dmenrollengine.dll

Description: Enroll Engine DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6456

Architecture: 64-bit

Operating System: Windows NT

SHA256: 01ee2c07b98bdf460359d5aea8939a17

File Size: 939.5 KB

Uploaded At: Dec. 1, 2025, 7:26 a.m.

Views: 13

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DiscoverEndpoint (Ordinal: 1, Address: 0x30060)
  • FindDiscoveryService (Ordinal: 2, Address: 0x82cf0)
  • CleanupExpiredOMADMSessions (Ordinal: 3, Address: 0x733d0)
  • EnableLogging (Ordinal: 4, Address: 0x76900)
  • DiscoverEndpointEx (Ordinal: 5, Address: 0x30140)
  • FindDiscoveryServiceEx (Ordinal: 6, Address: 0x30500)
  • GetEnrollmentClientContext (Ordinal: 7, Address: 0x72640)
  • SetEnrollmentAadResourceUrl (Ordinal: 8, Address: 0x6f630)
  • OpenEnrollmentsHKEY (Ordinal: 9, Address: 0x6f620)
  • GetDatabaseManagerInstance (Ordinal: 10, Address: 0x83a0)
  • GetProviderID (Ordinal: 11, Address: 0x6f5f0)
  • SetProviderID (Ordinal: 12, Address: 0x6f810)
  • SetEnrollmentUPN (Ordinal: 13, Address: 0x6f790)
  • SwitchAADLinkedEnrollment (Ordinal: 14, Address: 0x6f840)
  • SetEnrollmentDormant (Ordinal: 15, Address: 0x6f6e0)
  • _IsManagementRegistrationAllowed (Ordinal: 16, Address: 0x6fc00)
  • SetEnrollmentAadSendDeviceToken (Ordinal: 17, Address: 0x6f6b0)
  • GetEnrollmentsOfTypes (Ordinal: 18, Address: 0x10290)
  • DiscoverEndpointEx2 (Ordinal: 19, Address: 0x30240)
  • VerifyServerIsMmpcEx (Ordinal: 20, Address: 0xd4c0)
  • AutoEnrollMDM (Ordinal: 21, Address: 0x68a00)
  • BeginEnrollmentScope (Ordinal: 22, Address: 0xd0e0)
  • DllCanUnloadNow (Ordinal: 23, Address: 0x6a440)
  • DllGetActivationFactory (Ordinal: 24, Address: 0x6a470)
  • DllGetClassObject (Ordinal: 25, Address: 0x6a4b0)
  • EnrollEngineInitialize (Ordinal: 26, Address: 0x68d20)
  • FreeMmpcDiscoveryResultsData (Ordinal: 27, Address: 0x30960)
  • GetCertificatePolicy (Ordinal: 28, Address: 0x72fc0)
  • GetEnrollmentAadResourceUrl (Ordinal: 29, Address: 0x6f3e0)
  • GetEnrollmentAadSendDeviceToken (Ordinal: 30, Address: 0x6f470)
  • GetEnrollmentAuthPolicy (Ordinal: 31, Address: 0x100e0)
  • GetEnrollmentCertStore (Ordinal: 32, Address: 0x6f4a0)
  • GetEnrollmentClientCertThumbprint (Ordinal: 33, Address: 0x6f4d0)
  • GetEnrollmentCurCryptoProvider (Ordinal: 34, Address: 0x10110)
  • GetEnrollmentDiscoveryService (Ordinal: 35, Address: 0x6f500)
  • GetEnrollmentEntDmId (Ordinal: 36, Address: 0x10140)
  • GetEnrollmentForceAadToken (Ordinal: 37, Address: 0x10170)
  • GetEnrollmentLinkedEnrollmentHasPriority (Ordinal: 38, Address: 0x101a0)
  • GetEnrollmentLinkedEnrollmentId (Ordinal: 39, Address: 0x101d0)
  • GetEnrollmentLinkedEnrollmentLockedToMMPC (Ordinal: 40, Address: 0x10200)
  • GetEnrollmentPartnerOpaqueID (Ordinal: 41, Address: 0x6f530)
  • GetEnrollmentResourceCache (Ordinal: 42, Address: 0x10230)
  • GetEnrollmentSID (Ordinal: 43, Address: 0x6f560)
  • GetEnrollmentState (Ordinal: 44, Address: 0x6f590)
  • GetEnrollmentTenantID (Ordinal: 45, Address: 0x10260)
  • GetEnrollmentType (Ordinal: 46, Address: 0x6e00)
  • GetEnrollmentUPN (Ordinal: 47, Address: 0x6f5c0)
  • GetFirstEnrollmentGuidOfTypes (Ordinal: 48, Address: 0x102c0)
  • GetIsRecoveryAllowed (Ordinal: 49, Address: 0x10370)
  • GetMmpcEnrollmentFlag (Ordinal: 50, Address: 0x103a0)
