IEShims.dll

Description: Internet Explorer Compatibility Shims

Authors: © Microsoft Corporation. All rights reserved.

Version: 11.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 17c70f7c3e80812ec6f9e3c47215bc8a

File Size: 447.0 KB

Uploaded At: Dec. 1, 2025, 8:12 a.m.

Views: 16

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • AcRedirNotify (Ordinal: 1, Address: 0x348c0)
  • AcRedirNotifySetEnabled (Ordinal: 2, Address: 0x34950)
  • AcRedirSetEnabled (Ordinal: 3, Address: 0x34960)
  • IEShims_AdminCheckAndLaunch (Ordinal: 4, Address: 0x234c0)
  • IEShims_CreateWindowEx (Ordinal: 5, Address: 0x254b0)
  • IEShims_GetOriginatingThreadId (Ordinal: 6, Address: 0x2aad0)
  • IEShims_InDllMainContext (Ordinal: 7, Address: 0x25600)
  • IEShims_Initialize (Ordinal: 8, Address: 0x9830)
  • IEShims_SetRedirectRegistryForThread (Ordinal: 9, Address: 0x6120)
  • IEShims_Uninitialize (Ordinal: 10, Address: 0x16230)

Imported DLLs & Functions

api-ms-win-downlevel-advapi32-l1-1-0.dll
  • RegCloseKey (Address: 0x18004af68)
  • RegCreateKeyExW (Address: 0x18004af88)
  • RegEnumKeyExW (Address: 0x18004af98)
  • RegEnumValueW (Address: 0x18004afa0)
  • RegGetValueW (Address: 0x18004af78)
  • RegOpenKeyExW (Address: 0x18004af60)
  • RegQueryInfoKeyW (Address: 0x18004af90)
  • RegQueryValueExW (Address: 0x18004af70)
  • RegSetValueExW (Address: 0x18004af80)
api-ms-win-downlevel-shlwapi-l1-1-0.dll
  • PathFindFileNameW (Address: 0x18004b000)
  • PathGetArgsW (Address: 0x18004aff8)
  • PathIsUNCW (Address: 0x18004afc8)
  • PathSkipRootW (Address: 0x18004afc0)
  • StrCmpCW (Address: 0x18004afd8)
  • StrCmpICA (Address: 0x18004afe0)
  • StrCmpICW (Address: 0x18004afd0)
  • StrCmpIW (Address: 0x18004b008)
  • StrCmpNCW (Address: 0x18004afb8)
  • StrCmpNIA (Address: 0x18004afb0)
  • StrCmpNICW (Address: 0x18004aff0)
  • StrDupW (Address: 0x18004afe8)
iertutil.dll
  • (Address: 0x18004b068)
  • (Address: 0x18004b048)
  • (Address: 0x18004b040)
  • (Address: 0x18004b060)
  • (Address: 0x18004b018)
  • (Address: 0x18004b058)
  • (Address: 0x18004b020)
  • (Address: 0x18004b038)
  • (Address: 0x18004b028)
  • (Address: 0x18004b050)
  • (Address: 0x18004b030)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18004ae60)
  • AcquireSRWLockShared (Address: 0x18004ae70)
  • CloseHandle (Address: 0x18004ae80)
  • CloseThreadpoolTimer (Address: 0x18004aea8)
  • CopyFileExW (Address: 0x18004ace8)
  • CreateDirectoryW (Address: 0x18004ad08)
  • CreateFileMappingW (Address: 0x18004ac20)
  • CreateFileW (Address: 0x18004af48)
  • CreateMutexExW (Address: 0x18004aee8)
  • CreateMutexW (Address: 0x18004ac50)
  • CreateSemaphoreExW (Address: 0x18004aef8)
  • CreateThreadpoolTimer (Address: 0x18004aee0)
  • DebugBreak (Address: 0x18004ae40)
  • DecodePointer (Address: 0x18004af40)
  • DelayLoadFailureHook (Address: 0x18004abe8)
  • DeleteCriticalSection (Address: 0x18004aec8)
  • DeleteProcThreadAttributeList (Address: 0x18004af30)
  • DeviceIoControl (Address: 0x18004acf8)
