uireng.dll
Description: UI Recording Engine Library
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 32-bit
Operating System: Windows NT
SHA256: b43c50ad727ae6774bb03f75d1c9b937
File Size: 242.0 KB
Uploaded At: Dec. 1, 2025, 8:05 a.m.
Views: 15
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- UirGetScreenComment (Ordinal: 1, Address: 0xe2a0)
- UirInitializeEngine (Ordinal: 2, Address: 0xdde0)
- UirIsRecordingActive (Ordinal: 3, Address: 0xe320)
- UirOutCreateOutputFile (Ordinal: 4, Address: 0xe3b0)
- UirPauseRecordingSession (Ordinal: 5, Address: 0xe0f0)
- UirResumeRecordingSession (Ordinal: 6, Address: 0xe170)
- UirStartRecordingSession (Ordinal: 7, Address: 0xdfa0)
- UirStopRecordingSession (Ordinal: 8, Address: 0xe070)
- UirUninitializeEngine (Ordinal: 9, Address: 0xdeb0)
- UirUpdateRecordingSession (Ordinal: 10, Address: 0xe1f0)
Imported DLLs & Functions
ADVAPI32.dll
- CloseTrace (Address: 0x10026028)
- ControlTraceW (Address: 0x10026038)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x10026024)
- EnableTrace (Address: 0x10026044)
- EnableTraceEx (Address: 0x1002603c)
- EventRegister (Address: 0x10026050)
- EventUnregister (Address: 0x1002604c)
- EventWriteString (Address: 0x10026034)
- FlushTraceW (Address: 0x10026040)
- GetTraceEnableFlags (Address: 0x10026014)
- GetTraceEnableLevel (Address: 0x10026018)
- GetTraceLoggerHandle (Address: 0x1002601c)
- OpenTraceW (Address: 0x10026030)
- ProcessTrace (Address: 0x1002602c)
- RegCloseKey (Address: 0x10026008)
- RegisterTraceGuidsW (Address: 0x10026010)
- RegOpenKeyExW (Address: 0x10026054)
- RegOpenKeyW (Address: 0x10026004)
- RegQueryValueExW (Address: 0x10026000)
- StartTraceW (Address: 0x10026048)
- TraceMessage (Address: 0x10026020)
- UnregisterTraceGuids (Address: 0x1002600c)
AEPIC.dll
- PicFreeFileInfo (Address: 0x10026060)
- PicRetrieveFileInfo (Address: 0x1002605c)
GDI32.dll
- BitBlt (Address: 0x10026078)
- CreateCompatibleBitmap (Address: 0x10026074)
- CreateCompatibleDC (Address: 0x10026068)
- CreateDCW (Address: 0x10026070)
- CreatePen (Address: 0x10026080)
- CreateSolidBrush (Address: 0x100260b4)
- DeleteDC (Address: 0x100260a8)
- DeleteObject (Address: 0x1002607c)
- Ellipse (Address: 0x100260a4)
- ExcludeClipRect (Address: 0x1002606c)
- ExtCreatePen (Address: 0x10026090)
- GetCurrentObject (Address: 0x100260ac)
- GetObjectW (Address: 0x10026088)
- GetStockObject (Address: 0x100260b0)
- LineTo (Address: 0x10026098)
- MoveToEx (Address: 0x10026094)
- PolyBezier (Address: 0x1002609c)
- Rectangle (Address: 0x1002608c)
- SelectObject (Address: 0x10026084)
- SetDCBrushColor (Address: 0x100260a0)
- StretchBlt (Address: 0x100260b8)
gdiplus.dll
- GdipAlloc (Address: 0x1002643c)
- GdipCloneImage (Address: 0x10026438)
- GdipCreateBitmapFromHBITMAP (Address: 0x10026444)
- GdipDisposeImage (Address: 0x10026434)
