)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x10130168)
  • CoCreateGuid (Address: 0x1013016c)
  • CoCreateInstance (Address: 0x10130170)
  • IIDFromString (Address: 0x10130178)
  • StringFromGUID2 (Address: 0x10130174)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x10130180)
  • IsDebuggerPresent (Address: 0x10130188)
  • OutputDebugStringW (Address: 0x10130184)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x10130190)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x10130198)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x101301b0)
  • RaiseException (Address: 0x101301ac)
  • SetLastError (Address: 0x101301a0)
  • SetUnhandledExceptionFilter (Address: 0x101301a8)
  • UnhandledExceptionFilter (Address: 0x101301a4)
api-ms-win-core-featurestaging-l1-1-0.dll
  • GetFeatureEnabledState (Address: 0x101301c0)
  • RecordFeatureUsage (Address: 0x101301c4)
  • SubscribeFeatureStateChangeNotification (Address: 0x101301b8)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x101301bc)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x101301d0)
  • ReadFile (Address: 0x101301cc)
  • WriteFile (Address: 0x101301d4)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x101301dc)
  • DuplicateHandle (Address: 0x101301e0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x101301e8)
  • HeapAlloc (Address: 0x101301f0)
  • HeapFree (Address: 0x101301ec)
api-ms-win-core-heap-l2-1-0.dll
  • GlobalFree (Address: 0x101301fc)
  • LocalAlloc (Address: 0x101301f8)
  • LocalFree (Address: 0x10130200)
api-ms-win-core-io-l1-1-0.dll
  • GetOverlappedResult (Address: 0x10130208)
api-ms-win-core-io-l1-1-1.dll
  • CancelIo (Address: 0x10130210)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x10130218)
  • WTSGetActiveConsoleSessionId (Address: 0x1013021c)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
  • VerifyVersionInfoW (Address: 0x10130224)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x10130244)
  • FreeLibrary (Address: 0x10130254)
  • FreeLibraryAndExitThread (Address: 0x1013022c)
  • GetModuleFileNameA (Address: 0x10130238)
  • GetModuleFileNameW (Address: 0x1013023c)
  • GetModuleHandleA (Address: 0x10130248)
  • GetModuleHandleExA (Address: 0x10130230)
  • GetModuleHandleExW (Address: 0x10130250)
  • GetModuleHandleW (Address: 0x1013024c)
  • GetProcAddress (Address: 0x10130240)
  • LoadLibraryExW (Address: 0x10130234)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryW (Address: 0x1013025c)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x10130264)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x1013026c)
  • MapViewOfFileEx (Address: 0x10130270)
  • UnmapViewOfFile (Address: 0x10130274)
  • VirtualAlloc (Address: 0x10130278)
  • VirtualFree (Address: 0x1013027c)
api-ms-win-core-namedpipe-l1-1-0.dll
  • ConnectNamedPipe (Address: 0x1013028c)
  • CreateNamedPipeW (Address: 0x10130290)
  • DisconnectNamedPipe (Address: 0x10130288)
  • WaitNamedPipeW (Address: 0x10130284)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x101302b0)
  • GetCurrentProcess (Address: 0x101302cc)
  • GetCurrentProcessId (Address: 0x101302d8)
  • GetCurrentThread (Address: 0x101302ac)
  • GetCurrentThreadId (Address: 0x10130298)
  • GetExitCodeThread (Address: 0x101302bc)
