comsvcs.dll

Description: COM+ Services

Authors: © Microsoft Corporation. All rights reserved.

Version: 2001.12.10941.16384

Architecture: 64-bit

Operating System: Windows NT

SHA256: c67f64745f886699a029028a8b0fc3eb

File Size: 1.6 MB

Uploaded At: Dec. 1, 2025, 7:24 a.m.

Views: 15

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • CosGetCallContext (Ordinal: 5, Address: 0x38f30)
  • (Ordinal: 6, Address: 0x2960)
  • (Ordinal: 7, Address: 0x41830)
  • CoCreateActivity (Ordinal: 8, Address: 0x415d0)
  • CoEnterServiceDomain (Ordinal: 9, Address: 0x2e320)
  • CoLeaveServiceDomain (Ordinal: 10, Address: 0x2e450)
  • CoLoadServices (Ordinal: 11, Address: 0x79630)
  • ComSvcsExceptionFilter (Ordinal: 12, Address: 0x26c00)
  • ComSvcsLogError (Ordinal: 13, Address: 0x32770)
  • DispManGetContext (Ordinal: 14, Address: 0x33f00)
  • DllCanUnloadNow (Ordinal: 15, Address: 0x26d30)
  • DllGetClassObject (Ordinal: 16, Address: 0x26d80)
  • DllRegisterServer (Ordinal: 17, Address: 0x2960)
  • DllUnregisterServer (Ordinal: 18, Address: 0x2960)
  • GetMTAThreadPoolMetrics (Ordinal: 19, Address: 0x27060)
  • GetManagedExtensions (Ordinal: 20, Address: 0x27100)
  • GetObjectContext (Ordinal: 21, Address: 0x32850)
  • GetTrkSvrObject (Ordinal: 22, Address: 0x271d0)
  • MTSCreateActivity (Ordinal: 23, Address: 0x418f0)
  • MiniDumpW (Ordinal: 24, Address: 0x272b0)
  • RecycleSurrogate (Ordinal: 25, Address: 0x32890)
  • SafeRef (Ordinal: 26, Address: 0x328a0)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromProgID (Address: 0x18011e168)
  • CLSIDFromString (Address: 0x18011e1b0)
  • CoCreateFreeThreadedMarshaler (Address: 0x18011e0c8)
  • CoCreateGuid (Address: 0x18011e128)
  • CoCreateInstance (Address: 0x18011e0d0)
  • CoCreateInstanceEx (Address: 0x18011e108)
  • CoDisconnectObject (Address: 0x18011e150)
  • CoFreeUnusedLibraries (Address: 0x18011e120)
  • CoGetCallContext (Address: 0x18011e0d8)
  • CoGetClassObject (Address: 0x18011e198)
  • CoGetCurrentLogicalThreadId (Address: 0x18011e160)
  • CoGetDefaultContext (Address: 0x18011e178)
  • CoGetMarshalSizeMax (Address: 0x18011e138)
  • CoGetObjectContext (Address: 0x18011e0b0)
  • CoImpersonateClient (Address: 0x18011e140)
  • CoInitializeEx (Address: 0x18011e148)
  • CoMarshalInterface (Address: 0x18011e130)
  • CoReleaseMarshalData (Address: 0x18011e188)
  • CoRevertToSelf (Address: 0x18011e118)
  • CoSetProxyBlanket (Address: 0x18011e1a0)
  • CoTaskMemAlloc (Address: 0x18011e1a8)
  • CoTaskMemFree (Address: 0x18011e0c0)
  • CoTaskMemRealloc (Address: 0x18011e0b8)
  • CoUninitialize (Address: 0x18011e190)
  • CoUnmarshalInterface (Address: 0x18011e180)
  • CoWaitForMultipleHandles (Address: 0x18011e0f8)
  • CreateStreamOnHGlobal (Address: 0x18011e170)
  • GetHGlobalFromStream (Address: 0x18011e100)
  • IIDFromString (Address: 0x18011e110)
  • ProgIDFromCLSID (Address: 0x18011e0f0)
  • StringFromCLSID (Address: 0x18011e0e8)
  • StringFromGUID2 (Address: 0x18011e158)
  • StringFromIID (Address: 0x18011e0e0)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • NdrProxyForwardingFunction10 (Address: 0x18011e2d8)
  • NdrProxyForwardingFunction11 (Address: 0x18011e2d0)
  • NdrProxyForwardingFunction12 (Address: 0x18011e2b8)
  • NdrProxyForwardingFunction3 (Address: 0x18011e268)
