wimgapi.dll
Description: Windows Imaging Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5553
Architecture: 32-bit
Operating System: Windows NT
SHA256: 6ce69b632281d4271edae96668359275
File Size: 590.9 KB
Uploaded At: Dec. 1, 2025, 8:06 a.m.
Views: 7
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x15ee0)
- DllMain (Ordinal: 2, Address: 0x15eb0)
- WIMAddImagePath (Ordinal: 3, Address: 0x169e0)
- WIMAddImagePaths (Ordinal: 4, Address: 0x16f80)
- WIMAddWimbootEntry (Ordinal: 5, Address: 0x17790)
- WIMApplyImage (Ordinal: 6, Address: 0x18bb0)
- WIMCaptureImage (Ordinal: 7, Address: 0x1c330)
- WIMCloseHandle (Ordinal: 8, Address: 0x1d260)
- WIMCommitImageHandle (Ordinal: 9, Address: 0x20a50)
- WIMCopyFile (Ordinal: 10, Address: 0x22b50)
- WIMCreateFile (Ordinal: 11, Address: 0x1c7e0)
- WIMCreateImageFile (Ordinal: 12, Address: 0x26da0)
- WIMCreateWofCompressedFile (Ordinal: 13, Address: 0x18d50)
- WIMDeleteImage (Ordinal: 14, Address: 0x27720)
- WIMDeleteImageMounts (Ordinal: 15, Address: 0x1fac0)
- WIMEnumImageFiles (Ordinal: 16, Address: 0x26bd0)
- WIMExportImage (Ordinal: 17, Address: 0x283a0)
- WIMExtractImageDirectory (Ordinal: 18, Address: 0x293f0)
- WIMExtractImagePath (Ordinal: 19, Address: 0x28d60)
- WIMFindFirstImageFile (Ordinal: 20, Address: 0x268b0)
- WIMFindNextImageFile (Ordinal: 21, Address: 0x26ab0)
- WIMGetAttributes (Ordinal: 22, Address: 0x1d790)
- WIMGetImageCount (Ordinal: 23, Address: 0x1d740)
- WIMGetImageInformation (Ordinal: 24, Address: 0x2ada0)
- WIMGetMessageCallbackCount (Ordinal: 25, Address: 0x2c140)
- WIMGetMountedImageHandle (Ordinal: 26, Address: 0x226a0)
- WIMGetMountedImageInfo (Ordinal: 27, Address: 0x220a0)
- WIMGetMountedImageInfoFromHandle (Ordinal: 28, Address: 0x222e0)
- WIMGetMountedImages (Ordinal: 29, Address: 0x225f0)
- WIMGetWIMBootEntries (Ordinal: 30, Address: 0x17620)
- WIMGetWIMBootWIMPath (Ordinal: 31, Address: 0x17340)
- WIMInitFileIOCallbacks (Ordinal: 32, Address: 0x2cf40)
- WIMInitializeWofDriver (Ordinal: 33, Address: 0x180b0)
- WIMIsCurrentSystemWimboot (Ordinal: 34, Address: 0x178d0)
- WIMIsReferenceWim (Ordinal: 35, Address: 0x27290)
- WIMLoadImage (Ordinal: 36, Address: 0x2d2f0)
- WIMMountImage (Ordinal: 37, Address: 0x21370)
- WIMMountImageHandle (Ordinal: 38, Address: 0x1ff20)
- WIMProcessCustomImage (Ordinal: 39, Address: 0x31cb0)
- WIMReadFileEx (Ordinal: 40, Address: 0x1da00)
- WIMReadImageFile (Ordinal: 41, Address: 0x25e20)
- WIMRedirectFolderBeforeApply (Ordinal: 42, Address: 0x18b30)
- WIMRegisterLogFile (Ordinal: 43, Address: 0x336f0)
- WIMRegisterMessageCallback (Ordinal: 44, Address: 0x2c1b0)
- WIMRemountImage (Ordinal: 45, Address: 0x215a0)
- WIMSetBootImage (Ordinal: 46, Address: 0x1d360)
- WIMSetFileIOCallbackTemporaryPath (Ordinal: 47, Address: 0x2cf90)
- WIMSetImageInformation (Ordinal: 48, Address: 0x2b010)
- WIMSetImageUserSpecifiedCreationTime (Ordinal: 49, Address: 0x1c530)
- WIMSetReferenceFile (Ordinal: 50, Address: 0x1d590)
