PresentationHost_v0400.dll

Description: Windows Presentation Foundation Host Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.8.9316.0

Architecture: 32-bit

Operating System: Windows

SHA256: e14e267d3edc8507ca0ab80e8afc01fd

File Size: 234.1 KB

Uploaded At: Dec. 1, 2025, 7:19 a.m.

Views: 39

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllMain (Ordinal: 1, Address: 0xbcf0)
  • Activate (Ordinal: 2, Address: 0xbe10)
  • Deactivate (Ordinal: 3, Address: 0xc640)
  • ForwardTranslateAccelerator (Ordinal: 4, Address: 0xc300)
  • SaveToHistory (Ordinal: 5, Address: 0xc740)
  • LoadFromHistory (Ordinal: 6, Address: 0xc790)
  • ProcessUnhandledException (Ordinal: 7, Address: 0xcb40)
  • CreateIDispatchSTAForwarder (Ordinal: 8, Address: 0x1f3f0)
  • SetFakeActiveWindow (Ordinal: 9, Address: 0xba80)
  • DllRegisterServer (Ordinal: 10, Address: 0xbd80)
  • DllUnregisterServer (Ordinal: 11, Address: 0xbdf0)
  • ProcessCommandLine (Ordinal: 12, Address: 0x241b0)
  • DRMInitEnvironment (Ordinal: 601, Address: 0x1e450)
  • DRMCreateBoundLicense (Ordinal: 602, Address: 0x1e4a0)
  • DRMCreateLicenseStorageSession (Ordinal: 603, Address: 0x1e4e0)
  • DRMCreateEnablingBitsDecryptor (Ordinal: 604, Address: 0x1e530)
  • DRMCreateEnablingBitsEncryptor (Ordinal: 605, Address: 0x1e570)
  • DRMEncrypt (Ordinal: 606, Address: 0x1e5b0)
  • DRMDecrypt (Ordinal: 607, Address: 0x1e600)
  • DRMGetInfo (Ordinal: 608, Address: 0x1e650)
  • DRMGetBoundLicenseObjectCount (Ordinal: 609, Address: 0x1e690)
  • DRMGetBoundLicenseObject (Ordinal: 610, Address: 0x1e6d0)
  • DRMGetBoundLicenseAttribute (Ordinal: 611, Address: 0x1e710)
  • DRMGetSignedIssuanceLicense (Ordinal: 612, Address: 0x1e760)
  • DRMGetServiceLocation (Ordinal: 613, Address: 0x1e7b0)
  • DRMCloseEnvironmentHandle (Ordinal: 614, Address: 0x1e800)
  • DRMCloseHandle (Ordinal: 615, Address: 0x1e840)

Imported DLLs & Functions

ADVAPI32.dll
  • AddAccessAllowedAce (Address: 0x1003408c)
  • AddAce (Address: 0x10034094)
  • CopySid (Address: 0x10034070)
  • CreateProcessAsUserW (Address: 0x10034054)
  • CreateRestrictedToken (Address: 0x10034050)
  • CreateWellKnownSid (Address: 0x1003405c)
  • EqualSid (Address: 0x10034058)
  • GetAce (Address: 0x10034090)
  • GetAclInformation (Address: 0x10034080)
  • GetKernelObjectSecurity (Address: 0x10034074)
  • GetLengthSid (Address: 0x10034084)
  • GetSecurityDescriptorDacl (Address: 0x10034078)
  • GetSidSubAuthority (Address: 0x10034048)
  • GetSidSubAuthorityCount (Address: 0x1003404c)
  • GetTokenInformation (Address: 0x10034044)
  • GetTraceEnableFlags (Address: 0x10034028)
  • GetTraceEnableLevel (Address: 0x1003402c)
  • GetTraceLoggerHandle (Address: 0x10034030)
  • InitializeAcl (Address: 0x10034088)
  • LsaClose (Address: 0x1003406c)
  • LsaLookupPrivilegeValue (Address: 0x10034064)
  • LsaNtStatusToWinError (Address: 0x10034068)
