uireng.dll

Description: UI Recording Engine Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 32-bit

Operating System: Windows NT

SHA256: b43c50ad727ae6774bb03f75d1c9b937

File Size: 242.0 KB

Uploaded At: Dec. 1, 2025, 8:05 a.m.

Views: 15

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • UirGetScreenComment (Ordinal: 1, Address: 0xe2a0)
  • UirInitializeEngine (Ordinal: 2, Address: 0xdde0)
  • UirIsRecordingActive (Ordinal: 3, Address: 0xe320)
  • UirOutCreateOutputFile (Ordinal: 4, Address: 0xe3b0)
  • UirPauseRecordingSession (Ordinal: 5, Address: 0xe0f0)
  • UirResumeRecordingSession (Ordinal: 6, Address: 0xe170)
  • UirStartRecordingSession (Ordinal: 7, Address: 0xdfa0)
  • UirStopRecordingSession (Ordinal: 8, Address: 0xe070)
  • UirUninitializeEngine (Ordinal: 9, Address: 0xdeb0)
  • UirUpdateRecordingSession (Ordinal: 10, Address: 0xe1f0)

Imported DLLs & Functions

ADVAPI32.dll
  • CloseTrace (Address: 0x10026028)
  • ControlTraceW (Address: 0x10026038)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x10026024)
  • EnableTrace (Address: 0x10026044)
  • EnableTraceEx (Address: 0x1002603c)
  • EventRegister (Address: 0x10026050)
  • EventUnregister (Address: 0x1002604c)
  • EventWriteString (Address: 0x10026034)
  • FlushTraceW (Address: 0x10026040)
  • GetTraceEnableFlags (Address: 0x10026014)
  • GetTraceEnableLevel (Address: 0x10026018)
  • GetTraceLoggerHandle (Address: 0x1002601c)
  • OpenTraceW (Address: 0x10026030)
  • ProcessTrace (Address: 0x1002602c)
  • RegCloseKey (Address: 0x10026008)
  • RegisterTraceGuidsW (Address: 0x10026010)
  • RegOpenKeyExW (Address: 0x10026054)
  • RegOpenKeyW (Address: 0x10026004)
  • RegQueryValueExW (Address: 0x10026000)
  • StartTraceW (Address: 0x10026048)
  • TraceMessage (Address: 0x10026020)
  • UnregisterTraceGuids (Address: 0x1002600c)
AEPIC.dll
  • PicFreeFileInfo (Address: 0x10026060)
  • PicRetrieveFileInfo (Address: 0x1002605c)
GDI32.dll
  • BitBlt (Address: 0x10026078)
  • CreateCompatibleBitmap (Address: 0x10026074)
  • CreateCompatibleDC (Address: 0x10026068)
  • CreateDCW (Address: 0x10026070)
  • CreatePen (Address: 0x10026080)
  • CreateSolidBrush (Address: 0x100260b4)
  • DeleteDC (Address: 0x100260a8)
  • DeleteObject (Address: 0x1002607c)
  • Ellipse (Address: 0x100260a4)
  • ExcludeClipRect (Address: 0x1002606c)
  • ExtCreatePen (Address: 0x10026090)
  • GetCurrentObject (Address: 0x100260ac)
  • GetObjectW (Address: 0x10026088)
  • GetStockObject (Address: 0x100260b0)
  • LineTo (Address: 0x10026098)
  • MoveToEx (Address: 0x10026094)
  • PolyBezier (Address: 0x1002609c)
  • Rectangle (Address: 0x1002608c)
  • SelectObject (Address: 0x10026084)
  • SetDCBrushColor (Address: 0x100260a0)
  • StretchBlt (Address: 0x100260b8)
gdiplus.dll
  • GdipAlloc (Address: 0x1002643c)
  • GdipCloneImage (Address: 0x10026438)
  • GdipCreateBitmapFromHBITMAP (Address: 0x10026444)
  • GdipDisposeImage (Address: 0x10026434)
  • GdipFree (Address: 0x10026440)
