DeviceFlows.DataModel.dll

Description: DeviceFlows DataModel

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 582fdcd8574872f11c67cc8c2aad9ca3

File Size: 1.9 MB

Uploaded At: Dec. 1, 2025, 7:25 a.m.

Views: 9

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x115060)
  • DllGetActivationFactory (Ordinal: 2, Address: 0x115080)

Imported DLLs & Functions

api-ms-win-appmodel-runtime-l1-1-0.dll
  • PackageFamilyNameFromFullName (Address: 0x18012e028)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateFreeThreadedMarshaler (Address: 0x18012e058)
  • CoCreateInstance (Address: 0x18012e078)
  • CoGetApartmentType (Address: 0x18012e048)
  • CoGetInterfaceAndReleaseStream (Address: 0x18012e040)
  • CoGetObjectContext (Address: 0x18012e068)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x18012e080)
  • CoTaskMemAlloc (Address: 0x18012e088)
  • CoTaskMemFree (Address: 0x18012e050)
  • CoWaitForMultipleHandles (Address: 0x18012e070)
  • PropVariantClear (Address: 0x18012e060)
  • StringFromGUID2 (Address: 0x18012e038)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18012e098)
  • IsDebuggerPresent (Address: 0x18012e0a8)
  • OutputDebugStringW (Address: 0x18012e0a0)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18012e0b8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18012e0c8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18012e0f0)
  • RaiseException (Address: 0x18012e0e0)
  • SetLastError (Address: 0x18012e0f8)
  • SetUnhandledExceptionFilter (Address: 0x18012e0e8)
  • UnhandledExceptionFilter (Address: 0x18012e0d8)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18012e108)
  • GetFullPathNameW (Address: 0x18012e110)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18012e120)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18012e138)
  • HeapAlloc (Address: 0x18012e130)
  • HeapFree (Address: 0x18012e140)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18012e158)
  • LocalFree (Address: 0x18012e150)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
  • PowerClearRequest (Address: 0x18012e170)
  • PowerCreateRequest (Address: 0x18012e168)
  • PowerSetRequest (Address: 0x18012e178)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x18012e1a0)
  • GetModuleFileNameA (Address: 0x18012e188)
  • GetModuleHandleExW (Address: 0x18012e1a8)
  • GetModuleHandleW (Address: 0x18012e190)
  • GetProcAddress (Address: 0x18012e198)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryW (Address: 0x18012e1b8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18012e1c8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18012e1d8)
  • GetCurrentProcessId (Address: 0x18012e1f0)
  • GetCurrentThreadId (Address: 0x18012e1e8)
  • OpenProcessToken (Address: 0x18012e1f8)
  • TerminateProcess (Address: 0x18012e1e0)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18012e208)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18012e218)
api-ms-win-core-psapi-l1-1-0.dll
  • QueryFullProcessImageNameW (Address: 0x18012e228)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18012e240)
  • RegEnumKeyExW (Address: 0x18012e238)
  • RegGetValueW (Address: 0x18012e248)