  • LsaOpenPolicy (Address: 0x10034060)
  • OpenProcessToken (Address: 0x10034040)
  • RegCloseKey (Address: 0x1003400c)
  • RegCreateKeyExW (Address: 0x10034020)
  • RegDeleteKeyW (Address: 0x10034010)
  • RegDeleteValueW (Address: 0x10034024)
  • RegEnumKeyExW (Address: 0x10034018)
  • RegEnumKeyW (Address: 0x1003403c)
  • RegEnumValueW (Address: 0x10034038)
  • RegisterTraceGuidsW (Address: 0x10034034)
  • RegOpenKeyExW (Address: 0x10034004)
  • RegQueryInfoKeyW (Address: 0x10034014)
  • RegQueryValueExW (Address: 0x10034008)
  • RegSetValueExW (Address: 0x1003401c)
  • SetTokenInformation (Address: 0x1003407c)
  • TraceEvent (Address: 0x10034000)
GDI32.dll
  • BitBlt (Address: 0x100340a8)
  • CreateCompatibleBitmap (Address: 0x100340b4)
  • CreateCompatibleDC (Address: 0x100340b8)
  • CreateSolidBrush (Address: 0x100340bc)
  • DeleteDC (Address: 0x100340a4)
  • DeleteObject (Address: 0x100340ac)
  • GetDeviceCaps (Address: 0x100340c0)
  • GetObjectW (Address: 0x1003409c)
  • GetStockObject (Address: 0x100340a0)
  • SelectObject (Address: 0x100340b0)
KERNEL32.dll
  • ActivateActCtx (Address: 0x100341b8)
  • CloseHandle (Address: 0x1003411c)
  • CreateActCtxW (Address: 0x100341b4)
  • CreateEventW (Address: 0x100340f0)
  • CreateFileMappingW (Address: 0x1003421c)
  • CreateFileW (Address: 0x100341c4)
  • CreateMutexW (Address: 0x10034138)
  • CreateProcessW (Address: 0x100341d0)
  • CreateTimerQueueTimer (Address: 0x10034178)
  • CreateToolhelp32Snapshot (Address: 0x1003410c)
  • DeactivateActCtx (Address: 0x100341bc)
  • DecodePointer (Address: 0x100340e4)
  • DeleteCriticalSection (Address: 0x100340d8)
  • DeleteTimerQueueTimer (Address: 0x1003417c)
  • DisableThreadLibraryCalls (Address: 0x100340e0)
  • EncodePointer (Address: 0x10034248)
  • EnterCriticalSection (Address: 0x10034120)
  • ExitProcess (Address: 0x10034100)
  • ExpandEnvironmentStringsW (Address: 0x10034170)
  • FileTimeToSystemTime (Address: 0x10034198)
  • FindClose (Address: 0x10034158)
  • FindFirstFileW (Address: 0x10034154)
  • FindResourceExW (Address: 0x10034218)
  • FindResourceW (Address: 0x100340cc)
  • FlushInstructionCache (Address: 0x10034230)
  • FormatMessageW (Address: 0x100341ac)
  • FreeLibrary (Address: 0x10034270)
  • GetCommandLineW (Address: 0x100341a0)
  • GetCurrentProcess (Address: 0x10034148)
  • GetCurrentProcessId (Address: 0x10034110)
  • GetCurrentThread (Address: 0x10034278)
  • GetCurrentThreadId (Address: 0x10034274)
  • GetEnvironmentVariableW (Address: 0x10034188)
  • GetExitCodeProcess (Address: 0x100341d4)
  • GetFileAttributesExW (Address: 0x10034194)
  • GetLastError (Address: 0x100341dc)
  • GetLocaleInfoW (Address: 0x10034210)
  • GetModuleFileNameW (Address: 0x100340d4)
  • GetModuleHandleW (Address: 0x100341e8)
  • GetNativeSystemInfo (Address: 0x100341cc)
  • GetProcAddress (Address: 0x1003426c)