  • GetRecoveryInitiatedByServer (Ordinal: 51, Address: 0x103b0)
  • GetRecoveryRetryCount (Ordinal: 52, Address: 0x103e0)
  • GetRecoveryStatusEnum (Ordinal: 53, Address: 0x10410)
  • IsLockedToMmpc (Ordinal: 54, Address: 0xd170)
  • MmpcDiscoverEndpoint (Ordinal: 55, Address: 0x309b0)
  • SetEnrollState (Ordinal: 56, Address: 0x10440)
  • SetEnrollmentForceAadToken (Ordinal: 57, Address: 0x10470)
  • SetEnrollmentPartnerOpaqueID (Ordinal: 58, Address: 0x6f760)
  • SetEnrollmentResourceCache (Ordinal: 59, Address: 0x104a0)
  • SetIsRecoveryAllowed (Ordinal: 60, Address: 0x104d0)
  • SetMmpcEnrollmentFlag (Ordinal: 61, Address: 0x10500)
  • SetRecoveryInitiatedByServer (Ordinal: 62, Address: 0x10510)
  • SetRecoveryRetryCount (Ordinal: 63, Address: 0x10540)
  • SetRecoveryStateAndErrorCode (Ordinal: 64, Address: 0x10570)
  • SysprepGeneralize (Ordinal: 65, Address: 0xd390)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18009d330)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x18009d388)
  • CoCreateFreeThreadedMarshaler (Address: 0x18009d340)
  • CoCreateGuid (Address: 0x18009d348)
  • CoCreateInstance (Address: 0x18009d360)
  • CoInitializeEx (Address: 0x18009d398)
  • CoRevertToSelf (Address: 0x18009d390)
  • CoTaskMemAlloc (Address: 0x18009d370)
  • CoTaskMemFree (Address: 0x18009d368)
  • CoUninitialize (Address: 0x18009d3a0)
  • CoWaitForMultipleHandles (Address: 0x18009d358)
  • IIDFromString (Address: 0x18009d350)
  • StringFromCLSID (Address: 0x18009d380)
  • StringFromGUID2 (Address: 0x18009d378)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18009d3c0)
  • IsDebuggerPresent (Address: 0x18009d3b0)
  • OutputDebugStringW (Address: 0x18009d3b8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18009d3d0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18009d3e0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18009d408)
  • RaiseException (Address: 0x18009d3f0)
  • SetLastError (Address: 0x18009d3f8)
  • SetUnhandledExceptionFilter (Address: 0x18009d400)
  • UnhandledExceptionFilter (Address: 0x18009d410)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x18009d470)
  • CreateFileW (Address: 0x18009d450)
  • DeleteFileW (Address: 0x18009d458)
  • FindClose (Address: 0x18009d440)
  • FindFirstFileW (Address: 0x18009d448)
  • FindNextFileW (Address: 0x18009d420)
  • GetFileSize (Address: 0x18009d460)
  • GetFullPathNameW (Address: 0x18009d468)
  • ReadFile (Address: 0x18009d430)
  • RemoveDirectoryW (Address: 0x18009d428)
  • WriteFile (Address: 0x18009d438)
api-ms-win-core-file-l1-2-0.dll
  • GetTempPathW (Address: 0x18009d480)
api-ms-win-core-file-l2-1-0.dll
  • GetFileInformationByHandleEx (Address: 0x18009d490)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18009d4b0)
  • DuplicateHandle (Address: 0x18009d4a8)
  • GetHandleInformation (Address: 0x18009d4a0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18009d4c0)
  • HeapAlloc (Address: 0x18009d4d8)
  • HeapFree (Address: 0x18009d4c8)
  • HeapReAlloc (Address: 0x18009d4d0)
api-ms-win-core-heap-l2-1-0.dll
  • GlobalFree (Address: 0x18009d4f0)
  • LocalAlloc (Address: 0x18009d4e8)
  • LocalFree (Address: 0x18009d4f8)
api-ms-win-core-io-l1-1-0.dll
  • DeviceIoControl (Address: 0x18009d508)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18009d538)