  • RegOpenKeyExW (Address: 0x18012e250)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x18012e278)
  • GetStringTypeW (Address: 0x18012e260)
  • MultiByteToWideChar (Address: 0x18012e270)
  • WideCharToMultiByte (Address: 0x18012e268)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18012e2d0)
  • AcquireSRWLockShared (Address: 0x18012e2a0)
  • CreateEventExW (Address: 0x18012e2e8)
  • CreateEventW (Address: 0x18012e320)
  • CreateMutexExW (Address: 0x18012e298)
  • CreateSemaphoreExW (Address: 0x18012e308)
  • DeleteCriticalSection (Address: 0x18012e2b0)
  • EnterCriticalSection (Address: 0x18012e2e0)
  • InitializeCriticalSectionEx (Address: 0x18012e2d8)
  • LeaveCriticalSection (Address: 0x18012e2a8)
  • OpenSemaphoreW (Address: 0x18012e2c0)
  • ReleaseMutex (Address: 0x18012e318)
  • ReleaseSemaphore (Address: 0x18012e310)
  • ReleaseSRWLockExclusive (Address: 0x18012e300)
  • ReleaseSRWLockShared (Address: 0x18012e288)
  • ResetEvent (Address: 0x18012e290)
  • SetEvent (Address: 0x18012e2f8)
  • TryAcquireSRWLockShared (Address: 0x18012e2b8)
  • WaitForSingleObject (Address: 0x18012e2f0)
  • WaitForSingleObjectEx (Address: 0x18012e2c8)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x18012e350)
  • InitOnceComplete (Address: 0x18012e348)
  • InitOnceExecuteOnce (Address: 0x18012e358)
  • Sleep (Address: 0x18012e340)
  • SleepConditionVariableSRW (Address: 0x18012e330)
  • WakeAllConditionVariable (Address: 0x18012e338)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x18012e368)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18012e388)
  • GetTickCount (Address: 0x18012e390)
  • GetTickCount64 (Address: 0x18012e378)
  • GlobalMemoryStatusEx (Address: 0x18012e380)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18012e3b0)
  • CreateThreadpoolTimer (Address: 0x18012e3a0)
  • SetThreadpoolTimer (Address: 0x18012e3b8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18012e3a8)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x18012e3d0)
  • EncodePointer (Address: 0x18012e3c8)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x18012e3e0)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x18012e3f0)
  • RoGetActivationFactory (Address: 0x18012e3f8)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCompareStringOrdinal (Address: 0x18012e410)
  • WindowsCreateString (Address: 0x18012e408)
  • WindowsCreateStringReference (Address: 0x18012e418)
  • WindowsDeleteString (Address: 0x18012e420)
  • WindowsDuplicateString (Address: 0x18012e428)
  • WindowsGetStringLen (Address: 0x18012e430)
  • WindowsGetStringRawBuffer (Address: 0x18012e438)
  • WindowsIsStringEmpty (Address: 0x18012e440)
api-ms-win-devices-query-l1-1-0.dll
  • DevCloseObjectQuery (Address: 0x18012e460)
  • DevCreateObjectQuery (Address: 0x18012e468)
  • DevCreateObjectQueryFromId (Address: 0x18012e450)
  • DevFreeObjectProperties (Address: 0x18012e458)
  • DevGetObjectProperties (Address: 0x18012e470)
api-ms-win-devices-query-l1-1-1.dll
  • DevCreateObjectQueryEx (Address: 0x18012e480)
  • DevGetObjectPropertiesEx (Address: 0x18012e488)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x18012e4b8)