  • GetProcessHeap (Address: 0x1003423c)
  • GetProcessTimes (Address: 0x10034144)
  • GetStartupInfoW (Address: 0x1003419c)
  • GetSystemDefaultUILanguage (Address: 0x10034208)
  • GetSystemDirectoryW (Address: 0x10034104)
  • GetSystemTimeAsFileTime (Address: 0x1003414c)
  • GetTempFileNameW (Address: 0x100341c0)
  • GetTempPathW (Address: 0x1003418c)
  • GetThreadContext (Address: 0x100341f4)
  • GetUserDefaultLangID (Address: 0x1003415c)
  • GetUserDefaultUILanguage (Address: 0x1003420c)
  • GetVersionExW (Address: 0x100340e8)
  • GlobalAlloc (Address: 0x100340fc)
  • GlobalLock (Address: 0x1003412c)
  • GlobalUnlock (Address: 0x10034128)
  • HeapAlloc (Address: 0x10034244)
  • HeapFree (Address: 0x10034240)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1003425c)
  • InitializeCriticalSectionEx (Address: 0x100340dc)
  • InitializeSListHead (Address: 0x10034250)
  • InterlockedPopEntrySList (Address: 0x10034238)
  • InterlockedPushEntrySList (Address: 0x10034234)
  • IsDebuggerPresent (Address: 0x10034174)
  • IsProcessorFeaturePresent (Address: 0x10034260)
  • IsWow64Process (Address: 0x1003416c)
  • LeaveCriticalSection (Address: 0x10034124)
  • LoadLibraryExA (Address: 0x10034224)
  • LoadLibraryExW (Address: 0x100340d0)
  • LoadLibraryW (Address: 0x10034150)
  • LoadResource (Address: 0x100340c8)
  • LocalAlloc (Address: 0x10034180)
  • LocalFree (Address: 0x10034184)
  • LockResource (Address: 0x10034108)
  • lstrcmpiW (Address: 0x100341e4)
  • lstrcmpW (Address: 0x10034134)
  • MapViewOfFile (Address: 0x10034220)
  • Module32FirstW (Address: 0x10034114)
  • Module32NextW (Address: 0x10034118)
  • MulDiv (Address: 0x10034130)
  • MultiByteToWideChar (Address: 0x10034140)
  • OpenEventW (Address: 0x100341a4)
  • OpenProcess (Address: 0x10034164)
  • OutputDebugStringW (Address: 0x1003424c)
  • QueryPerformanceCounter (Address: 0x10034254)
  • QueueUserWorkItem (Address: 0x100340f4)
  • RaiseException (Address: 0x100341e0)
  • RegisterWaitForSingleObject (Address: 0x10034168)
  • ReleaseActCtx (Address: 0x100341b0)
  • ReleaseMutex (Address: 0x1003413c)
  • ResetEvent (Address: 0x10034190)
  • ResumeThread (Address: 0x100341f8)
  • SearchPathW (Address: 0x10034204)
  • SetEvent (Address: 0x100340ec)
  • SetLastError (Address: 0x1003427c)
  • SetThreadContext (Address: 0x100341f0)
  • SetUnhandledExceptionFilter (Address: 0x10034264)
  • SizeofResource (Address: 0x100341d8)
  • SuspendThread (Address: 0x100341fc)
  • SwitchToThread (Address: 0x100341a8)
  • TerminateProcess (Address: 0x10034160)
  • UnhandledExceptionFilter (Address: 0x10034268)
  • UnmapViewOfFile (Address: 0x10034214)
  • VirtualAlloc (Address: 0x1003422c)
  • VirtualFree (Address: 0x10034228)
  • VirtualProtect (Address: 0x10034200)
  • VirtualQuery (Address: 0x100341ec)
  • WaitForMultipleObjects (Address: 0x10034280)
