PresentationHost_v0400.dll

Description: Windows Presentation Foundation Host Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.8.9316.0

Architecture: 64-bit

Operating System: Windows

SHA256: 3ec4b7024ac0a1919ea6f42e31c2838d

File Size: 267.1 KB

Uploaded At: Dec. 1, 2025, 7:20 a.m.

Views: 32

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllMain (Ordinal: 1, Address: 0x2750)
  • Activate (Ordinal: 2, Address: 0x2ab0)
  • Deactivate (Ordinal: 3, Address: 0x34b0)
  • ForwardTranslateAccelerator (Ordinal: 4, Address: 0x3150)
  • SaveToHistory (Ordinal: 5, Address: 0x35f0)
  • LoadFromHistory (Ordinal: 6, Address: 0x3650)
  • ProcessUnhandledException (Ordinal: 7, Address: 0x3b00)
  • CreateIDispatchSTAForwarder (Ordinal: 8, Address: 0x19940)
  • SetFakeActiveWindow (Ordinal: 9, Address: 0x2580)
  • DllRegisterServer (Ordinal: 10, Address: 0x28c0)
  • DllUnregisterServer (Ordinal: 11, Address: 0x29d0)
  • ProcessCommandLine (Ordinal: 12, Address: 0x1f340)
  • DRMInitEnvironment (Ordinal: 601, Address: 0x18630)
  • DRMCreateBoundLicense (Ordinal: 602, Address: 0x186c0)
  • DRMCreateLicenseStorageSession (Ordinal: 603, Address: 0x18730)
  • DRMCreateEnablingBitsDecryptor (Ordinal: 604, Address: 0x187b0)
  • DRMCreateEnablingBitsEncryptor (Ordinal: 605, Address: 0x18820)
  • DRMEncrypt (Ordinal: 606, Address: 0x18890)
  • DRMDecrypt (Ordinal: 607, Address: 0x18910)
  • DRMGetInfo (Ordinal: 608, Address: 0x18990)
  • DRMGetBoundLicenseObjectCount (Ordinal: 609, Address: 0x18a00)
  • DRMGetBoundLicenseObject (Ordinal: 610, Address: 0x18a60)
  • DRMGetBoundLicenseAttribute (Ordinal: 611, Address: 0x18ac0)
  • DRMGetSignedIssuanceLicense (Ordinal: 612, Address: 0x18b40)
  • DRMGetServiceLocation (Ordinal: 613, Address: 0x18c00)
  • DRMCloseEnvironmentHandle (Ordinal: 614, Address: 0x18c80)
  • DRMCloseHandle (Ordinal: 615, Address: 0x18cc0)

Imported DLLs & Functions

ADVAPI32.dll
  • AddAccessAllowedAce (Address: 0x180028118)
  • AddAce (Address: 0x180028128)
  • CopySid (Address: 0x1800280e0)
  • CreateProcessAsUserW (Address: 0x1800280a8)
  • CreateRestrictedToken (Address: 0x1800280a0)
  • CreateWellKnownSid (Address: 0x1800280b8)
  • EqualSid (Address: 0x1800280b0)
  • GetAce (Address: 0x180028120)
  • GetAclInformation (Address: 0x180028100)
  • GetKernelObjectSecurity (Address: 0x1800280e8)
  • GetLengthSid (Address: 0x180028108)
  • GetSecurityDescriptorDacl (Address: 0x1800280f0)
  • GetSidSubAuthority (Address: 0x180028090)
  • GetSidSubAuthorityCount (Address: 0x180028098)
  • GetTokenInformation (Address: 0x180028088)
  • GetTraceEnableFlags (Address: 0x180028050)
  • GetTraceEnableLevel (Address: 0x180028058)
  • GetTraceLoggerHandle (Address: 0x180028060)
  • InitializeAcl (Address: 0x180028110)
  • LsaClose (Address: 0x1800280d8)
  • LsaLookupPrivilegeValue (Address: 0x1800280c8)
  • LsaNtStatusToWinError (Address: 0x1800280d0)
  • LsaOpenPolicy (Address: 0x1800280c0)
  • OpenProcessToken (Address: 0x180028080)