  • GdipGetImageEncoders (Address: 0x10026448)
  • GdipGetImageEncodersSize (Address: 0x1002642c)
  • GdiplusShutdown (Address: 0x1002644c)
  • GdiplusStartup (Address: 0x10026428)
  • GdipSaveImageToFile (Address: 0x10026430)
HID.DLL
  • HidP_GetCaps (Address: 0x100260d0)
  • HidP_GetLinkCollectionNodes (Address: 0x100260c0)
  • HidP_GetUsages (Address: 0x100260c8)
  • HidP_GetUsageValue (Address: 0x100260cc)
  • HidP_GetValueCaps (Address: 0x100260c4)
KERNEL32.dll
  • CloseHandle (Address: 0x10026118)
  • CreateDirectoryW (Address: 0x10026174)
  • CreateEventW (Address: 0x10026200)
  • CreateFileMappingW (Address: 0x100261f0)
  • CreateFileW (Address: 0x10026190)
  • CreateMutexExW (Address: 0x10026124)
  • CreateSemaphoreExW (Address: 0x100260e4)
  • CreateThread (Address: 0x1002617c)
  • DebugBreak (Address: 0x10026134)
  • DeleteCriticalSection (Address: 0x100261d8)
  • DeleteFileW (Address: 0x100261b0)
  • DuplicateHandle (Address: 0x1002623c)
  • EnterCriticalSection (Address: 0x10026140)
  • ExitProcess (Address: 0x1002614c)
  • ExpandEnvironmentStringsW (Address: 0x10026170)
  • FileTimeToSystemTime (Address: 0x1002620c)
  • FindClose (Address: 0x10026218)
  • FindFirstFileW (Address: 0x1002621c)
  • FindNextFileW (Address: 0x100261c4)
  • FindResourceW (Address: 0x100261b8)
  • FormatMessageW (Address: 0x10026104)
  • FreeLibrary (Address: 0x10026224)
  • GetCurrentProcess (Address: 0x1002619c)
  • GetCurrentProcessId (Address: 0x10026128)
  • GetCurrentThread (Address: 0x10026248)
  • GetCurrentThreadId (Address: 0x100260fc)
  • GetDateFormatW (Address: 0x100261f8)
  • GetDriveTypeW (Address: 0x100261c8)
  • GetFileAttributesW (Address: 0x10026168)
  • GetFileSize (Address: 0x100261bc)
  • GetLastError (Address: 0x10026108)
  • GetLongPathNameW (Address: 0x100261cc)
  • GetModuleFileNameA (Address: 0x100260e0)
  • GetModuleHandleExW (Address: 0x100260f4)
  • GetModuleHandleW (Address: 0x10026130)
  • GetProcAddress (Address: 0x10026120)
  • GetProcessHeap (Address: 0x1002612c)
  • GetProductInfo (Address: 0x10026210)
  • GetSystemDirectoryW (Address: 0x10026234)
  • GetSystemTimeAsFileTime (Address: 0x1002615c)
  • GetThreadPriority (Address: 0x10026244)
  • GetTickCount (Address: 0x10026148)
  • GetTimeFormatW (Address: 0x10026204)
  • GetVersionExW (Address: 0x10026214)
  • GetWindowsDirectoryW (Address: 0x10026228)
  • HeapAlloc (Address: 0x1002611c)
  • HeapFree (Address: 0x100260e8)
  • HeapReAlloc (Address: 0x100261dc)
  • InitializeConditionVariable (Address: 0x100261fc)
  • InitializeCriticalSection (Address: 0x1002613c)
  • IsDebuggerPresent (Address: 0x10026138)
  • K32GetModuleFileNameExW (Address: 0x10026154)
  • LeaveCriticalSection (Address: 0x10026144)
  • LoadLibraryExW (Address: 0x10026220)
  • LoadLibraryW (Address: 0x1002622c)
  • LoadResource (Address: 0x100261b4)
  • LocalFree (Address: 0x10026158)
  • LockResource (Address: 0x100261ac)
  • MapViewOfFile (Address: 0x100261f4)