- GdipFree (Address: 0x10026440)
- GdipGetImageEncoders (Address: 0x10026448)
- GdipGetImageEncodersSize (Address: 0x1002642c)
- GdiplusShutdown (Address: 0x1002644c)
- GdiplusStartup (Address: 0x10026428)
- GdipSaveImageToFile (Address: 0x10026430)
HID.DLL
- HidP_GetCaps (Address: 0x100260d0)
- HidP_GetLinkCollectionNodes (Address: 0x100260c0)
- HidP_GetUsages (Address: 0x100260c8)
- HidP_GetUsageValue (Address: 0x100260cc)
- HidP_GetValueCaps (Address: 0x100260c4)
KERNEL32.dll
- CloseHandle (Address: 0x10026118)
- CreateDirectoryW (Address: 0x10026174)
- CreateEventW (Address: 0x10026200)
- CreateFileMappingW (Address: 0x100261f0)
- CreateFileW (Address: 0x10026190)
- CreateMutexExW (Address: 0x10026124)
- CreateSemaphoreExW (Address: 0x100260e4)
- CreateThread (Address: 0x1002617c)
- DebugBreak (Address: 0x10026134)
- DeleteCriticalSection (Address: 0x100261d8)
- DeleteFileW (Address: 0x100261b0)
- DuplicateHandle (Address: 0x1002623c)
- EnterCriticalSection (Address: 0x10026140)
- ExitProcess (Address: 0x1002614c)
- ExpandEnvironmentStringsW (Address: 0x10026170)
- FileTimeToSystemTime (Address: 0x1002620c)
- FindClose (Address: 0x10026218)
- FindFirstFileW (Address: 0x1002621c)
- FindNextFileW (Address: 0x100261c4)
- FindResourceW (Address: 0x100261b8)
- FormatMessageW (Address: 0x10026104)
- FreeLibrary (Address: 0x10026224)
- GetCurrentProcess (Address: 0x1002619c)
- GetCurrentProcessId (Address: 0x10026128)
- GetCurrentThread (Address: 0x10026248)
- GetCurrentThreadId (Address: 0x100260fc)
- GetDateFormatW (Address: 0x100261f8)
- GetDriveTypeW (Address: 0x100261c8)
- GetFileAttributesW (Address: 0x10026168)
- GetFileSize (Address: 0x100261bc)
- GetLastError (Address: 0x10026108)
- GetLongPathNameW (Address: 0x100261cc)
- GetModuleFileNameA (Address: 0x100260e0)
- GetModuleHandleExW (Address: 0x100260f4)
- GetModuleHandleW (Address: 0x10026130)
- GetProcAddress (Address: 0x10026120)
- GetProcessHeap (Address: 0x1002612c)
- GetProductInfo (Address: 0x10026210)
- GetSystemDirectoryW (Address: 0x10026234)
- GetSystemTimeAsFileTime (Address: 0x1002615c)
- GetThreadPriority (Address: 0x10026244)
- GetTickCount (Address: 0x10026148)
- GetTimeFormatW (Address: 0x10026204)
- GetVersionExW (Address: 0x10026214)
- GetWindowsDirectoryW (Address: 0x10026228)
- HeapAlloc (Address: 0x1002611c)
- HeapFree (Address: 0x100260e8)
- HeapReAlloc (Address: 0x100261dc)
- InitializeConditionVariable (Address: 0x100261fc)
- InitializeCriticalSection (Address: 0x1002613c)
- IsDebuggerPresent (Address: 0x10026138)
- K32GetModuleFileNameExW (Address: 0x10026154)
- LeaveCriticalSection (Address: 0x10026144)
- LoadLibraryExW (Address: 0x10026220)
- LoadLibraryW (Address: 0x1002622c)
- LoadResource (Address: 0x100261b4)
- LocalFree (Address: 0x10026158)
- LockResource (Address: 0x100261ac)
- MapViewOfFile (Address: 0x100261f4)