  • FreeLibrary (Address: 0x18009d518)
  • GetModuleFileNameA (Address: 0x18009d540)
  • GetModuleHandleExW (Address: 0x18009d530)
  • GetModuleHandleW (Address: 0x18009d520)
  • GetProcAddress (Address: 0x18009d528)
  • LoadLibraryExW (Address: 0x18009d548)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryW (Address: 0x18009d558)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18009d568)
  • GetUserDefaultLocaleName (Address: 0x18009d570)
api-ms-win-core-path-l1-1-0.dll
  • PathAllocCombine (Address: 0x18009d590)
  • PathCchAppend (Address: 0x18009d588)
  • PathCchCombine (Address: 0x18009d580)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18009d5a0)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessAsUserW (Address: 0x18009d5b0)
  • CreateProcessW (Address: 0x18009d5d8)
  • CreateThread (Address: 0x18009d5e8)
  • GetCurrentProcess (Address: 0x18009d5f0)
  • GetCurrentProcessId (Address: 0x18009d5c8)
  • GetCurrentThreadId (Address: 0x18009d5c0)
  • GetExitCodeProcess (Address: 0x18009d5e0)
  • TerminateProcess (Address: 0x18009d5d0)
  • TerminateThread (Address: 0x18009d5b8)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18009d600)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18009d610)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18009d630)
  • RegCreateKeyExW (Address: 0x18009d648)
  • RegDeleteKeyExW (Address: 0x18009d680)
  • RegDeleteTreeW (Address: 0x18009d660)
  • RegDeleteValueW (Address: 0x18009d640)
  • RegEnumKeyExW (Address: 0x18009d668)
  • RegEnumValueW (Address: 0x18009d688)
  • RegGetValueW (Address: 0x18009d620)
  • RegNotifyChangeKeyValue (Address: 0x18009d628)
  • RegOpenCurrentUser (Address: 0x18009d670)
  • RegOpenKeyExW (Address: 0x18009d658)
  • RegQueryInfoKeyW (Address: 0x18009d638)
  • RegQueryValueExW (Address: 0x18009d650)
  • RegSetValueExW (Address: 0x18009d678)
api-ms-win-core-registry-l1-1-1.dll
  • RegDeleteKeyValueW (Address: 0x18009d6a0)
  • RegSetKeyValueW (Address: 0x18009d698)
api-ms-win-core-registry-l2-1-0.dll
  • RegDeleteKeyW (Address: 0x18009d6b8)
  • RegEnumKeyW (Address: 0x18009d6b0)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x18009d6c8)
  • WideCharToMultiByte (Address: 0x18009d6d0)
api-ms-win-core-string-l2-1-0.dll
  • CharLowerBuffW (Address: 0x18009d6e0)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpW (Address: 0x18009d6f8)
  • lstrlenA (Address: 0x18009d6f0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18009d780)
  • AcquireSRWLockShared (Address: 0x18009d760)
  • CreateEventExW (Address: 0x18009d720)
  • CreateEventW (Address: 0x18009d750)
  • CreateMutexExW (Address: 0x18009d7a8)
  • CreateSemaphoreExW (Address: 0x18009d770)
  • DeleteCriticalSection (Address: 0x18009d728)
  • EnterCriticalSection (Address: 0x18009d7b0)
  • InitializeCriticalSection (Address: 0x18009d738)
  • InitializeCriticalSectionEx (Address: 0x18009d778)
  • InitializeSRWLock (Address: 0x18009d718)
  • LeaveCriticalSection (Address: 0x18009d710)
  • OpenEventW (Address: 0x18009d798)
  • OpenSemaphoreW (Address: 0x18009d7a0)
  • ReleaseMutex (Address: 0x18009d730)
  • ReleaseSemaphore (Address: 0x18009d788)
  • ReleaseSRWLockExclusive (Address: 0x18009d768)
  • ReleaseSRWLockShared (Address: 0x18009d740)