  • EventRegister (Address: 0x18012e4a8)
  • EventSetInformation (Address: 0x18012e4a0)
  • EventUnregister (Address: 0x18012e498)
  • EventWriteTransfer (Address: 0x18012e4b0)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • DisplayConfigGetDeviceInfo (Address: 0x18012e4d0)
  • GetDisplayConfigBufferSizes (Address: 0x18012e4d8)
  • QueryDisplayConfig (Address: 0x18012e4c8)
api-ms-win-power-base-l1-1-0.dll
  • PowerDeterminePlatformRoleEx (Address: 0x18012e4e8)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolGetUniqueContext (Address: 0x18012e500)
  • SHTaskPoolQueueTask (Address: 0x18012e4f8)
msvcrt.dll
  • ___lc_codepage_func (Address: 0x18012e560)
  • ___lc_handle_func (Address: 0x18012e568)
  • ___mb_cur_max_func (Address: 0x18012e578)
  • __C_specific_handler (Address: 0x18012e638)
  • __crtLCMapStringW (Address: 0x18012e528)
  • __CxxFrameHandler3 (Address: 0x18012e590)
  • __dllonexit (Address: 0x18012e600)
  • __ExceptionPtrCopy (Address: 0x18012e5c8)
  • __ExceptionPtrCreate (Address: 0x18012e5a8)
  • __ExceptionPtrCurrentException (Address: 0x18012e660)
  • __ExceptionPtrDestroy (Address: 0x18012e618)
  • __ExceptionPtrRethrow (Address: 0x18012e6e8)
  • __pctype_func (Address: 0x18012e550)
  • __uncaught_exception (Address: 0x18012e540)
  • _amsg_exit (Address: 0x18012e5e0)
  • _callnewh (Address: 0x18012e680)
  • _CxxThrowException (Address: 0x18012e6a0)
  • _errno (Address: 0x18012e570)
  • _initterm (Address: 0x18012e5c0)
  • _ismbblead (Address: 0x18012e558)
  • _itow_s (Address: 0x18012e588)
  • _lock (Address: 0x18012e628)
  • _onexit (Address: 0x18012e5f8)
  • _purecall (Address: 0x18012e620)
  • _ui64tow_s (Address: 0x18012e6e0)
  • _unlock (Address: 0x18012e608)
  • _vsnprintf_s (Address: 0x18012e658)
  • _vsnwprintf (Address: 0x18012e5a0)
  • _wcsdup (Address: 0x18012e530)
  • _wcsicmp (Address: 0x18012e5b8)
  • _wsetlocale (Address: 0x18012e520)
  • _wtoi (Address: 0x18012e6c0)
  • _XcptFilter (Address: 0x18012e5e8)
  • ??_U@YAPEAX_K@Z (Address: 0x18012e700)
  • ??_V@YAXPEAX@Z (Address: 0x18012e598)
  • ??0bad_cast@@QEAA@AEBV0@@Z (Address: 0x18012e6c8)
  • ??0bad_cast@@QEAA@PEBD@Z (Address: 0x18012e6d8)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18012e688)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18012e690)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18012e678)
  • ??0exception@@QEAA@XZ (Address: 0x18012e640)
  • ??1bad_cast@@UEAA@XZ (Address: 0x18012e6d0)
  • ??1exception@@UEAA@XZ (Address: 0x18012e630)
  • ??1type_info@@UEAA@XZ (Address: 0x18012e5f0)
  • ??3@YAXPEAX@Z (Address: 0x18012e610)
  • ?terminate@@YAXXZ (Address: 0x18012e668)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18012e698)
  • abort (Address: 0x18012e538)
  • calloc (Address: 0x18012e548)
  • difftime (Address: 0x18012e6f8)
  • free (Address: 0x18012e5d8)
  • malloc (Address: 0x18012e5d0)
  • memcmp (Address: 0x18012e510)
  • memcpy (Address: 0x18012e6a8)
  • memcpy_s (Address: 0x18012e5b0)
  • memmove (Address: 0x18012e6b0)
  • memmove_s (Address: 0x18012e648)
  • memset (Address: 0x18012e670)
