appprelaunchlib.dll

Description: AppPrelaunch Automation Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.26100.4654

Architecture: 64-bit

Operating System: Windows NT

SHA256: 1018271fd147ef7a1e17e14f05276f31

File Size: 134.3 KB

Uploaded At: Dec. 3, 2025, 2:36 a.m.

Views: 7

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x6150)
  • DllGetClassObject (Ordinal: 2, Address: 0x6180)
  • DllInstall (Ordinal: 3, Address: 0x62d0)
  • DllRegisterServer (Ordinal: 4, Address: 0x6320)
  • DllUnregisterServer (Ordinal: 5, Address: 0x6450)

Imported DLLs & Functions

ADVAPI32.dll
  • GetTokenInformation (Address: 0x180010f98)
  • OpenProcessToken (Address: 0x180010fa0)
  • RegCloseKey (Address: 0x180010fd8)
  • RegCreateKeyExW (Address: 0x180010fb0)
  • RegDeleteValueW (Address: 0x180010fa8)
  • RegEnumKeyExW (Address: 0x180010fc8)
  • RegOpenKeyExW (Address: 0x180010fc0)
  • RegQueryInfoKeyW (Address: 0x180010fd0)
  • RegSetValueExW (Address: 0x180010fb8)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180011218)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180011238)
  • IsDebuggerPresent (Address: 0x180011230)
  • OutputDebugStringW (Address: 0x180011228)
api-ms-win-core-errorhandling-l1-1-0.dll
  • SetLastError (Address: 0x180011248)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180011260)
  • HeapAlloc (Address: 0x180011258)
  • HeapFree (Address: 0x180011268)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x180011278)
  • GetModuleHandleExW (Address: 0x180011280)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180011290)
api-ms-win-core-synch-l1-1-0.dll
  • CreateMutexExW (Address: 0x1800112b8)
  • CreateSemaphoreExW (Address: 0x1800112c8)
  • OpenSemaphoreW (Address: 0x1800112a8)
  • ReleaseMutex (Address: 0x1800112c0)
  • ReleaseSemaphore (Address: 0x1800112a0)
  • WaitForSingleObjectEx (Address: 0x1800112b0)
KERNEL32.dll
  • CloseHandle (Address: 0x1800110b0)
  • CreateFileW (Address: 0x1800110f0)
  • CreateThread (Address: 0x180011058)
  • DelayLoadFailureHook (Address: 0x1800110e0)
  • DeleteCriticalSection (Address: 0x180011170)
  • DeleteFileW (Address: 0x180011000)
  • EnterCriticalSection (Address: 0x180011178)
  • FindResourceExW (Address: 0x180011150)
  • FreeLibrary (Address: 0x180011100)
  • GetApplicationUserModelId (Address: 0x180011090)
  • GetCurrentProcess (Address: 0x180011040)
  • GetCurrentProcessId (Address: 0x180011070)
  • GetCurrentThreadId (Address: 0x1800110d0)
  • GetExitCodeProcess (Address: 0x180011078)
  • GetFileSizeEx (Address: 0x180011020)
  • GetLastError (Address: 0x180011108)
  • GetLocalTime (Address: 0x180011038)
  • GetLogicalProcessorInformation (Address: 0x180011060)
  • GetModuleFileNameW (Address: 0x180011158)
  • GetModuleHandleW (Address: 0x180011120)
  • GetProcAddress (Address: 0x180011110)
  • GetSystemTimeAsFileTime (Address: 0x1800110f8)
  • GetThreadLocale (Address: 0x180011160)
  • GetTickCount (Address: 0x1800110a8)
  • InitializeCriticalSection (Address: 0x180011188)
  • K32EnumProcesses (Address: 0x180011098)
  • LeaveCriticalSection (Address: 0x180011180)
  • LoadLibraryExW (Address: 0x180011118)
  • LoadResource (Address: 0x180011148)
  • lstrcmpiW (Address: 0x180011128)
  • MultiByteToWideChar (Address: 0x180011138)
  • OpenProcess (Address: 0x1800110a0)
  • OutputDebugStringA (Address: 0x1800110d8)
  • ProcessIdToSessionId (Address: 0x180011068)
  • QueryPerformanceCounter (Address: 0x1800110c8)
  • RaiseException (Address: 0x180011130)
  • ReadFile (Address: 0x180011030)