  • DuplicateHandle (Address: 0x18004ace0)
  • EncodePointer (Address: 0x18004ad18)
  • EnterCriticalSection (Address: 0x18004aeb8)
  • ExitThread (Address: 0x18004add0)
  • ExpandEnvironmentStringsW (Address: 0x18004ae30)
  • FindClose (Address: 0x18004ad20)
  • FindFirstFileW (Address: 0x18004ad30)
  • FindNextFileW (Address: 0x18004ad28)
  • FormatMessageW (Address: 0x18004ae00)
  • GetCurrentDirectoryW (Address: 0x18004ad88)
  • GetCurrentProcess (Address: 0x18004acd8)
  • GetCurrentProcessId (Address: 0x18004adb0)
  • GetCurrentThreadId (Address: 0x18004ad48)
  • GetEnvironmentVariableW (Address: 0x18004ae28)
  • GetFileAttributesW (Address: 0x18004ad68)
  • GetFileInformationByHandle (Address: 0x18004ad00)
  • GetFileSizeEx (Address: 0x18004af50)
  • GetFullPathNameW (Address: 0x18004ae20)
  • GetLastError (Address: 0x18004adc0)
  • GetLogicalDriveStringsW (Address: 0x18004ac08)
  • GetLongPathNameW (Address: 0x18004ae18)
  • GetModuleFileNameA (Address: 0x18004ae38)
  • GetModuleFileNameW (Address: 0x18004ad58)
  • GetModuleHandleA (Address: 0x18004acc8)
  • GetModuleHandleExW (Address: 0x18004ad50)
  • GetModuleHandleW (Address: 0x18004ae48)
  • GetProcAddress (Address: 0x18004ada8)
  • GetProcessHeap (Address: 0x18004adf0)
  • GetProcessId (Address: 0x18004adb8)
  • GetProcessIdOfThread (Address: 0x18004add8)
  • GetSystemDirectoryW (Address: 0x18004ae08)
  • GetSystemTimeAsFileTime (Address: 0x18004ac70)
  • GetThreadId (Address: 0x18004ade0)
  • GetTickCount (Address: 0x18004ac68)
  • GetTickCount64 (Address: 0x18004ac40)
  • GetWindowsDirectoryW (Address: 0x18004ae10)
  • HeapAlloc (Address: 0x18004ade8)
  • HeapFree (Address: 0x18004adf8)
  • InitializeCriticalSection (Address: 0x18004ac58)
  • InitializeCriticalSectionAndSpinCount (Address: 0x18004abe0)
  • InitializeCriticalSectionEx (Address: 0x18004aec0)
  • InitializeProcThreadAttributeList (Address: 0x18004af28)
  • InitializeSRWLock (Address: 0x18004ac60)
  • IsDebuggerPresent (Address: 0x18004ae50)
  • IsWow64Process (Address: 0x18004ac38)
  • LeaveCriticalSection (Address: 0x18004aef0)
  • LoadLibraryA (Address: 0x18004af00)
  • LocalAlloc (Address: 0x18004ad78)
  • LocalFree (Address: 0x18004ad90)
  • lstrcmpiW (Address: 0x18004ad10)
  • MapViewOfFile (Address: 0x18004ac18)
  • MultiByteToWideChar (Address: 0x18004ad98)
  • OpenEventW (Address: 0x18004af20)
  • OpenFileMappingW (Address: 0x18004ac30)
  • OpenProcess (Address: 0x18004ac48)
  • OpenSemaphoreW (Address: 0x18004aed8)
  • OutputDebugStringA (Address: 0x18004acc0)
  • OutputDebugStringW (Address: 0x18004ae58)
  • QueryDosDeviceW (Address: 0x18004ac10)
  • QueryFullProcessImageNameW (Address: 0x18004ac00)
  • QueryPerformanceCounter (Address: 0x18004ac78)
  • RaiseException (Address: 0x18004abf8)
  • RaiseFailFastException (Address: 0x18004af08)
  • ReleaseMutex (Address: 0x18004ae90)
  • ReleaseSemaphore (Address: 0x18004ae88)
  • ReleaseSRWLockExclusive (Address: 0x18004ae68)
  • ReleaseSRWLockShared (Address: 0x18004ae78)
