PresentationHostDLL.dll

Description: Windows Presentation Foundation Host Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 3.0.6920.9163

Architecture: 32-bit

Operating System: Windows

SHA256: 8674a5a4db4e5b200d40cbd631bade7a

File Size: 131.6 KB

Uploaded At: Dec. 1, 2025, 8:49 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllMain (Ordinal: 1, Address: 0x6501)
  • Activate (Ordinal: 2, Address: 0x8318)
  • Deactivate (Ordinal: 3, Address: 0x11395)
  • ForwardTranslateAccelerator (Ordinal: 4, Address: 0x31a9)
  • SaveToHistory (Ordinal: 5, Address: 0x1142c)
  • LoadFromHistory (Ordinal: 6, Address: 0x1147f)
  • ProcessUnhandledException (Ordinal: 7, Address: 0x117c1)
  • CreateIDispatchSTAForwarder (Ordinal: 8, Address: 0x18f1d)
  • DRMInitEnvironment (Ordinal: 601, Address: 0x183ef)
  • DRMCreateBoundLicense (Ordinal: 602, Address: 0x18428)
  • DRMCreateLicenseStorageSession (Ordinal: 603, Address: 0x1845b)
  • DRMCreateEnablingBitsDecryptor (Ordinal: 604, Address: 0x18491)
  • DRMCreateEnablingBitsEncryptor (Ordinal: 605, Address: 0x184c4)
  • DRMEncrypt (Ordinal: 606, Address: 0x184f7)
  • DRMDecrypt (Ordinal: 607, Address: 0x1852d)
  • DRMGetInfo (Ordinal: 608, Address: 0x18563)
  • DRMGetBoundLicenseObjectCount (Ordinal: 609, Address: 0x18596)
  • DRMGetBoundLicenseObject (Ordinal: 610, Address: 0x185c3)
  • DRMGetBoundLicenseAttribute (Ordinal: 611, Address: 0x185f3)
  • DRMGetSignedIssuanceLicense (Ordinal: 612, Address: 0x18629)
  • DRMGetServiceLocation (Ordinal: 613, Address: 0x1866b)
  • DRMCloseEnvironmentHandle (Ordinal: 614, Address: 0x186a1)
  • DRMCloseHandle (Ordinal: 615, Address: 0x186c8)

Imported DLLs & Functions

ADVAPI32.dll
  • GetSidSubAuthority (Address: 0x543c102c)
  • GetSidSubAuthorityCount (Address: 0x543c1030)
  • GetTokenInformation (Address: 0x543c1028)
  • GetTraceEnableLevel (Address: 0x543c1038)
  • GetTraceLoggerHandle (Address: 0x543c1040)
  • OpenProcessToken (Address: 0x543c1024)
  • RegCloseKey (Address: 0x543c1008)
  • RegCreateKeyExW (Address: 0x543c101c)
  • RegDeleteKeyW (Address: 0x543c100c)
  • RegDeleteValueW (Address: 0x543c1020)
  • RegEnumKeyExW (Address: 0x543c1014)
  • RegisterTraceGuidsW (Address: 0x543c1034)
  • RegOpenKeyExW (Address: 0x543c1000)
  • RegQueryInfoKeyW (Address: 0x543c1010)
  • RegQueryValueExW (Address: 0x543c1004)
  • RegSetValueExW (Address: 0x543c1018)
  • TraceEvent (Address: 0x543c103c)
GDI32.dll
  • BitBlt (Address: 0x543c13b8)
  • CreateCompatibleBitmap (Address: 0x543c13c4)
  • CreateCompatibleDC (Address: 0x543c13c0)
  • CreateSolidBrush (Address: 0x543c13bc)
  • DeleteDC (Address: 0x543c13a0)
  • DeleteObject (Address: 0x543c13a4)
  • GetDeviceCaps (Address: 0x543c13a8)
  • GetObjectW (Address: 0x543c13b0)
