LockAppBroker.dll

Description: Windows Lock App Broker DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5848

Architecture: 64-bit

Operating System: Windows NT

SHA256: 52ab62f0f45a5a464d027746d501a3f3

File Size: 446.5 KB

Uploaded At: Dec. 1, 2025, 7:32 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x21400)
  • DllGetActivationFactory (Ordinal: 2, Address: 0xf420)
  • DllGetClassObject (Ordinal: 3, Address: 0xe270)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCancelCall (Address: 0x18004d8e8)
  • CoCreateFreeThreadedMarshaler (Address: 0x18004d8d0)
  • CoCreateInstance (Address: 0x18004d8c0)
  • CoDecrementMTAUsage (Address: 0x18004d8f0)
  • CoDisableCallCancellation (Address: 0x18004d8a8)
  • CoEnableCallCancellation (Address: 0x18004d8a0)
  • CoGetApartmentType (Address: 0x18004d8c8)
  • CoGetCallContext (Address: 0x18004d898)
  • CoIncrementMTAUsage (Address: 0x18004d8e0)
  • CoInitializeEx (Address: 0x18004d8b0)
  • CoTaskMemAlloc (Address: 0x18004d8b8)
  • CoTaskMemFree (Address: 0x18004d890)
  • CoTaskMemRealloc (Address: 0x18004d888)
  • CoUninitialize (Address: 0x18004d8d8)
  • CoWaitForMultipleHandles (Address: 0x18004d8f8)
  • PropVariantClear (Address: 0x18004d900)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x18004d910)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • CStdStubBuffer2_Connect (Address: 0x18004d9d0)
  • CStdStubBuffer2_CountRefs (Address: 0x18004d9e0)
  • CStdStubBuffer2_Disconnect (Address: 0x18004da10)
  • CStdStubBuffer2_QueryInterface (Address: 0x18004d970)
  • NdrProxyForwardingFunction3 (Address: 0x18004d978)
  • NdrProxyForwardingFunction4 (Address: 0x18004d950)
  • NdrProxyForwardingFunction5 (Address: 0x18004d948)
  • ObjectStublessClient10 (Address: 0x18004da18)
  • ObjectStublessClient11 (Address: 0x18004d9e8)
  • ObjectStublessClient12 (Address: 0x18004da08)
  • ObjectStublessClient13 (Address: 0x18004d980)
  • ObjectStublessClient14 (Address: 0x18004d9f0)
  • ObjectStublessClient15 (Address: 0x18004d9a0)
  • ObjectStublessClient16 (Address: 0x18004d958)
  • ObjectStublessClient17 (Address: 0x18004d928)
  • ObjectStublessClient18 (Address: 0x18004d9b8)
  • ObjectStublessClient19 (Address: 0x18004d968)
  • ObjectStublessClient20 (Address: 0x18004d9a8)
  • ObjectStublessClient21 (Address: 0x18004da20)
  • ObjectStublessClient22 (Address: 0x18004d9c8)
  • ObjectStublessClient23 (Address: 0x18004d998)
  • ObjectStublessClient24 (Address: 0x18004d9d8)
  • ObjectStublessClient25 (Address: 0x18004d9f8)
  • ObjectStublessClient26 (Address: 0x18004d920)
  • ObjectStublessClient27 (Address: 0x18004d9c0)
  • ObjectStublessClient28 (Address: 0x18004d9b0)
  • ObjectStublessClient29 (Address: 0x18004d960)
  • ObjectStublessClient30 (Address: 0x18004d990)
  • ObjectStublessClient31 (Address: 0x18004da00)
  • ObjectStublessClient6 (Address: 0x18004d940)
  • ObjectStublessClient7 (Address: 0x18004d988)
  • ObjectStublessClient8 (Address: 0x18004d938)
  • ObjectStublessClient9 (Address: 0x18004d930)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x18004da38)
  • IsDebuggerPresent (Address: 0x18004da40)
  • OutputDebugStringW (Address: 0x18004da30)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x18004da50)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x18004da60)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x18004da80)
  • RaiseException (Address: 0x18004da70)
  • SetLastError (Address: 0x18004da90)
  • SetUnhandledExceptionFilter (Address: 0x18004da78)
  • UnhandledExceptionFilter (Address: 0x18004da88)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x18004daa0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x18004dab8)
  • DuplicateHandle (Address: 0x18004dab0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x18004dad8)
  • HeapAlloc (Address: 0x18004dad0)
  • HeapFree (Address: 0x18004dac8)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x18004daf0)
