ttdloader.dll

  • File Path: C:\Windows\SysWOW64\ttdloader.dll
  • Description: Time Travel Debugging Runtime Loader

Hashes

Type Hash
MD5 806E1AA9BAB57DD68BB6A277F98D716F
SHA1 C3396191B5B9DF66CA7AD325473C0664792CBDC2
SHA256 7A4875AE837C6D96BC8C1CD2AD926CCFBB0227FFC3384027A679F540D54E0BA6
SHA384 3772F2105636A046AD05E4C9E882B9DCA62E68ED77E2179A68FB52A7BDD47F6E477B148765A9D7FCE62B61DFCD1FB3B0
SHA512 C675BF6D4BE7D0BB737F9401D9DBE8BD2FBA780D6B9D9E283AE384DC4986A29D75ECD07DC1392EFAACC80DFAF576EA9415AA6730BF6A0DDBF7EE13932DBD33E1
SSDEEP 192:MV5qy6uwCPbUdbWLMWCJD1S8f4DBQABJJ+hKEwkqnajVkL2J:MraSPbUtWLMWKD1IDBRJJ+hKtklxtJ
IMP E84ACC723E724F9DA96F31B694E17B16
PESHA1 7F788FD0E81B02CC18522263452CEE7D88B523D5
PE256 A91E66F92D9B8BBD8545907D1B4F7EA6743E1E59D7F1FB94787E1940F4A35505

DLL Exports:

Function Name Ordinal Type
StubDllEntryWow64 4 Exported Function
TriggerOSNotification 5 Exported Function
StubDllEntry 3 Exported Function
InjectThread 1 Exported Function
ParametersBlock 2 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: TTDLoader.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/7a4875ae837c6d96bc8c1cd2ad926ccfbb0227ffc3384027a679f540d54e0ba6/detection/

File Similarity (ssdeep match)

