Windows.Internal.UI.Shell.WindowTabManager.dll

Description:

Authors:

Version:

Architecture: 32-bit

Operating System:

SHA256: c24573afd5f1e2da5d01de853b0cca5c

File Size: 312.5 KB

Uploaded At: Dec. 1, 2025, 8:06 a.m.

Views: 20

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0xcc40)
  • DllGetActivationFactory (Ordinal: 2, Address: 0xcc90)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x1004900c)
api-ms-win-core-com-l1-1-0.dll
  • CLSIDFromString (Address: 0x1004901c)
  • CoCreateFreeThreadedMarshaler (Address: 0x10049018)
  • CoCreateInstance (Address: 0x10049040)
  • CoGetObjectContext (Address: 0x10049020)
  • CoIncrementMTAUsage (Address: 0x10049014)
  • CoRevertToSelf (Address: 0x10049024)
  • CoTaskMemAlloc (Address: 0x1004902c)
  • CoTaskMemFree (Address: 0x10049030)
  • CoTaskMemRealloc (Address: 0x10049028)
  • CoWaitForMultipleHandles (Address: 0x10049034)
  • PropVariantClear (Address: 0x1004903c)
  • StringFromCLSID (Address: 0x10049038)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x10049048)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x10049054)
  • IsDebuggerPresent (Address: 0x10049058)
  • OutputDebugStringW (Address: 0x10049050)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1004906c)
  • RaiseException (Address: 0x10049070)
  • SetLastError (Address: 0x10049068)
  • SetUnhandledExceptionFilter (Address: 0x10049064)
  • UnhandledExceptionFilter (Address: 0x10049060)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x10049078)
  • DuplicateHandle (Address: 0x1004907c)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1004908c)
  • HeapAlloc (Address: 0x10049084)
  • HeapFree (Address: 0x10049088)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x10049098)
  • InterlockedFlushSList (Address: 0x10049094)
  • InterlockedPushEntrySList (Address: 0x1004909c)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x100490a8)
  • GetModuleFileNameA (Address: 0x100490a4)
  • GetModuleHandleExW (Address: 0x100490b0)
  • GetModuleHandleW (Address: 0x100490b4)
  • GetProcAddress (Address: 0x100490ac)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x100490bc)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x100490c4)
  • FlushViewOfFile (Address: 0x100490c8)
  • MapViewOfFile (Address: 0x100490d0)
  • OpenFileMappingW (Address: 0x100490cc)
  • UnmapViewOfFile (Address: 0x100490d8)
  • VirtualQuery (Address: 0x100490d4)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x100490ec)
  • GetCurrentProcessId (Address: 0x100490e8)
  • GetCurrentThread (Address: 0x100490f4)
  • GetCurrentThreadId (Address: 0x100490e0)
  • OpenProcessToken (Address: 0x100490f8)
  • OpenThreadToken (Address: 0x100490f0)
  • TerminateProcess (Address: 0x100490e4)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x10049100)
  • OpenProcess (Address: 0x10049104)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1004910c)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x10049124)
  • RegCreateKeyExW (Address: 0x10049118)
  • RegDeleteValueW (Address: 0x10049128)
  • RegGetValueW (Address: 0x10049114)
  • RegOpenKeyExW (Address: 0x1004911c)
  • RegSetValueExW (Address: 0x10049120)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x10049130)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x10049174)
  • AcquireSRWLockShared (Address: 0x10049178)
  • CreateEventExW (Address: 0x1004913c)
  • CreateEventW (Address: 0x10049180)
  • CreateMutexExW (Address: 0x1004916c)
  • CreateSemaphoreExW (Address: 0x10049148)
  • DeleteCriticalSection (Address: 0x10049144)
  • EnterCriticalSection (Address: 0x1004914c)
  • InitializeCriticalSection (Address: 0x10049140)
  • InitializeCriticalSectionEx (Address: 0x10049138)
  • LeaveCriticalSection (Address: 0x10049150)
  • OpenSemaphoreW (Address: 0x10049168)
  • ReleaseMutex (Address: 0x10049160)
  • ReleaseSemaphore (Address: 0x10049154)
  • ReleaseSRWLockExclusive (Address: 0x10049170)
  • ReleaseSRWLockShared (Address: 0x1004917c)
  • SetEvent (Address: 0x10049158)
  • WaitForSingleObject (Address: 0x1004915c)
