cscobj.dll

Description: In-proc COM object used by clients of CSC API

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5369

Architecture: 64-bit

Operating System: Windows NT

SHA256: fc8ec87c2c643b8d2acd0dee692d4475

File Size: 295.0 KB

Uploaded At: Dec. 1, 2025, 7:24 a.m.

Views: 13

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ProcessGroupPolicy (Ordinal: 1, Address: 0xf190)
  • ProcessPolicy (Ordinal: 2, Address: 0xf1b0)
  • DllCanUnloadNow (Ordinal: 3, Address: 0x1740)
  • DllGetClassObject (Ordinal: 4, Address: 0x1f00)
  • DllRegisterServer (Ordinal: 5, Address: 0xc430)
  • DllUnregisterServer (Ordinal: 6, Address: 0xc480)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x180037418)
  • CoCreateInstanceEx (Address: 0x1800373f0)
  • CoGetCallContext (Address: 0x1800373d8)
  • CoGetInterfaceAndReleaseStream (Address: 0x180037408)
  • CoInitializeEx (Address: 0x180037430)
  • CoMarshalInterface (Address: 0x180037420)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x180037410)
  • CoQueryProxyBlanket (Address: 0x1800373e0)
  • CoRevertToSelf (Address: 0x180037428)
  • CoSetProxyBlanket (Address: 0x1800373e8)
  • CoTaskMemAlloc (Address: 0x1800373d0)
  • CoTaskMemFree (Address: 0x1800373c8)
  • CoUninitialize (Address: 0x180037440)
  • CoUnmarshalInterface (Address: 0x180037400)
  • CoWaitForMultipleHandles (Address: 0x180037438)
  • CreateStreamOnHGlobal (Address: 0x1800373f8)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • CStdAsyncStubBuffer_AddRef (Address: 0x180037468)
  • CStdAsyncStubBuffer_Connect (Address: 0x1800374a0)
  • CStdAsyncStubBuffer_Disconnect (Address: 0x180037590)
  • CStdAsyncStubBuffer_Invoke (Address: 0x180037460)
  • CStdAsyncStubBuffer_QueryInterface (Address: 0x1800374a8)
  • CStdAsyncStubBuffer_Release (Address: 0x180037578)
  • CStdStubBuffer2_Connect (Address: 0x180037510)
  • CStdStubBuffer2_CountRefs (Address: 0x180037520)
  • CStdStubBuffer2_Disconnect (Address: 0x1800374c8)
  • CStdStubBuffer2_QueryInterface (Address: 0x180037470)
  • NdrProxyForwardingFunction20 (Address: 0x180037530)
  • NdrProxyForwardingFunction3 (Address: 0x180037568)
  • NdrProxyForwardingFunction4 (Address: 0x180037580)
  • NdrProxyForwardingFunction5 (Address: 0x180037588)
  • NdrProxyForwardingFunction6 (Address: 0x180037518)
  • NdrProxyForwardingFunction7 (Address: 0x180037500)
  • ObjectStublessClient10 (Address: 0x180037508)
  • ObjectStublessClient11 (Address: 0x180037528)
  • ObjectStublessClient12 (Address: 0x180037540)
  • ObjectStublessClient13 (Address: 0x1800374b8)
  • ObjectStublessClient14 (Address: 0x180037538)
  • ObjectStublessClient15 (Address: 0x180037560)
  • ObjectStublessClient16 (Address: 0x180037490)
  • ObjectStublessClient17 (Address: 0x1800374f0)
  • ObjectStublessClient18 (Address: 0x1800374d8)
  • ObjectStublessClient19 (Address: 0x180037458)
  • ObjectStublessClient20 (Address: 0x180037450)
  • ObjectStublessClient21 (Address: 0x180037570)
  • ObjectStublessClient22 (Address: 0x180037478)
  • ObjectStublessClient23 (Address: 0x180037480)
  • ObjectStublessClient24 (Address: 0x180037550)
  • ObjectStublessClient25 (Address: 0x180037558)
  • ObjectStublessClient26 (Address: 0x180037548)
  • ObjectStublessClient27 (Address: 0x1800374d0)
  • ObjectStublessClient3 (Address: 0x1800374f8)
  • ObjectStublessClient4 (Address: 0x1800374e8)
  • ObjectStublessClient5 (Address: 0x180037498)
  • ObjectStublessClient6 (Address: 0x180037488)
  • ObjectStublessClient7 (Address: 0x1800374c0)
  • ObjectStublessClient8 (Address: 0x1800374b0)
  • ObjectStublessClient9 (Address: 0x1800374e0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800375a0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800375b0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800375d0)