  • RegCloseKey (Address: 0x180028018)
  • RegCreateKeyExW (Address: 0x180028040)
  • RegDeleteKeyW (Address: 0x180028020)
  • RegDeleteValueW (Address: 0x180028048)
  • RegEnumKeyExW (Address: 0x180028030)
  • RegEnumKeyW (Address: 0x180028078)
  • RegEnumValueW (Address: 0x180028070)
  • RegisterTraceGuidsW (Address: 0x180028068)
  • RegOpenKeyExW (Address: 0x180028008)
  • RegQueryInfoKeyW (Address: 0x180028028)
  • RegQueryValueExW (Address: 0x180028010)
  • RegSetValueExW (Address: 0x180028038)
  • SetTokenInformation (Address: 0x1800280f8)
  • TraceEvent (Address: 0x180028000)
GDI32.dll
  • BitBlt (Address: 0x180028150)
  • CreateCompatibleBitmap (Address: 0x180028168)
  • CreateCompatibleDC (Address: 0x180028170)
  • CreateSolidBrush (Address: 0x180028178)
  • DeleteDC (Address: 0x180028148)
  • DeleteObject (Address: 0x180028158)
  • GetDeviceCaps (Address: 0x180028180)
  • GetObjectW (Address: 0x180028138)
  • GetStockObject (Address: 0x180028140)
  • SelectObject (Address: 0x180028160)
KERNEL32.dll
  • ActivateActCtx (Address: 0x180028370)
  • CloseHandle (Address: 0x180028238)
  • CreateActCtxW (Address: 0x180028368)
  • CreateEventW (Address: 0x1800281e0)
  • CreateFileMappingW (Address: 0x180028438)
  • CreateFileW (Address: 0x180028388)
  • CreateMutexW (Address: 0x180028270)
  • CreateProcessW (Address: 0x1800283a0)
  • CreateTimerQueueTimer (Address: 0x1800282f0)
  • CreateToolhelp32Snapshot (Address: 0x180028218)
  • DeactivateActCtx (Address: 0x180028378)
  • DecodePointer (Address: 0x1800281c8)
  • DeleteCriticalSection (Address: 0x1800281b0)
  • DeleteTimerQueueTimer (Address: 0x1800282f8)
  • DisableThreadLibraryCalls (Address: 0x1800281c0)
  • EncodePointer (Address: 0x180028490)
  • EnterCriticalSection (Address: 0x180028240)
  • ExitProcess (Address: 0x180028200)
  • ExpandEnvironmentStringsW (Address: 0x1800282e0)
  • FileTimeToSystemTime (Address: 0x180028330)
  • FindClose (Address: 0x1800282b0)
  • FindFirstFileW (Address: 0x1800282a8)
  • FindResourceExW (Address: 0x180028430)
  • FindResourceW (Address: 0x180028198)
  • FlushInstructionCache (Address: 0x180028460)
  • FormatMessageW (Address: 0x180028358)
  • FreeLibrary (Address: 0x1800284e0)
  • GetCommandLineW (Address: 0x180028340)
  • GetCurrentProcess (Address: 0x180028290)
  • GetCurrentProcessId (Address: 0x180028220)
  • GetCurrentThread (Address: 0x1800284f0)
  • GetCurrentThreadId (Address: 0x1800284e8)
  • GetEnvironmentVariableW (Address: 0x180028310)
  • GetExitCodeProcess (Address: 0x1800283a8)
  • GetFileAttributesExW (Address: 0x180028328)
  • GetLastError (Address: 0x1800283b8)
  • GetLocaleInfoW (Address: 0x180028420)
  • GetModuleFileNameW (Address: 0x1800281a8)
  • GetModuleHandleW (Address: 0x1800283d0)
  • GetNativeSystemInfo (Address: 0x180028398)
  • GetProcAddress (Address: 0x1800284d8)
  • GetProcessHeap (Address: 0x180028478)
  • GetProcessTimes (Address: 0x180028288)
  • GetStartupInfoW (Address: 0x180028338)
