modernexecserver.dll
Description: Modern Execution Server
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: e488936d13de255262cfb56fb84675c1
File Size: 477.0 KB
Uploaded At: Dec. 1, 2025, 7:33 a.m.
Views: 8
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x1b590)
- DllGetActivationFactory (Ordinal: 2, Address: 0x29080)
- DllGetClassObject (Ordinal: 3, Address: 0x1c010)
Imported DLLs & Functions
api-ms-win-appmodel-identity-l1-2-0.dll
- AppXFreeMemory (Address: 0x180059538)
- AppXGetPackageSid (Address: 0x180059530)
api-ms-win-appmodel-runtime-l1-1-0.dll
- GetPackageFullName (Address: 0x180059548)
- GetPackagesByPackageFamily (Address: 0x180059558)
- PackageFamilyNameFromFullName (Address: 0x180059550)
api-ms-win-appmodel-runtime-l1-1-1.dll
- FindPackagesByPackageFamily (Address: 0x180059588)
- FormatApplicationUserModelId (Address: 0x180059580)
- ParseApplicationUserModelId (Address: 0x180059570)
- VerifyPackageFamilyName (Address: 0x180059568)
- VerifyPackageFullName (Address: 0x180059578)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180059598)
api-ms-win-core-biptcltapi-l1-1-7.dll
- BiPtFreeMemory (Address: 0x1800595a8)
api-ms-win-core-com-l1-1-0.dll
- CoCancelCall (Address: 0x1800595d8)
- CoCreateFreeThreadedMarshaler (Address: 0x180059628)
- CoCreateInstance (Address: 0x1800595f8)
- CoDisableCallCancellation (Address: 0x180059600)
- CoEnableCallCancellation (Address: 0x1800595d0)
- CoGetApartmentType (Address: 0x1800595b8)
- CoGetCallContext (Address: 0x1800595e8)
- CoGetInterfaceAndReleaseStream (Address: 0x1800595c0)
- CoGetMalloc (Address: 0x180059640)
- CoImpersonateClient (Address: 0x180059608)
- CoInitializeEx (Address: 0x180059620)
- CoMarshalInterThreadInterfaceInStream (Address: 0x1800595f0)
- CoReleaseMarshalData (Address: 0x1800595c8)
- CoRevertToSelf (Address: 0x180059610)
- CoTaskMemAlloc (Address: 0x180059630)
- CoTaskMemFree (Address: 0x1800595e0)
- CoTaskMemRealloc (Address: 0x180059638)
- CoUninitialize (Address: 0x180059618)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x180059650)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180059660)
- IsDebuggerPresent (Address: 0x180059668)
- OutputDebugStringW (Address: 0x180059670)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180059680)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180059690)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800596b0)
- RaiseException (Address: 0x1800596b8)
- SetLastError (Address: 0x1800596a8)
- SetUnhandledExceptionFilter (Address: 0x1800596c0)
- UnhandledExceptionFilter (Address: 0x1800596a0)
api-ms-win-core-errorhandling-l1-1-2.dll
- RaiseFailFastException (Address: 0x1800596d0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800596e0)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800596f0)
- HeapAlloc (Address: 0x180059700)
- HeapFree (Address: 0x1800596f8)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x180059710)
- LocalFree (Address: 0x180059718)
- LocalReAlloc (Address: 0x180059720)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x180059748)
- GetModuleFileNameA (Address: 0x180059738)
- GetModuleHandleExW (Address: 0x180059730)
- GetModuleHandleW (Address: 0x180059750)
- GetProcAddress (Address: 0x180059740)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x180059760)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x180059780)
- GetCurrentProcess (Address: 0x1800597a8)
- GetCurrentProcessId (Address: 0x1800597a0)
- GetCurrentThread (Address: 0x180059790)
- GetCurrentThreadId (Address: 0x1800597b0)
- GetThreadId (Address: 0x180059770)
- OpenProcessToken (Address: 0x180059778)
- OpenThreadToken (Address: 0x180059798)
- ProcessIdToSessionId (Address: 0x180059788)
- TerminateProcess (Address: 0x1800597b8)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x1800597c8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800597d8)