File Score
C:\Program Files (x86)\Common Files\Microsoft Shared\ink\TabTip32.exe 38
C:\Program Files (x86)\Windows Kits\10\Redist\10.0.19041.0\ucrt\DLLs\x64\api-ms-win-core-localization-l1-2-0.dll 35
C:\Program Files (x86)\Windows Kits\10\Redist\10.0.19041.0\ucrt\DLLs\x64\api-ms-win-core-timezone-l1-1-0.dll 44
C:\Program Files (x86)\Windows Kits\10\Redist\10.0.19041.0\ucrt\DLLs\x86\api-ms-win-core-sysinfo-l1-1-0.dll 43
C:\Program Files (x86)\Windows Kits\10\Windows Performance Toolkit\api-ms-win-core-console-l1-2-0.dll 49
C:\Windows\system32\69fe178f-26e7-43a9-aa7d-2b616b672dde_eventlogservice.dll 49
C:\Windows\system32\AppVClientPS.dll 33
C:\Windows\system32\AppVSentinel.dll 46
C:\Windows\system32\AppVTerminator.dll 35
C:\Windows\system32\avrt.dll 35
C:\Windows\system32\backgroundTaskHost.exe 40
C:\Windows\system32\bootstr.dll 46
C:\Windows\system32\BOOTVID.DLL 35
C:\Windows\system32\computelibeventlog.dll 35
C:\Windows\system32\DefaultDeviceManager.dll 35
C:\Windows\system32\DeviceCensus.exe 27
C:\WINDOWS\system32\DeviceCensus.exe 27
C:\Windows\system32\dllhost.exe 54
C:\Windows\system32\downlevel\api-ms-win-base-util-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-com-l1-1-0.dll 57
C:\Windows\system32\downlevel\api-ms-win-core-comm-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-console-l1-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-core-datetime-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-datetime-l1-1-1.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-debug-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-debug-l1-1-1.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-delayload-l1-1-0.dll 52
C:\Windows\system32\downlevel\api-ms-win-core-errorhandling-l1-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-core-errorhandling-l1-1-1.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-fibers-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-fibers-l1-1-1.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-file-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-file-l1-2-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-file-l1-2-1.dll 52
C:\Windows\system32\downlevel\API-MS-Win-core-file-l2-1-0.dll 54
C:\Windows\system32\downlevel\API-MS-Win-core-file-l2-1-1.dll 50
C:\Windows\system32\downlevel\api-ms-win-core-handle-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-heap-l1-1-0.dll 44
C:\Windows\system32\downlevel\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-core-interlocked-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-io-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-io-l1-1-1.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-kernel32-legacy-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-kernel32-legacy-l1-1-1.dll 50
C:\Windows\system32\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll 49
C:\Windows\system32\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll 69
C:\Windows\system32\downlevel\api-ms-win-core-localization-l1-2-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-localization-l1-2-1.dll 46
C:\Windows\system32\downlevel\API-MS-Win-core-localization-obsolete-l1-2-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-memory-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-memory-l1-1-1.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-memory-l1-1-2.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-namedpipe-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-privateprofile-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-privateprofile-l1-1-1.dll 50
C:\Windows\system32\downlevel\api-ms-win-core-processenvironment-l1-1-0.dll 74
C:\Windows\system32\downlevel\api-ms-win-core-processenvironment-l1-2-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-processthreads-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-core-processthreads-l1-1-1.dll 65
C:\Windows\system32\downlevel\api-ms-win-core-processthreads-l1-1-2.dll 52
C:\Windows\system32\downlevel\api-ms-win-core-processtopology-obsolete-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-profile-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-realtime-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-registry-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-registry-l2-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-core-rtlsupport-l1-1-0.dll 54
C:\Windows\system32\downlevel\api-ms-win-core-shlwapi-legacy-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll 38
C:\Windows\system32\downlevel\api-ms-win-core-shutdown-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-stringansi-l1-1-0.dll 54
C:\Windows\system32\downlevel\api-ms-win-core-string-l1-1-0.dll 50
C:\Windows\system32\downlevel\API-MS-Win-core-string-l2-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-stringloader-l1-1-1.dll 46
C:\Windows\system32\downlevel\API-MS-Win-core-string-obsolete-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-synch-l1-1-0.dll 35
C:\Windows\system32\downlevel\api-ms-win-core-synch-l1-2-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-sysinfo-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-sysinfo-l1-2-0.dll 52
C:\Windows\system32\downlevel\api-ms-win-core-sysinfo-l1-2-1.dll 52
C:\Windows\system32\downlevel\api-ms-win-core-threadpool-l1-2-0.dll 54
C:\Windows\system32\downlevel\api-ms-win-core-threadpool-legacy-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-core-threadpool-private-l1-1-0.dll 52
C:\Windows\system32\downlevel\api-ms-win-core-timezone-l1-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-core-url-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-core-util-l1-1-0.dll 44
C:\Windows\system32\downlevel\api-ms-win-core-version-l1-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-core-wow64-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-core-xstate-l1-1-0.dll 47
C:\Windows\system32\downlevel\API-MS-Win-core-xstate-l2-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-crt-conio-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-crt-convert-l1-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-crt-environment-l1-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-crt-filesystem-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-crt-heap-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-crt-locale-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-crt-math-l1-1-0.dll 41