  • GetSystemDefaultUILanguage (Address: 0x180028410)
  • GetSystemDirectoryW (Address: 0x180028208)
  • GetSystemTimeAsFileTime (Address: 0x180028298)
  • GetTempFileNameW (Address: 0x180028380)
  • GetTempPathW (Address: 0x180028318)
  • GetThreadContext (Address: 0x1800283e8)
  • GetUserDefaultLangID (Address: 0x1800282b8)
  • GetUserDefaultUILanguage (Address: 0x180028418)
  • GetVersionExW (Address: 0x1800281d0)
  • GlobalAlloc (Address: 0x1800281f8)
  • GlobalLock (Address: 0x180028258)
  • GlobalUnlock (Address: 0x180028250)
  • HeapAlloc (Address: 0x180028488)
  • HeapFree (Address: 0x180028480)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800284b8)
  • InitializeCriticalSectionEx (Address: 0x1800281b8)
  • InitializeSListHead (Address: 0x1800284a0)
  • InterlockedPopEntrySList (Address: 0x180028470)
  • InterlockedPushEntrySList (Address: 0x180028468)
  • IsDebuggerPresent (Address: 0x1800282e8)
  • IsProcessorFeaturePresent (Address: 0x1800284c0)
  • IsWow64Process (Address: 0x1800282d8)
  • LeaveCriticalSection (Address: 0x180028248)
  • LoadLibraryExA (Address: 0x180028448)
  • LoadLibraryExW (Address: 0x1800281a0)
  • LoadLibraryW (Address: 0x1800282a0)
  • LoadResource (Address: 0x180028190)
  • LocalAlloc (Address: 0x180028300)
  • LocalFree (Address: 0x180028308)
  • LockResource (Address: 0x180028210)
  • lstrcmpiW (Address: 0x1800283c8)
  • lstrcmpW (Address: 0x180028268)
  • MapViewOfFile (Address: 0x180028440)
  • Module32FirstW (Address: 0x180028228)
  • Module32NextW (Address: 0x180028230)
  • MulDiv (Address: 0x180028260)
  • MultiByteToWideChar (Address: 0x180028280)
  • OpenEventW (Address: 0x180028348)
  • OpenProcess (Address: 0x1800282c8)
  • OutputDebugStringW (Address: 0x180028498)
  • QueryPerformanceCounter (Address: 0x1800284a8)
  • QueueUserWorkItem (Address: 0x1800281e8)
  • RaiseException (Address: 0x1800283c0)
  • RegisterWaitForSingleObject (Address: 0x1800282d0)
  • ReleaseActCtx (Address: 0x180028360)
  • ReleaseMutex (Address: 0x180028278)
  • ResetEvent (Address: 0x180028320)
  • ResumeThread (Address: 0x1800283f0)
  • SearchPathW (Address: 0x180028408)
  • SetEvent (Address: 0x1800281d8)
  • SetLastError (Address: 0x1800284f8)
  • SetThreadContext (Address: 0x1800283e0)
  • SetUnhandledExceptionFilter (Address: 0x1800284c8)
  • SizeofResource (Address: 0x1800283b0)
  • SuspendThread (Address: 0x1800283f8)
  • SwitchToThread (Address: 0x180028350)
  • TerminateProcess (Address: 0x1800282c0)
  • UnhandledExceptionFilter (Address: 0x1800284d0)
  • UnmapViewOfFile (Address: 0x180028428)
  • VirtualAlloc (Address: 0x180028458)
  • VirtualFree (Address: 0x180028450)
  • VirtualProtect (Address: 0x180028400)
  • VirtualQuery (Address: 0x1800283d8)
  • WaitForMultipleObjects (Address: 0x180028500)
  • WaitForSingleObject (Address: 0x1800281f0)
  • WaitForSingleObjectEx (Address: 0x1800284b0)
  • WriteFile (Address: 0x180028390)
mscoree.dll