  • WaitForSingleObject (Address: 0x100340f8)
  • WaitForSingleObjectEx (Address: 0x10034258)
  • WriteFile (Address: 0x100341c8)
mscoree.dll
  • CLRCreateInstance (Address: 0x1003449c)
  • CoEEShutDownCOM (Address: 0x100344a0)
  • LoadLibraryShim (Address: 0x100344a4)
ntdll.dll
  • RtlInitUnicodeString (Address: 0x100344ac)
ole32.dll
  • CLSIDFromProgID (Address: 0x100344e0)
  • CLSIDFromString (Address: 0x100344e4)
  • CoAllowSetForegroundWindow (Address: 0x100344f0)
  • CoCreateInstance (Address: 0x100344bc)
  • CoGetClassObject (Address: 0x100344cc)
  • CoInitialize (Address: 0x10034510)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x100344c8)
  • CoRegisterClassObject (Address: 0x10034508)
  • CoRegisterMessageFilter (Address: 0x100344e8)
  • CoReleaseMarshalData (Address: 0x100344ec)
  • CoRevokeClassObject (Address: 0x10034500)
  • CoTaskMemAlloc (Address: 0x10034514)
  • CoTaskMemFree (Address: 0x100344b8)
  • CoTaskMemRealloc (Address: 0x100344d0)
  • CoUninitialize (Address: 0x1003450c)
  • CoUnmarshalInterface (Address: 0x100344c4)
  • CreateBindCtx (Address: 0x100344fc)
  • CreateStreamOnHGlobal (Address: 0x100344d4)
  • OleCreateMenuDescriptor (Address: 0x100344f4)
  • OleDestroyMenuDescriptor (Address: 0x100344f8)
  • OleInitialize (Address: 0x100344b4)
  • OleLockRunning (Address: 0x100344dc)
  • OleTranslateAccelerator (Address: 0x10034504)
  • OleUninitialize (Address: 0x100344d8)
  • StringFromGUID2 (Address: 0x100344c0)
OLEAUT32.dll
  • DispCallFunc (Address: 0x100342a4)
  • LoadRegTypeLib (Address: 0x100342ac)
  • LoadTypeLib (Address: 0x10034294)
  • OleCreateFontIndirect (Address: 0x100342a8)
  • SysAllocString (Address: 0x100342b8)
  • SysAllocStringByteLen (Address: 0x10034298)
  • SysAllocStringLen (Address: 0x100342b0)
  • SysFreeString (Address: 0x10034288)
  • SysStringLen (Address: 0x1003428c)
  • VariantClear (Address: 0x100342a0)
  • VariantCopy (Address: 0x100342b4)
  • VariantInit (Address: 0x1003429c)
  • VarUI4FromStr (Address: 0x10034290)
PSAPI.DLL
  • GetMappedFileNameW (Address: 0x100342c0)
SHELL32.dll
  • CommandLineToArgvW (Address: 0x100342cc)
  • ShellExecuteExW (Address: 0x100342d8)
  • ShellExecuteW (Address: 0x100342d0)
  • SHGetFolderPathW (Address: 0x100342c8)
  • SHGetKnownFolderPath (Address: 0x100342d4)
SHLWAPI.dll
  • AssocQueryStringW (Address: 0x100342e4)
  • PathAppendW (Address: 0x100342e0)
  • PathCombineW (Address: 0x100342ec)
  • PathFindExtensionW (Address: 0x100342e8)
  • PathIsURLW (Address: 0x100342f0)
  • UrlCreateFromPathW (Address: 0x100342f4)
ucrtbase_clr0400.dll
  • __stdio_common_vswprintf (Address: 0x10034564)
  • __stdio_common_vswprintf_s (Address: 0x1003455c)
  • _beginthreadex (Address: 0x10034568)
  • _callnewh (Address: 0x10034594)
  • _cexit (Address: 0x10034524)
  • _configure_narrow_argv (Address: 0x1003453c)