  • GetStockObject (Address: 0x543c13ac)
  • SelectObject (Address: 0x543c13b4)
KERNEL32.dll
  • CloseHandle (Address: 0x543c1090)
  • CreateEventW (Address: 0x543c1058)
  • CreateFileMappingW (Address: 0x543c1170)
  • CreateFileW (Address: 0x543c1174)
  • CreateMutexW (Address: 0x543c10b4)
  • CreateToolhelp32Snapshot (Address: 0x543c1080)
  • DeleteCriticalSection (Address: 0x543c10f4)
  • DeleteTimerQueueTimer (Address: 0x543c11bc)
  • DisableThreadLibraryCalls (Address: 0x543c1050)
  • EnterCriticalSection (Address: 0x543c10ac)
  • ExitProcess (Address: 0x543c1074)
  • FindClose (Address: 0x543c10d4)
  • FindFirstFileW (Address: 0x543c10d0)
  • FindResourceExW (Address: 0x543c1168)
  • FindResourceW (Address: 0x543c110c)
  • FlushInstructionCache (Address: 0x543c10a8)
  • FreeLibrary (Address: 0x543c10f0)
  • GetACP (Address: 0x543c1134)
  • GetCurrentProcess (Address: 0x543c10a4)
  • GetCurrentProcessId (Address: 0x543c1084)
  • GetCurrentThread (Address: 0x543c1120)
  • GetCurrentThreadId (Address: 0x543c10fc)
  • GetLastError (Address: 0x543c105c)
  • GetLocaleInfoA (Address: 0x543c1138)
  • GetLocaleInfoW (Address: 0x543c1178)
  • GetModuleFileNameW (Address: 0x543c104c)
  • GetModuleHandleW (Address: 0x543c1048)
  • GetProcAddress (Address: 0x543c10c0)
  • GetProcessHeap (Address: 0x543c1148)
  • GetProcessTimes (Address: 0x543c10c4)
  • GetSystemDefaultUILanguage (Address: 0x543c1194)
  • GetSystemDirectoryW (Address: 0x543c1078)
  • GetSystemTimeAsFileTime (Address: 0x543c10c8)
  • GetThreadContext (Address: 0x543c11b8)
  • GetThreadLocale (Address: 0x543c113c)
  • GetTickCount (Address: 0x543c1130)
  • GetUserDefaultLangID (Address: 0x543c10d8)
  • GetUserDefaultUILanguage (Address: 0x543c1198)
  • GetVersionExA (Address: 0x543c1140)
  • GetVersionExW (Address: 0x543c117c)
  • GlobalAlloc (Address: 0x543c1070)
  • GlobalLock (Address: 0x543c10a0)
  • GlobalUnlock (Address: 0x543c109c)
  • HeapAlloc (Address: 0x543c114c)
  • HeapFree (Address: 0x543c1144)
  • InitializeCriticalSection (Address: 0x543c10f8)
  • InterlockedCompareExchange (Address: 0x543c1068)
  • InterlockedDecrement (Address: 0x543c1188)
  • InterlockedExchange (Address: 0x543c1114)
  • InterlockedIncrement (Address: 0x543c1184)
  • IsDebuggerPresent (Address: 0x543c1128)
  • IsProcessorFeaturePresent (Address: 0x543c1158)
  • LeaveCriticalSection (Address: 0x543c10b0)
  • LoadLibraryA (Address: 0x543c1150)
  • LoadLibraryExW (Address: 0x543c1110)
  • LoadLibraryW (Address: 0x543c10cc)
  • LoadResource (Address: 0x543c1108)
  • LocalAlloc (Address: 0x543c10e0)
  • LocalFree (Address: 0x543c10e4)
  • LockResource (Address: 0x543c107c)
  • lstrcmpiW (Address: 0x543c115c)
  • lstrcmpW (Address: 0x543c1094)
  • lstrlenW (Address: 0x543c1154)
