kwpsshellext64.dll
Description: KWPS Shellext
Authors: Copyright©2025 Kingsoft Corporation. All rights reserved.
Version: 12.1.0.23125
Architecture: 64-bit
Operating System: Windows NT
SHA256: d3acd92c22d84d75bc15a7f4bad8fa6b
File Size: 1.5 MB
Uploaded At: Dec. 4, 2025, 6:11 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x6aa0)
- DllGetClassObject (Ordinal: 2, Address: 0x6b80)
- DllInstall (Ordinal: 3, Address: 0x6d70)
- DllRegisterServer (Ordinal: 4, Address: 0x6db0)
- DllUnregisterServer (Ordinal: 5, Address: 0x8a10)
Imported DLLs & Functions
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18011c440)
- AreFileApisANSI (Address: 0x18011c478)
- CloseHandle (Address: 0x18011c0f8)
- CompareFileTime (Address: 0x18011c1c8)
- CompareStringEx (Address: 0x18011c4a0)
- CompareStringW (Address: 0x18011c3b8)
- CreateDirectoryW (Address: 0x18011c1d0)
- CreateEventW (Address: 0x18011c2b0)
- CreateFileW (Address: 0x18011c180)
- CreateProcessW (Address: 0x18011c268)
- CreateToolhelp32Snapshot (Address: 0x18011c288)
- DecodePointer (Address: 0x18011c020)
- DeleteCriticalSection (Address: 0x18011c040)
- DeleteFileW (Address: 0x18011c260)
- DisableThreadLibraryCalls (Address: 0x18011c058)
- EncodePointer (Address: 0x18011c060)
- EnterCriticalSection (Address: 0x18011c098)
- EnumSystemLocalesW (Address: 0x18011c388)
- ExitProcess (Address: 0x18011c3e0)
- ExpandEnvironmentStringsW (Address: 0x18011c270)
- FileTimeToSystemTime (Address: 0x18011c220)
- FindClose (Address: 0x18011c1d8)
- FindFirstFileExW (Address: 0x18011c468)
- FindFirstFileW (Address: 0x18011c150)
- FindNextFileW (Address: 0x18011c1e0)
- FindResourceExW (Address: 0x18011c170)
- FindResourceW (Address: 0x18011c0e0)
- FlushFileBuffers (Address: 0x18011c370)
- FlushInstructionCache (Address: 0x18011c2f0)
- FormatMessageA (Address: 0x18011c428)
- FreeEnvironmentStringsW (Address: 0x18011c330)
- FreeLibrary (Address: 0x18011c0a8)
- GetACP (Address: 0x18011c350)
- GetCommandLineA (Address: 0x18011c340)
- GetCommandLineW (Address: 0x18011c230)
- GetCompressedFileSizeW (Address: 0x18011c2a8)
- GetConsoleCP (Address: 0x18011c368)
- GetConsoleMode (Address: 0x18011c380)
- GetCPInfo (Address: 0x18011c4a8)
- GetCurrentProcess (Address: 0x18011c1a8)
- GetCurrentProcessId (Address: 0x18011c048)
- GetCurrentThread (Address: 0x18011c158)
- GetCurrentThreadId (Address: 0x18011c050)
- GetDateFormatW (Address: 0x18011c3c8)
- GetDriveTypeW (Address: 0x18011c130)
- GetEnvironmentStringsW (Address: 0x18011c338)
- GetEnvironmentVariableW (Address: 0x18011c250)
- GetFileAttributesExW (Address: 0x18011c1f0)
- GetFileAttributesW (Address: 0x18011c1e8)
- GetFileInformationByHandleEx (Address: 0x18011c190)
- GetFileSizeEx (Address: 0x18011c188)
- GetFileType (Address: 0x18011c3d0)
- GetLastError (Address: 0x18011c030)
- GetLocaleInfoEx (Address: 0x18011c498)
- GetLocaleInfoW (Address: 0x18011c3a0)