  • LocalFree (Address: 0x18004dae8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetSystemPowerStatus (Address: 0x18004db08)
  • RegisterWaitForSingleObject (Address: 0x18004db00)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x18004db30)
  • FreeLibrary (Address: 0x18004db28)
  • GetModuleFileNameA (Address: 0x18004db18)
  • GetModuleHandleExW (Address: 0x18004db40)
  • GetModuleHandleW (Address: 0x18004db48)
  • GetProcAddress (Address: 0x18004db20)
  • LoadStringW (Address: 0x18004db38)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x18004db58)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x18004db70)
  • MapViewOfFile (Address: 0x18004db78)
  • UnmapViewOfFile (Address: 0x18004db68)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x18004db88)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x18004dbc8)
  • GetCurrentProcess (Address: 0x18004dbe0)
  • GetCurrentProcessId (Address: 0x18004dbb8)
  • GetCurrentThread (Address: 0x18004db98)
  • GetCurrentThreadId (Address: 0x18004dbd0)
  • GetExitCodeProcess (Address: 0x18004dbd8)
  • GetProcessId (Address: 0x18004dba8)
  • OpenProcessToken (Address: 0x18004dbc0)
  • OpenThreadToken (Address: 0x18004dba0)
  • TerminateProcess (Address: 0x18004dbb0)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x18004dbf0)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x18004dc00)
api-ms-win-core-psapi-l1-1-0.dll
  • QueryFullProcessImageNameW (Address: 0x18004dc10)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x18004dc40)
  • RegCreateKeyExW (Address: 0x18004dc28)
  • RegGetValueW (Address: 0x18004dc20)
  • RegOpenKeyExW (Address: 0x18004dc38)
  • RegQueryInfoKeyW (Address: 0x18004dc30)
  • RegQueryValueExW (Address: 0x18004dc48)
  • RegSetValueExW (Address: 0x18004dc50)
api-ms-win-core-registryuserspecific-l1-1-0.dll
  • SHRegGetUSValueW (Address: 0x18004dc60)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x18004dc70)
  • RtlLookupFunctionEntry (Address: 0x18004dc78)
  • RtlVirtualUnwind (Address: 0x18004dc80)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x18004dc90)
api-ms-win-core-string-l2-1-1.dll
  • SHLoadIndirectString (Address: 0x18004dca0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x18004dd58)
  • AcquireSRWLockShared (Address: 0x18004dcc8)
  • CreateEventExW (Address: 0x18004dd48)
  • CreateEventW (Address: 0x18004dcb0)
  • CreateMutexExW (Address: 0x18004dd30)
  • CreateSemaphoreExW (Address: 0x18004dcd0)
  • DeleteCriticalSection (Address: 0x18004dce8)
  • EnterCriticalSection (Address: 0x18004dd38)
  • InitializeCriticalSectionEx (Address: 0x18004dce0)
  • InitializeSRWLock (Address: 0x18004dcc0)
  • LeaveCriticalSection (Address: 0x18004dd40)
  • OpenEventW (Address: 0x18004dd50)
  • OpenSemaphoreW (Address: 0x18004dd20)
  • ReleaseMutex (Address: 0x18004dd10)
  • ReleaseSemaphore (Address: 0x18004dcf8)
  • ReleaseSRWLockExclusive (Address: 0x18004dcd8)
  • ReleaseSRWLockShared (Address: 0x18004dcb8)
  • ResetEvent (Address: 0x18004dd60)
  • SetEvent (Address: 0x18004dd08)
  • TryAcquireSRWLockShared (Address: 0x18004dcf0)
  • WaitForMultipleObjectsEx (Address: 0x18004dd28)
  • WaitForSingleObject (Address: 0x18004dd00)
  • WaitForSingleObjectEx (Address: 0x18004dd18)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x18004dd90)
  • InitOnceComplete (Address: 0x18004dd78)
  • InitOnceExecuteOnce (Address: 0x18004dd88)
  • Sleep (Address: 0x18004dd80)
  • WaitOnAddress (Address: 0x18004dd98)
  • WakeByAddressAll (Address: 0x18004dd70)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x18004dda8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x18004ddb8)
  • GetTickCount (Address: 0x18004ddc8)
  • GetVersionExW (Address: 0x18004ddc0)
api-ms-win-core-sysinfo-l1-2-0.dll
  • GetProductInfo (Address: 0x18004ddd8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x18004de10)
  • CloseThreadpoolWork (Address: 0x18004de00)
  • CreateThreadpoolTimer (Address: 0x18004dde8)