  • ResetEvent (Address: 0x18009d790)
  • SetEvent (Address: 0x18009d758)
  • WaitForSingleObject (Address: 0x18009d708)
  • WaitForSingleObjectEx (Address: 0x18009d748)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x18009d7c8)
  • InitOnceComplete (Address: 0x18009d7c0)
  • InitOnceExecuteOnce (Address: 0x18009d7e8)
  • Sleep (Address: 0x18009d7d8)
  • SleepConditionVariableSRW (Address: 0x18009d7e0)
  • WakeAllConditionVariable (Address: 0x18009d7d0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetComputerNameExW (Address: 0x18009d808)
  • GetSystemTime (Address: 0x18009d820)
  • GetSystemTimeAsFileTime (Address: 0x18009d810)
  • GetSystemWindowsDirectoryW (Address: 0x18009d7f8)
  • GetTickCount (Address: 0x18009d800)
  • GetVersionExW (Address: 0x18009d818)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetProductInfo (Address: 0x18009d830)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18009d840)
  • CreateThreadpoolTimer (Address: 0x18009d858)
  • SetThreadpoolTimer (Address: 0x18009d848)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18009d850)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x18009d870)
  • SystemTimeToFileTime (Address: 0x18009d868)
api-ms-win-core-url-l1-1-0.dll
  • UrlEscapeW (Address: 0x18009d880)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x18009d898)
  • EncodePointer (Address: 0x18009d890)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x18009d8a8)
  • RoOriginateErrorW (Address: 0x18009d8b8)
  • RoTransformError (Address: 0x18009d8b0)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x18009d8c8)
  • RoGetActivationFactory (Address: 0x18009d8d0)
  • RoInitialize (Address: 0x18009d8e0)
  • RoUninitialize (Address: 0x18009d8d8)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x18009d8f8)
  • WindowsCreateStringReference (Address: 0x18009d8f0)
  • WindowsDeleteString (Address: 0x18009d918)
  • WindowsDuplicateString (Address: 0x18009d908)
  • WindowsGetStringRawBuffer (Address: 0x18009d910)
  • WindowsIsStringEmpty (Address: 0x18009d920)
  • WindowsStringHasEmbeddedNull (Address: 0x18009d900)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x18009d938)
  • EventProviderEnabled (Address: 0x18009d950)
  • EventRegister (Address: 0x18009d958)
  • EventSetInformation (Address: 0x18009d940)
  • EventUnregister (Address: 0x18009d948)
  • EventWriteTransfer (Address: 0x18009d930)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x18009d980)
  • OpenSCManagerW (Address: 0x18009d970)
  • OpenServiceW (Address: 0x18009d978)
  • StartServiceW (Address: 0x18009d968)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfigW (Address: 0x18009d998)
  • QueryServiceStatusEx (Address: 0x18009d990)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x18009d9a8)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x18009d9e0)
  • BCryptCreateHash (Address: 0x18009d9d0)
  • BCryptDestroyHash (Address: 0x18009d9f0)
  • BCryptFinishHash (Address: 0x18009d9c8)
  • BCryptGenRandom (Address: 0x18009d9e8)
  • BCryptGetProperty (Address: 0x18009d9d8)
  • BCryptHashData (Address: 0x18009d9b8)
  • BCryptOpenAlgorithmProvider (Address: 0x18009d9c0)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x18009d1a8)
  • CertCloseStore (Address: 0x18009d208)