- GetLocalTime (Address: 0x18011c128)
- GetLongPathNameW (Address: 0x18011c2a0)
- GetModuleFileNameW (Address: 0x18011c0b0)
- GetModuleHandleExW (Address: 0x18011c3e8)
- GetModuleHandleW (Address: 0x18011c0b8)
- GetNumberFormatW (Address: 0x18011c198)
- GetOEMCP (Address: 0x18011c348)
- GetPrivateProfileIntW (Address: 0x18011c238)
- GetPrivateProfileStringW (Address: 0x18011c240)
- GetProcAddress (Address: 0x18011c0c0)
- GetProcessHeap (Address: 0x18011c090)
- GetStartupInfoW (Address: 0x18011c320)
- GetStdHandle (Address: 0x18011c3d8)
- GetStringTypeW (Address: 0x18011c458)
- GetSystemDirectoryW (Address: 0x18011c138)
- GetSystemInfo (Address: 0x18011c420)
- GetSystemTime (Address: 0x18011c210)
- GetSystemTimeAsFileTime (Address: 0x18011c490)
- GetThreadContext (Address: 0x18011c2e0)
- GetTickCount (Address: 0x18011c148)
- GetTimeFormatW (Address: 0x18011c3c0)
- GetTimeZoneInformation (Address: 0x18011c360)
- GetUserDefaultLCID (Address: 0x18011c390)
- GetUserDefaultUILanguage (Address: 0x18011c248)
- GetWindowsDirectoryW (Address: 0x18011c1b0)
- GlobalLock (Address: 0x18011c110)
- GlobalUnlock (Address: 0x18011c108)
- HeapAlloc (Address: 0x18011c070)
- HeapDestroy (Address: 0x18011c068)
- HeapFree (Address: 0x18011c080)
- HeapReAlloc (Address: 0x18011c078)
- HeapSize (Address: 0x18011c088)
- InitializeCriticalSectionAndSpinCount (Address: 0x18011c038)
- InitializeCriticalSectionEx (Address: 0x18011c448)
- InitializeSListHead (Address: 0x18011c3b0)
- InitializeSRWLock (Address: 0x18011c430)
- InterlockedFlushSList (Address: 0x18011c410)
- InterlockedPushEntrySList (Address: 0x18011c418)
- IsDebuggerPresent (Address: 0x18011c4b0)
- IsProcessorFeaturePresent (Address: 0x18011c4f8)
- IsValidCodePage (Address: 0x18011c358)
- IsValidLocale (Address: 0x18011c398)
- IsWow64Process (Address: 0x18011c1b8)
- LCMapStringEx (Address: 0x18011c488)
- LCMapStringW (Address: 0x18011c3a8)
- LeaveCriticalSection (Address: 0x18011c0a0)
- LoadLibraryExA (Address: 0x18011c318)
- LoadLibraryExW (Address: 0x18011c0c8)
- LoadLibraryW (Address: 0x18011c140)
- LoadResource (Address: 0x18011c0d0)
- LocalFree (Address: 0x18011c460)
- LockResource (Address: 0x18011c178)
- lstrcmpiW (Address: 0x18011c0e8)
- lstrlenW (Address: 0x18011c1c0)
- MultiByteToWideChar (Address: 0x18011c0f0)
- OpenProcess (Address: 0x18011c100)
- OutputDebugStringA (Address: 0x18011c2b8)
- OutputDebugStringW (Address: 0x18011c018)
- Process32FirstW (Address: 0x18011c290)
- Process32NextW (Address: 0x18011c298)
- ProcessIdToSessionId (Address: 0x18011c280)
- QueryFullProcessImageNameW (Address: 0x18011c118)
- QueryPerformanceCounter (Address: 0x18011c2c0)
- QueryPerformanceFrequency (Address: 0x18011c2c8)
- RaiseException (Address: 0x18011c028)
- ReadConsoleW (Address: 0x18011c378)
- ReadFile (Address: 0x18011c1f8)
- ReleaseSRWLockExclusive (Address: 0x18011c438)
- ResetEvent (Address: 0x18011c4c0)
