CoreMessagingXP.dll
Description: Microsoft CoreMessaging Dll
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.26107.1009
Architecture: 64-bit
Operating System: Windows NT
SHA256: 47ace7c6660a16f79441d37195ddad70
File Size: 1.0 MB
Uploaded At: Dec. 1, 2025, 2:55 p.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- CoreMsgCreateSession (Ordinal: 1, Address: 0xcfc0)
- CoreMsgGetExistingSession (Ordinal: 2, Address: 0xd000)
- CoreUICallComputeMaximumMessageSize (Ordinal: 3, Address: 0x8cab0)
- CoreUICallCreateConversationHost (Ordinal: 4, Address: 0x8cf10)
- CoreUICallCreateEndpointHost (Ordinal: 5, Address: 0x8d040)
- CoreUICallCreateEndpointHostWithSendPriority (Ordinal: 6, Address: 0x8d060)
- CoreUICallGetAddressOfParameterInBuffer (Ordinal: 7, Address: 0x8cbd0)
- CoreUICallReceive (Ordinal: 8, Address: 0x8cc40)
- CoreUICallSend (Ordinal: 9, Address: 0x8cd20)
- CoreUICallSendVaList (Ordinal: 10, Address: 0x8cd60)
- CoreUIConfigureTestHost (Ordinal: 11, Address: 0xd050)
- CoreUIConfigureUserIntegration (Ordinal: 12, Address: 0xd070)
- CoreUICreateAnonymousStream (Ordinal: 13, Address: 0xd6b0)
- CoreUIEnableCrossProcessPrototyping (Ordinal: 14, Address: 0xd7f0)
- CoreUIInitializeTestService (Ordinal: 15, Address: 0xd170)
- CoreUIRouteToTestRegistrar (Ordinal: 16, Address: 0xd800)
- CoreUIUninitializeTestService (Ordinal: 17, Address: 0xd1a0)
- DllCanUnloadNow (Ordinal: 18, Address: 0x8eab0)
- DllGetActivationFactory (Ordinal: 19, Address: 0x8eb00)
- DllGetClassObject (Ordinal: 20, Address: 0x8ecf0)
- MsgBlobCreateShared (Ordinal: 21, Address: 0x8f40)
- MsgBlobCreateStack (Ordinal: 22, Address: 0x9020)
- MsgBufferShare (Ordinal: 23, Address: 0x9070)
- MsgRelease (Ordinal: 24, Address: 0x9100)
- MsgStringCreateShared (Ordinal: 25, Address: 0x9180)
- MsgStringCreateStack (Ordinal: 26, Address: 0x92a0)
- WinUICreateDispatcherQueueController (Ordinal: 27, Address: 0x93980)
- WinUIGetDispatcherQueueForCurrentThread (Ordinal: 28, Address: 0x985a0)
Imported DLLs & Functions
ADVAPI32.dll
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800b5ec8)
- EventRegister (Address: 0x1800b5e90)
- EventUnregister (Address: 0x1800b5e98)
- EventWriteTransfer (Address: 0x1800b5ea8)
- GetTokenInformation (Address: 0x1800b5ed0)
- OpenProcessToken (Address: 0x1800b5eb0)
- OpenThreadToken (Address: 0x1800b5ee0)
- RegCloseKey (Address: 0x1800b5ec0)
- RegCreateKeyExW (Address: 0x1800b5ea0)
- RegQueryValueExW (Address: 0x1800b5eb8)
- RegSetValueExW (Address: 0x1800b5e88)
- RevertToSelf (Address: 0x1800b5ed8)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800b60d8)
- IsDebuggerPresent (Address: 0x1800b60e8)
- OutputDebugStringW (Address: 0x1800b60e0)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800b60f8)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800b6108)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800b6118)
- RaiseException (Address: 0x1800b6128)
- SetLastError (Address: 0x1800b6120)
api-ms-win-core-fibers-l1-1-0.dll
- FlsAlloc (Address: 0x1800b6138)
- FlsFree (Address: 0x1800b6140)
- FlsGetValue (Address: 0x1800b6150)
- FlsSetValue (Address: 0x1800b6148)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800b6160)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800b6170)
- HeapAlloc (Address: 0x1800b6180)
- HeapFree (Address: 0x1800b6178)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x1800b6190)
- InterlockedFlushSList (Address: 0x1800b61a0)
- InterlockedPushEntrySList (Address: 0x1800b6198)
api-ms-win-core-libraryloader-l1-2-0.dll
- GetModuleFileNameA (Address: 0x1800b61b0)
- GetModuleHandleExW (Address: 0x1800b61b8)
- GetModuleHandleW (Address: 0x1800b61c0)