  • WaitForSingleObjectEx (Address: 0x10049164)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x10049188)
  • InitOnceComplete (Address: 0x1004918c)
  • InitOnceExecuteOnce (Address: 0x10049190)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x10049198)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetProductInfo (Address: 0x100491a0)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x100491ac)
  • CreateThreadpoolTimer (Address: 0x100491b0)
  • SetThreadpoolTimer (Address: 0x100491b4)
  • TrySubmitThreadpoolCallback (Address: 0x100491a8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x100491b8)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x100491c0)
  • EncodePointer (Address: 0x100491c4)
api-ms-win-core-winrt-error-l1-1-0.dll
  • GetRestrictedErrorInfo (Address: 0x100491d0)
  • RoFailFastWithErrorContext (Address: 0x100491e0)
  • RoOriginateError (Address: 0x100491d8)
  • RoOriginateErrorW (Address: 0x100491d4)
  • RoTransformError (Address: 0x100491dc)
  • SetRestrictedErrorInfo (Address: 0x100491cc)
api-ms-win-core-winrt-error-l1-1-1.dll
  • RoOriginateLanguageException (Address: 0x100491e8)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x100491f0)
  • RoGetActivationFactory (Address: 0x100491f4)
api-ms-win-core-winrt-propertysetprivate-l1-1-1.dll
  • RoCreatePropertySetSerializer (Address: 0x100491fc)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x1004921c)
  • WindowsCreateStringReference (Address: 0x10049214)
  • WindowsDeleteString (Address: 0x10049204)
  • WindowsDeleteStringBuffer (Address: 0x10049208)
  • WindowsDuplicateString (Address: 0x10049218)
  • WindowsGetStringLen (Address: 0x1004922c)
  • WindowsGetStringRawBuffer (Address: 0x10049210)
  • WindowsIsStringEmpty (Address: 0x1004920c)
  • WindowsPreallocateStringBuffer (Address: 0x10049224)
  • WindowsPromoteStringBuffer (Address: 0x10049220)
  • WindowsStringHasEmbeddedNull (Address: 0x10049228)
api-ms-win-crt-private-l1-1-0.dll
  • __CxxFrameHandler3 (Address: 0x100492a0)
  • __std_terminate (Address: 0x1004929c)
  • _CxxThrowException (Address: 0x100492b0)
  • _except_handler4_common (Address: 0x1004927c)
  • _o___std_exception_copy (Address: 0x1004928c)
  • _o___std_exception_destroy (Address: 0x10049288)
  • _o___std_type_info_destroy_list (Address: 0x10049284)
  • _o___stdio_common_vsnprintf_s (Address: 0x10049298)
  • _o___stdio_common_vswprintf (Address: 0x10049294)
  • _o___stdio_common_vswprintf_s (Address: 0x10049290)
  • _o__callnewh (Address: 0x10049280)
  • _o__cexit (Address: 0x10049264)
  • _o__configure_narrow_argv (Address: 0x10049268)
  • _o__crt_atexit (Address: 0x10049234)
  • _o__errno (Address: 0x10049238)
  • _o__execute_onexit_table (Address: 0x1004923c)
  • _o__get_errno (Address: 0x10049240)
  • _o__initialize_narrow_environment (Address: 0x10049244)
  • _o__initialize_onexit_table (Address: 0x10049248)
  • _o__invalid_parameter_noinfo (Address: 0x1004924c)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x10049250)
  • _o__purecall (Address: 0x10049254)
  • _o__register_onexit_function (Address: 0x10049258)
  • _o__seh_filter_dll (Address: 0x1004925c)
  • _o__set_errno (Address: 0x10049260)
  • _o_free (Address: 0x1004926c)
  • _o_iswspace (Address: 0x10049270)
  • _o_malloc (Address: 0x10049274)
  • _o_terminate (Address: 0x10049278)
  • memcmp (Address: 0x100492a8)
  • memcpy (Address: 0x100492a4)
  • memmove (Address: 0x100492ac)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x100492bc)
  • _initterm_e (Address: 0x100492b8)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x100492c4)
  • strlen (Address: 0x100492cc)
  • wcslen (Address: 0x100492c8)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x100492d4)
  • EventRegister (Address: 0x100492e4)
  • EventSetInformation (Address: 0x100492e0)
  • EventUnregister (Address: 0x100492dc)
  • EventWriteTransfer (Address: 0x100492d8)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • GetWindowThreadProcessId (Address: 0x100492ec)
api-ms-win-security-base-l1-1-0.dll
  • DuplicateTokenEx (Address: 0x100492f8)
  • EqualSid (Address: 0x10049304)
  • GetAce (Address: 0x10049300)