api-ms-win-core-psm-key-l1-1-0.dll
- PsmCreateKey (Address: 0x180059808)
- PsmGetApplicationNameFromKey (Address: 0x1800597e8)
- PsmGetPackageFullNameFromKey (Address: 0x180059800)
- PsmIsDynamicKey (Address: 0x1800597f8)
- PsmIsValidKey (Address: 0x1800597f0)
api-ms-win-core-psm-key-l1-1-1.dll
- PsmCreateKeyWithDynamicId (Address: 0x180059818)
api-ms-win-core-psm-plm-l1-2-0.dll
- PsmDisconnect (Address: 0x180059828)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x180059880)
- RegCopyTreeW (Address: 0x180059858)
- RegCreateKeyExW (Address: 0x180059850)
- RegDeleteKeyExW (Address: 0x180059860)
- RegDeleteTreeW (Address: 0x180059838)
- RegEnumKeyExW (Address: 0x180059848)
- RegGetValueW (Address: 0x180059878)
- RegOpenKeyExW (Address: 0x180059868)
- RegQueryInfoKeyW (Address: 0x180059870)
- RegQueryValueExW (Address: 0x180059840)
- RegSetValueExW (Address: 0x180059888)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800598a0)
- RtlLookupFunctionEntry (Address: 0x180059898)
- RtlVirtualUnwind (Address: 0x1800598a8)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1800598b8)
api-ms-win-core-string-l2-1-1.dll
- SHLoadIndirectString (Address: 0x1800598c8)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x180059940)
- AcquireSRWLockShared (Address: 0x180059908)
- CreateEventExW (Address: 0x180059900)
- CreateEventW (Address: 0x180059918)
- CreateMutexExW (Address: 0x180059928)
- CreateSemaphoreExW (Address: 0x1800598d8)
- DeleteCriticalSection (Address: 0x1800598f0)
- EnterCriticalSection (Address: 0x180059970)
- InitializeCriticalSectionEx (Address: 0x180059920)
- InitializeSRWLock (Address: 0x180059958)
- LeaveCriticalSection (Address: 0x180059938)
- OpenEventW (Address: 0x180059948)
- OpenSemaphoreW (Address: 0x180059910)
- ReleaseMutex (Address: 0x1800598e8)
- ReleaseSemaphore (Address: 0x1800598e0)
- ReleaseSRWLockExclusive (Address: 0x1800598f8)
- ReleaseSRWLockShared (Address: 0x180059930)
- ResetEvent (Address: 0x180059960)
- SetEvent (Address: 0x180059978)
- WaitForSingleObject (Address: 0x180059950)
- WaitForSingleObjectEx (Address: 0x180059968)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x180059998)
- InitOnceComplete (Address: 0x1800599a0)
- InitOnceExecuteOnce (Address: 0x180059988)
- Sleep (Address: 0x180059990)
api-ms-win-core-synch-l1-2-1.dll
- WaitForMultipleObjects (Address: 0x1800599b0)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1800599c8)
- GetTickCount (Address: 0x1800599c0)
- GetTickCount64 (Address: 0x1800599d0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1800599e0)
- CreateThreadpoolTimer (Address: 0x1800599f8)
- SetThreadpoolTimer (Address: 0x1800599f0)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800599e8)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- CreateTimerQueueTimer (Address: 0x180059a08)
- DeleteTimerQueueTimer (Address: 0x180059a10)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x180059a20)
- EncodePointer (Address: 0x180059a28)
api-ms-win-core-winrt-error-l1-1-0.dll
- RoOriginateError (Address: 0x180059a40)
- RoOriginateErrorW (Address: 0x180059a50)
- RoTransformError (Address: 0x180059a38)
- SetRestrictedErrorInfo (Address: 0x180059a48)
api-ms-win-core-winrt-error-l1-1-1.dll
- RoGetMatchingRestrictedErrorInfo (Address: 0x180059a60)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x180059a70)
- RoGetActivationFactory (Address: 0x180059a78)
api-ms-win-core-winrt-propertysetprivate-l1-1-1.dll
- RoCreatePropertySetSerializer (Address: 0x180059a88)
api-ms-win-core-winrt-robuffer-l1-1-0.dll
- RoGetBufferMarshaler (Address: 0x180059a98)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCompareStringOrdinal (Address: 0x180059ab8)
- WindowsCreateString (Address: 0x180059ae8)