- GetProcAddress (Address: 0x1800b61c8)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800b61d8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcessId (Address: 0x1800b61e8)
- GetCurrentThreadId (Address: 0x1800b61f0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800b6200)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlLookupFunctionEntry (Address: 0x1800b6220)
- RtlPcToFileHeader (Address: 0x1800b6218)
- RtlUnwindEx (Address: 0x1800b6210)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x1800b6230)
- WideCharToMultiByte (Address: 0x1800b6238)
api-ms-win-core-synch-l1-1-0.dll
- CreateMutexExW (Address: 0x1800b6298)
- CreateSemaphoreExW (Address: 0x1800b6248)
- DeleteCriticalSection (Address: 0x1800b6258)
- EnterCriticalSection (Address: 0x1800b6260)
- InitializeCriticalSectionEx (Address: 0x1800b6290)
- LeaveCriticalSection (Address: 0x1800b6250)
- OpenSemaphoreW (Address: 0x1800b6288)
- ReleaseMutex (Address: 0x1800b6278)
- ReleaseSemaphore (Address: 0x1800b6268)
- WaitForSingleObject (Address: 0x1800b6270)
- WaitForSingleObjectEx (Address: 0x1800b6280)
api-ms-win-core-synch-l1-2-0.dll
- SleepConditionVariableSRW (Address: 0x1800b62a8)
- WakeAllConditionVariable (Address: 0x1800b62b0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1800b62c8)
- GetTickCount (Address: 0x1800b62c0)
api-ms-win-core-util-l1-1-0.dll
- EncodePointer (Address: 0x1800b62d8)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x1800b6300)
- RoFailFastWithErrorContext (Address: 0x1800b6310)
- RoOriginateError (Address: 0x1800b62f8)
- RoOriginateErrorW (Address: 0x1800b62e8)
- RoTransformError (Address: 0x1800b62f0)
- SetRestrictedErrorInfo (Address: 0x1800b6308)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x1800b6330)
- RoGetMatchingRestrictedErrorInfo (Address: 0x1800b6320)
- RoReportFailedDelegate (Address: 0x1800b6328)
api-ms-win-core-winrt-l1-1-0.dll
- RoGetActivationFactory (Address: 0x1800b6340)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCreateString (Address: 0x1800b6368)
- WindowsCreateStringReference (Address: 0x1800b6370)
- WindowsGetStringRawBuffer (Address: 0x1800b6360)
- WindowsIsStringEmpty (Address: 0x1800b6358)
- WindowsStringHasEmbeddedNull (Address: 0x1800b6350)
api-ms-win-crt-heap-l1-1-0.dll
- _aligned_free (Address: 0x1800b63a0)
- _aligned_offset_malloc (Address: 0x1800b63b0)
- _callnewh (Address: 0x1800b6398)
- _calloc_base (Address: 0x1800b63c0)
- _free_base (Address: 0x1800b63b8)
- calloc (Address: 0x1800b63a8)
- free (Address: 0x1800b6390)
- malloc (Address: 0x1800b6380)
- realloc (Address: 0x1800b6388)
api-ms-win-crt-math-l1-1-0.dll
- ceilf (Address: 0x1800b63d0)
api-ms-win-crt-runtime-l1-1-0.dll
- _cexit (Address: 0x1800b63f8)
- _configure_narrow_argv (Address: 0x1800b6418)
- _crt_atexit (Address: 0x1800b6440)
- _errno (Address: 0x1800b63e8)
- _execute_onexit_table (Address: 0x1800b6450)
- _initialize_narrow_environment (Address: 0x1800b6420)
- _initialize_onexit_table (Address: 0x1800b6428)
- _initterm (Address: 0x1800b6400)
- _initterm_e (Address: 0x1800b6408)
- _invalid_parameter_noinfo (Address: 0x1800b6430)
- _invalid_parameter_noinfo_noreturn (Address: 0x1800b6438)
- _register_onexit_function (Address: 0x1800b6448)
- _seh_filter_dll (Address: 0x1800b6410)
- abort (Address: 0x1800b63f0)
- terminate (Address: 0x1800b63e0)
api-ms-win-crt-stdio-l1-1-0.dll
- __stdio_common_vswprintf (Address: 0x1800b6460)
api-ms-win-crt-string-l1-1-0.dll
- strcpy_s (Address: 0x1800b6470)
- wmemcpy_s (Address: 0x1800b6478)
api-ms-win-crt-utility-l1-1-0.dll
- rand_s (Address: 0x1800b6488)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x1800b5ff0)
- AcquireSRWLockShared (Address: 0x1800b6038)
- CallbackMayRunLong (Address: 0x1800b6018)