  • MapViewOfFile (Address: 0x543c116c)
  • Module32FirstW (Address: 0x543c1088)
  • Module32NextW (Address: 0x543c108c)
  • MulDiv (Address: 0x543c1098)
  • MultiByteToWideChar (Address: 0x543c1100)
  • OpenProcess (Address: 0x543c10dc)
  • OutputDebugStringW (Address: 0x543c11a0)
  • QueryPerformanceCounter (Address: 0x543c112c)
  • QueueUserWorkItem (Address: 0x543c1060)
  • RaiseException (Address: 0x543c1064)
  • RegisterWaitForSingleObject (Address: 0x543c10ec)
  • ReleaseMutex (Address: 0x543c10b8)
  • ResumeThread (Address: 0x543c11a4)
  • SearchPathW (Address: 0x543c119c)
  • SetEnvironmentVariableW (Address: 0x543c1180)
  • SetEvent (Address: 0x543c1054)
  • SetLastError (Address: 0x543c118c)
  • SetThreadContext (Address: 0x543c11b4)
  • SetUnhandledExceptionFilter (Address: 0x543c1124)
  • SizeofResource (Address: 0x543c1104)
  • Sleep (Address: 0x543c1118)
  • SuspendThread (Address: 0x543c11a8)
  • TerminateProcess (Address: 0x543c10e8)
  • UnhandledExceptionFilter (Address: 0x543c111c)
  • UnmapViewOfFile (Address: 0x543c1190)
  • VirtualAlloc (Address: 0x543c1164)
  • VirtualFree (Address: 0x543c1160)
  • VirtualProtect (Address: 0x543c11ac)
  • VirtualQuery (Address: 0x543c11b0)
  • WaitForMultipleObjects (Address: 0x543c10bc)
  • WaitForSingleObject (Address: 0x543c106c)
mscoree.dll
  • CorBindToRuntimeEx (Address: 0x543c145c)
MSVCR80.dll
  • __clean_type_info_names_internal (Address: 0x543c11e0)
  • __CppXcptFilter (Address: 0x543c11ec)
  • __dllonexit (Address: 0x543c1210)
  • _adjust_fdiv (Address: 0x543c11f0)
  • _amsg_exit (Address: 0x543c11f4)
  • _beginthreadex (Address: 0x543c1234)
  • _callnewh (Address: 0x543c125c)
  • _crt_debugger_hook (Address: 0x543c11e8)
  • _CxxThrowException (Address: 0x543c11d0)
  • _decode_pointer (Address: 0x543c1200)
  • _encode_pointer (Address: 0x543c120c)
  • _encoded_null (Address: 0x543c11fc)
  • _except_handler4_common (Address: 0x543c11e4)
  • _initterm (Address: 0x543c1264)
  • _initterm_e (Address: 0x543c11f8)
  • _lock (Address: 0x543c1208)
  • _malloc_crt (Address: 0x543c1268)
  • _onexit (Address: 0x543c1204)
  • _purecall (Address: 0x543c1238)
  • _recalloc (Address: 0x543c123c)
  • _ultow_s (Address: 0x543c121c)
  • _unlock (Address: 0x543c1214)
  • _vsnwprintf (Address: 0x543c1228)
  • _wcsicmp (Address: 0x543c1250)
  • _wcslwr_s (Address: 0x543c1218)
  • _wcsnicmp (Address: 0x543c1244)
  • ?_type_info_dtor_internal_method@type_info@@QAEXXZ (Address: 0x543c11dc)
  • ??_V@YAXPAX@Z (Address: 0x543c1254)
  • ??3@YAXPAX@Z (Address: 0x543c1258)
  • ?terminate@@YAXXZ (Address: 0x543c11d8)
  • bsearch (Address: 0x543c11cc)
  • free (Address: 0x543c1240)
  • malloc (Address: 0x543c1260)
  • memcpy (Address: 0x543c11c8)
