eapp3hst.dll

Description: Microsoft ThirdPartyEapDispatcher

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 08baa2945ce5b60419ec05451f3fce1d

File Size: 361.0 KB

Uploaded At: Dec. 1, 2025, 7:27 a.m.

Views: 8

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x21a0)
  • DllGetClassObject (Ordinal: 2, Address: 0x21f0)
  • DllRegisterServer (Ordinal: 3, Address: 0x2050)
  • DllUnregisterServer (Ordinal: 4, Address: 0x2110)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x18003ea18)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • ObjectStublessClient10 (Address: 0x18003ea38)
  • ObjectStublessClient11 (Address: 0x18003ea58)
  • ObjectStublessClient12 (Address: 0x18003ea48)
  • ObjectStublessClient13 (Address: 0x18003ea88)
  • ObjectStublessClient14 (Address: 0x18003ea50)
  • ObjectStublessClient15 (Address: 0x18003ea78)
  • ObjectStublessClient3 (Address: 0x18003ea70)
  • ObjectStublessClient4 (Address: 0x18003ea60)
  • ObjectStublessClient5 (Address: 0x18003ea40)
  • ObjectStublessClient6 (Address: 0x18003ea30)
  • ObjectStublessClient7 (Address: 0x18003ea80)
  • ObjectStublessClient8 (Address: 0x18003ea68)
  • ObjectStublessClient9 (Address: 0x18003ea28)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18003eaa0)
  • IsDebuggerPresent (Address: 0x18003eab0)
  • OutputDebugStringA (Address: 0x18003ea98)
  • OutputDebugStringW (Address: 0x18003eaa8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18003eac0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18003ead0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18003eaf8)
  • RaiseException (Address: 0x18003eb00)
  • SetLastError (Address: 0x18003eaf0)
  • SetUnhandledExceptionFilter (Address: 0x18003eae0)
  • UnhandledExceptionFilter (Address: 0x18003eae8)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x18003eb10)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18003eb30)
  • DuplicateHandle (Address: 0x18003eb20)
  • GetHandleInformation (Address: 0x18003eb28)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18003eb40)
  • HeapAlloc (Address: 0x18003eb48)
  • HeapFree (Address: 0x18003eb50)
  • HeapSize (Address: 0x18003eb58)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18003eb68)
  • LocalFree (Address: 0x18003eb70)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18003eb80)
  • FindResourceExW (Address: 0x18003ebd0)
  • FreeLibrary (Address: 0x18003ebb8)
  • GetModuleFileNameA (Address: 0x18003eba8)
  • GetModuleFileNameW (Address: 0x18003eb98)
  • GetModuleHandleExW (Address: 0x18003eb88)
  • GetModuleHandleW (Address: 0x18003ebc0)
  • GetProcAddress (Address: 0x18003eba0)
  • LoadLibraryExW (Address: 0x18003ebb0)
  • LoadResource (Address: 0x18003ebc8)
  • SizeofResource (Address: 0x18003eb90)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryW (Address: 0x18003ebe0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18003ec00)
  • GetThreadLocale (Address: 0x18003ebf8)
  • SetThreadLocale (Address: 0x18003ebf0)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x18003ec10)
  • MapViewOfFile (Address: 0x18003ec20)
  • UnmapViewOfFile (Address: 0x18003ec18)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18003ec30)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x18003ec48)
  • GetCurrentProcessId (Address: 0x18003ec60)
  • GetCurrentThreadId (Address: 0x18003ec50)
  • GetProcessId (Address: 0x18003ec40)
  • TerminateProcess (Address: 0x18003ec58)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18003ec70)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18003ec80)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18003ecc0)
  • RegCreateKeyExW (Address: 0x18003eca8)
  • RegDeleteValueW (Address: 0x18003ecd0)
  • RegEnumKeyExW (Address: 0x18003ec90)
  • RegLoadMUIStringW (Address: 0x18003ecb8)
  • RegOpenKeyExW (Address: 0x18003eca0)
  • RegQueryInfoKeyW (Address: 0x18003ecc8)
  • RegQueryValueExW (Address: 0x18003ecb0)
  • RegSetValueExW (Address: 0x18003ec98)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x18003ece0)
  • WideCharToMultiByte (Address: 0x18003ece8)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x18003ecf8)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x18003ed08)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18003ed50)
  • AcquireSRWLockShared (Address: 0x18003ed78)
  • CreateMutexExW (Address: 0x18003ed40)
  • CreateSemaphoreExW (Address: 0x18003ed48)
  • DeleteCriticalSection (Address: 0x18003ed98)
  • EnterCriticalSection (Address: 0x18003ed70)
  • InitializeCriticalSection (Address: 0x18003eda0)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18003ed80)
  • InitializeCriticalSectionEx (Address: 0x18003ed38)
  • LeaveCriticalSection (Address: 0x18003ed68)
  • OpenSemaphoreW (Address: 0x18003ed60)
  • ReleaseMutex (Address: 0x18003ed90)