  • setlocale (Address: 0x18012e580)
  • swscanf (Address: 0x18012e518)
  • time (Address: 0x18012e6f0)
  • wcschr (Address: 0x18012e708)
  • wcslen (Address: 0x18012e6b8)
  • wcsstr (Address: 0x18012e650)
ntdll.dll
  • EtwTraceMessage (Address: 0x18012e748)
  • NtQueryInformationToken (Address: 0x18012e760)
  • RtlAllocateHeap (Address: 0x18012e750)
  • RtlCaptureContext (Address: 0x18012e718)
  • RtlCompareUnicodeString (Address: 0x18012e768)
  • RtlFreeHeap (Address: 0x18012e758)
  • RtlInitUnicodeString (Address: 0x18012e738)
  • RtlIsMultiSessionSku (Address: 0x18012e740)
  • RtlLookupFunctionEntry (Address: 0x18012e720)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x18012e770)
  • RtlVirtualUnwind (Address: 0x18012e728)
  • ZwQueryLicenseValue (Address: 0x18012e730)
OLEAUT32.dll
  • SysAllocString (Address: 0x18012e008)
  • SysFreeString (Address: 0x18012e000)
RPCRT4.dll
  • UuidFromStringW (Address: 0x18012e018)
wincorlib.DLL
  • ?__abi_cast_Object_to_String@__abi_details@@YAPE$AAVString@Platform@@_NPE$AAVObject@3@@Z (Address: 0x18012e830)
  • ?__abi_cast_String_to_Object@__abi_details@@YAPE$AAVObject@Platform@@PE$AAVString@3@@Z (Address: 0x18012e828)
  • ?__abi_FailFast@@YAXXZ (Address: 0x18012e960)
  • ?__abi_make_type_id@@YAPE$AAVType@Platform@@AEBU__abi_type_descriptor@@@Z (Address: 0x18012e7b8)
  • ?__abi_ObjectToString@__abi_details@@YAPE$AAVString@Platform@@PE$AAVObject@3@_N@Z (Address: 0x18012e780)
  • ?__abi_WinRTraiseAccessDeniedException@@YAXXZ (Address: 0x18012e838)
  • ?__abi_WinRTraiseChangedStateException@@YAXXZ (Address: 0x18012e800)
  • ?__abi_WinRTraiseClassNotRegisteredException@@YAXXZ (Address: 0x18012e818)
  • ?__abi_WinRTraiseCOMException@@YAXJ@Z (Address: 0x18012e810)
  • ?__abi_WinRTraiseDisconnectedException@@YAXXZ (Address: 0x18012e850)
  • ?__abi_WinRTraiseFailureException@@YAXXZ (Address: 0x18012e848)
  • ?__abi_WinRTraiseInvalidArgumentException@@YAXXZ (Address: 0x18012e820)
  • ?__abi_WinRTraiseInvalidCastException@@YAXXZ (Address: 0x18012e930)
  • ?__abi_WinRTraiseNotImplementedException@@YAXXZ (Address: 0x18012e928)
  • ?__abi_WinRTraiseNullReferenceException@@YAXXZ (Address: 0x18012e808)
  • ?__abi_WinRTraiseObjectDisposedException@@YAXXZ (Address: 0x18012e938)
  • ?__abi_WinRTraiseOperationCanceledException@@YAXXZ (Address: 0x18012e840)
  • ?__abi_WinRTraiseOutOfBoundsException@@YAXXZ (Address: 0x18012e7f8)
  • ?__abi_WinRTraiseOutOfMemoryException@@YAXXZ (Address: 0x18012e7e8)
  • ?__abi_WinRTraiseWrongThreadException@@YAXXZ (Address: 0x18012e7f0)
  • ??0ChangedStateException@Platform@@QE$AAA@XZ (Address: 0x18012e868)
  • ??0Delegate@Platform@@QE$AAA@XZ (Address: 0x18012e918)
  • ??0DisconnectedException@Platform@@QE$AAA@XZ (Address: 0x18012e890)
  • ??0Exception@Platform@@QE$AAA@HPE$AAVString@1@@Z (Address: 0x18012e7d0)
  • ??0FailureException@Platform@@QE$AAA@XZ (Address: 0x18012e908)
  • ??0NotImplementedException@Platform@@QE$AAA@XZ (Address: 0x18012e920)
  • ??0NullReferenceException@Platform@@QE$AAA@XZ (Address: 0x18012e7c0)
  • ??0Object@Platform@@QE$AAA@XZ (Address: 0x18012e910)
  • ??0OutOfBoundsException@Platform@@QE$AAA@XZ (Address: 0x18012e858)