- MoveFileExW (Address: 0x1002618c)
- MultiByteToWideChar (Address: 0x100260dc)
- OpenProcess (Address: 0x100261d4)
- OpenSemaphoreW (Address: 0x10026114)
- OutputDebugStringW (Address: 0x1002610c)
- QueryFullProcessImageNameW (Address: 0x10026164)
- QueryPerformanceCounter (Address: 0x100261a4)
- ReadFile (Address: 0x100261d0)
- ReadProcessMemory (Address: 0x10026160)
- RegisterWaitForSingleObject (Address: 0x10026188)
- ReleaseMutex (Address: 0x10026100)
- ReleaseSemaphore (Address: 0x100260f0)
- RemoveDirectoryW (Address: 0x1002616c)
- ResetEvent (Address: 0x10026240)
- ResumeThread (Address: 0x10026230)
- SearchPathW (Address: 0x10026238)
- SetEvent (Address: 0x1002624c)
- SetLastError (Address: 0x100260ec)
- SetThreadPriority (Address: 0x100261ec)
- SetUnhandledExceptionFilter (Address: 0x10026198)
- SizeofResource (Address: 0x100261a8)
- Sleep (Address: 0x10026180)
- SleepConditionVariableCS (Address: 0x100261e0)
- SystemTimeToTzSpecificLocalTime (Address: 0x10026208)
- TerminateProcess (Address: 0x100261a0)
- UnhandledExceptionFilter (Address: 0x10026194)
- UnmapViewOfFile (Address: 0x100260d8)
- UnregisterWait (Address: 0x10026184)
- WaitForMultipleObjects (Address: 0x10026178)
- WaitForSingleObject (Address: 0x100260f8)
- WaitForSingleObjectEx (Address: 0x10026110)
- WakeAllConditionVariable (Address: 0x100261e4)
- WakeConditionVariable (Address: 0x100261e8)
- WideCharToMultiByte (Address: 0x100261c0)
- WriteFile (Address: 0x10026150)
msdrm.dll
- DRMIsWindowProtected (Address: 0x10026454)
MSIMG32.dll
- AlphaBlend (Address: 0x10026254)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x10026470)
- __dllonexit (Address: 0x100264f0)
- _amsg_exit (Address: 0x10026490)
- _callnewh (Address: 0x10026488)
- _CxxThrowException (Address: 0x100264dc)
- _except_handler4_common (Address: 0x100264a8)
- _ftol2 (Address: 0x100264e0)
- _ftol2_sse (Address: 0x100264e4)
- _initterm (Address: 0x10026494)
- _itow_s (Address: 0x100264b4)
- _lock (Address: 0x1002649c)
- _onexit (Address: 0x100264a4)
- _purecall (Address: 0x1002647c)
- _snwscanf_s (Address: 0x100264f8)
- _unlock (Address: 0x100264a0)
- _vscwprintf (Address: 0x100264fc)
- _vsnprintf (Address: 0x10026478)
- _vsnprintf_s (Address: 0x1002646c)
- _vsnwprintf (Address: 0x100264ec)
- _wcsicmp (Address: 0x10026474)
- _wcsnicmp (Address: 0x100264cc)
- _wcstoui64 (Address: 0x100264b8)
- _wcsupr (Address: 0x100264c4)
- _wtoi (Address: 0x100264d0)
- _XcptFilter (Address: 0x1002648c)
- ??0exception@@QAE@ABV0@@Z (Address: 0x10026468)
- ??0exception@@QAE@XZ (Address: 0x10026464)
- ??1exception@@UAE@XZ (Address: 0x10026460)
- ??1type_info@@UAE@XZ (Address: 0x100264f4)
- ?terminate@@YAXXZ (Address: 0x10026498)
- free (Address: 0x10026480)
- malloc (Address: 0x10026484)
- memcpy (Address: 0x100264e8)
- memcpy_s (Address: 0x1002645c)