  • CertComparePublicKeyInfo (Address: 0x18009d180)
  • CertDeleteCertificateFromStore (Address: 0x18009d138)
  • CertEnumCertificatesInStore (Address: 0x18009d198)
  • CertFindCertificateInStore (Address: 0x18009d150)
  • CertFreeCertificateChain (Address: 0x18009d170)
  • CertFreeCertificateContext (Address: 0x18009d140)
  • CertGetCertificateChain (Address: 0x18009d168)
  • CertGetCertificateContextProperty (Address: 0x18009d1e0)
  • CertGetNameStringW (Address: 0x18009d1b0)
  • CertOpenStore (Address: 0x18009d148)
  • CertSetCertificateContextProperty (Address: 0x18009d188)
  • CryptAcquireCertificatePrivateKey (Address: 0x18009d160)
  • CryptEncodeObject (Address: 0x18009d1f8)
  • CryptEncodeObjectEx (Address: 0x18009d1b8)
  • CryptExportPublicKeyInfo (Address: 0x18009d1c0)
  • CryptExportPublicKeyInfoEx (Address: 0x18009d158)
  • CryptFindOIDInfo (Address: 0x18009d178)
  • CryptMsgCalculateEncodedLength (Address: 0x18009d1d0)
  • CryptMsgClose (Address: 0x18009d200)
  • CryptMsgGetParam (Address: 0x18009d1f0)
  • CryptMsgOpenToEncode (Address: 0x18009d1d8)
  • CryptMsgUpdate (Address: 0x18009d1e8)
  • CryptSignAndEncodeCertificate (Address: 0x18009d1c8)
  • PFXExportCertStoreEx (Address: 0x18009d1a0)
  • PFXImportCertStore (Address: 0x18009d190)
DEVOBJ.dll
  • DevObjCreateDeviceInfoList (Address: 0x18009d238)
  • DevObjDestroyDeviceInfoList (Address: 0x18009d218)
  • DevObjEnumDeviceInterfaces (Address: 0x18009d228)
  • DevObjGetClassDevs (Address: 0x18009d220)
  • DevObjGetDeviceInterfaceDetail (Address: 0x18009d230)
msvcp110_win.dll
  • ?_Add_vtordisp1@?$basic_istream@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x18009da88)
  • ?_Add_vtordisp2@?$basic_ostream@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x18009da60)
  • ?_BADOFF@std@@3_JB (Address: 0x18009dad0)
  • ?_Lock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x18009db98)
  • ?_Orphan_all@_Container_base0@std@@QEAAXXZ (Address: 0x18009da68)
  • ?_Osfx@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAXXZ (Address: 0x18009db58)
  • ?_Pninc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ (Address: 0x18009db50)
  • ?_Swap_all@_Container_base0@std@@QEAAXAEAU12@@Z (Address: 0x18009da10)
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x18009da78)
  • ?_Unlock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x18009da38)
  • ?_Winerror_map@std@@YAPEBDH@Z (Address: 0x18009da90)
  • ?_Xbad_alloc@std@@YAXXZ (Address: 0x18009dab8)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x18009da80)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x18009da98)
  • ??0?$basic_ios@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x18009daf0)
  • ??0?$basic_iostream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@@Z (Address: 0x18009db60)
  • ??0?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x18009dae0)
  • ??0id@locale@std@@QEAA@_K@Z (Address: 0x18009da70)
  • ??1?$basic_ios@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x18009db68)
  • ??1?$basic_iostream@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x18009da48)
  • ??1?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x18009db88)
  • ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@H@Z (Address: 0x18009da58)