- WIMSetTemporaryPath (Ordinal: 51, Address: 0x1d2e0)
- WIMSetWimGuid (Ordinal: 52, Address: 0x1c500)
- WIMSingleInstanceFile (Ordinal: 53, Address: 0x26f10)
- WIMSplitFile (Ordinal: 54, Address: 0x34190)
- WIMUnmountImage (Ordinal: 55, Address: 0x218b0)
- WIMUnmountImageHandle (Ordinal: 56, Address: 0x20fe0)
- WIMUnregisterLogFile (Ordinal: 57, Address: 0x338a0)
- WIMUnregisterMessageCallback (Ordinal: 58, Address: 0x2c2d0)
- WIMUpdateWIMBootEntry (Ordinal: 59, Address: 0x174e0)
- WIMWriteFileWithIntegrity (Ordinal: 60, Address: 0x257f0)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x1008802c)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x10088034)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1008803c)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x10088050)
- SetLastError (Address: 0x10088048)
- SetUnhandledExceptionFilter (Address: 0x10088044)
- UnhandledExceptionFilter (Address: 0x1008804c)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x10088074)
- CreateFileW (Address: 0x100880d0)
- DeleteFileW (Address: 0x100880c8)
- FindClose (Address: 0x10088094)
- FindFirstFileW (Address: 0x1008809c)
- FindNextFileW (Address: 0x10088098)
- FlushFileBuffers (Address: 0x100880d4)
- GetDriveTypeW (Address: 0x100880bc)
- GetFileAttributesW (Address: 0x100880a0)
- GetFileInformationByHandle (Address: 0x100880cc)
- GetFileSize (Address: 0x10088088)
- GetFileSizeEx (Address: 0x1008807c)
- GetFinalPathNameByHandleW (Address: 0x10088064)
- GetFullPathNameW (Address: 0x10088068)
- GetLogicalDriveStringsW (Address: 0x100880b0)
- GetLongPathNameW (Address: 0x1008805c)
- GetTempFileNameW (Address: 0x1008808c)
- GetVolumeInformationByHandleW (Address: 0x100880b4)
- GetVolumeInformationW (Address: 0x1008806c)
- GetVolumePathNameW (Address: 0x10088078)
- LocalFileTimeToFileTime (Address: 0x100880a8)
- LockFileEx (Address: 0x100880ac)
- ReadFile (Address: 0x10088080)
- RemoveDirectoryW (Address: 0x100880b8)
- SetEndOfFile (Address: 0x100880c4)
- SetFileAttributesW (Address: 0x10088058)
- SetFileInformationByHandle (Address: 0x10088060)
- SetFilePointer (Address: 0x10088084)
- SetFilePointerEx (Address: 0x100880c0)
- SetFileTime (Address: 0x10088090)
- UnlockFileEx (Address: 0x10088070)
- WriteFile (Address: 0x100880a4)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x100880dc)
- GetVolumeNameForVolumeMountPointW (Address: 0x100880e0)
- GetVolumePathNamesForVolumeNameW (Address: 0x100880e4)
api-ms-win-core-file-l2-1-0.dll
- CopyFileExW (Address: 0x100880ec)
- GetFileInformationByHandleEx (Address: 0x100880f0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x10088100)
- DuplicateHandle (Address: 0x100880fc)
- GetHandleInformation (Address: 0x100880f8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1008810c)
- HeapAlloc (Address: 0x10088114)
- HeapFree (Address: 0x10088110)
- HeapReAlloc (Address: 0x10088108)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1008811c)
- LocalFree (Address: 0x10088120)