  • RaiseException (Address: 0x1800375d8)
  • SetLastError (Address: 0x1800375e0)
  • SetUnhandledExceptionFilter (Address: 0x1800375c8)
  • UnhandledExceptionFilter (Address: 0x1800375c0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800375f0)
  • DuplicateHandle (Address: 0x1800375f8)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180037608)
  • HeapAlloc (Address: 0x180037610)
  • HeapDestroy (Address: 0x180037630)
  • HeapFree (Address: 0x180037618)
  • HeapReAlloc (Address: 0x180037620)
  • HeapSize (Address: 0x180037628)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x180037640)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180037658)
  • FindResourceExW (Address: 0x180037680)
  • FreeLibrary (Address: 0x180037678)
  • FreeLibraryAndExitThread (Address: 0x180037650)
  • GetProcAddress (Address: 0x180037690)
  • LoadResource (Address: 0x180037668)
  • LoadStringW (Address: 0x180037670)
  • LockResource (Address: 0x180037688)
  • SizeofResource (Address: 0x180037660)
api-ms-win-core-libraryloader-l1-2-1.dll
  • FindResourceW (Address: 0x1800376a8)
  • LoadLibraryW (Address: 0x1800376a0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800376b8)
api-ms-win-core-marshal-l1-1-0.dll
  • HWND_UserFree (Address: 0x1800376e0)
  • HWND_UserFree64 (Address: 0x1800376e8)
  • HWND_UserMarshal (Address: 0x1800376c8)
  • HWND_UserMarshal64 (Address: 0x1800376d8)
  • HWND_UserSize (Address: 0x180037700)
  • HWND_UserSize64 (Address: 0x1800376f0)
  • HWND_UserUnmarshal (Address: 0x1800376f8)
  • HWND_UserUnmarshal64 (Address: 0x1800376d0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x180037710)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x180037720)
  • GetCurrentProcess (Address: 0x180037738)
  • GetCurrentProcessId (Address: 0x180037740)
  • GetCurrentThread (Address: 0x180037730)
  • GetCurrentThreadId (Address: 0x180037728)
  • OpenThreadToken (Address: 0x180037758)
  • SetThreadToken (Address: 0x180037748)
  • TerminateProcess (Address: 0x180037750)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x180037768)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180037778)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800377a8)
  • RegCreateKeyExW (Address: 0x1800377c0)
  • RegDeleteKeyExW (Address: 0x180037798)
  • RegDeleteValueW (Address: 0x180037788)
  • RegEnumValueW (Address: 0x180037790)
  • RegOpenCurrentUser (Address: 0x1800377c8)
  • RegOpenKeyExW (Address: 0x1800377b8)
  • RegQueryValueExW (Address: 0x1800377b0)
  • RegSetValueExW (Address: 0x1800377a0)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800377e0)
  • RtlLookupFunctionEntry (Address: 0x1800377e8)
  • RtlVirtualUnwind (Address: 0x1800377d8)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x180037800)
  • CompareStringW (Address: 0x1800377f8)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x180037810)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180037848)
  • CreateEventW (Address: 0x180037868)
  • DeleteCriticalSection (Address: 0x180037860)
  • EnterCriticalSection (Address: 0x180037820)
  • InitializeCriticalSection (Address: 0x180037858)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180037830)
  • LeaveCriticalSection (Address: 0x180037828)
  • ReleaseSRWLockExclusive (Address: 0x180037850)
  • SetEvent (Address: 0x180037838)
  • WaitForSingleObject (Address: 0x180037840)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180037888)
  • SleepConditionVariableSRW (Address: 0x180037880)
  • WakeAllConditionVariable (Address: 0x180037878)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1800378a8)