  • NdrProxyForwardingFunction4 (Address: 0x18011e230)
  • NdrProxyForwardingFunction5 (Address: 0x18011e238)
  • NdrProxyForwardingFunction6 (Address: 0x18011e218)
  • NdrProxyForwardingFunction7 (Address: 0x18011e1e0)
  • NdrProxyForwardingFunction8 (Address: 0x18011e2c8)
  • NdrProxyForwardingFunction9 (Address: 0x18011e2c0)
  • ObjectStublessClient10 (Address: 0x18011e258)
  • ObjectStublessClient11 (Address: 0x18011e200)
  • ObjectStublessClient12 (Address: 0x18011e1f0)
  • ObjectStublessClient13 (Address: 0x18011e220)
  • ObjectStublessClient14 (Address: 0x18011e1f8)
  • ObjectStublessClient15 (Address: 0x18011e210)
  • ObjectStublessClient16 (Address: 0x18011e260)
  • ObjectStublessClient17 (Address: 0x18011e250)
  • ObjectStublessClient18 (Address: 0x18011e208)
  • ObjectStublessClient19 (Address: 0x18011e228)
  • ObjectStublessClient20 (Address: 0x18011e288)
  • ObjectStublessClient21 (Address: 0x18011e2a0)
  • ObjectStublessClient22 (Address: 0x18011e270)
  • ObjectStublessClient23 (Address: 0x18011e290)
  • ObjectStublessClient24 (Address: 0x18011e2a8)
  • ObjectStublessClient25 (Address: 0x18011e2b0)
  • ObjectStublessClient26 (Address: 0x18011e298)
  • ObjectStublessClient27 (Address: 0x18011e278)
  • ObjectStublessClient28 (Address: 0x18011e280)
  • ObjectStublessClient3 (Address: 0x18011e1c8)
  • ObjectStublessClient4 (Address: 0x18011e1e8)
  • ObjectStublessClient5 (Address: 0x18011e1d8)
  • ObjectStublessClient6 (Address: 0x18011e1d0)
  • ObjectStublessClient7 (Address: 0x18011e1c0)
  • ObjectStublessClient8 (Address: 0x18011e240)
  • ObjectStublessClient9 (Address: 0x18011e248)
api-ms-win-core-com-private-l1-1-0.dll
  • CoDeactivateObject (Address: 0x18011e2f0)
  • CoGetApartmentID (Address: 0x18011e308)
  • CoGetProcessIdentifier (Address: 0x18011e318)
  • CoPopServiceDomain (Address: 0x18011e310)
  • CoPushServiceDomain (Address: 0x18011e300)
  • CoReactivateObject (Address: 0x18011e2e8)
  • CoRetireServer (Address: 0x18011e2f8)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18011e330)
  • IsDebuggerPresent (Address: 0x18011e338)
  • OutputDebugStringA (Address: 0x18011e340)
  • OutputDebugStringW (Address: 0x18011e328)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18011e350)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18011e360)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18011e380)
  • RaiseException (Address: 0x18011e378)
  • SetLastError (Address: 0x18011e370)
  • SetUnhandledExceptionFilter (Address: 0x18011e390)
  • UnhandledExceptionFilter (Address: 0x18011e388)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18011e408)
  • CreateDirectoryW (Address: 0x18011e400)
  • CreateFileW (Address: 0x18011e3e8)
  • DeleteFileW (Address: 0x18011e3a0)
  • FindClose (Address: 0x18011e410)
  • FindFirstFileW (Address: 0x18011e3f0)
  • FindNextFileW (Address: 0x18011e3b8)
  • GetDiskFreeSpaceExW (Address: 0x18011e3c0)
  • GetDriveTypeW (Address: 0x18011e3a8)
  • GetFileAttributesExW (Address: 0x18011e3d8)
  • GetFileAttributesW (Address: 0x18011e3c8)
  • GetLongPathNameW (Address: 0x18011e418)
  • GetVolumeInformationW (Address: 0x18011e3b0)
  • SetFileAttributesW (Address: 0x18011e3d0)
  • SetFilePointer (Address: 0x18011e3e0)
  • WriteFile (Address: 0x18011e3f8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18011e428)