  • OpenProcessToken (Address: 0x1013029c)
  • OpenThread (Address: 0x101302b8)
  • OpenThreadToken (Address: 0x101302a0)
  • ProcessIdToSessionId (Address: 0x101302a8)
  • SetThreadPriority (Address: 0x101302a4)
  • SwitchToThread (Address: 0x101302c4)
  • TerminateProcess (Address: 0x101302c8)
  • TlsAlloc (Address: 0x101302d0)
  • TlsFree (Address: 0x101302c0)
  • TlsGetValue (Address: 0x101302d4)
  • TlsSetValue (Address: 0x101302b4)
api-ms-win-core-processthreads-l1-1-1.dll
  • GetProcessMitigationPolicy (Address: 0x101302e4)
  • IsProcessorFeaturePresent (Address: 0x101302e0)
api-ms-win-core-processtopology-obsolete-l1-1-0.dll
  • SetThreadAffinityMask (Address: 0x101302ec)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x101302f4)
  • QueryPerformanceFrequency (Address: 0x101302f8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x10130308)
  • RegEnumKeyExW (Address: 0x10130314)
  • RegGetValueW (Address: 0x10130300)
  • RegOpenKeyExW (Address: 0x1013030c)
  • RegQueryInfoKeyW (Address: 0x10130310)
  • RegQueryValueExW (Address: 0x10130304)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x10130320)
  • WideCharToMultiByte (Address: 0x1013031c)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x10130344)
  • AcquireSRWLockShared (Address: 0x10130380)
  • CancelWaitableTimer (Address: 0x1013038c)
  • CreateEventW (Address: 0x10130340)
  • CreateMutexExW (Address: 0x10130360)
  • CreateSemaphoreExW (Address: 0x10130354)
  • CreateWaitableTimerExW (Address: 0x1013037c)
  • DeleteCriticalSection (Address: 0x1013036c)
  • EnterCriticalSection (Address: 0x10130328)
  • InitializeCriticalSection (Address: 0x1013033c)
  • InitializeCriticalSectionAndSpinCount (Address: 0x10130388)
  • InitializeCriticalSectionEx (Address: 0x10130334)
  • InitializeSRWLock (Address: 0x10130378)
  • LeaveCriticalSection (Address: 0x10130330)
  • OpenEventW (Address: 0x10130358)
  • OpenSemaphoreW (Address: 0x10130384)
  • ReleaseMutex (Address: 0x1013032c)
  • ReleaseSemaphore (Address: 0x1013034c)
  • ReleaseSRWLockExclusive (Address: 0x10130364)
  • ReleaseSRWLockShared (Address: 0x10130370)
  • ResetEvent (Address: 0x1013035c)
  • SetEvent (Address: 0x10130350)
  • SetWaitableTimer (Address: 0x10130390)
  • TryEnterCriticalSection (Address: 0x10130374)
  • WaitForMultipleObjectsEx (Address: 0x10130348)
  • WaitForSingleObject (Address: 0x10130338)
  • WaitForSingleObjectEx (Address: 0x10130368)
api-ms-win-core-synch-l1-2-0.dll
  • InitializeConditionVariable (Address: 0x101303ac)
  • Sleep (Address: 0x1013039c)
  • SleepConditionVariableCS (Address: 0x101303a8)
  • SleepConditionVariableSRW (Address: 0x101303a0)
  • WakeAllConditionVariable (Address: 0x10130398)
  • WakeConditionVariable (Address: 0x101303a4)
api-ms-win-core-synch-l1-2-1.dll
  • CreateSemaphoreW (Address: 0x101303b8)
  • CreateWaitableTimerW (Address: 0x101303b4)
  • WaitForMultipleObjects (Address: 0x101303bc)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetLocalTime (Address: 0x101303c4)
  • GetSystemDirectoryW (Address: 0x101303d0)
  • GetSystemInfo (Address: 0x101303d4)
  • GetSystemTime (Address: 0x101303e4)
  • GetSystemTimeAsFileTime (Address: 0x101303c8)
  • GetTickCount (Address: 0x101303e0)
  • GetTickCount64 (Address: 0x101303cc)