  • ?eback@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x18009daf8)
  • ?egptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x18009db18)
  • ?epptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x18009db30)
  • ?fill@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAGXZ (Address: 0x18009db80)
  • ?flags@ios_base@std@@QEBAHXZ (Address: 0x18009da00)
  • ?flush@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV12@XZ (Address: 0x18009da50)
  • ?gbump@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXH@Z (Address: 0x18009db20)
  • ?good@ios_base@std@@QEBA_NXZ (Address: 0x18009da30)
  • ?gptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x18009db00)
  • ?imbue@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAXAEBVlocale@2@@Z (Address: 0x18009daa0)
  • ?pbase@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x18009db08)
  • ?pbump@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXH@Z (Address: 0x18009db38)
  • ?pptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x18009db10)
  • ?rdbuf@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAPEAV?$basic_streambuf@GU?$char_traits@G@std@@@2@XZ (Address: 0x18009db78)
  • ?setbuf@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAPEAV12@PEAG_J@Z (Address: 0x18009dab0)
  • ?setg@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXPEAG00@Z (Address: 0x18009db28)
  • ?setp@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXPEAG0@Z (Address: 0x18009db40)
  • ?setp@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXPEAG00@Z (Address: 0x18009db48)
  • ?setstate@?$basic_ios@GU?$char_traits@G@std@@@std@@QEAAXH_N@Z (Address: 0x18009db70)
  • ?showmanyc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JXZ (Address: 0x18009da18)
  • ?sputc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGG@Z (Address: 0x18009db90)
  • ?sputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAA_JPEBG_J@Z (Address: 0x18009dad8)
  • ?sync@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAHXZ (Address: 0x18009daa8)
  • ?tie@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAPEAV?$basic_ostream@GU?$char_traits@G@std@@@2@XZ (Address: 0x18009dae8)
  • ?uflow@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAGXZ (Address: 0x18009da20)
  • ?uncaught_exception@std@@YA_NXZ (Address: 0x18009dac8)
  • ?width@ios_base@std@@QEAA_J_J@Z (Address: 0x18009da40)
  • ?width@ios_base@std@@QEBA_JXZ (Address: 0x18009da08)
  • ?xsgetn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEAG_J@Z (Address: 0x18009da28)
  • ?xsputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEBG_J@Z (Address: 0x18009dac0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18009dc38)
  • __CxxFrameHandler3 (Address: 0x18009dbe0)
  • __dllonexit (Address: 0x18009dc20)
  • __RTDynamicCast (Address: 0x18009dbc0)
  • _amsg_exit (Address: 0x18009dc48)
  • _callnewh (Address: 0x18009dc58)
  • _CxxThrowException (Address: 0x18009dbc8)
  • _errno (Address: 0x18009dd20)
  • _initterm (Address: 0x18009dc40)
  • _itow_s (Address: 0x18009dca8)
  • _lock (Address: 0x18009dc30)
  • _onexit (Address: 0x18009dc18)
  • _purecall (Address: 0x18009dbf8)
  • _set_errno (Address: 0x18009dcb8)
  • _unlock (Address: 0x18009dc28)
  • _vsnprintf_s (Address: 0x18009dd88)
  • _vsnwprintf (Address: 0x18009dbe8)