  • memcpy_s (Address: 0x543c1248)
  • memset (Address: 0x543c11c4)
  • swprintf_s (Address: 0x543c1220)
  • wcschr (Address: 0x543c1224)
  • wcscpy_s (Address: 0x543c11d4)
  • wcsncmp (Address: 0x543c1230)
  • wcsncpy_s (Address: 0x543c124c)
  • wcsstr (Address: 0x543c122c)
ole32.dll
  • CLSIDFromProgID (Address: 0x543c13f8)
  • CLSIDFromString (Address: 0x543c13f4)
  • CoAllowSetForegroundWindow (Address: 0x543c13e8)
  • CoCreateInstance (Address: 0x543c13d4)
  • CoGetClassObject (Address: 0x543c1418)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x543c140c)
  • CoReleaseMarshalData (Address: 0x543c13ec)
  • CoTaskMemAlloc (Address: 0x543c13cc)
  • CoTaskMemFree (Address: 0x543c1410)
  • CoTaskMemRealloc (Address: 0x543c13d0)
  • CoUnmarshalInterface (Address: 0x543c13d8)
  • CreateBindCtx (Address: 0x543c13dc)
  • CreateStreamOnHGlobal (Address: 0x543c1404)
  • OleCreateMenuDescriptor (Address: 0x543c13e4)
  • OleDestroyMenuDescriptor (Address: 0x543c13e0)
  • OleInitialize (Address: 0x543c1408)
  • OleLockRunning (Address: 0x543c13fc)
  • OleTranslateAccelerator (Address: 0x543c1414)
  • OleUninitialize (Address: 0x543c13f0)
  • StringFromGUID2 (Address: 0x543c1400)
OLEAUT32.dll
  • DispCallFunc (Address: 0x543c1434)
  • LoadRegTypeLib (Address: 0x543c142c)
  • LoadTypeLib (Address: 0x543c1428)
  • OleCreateFontIndirect (Address: 0x543c1430)
  • SysAllocString (Address: 0x543c1450)
  • SysAllocStringByteLen (Address: 0x543c1440)
  • SysAllocStringLen (Address: 0x543c1420)
  • SysFreeString (Address: 0x543c144c)
  • SysStringByteLen (Address: 0x543c1424)
  • SysStringLen (Address: 0x543c1448)
  • VariantClear (Address: 0x543c1438)
  • VariantCopy (Address: 0x543c1454)
  • VariantInit (Address: 0x543c143c)
  • VarUI4FromStr (Address: 0x543c1444)
PSAPI.DLL
  • GetMappedFileNameW (Address: 0x543c14ac)
SHELL32.dll
  • SHGetFolderPathW (Address: 0x543c1494)
SHLWAPI.dll
  • PathCombineW (Address: 0x543c1464)
urlmon.dll
  • CoInternetParseUrl (Address: 0x543c1484)
  • CompareSecurityIds (Address: 0x543c148c)
  • CreateURLMoniker (Address: 0x543c1480)
  • UrlMkGetSessionOption (Address: 0x543c1488)
  • URLOpenBlockingStreamW (Address: 0x543c147c)
USER32.dll
  • BeginPaint (Address: 0x543c1374)
  • CallWindowProcW (Address: 0x543c1358)
  • CharNextW (Address: 0x543c12ac)
  • CheckMenuItem (Address: 0x543c1328)
  • ClientToScreen (Address: 0x543c1320)
  • CreateAcceleratorTableW (Address: 0x543c132c)
  • CreateMenu (Address: 0x543c12d8)
  • CreateWindowExW (Address: 0x543c12ec)
  • DefWindowProcW (Address: 0x543c1288)
  • DestroyAcceleratorTable (Address: 0x543c136c)
  • DestroyMenu (Address: 0x543c12c4)
  • DestroyWindow (Address: 0x543c1354)
  • DispatchMessageW (Address: 0x543c127c)