  • CLRCreateInstance (Address: 0x180028958)
  • CoEEShutDownCOM (Address: 0x180028950)
  • LoadLibraryShim (Address: 0x180028960)
ntdll.dll
  • RtlCaptureContext (Address: 0x180028978)
  • RtlInitUnicodeString (Address: 0x180028980)
  • RtlLookupFunctionEntry (Address: 0x180028970)
  • RtlVirtualUnwind (Address: 0x180028988)
ole32.dll
  • CLSIDFromProgID (Address: 0x1800289d8)
  • CLSIDFromString (Address: 0x1800289e0)
  • CoAllowSetForegroundWindow (Address: 0x180028a00)
  • CoCreateInstance (Address: 0x1800289c0)
  • CoGetClassObject (Address: 0x1800289d0)
  • CoInitialize (Address: 0x180028a20)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x180028a48)
  • CoRegisterClassObject (Address: 0x1800289f8)
  • CoRegisterMessageFilter (Address: 0x1800289e8)
  • CoReleaseMarshalData (Address: 0x1800289f0)
  • CoRevokeClassObject (Address: 0x180028a38)
  • CoTaskMemAlloc (Address: 0x1800289b8)
  • CoTaskMemFree (Address: 0x1800289a8)
  • CoTaskMemRealloc (Address: 0x1800289b0)
  • CoUninitialize (Address: 0x180028a28)
  • CoUnmarshalInterface (Address: 0x180028a30)
  • CreateBindCtx (Address: 0x180028a18)
  • CreateStreamOnHGlobal (Address: 0x180028a58)
  • OleCreateMenuDescriptor (Address: 0x180028a08)
  • OleDestroyMenuDescriptor (Address: 0x180028a10)
  • OleInitialize (Address: 0x180028a50)
  • OleLockRunning (Address: 0x1800289a0)
  • OleTranslateAccelerator (Address: 0x180028a40)
  • OleUninitialize (Address: 0x180028998)
  • StringFromGUID2 (Address: 0x1800289c8)
OLEAUT32.dll
  • DispCallFunc (Address: 0x180028548)
  • LoadRegTypeLib (Address: 0x180028558)
  • LoadTypeLib (Address: 0x180028528)
  • OleCreateFontIndirect (Address: 0x180028550)
  • SysAllocString (Address: 0x180028570)
  • SysAllocStringByteLen (Address: 0x180028530)
  • SysAllocStringLen (Address: 0x180028560)
  • SysFreeString (Address: 0x180028510)
  • SysStringLen (Address: 0x180028518)
  • VariantClear (Address: 0x180028540)
  • VariantCopy (Address: 0x180028568)
  • VariantInit (Address: 0x180028538)
  • VarUI4FromStr (Address: 0x180028520)
PSAPI.DLL
  • GetMappedFileNameW (Address: 0x180028580)
SHELL32.dll
  • CommandLineToArgvW (Address: 0x180028598)
  • ShellExecuteExW (Address: 0x1800285b0)
  • ShellExecuteW (Address: 0x1800285a0)
  • SHGetFolderPathW (Address: 0x180028590)
  • SHGetKnownFolderPath (Address: 0x1800285a8)
SHLWAPI.dll
  • AssocQueryStringW (Address: 0x1800285d0)
  • PathAppendW (Address: 0x1800285c8)
  • PathCombineW (Address: 0x1800285c0)
  • PathFindExtensionW (Address: 0x1800285e0)
  • PathIsURLW (Address: 0x1800285e8)
  • UrlCreateFromPathW (Address: 0x1800285d8)
ucrtbase_clr0400.dll
  • __stdio_common_vswprintf (Address: 0x180028af0)
  • __stdio_common_vswprintf_s (Address: 0x180028ae0)
  • _beginthreadex (Address: 0x180028af8)
  • _callnewh (Address: 0x180028b50)
  • _cexit (Address: 0x180028a68)
  • _configure_narrow_argv (Address: 0x180028aa0)
  • _crt_atexit (Address: 0x180028b60)
  • _errno (Address: 0x180028b20)