  • DuplicateHandle (Address: 0x18011e430)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18011e450)
  • HeapAlloc (Address: 0x18011e440)
  • HeapDestroy (Address: 0x18011e458)
  • HeapFree (Address: 0x18011e448)
api-ms-win-core-heap-l2-1-0.dll
  • GlobalAlloc (Address: 0x18011e468)
  • GlobalFree (Address: 0x18011e470)
  • LocalAlloc (Address: 0x18011e480)
  • LocalFree (Address: 0x18011e478)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • GlobalLock (Address: 0x18011e490)
  • GlobalUnlock (Address: 0x18011e498)
api-ms-win-core-io-l1-1-0.dll
  • CreateIoCompletionPort (Address: 0x18011e4c0)
  • DeviceIoControl (Address: 0x18011e4a8)
  • GetQueuedCompletionStatus (Address: 0x18011e4b0)
  • PostQueuedCompletionStatus (Address: 0x18011e4b8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FindResourceExW (Address: 0x18011e520)
  • FreeLibrary (Address: 0x18011e510)
  • FreeLibraryAndExitThread (Address: 0x18011e4e0)
  • GetModuleFileNameA (Address: 0x18011e508)
  • GetModuleFileNameW (Address: 0x18011e530)
  • GetModuleHandleExW (Address: 0x18011e4d0)
  • GetModuleHandleW (Address: 0x18011e518)
  • GetProcAddress (Address: 0x18011e500)
  • LoadLibraryExW (Address: 0x18011e4f8)
  • LoadResource (Address: 0x18011e4d8)
  • LoadStringW (Address: 0x18011e4e8)
  • LockResource (Address: 0x18011e4f0)
  • SizeofResource (Address: 0x18011e528)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18011e540)
  • GetThreadLocale (Address: 0x18011e548)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualAlloc (Address: 0x18011e568)
  • VirtualProtect (Address: 0x18011e558)
  • VirtualQuery (Address: 0x18011e560)
api-ms-win-core-path-l1-1-0.dll
  • PathCchRemoveExtension (Address: 0x18011e578)
  • PathCchStripToRoot (Address: 0x18011e580)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18011e590)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessAsUserW (Address: 0x18011e5b0)
  • CreateProcessW (Address: 0x18011e608)
  • CreateThread (Address: 0x18011e5a8)
  • ExitProcess (Address: 0x18011e638)
  • GetCurrentProcess (Address: 0x18011e5c8)
  • GetCurrentProcessId (Address: 0x18011e600)
  • GetCurrentThread (Address: 0x18011e5f8)
  • GetCurrentThreadId (Address: 0x18011e5e8)
  • GetExitCodeProcess (Address: 0x18011e5f0)
  • GetExitCodeThread (Address: 0x18011e628)
  • GetThreadPriority (Address: 0x18011e618)
  • OpenProcessToken (Address: 0x18011e5c0)
  • OpenThreadToken (Address: 0x18011e5e0)
  • SetThreadPriority (Address: 0x18011e620)
  • SetThreadStackGuarantee (Address: 0x18011e5d8)
  • SetThreadToken (Address: 0x18011e630)
  • TerminateProcess (Address: 0x18011e640)
  • TlsAlloc (Address: 0x18011e5a0)
  • TlsFree (Address: 0x18011e610)
  • TlsGetValue (Address: 0x18011e5d0)
  • TlsSetValue (Address: 0x18011e5b8)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18011e650)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18011e660)
  • QueryPerformanceFrequency (Address: 0x18011e668)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18011e6a8)
  • RegCreateKeyExW (Address: 0x18011e690)
  • RegDeleteValueW (Address: 0x18011e678)
  • RegEnumKeyExW (Address: 0x18011e6b0)
  • RegEnumValueW (Address: 0x18011e698)
  • RegGetValueW (Address: 0x18011e680)
