IEShims.dll
Description: Internet Explorer Compatibility Shims
Authors: © Microsoft Corporation. All rights reserved.
Version: 11.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 17c70f7c3e80812ec6f9e3c47215bc8a
File Size: 447.0 KB
Uploaded At: Dec. 1, 2025, 8:12 a.m.
Views: 16
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- AcRedirNotify (Ordinal: 1, Address: 0x348c0)
- AcRedirNotifySetEnabled (Ordinal: 2, Address: 0x34950)
- AcRedirSetEnabled (Ordinal: 3, Address: 0x34960)
- IEShims_AdminCheckAndLaunch (Ordinal: 4, Address: 0x234c0)
- IEShims_CreateWindowEx (Ordinal: 5, Address: 0x254b0)
- IEShims_GetOriginatingThreadId (Ordinal: 6, Address: 0x2aad0)
- IEShims_InDllMainContext (Ordinal: 7, Address: 0x25600)
- IEShims_Initialize (Ordinal: 8, Address: 0x9830)
- IEShims_SetRedirectRegistryForThread (Ordinal: 9, Address: 0x6120)
- IEShims_Uninitialize (Ordinal: 10, Address: 0x16230)
Imported DLLs & Functions
api-ms-win-downlevel-advapi32-l1-1-0.dll
- RegCloseKey (Address: 0x18004af68)
- RegCreateKeyExW (Address: 0x18004af88)
- RegEnumKeyExW (Address: 0x18004af98)
- RegEnumValueW (Address: 0x18004afa0)
- RegGetValueW (Address: 0x18004af78)
- RegOpenKeyExW (Address: 0x18004af60)
- RegQueryInfoKeyW (Address: 0x18004af90)
- RegQueryValueExW (Address: 0x18004af70)
- RegSetValueExW (Address: 0x18004af80)
api-ms-win-downlevel-shlwapi-l1-1-0.dll
- PathFindFileNameW (Address: 0x18004b000)
- PathGetArgsW (Address: 0x18004aff8)
- PathIsUNCW (Address: 0x18004afc8)
- PathSkipRootW (Address: 0x18004afc0)
- StrCmpCW (Address: 0x18004afd8)
- StrCmpICA (Address: 0x18004afe0)
- StrCmpICW (Address: 0x18004afd0)
- StrCmpIW (Address: 0x18004b008)
- StrCmpNCW (Address: 0x18004afb8)
- StrCmpNIA (Address: 0x18004afb0)
- StrCmpNICW (Address: 0x18004aff0)
- StrDupW (Address: 0x18004afe8)
iertutil.dll
- (Address: 0x18004b068)
- (Address: 0x18004b048)
- (Address: 0x18004b040)
- (Address: 0x18004b060)
- (Address: 0x18004b018)
- (Address: 0x18004b058)
- (Address: 0x18004b020)
- (Address: 0x18004b038)
- (Address: 0x18004b028)
- (Address: 0x18004b050)
- (Address: 0x18004b030)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18004ae60)
- AcquireSRWLockShared (Address: 0x18004ae70)
- CloseHandle (Address: 0x18004ae80)
- CloseThreadpoolTimer (Address: 0x18004aea8)
- CopyFileExW (Address: 0x18004ace8)
- CreateDirectoryW (Address: 0x18004ad08)
- CreateFileMappingW (Address: 0x18004ac20)
- CreateFileW (Address: 0x18004af48)
- CreateMutexExW (Address: 0x18004aee8)
- CreateMutexW (Address: 0x18004ac50)
- CreateSemaphoreExW (Address: 0x18004aef8)
- CreateThreadpoolTimer (Address: 0x18004aee0)
- DebugBreak (Address: 0x18004ae40)
- DecodePointer (Address: 0x18004af40)
- DelayLoadFailureHook (Address: 0x18004abe8)
- DeleteCriticalSection (Address: 0x18004aec8)
- DeleteProcThreadAttributeList (Address: 0x18004af30)
- DeviceIoControl (Address: 0x18004acf8)