C:\Windows\system32\downlevel\api-ms-win-crt-multibyte-l1-1-0.dll 35
C:\Windows\system32\downlevel\api-ms-win-crt-process-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-crt-runtime-l1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-crt-stdio-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-crt-string-l1-1-0.dll 30
C:\Windows\system32\downlevel\api-ms-win-crt-time-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-crt-utility-l1-1-0.dll 44
C:\Windows\system32\downlevel\API-MS-Win-devices-config-L1-1-0.dll 41
C:\Windows\system32\downlevel\API-MS-Win-devices-config-L1-1-1.dll 46
C:\Windows\system32\downlevel\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll 52
C:\Windows\system32\downlevel\api-ms-win-eventing-consumer-l1-1-0.dll 43
C:\Windows\system32\downlevel\API-MS-Win-Eventing-Controller-L1-1-0.dll 50
C:\Windows\system32\downlevel\API-MS-Win-Eventing-Legacy-L1-1-0.dll 47
C:\Windows\system32\downlevel\API-MS-Win-Eventing-Provider-L1-1-0.dll 44
C:\Windows\system32\downlevel\API-MS-Win-EventLog-Legacy-L1-1-0.dll 46
C:\Windows\system32\downlevel\api-ms-win-security-base-l1-1-0.dll 36
C:\Windows\system32\downlevel\api-ms-win-security-cryptoapi-l1-1-0.dll 47
C:\Windows\system32\downlevel\API-MS-Win-Security-Lsalookup-L2-1-0.dll 50
C:\Windows\system32\downlevel\API-MS-Win-Security-Lsalookup-L2-1-1.dll 47
C:\Windows\system32\downlevel\API-MS-Win-security-lsapolicy-l1-1-0.dll 49
C:\Windows\system32\downlevel\API-MS-Win-security-provider-L1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-security-sddl-l1-1-0.dll 50
C:\Windows\system32\downlevel\api-ms-win-service-core-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-service-core-l1-1-1.dll 44
C:\Windows\system32\downlevel\api-ms-win-service-management-l1-1-0.dll 49
C:\Windows\system32\downlevel\api-ms-win-service-management-l2-1-0.dll 47
C:\Windows\system32\downlevel\api-ms-win-service-private-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-service-private-l1-1-1.dll 43
C:\Windows\system32\downlevel\api-ms-win-service-winsvc-l1-1-0.dll 43
C:\Windows\system32\downlevel\api-ms-win-shcore-stream-l1-1-0.dll 47
C:\Windows\system32\drivers\UMDF\SDFLauncher.dll 36
C:\Windows\system32\DriverStore\FileRepository\sdflauncher.inf_amd64_1ea082c6cf8f6982\SDFLauncher.dll 36
C:\Windows\system32\dsrole.dll 35
C:\Windows\system32\IME\IMETC\IMTCTRLN.DLL 29
C:\Windows\system32\IME\SHARED\IMEDICAPICCPS.DLL 38
C:\Windows\system32\IME\SHARED\IMESEARCHPS.DLL 41
C:\Windows\system32\kd.dll 44
C:\Windows\system32\kd_02_1af4.dll 38
C:\Windows\system32\kd_07_1415.dll 36
C:\Windows\system32\kdnet_uart16550.dll 43
C:\Windows\system32\kdstub.dll 35
C:\Windows\system32\ksuser.dll 33
C:\Windows\system32\microsoft-windows-battery-events.dll 44
C:\Windows\system32\microsoft-windows-hal-events.dll 33
C:\Windows\system32\microsoft-windows-sleepstudy-events.dll 41
C:\Windows\system32\msdmo.dll 29
C:\Windows\system32\NDKPing.exe 41
C:\Windows\system32\oobe\FirstLogonAnim.exe 41
C:\Windows\system32\pcwum.dll 36
C:\Windows\system32\prproc.exe 38
C:\Windows\system32\psapi.dll 33
C:\Windows\system32\ResetEngine.exe 33
C:\WINDOWS\system32\ResetEngine.exe 38
C:\WINDOWS\system32\ScriptRunner.exe 35
C:\Windows\system32\setupetw.dll 35
C:\Windows\system32\sfc.dll 55
C:\Windows\system32\SlideToShutDown.exe 33
C:\Windows\system32\smphost.dll 24
C:\Windows\system32\spwizres.dll 38
C:\Windows\system32\streamci.dll 33
C:\Windows\system32\ttdloader.dll 54
C:\Windows\system32\UtilityVmSysprep.dll 35
C:\Windows\system32\uxlibres.dll 44
C:\Windows\system32\VmApplicationHealthMonitorProxy.dll 40
C:\Windows\system32\wbem\Microsoft.AppV.AppVClientWmi.dll 27
C:\Windows\system32\winnsi.dll 32
C:\Windows\system32\wshhyperv.dll 44
C:\Windows\system32\wshunix.dll 43
C:\Windows\system32\wuauclt.exe 35
C:\Windows\SysWOW64\AppVClientPS.dll 35
C:\Windows\SysWOW64\AppVSentinel.dll 41
C:\Windows\SysWOW64\AppVTerminator.dll 40
C:\Windows\SysWOW64\avrt.dll 38
C:\Windows\SysWOW64\backgroundTaskHost.exe 41
C:\Windows\SysWOW64\BOOTVID.DLL 32
C:\Windows\SysWOW64\CameraSettingsUIHost.exe 27
C:\Windows\SysWOW64\DefaultDeviceManager.dll 35
C:\Windows\SysWOW64\dllhost.exe 36
C:\Windows\SysWOW64\downlevel\api-ms-win-base-util-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-com-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-comm-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-console-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-datetime-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-datetime-l1-1-1.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-debug-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-debug-l1-1-1.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-delayload-l1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-core-errorhandling-l1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-core-errorhandling-l1-1-1.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-fibers-l1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-core-fibers-l1-1-1.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-file-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-file-l1-2-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-file-l1-2-1.dll 49
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-file-l2-1-0.dll 52
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-file-l2-1-1.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-handle-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-heap-l1-1-0.dll 49
C:\Windows\SysWOW64\downlevel\API-MS-Win-Core-Heap-Obsolete-L1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-interlocked-l1-1-0.dll 41
C:\Windows\SysWOW64\downlevel\api-ms-win-core-io-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-io-l1-1-1.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-kernel32-legacy-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-kernel32-legacy-l1-1-1.dll 47
C:\Windows\SysWOW64\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\API-MS-Win-Core-Kernel32-Private-L1-1-1.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-libraryloader-l1-1-1.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-localization-l1-2-0.dll 36
C:\Windows\SysWOW64\downlevel\api-ms-win-core-localization-l1-2-1.dll 49