  • RegNotifyChangeKeyValue (Address: 0x18011e6a0)
  • RegOpenKeyExW (Address: 0x18011e6c8)
  • RegQueryInfoKeyW (Address: 0x18011e688)
  • RegQueryValueExW (Address: 0x18011e6c0)
  • RegSetValueExW (Address: 0x18011e6b8)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathRemoveFileSpecW (Address: 0x18011e6e0)
  • PathStripPathW (Address: 0x18011e6d8)
  • PathStripToRootW (Address: 0x18011e6e8)
api-ms-win-core-sidebyside-l1-1-0.dll
  • ActivateActCtx (Address: 0x18011e708)
  • CreateActCtxW (Address: 0x18011e700)
  • DeactivateActCtx (Address: 0x18011e710)
  • ReleaseActCtx (Address: 0x18011e6f8)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x18011e720)
  • WideCharToMultiByte (Address: 0x18011e728)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x18011e738)
  • CharPrevW (Address: 0x18011e740)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x18011e750)
  • lstrcpynW (Address: 0x18011e758)
  • lstrcpyW (Address: 0x18011e760)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18011e7a0)
  • AcquireSRWLockShared (Address: 0x18011e7e0)
  • CreateEventW (Address: 0x18011e810)
  • CreateMutexExW (Address: 0x18011e7d8)
  • CreateSemaphoreExW (Address: 0x18011e770)
  • DeleteCriticalSection (Address: 0x18011e820)
  • EnterCriticalSection (Address: 0x18011e790)
  • InitializeCriticalSection (Address: 0x18011e7e8)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18011e788)
  • InitializeCriticalSectionEx (Address: 0x18011e818)
  • LeaveCriticalSection (Address: 0x18011e808)
  • OpenEventW (Address: 0x18011e778)
  • OpenSemaphoreW (Address: 0x18011e7b8)
  • ReleaseMutex (Address: 0x18011e7f8)
  • ReleaseSemaphore (Address: 0x18011e780)
  • ReleaseSRWLockExclusive (Address: 0x18011e798)
  • ReleaseSRWLockShared (Address: 0x18011e7c8)
  • ResetEvent (Address: 0x18011e7b0)
  • SetEvent (Address: 0x18011e800)
  • SetWaitableTimerEx (Address: 0x18011e7d0)
  • WaitForMultipleObjectsEx (Address: 0x18011e7f0)
  • WaitForSingleObject (Address: 0x18011e7c0)
  • WaitForSingleObjectEx (Address: 0x18011e7a8)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18011e830)
api-ms-win-core-synch-l1-2-1.dll
  • CreateSemaphoreW (Address: 0x18011e840)
  • CreateWaitableTimerW (Address: 0x18011e848)
  • WaitForMultipleObjects (Address: 0x18011e850)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x18011e860)
  • GetLocalTime (Address: 0x18011e868)
  • GetSystemInfo (Address: 0x18011e890)
  • GetSystemTimeAsFileTime (Address: 0x18011e880)
  • GetSystemWindowsDirectoryW (Address: 0x18011e898)
  • GetTickCount (Address: 0x18011e878)
  • GetTickCount64 (Address: 0x18011e870)
  • GlobalMemoryStatusEx (Address: 0x18011e888)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18011e8b0)
  • CloseThreadpoolWork (Address: 0x18011e8c8)
  • CreateThreadpoolTimer (Address: 0x18011e8a8)
  • CreateThreadpoolWork (Address: 0x18011e8b8)
  • SetThreadpoolTimer (Address: 0x18011e8e0)
  • SubmitThreadpoolWork (Address: 0x18011e8c0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18011e8d0)
  • WaitForThreadpoolWorkCallbacks (Address: 0x18011e8d8)
api-ms-win-core-threadpool-private-l1-1-0.dll
  • RegisterWaitForSingleObjectEx (Address: 0x18011e8f0)
api-ms-win-core-version-l1-1-0.dll
  • VerQueryValueW (Address: 0x18011e900)
api-ms-win-eventing-consumer-l1-1-0.dll