- DuplicateHandle (Address: 0x18004ace0)
- EncodePointer (Address: 0x18004ad18)
- EnterCriticalSection (Address: 0x18004aeb8)
- ExitThread (Address: 0x18004add0)
- ExpandEnvironmentStringsW (Address: 0x18004ae30)
- FindClose (Address: 0x18004ad20)
- FindFirstFileW (Address: 0x18004ad30)
- FindNextFileW (Address: 0x18004ad28)
- FormatMessageW (Address: 0x18004ae00)
- GetCurrentDirectoryW (Address: 0x18004ad88)
- GetCurrentProcess (Address: 0x18004acd8)
- GetCurrentProcessId (Address: 0x18004adb0)
- GetCurrentThreadId (Address: 0x18004ad48)
- GetEnvironmentVariableW (Address: 0x18004ae28)
- GetFileAttributesW (Address: 0x18004ad68)
- GetFileInformationByHandle (Address: 0x18004ad00)
- GetFileSizeEx (Address: 0x18004af50)
- GetFullPathNameW (Address: 0x18004ae20)
- GetLastError (Address: 0x18004adc0)
- GetLogicalDriveStringsW (Address: 0x18004ac08)
- GetLongPathNameW (Address: 0x18004ae18)
- GetModuleFileNameA (Address: 0x18004ae38)
- GetModuleFileNameW (Address: 0x18004ad58)
- GetModuleHandleA (Address: 0x18004acc8)
- GetModuleHandleExW (Address: 0x18004ad50)
- GetModuleHandleW (Address: 0x18004ae48)
- GetProcAddress (Address: 0x18004ada8)
- GetProcessHeap (Address: 0x18004adf0)
- GetProcessId (Address: 0x18004adb8)
- GetProcessIdOfThread (Address: 0x18004add8)
- GetSystemDirectoryW (Address: 0x18004ae08)
- GetSystemTimeAsFileTime (Address: 0x18004ac70)
- GetThreadId (Address: 0x18004ade0)
- GetTickCount (Address: 0x18004ac68)
- GetTickCount64 (Address: 0x18004ac40)
- GetWindowsDirectoryW (Address: 0x18004ae10)
- HeapAlloc (Address: 0x18004ade8)
- HeapFree (Address: 0x18004adf8)
- InitializeCriticalSection (Address: 0x18004ac58)
- InitializeCriticalSectionAndSpinCount (Address: 0x18004abe0)
- InitializeCriticalSectionEx (Address: 0x18004aec0)
- InitializeProcThreadAttributeList (Address: 0x18004af28)
- InitializeSRWLock (Address: 0x18004ac60)
- IsDebuggerPresent (Address: 0x18004ae50)
- IsWow64Process (Address: 0x18004ac38)
- LeaveCriticalSection (Address: 0x18004aef0)
- LoadLibraryA (Address: 0x18004af00)
- LocalAlloc (Address: 0x18004ad78)
- LocalFree (Address: 0x18004ad90)
- lstrcmpiW (Address: 0x18004ad10)
- MapViewOfFile (Address: 0x18004ac18)
- MultiByteToWideChar (Address: 0x18004ad98)
- OpenEventW (Address: 0x18004af20)
- OpenFileMappingW (Address: 0x18004ac30)
- OpenProcess (Address: 0x18004ac48)
- OpenSemaphoreW (Address: 0x18004aed8)
- OutputDebugStringA (Address: 0x18004acc0)
- OutputDebugStringW (Address: 0x18004ae58)
- QueryDosDeviceW (Address: 0x18004ac10)
- QueryFullProcessImageNameW (Address: 0x18004ac00)
- QueryPerformanceCounter (Address: 0x18004ac78)
- RaiseException (Address: 0x18004abf8)
- RaiseFailFastException (Address: 0x18004af08)
- ReleaseMutex (Address: 0x18004ae90)
- ReleaseSemaphore (Address: 0x18004ae88)
- ReleaseSRWLockExclusive (Address: 0x18004ae68)
- ReleaseSRWLockShared (Address: 0x18004ae78)