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-localization-obsolete-l1-2-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-memory-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-memory-l1-1-1.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-memory-l1-1-2.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-core-namedpipe-l1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-core-privateprofile-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-privateprofile-l1-1-1.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processenvironment-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processenvironment-l1-2-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processthreads-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processthreads-l1-1-1.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processthreads-l1-1-2.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-core-processtopology-obsolete-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-profile-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-realtime-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-registry-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-registry-l2-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-rtlsupport-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-core-shlwapi-legacy-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-shlwapi-obsolete-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-shutdown-l1-1-0.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-core-stringansi-l1-1-0.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-core-string-l1-1-0.dll 49
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-string-l2-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-stringloader-l1-1-1.dll 46
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-string-obsolete-l1-1-0.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-core-synch-l1-1-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-synch-l1-2-0.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-core-sysinfo-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-sysinfo-l1-2-0.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-core-sysinfo-l1-2-1.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-core-threadpool-l1-2-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-core-threadpool-legacy-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-threadpool-private-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-timezone-l1-1-0.dll 55
C:\Windows\SysWOW64\downlevel\api-ms-win-core-url-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-util-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-version-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-core-wow64-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-core-xstate-l1-1-0.dll 52
C:\Windows\SysWOW64\downlevel\API-MS-Win-core-xstate-l2-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-conio-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-convert-l1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-environment-l1-1-0.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-filesystem-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-heap-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-locale-l1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-math-l1-1-0.dll 38
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-multibyte-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-process-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-runtime-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-stdio-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-string-l1-1-0.dll 33
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-time-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-crt-utility-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\API-MS-Win-devices-config-L1-1-0.dll 33
C:\Windows\SysWOW64\downlevel\API-MS-Win-devices-config-L1-1-1.dll 36
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-ClassicProvider-L1-1-0.dll 52
C:\Windows\SysWOW64\downlevel\api-ms-win-eventing-consumer-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-Controller-L1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-Legacy-L1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\API-MS-Win-Eventing-Provider-L1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\API-MS-Win-EventLog-Legacy-L1-1-0.dll 49
C:\Windows\SysWOW64\downlevel\api-ms-win-security-base-l1-1-0.dll 35
C:\Windows\SysWOW64\downlevel\api-ms-win-security-cryptoapi-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\API-MS-Win-Security-Lsalookup-L2-1-0.dll 46
C:\Windows\SysWOW64\downlevel\API-MS-Win-Security-Lsalookup-L2-1-1.dll 49
C:\Windows\SysWOW64\downlevel\API-MS-Win-security-lsapolicy-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\API-MS-Win-security-provider-L1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-security-sddl-l1-1-0.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-service-core-l1-1-0.dll 44
C:\Windows\SysWOW64\downlevel\api-ms-win-service-core-l1-1-1.dll 46
C:\Windows\SysWOW64\downlevel\api-ms-win-service-management-l1-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-service-management-l2-1-0.dll 47
C:\Windows\SysWOW64\downlevel\api-ms-win-service-private-l1-1-0.dll 43
C:\Windows\SysWOW64\downlevel\api-ms-win-service-private-l1-1-1.dll 40
C:\Windows\SysWOW64\downlevel\api-ms-win-service-winsvc-l1-1-0.dll 50
C:\Windows\SysWOW64\downlevel\api-ms-win-shcore-stream-l1-1-0.dll 47
C:\Windows\SysWOW64\dsrole.dll 43
C:\Windows\SysWOW64\fltLib.dll 33
C:\Windows\SysWOW64\IME\IMETC\IMTCTRLN.DLL 35
C:\Windows\SysWOW64\IME\SHARED\imecfmps.dll 33
C:\Windows\SysWOW64\IME\SHARED\IMEDICAPICCPS.DLL 33
C:\Windows\SysWOW64\IME\SHARED\IMESEARCHPS.DLL 38
C:\Windows\SysWOW64\ksuser.dll 36
C:\Windows\SysWOW64\LocationFrameworkPS.dll 38
C:\Windows\SysWOW64\pcwum.dll 40
C:\Windows\SysWOW64\psapi.dll 38
C:\Windows\SysWOW64\sfc.dll 47
C:\Windows\SysWOW64\smphost.dll 32
C:\Windows\SysWOW64\uxlibres.dll 47
C:\Windows\SysWOW64\wbem\Microsoft.AppV.AppVClientWmi.dll 27
C:\Windows\SysWOW64\winnsi.dll 35
C:\Windows\SysWOW64\wshhyperv.dll 54
C:\Windows\SysWOW64\wshunix.dll 41

Possible Misuse

The following table contains possible examples of ttdloader.dll being misused. While ttdloader.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma image_load_tttracer_mod_load.yml - '\ttdloader.dll' DRL 1.0

MIT License. Copyright (c) 2020-2021 Strontic.