- CloseThreadpoolTimer (Address: 0x1800b5ef8)
- CloseThreadpoolWait (Address: 0x1800b5f90)
- CreateEventW (Address: 0x1800b6010)
- CreateThread (Address: 0x1800b6008)
- CreateThreadpoolTimer (Address: 0x1800b5ef0)
- CreateThreadpoolWait (Address: 0x1800b5fa0)
- CreateWaitableTimerExW (Address: 0x1800b5f28)
- DecodePointer (Address: 0x1800b5f60)
- DisableThreadLibraryCalls (Address: 0x1800b6070)
- DuplicateHandle (Address: 0x1800b6020)
- FreeLibrary (Address: 0x1800b6058)
- GetCurrentProcess (Address: 0x1800b6028)
- GetCurrentThread (Address: 0x1800b6050)
- GetHandleInformation (Address: 0x1800b5f10)
- GetModuleHandleExA (Address: 0x1800b5f78)
- GetSystemInfo (Address: 0x1800b5fc0)
- GetThreadPriority (Address: 0x1800b5f30)
- GetTickCount64 (Address: 0x1800b5f48)
- HeapSize (Address: 0x1800b5fa8)
- InitializeCriticalSection (Address: 0x1800b6080)
- InitializeSRWLock (Address: 0x1800b5fd8)
- InitOnceExecuteOnce (Address: 0x1800b5f18)
- InterlockedPopEntrySList (Address: 0x1800b5fd0)
- LoadLibraryExW (Address: 0x1800b6078)
- LoadLibraryW (Address: 0x1800b6030)
- LocalFree (Address: 0x1800b5f50)
- OpenProcess (Address: 0x1800b5f68)
- OpenThread (Address: 0x1800b5f40)
- QueryDepthSList (Address: 0x1800b5fc8)
- RaiseFailFastException (Address: 0x1800b5f58)
- ReleaseSRWLockExclusive (Address: 0x1800b5fe8)
- ReleaseSRWLockShared (Address: 0x1800b6040)
- ResetEvent (Address: 0x1800b6048)
- RtlCaptureStackBackTrace (Address: 0x1800b6060)
- SetEvent (Address: 0x1800b5ff8)
- SetThreadpoolTimer (Address: 0x1800b5f08)
- SetThreadpoolWait (Address: 0x1800b5f98)
- SetThreadPriority (Address: 0x1800b5fe0)
- SetWaitableTimer (Address: 0x1800b5f20)
- Sleep (Address: 0x1800b5f70)
- TlsAlloc (Address: 0x1800b6088)
- TlsFree (Address: 0x1800b5f80)
- TlsGetValue (Address: 0x1800b6090)
- TlsSetValue (Address: 0x1800b6068)
- VirtualAlloc (Address: 0x1800b5fb8)
- VirtualFree (Address: 0x1800b5fb0)
- WaitForMultipleObjects (Address: 0x1800b6000)
- WaitForMultipleObjectsEx (Address: 0x1800b5f38)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800b5f00)
- WaitForThreadpoolWaitCallbacks (Address: 0x1800b5f88)
Microsoft.Internal.FrameworkUdk.dll
- Containment_GetChangeEnabled (Address: 0x1800b60a0)
ntdll.dll
- AlpcGetMessageAttribute (Address: 0x1800b64d0)
- AlpcInitializeMessageAttribute (Address: 0x1800b64c0)
- NtAllocateReserveObject (Address: 0x1800b64e8)
- NtAlpcAcceptConnectPort (Address: 0x1800b64a0)
- NtAlpcConnectPort (Address: 0x1800b6500)
- NtAlpcCreatePort (Address: 0x1800b64a8)
- NtAlpcDisconnectPort (Address: 0x1800b64b8)
- NtAlpcImpersonateClientOfPort (Address: 0x1800b64c8)
- NtAlpcQueryInformation (Address: 0x1800b6498)
- NtAlpcSendWaitReceivePort (Address: 0x1800b64d8)
- NtAssociateWaitCompletionPacket (Address: 0x1800b6518)
- NtCancelWaitCompletionPacket (Address: 0x1800b6510)
- NtClose (Address: 0x1800b64e0)
- NtCreateIoCompletion (Address: 0x1800b6528)
- NtCreateWaitCompletionPacket (Address: 0x1800b6520)
- NtQuerySystemInformation (Address: 0x1800b6550)
- NtRemoveIoCompletionEx (Address: 0x1800b6508)
- NtSetIoCompletionEx (Address: 0x1800b64f8)
- RtlActivateActivationContextUnsafeFast (Address: 0x1800b6538)
- RtlDeactivateActivationContextUnsafeFast (Address: 0x1800b6530)
- RtlFreeUnicodeString (Address: 0x1800b64f0)
- RtlInitUnicodeString (Address: 0x1800b64b0)
- RtlQueryInformationActiveActivationContext (Address: 0x1800b6548)
- RtlReleaseActivationContext (Address: 0x1800b6540)
SHCORE.dll
- GetFeatureEnabledState (Address: 0x1800b60c0)
- RecordFeatureUsage (Address: 0x1800b60b0)
- SubscribeFeatureStateChangeNotification (Address: 0x1800b60b8)
- UnsubscribeFeatureStateChangeNotification (Address: 0x1800b60c8)