  • CloseTrace (Address: 0x18011e918)
  • OpenTraceW (Address: 0x18011e920)
  • ProcessTrace (Address: 0x18011e910)
api-ms-win-eventing-controller-l1-1-0.dll
  • ControlTraceW (Address: 0x18011e930)
  • StartTraceW (Address: 0x18011e938)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheck (Address: 0x18011e9e8)
  • AddAccessAllowedAce (Address: 0x18011e990)
  • AddAccessAllowedAceEx (Address: 0x18011e998)
  • AddAce (Address: 0x18011e958)
  • AllocateAndInitializeSid (Address: 0x18011ea00)
  • CheckTokenMembership (Address: 0x18011e970)
  • CopySid (Address: 0x18011e9f8)
  • DeleteAce (Address: 0x18011e948)
  • DuplicateTokenEx (Address: 0x18011e9b0)
  • EqualSid (Address: 0x18011e978)
  • FreeSid (Address: 0x18011e9d0)
  • GetAce (Address: 0x18011e9d8)
  • GetAclInformation (Address: 0x18011e9e0)
  • GetLengthSid (Address: 0x18011e9c8)
  • GetSecurityDescriptorDacl (Address: 0x18011ea30)
  • GetSecurityDescriptorLength (Address: 0x18011ea18)
  • GetSidIdentifierAuthority (Address: 0x18011e9a8)
  • GetSidSubAuthority (Address: 0x18011e9f0)
  • GetSidSubAuthorityCount (Address: 0x18011ea10)
  • GetTokenInformation (Address: 0x18011ea28)
  • ImpersonateSelf (Address: 0x18011ea08)
  • InitializeAcl (Address: 0x18011e980)
  • InitializeSecurityDescriptor (Address: 0x18011e9b8)
  • IsValidSecurityDescriptor (Address: 0x18011ea20)
  • IsValidSid (Address: 0x18011e950)
  • RevertToSelf (Address: 0x18011e9c0)
  • SetKernelObjectSecurity (Address: 0x18011e988)
  • SetSecurityDescriptorControl (Address: 0x18011ea38)
  • SetSecurityDescriptorDacl (Address: 0x18011e960)
  • SetSecurityDescriptorGroup (Address: 0x18011e968)
  • SetSecurityDescriptorOwner (Address: 0x18011e9a0)
combase.dll
  • (Address: 0x18011ea48)
KERNEL32.dll
  • ChangeTimerQueueTimer (Address: 0x18011ddc0)
  • CreateTimerQueueTimer (Address: 0x18011ddd8)
  • DeleteTimerQueueTimer (Address: 0x18011dde0)
  • GetComputerNameW (Address: 0x18011dde8)
  • GetCurrentPackageId (Address: 0x18011de08)
  • MoveFileW (Address: 0x18011ddf0)
  • QueueUserWorkItem (Address: 0x18011de00)
  • RegisterWaitForSingleObject (Address: 0x18011ddd0)
  • UnregisterWait (Address: 0x18011ddf8)
  • UnregisterWaitEx (Address: 0x18011ddc8)
msvcrt.dll
  • __C_specific_handler (Address: 0x18011ebe8)
  • __CxxFrameHandler3 (Address: 0x18011ea88)
  • __dllonexit (Address: 0x18011eaa8)
  • __doserrno (Address: 0x18011eac0)
  • _amsg_exit (Address: 0x18011eb28)
  • _beginthreadex (Address: 0x18011eb88)
  • _CxxThrowException (Address: 0x18011eb48)
  • _initterm (Address: 0x18011ebf0)
  • _local_unwind (Address: 0x18011eb40)
  • _lock (Address: 0x18011eae0)
  • _onexit (Address: 0x18011eaa0)
  • _purecall (Address: 0x18011eb10)
  • _ultow (Address: 0x18011eb30)
  • _unlock (Address: 0x18011ead8)
  • _vsnprintf (Address: 0x18011ebc8)
  • _vsnprintf_s (Address: 0x18011eb70)
  • _vsnwprintf (Address: 0x18011eb00)
  • _waccess (Address: 0x18011ea90)
  • _wcsdup (Address: 0x18011ebc0)
  • _wcsicmp (Address: 0x18011ebe0)
  • _wcsupr (Address: 0x18011eaf0)
  • _wtoi (Address: 0x18011ebd8)
  • _XcptFilter (Address: 0x18011eb38)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18011ebb0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18011eb68)
  • ??0exception@@QEAA@XZ (Address: 0x18011eb60)