- WindowsCreateStringReference (Address: 0x180059ae0)
- WindowsDeleteString (Address: 0x180059af0)
- WindowsDuplicateString (Address: 0x180059aa8)
- WindowsGetStringLen (Address: 0x180059ad8)
- WindowsGetStringRawBuffer (Address: 0x180059ad0)
- WindowsIsStringEmpty (Address: 0x180059ac8)
- WindowsStringHasEmbeddedNull (Address: 0x180059ac0)
- WindowsSubstringWithSpecifiedLength (Address: 0x180059ab0)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x180059b18)
- EventProviderEnabled (Address: 0x180059b08)
- EventRegister (Address: 0x180059b20)
- EventSetInformation (Address: 0x180059b10)
- EventUnregister (Address: 0x180059b00)
- EventWriteTransfer (Address: 0x180059b28)
api-ms-win-security-accesshlpr-l1-1-0.dll
- FreeTransientObjectSecurityDescriptor (Address: 0x180059b38)
- QueryTransientObjectSecurityDescriptor (Address: 0x180059b40)
api-ms-win-security-base-l1-1-0.dll
- GetSecurityDescriptorDacl (Address: 0x180059b50)
- GetTokenInformation (Address: 0x180059b58)
- IsWellKnownSid (Address: 0x180059b60)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x180059b70)
api-ms-win-security-provider-l1-1-0.dll
- SetNamedSecurityInfoW (Address: 0x180059b80)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x180059b90)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180059b98)
- ConvertStringSidToSidW (Address: 0x180059ba0)
api-ms-win-shcore-comhelpers-l1-1-0.dll
- IUnknown_SetSite (Address: 0x180059bb0)
api-ms-win-shcore-registry-l1-1-0.dll
- SHEnumKeyExW (Address: 0x180059bc0)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolGetUniqueContext (Address: 0x180059bd0)
- SHTaskPoolQueueTask (Address: 0x180059bd8)
api-ms-win-shcore-thread-l1-1-0.dll
- SHCreateThreadWithHandle (Address: 0x180059be8)
- SHGetThreadRef (Address: 0x180059bf0)
combase.dll
- (Address: 0x180059c00)
- (Address: 0x180059c08)
CoreMessaging.dll
- CoreUICreate (Address: 0x180059350)
msvcrt.dll
- __C_specific_handler (Address: 0x180059c28)
- __CxxFrameHandler3 (Address: 0x180059cd8)
- __dllonexit (Address: 0x180059ca8)
- _amsg_exit (Address: 0x180059c98)
- _callnewh (Address: 0x180059c58)
- _CxxThrowException (Address: 0x180059c78)
- _initterm (Address: 0x180059c30)
- _lock (Address: 0x180059cd0)
- _onexit (Address: 0x180059cc8)
- _purecall (Address: 0x180059c68)
- _unlock (Address: 0x180059c90)
- _XcptFilter (Address: 0x180059cb8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x180059cb0)
- ??0exception@@QEAA@XZ (Address: 0x180059c60)
- ??1exception@@UEAA@XZ (Address: 0x180059c88)
- ??1type_info@@UEAA@XZ (Address: 0x180059c50)
- ?terminate@@YAXXZ (Address: 0x180059c48)
- free (Address: 0x180059cc0)
- malloc (Address: 0x180059c70)
- memcmp (Address: 0x180059c80)
- memcpy (Address: 0x180059ce0)
- memmove (Address: 0x180059ca0)
- memset (Address: 0x180059ce8)
- realloc (Address: 0x180059c38)
- toupper (Address: 0x180059c18)
- wcscspn (Address: 0x180059c20)
- wcsrchr (Address: 0x180059c40)
ntdll.dll
- _vsnprintf_s (Address: 0x180059d58)
- _vsnwprintf (Address: 0x180059e20)
- _wcsicmp (Address: 0x180059da8)
- _wcsnicmp (Address: 0x180059dc0)
- memcpy_s (Address: 0x180059d98)
- memmove_s (Address: 0x180059d50)
- NtClose (Address: 0x180059d38)
- NtOpenProcessTokenEx (Address: 0x180059d80)
- NtOpenThreadToken (Address: 0x180059d30)
- NtQueryInformationProcess (Address: 0x180059d88)
- NtQueryInformationToken (Address: 0x180059da0)
- RtlAcquireSRWLockExclusive (Address: 0x180059e48)
- RtlAcquireSRWLockShared (Address: 0x180059e30)
- RtlAllocateHeap (Address: 0x180059d08)
- RtlCompareUnicodeStrings (Address: 0x180059d10)
- RtlConvertSidToUnicodeString (Address: 0x180059d78)
- RtlCopySid (Address: 0x180059db8)
- RtlEqualSid (Address: 0x180059d68)
- RtlExpandEnvironmentStrings (Address: 0x180059e50)
- RtlFreeHeap (Address: 0x180059cf8)
- RtlFreeUnicodeString (Address: 0x180059d70)