  • GetSystemWindowsDirectoryW (Address: 0x1800378a0)
  • GetTickCount (Address: 0x180037898)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • QueueUserWorkItem (Address: 0x1800378b8)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x1800378c8)
api-ms-win-security-base-l1-1-0.dll
  • CopySid (Address: 0x1800378f8)
  • DuplicateTokenEx (Address: 0x1800378e0)
  • GetLengthSid (Address: 0x1800378f0)
  • GetTokenInformation (Address: 0x180037900)
  • ImpersonateLoggedOnUser (Address: 0x1800378e8)
  • IsValidSid (Address: 0x180037908)
  • RevertToSelf (Address: 0x1800378d8)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountSidW (Address: 0x180037918)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180037930)
  • ConvertStringSidToSidW (Address: 0x180037928)
msvcrt.dll
  • __C_specific_handler (Address: 0x1800379f0)
  • __CxxFrameHandler3 (Address: 0x180037948)
  • __dllonexit (Address: 0x180037940)
  • _amsg_exit (Address: 0x180037970)
  • _callnewh (Address: 0x180037980)
  • _i64tow_s (Address: 0x180037998)
  • _initterm (Address: 0x180037968)
  • _lock (Address: 0x180037958)
  • _onexit (Address: 0x180037960)
  • _purecall (Address: 0x1800379d0)
  • _unlock (Address: 0x180037950)
  • _vsnwprintf (Address: 0x1800379d8)
  • _XcptFilter (Address: 0x180037978)
  • ?terminate@@YAXXZ (Address: 0x1800379b0)
  • free (Address: 0x180037990)
  • malloc (Address: 0x180037988)
  • memcmp (Address: 0x1800379e0)
  • memcpy_s (Address: 0x1800379c8)
  • memmove (Address: 0x1800379a8)
  • memmove_s (Address: 0x1800379a0)
  • memset (Address: 0x1800379f8)
  • wcschr (Address: 0x1800379e8)
  • wcscspn (Address: 0x1800379b8)
  • wcsspn (Address: 0x1800379c0)
ntdll.dll
  • EtwGetTraceEnableFlags (Address: 0x180037a48)
  • EtwGetTraceEnableLevel (Address: 0x180037a50)
  • EtwGetTraceLoggerHandle (Address: 0x180037a58)
  • EtwRegisterTraceGuidsW (Address: 0x180037a70)
  • EtwTraceMessage (Address: 0x180037a68)
  • EtwUnregisterTraceGuids (Address: 0x180037a38)
  • RtlAppendPathElement (Address: 0x180037a18)
  • RtlFreeUnicodeString (Address: 0x180037a30)
  • RtlGetLengthWithoutLastFullDosOrNtPathElement (Address: 0x180037a08)
  • RtlGetLengthWithoutTrailingPathSeperators (Address: 0x180037a40)
  • RtlInitUnicodeString (Address: 0x180037a28)
  • RtlNtStatusToDosError (Address: 0x180037a60)
  • RtlpApplyLengthFunction (Address: 0x180037a10)
  • RtlpEnsureBufferSize (Address: 0x180037a20)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x180037340)
  • CStdStubBuffer_Connect (Address: 0x180037360)
  • CStdStubBuffer_CountRefs (Address: 0x180037358)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800372f0)
  • CStdStubBuffer_DebugServerRelease (Address: 0x180037390)
  • CStdStubBuffer_Disconnect (Address: 0x180037398)
  • CStdStubBuffer_Invoke (Address: 0x1800372f8)
  • CStdStubBuffer_IsIIDSupported (Address: 0x180037370)
  • CStdStubBuffer_QueryInterface (Address: 0x180037368)
  • IUnknown_AddRef_Proxy (Address: 0x180037330)
  • IUnknown_QueryInterface_Proxy (Address: 0x180037380)
  • IUnknown_Release_Proxy (Address: 0x180037348)
  • NdrCStdStubBuffer_Release (Address: 0x180037300)
  • NdrCStdStubBuffer2_Release (Address: 0x180037328)
  • NdrDllCanUnloadNow (Address: 0x180037308)
  • NdrDllGetClassObject (Address: 0x180037310)
  • NdrDllRegisterProxy (Address: 0x180037318)
  • NdrDllUnregisterProxy (Address: 0x180037320)
  • NdrOleAllocate (Address: 0x180037388)
  • NdrOleFree (Address: 0x180037338)
  • NdrStubCall3 (Address: 0x180037378)
  • NdrStubForwardingFunction (Address: 0x180037350)
USERENV.dll
  • ProcessGroupPolicyCompleted (Address: 0x1800373a8)
WTSAPI32.dll
  • WTSQueryUserToken (Address: 0x1800373b8)