  • GetVersion (Address: 0x101303dc)
  • GetVersionExW (Address: 0x101303d8)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetNativeSystemInfo (Address: 0x101303ec)
  • VerSetConditionMask (Address: 0x101303f0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CancelThreadpoolIo (Address: 0x10130400)
  • CloseThreadpoolIo (Address: 0x10130408)
  • CloseThreadpoolTimer (Address: 0x1013041c)
  • CloseThreadpoolWork (Address: 0x10130424)
  • CreateThreadpoolIo (Address: 0x1013040c)
  • CreateThreadpoolTimer (Address: 0x101303f8)
  • CreateThreadpoolWork (Address: 0x10130418)
  • SetThreadpoolTimer (Address: 0x10130404)
  • StartThreadpoolIo (Address: 0x101303fc)
  • SubmitThreadpoolWork (Address: 0x10130420)
  • WaitForThreadpoolIoCallbacks (Address: 0x10130410)
  • WaitForThreadpoolTimerCallbacks (Address: 0x10130414)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x10130430)
  • DeleteTimerQueueTimer (Address: 0x1013042c)
  • QueueUserWorkItem (Address: 0x10130434)
api-ms-win-core-timezone-l1-1-0.dll
  • GetTimeZoneInformation (Address: 0x10130440)
  • SystemTimeToFileTime (Address: 0x1013043c)
api-ms-win-core-util-l1-1-0.dll
  • Beep (Address: 0x10130448)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x10130454)
  • RoGetActivationFactory (Address: 0x1013045c)
  • RoInitialize (Address: 0x10130458)
  • RoUninitialize (Address: 0x10130450)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x10130468)
  • WindowsDeleteString (Address: 0x10130464)
  • WindowsGetStringRawBuffer (Address: 0x1013046c)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • GetTraceEnableFlags (Address: 0x10130488)
  • GetTraceEnableLevel (Address: 0x10130484)
  • GetTraceLoggerHandle (Address: 0x1013047c)
  • RegisterTraceGuidsW (Address: 0x10130474)
  • TraceMessage (Address: 0x10130478)
  • UnregisterTraceGuids (Address: 0x10130480)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x10130498)
  • EventRegister (Address: 0x10130494)
  • EventUnregister (Address: 0x10130490)
  • EventWriteTransfer (Address: 0x1013049c)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x101304d0)
  • AllocateAndInitializeSid (Address: 0x101304a4)
  • CopySid (Address: 0x101304c4)
  • DuplicateToken (Address: 0x101304ac)
  • FreeSid (Address: 0x101304bc)
  • GetLengthSid (Address: 0x101304c8)
  • GetSecurityDescriptorLength (Address: 0x101304b4)
  • GetTokenInformation (Address: 0x101304c0)
  • InitializeAcl (Address: 0x101304cc)
  • InitializeSecurityDescriptor (Address: 0x101304a8)
  • MakeSelfRelativeSD (Address: 0x101304b8)
  • SetSecurityDescriptorDacl (Address: 0x101304b0)
api-ms-win-security-credentials-l1-1-0.dll
  • CredProtectW (Address: 0x101304dc)
  • CredUnprotectW (Address: 0x101304d8)
api-ms-win-security-cryptoapi-l1-1-0.dll
  • CryptAcquireContextW (Address: 0x101304f0)
  • CryptCreateHash (Address: 0x101304e4)
  • CryptDecrypt (Address: 0x101304e8)
  • CryptDestroyHash (Address: 0x101304fc)
  • CryptDestroyKey (Address: 0x10130508)
  • CryptGenRandom (Address: 0x101304ec)
  • CryptGetHashParam (Address: 0x101304f4)
  • CryptGetUserKey (Address: 0x101304f8)
  • CryptHashData (Address: 0x10130504)
  • CryptReleaseContext (Address: 0x10130500)
api-ms-win-security-provider-l1-1-0.dll
