CredentialEnrollmentManagerForUser.dll
Description: Credential Enrollment Manager ForUser API
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5737
Architecture: 64-bit
Operating System: Windows NT
SHA256: 18c6f5ea9cd17139dc9d747d73aceab4
File Size: 76.8 KB
Uploaded At: Dec. 1, 2025, 7:24 a.m.
Views: 13
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x4c80)
- DllGetActivationFactory (Ordinal: 2, Address: 0x49b0)
- DllGetClassObject (Ordinal: 3, Address: 0x4b90)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x18000c998)
api-ms-win-core-com-l1-1-0.dll
- CoCreateFreeThreadedMarshaler (Address: 0x18000c9b8)
- CoCreateInstance (Address: 0x18000c9a8)
- CoTaskMemAlloc (Address: 0x18000c9b0)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x18000c9d8)
- IsDebuggerPresent (Address: 0x18000c9d0)
- OutputDebugStringW (Address: 0x18000c9c8)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x18000c9e8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x18000c9f8)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18000ca08)
- RaiseException (Address: 0x18000ca28)
- SetLastError (Address: 0x18000ca20)
- SetUnhandledExceptionFilter (Address: 0x18000ca18)
- UnhandledExceptionFilter (Address: 0x18000ca10)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18000ca40)
- DuplicateHandle (Address: 0x18000ca38)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18000ca60)
- HeapAlloc (Address: 0x18000ca50)
- HeapFree (Address: 0x18000ca58)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x18000ca70)
- LocalFree (Address: 0x18000ca78)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x18000ca88)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x18000caa8)
- FreeLibrary (Address: 0x18000ca98)
- GetModuleFileNameA (Address: 0x18000cab0)
- GetModuleHandleExW (Address: 0x18000cab8)
- GetModuleHandleW (Address: 0x18000cac0)
- GetProcAddress (Address: 0x18000caa0)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18000cad0)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18000caf0)
- GetCurrentProcessId (Address: 0x18000cb00)
- GetCurrentThreadId (Address: 0x18000cae8)
- OpenProcessToken (Address: 0x18000caf8)
- TerminateProcess (Address: 0x18000cae0)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x18000cb10)
- OpenProcess (Address: 0x18000cb18)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18000cb28)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18000cb38)
- RtlLookupFunctionEntry (Address: 0x18000cb48)
- RtlVirtualUnwind (Address: 0x18000cb40)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18000cb80)
- AcquireSRWLockShared (Address: 0x18000cba8)
- CreateMutexExW (Address: 0x18000cb78)
- CreateSemaphoreExW (Address: 0x18000cb88)
- OpenSemaphoreW (Address: 0x18000cb90)
- ReleaseMutex (Address: 0x18000cb98)
- ReleaseSemaphore (Address: 0x18000cb68)
- ReleaseSRWLockExclusive (Address: 0x18000cb60)
- ReleaseSRWLockShared (Address: 0x18000cba0)
- WaitForSingleObject (Address: 0x18000cb58)
- WaitForSingleObjectEx (Address: 0x18000cb70)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x18000cbb8)
- InitOnceComplete (Address: 0x18000cbc0)
- InitOnceExecuteOnce (Address: 0x18000cbc8)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x18000cbd8)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x18000cbe8)
- EncodePointer (Address: 0x18000cbf0)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x18000cc00)
- RoOriginateError (Address: 0x18000cc08)
- RoOriginateErrorW (Address: 0x18000cc18)
- SetRestrictedErrorInfo (Address: 0x18000cc10)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x18000cc30)
- RoGetActivationFactory (Address: 0x18000cc28)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateString (Address: 0x18000cc40)
- WindowsCreateStringReference (Address: 0x18000cc58)
- WindowsGetStringRawBuffer (Address: 0x18000cc60)
- WindowsIsStringEmpty (Address: 0x18000cc50)
- WindowsStringHasEmbeddedNull (Address: 0x18000cc48)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x18000ccd8)
- __CxxFrameHandler3 (Address: 0x18000cce0)
- __CxxFrameHandler4 (Address: 0x18000cd28)
- _CxxThrowException (Address: 0x18000cce8)
- _o___std_exception_copy (Address: 0x18000cd20)
- _o___std_exception_destroy (Address: 0x18000cd18)
- _o___std_type_info_destroy_list (Address: 0x18000cd10)
- _o___stdio_common_vsnprintf_s (Address: 0x18000ccf8)
- _o___stdio_common_vswprintf (Address: 0x18000ccf0)
- _o__callnewh (Address: 0x18000cd08)
- _o__cexit (Address: 0x18000cd00)
- _o__configure_narrow_argv (Address: 0x18000cc70)
- _o__crt_atexit (Address: 0x18000cc78)
- _o__errno (Address: 0x18000cc80)
- _o__execute_onexit_table (Address: 0x18000cc88)
- _o__initialize_narrow_environment (Address: 0x18000cc90)
- _o__initialize_onexit_table (Address: 0x18000cc98)
- _o__invalid_parameter_noinfo (Address: 0x18000cca0)
- _o__purecall (Address: 0x18000cca8)
- _o__register_onexit_function (Address: 0x18000ccb0)
- _o__seh_filter_dll (Address: 0x18000ccb8)
- _o_free (Address: 0x18000ccc8)
- _o_malloc (Address: 0x18000ccd0)
- memcpy (Address: 0x18000ccc0)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x18000cd40)
- _initterm_e (Address: 0x18000cd38)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x18000cd50)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x18000cd78)
- EventSetInformation (Address: 0x18000cd60)
- EventUnregister (Address: 0x18000cd70)
- EventWriteTransfer (Address: 0x18000cd68)
api-ms-win-security-base-l1-1-0.dll
- EqualSid (Address: 0x18000cd88)
- GetAce (Address: 0x18000cd90)
- GetTokenInformation (Address: 0x18000cda0)
- RevertToSelf (Address: 0x18000cd98)
combase.dll
- (Address: 0x18000cdb0)
- (Address: 0x18000cdb8)
ntdll.dll
- NtQuerySecurityObject (Address: 0x18000cde8)
- NtSetSecurityObject (Address: 0x18000cdd8)
- RtlAddAccessAllowedAce (Address: 0x18000cdc8)
- RtlAddAce (Address: 0x18000cde0)
- RtlCreateAcl (Address: 0x18000cdf8)
- RtlCreateSecurityDescriptor (Address: 0x18000ce18)
- RtlGetAce (Address: 0x18000cdf0)
- RtlGetDaclSecurityDescriptor (Address: 0x18000ce10)
- RtlLengthSid (Address: 0x18000ce00)
- RtlQueryInformationAcl (Address: 0x18000ce08)
- RtlSetDaclSecurityDescriptor (Address: 0x18000cdd0)
OLEAUT32.dll
- SysFreeString (Address: 0x18000c988)