UserDataPlatformHelperUtil.dll

Description: Platform Utilities for data access

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: b74d8b20e252545d9992e513a4ad8834

File Size: 49.5 KB

Uploaded At: Dec. 1, 2025, 8:05 a.m.

Views: 8

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ??0CalculateSize@Comms@@QAE@_N0@Z (Ordinal: 1, Address: 0x32c0)
  • ??0Deserializer@Comms@@QAE@PBE0_N1@Z (Ordinal: 2, Address: 0x2b50)
  • ??0RpcClient@Comms@@QAE@XZ (Ordinal: 3, Address: 0x2de0)
  • ??0SecureRpcClient@Comms@@QAE@XZ (Ordinal: 4, Address: 0x2f20)
  • ??0SerializeBuffer@Comms@@QAE@ABVCalculateSize@1@_N1@Z (Ordinal: 5, Address: 0x3330)
  • ??1Deserializer@Comms@@QAE@XZ (Ordinal: 6, Address: 0x24e0)
  • ??1RpcClient@Comms@@QAE@XZ (Ordinal: 7, Address: 0x2e00)
  • ??1SecureRpcClient@Comms@@UAE@XZ (Ordinal: 8, Address: 0x2f40)
  • ?CopyBytesIn@CalculateSize@Comms@@UAEXPBXIABVtype_info@@@Z (Ordinal: 9, Address: 0x32f0)
  • ?CopyBytesIn@SerializeBuffer@Comms@@UAEXPBXIABVtype_info@@@Z (Ordinal: 10, Address: 0x33e0)
  • ?CopyBytesOut@Deserializer@Comms@@QAE_NPAXIABVtype_info@@@Z (Ordinal: 11, Address: 0x2b90)
  • CreateKnownFolderPath (Ordinal: 12, Address: 0x45c0)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@AAPAD@Z (Ordinal: 13, Address: 0x2c30)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@AAPAG@Z (Ordinal: 14, Address: 0x2cc0)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@AAPBD@Z (Ordinal: 15, Address: 0x2cb0)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@AAPBG@Z (Ordinal: 16, Address: 0x2d40)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@AAV?$basic_string@GU?$char_traits@G@utl@@V?$allocator@G@2@@utl@@@Z (Ordinal: 17, Address: 0x2600)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@AAV?$vector@EV?$allocator@E@utl@@@utl@@@Z (Ordinal: 18, Address: 0x26e0)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@AAVNullType@detail@1@@Z (Ordinal: 19, Address: 0x2d50)
  • ?DeserializeObject@Comms@@YG_NAAVDeserializer@1@ABVNullType@detail@1@@Z (Ordinal: 20, Address: 0x2d50)
  • ?GetBuffer@Deserializer@Comms@@QAEPAXI@Z (Ordinal: 21, Address: 0x2520)
  • ?GetBuffer@SerializeBuffer@Comms@@QAEXAAV?$vector@EV?$allocator@E@utl@@@utl@@@Z (Ordinal: 22, Address: 0x24a0)
  • ?GetBuffer@SerializeBuffer@Comms@@QBEPBV?$vector@EV?$allocator@E@utl@@@utl@@XZ (Ordinal: 23, Address: 0x2490)
  • GetRpcClientThreadToken (Ordinal: 24, Address: 0x4d10)
  • GetSupportedImageFileExtensions (Ordinal: 25, Address: 0x5320)
  • GetTempFileNameWithExt (Ordinal: 26, Address: 0x43a0)
  • GetThreadIOPriority (Ordinal: 27, Address: 0x6430)
  • ?GetTotal@CalculateSize@Comms@@QBEIXZ (Ordinal: 28, Address: 0x2480)
  • ?Initialize@SerializeBuffer@Comms@@QAE_NXZ (Ordinal: 29, Address: 0x33b0)
  • ?InitializeBinding@RpcClient@Comms@@QAEJPBGAAPAX@Z (Ordinal: 30, Address: 0x2e10)
  • IsActiveDebugger (Ordinal: 31, Address: 0x2ef0)
  • IsImageExtension (Ordinal: 32, Address: 0x5660)
  • ?ReleaseBuffer@Deserializer@Comms@@QAEXPBX@Z (Ordinal: 33, Address: 0x2580)
  • ResizeImageBySizeInMemory (Ordinal: 34, Address: 0x5ec0)
  • ResizeImageBySizeToStream (Ordinal: 35, Address: 0x61c0)
  • ?SerializeObject@Comms@@YGXAAVSerializeBase@1@ABV?$basic_string@GU?$char_traits@G@utl@@V?$allocator@G@2@@utl@@@Z (Ordinal: 36, Address: 0x25b0)
  • ?SerializeObject@Comms@@YGXAAVSerializeBase@1@ABV?$vector@EV?$allocator@E@utl@@@utl@@@Z (Ordinal: 37, Address: 0x2690)