  • ResolveDelayLoadedAPI (Address: 0x18004abf0)
  • RtlCaptureContext (Address: 0x18004acb0)
  • RtlLookupFunctionEntry (Address: 0x18004aca8)
  • RtlVirtualUnwind (Address: 0x18004aca0)
  • SearchPathW (Address: 0x18004ad60)
  • SetEnvironmentVariableW (Address: 0x18004acd0)
  • SetFileAttributesW (Address: 0x18004acf0)
  • SetLastError (Address: 0x18004ad70)
  • SetThreadpoolTimer (Address: 0x18004ae98)
  • SetUnhandledExceptionFilter (Address: 0x18004ac90)
  • Sleep (Address: 0x18004acb8)
  • SleepConditionVariableSRW (Address: 0x18004ac80)
  • TerminateProcess (Address: 0x18004af38)
  • TlsAlloc (Address: 0x18004af18)
  • TlsFree (Address: 0x18004ad38)
  • TlsGetValue (Address: 0x18004af10)
  • TlsSetValue (Address: 0x18004adc8)
  • UnhandledExceptionFilter (Address: 0x18004ac98)
  • UnmapViewOfFile (Address: 0x18004ac28)
  • VirtualProtect (Address: 0x18004ad40)
  • VirtualQuery (Address: 0x18004ad80)
  • WaitForSingleObject (Address: 0x18004aed0)
  • WaitForSingleObjectEx (Address: 0x18004aeb0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18004aea0)
  • WakeAllConditionVariable (Address: 0x18004ac88)
  • WideCharToMultiByte (Address: 0x18004ada0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18004b080)
  • __CxxFrameHandler3 (Address: 0x18004b1d0)
  • __dllonexit (Address: 0x18004b1b8)
  • _amsg_exit (Address: 0x18004b098)
  • _CxxThrowException (Address: 0x18004b0c8)
  • _initterm (Address: 0x18004b120)
  • _lock (Address: 0x18004b1a8)
  • _onexit (Address: 0x18004b1c0)
  • _stricmp (Address: 0x18004b078)
  • _unlock (Address: 0x18004b1b0)
  • _vscwprintf (Address: 0x18004b108)
  • _vsnprintf_s (Address: 0x18004b100)
  • _vsnwprintf (Address: 0x18004b110)
  • _wcsicmp (Address: 0x18004b0e0)
  • _wcslwr (Address: 0x18004b130)
  • _wcsnicmp (Address: 0x18004b190)
  • _wfopen (Address: 0x18004b0a8)
  • _XcptFilter (Address: 0x18004b090)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18004b0e8)
  • ??0exception@@QEAA@XZ (Address: 0x18004b0f8)
  • ??1exception@@UEAA@XZ (Address: 0x18004b0f0)
  • ??1type_info@@UEAA@XZ (Address: 0x18004b1a0)
  • ?terminate@@YAXXZ (Address: 0x18004b0b0)
  • calloc (Address: 0x18004b088)
  • fclose (Address: 0x18004b0a0)
  • fputws (Address: 0x18004b0d0)
  • free (Address: 0x18004b178)
  • iswctype (Address: 0x18004b158)
  • iswspace (Address: 0x18004b188)
  • malloc (Address: 0x18004b198)
  • memcmp (Address: 0x18004b0c0)
  • memcpy_s (Address: 0x18004b168)
  • memmove (Address: 0x18004b0b8)
  • memmove_s (Address: 0x18004b148)
  • memset (Address: 0x18004b1c8)
  • realloc (Address: 0x18004b170)
  • towlower (Address: 0x18004b150)
  • wcschr (Address: 0x18004b140)
  • wcscmp (Address: 0x18004b1d8)
  • wcsncmp (Address: 0x18004b0d8)
  • wcspbrk (Address: 0x18004b138)
  • wcsrchr (Address: 0x18004b118)
  • wcsspn (Address: 0x18004b160)
  • wcsstr (Address: 0x18004b128)
  • wcstok_s (Address: 0x18004b180)
ntdll.dll
  • NtQueryObject (Address: 0x18004b1f0)
  • RtlNtStatusToDosError (Address: 0x18004b1e8)