- memmove (Address: 0x100264ac)
- memset (Address: 0x10026500)
- wcschr (Address: 0x100264d4)
- wcscpy_s (Address: 0x100264b0)
- wcsrchr (Address: 0x100264c8)
- wcsstr (Address: 0x100264c0)
- wcstol (Address: 0x100264d8)
- wcstoul (Address: 0x100264bc)
ntdll.dll
- NtApphelpCacheControl (Address: 0x10026518)
- NtClose (Address: 0x10026520)
- NtQueryInformationProcess (Address: 0x10026530)
- NtQueryValueKey (Address: 0x1002651c)
- RtlAllocateHeap (Address: 0x10026528)
- RtlAppendUnicodeStringToString (Address: 0x1002653c)
- RtlAppendUnicodeToString (Address: 0x10026540)
- RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x1002650c)
- RtlFormatCurrentUserKeyPath (Address: 0x10026544)
- RtlFreeHeap (Address: 0x10026524)
- RtlFreeUnicodeString (Address: 0x10026508)
- RtlGetFullPathName_UEx (Address: 0x10026510)
- RtlInitUnicodeString (Address: 0x10026514)
- RtlInitUnicodeStringEx (Address: 0x1002652c)
- ZwClose (Address: 0x10026534)
- ZwCreateFile (Address: 0x10026548)
- ZwOpenKey (Address: 0x10026538)
ole32.dll
- CLSIDFromString (Address: 0x10026568)
- CoCreateGuid (Address: 0x10026564)
- CoCreateInstance (Address: 0x1002655c)
- CoInitialize (Address: 0x10026560)
- CoInitializeEx (Address: 0x10026558)
- CoUninitialize (Address: 0x10026554)
- StringFromGUID2 (Address: 0x10026550)
OLEACC.dll
- GetRoleTextW (Address: 0x1002625c)
OLEAUT32.dll
- SysAllocString (Address: 0x10026264)
- SysFreeString (Address: 0x1002626c)
- SysStringLen (Address: 0x10026268)
- VariantClear (Address: 0x10026274)
- VariantInit (Address: 0x10026270)
RPCRT4.dll
- NdrServerCall2 (Address: 0x1002627c)
- RpcServerListen (Address: 0x10026288)
- RpcServerRegisterIf2 (Address: 0x10026284)
- RpcServerUseProtseqEpW (Address: 0x10026280)
SHELL32.dll
- CommandLineToArgvW (Address: 0x10026290)
- ShellExecuteW (Address: 0x10026298)
- SHFileOperationW (Address: 0x10026294)
SHLWAPI.dll
- PathCombineW (Address: 0x100262a4)
- PathFindFileNameW (Address: 0x100262a0)
- PathRemoveBlanksW (Address: 0x100262a8)
- PathRemoveExtensionW (Address: 0x100262b0)
- SHCreateStreamOnFileEx (Address: 0x100262ac)
USER32.dll
- BeginPaint (Address: 0x100263b0)
- CallNextHookEx (Address: 0x100263b8)
- ClientToScreen (Address: 0x100262c8)
- CloseDesktop (Address: 0x100262c0)
- CopyImage (Address: 0x10026304)
- CreateDesktopW (Address: 0x100262d0)
- CreateDialogParamW (Address: 0x10026320)
- CreateWindowExW (Address: 0x100263e8)
- DefWindowProcW (Address: 0x100263f8)
- DestroyWindow (Address: 0x100263dc)
- DispatchMessageW (Address: 0x10026334)
- DrawIcon (Address: 0x10026358)
- EnableWindow (Address: 0x100262f8)
- EndPaint (Address: 0x10026400)
- EnumWindows (Address: 0x100263d8)
- FillRect (Address: 0x10026308)
- FindWindowExW (Address: 0x100263c0)
- FindWindowW (Address: 0x100262dc)
- GetAsyncKeyState (Address: 0x1002638c)
- GetClassNameW (Address: 0x10026368)