  • ?SerializeObject@Comms@@YGXAAVSerializeBase@1@ABVNullType@detail@1@@Z (Ordinal: 38, Address: 0x32b0)
  • ?SerializeObject@Comms@@YGXAAVSerializeBase@1@PBD@Z (Ordinal: 39, Address: 0x31f0)
  • ?SerializeObject@Comms@@YGXAAVSerializeBase@1@PBG@Z (Ordinal: 40, Address: 0x3250)
  • SetPoolThreadBasePriority (Ordinal: 41, Address: 0x64f0)
  • SetThreadIOPriority (Ordinal: 42, Address: 0x6490)
  • ?_InitializeSecureRpcBinding@SecureRpcClient@Comms@@IAEJPBG0@Z (Ordinal: 43, Address: 0x2f70)
  • DefaultMakeHresultFromJetError (Ordinal: 44, Address: 0x7290)
  • ConvertHtmlStringToPlainTextStringOneCore (Ordinal: 45, Address: 0x6650)
  • ConvertPlainTextStringToHtmlStringOneCore (Ordinal: 46, Address: 0x6680)
  • DllCanUnloadNow (Ordinal: 47, Address: 0x3610)
  • DllGetClassObject (Ordinal: 48, Address: 0x3640)
  • FreeEnumColumn (Ordinal: 49, Address: 0x6fc0)
  • GenerateUserModeServiceName (Ordinal: 50, Address: 0x4e20)
  • GetCalendarColors (Ordinal: 51, Address: 0x6720)
  • GetCombinedTransientObjectSecurityDescriptor (Ordinal: 52, Address: 0x50a0)
  • GetContentTypeFromFilePath (Ordinal: 53, Address: 0x6ac0)
  • GetFileExtensionFromContentType (Ordinal: 54, Address: 0x6d10)
  • GetNextNewCalendarColor (Ordinal: 55, Address: 0x6760)
  • GetQueryProcessHandle (Ordinal: 56, Address: 0x5230)
  • GetUserContextFromHandle (Ordinal: 57, Address: 0x48e0)
  • GetUserTokenFromContext (Ordinal: 58, Address: 0x48a0)
  • IsCommsSystemService (Ordinal: 59, Address: 0x4d90)
  • JetReallocMethod (Ordinal: 60, Address: 0x6f60)
  • PrependHtmlOneCore (Ordinal: 61, Address: 0x66a0)
  • RunServicesInProc (Ordinal: 62, Address: 0x4920)
  • SetCommsServiceJetGlobalSystemParameters (Ordinal: 63, Address: 0x7240)
  • StartAndWaitForService (Ordinal: 64, Address: 0x4950)
  • StartAndWaitForServiceForUser (Ordinal: 65, Address: 0x4980)
  • StopAndWaitForFullyNamedService (Ordinal: 66, Address: 0x4b90)
  • StopAndWaitForService (Ordinal: 67, Address: 0x4b20)
  • UT_UninitializeTrident (Ordinal: 68, Address: 0x6630)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x1000c020)
api-ms-win-core-debug-l1-1-0.dll
  • IsDebuggerPresent (Address: 0x1000c028)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1000c030)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1000c038)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1000c04c)
  • RaiseException (Address: 0x1000c044)
  • SetLastError (Address: 0x1000c048)
  • SetUnhandledExceptionFilter (Address: 0x1000c040)
  • UnhandledExceptionFilter (Address: 0x1000c050)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x1000c060)
  • GetFileAttributesW (Address: 0x1000c05c)
  • GetTempFileNameW (Address: 0x1000c058)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1000c068)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1000c078)
  • HeapAlloc (Address: 0x1000c07c)
  • HeapFree (Address: 0x1000c074)
  • HeapReAlloc (Address: 0x1000c070)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x1000c084)
  • LocalFree (Address: 0x1000c088)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x1000c098)
  • FreeLibrary (Address: 0x1000c09c)
  • GetModuleHandleW (Address: 0x1000c090)
  • GetProcAddress (Address: 0x1000c094)
  • LoadLibraryExW (Address: 0x1000c0a0)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1000c0b8)