  • MoveFileExW (Address: 0x1002618c)
  • MultiByteToWideChar (Address: 0x100260dc)
  • OpenProcess (Address: 0x100261d4)
  • OpenSemaphoreW (Address: 0x10026114)
  • OutputDebugStringW (Address: 0x1002610c)
  • QueryFullProcessImageNameW (Address: 0x10026164)
  • QueryPerformanceCounter (Address: 0x100261a4)
  • ReadFile (Address: 0x100261d0)
  • ReadProcessMemory (Address: 0x10026160)
  • RegisterWaitForSingleObject (Address: 0x10026188)
  • ReleaseMutex (Address: 0x10026100)
  • ReleaseSemaphore (Address: 0x100260f0)
  • RemoveDirectoryW (Address: 0x1002616c)
  • ResetEvent (Address: 0x10026240)
  • ResumeThread (Address: 0x10026230)
  • SearchPathW (Address: 0x10026238)
  • SetEvent (Address: 0x1002624c)
  • SetLastError (Address: 0x100260ec)
  • SetThreadPriority (Address: 0x100261ec)
  • SetUnhandledExceptionFilter (Address: 0x10026198)
  • SizeofResource (Address: 0x100261a8)
  • Sleep (Address: 0x10026180)
  • SleepConditionVariableCS (Address: 0x100261e0)
  • SystemTimeToTzSpecificLocalTime (Address: 0x10026208)
  • TerminateProcess (Address: 0x100261a0)
  • UnhandledExceptionFilter (Address: 0x10026194)
  • UnmapViewOfFile (Address: 0x100260d8)
  • UnregisterWait (Address: 0x10026184)
  • WaitForMultipleObjects (Address: 0x10026178)
  • WaitForSingleObject (Address: 0x100260f8)
  • WaitForSingleObjectEx (Address: 0x10026110)
  • WakeAllConditionVariable (Address: 0x100261e4)
  • WakeConditionVariable (Address: 0x100261e8)
  • WideCharToMultiByte (Address: 0x100261c0)
  • WriteFile (Address: 0x10026150)
msdrm.dll
  • DRMIsWindowProtected (Address: 0x10026454)
MSIMG32.dll
  • AlphaBlend (Address: 0x10026254)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x10026470)
  • __dllonexit (Address: 0x100264f0)
  • _amsg_exit (Address: 0x10026490)
  • _callnewh (Address: 0x10026488)
  • _CxxThrowException (Address: 0x100264dc)
  • _except_handler4_common (Address: 0x100264a8)
  • _ftol2 (Address: 0x100264e0)
  • _ftol2_sse (Address: 0x100264e4)
  • _initterm (Address: 0x10026494)
  • _itow_s (Address: 0x100264b4)
  • _lock (Address: 0x1002649c)
  • _onexit (Address: 0x100264a4)
  • _purecall (Address: 0x1002647c)
  • _snwscanf_s (Address: 0x100264f8)
  • _unlock (Address: 0x100264a0)
  • _vscwprintf (Address: 0x100264fc)
  • _vsnprintf (Address: 0x10026478)
  • _vsnprintf_s (Address: 0x1002646c)
  • _vsnwprintf (Address: 0x100264ec)
  • _wcsicmp (Address: 0x10026474)
  • _wcsnicmp (Address: 0x100264cc)
  • _wcstoui64 (Address: 0x100264b8)
  • _wcsupr (Address: 0x100264c4)
  • _wtoi (Address: 0x100264d0)
  • _XcptFilter (Address: 0x1002648c)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x10026468)
  • ??0exception@@QAE@XZ (Address: 0x10026464)
  • ??1exception@@UAE@XZ (Address: 0x10026460)
  • ??1type_info@@UAE@XZ (Address: 0x100264f4)
  • ?terminate@@YAXXZ (Address: 0x10026498)
  • free (Address: 0x10026480)
  • malloc (Address: 0x10026484)
  • memcpy (Address: 0x100264e8)
  • memcpy_s (Address: 0x1002645c)