api-ms-win-core-io-l1-1-0.dll
- DeviceIoControl (Address: 0x10088128)
- GetOverlappedResult (Address: 0x1008812c)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- DosDateTimeToFileTime (Address: 0x10088134)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1008814c)
- FreeLibrary (Address: 0x10088140)
- GetModuleFileNameW (Address: 0x10088150)
- GetModuleHandleExW (Address: 0x10088148)
- GetModuleHandleW (Address: 0x10088154)
- GetProcAddress (Address: 0x10088144)
- LoadLibraryExW (Address: 0x1008813c)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryW (Address: 0x1008815c)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x10088164)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x10088170)
- MapViewOfFile (Address: 0x10088174)
- UnmapViewOfFile (Address: 0x1008816c)
api-ms-win-core-privateprofile-l1-1-0.dll
- GetPrivateProfileSectionW (Address: 0x1008817c)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x10088188)
- GetCurrentDirectoryW (Address: 0x10088184)
- GetEnvironmentVariableW (Address: 0x1008818c)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessW (Address: 0x100881a4)
- CreateThread (Address: 0x100881b0)
- GetCurrentProcess (Address: 0x100881c4)
- GetCurrentProcessId (Address: 0x100881a8)
- GetCurrentThread (Address: 0x100881cc)
- GetCurrentThreadId (Address: 0x10088198)
- GetExitCodeProcess (Address: 0x10088194)
- OpenProcessToken (Address: 0x100881a0)
- OpenThreadToken (Address: 0x1008819c)
- SetThreadToken (Address: 0x100881ac)
- TerminateProcess (Address: 0x100881c8)
- TlsAlloc (Address: 0x100881c0)
- TlsFree (Address: 0x100881bc)
- TlsGetValue (Address: 0x100881b8)
- TlsSetValue (Address: 0x100881b4)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x100881d4)
api-ms-win-core-processthreads-l1-1-3.dll
- SetThreadIdealProcessor (Address: 0x100881dc)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x100881e4)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x100881f0)
- RegCreateKeyExW (Address: 0x10088200)
- RegDeleteKeyExW (Address: 0x10088208)
- RegDeleteValueW (Address: 0x1008820c)
- RegEnumKeyExW (Address: 0x1008821c)
- RegEnumValueW (Address: 0x100881f4)
- RegFlushKey (Address: 0x10088214)
- RegLoadKeyW (Address: 0x10088204)
- RegOpenKeyExW (Address: 0x100881ec)
- RegQueryInfoKeyW (Address: 0x100881f8)
- RegQueryValueExW (Address: 0x100881fc)
- RegSetValueExW (Address: 0x10088210)
- RegUnLoadKeyW (Address: 0x10088218)
api-ms-win-core-string-l1-1-0.dll
- CompareStringW (Address: 0x1008822c)
- MultiByteToWideChar (Address: 0x10088228)
- WideCharToMultiByte (Address: 0x10088224)
api-ms-win-core-string-l2-1-0.dll
- CharUpperW (Address: 0x10088234)
api-ms-win-core-synch-l1-1-0.dll
- CreateEventW (Address: 0x1008826c)
- CreateMutexW (Address: 0x10088248)
- CreateSemaphoreExW (Address: 0x10088250)
- DeleteCriticalSection (Address: 0x10088268)
- EnterCriticalSection (Address: 0x1008825c)
- InitializeCriticalSection (Address: 0x10088244)
- InitializeCriticalSectionAndSpinCount (Address: 0x10088240)