- RtlGetDeviceFamilyInfoEnum (Address: 0x180059d40)
- RtlInitializeConditionVariable (Address: 0x180059df8)
- RtlInitializeSRWLock (Address: 0x180059d20)
- RtlInitUnicodeString (Address: 0x180059db0)
- RtlIsMultiSessionSku (Address: 0x180059d48)
- RtlLengthSid (Address: 0x180059e18)
- RtlNtStatusToDosError (Address: 0x180059e10)
- RtlQueryUnbiasedInterruptTime (Address: 0x180059d28)
- RtlRbInsertNodeEx (Address: 0x180059d90)
- RtlRbRemoveNode (Address: 0x180059d00)
- RtlReleaseSRWLockExclusive (Address: 0x180059e40)
- RtlReleaseSRWLockShared (Address: 0x180059d18)
- RtlSleepConditionVariableSRW (Address: 0x180059e28)
- RtlValidSid (Address: 0x180059d60)
- RtlWaitOnAddress (Address: 0x180059dd0)
- RtlWakeAddressAll (Address: 0x180059dc8)
- RtlWakeAllConditionVariable (Address: 0x180059e38)
- TpAllocTimer (Address: 0x180059df0)
- TpAllocWork (Address: 0x180059dd8)
- TpPostWork (Address: 0x180059de0)
- TpReleaseTimer (Address: 0x180059e00)
- TpReleaseWork (Address: 0x180059de8)
- TpSetTimerEx (Address: 0x180059e08)
RMCLIENT.dll
- HamCloseActivity (Address: 0x180059440)
- HamConnectForDebugging (Address: 0x180059368)
- HamConnectForServicing (Address: 0x180059398)
- HamConnectForSessionState (Address: 0x180059378)
- HamConnectForStateChangeNotifications (Address: 0x1800593a8)
- HamConnectToServer (Address: 0x180059390)
- HamConnectToServerEx (Address: 0x180059370)
- HamCreateActivity (Address: 0x180059460)
- HamDebugClosePackageHandle (Address: 0x180059468)
- HamDebugModeEnable (Address: 0x180059450)
- HamDebugOpenPackageHandle (Address: 0x180059478)
- HamDebugQueryPackageState (Address: 0x180059470)
- HamDebugSuspendPackage (Address: 0x180059480)
- HamDebugTerminatePackage (Address: 0x180059488)
- HamDisconnectForServicing (Address: 0x180059438)
- HamDisconnectForSessionState (Address: 0x1800593b0)
- HamDisconnectFromServer (Address: 0x1800593a0)
- HamGetApplicationStateForPsmKey (Address: 0x1800593c8)
- HamHostIdCreateSingleUse (Address: 0x180059400)
- HamHostIdFindOrCreate (Address: 0x1800593f0)
- HamHostIdInitializeKey (Address: 0x1800593f8)
- HamHostIdRetrieveDynamicId (Address: 0x180059408)
- HamInitializeActivityDynamicProperties (Address: 0x1800593e8)
- HamInitializeStateChangeFlags (Address: 0x180059388)
- HamIsHostBeingDebugged (Address: 0x180059380)
- HamPopulateActivityProperties (Address: 0x180059458)
- HamServicingClosePackageHandle (Address: 0x180059410)
- HamServicingEnableServicing (Address: 0x180059428)
- HamServicingOpenPackageHandle (Address: 0x180059418)
- HamServicingQueryActiveAppsInPackage (Address: 0x180059430)
- HamServicingTerminatePackage (Address: 0x180059420)
- HamSessionStateLogoffSession (Address: 0x1800593c0)
- HamSessionStateLogoffUser (Address: 0x1800593b8)
- HamSetCommitProperties (Address: 0x180059360)
- HamStartActivityAsync (Address: 0x180059448)
- HamStopActivity (Address: 0x180059498)
- HamTerminateActivityHost (Address: 0x1800593d8)
- HamTerminateActivityHostEx (Address: 0x1800593e0)
- HamTerminateIfSuspendedByProcess (Address: 0x1800593d0)
- HamUpdateActivityProperties (Address: 0x180059490)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x1800594a8)
- NdrClientCall3 (Address: 0x1800594d8)
- NdrServerCall2 (Address: 0x180059520)
- NdrServerCallAll (Address: 0x1800594e8)
- RpcBindingFree (Address: 0x1800594b0)
- RpcBindingVectorFree (Address: 0x180059510)
- RpcEpRegisterW (Address: 0x1800594f0)
- RpcEpUnregister (Address: 0x180059518)
- RpcImpersonateClient (Address: 0x1800594c0)
- RpcRevertToSelf (Address: 0x1800594e0)
- RpcRevertToSelfEx (Address: 0x1800594b8)
- RpcServerInqBindings (Address: 0x1800594d0)
- RpcServerInqCallAttributesW (Address: 0x1800594c8)
- RpcServerRegisterIf3 (Address: 0x180059508)
- RpcServerUnregisterIfEx (Address: 0x1800594f8)
- RpcServerUseProtseqW (Address: 0x180059500)