  • EnableMenuItem (Address: 0x543c12b8)
  • EndPaint (Address: 0x543c137c)
  • FillRect (Address: 0x543c1378)
  • GetClassInfoExW (Address: 0x543c134c)
  • GetClassInfoW (Address: 0x543c12e8)
  • GetClassNameW (Address: 0x543c1294)
  • GetClientRect (Address: 0x543c12b0)
  • GetDC (Address: 0x543c1380)
  • GetDesktopWindow (Address: 0x543c1308)
  • GetDlgItem (Address: 0x543c1394)
  • GetFocus (Address: 0x543c138c)
  • GetKeyState (Address: 0x543c1284)
  • GetMenuItemCount (Address: 0x543c1344)
  • GetMenuItemID (Address: 0x543c133c)
  • GetMenuItemInfoW (Address: 0x543c12bc)
  • GetMenuStringW (Address: 0x543c12d4)
  • GetMessageExtraInfo (Address: 0x543c1270)
  • GetMessageW (Address: 0x543c1290)
  • GetParent (Address: 0x543c1334)
  • GetSubMenu (Address: 0x543c1340)
  • GetSysColor (Address: 0x543c1370)
  • GetWindow (Address: 0x543c12a0)
  • GetWindowLongW (Address: 0x543c135c)
  • GetWindowTextLengthW (Address: 0x543c1348)
  • GetWindowTextW (Address: 0x543c1364)
  • GetWindowThreadProcessId (Address: 0x543c1324)
  • InsertMenuW (Address: 0x543c12d0)
  • InvalidateRect (Address: 0x543c1310)
  • InvalidateRgn (Address: 0x543c130c)
  • IsChild (Address: 0x543c1388)
  • IsWindow (Address: 0x543c1390)
  • KillTimer (Address: 0x543c12dc)
  • LoadCursorW (Address: 0x543c12f8)
  • LoadMenuW (Address: 0x543c12cc)
  • LoadStringW (Address: 0x543c12c0)
  • MessageBoxW (Address: 0x543c129c)
  • MoveWindow (Address: 0x543c1304)
  • MsgWaitForMultipleObjects (Address: 0x543c1274)
  • PeekMessageW (Address: 0x543c1278)
  • PostMessageW (Address: 0x543c128c)
  • PostThreadMessageW (Address: 0x543c1300)
  • RedrawWindow (Address: 0x543c1338)
  • RegisterClassExW (Address: 0x543c1350)
  • RegisterClassW (Address: 0x543c12f4)
  • RegisterRawInputDevices (Address: 0x543c12e0)
  • RegisterWindowMessageW (Address: 0x543c1360)
  • ReleaseCapture (Address: 0x543c1314)
  • ReleaseDC (Address: 0x543c1384)
  • RemoveMenu (Address: 0x543c12c8)
  • ScreenToClient (Address: 0x543c131c)
  • SendMessageW (Address: 0x543c1398)
  • SetCapture (Address: 0x543c1318)
  • SetFocus (Address: 0x543c12f0)
  • SetMessageExtraInfo (Address: 0x543c1280)
  • SetParent (Address: 0x543c12a8)
  • SetTimer (Address: 0x543c12e4)
  • SetWindowLongW (Address: 0x543c12a4)
  • SetWindowPos (Address: 0x543c1330)
  • SetWindowTextW (Address: 0x543c1368)
  • ShowWindow (Address: 0x543c12fc)
  • TranslateMessage (Address: 0x543c1298)
  • UnregisterClassA (Address: 0x543c12b4)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x543c14a4)
  • GetFileVersionInfoW (Address: 0x543c14a0)
  • VerQueryValueW (Address: 0x543c149c)
WININET.dll
  • InternetErrorDlg (Address: 0x543c146c)
  • InternetGetCookieExW (Address: 0x543c1474)
  • InternetSetCookieExW (Address: 0x543c1470)