- LeaveCriticalSection (Address: 0x10088260)
- OpenEventW (Address: 0x10088274)
- ReleaseMutex (Address: 0x10088258)
- ReleaseSemaphore (Address: 0x10088254)
- ResetEvent (Address: 0x10088270)
- SetEvent (Address: 0x1008823c)
- WaitForMultipleObjectsEx (Address: 0x10088264)
- WaitForSingleObject (Address: 0x1008824c)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x1008827c)
api-ms-win-core-synch-l1-2-1.dll
- CreateSemaphoreW (Address: 0x10088284)
- WaitForMultipleObjects (Address: 0x10088288)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemDirectoryW (Address: 0x1008829c)
- GetSystemInfo (Address: 0x10088298)
- GetSystemTimeAsFileTime (Address: 0x100882a0)
- GetTickCount (Address: 0x10088294)
- GlobalMemoryStatusEx (Address: 0x10088290)
api-ms-win-core-version-l1-1-0.dll
- GetFileVersionInfoExW (Address: 0x100882ac)
- GetFileVersionInfoSizeExW (Address: 0x100882a8)
- VerQueryValueW (Address: 0x100882b0)
api-ms-win-core-wow64-l1-1-0.dll
- Wow64DisableWow64FsRedirection (Address: 0x100882b8)
- Wow64RevertWow64FsRedirection (Address: 0x100882bc)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x100882c8)
- AddAccessAllowedAceEx (Address: 0x10088308)
- AdjustTokenPrivileges (Address: 0x100882fc)
- AllocateAndInitializeSid (Address: 0x100882d8)
- EqualSid (Address: 0x100882ec)
- FreeSid (Address: 0x100882d4)
- GetAclInformation (Address: 0x1008830c)
- GetLengthSid (Address: 0x100882cc)
- GetSecurityDescriptorControl (Address: 0x10088300)
- GetSecurityDescriptorDacl (Address: 0x100882f8)
- GetSecurityDescriptorGroup (Address: 0x100882e8)
- GetSecurityDescriptorLength (Address: 0x100882e4)
- GetSecurityDescriptorOwner (Address: 0x100882dc)
- GetSecurityDescriptorSacl (Address: 0x100882f0)
- GetTokenInformation (Address: 0x100882f4)
- InitializeAcl (Address: 0x100882c4)
- InitializeSecurityDescriptor (Address: 0x100882e0)
- RevertToSelf (Address: 0x10088304)
- SetSecurityDescriptorDacl (Address: 0x100882d0)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x10088314)
- BCryptCreateHash (Address: 0x10088324)
- BCryptDestroyHash (Address: 0x10088318)
- BCryptFinishHash (Address: 0x1008831c)
- BCryptGetProperty (Address: 0x10088328)
- BCryptHashData (Address: 0x10088320)
- BCryptOpenAlgorithmProvider (Address: 0x1008832c)
msvcrt.dll
- __dllonexit (Address: 0x10088364)
- _amsg_exit (Address: 0x10088394)
- _callnewh (Address: 0x10088348)
- _except_handler4_common (Address: 0x10088374)
- _initterm (Address: 0x10088378)
- _lock (Address: 0x1008836c)
- _onexit (Address: 0x10088360)
- _purecall (Address: 0x100883b0)
- _strnicmp (Address: 0x1008834c)
- _unlock (Address: 0x10088368)
- _vscwprintf (Address: 0x100883b8)
- _vsnwprintf (Address: 0x100883c0)
- _wcsicmp (Address: 0x10088384)
- _wcslwr (Address: 0x10088350)
- _wcsnicmp (Address: 0x100883d0)
- _wcsrev (Address: 0x10088370)
- _wcstoi64 (Address: 0x100883ac)
- _wcsupr (Address: 0x10088354)
- _wtoi (Address: 0x100883bc)
- _XcptFilter (Address: 0x10088344)