  • ReleaseSemaphore (Address: 0x18003ed18)
  • ReleaseSRWLockExclusive (Address: 0x18003ed58)
  • ReleaseSRWLockShared (Address: 0x18003ed88)
  • WaitForMultipleObjectsEx (Address: 0x18003ed20)
  • WaitForSingleObject (Address: 0x18003ed28)
  • WaitForSingleObjectEx (Address: 0x18003ed30)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x18003edb0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x18003edd8)
  • GetSystemInfo (Address: 0x18003edd0)
  • GetSystemTimeAsFileTime (Address: 0x18003edc0)
  • GetTickCount (Address: 0x18003edc8)
  • GetVersionExW (Address: 0x18003ede0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18003edf0)
  • CreateThreadpoolTimer (Address: 0x18003edf8)
  • SetThreadpoolTimer (Address: 0x18003ee08)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18003ee00)
api-ms-win-security-base-l1-1-0.dll
  • ImpersonateLoggedOnUser (Address: 0x18003ee20)
  • RevertToSelf (Address: 0x18003ee18)
combase.dll
  • GetErrorInfo (Address: 0x18003ee30)
msvcrt.dll
  • __C_specific_handler (Address: 0x18003eec0)
  • __CxxFrameHandler3 (Address: 0x18003eec8)
  • __dllonexit (Address: 0x18003ef08)
  • _amsg_exit (Address: 0x18003ee68)
  • _beginthreadex (Address: 0x18003ef70)
  • _CxxThrowException (Address: 0x18003ef10)
  • _endthreadex (Address: 0x18003ef60)
  • _errno (Address: 0x18003ef48)
  • _initterm (Address: 0x18003ee88)
  • _lock (Address: 0x18003eef8)
  • _onexit (Address: 0x18003ef00)
  • _purecall (Address: 0x18003ef50)
  • _unlock (Address: 0x18003ef38)
  • _vsnprintf (Address: 0x18003eed0)
  • _vsnprintf_s (Address: 0x18003ef18)
  • _vsnwprintf (Address: 0x18003ee90)
  • _wtol (Address: 0x18003ef28)
  • _XcptFilter (Address: 0x18003ee60)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x18003eeb0)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x18003eea8)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18003eea0)
  • ??0exception@@QEAA@XZ (Address: 0x18003eeb8)
  • ??1exception@@UEAA@XZ (Address: 0x18003ee98)
  • ??1type_info@@UEAA@XZ (Address: 0x18003ee58)
  • ?terminate@@YAXXZ (Address: 0x18003eef0)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x18003ee78)
  • free (Address: 0x18003ee80)
  • malloc (Address: 0x18003ee70)
  • memcmp (Address: 0x18003ee50)
  • memcpy (Address: 0x18003ee48)
  • memcpy_s (Address: 0x18003eed8)
  • memmove (Address: 0x18003ee40)
  • memmove_s (Address: 0x18003ef58)
  • memset (Address: 0x18003ef78)
  • realloc (Address: 0x18003ef40)
  • swprintf_s (Address: 0x18003ef20)
  • wcscat_s (Address: 0x18003ef68)
  • wcscpy_s (Address: 0x18003ef30)
  • wcsncpy_s (Address: 0x18003eee0)
  • wcsrchr (Address: 0x18003eee8)
ntdll.dll
  • DbgPrint (Address: 0x18003ef90)
  • EtwEventEnabled (Address: 0x18003eff0)
  • EtwEventRegister (Address: 0x18003efc0)
  • EtwEventUnregister (Address: 0x18003efb8)
  • EtwEventWriteTransfer (Address: 0x18003ef88)
  • EtwGetTraceEnableFlags (Address: 0x18003efd8)
  • EtwGetTraceEnableLevel (Address: 0x18003efe0)
  • EtwGetTraceLoggerHandle (Address: 0x18003efe8)
  • EtwRegisterTraceGuidsW (Address: 0x18003efd0)
  • EtwTraceMessage (Address: 0x18003efb0)
  • EtwUnregisterTraceGuids (Address: 0x18003efc8)
  • RtlCaptureContext (Address: 0x18003efa8)
  • RtlLookupFunctionEntry (Address: 0x18003efa0)
  • RtlVirtualUnwind (Address: 0x18003ef98)
OLEAUT32.dll
  • HWND_UserFree (Address: 0x18003e958)
  • HWND_UserFree64 (Address: 0x18003e950)
  • HWND_UserMarshal (Address: 0x18003e938)
  • HWND_UserMarshal64 (Address: 0x18003e930)
  • HWND_UserSize (Address: 0x18003e940)
  • HWND_UserSize64 (Address: 0x18003e948)
  • HWND_UserUnmarshal (Address: 0x18003e960)
  • HWND_UserUnmarshal64 (Address: 0x18003e928)
  • SysAllocString (Address: 0x18003e968)
  • SysFreeString (Address: 0x18003e918)
  • VarUI4FromStr (Address: 0x18003e920)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x18003ea00)
  • CStdStubBuffer_Connect (Address: 0x18003e990)
  • CStdStubBuffer_CountRefs (Address: 0x18003e9e0)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x18003e9f8)
  • CStdStubBuffer_DebugServerRelease (Address: 0x18003e9c0)
  • CStdStubBuffer_Disconnect (Address: 0x18003e9b8)
  • CStdStubBuffer_Invoke (Address: 0x18003e980)
  • CStdStubBuffer_IsIIDSupported (Address: 0x18003e998)
  • CStdStubBuffer_QueryInterface (Address: 0x18003e9d0)
  • IUnknown_AddRef_Proxy (Address: 0x18003e978)
  • IUnknown_QueryInterface_Proxy (Address: 0x18003e9b0)
  • IUnknown_Release_Proxy (Address: 0x18003ea08)
  • NdrCStdStubBuffer_Release (Address: 0x18003e988)
  • NdrDllCanUnloadNow (Address: 0x18003e9a0)
  • NdrDllGetClassObject (Address: 0x18003e9a8)
  • NdrDllRegisterProxy (Address: 0x18003e9d8)
  • NdrDllUnregisterProxy (Address: 0x18003e9e8)
  • NdrOleAllocate (Address: 0x18003e9c8)
  • NdrOleFree (Address: 0x18003e9f0)