  • CreateThreadpoolWork (Address: 0x18004de08)
  • FreeLibraryWhenCallbackReturns (Address: 0x18004de20)
  • SetThreadpoolTimer (Address: 0x18004ddf0)
  • SubmitThreadpoolWork (Address: 0x18004ddf8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18004de18)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • CreateTimerQueueTimer (Address: 0x18004de30)
  • DeleteTimerQueueTimer (Address: 0x18004de40)
  • UnregisterWaitEx (Address: 0x18004de38)
api-ms-win-core-timezone-l1-1-0.dll
  • GetDynamicTimeZoneInformation (Address: 0x18004de50)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x18004de60)
  • EncodePointer (Address: 0x18004de68)
api-ms-win-core-winrt-error-l1-1-0.dll
  • RoOriginateError (Address: 0x18004de80)
  • RoOriginateErrorW (Address: 0x18004de88)
  • RoTransformError (Address: 0x18004de78)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x18004dea0)
  • RoGetActivationFactory (Address: 0x18004de98)
api-ms-win-core-winrt-string-l1-1-0.dll
  • HSTRING_UserFree (Address: 0x18004df20)
  • HSTRING_UserFree64 (Address: 0x18004def0)
  • HSTRING_UserMarshal (Address: 0x18004def8)
  • HSTRING_UserMarshal64 (Address: 0x18004dee0)
  • HSTRING_UserSize (Address: 0x18004df00)
  • HSTRING_UserSize64 (Address: 0x18004dee8)
  • HSTRING_UserUnmarshal (Address: 0x18004ded8)
  • HSTRING_UserUnmarshal64 (Address: 0x18004ded0)
  • WindowsCreateString (Address: 0x18004dec8)
  • WindowsCreateStringReference (Address: 0x18004dec0)
  • WindowsDeleteString (Address: 0x18004deb8)
  • WindowsDuplicateString (Address: 0x18004deb0)
  • WindowsGetStringRawBuffer (Address: 0x18004df08)
  • WindowsIsStringEmpty (Address: 0x18004df18)
  • WindowsStringHasEmbeddedNull (Address: 0x18004df10)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x18004df38)
  • EventRegister (Address: 0x18004df50)
  • EventSetInformation (Address: 0x18004df30)
  • EventUnregister (Address: 0x18004df48)
  • EventWriteTransfer (Address: 0x18004df40)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • GetSystemMetrics (Address: 0x18004df60)
  • SystemParametersInfoW (Address: 0x18004df68)
api-ms-win-power-base-l1-1-0.dll
  • GetPwrCapabilities (Address: 0x18004df78)
api-ms-win-rtcore-ntuser-powermanagement-l1-1-0.dll
  • RegisterPowerSettingNotification (Address: 0x18004df90)
  • UnregisterPowerSettingNotification (Address: 0x18004df88)
api-ms-win-rtcore-ntuser-private-l1-1-0.dll
  • GetWindowBand (Address: 0x18004dfa0)
api-ms-win-rtcore-ntuser-synch-l1-1-0.dll
  • MsgWaitForMultipleObjectsEx (Address: 0x18004dfb0)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • DefWindowProcW (Address: 0x18004e000)
  • DestroyWindow (Address: 0x18004dfd8)
  • DispatchMessageW (Address: 0x18004dfe0)
  • GetWindowLongPtrW (Address: 0x18004dfc8)
  • PeekMessageW (Address: 0x18004dff8)
  • PostMessageW (Address: 0x18004dff0)
  • PostQuitMessage (Address: 0x18004dfc0)
  • SetWindowLongPtrW (Address: 0x18004dfd0)
  • TranslateMessage (Address: 0x18004dfe8)
api-ms-win-security-base-l1-1-0.dll
  • DuplicateTokenEx (Address: 0x18004e018)
  • EqualSid (Address: 0x18004e010)
  • GetSidSubAuthority (Address: 0x18004e030)
  • GetTokenInformation (Address: 0x18004e028)
  • IsValidSid (Address: 0x18004e020)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x18004e040)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x18004e058)
  • ConvertStringSidToSidW (Address: 0x18004e050)
api-ms-win-shcore-scaling-l1-1-0.dll
  • GetScaleFactorForDevice (Address: 0x18004e068)
api-ms-win-shcore-stream-l1-1-0.dll
  • SHCreateMemStream (Address: 0x18004e080)
  • SHCreateStreamOnFileW (Address: 0x18004e078)
api-ms-win-shcore-stream-winrt-l1-1-0.dll
  • CreateRandomAccessStreamOverStream (Address: 0x18004e098)
  • CreateStreamOverRandomAccessStream (Address: 0x18004e090)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolGetUniqueContext (Address: 0x18004e0a8)
  • SHTaskPoolQueueTask (Address: 0x18004e0b0)