- ResumeThread (Address: 0x18011c2d8)
- RtlCaptureContext (Address: 0x18011c4c8)
- RtlLookupFunctionEntry (Address: 0x18011c4d0)
- RtlPcToFileHeader (Address: 0x18011c500)
- RtlUnwind (Address: 0x18011c000)
- RtlUnwindEx (Address: 0x18011c008)
- RtlVirtualUnwind (Address: 0x18011c4d8)
- SetEndOfFile (Address: 0x18011c470)
- SetEnvironmentVariableW (Address: 0x18011c258)
- SetEvent (Address: 0x18011c4b8)
- SetFilePointerEx (Address: 0x18011c200)
- SetLastError (Address: 0x18011c1a0)
- SetStdHandle (Address: 0x18011c328)
- SetThreadContext (Address: 0x18011c2e8)
- SetUnhandledExceptionFilter (Address: 0x18011c4e8)
- SizeofResource (Address: 0x18011c0d8)
- Sleep (Address: 0x18011c278)
- SuspendThread (Address: 0x18011c2d0)
- SystemTimeToFileTime (Address: 0x18011c228)
- SystemTimeToTzSpecificLocalTime (Address: 0x18011c218)
- TerminateProcess (Address: 0x18011c4f0)
- TlsAlloc (Address: 0x18011c408)
- TlsFree (Address: 0x18011c3f0)
- TlsGetValue (Address: 0x18011c400)
- TlsSetValue (Address: 0x18011c3f8)
- TryEnterCriticalSection (Address: 0x18011c450)
- UnhandledExceptionFilter (Address: 0x18011c4e0)
- VerifyVersionInfoW (Address: 0x18011c168)
- VerSetConditionMask (Address: 0x18011c160)
- VirtualAlloc (Address: 0x18011c2f8)
- VirtualFree (Address: 0x18011c308)
- VirtualProtect (Address: 0x18011c300)
- VirtualQuery (Address: 0x18011c310)
- WaitForSingleObjectEx (Address: 0x18011c480)
- WideCharToMultiByte (Address: 0x18011c120)
- WriteConsoleW (Address: 0x18011c010)
- WriteFile (Address: 0x18011c208)
PROPSYS.dll
- PropVariantToString (Address: 0x18011c510)
USER32.dll
- CharNextW (Address: 0x18011c618)
- CreateMenu (Address: 0x18011c5e8)
- EnumChildWindows (Address: 0x18011c520)
- FindWindowExW (Address: 0x18011c560)
- GetDC (Address: 0x18011c5c0)
- GetDlgCtrlID (Address: 0x18011c538)
- GetDlgItem (Address: 0x18011c620)
- GetDlgItemTextW (Address: 0x18011c540)
- GetIconInfo (Address: 0x18011c5b0)
- GetMenuItemCount (Address: 0x18011c610)
- GetMenuItemInfoW (Address: 0x18011c608)
- GetMenuStringW (Address: 0x18011c5f0)
- GetParent (Address: 0x18011c568)
- GetSubMenu (Address: 0x18011c548)
- GetSysColor (Address: 0x18011c528)
- GetWindowLongPtrW (Address: 0x18011c578)
- GetWindowRect (Address: 0x18011c580)
- GetWindowTextLengthW (Address: 0x18011c598)
- GetWindowTextW (Address: 0x18011c588)
- InsertMenuItemW (Address: 0x18011c5c8)
- InsertMenuW (Address: 0x18011c5e0)
- KillTimer (Address: 0x18011c5f8)
- MonitorFromWindow (Address: 0x18011c550)
- ReleaseDC (Address: 0x18011c5b8)
- RemoveMenu (Address: 0x18011c5d8)
- SendMessageW (Address: 0x18011c5a8)
- SetDlgItemTextW (Address: 0x18011c590)
- SetMenuItemBitmaps (Address: 0x18011c5d0)
- SetTimer (Address: 0x18011c600)
- SetWindowLongPtrW (Address: 0x18011c570)
- SetWindowPos (Address: 0x18011c5a0)
- SetWindowTextW (Address: 0x18011c530)
- SystemParametersInfoW (Address: 0x18011c558)