  • ??1exception@@UEAA@XZ (Address: 0x18011eb58)
  • ??1type_info@@UEAA@XZ (Address: 0x18011ea98)
  • ?terminate@@YAXXZ (Address: 0x18011eb20)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18011eb98)
  • exp (Address: 0x18011ea80)
  • free (Address: 0x18011ea70)
  • iswalpha (Address: 0x18011eab0)
  • iswdigit (Address: 0x18011eba0)
  • malloc (Address: 0x18011ea58)
  • mbstowcs (Address: 0x18011ea68)
  • memcmp (Address: 0x18011eb90)
  • memcpy (Address: 0x18011eb80)
  • memcpy_s (Address: 0x18011eb50)
  • memmove (Address: 0x18011eaf8)
  • memmove_s (Address: 0x18011eb08)
  • memset (Address: 0x18011eae8)
  • realloc (Address: 0x18011eba8)
  • sqrt (Address: 0x18011ead0)
  • time (Address: 0x18011eb78)
  • wcscat_s (Address: 0x18011eb18)
  • wcschr (Address: 0x18011ea78)
  • wcscmp (Address: 0x18011ebf8)
  • wcscpy_s (Address: 0x18011eab8)
  • wcsrchr (Address: 0x18011ea60)
  • wcsstr (Address: 0x18011ebb8)
  • wcstok_s (Address: 0x18011ebd0)
  • wcstombs (Address: 0x18011eac8)
ntdll.dll
  • EtwGetTraceEnableFlags (Address: 0x18011ec90)
  • EtwGetTraceEnableLevel (Address: 0x18011ec58)
  • EtwGetTraceLoggerHandle (Address: 0x18011ec80)
  • EtwLogTraceEvent (Address: 0x18011ecd8)
  • EtwNotificationRegister (Address: 0x18011ecc0)
  • EtwNotificationUnregister (Address: 0x18011ec78)
  • EtwRegisterTraceGuidsW (Address: 0x18011ec50)
  • EtwTraceMessage (Address: 0x18011ec88)
  • EtwUnregisterTraceGuids (Address: 0x18011ec98)
  • NtQuerySystemInformation (Address: 0x18011eca8)
  • RtlAllocateHeap (Address: 0x18011ec30)
  • RtlCaptureContext (Address: 0x18011ec70)
  • RtlCreateServiceSid (Address: 0x18011ecc8)
  • RtlDelete (Address: 0x18011eca0)
  • RtlDeleteCriticalSection (Address: 0x18011ec08)
  • RtlDllShutdownInProgress (Address: 0x18011ec40)
  • RtlFreeHeap (Address: 0x18011ec20)
  • RtlImageNtHeader (Address: 0x18011ec28)
  • RtlInitializeCriticalSectionAndSpinCount (Address: 0x18011ec10)
  • RtlInitUnicodeString (Address: 0x18011ecd0)
  • RtlLookupFunctionEntry (Address: 0x18011ec68)
  • RtlNtStatusToDosError (Address: 0x18011ecb0)
  • RtlReportException (Address: 0x18011ec38)
  • RtlSplay (Address: 0x18011ec18)
  • RtlVirtualUnwind (Address: 0x18011ec60)
  • ShipAssertMsgA (Address: 0x18011ecb8)
  • WinSqmSetDWORD (Address: 0x18011ec48)
ole32.dll
  • CoGetInterceptor (Address: 0x18011ed10)
  • CoGetObject (Address: 0x18011ed08)
  • CreateAntiMoniker (Address: 0x18011ed30)
  • CreateBindCtx (Address: 0x18011ed18)
  • CreateGenericComposite (Address: 0x18011ecf8)
  • MkParseDisplayName (Address: 0x18011ece8)
  • MonikerCommonPrefixWith (Address: 0x18011ecf0)
  • MonikerRelativePathTo (Address: 0x18011ed00)
  • OleLoadFromStream (Address: 0x18011ed28)
  • OleSaveToStream (Address: 0x18011ed20)
OLEAUT32.dll
  • BSTR_UserFree (Address: 0x18011df30)
  • BSTR_UserFree64 (Address: 0x18011de20)
  • BSTR_UserMarshal (Address: 0x18011de88)
  • BSTR_UserMarshal64 (Address: 0x18011de80)
  • BSTR_UserSize (Address: 0x18011df58)
  • BSTR_UserSize64 (Address: 0x18011de58)
  • BSTR_UserUnmarshal (Address: 0x18011df40)
  • BSTR_UserUnmarshal64 (Address: 0x18011df50)
  • CreateErrorInfo (Address: 0x18011de98)
  • GetErrorInfo (Address: 0x18011dea0)
  • LoadRegTypeLib (Address: 0x18011de18)
  • LoadTypeLib (Address: 0x18011df18)