api-ms-win-shlwapi-winrt-storage-l1-1-1.dll
  • SHCreateWorkerWindowW (Address: 0x18004e0c0)
api-ms-win-stateseparation-helpers-l1-1-0.dll
  • GetPersistedRegistryLocationW (Address: 0x18004e0d0)
MrmCoreR.dll
  • ResourceManagerQueueGetString (Address: 0x18004d788)
msvcp110_win.dll
  • ?_Orphan_all@_Container_base0@std@@QEAAXXZ (Address: 0x18004e0e8)
  • ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x18004e0e0)
  • ?_Winerror_map@std@@YAPEBDH@Z (Address: 0x18004e100)
  • ?_Xbad_alloc@std@@YAXXZ (Address: 0x18004e110)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x18004e0f8)
  • ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x18004e108)
  • ??0id@locale@std@@QEAA@_K@Z (Address: 0x18004e0f0)
msvcrt.dll
  • __C_specific_handler (Address: 0x18004e1f0)
  • __CxxFrameHandler3 (Address: 0x18004e168)
  • __dllonexit (Address: 0x18004e208)
  • _amsg_exit (Address: 0x18004e1d8)
  • _callnewh (Address: 0x18004e1c8)
  • _CxxThrowException (Address: 0x18004e158)
  • _get_errno (Address: 0x18004e160)
  • _initterm (Address: 0x18004e1e8)
  • _lock (Address: 0x18004e218)
  • _onexit (Address: 0x18004e200)
  • _purecall (Address: 0x18004e190)
  • _set_errno (Address: 0x18004e120)
  • _unlock (Address: 0x18004e210)
  • _vsnprintf_s (Address: 0x18004e1b0)
  • _vsnwprintf (Address: 0x18004e170)
  • _wcsicmp (Address: 0x18004e180)
  • _XcptFilter (Address: 0x18004e1d0)
  • ??_V@YAXPEAX@Z (Address: 0x18004e138)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x18004e1a8)
  • ??0exception@@QEAA@XZ (Address: 0x18004e1a0)
  • ??1exception@@UEAA@XZ (Address: 0x18004e198)
  • ??1type_info@@UEAA@XZ (Address: 0x18004e1f8)
  • ??3@YAXPEAX@Z (Address: 0x18004e188)
  • ?terminate@@YAXXZ (Address: 0x18004e220)
  • free (Address: 0x18004e1e0)
  • malloc (Address: 0x18004e1c0)
  • memcmp (Address: 0x18004e150)
  • memcpy (Address: 0x18004e148)
  • memcpy_s (Address: 0x18004e178)
  • memmove (Address: 0x18004e140)
  • memmove_s (Address: 0x18004e1b8)
  • memset (Address: 0x18004e228)
  • realloc (Address: 0x18004e130)
  • wcschr (Address: 0x18004e128)
ntdll.dll
  • NtQueryInformationToken (Address: 0x18004e260)
  • NtQueryWnfStateData (Address: 0x18004e248)
  • NtSetInformationProcess (Address: 0x18004e288)
  • RtlAllocateHeap (Address: 0x18004e268)
  • RtlCompareUnicodeString (Address: 0x18004e278)
  • RtlFreeHeap (Address: 0x18004e258)
  • RtlInitUnicodeString (Address: 0x18004e270)
  • RtlNtStatusToDosErrorNoTeb (Address: 0x18004e280)
  • RtlPublishWnfStateData (Address: 0x18004e238)
  • RtlSubscribeWnfStateChangeNotification (Address: 0x18004e250)
  • RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x18004e240)
ole32.dll
  • CoGetCallerTID (Address: 0x18004e298)
OLEAUT32.dll
  • SysAllocString (Address: 0x18004d798)
  • SysFreeString (Address: 0x18004d7a8)
  • VariantClear (Address: 0x18004d7a0)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x18004d7d0)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x18004d808)
  • CStdStubBuffer_DebugServerRelease (Address: 0x18004d7b8)
  • CStdStubBuffer_Invoke (Address: 0x18004d820)
  • CStdStubBuffer_IsIIDSupported (Address: 0x18004d800)
  • IUnknown_AddRef_Proxy (Address: 0x18004d810)
  • IUnknown_QueryInterface_Proxy (Address: 0x18004d7e0)
  • IUnknown_Release_Proxy (Address: 0x18004d7c8)
  • NdrCStdStubBuffer2_Release (Address: 0x18004d7f0)
  • NdrDllCanUnloadNow (Address: 0x18004d7c0)
  • NdrDllGetClassObject (Address: 0x18004d828)
  • NdrOleAllocate (Address: 0x18004d7f8)
  • NdrOleFree (Address: 0x18004d7d8)
  • NdrStubCall3 (Address: 0x18004d7e8)
  • NdrStubForwardingFunction (Address: 0x18004d818)
SHCORE.dll
  • (Address: 0x18004d848)
  • (Address: 0x18004d840)
  • (Address: 0x18004d838)
SHELL32.dll
  • (Address: 0x18004d858)
  • DuplicateIcon (Address: 0x18004d860)
twinapi.appcore.dll
  • (Address: 0x18004e2a8)
  • (Address: 0x18004e2b0)
USER32.dll
  • DestroyIcon (Address: 0x18004d870)
  • GetSysColor (Address: 0x18004d878)