- bsearch (Address: 0x1008839c)
- free (Address: 0x1008838c)
- iswspace (Address: 0x100883d4)
- malloc (Address: 0x1008837c)
- memcmp (Address: 0x10088338)
- memcpy (Address: 0x1008833c)
- memcpy_s (Address: 0x10088358)
- memmove (Address: 0x100883c4)
- memmove_s (Address: 0x100883a4)
- memset (Address: 0x100883dc)
- qsort (Address: 0x10088340)
- strcpy_s (Address: 0x100883b4)
- strncpy_s (Address: 0x1008835c)
- swscanf_s (Address: 0x10088390)
- towlower (Address: 0x10088334)
- towupper (Address: 0x10088380)
- wcschr (Address: 0x100883a8)
- wcsncmp (Address: 0x100883d8)
- wcsnlen (Address: 0x100883cc)
- wcsrchr (Address: 0x10088388)
- wcsstr (Address: 0x100883c8)
- wcstok_s (Address: 0x100883a0)
- wcstoul (Address: 0x10088398)
ntdll.dll
- DbgPrintEx (Address: 0x100883e8)
- NtClose (Address: 0x10088464)
- NtCreateFile (Address: 0x10088438)
- NtOpenFile (Address: 0x10088470)
- NtQueryDirectoryFile (Address: 0x10088468)
- NtQueryEaFile (Address: 0x1008843c)
- NtQueryInformationFile (Address: 0x10088454)
- NtQueryInformationProcess (Address: 0x10088440)
- NtQuerySecurityObject (Address: 0x10088428)
- NtQueryVolumeInformationFile (Address: 0x10088434)
- NtSetEaFile (Address: 0x10088418)
- NtSetInformationFile (Address: 0x10088458)
- NtSetSecurityObject (Address: 0x10088444)
- NtUnloadKey2 (Address: 0x10088424)
- NtYieldExecution (Address: 0x100883ec)
- RtlAcquireResourceExclusive (Address: 0x10088410)
- RtlAcquireResourceShared (Address: 0x1008840c)
- RtlAdjustPrivilege (Address: 0x10088478)
- RtlAllocateHeap (Address: 0x1008846c)
- RtlCompressBuffer (Address: 0x10088420)
- RtlDeleteResource (Address: 0x10088404)
- RtlDosPathNameToNtPathName_U (Address: 0x10088474)
- RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x10088400)
- RtlDowncaseUnicodeChar (Address: 0x100883e4)
- RtlFindAceByType (Address: 0x10088448)
- RtlFreeHeap (Address: 0x10088460)
- RtlGetCompressionWorkSpaceSize (Address: 0x10088480)
- RtlGetLastNtStatus (Address: 0x10088450)
- RtlGetPersistedStateLocation (Address: 0x1008841c)
- RtlGetVersion (Address: 0x100883fc)
- RtlImpersonateSelf (Address: 0x10088430)
- RtlInitializeCriticalSection (Address: 0x100883f4)
- RtlInitializeResource (Address: 0x10088414)
- RtlInitUnicodeString (Address: 0x1008842c)
- RtlNtStatusToDosError (Address: 0x1008847c)
- RtlRaiseStatus (Address: 0x100883f0)
- RtlReAllocateHeap (Address: 0x100883f8)
- RtlReleaseResource (Address: 0x10088408)
- RtlSetControlSecurityDescriptor (Address: 0x1008844c)
- RtlSetIoCompletionCallback (Address: 0x1008845c)
RPCRT4.dll
- I_RpcMapWin32Status (Address: 0x10088004)
- NdrClientCall2 (Address: 0x1008801c)
- RpcBindingFree (Address: 0x10088020)
- RpcBindingFromStringBindingW (Address: 0x10088014)
- RpcBindingSetAuthInfoW (Address: 0x10088018)
- RpcStringBindingComposeW (Address: 0x10088010)
- RpcStringFreeW (Address: 0x1008800c)
- UuidCreate (Address: 0x10088000)
- UuidFromStringW (Address: 0x10088024)
- UuidToStringW (Address: 0x10088008)