- GetClientRect (Address: 0x100263f4)
- GetCursorInfo (Address: 0x10026348)
- GetCursorPos (Address: 0x100263a4)
- GetDC (Address: 0x10026350)
- GetDesktopWindow (Address: 0x10026354)
- GetDlgItem (Address: 0x100262ec)
- GetDoubleClickTime (Address: 0x10026398)
- GetGUIThreadInfo (Address: 0x10026404)
- GetIconInfo (Address: 0x1002635c)
- GetKeyNameTextW (Address: 0x1002637c)
- GetKeyState (Address: 0x10026378)
- GetMessageW (Address: 0x1002633c)
- GetParent (Address: 0x10026370)
- GetPointerDevices (Address: 0x1002632c)
- GetProcessDefaultLayout (Address: 0x100262e0)
- GetRawInputData (Address: 0x100263fc)
- GetRawInputDeviceInfoW (Address: 0x10026328)
- GetSystemMetrics (Address: 0x10026394)
- GetThreadDesktop (Address: 0x100262bc)
- GetWindowInfo (Address: 0x10026384)
- GetWindowLongW (Address: 0x10026374)
- GetWindowRect (Address: 0x10026364)
- GetWindowTextLengthW (Address: 0x10026324)
- GetWindowTextW (Address: 0x100262fc)
- GetWindowThreadProcessId (Address: 0x10026344)
- InternalGetWindowText (Address: 0x1002636c)
- InvalidateRect (Address: 0x100263a8)
- IsDialogMessageW (Address: 0x100262c4)
- IsHungAppWindow (Address: 0x1002639c)
- IsRectEmpty (Address: 0x100262d4)
- LoadCursorW (Address: 0x10026360)
- LoadIconW (Address: 0x100262d8)
- LoadImageW (Address: 0x10026390)
- MapVirtualKeyW (Address: 0x10026380)
- MsgWaitForMultipleObjectsEx (Address: 0x1002631c)
- PeekMessageW (Address: 0x10026318)
- PhysicalToLogicalPointForPerMonitorDPI (Address: 0x100263d4)
- PostThreadMessageW (Address: 0x10026330)
- PtInRect (Address: 0x10026388)
- RegisterClassExW (Address: 0x100263e4)
- RegisterRawInputDevices (Address: 0x100263e0)
- RegisterWindowMessageW (Address: 0x10026408)
- ReleaseCapture (Address: 0x100262f4)
- ReleaseDC (Address: 0x1002634c)
- SendMessageW (Address: 0x100263a0)
- SetCapture (Address: 0x100262e4)
- SetLayeredWindowAttributes (Address: 0x100263ec)
- SetProcessDefaultLayout (Address: 0x100262cc)
- SetThreadDesktop (Address: 0x100262b8)
- SetTimer (Address: 0x10026314)
- SetWindowLongW (Address: 0x100263f0)
- SetWindowPos (Address: 0x10026300)
- SetWindowsHookExW (Address: 0x100263bc)
- SetWinEventHook (Address: 0x100263c8)
- ShowWindow (Address: 0x10026310)
- ShowWindowAsync (Address: 0x100263cc)
- SwitchDesktop (Address: 0x100262e8)
- SystemParametersInfoW (Address: 0x100262f0)
- TranslateMessage (Address: 0x10026338)
- UnhookWindowsHookEx (Address: 0x100263b4)
- UnhookWinEvent (Address: 0x100263d0)
- UnregisterClassW (Address: 0x1002630c)
- UpdateWindow (Address: 0x100263ac)
- WindowFromPhysicalPoint (Address: 0x100263c4)
- WindowFromPoint (Address: 0x10026340)
VERSION.dll
- GetFileVersionInfoSizeW (Address: 0x10026418)
- GetFileVersionInfoW (Address: 0x10026410)
- VerQueryValueW (Address: 0x10026414)
XmlLite.dll
- CreateXmlWriter (Address: 0x10026420)