  • _execute_onexit_table (Address: 0x180028a80)
  • _initialize_narrow_environment (Address: 0x180028a98)
  • _initialize_onexit_table (Address: 0x180028a90)
  • _initterm (Address: 0x180028a78)
  • _initterm_e (Address: 0x180028b70)
  • _invalid_parameter_noinfo (Address: 0x180028b28)
  • _invalid_parameter_noinfo_noreturn (Address: 0x180028ab8)
  • _recalloc (Address: 0x180028b18)
  • _register_onexit_function (Address: 0x180028a88)
  • _seh_filter_dll (Address: 0x180028aa8)
  • _ultow_s (Address: 0x180028ad8)
  • _wcsicmp (Address: 0x180028b40)
  • _wcslwr_s (Address: 0x180028ad0)
  • _wcsnicmp (Address: 0x180028b00)
  • bsearch (Address: 0x180028b68)
  • free (Address: 0x180028b30)
  • isdigit (Address: 0x180028ac0)
  • iswdigit (Address: 0x180028ab0)
  • malloc (Address: 0x180028b48)
  • terminate (Address: 0x180028a70)
  • tolower (Address: 0x180028ac8)
  • wcscat_s (Address: 0x180028b08)
  • wcscmp (Address: 0x180028b58)
  • wcscpy_s (Address: 0x180028b10)
  • wcsncmp (Address: 0x180028ae8)
  • wcsncpy_s (Address: 0x180028b38)
urlmon.dll
  • CoInternetCombineUrl (Address: 0x180028ba0)
  • CoInternetCreateSecurityManager (Address: 0x180028bd0)
  • CoInternetParseUrl (Address: 0x180028ba8)
  • CompareSecurityIds (Address: 0x180028bc8)
  • CreateURLMoniker (Address: 0x180028bb0)
  • CreateURLMonikerEx (Address: 0x180028b88)
  • GetClassFileOrMime (Address: 0x180028b90)
  • RegisterBindStatusCallback (Address: 0x180028b80)
  • URLDownloadToCacheFileW (Address: 0x180028b98)
  • UrlMkGetSessionOption (Address: 0x180028bc0)
  • URLOpenBlockingStreamW (Address: 0x180028bb8)
USER32.dll
  • BeginPaint (Address: 0x180028878)
  • CallWindowProcW (Address: 0x180028608)
  • CharNextW (Address: 0x180028860)
  • CheckMenuItem (Address: 0x1800286e8)
  • ClientToScreen (Address: 0x180028640)
  • CreateAcceleratorTableW (Address: 0x180028648)
  • CreateMenu (Address: 0x180028718)
  • CreateWindowExW (Address: 0x1800287a8)
  • DefWindowProcW (Address: 0x180028828)
  • DestroyAcceleratorTable (Address: 0x180028798)
  • DestroyMenu (Address: 0x180028740)
  • DestroyWindow (Address: 0x180028650)
  • DispatchMessageW (Address: 0x180028840)
  • EnableMenuItem (Address: 0x180028758)
  • EndPaint (Address: 0x1800286a0)
  • FillRect (Address: 0x180028618)
  • GetActiveWindow (Address: 0x180028868)
  • GetClassInfoExW (Address: 0x180028658)
  • GetClassInfoW (Address: 0x1800286f8)
  • GetClassNameW (Address: 0x180028810)
  • GetClientRect (Address: 0x1800287b0)
  • GetDC (Address: 0x1800285f8)
  • GetDesktopWindow (Address: 0x180028778)
  • GetDlgItem (Address: 0x180028688)
  • GetFocus (Address: 0x180028690)
  • GetKeyState (Address: 0x180028830)
  • GetMenuItemCount (Address: 0x1800286d0)
  • GetMenuItemID (Address: 0x1800286e0)
  • GetMenuItemInfoW (Address: 0x180028750)
  • GetMenuStringW (Address: 0x180028720)
  • GetMessageExtraInfo (Address: 0x180028858)
  • GetMessageW (Address: 0x180028818)
  • GetParent (Address: 0x180028638)