  • LPSAFEARRAY_UserFree (Address: 0x18011df08)
  • LPSAFEARRAY_UserFree64 (Address: 0x18011def8)
  • LPSAFEARRAY_UserMarshal (Address: 0x18011dee0)
  • LPSAFEARRAY_UserMarshal64 (Address: 0x18011def0)
  • LPSAFEARRAY_UserSize (Address: 0x18011df10)
  • LPSAFEARRAY_UserSize64 (Address: 0x18011ded8)
  • LPSAFEARRAY_UserUnmarshal (Address: 0x18011df00)
  • LPSAFEARRAY_UserUnmarshal64 (Address: 0x18011dee8)
  • SafeArrayAccessData (Address: 0x18011deb8)
  • SafeArrayCreate (Address: 0x18011de48)
  • SafeArrayCreateVector (Address: 0x18011deb0)
  • SafeArrayDestroy (Address: 0x18011de50)
  • SafeArrayUnaccessData (Address: 0x18011dea8)
  • SetErrorInfo (Address: 0x18011de90)
  • SysAllocString (Address: 0x18011de78)
  • SysAllocStringByteLen (Address: 0x18011de28)
  • SysAllocStringLen (Address: 0x18011de38)
  • SysFreeString (Address: 0x18011df68)
  • SysStringByteLen (Address: 0x18011df60)
  • SysStringLen (Address: 0x18011de68)
  • VARIANT_UserFree (Address: 0x18011df70)
  • VARIANT_UserFree64 (Address: 0x18011df38)
  • VARIANT_UserMarshal (Address: 0x18011de40)
  • VARIANT_UserMarshal64 (Address: 0x18011dec8)
  • VARIANT_UserSize (Address: 0x18011de30)
  • VARIANT_UserSize64 (Address: 0x18011ded0)
  • VARIANT_UserUnmarshal (Address: 0x18011de60)
  • VARIANT_UserUnmarshal64 (Address: 0x18011df78)
  • VariantChangeType (Address: 0x18011df20)
  • VariantClear (Address: 0x18011dec0)
  • VariantCopy (Address: 0x18011df48)
  • VariantInit (Address: 0x18011de70)
  • VarUI4FromStr (Address: 0x18011df28)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x18011dfb8)
  • CStdStubBuffer_Connect (Address: 0x18011dfe8)
  • CStdStubBuffer_CountRefs (Address: 0x18011e030)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x18011dfc0)
  • CStdStubBuffer_DebugServerRelease (Address: 0x18011dfb0)
  • CStdStubBuffer_Disconnect (Address: 0x18011dfc8)
  • CStdStubBuffer_Invoke (Address: 0x18011dff8)
  • CStdStubBuffer_IsIIDSupported (Address: 0x18011dfd0)
  • CStdStubBuffer_QueryInterface (Address: 0x18011e020)
  • I_RpcBindingInqLocalClientPID (Address: 0x18011e038)
  • I_RpcBindingInqTransportType (Address: 0x18011e048)
  • I_RpcTurnOnEEInfoPropagation (Address: 0x18011e028)
  • IUnknown_AddRef_Proxy (Address: 0x18011df90)
  • IUnknown_QueryInterface_Proxy (Address: 0x18011dfa8)
  • IUnknown_Release_Proxy (Address: 0x18011e078)
  • MesDecodeBufferHandleCreate (Address: 0x18011e098)
  • MesEncodeDynBufferHandleCreate (Address: 0x18011df98)
  • MesHandleFree (Address: 0x18011df88)
  • NdrClientCall3 (Address: 0x18011dfa0)
  • NdrCStdStubBuffer_Release (Address: 0x18011e0a0)
  • NdrCStdStubBuffer2_Release (Address: 0x18011e060)
  • NdrDllCanUnloadNow (Address: 0x18011e088)
  • NdrDllGetClassObject (Address: 0x18011e070)
  • NdrMesTypeDecode3 (Address: 0x18011e018)
  • NdrMesTypeEncode3 (Address: 0x18011e040)
  • NdrOleAllocate (Address: 0x18011e010)
  • NdrOleFree (Address: 0x18011e068)
  • NdrStubCall3 (Address: 0x18011dfe0)
  • NdrStubForwardingFunction (Address: 0x18011e090)
  • RpcStringFreeA (Address: 0x18011dfd8)
  • RpcStringFreeW (Address: 0x18011e008)
  • UuidCreate (Address: 0x18011e050)
  • UuidCreateSequential (Address: 0x18011e058)
  • UuidFromStringW (Address: 0x18011e080)
  • UuidToStringA (Address: 0x18011e000)
  • UuidToStringW (Address: 0x18011dff0)