  • SetEntriesInAclW (Address: 0x10130510)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertStringSidToSidW (Address: 0x10130518)
api-ms-win-security-systemfunctions-l1-1-0.dll
  • SystemFunction036 (Address: 0x10130520)
AUTHZ.dll
  • AuthziSourceAudit (Address: 0x10130000)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x10130560)
  • BCryptCreateHash (Address: 0x10130558)
  • BCryptDecrypt (Address: 0x10130528)
  • BCryptDestroyHash (Address: 0x1013053c)
  • BCryptDestroyKey (Address: 0x10130564)
  • BCryptEncrypt (Address: 0x10130548)
  • BCryptExportKey (Address: 0x10130554)
  • BCryptFinalizeKeyPair (Address: 0x10130534)
  • BCryptFinishHash (Address: 0x10130538)
  • BCryptGenerateKeyPair (Address: 0x1013052c)
  • BCryptGenerateSymmetricKey (Address: 0x1013055c)
  • BCryptGetFipsAlgorithmMode (Address: 0x10130568)
  • BCryptGetProperty (Address: 0x10130550)
  • BCryptHashData (Address: 0x10130544)
  • BCryptImportKey (Address: 0x1013054c)
  • BCryptImportKeyPair (Address: 0x10130540)
  • BCryptOpenAlgorithmProvider (Address: 0x10130530)
CRYPT32.dll
  • CertCloseStore (Address: 0x10130014)
  • CertDuplicateCertificateContext (Address: 0x1013001c)
  • CertFindCertificateInStore (Address: 0x10130010)
  • CertFreeCertificateContext (Address: 0x10130018)
  • CertGetCertificateContextProperty (Address: 0x10130030)
  • CertGetIssuerCertificateFromStore (Address: 0x1013002c)
  • CertGetNameStringW (Address: 0x10130024)
  • CertOpenStore (Address: 0x1013000c)
  • CryptAcquireCertificatePrivateKey (Address: 0x10130028)
  • CryptProtectMemory (Address: 0x10130034)
  • CryptStringToBinaryW (Address: 0x10130020)
  • CryptUnprotectData (Address: 0x10130008)
IPHLPAPI.DLL
  • CreateSortedAddressPairs (Address: 0x1013003c)
  • FreeMibTable (Address: 0x10130040)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x1013058c)
  • __dllonexit (Address: 0x101305f8)
  • __RTDynamicCast (Address: 0x10130594)
  • _aligned_free (Address: 0x10130580)
  • _aligned_malloc (Address: 0x10130584)
  • _amsg_exit (Address: 0x10130608)
  • _callnewh (Address: 0x10130614)
  • _CIsqrt (Address: 0x10130574)
  • _except_handler4_common (Address: 0x101305e8)
  • _ftol2 (Address: 0x10130598)
  • _ftol2_sse (Address: 0x10130570)
  • _initterm (Address: 0x10130604)
  • _itoa_s (Address: 0x1013059c)
  • _lock (Address: 0x10130600)
  • _ltow_s (Address: 0x101305c8)
  • _onexit (Address: 0x101305ec)
  • _purecall (Address: 0x101305f0)
  • _snwprintf_s (Address: 0x101305d8)
  • _unlock (Address: 0x101305fc)
  • _vsnprintf (Address: 0x101305a8)
  • _vsnwprintf (Address: 0x1013061c)
  • _wcsicmp (Address: 0x10130588)
  • _wcsnicmp (Address: 0x101305a0)
  • _wfopen_s (Address: 0x101305b0)
  • _XcptFilter (Address: 0x1013060c)
  • ??1type_info@@UAE@XZ (Address: 0x101305d4)
  • ?terminate@@YAXXZ (Address: 0x101305d0)
  • fclose (Address: 0x101305b8)
  • free (Address: 0x10130610)
  • fwrite (Address: 0x101305b4)
  • malloc (Address: 0x10130618)
  • memcmp (Address: 0x101305c0)
  • memcpy (Address: 0x101305e4)
  • memcpy_s (Address: 0x10130578)
  • memmove (Address: 0x101305e0)
  • memmove_s (Address: 0x101305cc)
  • memset (Address: 0x10130620)
  • printf (Address: 0x101305bc)
  • rand_s (Address: 0x101305c4)
  • realloc (Address: 0x101305ac)
  • sprintf_s (Address: 0x101305f4)