  • _crt_atexit (Address: 0x10034528)
  • _errno (Address: 0x1003457c)
  • _execute_onexit_table (Address: 0x1003452c)
  • _initialize_narrow_environment (Address: 0x10034538)
  • _initialize_onexit_table (Address: 0x10034534)
  • _initterm (Address: 0x10034520)
  • _initterm_e (Address: 0x1003459c)
  • _invalid_parameter_noinfo (Address: 0x10034580)
  • _invalid_parameter_noinfo_noreturn (Address: 0x10034548)
  • _recalloc (Address: 0x10034578)
  • _register_onexit_function (Address: 0x10034530)
  • _seh_filter_dll (Address: 0x10034540)
  • _ultow_s (Address: 0x10034558)
  • _wcsicmp (Address: 0x1003458c)
  • _wcslwr_s (Address: 0x10034554)
  • _wcsnicmp (Address: 0x1003456c)
  • bsearch (Address: 0x10034598)
  • free (Address: 0x10034584)
  • isdigit (Address: 0x1003454c)
  • iswdigit (Address: 0x10034544)
  • malloc (Address: 0x10034590)
  • terminate (Address: 0x1003451c)
  • tolower (Address: 0x10034550)
  • wcscat_s (Address: 0x10034570)
  • wcscpy_s (Address: 0x10034574)
  • wcsncmp (Address: 0x10034560)
  • wcsncpy_s (Address: 0x10034588)
urlmon.dll
  • CoInternetCombineUrl (Address: 0x100345ac)
  • CoInternetCreateSecurityManager (Address: 0x100345cc)
  • CoInternetParseUrl (Address: 0x100345b0)
  • CompareSecurityIds (Address: 0x100345c8)
  • CreateURLMoniker (Address: 0x100345b4)
  • CreateURLMonikerEx (Address: 0x100345bc)
  • GetClassFileOrMime (Address: 0x100345a4)
  • RegisterBindStatusCallback (Address: 0x100345a8)
  • URLDownloadToCacheFileW (Address: 0x100345b8)
  • UrlMkGetSessionOption (Address: 0x100345c4)
  • URLOpenBlockingStreamW (Address: 0x100345c0)
USER32.dll
  • BeginPaint (Address: 0x10034348)
  • CallWindowProcW (Address: 0x100343b0)
  • CharNextW (Address: 0x1003442c)
  • CheckMenuItem (Address: 0x100343f0)
  • ClientToScreen (Address: 0x10034314)
  • CreateAcceleratorTableW (Address: 0x10034318)
  • CreateMenu (Address: 0x10034380)
  • CreateWindowExW (Address: 0x100343cc)
  • DefWindowProcW (Address: 0x10034410)
  • DestroyAcceleratorTable (Address: 0x100343e8)
  • DestroyMenu (Address: 0x10034394)
  • DestroyWindow (Address: 0x1003431c)
  • DispatchMessageW (Address: 0x1003441c)
  • EnableMenuItem (Address: 0x100343a0)
  • EndPaint (Address: 0x10034344)
  • FillRect (Address: 0x10034300)
  • GetActiveWindow (Address: 0x10034430)
  • GetClassInfoExW (Address: 0x10034320)
  • GetClassInfoW (Address: 0x10034370)
  • GetClassNameW (Address: 0x10034404)
  • GetClientRect (Address: 0x100343d0)
  • GetDC (Address: 0x100343c0)
  • GetDesktopWindow (Address: 0x100343e4)
  • GetDlgItem (Address: 0x10034338)
  • GetFocus (Address: 0x1003433c)
  • GetKeyState (Address: 0x10034414)
  • GetMenuItemCount (Address: 0x1003435c)
  • GetMenuItemID (Address: 0x10034364)
  • GetMenuItemInfoW (Address: 0x1003439c)
  • GetMenuStringW (Address: 0x10034384)
  • GetMessageExtraInfo (Address: 0x10034428)