  • GetTokenInformation (Address: 0x100492fc)
  • RevertToSelf (Address: 0x100492f4)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x1004930c)
api-ms-win-shcore-comhelpers-l1-1-0.dll
  • IUnknown_QueryService (Address: 0x10049314)
combase.dll
  • (Address: 0x10049320)
  • (Address: 0x1004931c)
ext-ms-win-session-usermgr-l1-1-0.dll
  • UMgrGetConstrainedUserToken (Address: 0x10049328)
  • UMgrOpenProcessTokenForQuery (Address: 0x1004932c)
msvcp_win.dll
  • ?__ExceptionPtrAssign@@YAXPAXPBX@Z (Address: 0x1004936c)
  • ?__ExceptionPtrCopy@@YAXPAXPBX@Z (Address: 0x10049384)
  • ?__ExceptionPtrCopyException@@YAXPAXPBX1@Z (Address: 0x100493b8)
  • ?__ExceptionPtrCreate@@YAXPAX@Z (Address: 0x1004939c)
  • ?__ExceptionPtrCurrentException@@YAXPAX@Z (Address: 0x10049398)
  • ?__ExceptionPtrDestroy@@YAXPAX@Z (Address: 0x10049380)
  • ?__ExceptionPtrRethrow@@YAXPBX@Z (Address: 0x100493a0)
  • ?_Lock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UAEXXZ (Address: 0x10049360)
  • ?_Osfx@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEXXZ (Address: 0x1004933c)
  • ?_Pninc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IAEPA_WXZ (Address: 0x10049378)
  • ?_Unlock@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UAEXXZ (Address: 0x10049374)
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x100493ac)
  • ?_Xlength_error@std@@YAXPBD@Z (Address: 0x100493b4)
  • ?_Xout_of_range@std@@YAXPBD@Z (Address: 0x100493b0)
  • ??0?$basic_ios@_WU?$char_traits@_W@std@@@std@@IAE@XZ (Address: 0x10049368)
  • ??0?$basic_iostream@_WU?$char_traits@_W@std@@@std@@QAE@PAV?$basic_streambuf@_WU?$char_traits@_W@std@@@1@@Z (Address: 0x10049388)
  • ??0?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IAE@XZ (Address: 0x10049340)
  • ??1?$basic_ios@_WU?$char_traits@_W@std@@@std@@UAE@XZ (Address: 0x100493a8)
  • ??1?$basic_iostream@_WU?$char_traits@_W@std@@@std@@UAE@XZ (Address: 0x100493a4)
  • ??1?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@UAE@XZ (Address: 0x10049394)
  • ??6?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV01@_J@Z (Address: 0x1004938c)
  • ?flush@?$basic_ostream@_WU?$char_traits@_W@std@@@std@@QAEAAV12@XZ (Address: 0x10049338)
  • ?gbump@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@IAEXH@Z (Address: 0x1004937c)
  • ?imbue@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MAEXABVlocale@2@@Z (Address: 0x10049348)
  • ?setbuf@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MAEPAV12@PA_W_J@Z (Address: 0x1004934c)
  • ?setstate@?$basic_ios@_WU?$char_traits@_W@std@@@std@@QAEXH_N@Z (Address: 0x10049334)
  • ?showmanyc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MAE_JXZ (Address: 0x10049358)
  • ?sputc@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QAEG_W@Z (Address: 0x10049364)
  • ?sputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@QAE_JPB_W_J@Z (Address: 0x10049344)
  • ?sync@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MAEHXZ (Address: 0x1004935c)
  • ?uflow@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MAEGXZ (Address: 0x10049354)
  • ?uncaught_exception@std@@YA_NXZ (Address: 0x10049370)
  • ?xsgetn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MAE_JPA_W_J@Z (Address: 0x10049350)
  • ?xsputn@?$basic_streambuf@_WU?$char_traits@_W@std@@@std@@MAE_JPB_W_J@Z (Address: 0x10049390)
ntdll.dll
  • NtQuerySecurityObject (Address: 0x100493dc)
  • NtSetSecurityObject (Address: 0x100493c8)
  • RtlAddAccessAllowedAce (Address: 0x100493d4)
  • RtlAddAce (Address: 0x100493d8)
  • RtlCreateAcl (Address: 0x100493c4)
  • RtlCreateSecurityDescriptor (Address: 0x100493ec)
  • RtlFreeUnicodeString (Address: 0x100493f0)
  • RtlGetAce (Address: 0x100493e8)
  • RtlGetDaclSecurityDescriptor (Address: 0x100493e4)
  • RtlGetTokenNamedObjectPath (Address: 0x100493d0)
  • RtlLengthSid (Address: 0x100493e0)
  • RtlQueryInformationAcl (Address: 0x100493c0)
  • RtlSetDaclSecurityDescriptor (Address: 0x100493cc)
OLEAUT32.dll
  • SysFreeString (Address: 0x10049000)
  • SysStringLen (Address: 0x10049004)
twinapi.appcore.dll
  • (Address: 0x100493f8)
  • (Address: 0x100493fc)