  • GetCurrentProcessId (Address: 0x1000c0bc)
  • GetCurrentThread (Address: 0x1000c0a8)
  • GetCurrentThreadId (Address: 0x1000c0b0)
  • OpenThreadToken (Address: 0x1000c0ac)
  • TerminateProcess (Address: 0x1000c0b4)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x1000c0c4)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1000c0cc)
api-ms-win-core-quirks-l1-1-0.dll
  • QuirkIsEnabled (Address: 0x1000c0d4)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1000c0e0)
  • RegCreateKeyExW (Address: 0x1000c0e8)
  • RegGetValueW (Address: 0x1000c0e4)
  • RegSetValueExW (Address: 0x1000c0dc)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFindExtensionW (Address: 0x1000c0f0)
  • PathMatchSpecW (Address: 0x1000c0f4)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • StrStrIW (Address: 0x1000c0fc)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1000c114)
  • DeleteCriticalSection (Address: 0x1000c10c)
  • EnterCriticalSection (Address: 0x1000c118)
  • InitializeCriticalSection (Address: 0x1000c11c)
  • InitializeCriticalSectionEx (Address: 0x1000c108)
  • LeaveCriticalSection (Address: 0x1000c104)
  • ReleaseSRWLockExclusive (Address: 0x1000c110)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x1000c128)
  • InitOnceComplete (Address: 0x1000c124)
  • InitOnceExecuteOnce (Address: 0x1000c130)
  • Sleep (Address: 0x1000c138)
  • SleepConditionVariableSRW (Address: 0x1000c134)
  • WakeAllConditionVariable (Address: 0x1000c12c)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1000c140)
  • GetTickCount (Address: 0x1000c148)
  • GetTickCount64 (Address: 0x1000c144)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x1000c154)
  • EventUnregister (Address: 0x1000c150)
api-ms-win-security-base-l1-1-0.dll
  • GetSecurityDescriptorDacl (Address: 0x1000c168)
  • MakeAbsoluteSD (Address: 0x1000c15c)
  • MakeSelfRelativeSD (Address: 0x1000c160)
  • SetSecurityDescriptorDacl (Address: 0x1000c164)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x1000c170)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x1000c1cc)
  • __dllonexit (Address: 0x1000c194)
  • _amsg_exit (Address: 0x1000c190)
  • _callnewh (Address: 0x1000c1d8)
  • _CIsqrt (Address: 0x1000c18c)
  • _except_handler4_common (Address: 0x1000c1b4)
  • _ftol2 (Address: 0x1000c1a8)
  • _initterm (Address: 0x1000c1a0)
  • _lock (Address: 0x1000c1b0)
  • _onexit (Address: 0x1000c188)
  • _purecall (Address: 0x1000c1c8)
  • _unlock (Address: 0x1000c180)
  • _vsnwprintf (Address: 0x1000c1ac)
  • _XcptFilter (Address: 0x1000c184)
  • ??1type_info@@UAE@XZ (Address: 0x1000c1a4)
  • ?raw_name@type_info@@QBEPBDXZ (Address: 0x1000c1d0)
  • free (Address: 0x1000c1b8)
  • malloc (Address: 0x1000c1d4)
  • memcpy (Address: 0x1000c19c)
  • memcpy_s (Address: 0x1000c1bc)
  • memmove (Address: 0x1000c198)
  • memset (Address: 0x1000c1dc)
  • rand (Address: 0x1000c1c0)
  • srand (Address: 0x1000c1c4)
ntdll.dll
  • NtQueryInformationThread (Address: 0x1000c1e4)
  • NtSetInformationThread (Address: 0x1000c1e8)
RPCRT4.dll
  • RpcBindingFree (Address: 0x1000c014)
  • RpcBindingFromStringBindingW (Address: 0x1000c000)
  • RpcBindingSetAuthInfoExW (Address: 0x1000c018)
  • RpcImpersonateClient (Address: 0x1000c008)
  • RpcRevertToSelf (Address: 0x1000c010)
  • RpcStringBindingComposeW (Address: 0x1000c004)
  • RpcStringFreeW (Address: 0x1000c00c)