- ResolveDelayLoadedAPI (Address: 0x18004abf0)
- RtlCaptureContext (Address: 0x18004acb0)
- RtlLookupFunctionEntry (Address: 0x18004aca8)
- RtlVirtualUnwind (Address: 0x18004aca0)
- SearchPathW (Address: 0x18004ad60)
- SetEnvironmentVariableW (Address: 0x18004acd0)
- SetFileAttributesW (Address: 0x18004acf0)
- SetLastError (Address: 0x18004ad70)
- SetThreadpoolTimer (Address: 0x18004ae98)
- SetUnhandledExceptionFilter (Address: 0x18004ac90)
- Sleep (Address: 0x18004acb8)
- SleepConditionVariableSRW (Address: 0x18004ac80)
- TerminateProcess (Address: 0x18004af38)
- TlsAlloc (Address: 0x18004af18)
- TlsFree (Address: 0x18004ad38)
- TlsGetValue (Address: 0x18004af10)
- TlsSetValue (Address: 0x18004adc8)
- UnhandledExceptionFilter (Address: 0x18004ac98)
- UnmapViewOfFile (Address: 0x18004ac28)
- VirtualProtect (Address: 0x18004ad40)
- VirtualQuery (Address: 0x18004ad80)
- WaitForSingleObject (Address: 0x18004aed0)
- WaitForSingleObjectEx (Address: 0x18004aeb0)
- WaitForThreadpoolTimerCallbacks (Address: 0x18004aea0)
- WakeAllConditionVariable (Address: 0x18004ac88)
- WideCharToMultiByte (Address: 0x18004ada0)
msvcrt.dll
- __C_specific_handler (Address: 0x18004b080)
- __CxxFrameHandler3 (Address: 0x18004b1d0)
- __dllonexit (Address: 0x18004b1b8)
- _amsg_exit (Address: 0x18004b098)
- _CxxThrowException (Address: 0x18004b0c8)
- _initterm (Address: 0x18004b120)
- _lock (Address: 0x18004b1a8)
- _onexit (Address: 0x18004b1c0)
- _stricmp (Address: 0x18004b078)
- _unlock (Address: 0x18004b1b0)
- _vscwprintf (Address: 0x18004b108)
- _vsnprintf_s (Address: 0x18004b100)
- _vsnwprintf (Address: 0x18004b110)
- _wcsicmp (Address: 0x18004b0e0)
- _wcslwr (Address: 0x18004b130)
- _wcsnicmp (Address: 0x18004b190)
- _wfopen (Address: 0x18004b0a8)
- _XcptFilter (Address: 0x18004b090)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x18004b0e8)
- ??0exception@@QEAA@XZ (Address: 0x18004b0f8)
- ??1exception@@UEAA@XZ (Address: 0x18004b0f0)
- ??1type_info@@UEAA@XZ (Address: 0x18004b1a0)
- ?terminate@@YAXXZ (Address: 0x18004b0b0)
- calloc (Address: 0x18004b088)
- fclose (Address: 0x18004b0a0)
- fputws (Address: 0x18004b0d0)
- free (Address: 0x18004b178)
- iswctype (Address: 0x18004b158)
- iswspace (Address: 0x18004b188)
- malloc (Address: 0x18004b198)
- memcmp (Address: 0x18004b0c0)
- memcpy_s (Address: 0x18004b168)
- memmove (Address: 0x18004b0b8)
- memmove_s (Address: 0x18004b148)
- memset (Address: 0x18004b1c8)
- realloc (Address: 0x18004b170)
- towlower (Address: 0x18004b150)
- wcschr (Address: 0x18004b140)
- wcscmp (Address: 0x18004b1d8)
- wcsncmp (Address: 0x18004b0d8)
- wcspbrk (Address: 0x18004b138)
- wcsrchr (Address: 0x18004b118)
- wcsspn (Address: 0x18004b160)
- wcsstr (Address: 0x18004b128)
- wcstok_s (Address: 0x18004b180)
ntdll.dll
- NtQueryObject (Address: 0x18004b1f0)
- RtlNtStatusToDosError (Address: 0x18004b1e8)