  • _vsnwprintf_s (Address: 0x18009dd28)
  • _wcsdup (Address: 0x18009dd58)
  • _wcsicmp (Address: 0x18009dd68)
  • _wcslwr (Address: 0x18009dcf0)
  • _wcsnicmp (Address: 0x18009dd78)
  • _wtof (Address: 0x18009dd00)
  • _wtoi (Address: 0x18009dd30)
  • _wtol (Address: 0x18009dc98)
  • _XcptFilter (Address: 0x18009dc50)
  • ??_V@YAXPEAX@Z (Address: 0x18009dd70)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18009dd90)
  • ??0exception@@QEAA@XZ (Address: 0x18009dd98)
  • ??1exception@@UEAA@XZ (Address: 0x18009dc00)
  • ??1type_info@@UEAA@XZ (Address: 0x18009dc08)
  • ??3@YAXPEAX@Z (Address: 0x18009dbd8)
  • ?terminate@@YAXXZ (Address: 0x18009dc10)
  • free (Address: 0x18009dd50)
  • isspace (Address: 0x18009dc90)
  • ldiv (Address: 0x18009dd60)
  • malloc (Address: 0x18009dc60)
  • memcmp (Address: 0x18009dbb8)
  • memcpy (Address: 0x18009dbb0)
  • memcpy_s (Address: 0x18009dbf0)
  • memmove (Address: 0x18009dba8)
  • memmove_s (Address: 0x18009dd80)
  • memset (Address: 0x18009dbd0)
  • realloc (Address: 0x18009dd08)
  • sprintf_s (Address: 0x18009dd10)
  • strchr (Address: 0x18009dcd0)
  • strncpy_s (Address: 0x18009dcb0)
  • strrchr (Address: 0x18009dcd8)
  • strtol (Address: 0x18009dcc0)
  • swprintf (Address: 0x18009dcc8)
  • swscanf_s (Address: 0x18009dc80)
  • toupper (Address: 0x18009dce8)
  • towlower (Address: 0x18009dcf8)
  • wcschr (Address: 0x18009dd38)
  • wcscmp (Address: 0x18009dce0)
  • wcscpy_s (Address: 0x18009dd40)
  • wcsncmp (Address: 0x18009dca0)
  • wcsnlen (Address: 0x18009dd18)
  • wcsrchr (Address: 0x18009dc88)
  • wcsstr (Address: 0x18009dc70)
  • wcstod (Address: 0x18009dc68)
  • wcstok_s (Address: 0x18009dd48)
  • wcstoul (Address: 0x18009dc78)
ntdll.dll
  • RtlCaptureContext (Address: 0x18009ddc8)
  • RtlGetDeviceFamilyInfoEnum (Address: 0x18009dde0)
  • RtlGetVersion (Address: 0x18009ddc0)
  • RtlIsStateSeparationEnabled (Address: 0x18009dda8)
  • RtlLookupFunctionEntry (Address: 0x18009ddd0)
  • RtlNtStatusToDosError (Address: 0x18009ddb0)
  • RtlPublishWnfStateData (Address: 0x18009ddb8)
  • RtlVirtualUnwind (Address: 0x18009ddd8)
OLEAUT32.dll
  • SafeArrayAccessData (Address: 0x18009d298)
  • SafeArrayCreate (Address: 0x18009d268)
  • SafeArrayDestroy (Address: 0x18009d290)
  • SafeArrayGetLBound (Address: 0x18009d2c8)
  • SafeArrayGetUBound (Address: 0x18009d288)
  • SafeArrayLock (Address: 0x18009d270)
  • SafeArrayUnaccessData (Address: 0x18009d248)
  • SafeArrayUnlock (Address: 0x18009d280)
  • SysAllocString (Address: 0x18009d2c0)
  • SysAllocStringByteLen (Address: 0x18009d260)
  • SysAllocStringLen (Address: 0x18009d250)
  • SysFreeString (Address: 0x18009d2b8)
  • SysStringByteLen (Address: 0x18009d2a8)
  • SysStringLen (Address: 0x18009d2b0)
  • VariantChangeType (Address: 0x18009d258)
  • VariantClear (Address: 0x18009d278)
  • VariantInit (Address: 0x18009d2a0)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x18009d2f8)
  • NdrClientCall3 (Address: 0x18009d2e8)
  • RpcBindingBind (Address: 0x18009d300)
  • RpcBindingCreateW (Address: 0x18009d308)
  • RpcBindingFree (Address: 0x18009d2f0)
  • UuidCreate (Address: 0x18009d2e0)
  • UuidFromStringW (Address: 0x18009d2d8)
USERENV.dll
  • EnterCriticalPolicySection (Address: 0x18009d320)
  • LeaveCriticalPolicySection (Address: 0x18009d318)