  • wcschr (Address: 0x101305a4)
  • wcsnlen (Address: 0x101305dc)
  • wcsrchr (Address: 0x1013057c)
  • wcstok_s (Address: 0x10130590)
ncrypt.dll
  • NCryptDecrypt (Address: 0x10130628)
  • NCryptFreeObject (Address: 0x1013062c)
  • NCryptIsKeyHandle (Address: 0x10130630)
ntdll.dll
  • RtlGetLastNtStatus (Address: 0x10130640)
  • RtlIpv4StringToAddressW (Address: 0x1013063c)
  • RtlIpv6StringToAddressW (Address: 0x10130638)
  • RtlVerifyVersionInfo (Address: 0x10130644)
OLEAUT32.dll
  • SysAllocString (Address: 0x1013004c)
  • SysAllocStringByteLen (Address: 0x10130048)
  • SysAllocStringLen (Address: 0x10130064)
  • SysFreeString (Address: 0x10130060)
  • SysStringLen (Address: 0x1013006c)
  • VarBstrCat (Address: 0x1013005c)
  • VariantChangeType (Address: 0x10130050)
  • VariantClear (Address: 0x10130054)
  • VariantCopy (Address: 0x10130068)
  • VariantInit (Address: 0x10130058)
SspiCli.dll
  • AcceptSecurityContext (Address: 0x101300c0)
  • AcquireCredentialsHandleW (Address: 0x101300a8)
  • DecryptMessage (Address: 0x10130098)
  • DeleteSecurityContext (Address: 0x101300b0)
  • EncryptMessage (Address: 0x101300bc)
  • FreeContextBuffer (Address: 0x101300b4)
  • FreeCredentialsHandle (Address: 0x1013009c)
  • InitializeSecurityContextW (Address: 0x10130090)
  • InitSecurityInterfaceW (Address: 0x101300b8)
  • LogonUserExExW (Address: 0x101300a0)
  • LsaCallAuthenticationPackage (Address: 0x1013008c)
  • LsaConnectUntrusted (Address: 0x10130078)
  • LsaDeregisterLogonProcess (Address: 0x10130084)
  • LsaFreeReturnBuffer (Address: 0x10130088)
  • LsaLogonUser (Address: 0x101300c4)
  • LsaLookupAuthenticationPackage (Address: 0x1013007c)
  • QueryContextAttributesW (Address: 0x101300ac)
  • QuerySecurityPackageInfoW (Address: 0x10130094)
  • SeciAllocateAndSetIPAddress (Address: 0x10130074)
  • SeciFreeCallContext (Address: 0x10130080)
  • SetContextAttributesW (Address: 0x101300a4)
WS2_32.dll
  • accept (Address: 0x101300d8)
  • bind (Address: 0x1013011c)
  • closesocket (Address: 0x10130150)
  • connect (Address: 0x10130148)
  • FreeAddrInfoW (Address: 0x101300e0)
  • GetAddrInfoW (Address: 0x101300d4)
  • GetNameInfoW (Address: 0x10130114)
  • getpeername (Address: 0x101300f4)
  • getsockname (Address: 0x101300f8)
  • getsockopt (Address: 0x10130158)
  • htonl (Address: 0x10130104)
  • htons (Address: 0x1013013c)
  • listen (Address: 0x10130124)
  • ntohl (Address: 0x10130100)
  • ntohs (Address: 0x101300fc)
  • recv (Address: 0x10130120)
  • select (Address: 0x10130134)
  • send (Address: 0x10130144)
  • setsockopt (Address: 0x10130140)
  • shutdown (Address: 0x101300d0)
  • socket (Address: 0x101300e4)
  • WSAAddressToStringW (Address: 0x10130154)
  • WSACleanup (Address: 0x101300ec)
  • WSAEnumNetworkEvents (Address: 0x101300e8)
  • WSAEventSelect (Address: 0x10130128)
  • WSAGetLastError (Address: 0x10130118)
  • WSAIoctl (Address: 0x1013014c)
  • WSALookupServiceBeginW (Address: 0x101300dc)
  • WSALookupServiceEnd (Address: 0x1013010c)
  • WSALookupServiceNextW (Address: 0x10130108)
  • WSANSPIoctl (Address: 0x10130110)
  • WSARecv (Address: 0x10130138)
  • WSASend (Address: 0x101300cc)
  • WSASocketW (Address: 0x1013012c)
  • WSAStartup (Address: 0x101300f0)
  • WSAStringToAddressW (Address: 0x10130130)