  • memmove (Address: 0x100264ac)
  • memset (Address: 0x10026500)
  • wcschr (Address: 0x100264d4)
  • wcscpy_s (Address: 0x100264b0)
  • wcsrchr (Address: 0x100264c8)
  • wcsstr (Address: 0x100264c0)
  • wcstol (Address: 0x100264d8)
  • wcstoul (Address: 0x100264bc)
ntdll.dll
  • NtApphelpCacheControl (Address: 0x10026518)
  • NtClose (Address: 0x10026520)
  • NtQueryInformationProcess (Address: 0x10026530)
  • NtQueryValueKey (Address: 0x1002651c)
  • RtlAllocateHeap (Address: 0x10026528)
  • RtlAppendUnicodeStringToString (Address: 0x1002653c)
  • RtlAppendUnicodeToString (Address: 0x10026540)
  • RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x1002650c)
  • RtlFormatCurrentUserKeyPath (Address: 0x10026544)
  • RtlFreeHeap (Address: 0x10026524)
  • RtlFreeUnicodeString (Address: 0x10026508)
  • RtlGetFullPathName_UEx (Address: 0x10026510)
  • RtlInitUnicodeString (Address: 0x10026514)
  • RtlInitUnicodeStringEx (Address: 0x1002652c)
  • ZwClose (Address: 0x10026534)
  • ZwCreateFile (Address: 0x10026548)
  • ZwOpenKey (Address: 0x10026538)
ole32.dll
  • CLSIDFromString (Address: 0x10026568)
  • CoCreateGuid (Address: 0x10026564)
  • CoCreateInstance (Address: 0x1002655c)
  • CoInitialize (Address: 0x10026560)
  • CoInitializeEx (Address: 0x10026558)
  • CoUninitialize (Address: 0x10026554)
  • StringFromGUID2 (Address: 0x10026550)
OLEACC.dll
  • GetRoleTextW (Address: 0x1002625c)
OLEAUT32.dll
  • SysAllocString (Address: 0x10026264)
  • SysFreeString (Address: 0x1002626c)
  • SysStringLen (Address: 0x10026268)
  • VariantClear (Address: 0x10026274)
  • VariantInit (Address: 0x10026270)
RPCRT4.dll
  • NdrServerCall2 (Address: 0x1002627c)
  • RpcServerListen (Address: 0x10026288)
  • RpcServerRegisterIf2 (Address: 0x10026284)
  • RpcServerUseProtseqEpW (Address: 0x10026280)
SHELL32.dll
  • CommandLineToArgvW (Address: 0x10026290)
  • ShellExecuteW (Address: 0x10026298)
  • SHFileOperationW (Address: 0x10026294)
SHLWAPI.dll
  • PathCombineW (Address: 0x100262a4)
  • PathFindFileNameW (Address: 0x100262a0)
  • PathRemoveBlanksW (Address: 0x100262a8)
  • PathRemoveExtensionW (Address: 0x100262b0)
  • SHCreateStreamOnFileEx (Address: 0x100262ac)
USER32.dll
  • BeginPaint (Address: 0x100263b0)
  • CallNextHookEx (Address: 0x100263b8)
  • ClientToScreen (Address: 0x100262c8)
  • CloseDesktop (Address: 0x100262c0)
  • CopyImage (Address: 0x10026304)
  • CreateDesktopW (Address: 0x100262d0)
  • CreateDialogParamW (Address: 0x10026320)
  • CreateWindowExW (Address: 0x100263e8)
  • DefWindowProcW (Address: 0x100263f8)
  • DestroyWindow (Address: 0x100263dc)
  • DispatchMessageW (Address: 0x10026334)
  • DrawIcon (Address: 0x10026358)
  • EnableWindow (Address: 0x100262f8)
  • EndPaint (Address: 0x10026400)
  • EnumWindows (Address: 0x100263d8)
  • FillRect (Address: 0x10026308)
  • FindWindowExW (Address: 0x100263c0)
  • FindWindowW (Address: 0x100262dc)
  • GetAsyncKeyState (Address: 0x1002638c)
  • GetClassNameW (Address: 0x10026368)