  • GetMessageW (Address: 0x10034408)
  • GetParent (Address: 0x10034310)
  • GetSubMenu (Address: 0x10034360)
  • GetSysColor (Address: 0x1003432c)
  • GetWindow (Address: 0x100343f8)
  • GetWindowLongW (Address: 0x100343ec)
  • GetWindowTextLengthW (Address: 0x10034354)
  • GetWindowTextW (Address: 0x10034434)
  • GetWindowThreadProcessId (Address: 0x1003436c)
  • InsertMenuW (Address: 0x10034388)
  • InvalidateRect (Address: 0x10034368)
  • InvalidateRgn (Address: 0x100342fc)
  • IsChild (Address: 0x10034340)
  • IsWindow (Address: 0x10034330)
  • KillTimer (Address: 0x1003437c)
  • LoadCursorW (Address: 0x100343f4)
  • LoadMenuW (Address: 0x1003438c)
  • LoadStringW (Address: 0x10034398)
  • MessageBeep (Address: 0x100343a8)
  • MessageBoxW (Address: 0x100343fc)
  • MoveWindow (Address: 0x100343b8)
  • MsgWaitForMultipleObjects (Address: 0x10034424)
  • PeekMessageW (Address: 0x10034420)
  • PostMessageW (Address: 0x1003440c)
  • PostQuitMessage (Address: 0x100343a4)
  • PostThreadMessageW (Address: 0x100343bc)
  • RedrawWindow (Address: 0x10034324)
  • RegisterClassExW (Address: 0x10034350)
  • RegisterClassW (Address: 0x100343d4)
  • RegisterRawInputDevices (Address: 0x10034378)
  • RegisterWindowMessageW (Address: 0x10034358)
  • ReleaseCapture (Address: 0x10034304)
  • ReleaseDC (Address: 0x100343e0)
  • RemoveMenu (Address: 0x10034390)
  • ScreenToClient (Address: 0x1003430c)
  • SendMessageW (Address: 0x10034334)
  • SetCapture (Address: 0x10034308)
  • SetFocus (Address: 0x100343c8)
  • SetMessageExtraInfo (Address: 0x10034418)
  • SetParent (Address: 0x100343d8)
  • SetTimer (Address: 0x10034374)
  • SetWindowLongW (Address: 0x100343dc)
  • SetWindowPos (Address: 0x10034328)
  • SetWindowTextW (Address: 0x1003434c)
  • ShowWindow (Address: 0x100343c4)
  • TranslateMessage (Address: 0x10034400)
  • UnregisterClassW (Address: 0x100343b4)
  • WaitForInputIdle (Address: 0x100343ac)
VCRUNTIME140_CLR0400.dll
  • __current_exception (Address: 0x1003445c)
  • __current_exception_context (Address: 0x10034458)
  • __CxxFrameHandler3 (Address: 0x10034444)
  • __std_type_info_destroy_list (Address: 0x1003444c)
  • _CxxThrowException (Address: 0x10034468)
  • _except_handler4_common (Address: 0x10034454)
  • _purecall (Address: 0x10034440)
  • memcmp (Address: 0x1003446c)
  • memcpy (Address: 0x10034464)
  • memmove (Address: 0x10034460)
  • memset (Address: 0x10034450)
  • wcschr (Address: 0x10034448)
  • wcsstr (Address: 0x1003443c)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x1003447c)
  • GetFileVersionInfoW (Address: 0x10034474)
  • VerQueryValueW (Address: 0x10034478)
WININET.dll
  • InternetCrackUrlW (Address: 0x10034484)
  • InternetCreateUrlW (Address: 0x10034494)
  • InternetErrorDlg (Address: 0x10034488)
  • InternetGetCookieExW (Address: 0x1003448c)
  • InternetSetCookieExW (Address: 0x10034490)