  • ??0OutOfMemoryException@Platform@@QE$AAA@XZ (Address: 0x18012e860)
  • ?AlignedFree@Heap@Details@Platform@@SAXPEAX@Z (Address: 0x18012e8d8)
  • ?Allocate@Heap@Details@Platform@@SAPEAX_K@Z (Address: 0x18012e8e8)
  • ?Allocate@Heap@Details@Platform@@SAPEAX_K0@Z (Address: 0x18012e8f0)
  • ?AllocateException@Heap@Details@Platform@@SAPEAX_K0@Z (Address: 0x18012e8d0)
  • ?CreateException@Exception@Platform@@SAPE$AAV12@H@Z (Address: 0x18012e880)
  • ?CreateException@Exception@Platform@@SAPE$AAV12@HPE$AAVString@2@@Z (Address: 0x18012e888)
  • ?CreateValue@Details@Platform@@YAPE$AAVObject@2@W4TypeCode@2@PEBX@Z (Address: 0x18012e798)
  • ?Equals@Object@Platform@@QE$AAA_NPE$AAV12@@Z (Address: 0x18012e7b0)
  • ?EventSourceAdd@Details@Platform@@YA?AVEventRegistrationToken@Foundation@Windows@@PEAPEAXPEAUEventLock@12@PE$AAVDelegate@2@@Z (Address: 0x18012e8b0)
  • ?EventSourceGetTargetArray@Details@Platform@@YAPEAXPEAXPEAUEventLock@12@@Z (Address: 0x18012e898)
  • ?EventSourceGetTargetArrayEvent@Details@Platform@@YAPEAXPEAXIPEBXPEA_J@Z (Address: 0x18012e8c0)
  • ?EventSourceGetTargetArraySize@Details@Platform@@YAIPEAX@Z (Address: 0x18012e8c8)
  • ?EventSourceInitialize@Details@Platform@@YAXPEAPEAX@Z (Address: 0x18012e8a8)
  • ?EventSourceRemove@Details@Platform@@YAXPEAPEAXPEAUEventLock@12@VEventRegistrationToken@Foundation@Windows@@@Z (Address: 0x18012e8f8)
  • ?EventSourceUninitialize@Details@Platform@@YAXPEAPEAX@Z (Address: 0x18012e8a0)
  • ?Free@Heap@Details@Platform@@SAXPEAX@Z (Address: 0x18012e8e0)
  • ?get@FullName@Type@Platform@@QE$AAAPE$AAVString@3@XZ (Address: 0x18012e7a8)
  • ?get@Message@Exception@Platform@@QE$AAAPE$AAVString@3@XZ (Address: 0x18012e870)
  • ?GetActivationFactory@Details@Platform@@YAJPEAVModuleBase@1WRL@Microsoft@@PEAUHSTRING__@@PEAPEAUIActivationFactory@@@Z (Address: 0x18012e970)
  • ?GetActivationFactoryByPCWSTR@@YAJPEAXAEAVGuid@Platform@@PEAPEAX@Z (Address: 0x18012e958)
  • ?GetIBoxArrayVtable@Details@Platform@@YAPEAXPEAX@Z (Address: 0x18012e900)
  • ?GetIBoxVtable@Details@Platform@@YAPEAXPEAX@Z (Address: 0x18012e790)
  • ?GetIidsFn@@YAJHPEAKPEBU__s_GUID@@PEAPEAVGuid@Platform@@@Z (Address: 0x18012e950)
  • ?GetType@Object@Platform@@QE$AAAPE$AAVType@2@XZ (Address: 0x18012e7a0)
  • ?GetTypeCode@Type@Platform@@SA?AW4TypeCode@2@PE$AAV12@@Z (Address: 0x18012e788)
  • ?GetWeakReference@Details@Platform@@YAPEAU__abi_IUnknown@@QE$ADVObject@2@@Z (Address: 0x18012e7e0)
  • ?InitializeData@Details@Platform@@YAJH@Z (Address: 0x18012e940)
  • ?ReCreateException@Exception@Platform@@SAPE$AAV12@H@Z (Address: 0x18012e878)
  • ?ReCreateFromException@Details@Platform@@YAJPE$AAVException@2@@Z (Address: 0x18012e968)
  • ?ReleaseTarget@ControlBlock@Details@Platform@@AEAAXXZ (Address: 0x18012e8b8)
  • ?ResolveWeakReference@Details@Platform@@YAPE$AAVObject@2@AEBU_GUID@@PEAPEAU__abi_IUnknown@@@Z (Address: 0x18012e7d8)
  • ?TerminateModule@Details@Platform@@YA_NPEAVModuleBase@1WRL@Microsoft@@@Z (Address: 0x18012e978)
  • ?ToString@Guid@Platform@@QEAAPE$AAVString@2@XZ (Address: 0x18012e7c8)
  • ?UninitializeData@Details@Platform@@YAXH@Z (Address: 0x18012e948)