  • GetClientRect (Address: 0x100263f4)
  • GetCursorInfo (Address: 0x10026348)
  • GetCursorPos (Address: 0x100263a4)
  • GetDC (Address: 0x10026350)
  • GetDesktopWindow (Address: 0x10026354)
  • GetDlgItem (Address: 0x100262ec)
  • GetDoubleClickTime (Address: 0x10026398)
  • GetGUIThreadInfo (Address: 0x10026404)
  • GetIconInfo (Address: 0x1002635c)
  • GetKeyNameTextW (Address: 0x1002637c)
  • GetKeyState (Address: 0x10026378)
  • GetMessageW (Address: 0x1002633c)
  • GetParent (Address: 0x10026370)
  • GetPointerDevices (Address: 0x1002632c)
  • GetProcessDefaultLayout (Address: 0x100262e0)
  • GetRawInputData (Address: 0x100263fc)
  • GetRawInputDeviceInfoW (Address: 0x10026328)
  • GetSystemMetrics (Address: 0x10026394)
  • GetThreadDesktop (Address: 0x100262bc)
  • GetWindowInfo (Address: 0x10026384)
  • GetWindowLongW (Address: 0x10026374)
  • GetWindowRect (Address: 0x10026364)
  • GetWindowTextLengthW (Address: 0x10026324)
  • GetWindowTextW (Address: 0x100262fc)
  • GetWindowThreadProcessId (Address: 0x10026344)
  • InternalGetWindowText (Address: 0x1002636c)
  • InvalidateRect (Address: 0x100263a8)
  • IsDialogMessageW (Address: 0x100262c4)
  • IsHungAppWindow (Address: 0x1002639c)
  • IsRectEmpty (Address: 0x100262d4)
  • LoadCursorW (Address: 0x10026360)
  • LoadIconW (Address: 0x100262d8)
  • LoadImageW (Address: 0x10026390)
  • MapVirtualKeyW (Address: 0x10026380)
  • MsgWaitForMultipleObjectsEx (Address: 0x1002631c)
  • PeekMessageW (Address: 0x10026318)
  • PhysicalToLogicalPointForPerMonitorDPI (Address: 0x100263d4)
  • PostThreadMessageW (Address: 0x10026330)
  • PtInRect (Address: 0x10026388)
  • RegisterClassExW (Address: 0x100263e4)
  • RegisterRawInputDevices (Address: 0x100263e0)
  • RegisterWindowMessageW (Address: 0x10026408)
  • ReleaseCapture (Address: 0x100262f4)
  • ReleaseDC (Address: 0x1002634c)
  • SendMessageW (Address: 0x100263a0)
  • SetCapture (Address: 0x100262e4)
  • SetLayeredWindowAttributes (Address: 0x100263ec)
  • SetProcessDefaultLayout (Address: 0x100262cc)
  • SetThreadDesktop (Address: 0x100262b8)
  • SetTimer (Address: 0x10026314)
  • SetWindowLongW (Address: 0x100263f0)
  • SetWindowPos (Address: 0x10026300)
  • SetWindowsHookExW (Address: 0x100263bc)
  • SetWinEventHook (Address: 0x100263c8)
  • ShowWindow (Address: 0x10026310)
  • ShowWindowAsync (Address: 0x100263cc)
  • SwitchDesktop (Address: 0x100262e8)
  • SystemParametersInfoW (Address: 0x100262f0)
  • TranslateMessage (Address: 0x10026338)
  • UnhookWindowsHookEx (Address: 0x100263b4)
  • UnhookWinEvent (Address: 0x100263d0)
  • UnregisterClassW (Address: 0x1002630c)
  • UpdateWindow (Address: 0x100263ac)
  • WindowFromPhysicalPoint (Address: 0x100263c4)
  • WindowFromPoint (Address: 0x10026340)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x10026418)
  • GetFileVersionInfoW (Address: 0x10026410)
  • VerQueryValueW (Address: 0x10026414)
XmlLite.dll
  • CreateXmlWriter (Address: 0x10026420)