  • ResolveDelayLoadedAPI (Address: 0x1800110e8)
  • ResumeThread (Address: 0x180010ff8)
  • RtlCaptureContext (Address: 0x180010ff0)
  • RtlLookupFunctionEntry (Address: 0x180010fe8)
  • RtlVirtualUnwind (Address: 0x180011028)
  • SetEndOfFile (Address: 0x180011010)
  • SetFilePointerEx (Address: 0x180011018)
  • SetThreadAffinityMask (Address: 0x180011050)
  • SetThreadLocale (Address: 0x180011168)
  • SetThreadPriority (Address: 0x180011048)
  • SetUnhandledExceptionFilter (Address: 0x1800110c0)
  • SizeofResource (Address: 0x180011140)
  • Sleep (Address: 0x180011198)
  • TerminateProcess (Address: 0x180011088)
  • UnhandledExceptionFilter (Address: 0x1800110b8)
  • WaitForSingleObject (Address: 0x180011080)
  • WriteFile (Address: 0x180011008)
  • WTSGetActiveConsoleSessionId (Address: 0x180011190)
msvcrt.dll
  • __C_specific_handler (Address: 0x180011340)
  • __CxxFrameHandler3 (Address: 0x180011398)
  • __CxxFrameHandler4 (Address: 0x180011358)
  • __dllonexit (Address: 0x1800113f8)
  • _amsg_exit (Address: 0x1800113b8)
  • _callnewh (Address: 0x180011348)
  • _CxxThrowException (Address: 0x180011388)
  • _errno (Address: 0x1800113d8)
  • _initterm (Address: 0x1800113c0)
  • _lock (Address: 0x1800113e8)
  • _onexit (Address: 0x180011400)
  • _purecall (Address: 0x1800112f0)
  • _unlock (Address: 0x1800113f0)
  • _vsnwprintf (Address: 0x180011328)
  • _wcsnicmp (Address: 0x180011300)
  • _wfopen (Address: 0x180011330)
  • _XcptFilter (Address: 0x1800113b0)
  • ??_V@YAXPEAX@Z (Address: 0x180011350)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180011360)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180011368)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180011370)
  • ??1exception@@UEAA@XZ (Address: 0x180011378)
  • ??1type_info@@UEAA@XZ (Address: 0x1800113d0)
  • ??3@YAXPEAX@Z (Address: 0x180011318)
  • ?terminate@@YAXXZ (Address: 0x1800113c8)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180011380)
  • free (Address: 0x1800112f8)
  • malloc (Address: 0x180011390)
  • memcmp (Address: 0x180011408)
  • memcpy (Address: 0x1800113a0)
  • memcpy_s (Address: 0x1800112d8)
  • memmove (Address: 0x1800113a8)
  • memset (Address: 0x180011410)
  • realloc (Address: 0x1800113e0)
  • vfwprintf (Address: 0x180011310)
  • wcscat_s (Address: 0x1800112e8)
  • wcscpy_s (Address: 0x1800112e0)
  • wcsncpy_s (Address: 0x180011338)
  • wcsrchr (Address: 0x180011308)
  • wprintf_s (Address: 0x180011320)
ntdll.dll
  • NtQueryInformationProcess (Address: 0x180011428)
  • NtQuerySystemInformation (Address: 0x180011438)
  • NtSetInformationProcess (Address: 0x180011430)
  • RtlRandomEx (Address: 0x180011420)
ole32.dll
  • CoAllowSetForegroundWindow (Address: 0x180011468)
  • CoCreateInstance (Address: 0x180011480)
  • CoGetObject (Address: 0x180011478)
  • CoTaskMemAlloc (Address: 0x180011458)
  • CoTaskMemFree (Address: 0x180011448)
  • CoTaskMemRealloc (Address: 0x180011450)
  • CreateBindCtx (Address: 0x180011470)
  • StringFromGUID2 (Address: 0x180011460)
OLEAUT32.dll
  • LoadRegTypeLib (Address: 0x1800111e0)
  • LoadTypeLib (Address: 0x1800111c8)
  • RegisterTypeLib (Address: 0x1800111d0)
  • SysAllocString (Address: 0x1800111c0)
  • SysFreeString (Address: 0x1800111a8)
  • SysStringLen (Address: 0x1800111d8)
  • UnRegisterTypeLib (Address: 0x1800111b8)
  • VarUI4FromStr (Address: 0x1800111b0)
USER32.dll
  • CharNextW (Address: 0x180011208)
  • LockSetForegroundWindow (Address: 0x1800111f8)
  • SendInput (Address: 0x1800111f0)
  • UnregisterClassA (Address: 0x180011200)