  • GetSubMenu (Address: 0x1800287f8)
  • GetSysColor (Address: 0x180028670)
  • GetWindow (Address: 0x1800287d0)
  • GetWindowLongPtrW (Address: 0x1800287d8)
  • GetWindowLongW (Address: 0x1800287e0)
  • GetWindowTextLengthW (Address: 0x1800286c0)
  • GetWindowTextW (Address: 0x1800286b8)
  • GetWindowThreadProcessId (Address: 0x1800286f0)
  • InsertMenuW (Address: 0x180028728)
  • InvalidateRect (Address: 0x180028600)
  • InvalidateRgn (Address: 0x180028610)
  • IsChild (Address: 0x180028698)
  • IsWindow (Address: 0x180028678)
  • KillTimer (Address: 0x180028710)
  • LoadCursorW (Address: 0x1800287f0)
  • LoadMenuW (Address: 0x180028730)
  • LoadStringW (Address: 0x180028748)
  • MessageBeep (Address: 0x180028768)
  • MessageBoxW (Address: 0x180028800)
  • MoveWindow (Address: 0x180028780)
  • MsgWaitForMultipleObjects (Address: 0x180028850)
  • PeekMessageW (Address: 0x180028848)
  • PostMessageW (Address: 0x180028820)
  • PostQuitMessage (Address: 0x180028760)
  • PostThreadMessageW (Address: 0x180028788)
  • RedrawWindow (Address: 0x180028660)
  • RegisterClassExW (Address: 0x180028870)
  • RegisterClassW (Address: 0x1800287b8)
  • RegisterRawInputDevices (Address: 0x180028708)
  • RegisterWindowMessageW (Address: 0x1800286c8)
  • ReleaseCapture (Address: 0x180028620)
  • ReleaseDC (Address: 0x1800286d8)
  • RemoveMenu (Address: 0x180028738)
  • ScreenToClient (Address: 0x180028630)
  • SendMessageW (Address: 0x180028680)
  • SetCapture (Address: 0x180028628)
  • SetFocus (Address: 0x1800287a0)
  • SetMessageExtraInfo (Address: 0x180028838)
  • SetParent (Address: 0x1800287c0)
  • SetTimer (Address: 0x180028700)
  • SetWindowLongPtrW (Address: 0x1800287c8)
  • SetWindowLongW (Address: 0x1800287e8)
  • SetWindowPos (Address: 0x180028668)
  • SetWindowTextW (Address: 0x1800286b0)
  • ShowWindow (Address: 0x180028790)
  • TranslateMessage (Address: 0x180028808)
  • UnregisterClassW (Address: 0x1800286a8)
  • WaitForInputIdle (Address: 0x180028770)
VCRUNTIME140_1_CLR0400.dll
  • __CxxFrameHandler4 (Address: 0x180028888)
VCRUNTIME140_CLR0400.dll
  • __C_specific_handler (Address: 0x1800288a8)
  • __current_exception (Address: 0x1800288a0)
  • __current_exception_context (Address: 0x180028898)
  • __std_type_info_destroy_list (Address: 0x1800288b0)
  • _CxxThrowException (Address: 0x1800288f0)
  • _purecall (Address: 0x1800288d0)
  • memcmp (Address: 0x1800288e8)
  • memcpy (Address: 0x1800288b8)
  • memmove (Address: 0x1800288e0)
  • memset (Address: 0x1800288c0)
  • wcschr (Address: 0x1800288c8)
  • wcsstr (Address: 0x1800288d8)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x180028910)
  • GetFileVersionInfoW (Address: 0x180028908)
  • VerQueryValueW (Address: 0x180028900)
WININET.dll
  • InternetCrackUrlW (Address: 0x180028928)
  • InternetCreateUrlW (Address: 0x180028920)
  • InternetErrorDlg (Address: 0x180028930)
  • InternetGetCookieExW (Address: 0x180028938)
  • InternetSetCookieExW (Address: 0x180028940)