werhandler.dll
Description: WPS Office WER Handler
Authors: Copyright©2025 Kingsoft Corporation. All rights reserved.
Version: 12.1.0.23125
Architecture: 32-bit
Operating System: Windows NT
SHA256: 211925b8d9f0b2142a43fa6c2a977a2b
File Size: 272.0 KB
Uploaded At: Dec. 4, 2025, 6:11 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- OutOfProcessExceptionEventCallback (Ordinal: 1, Address: 0x1270)
- OutOfProcessExceptionEventDebuggerLaunchCallback (Ordinal: 2, Address: 0x1510)
- OutOfProcessExceptionEventSignatureCallback (Ordinal: 3, Address: 0x18d0)
Imported DLLs & Functions
KERNEL32.dll
- CloseHandle (Address: 0x10029018)
- CreateEventW (Address: 0x100290f4)
- CreateFileW (Address: 0x1002900c)
- CreateToolhelp32Snapshot (Address: 0x10029078)
- DecodePointer (Address: 0x10029014)
- DeleteCriticalSection (Address: 0x10029028)
- EncodePointer (Address: 0x100290d4)
- EnterCriticalSection (Address: 0x100290b4)
- EnumSystemLocalesW (Address: 0x10029154)
- ExitProcess (Address: 0x10029130)
- FindClose (Address: 0x100290c4)
- FindFirstFileExW (Address: 0x100290c8)
- FindNextFileW (Address: 0x100290cc)
- FlushFileBuffers (Address: 0x10029184)
- FreeEnvironmentStringsW (Address: 0x10029174)
- FreeLibrary (Address: 0x1002905c)
- GetACP (Address: 0x10029164)
- GetCommandLineA (Address: 0x1002916c)
- GetCommandLineW (Address: 0x10029084)
- GetConsoleCP (Address: 0x1002909c)
- GetConsoleMode (Address: 0x10029158)
- GetCPInfo (Address: 0x100290e4)
- GetCurrentProcess (Address: 0x10029034)
- GetCurrentProcessId (Address: 0x10029038)
- GetCurrentThread (Address: 0x10029090)
- GetCurrentThreadId (Address: 0x100290c0)
- GetEnvironmentStringsW (Address: 0x10029170)
- GetFileType (Address: 0x10029140)
- GetLastError (Address: 0x10029020)
- GetLocaleInfoW (Address: 0x10029148)
- GetLocalTime (Address: 0x10029040)
- GetModuleFileNameW (Address: 0x10029060)
- GetModuleHandleA (Address: 0x10029064)
- GetModuleHandleExW (Address: 0x1002906c)
- GetModuleHandleW (Address: 0x10029068)
- GetOEMCP (Address: 0x10029168)
- GetProcAddress (Address: 0x10029070)
- GetProcessHeap (Address: 0x10029178)
- GetProcessId (Address: 0x10029004)
- GetStartupInfoW (Address: 0x1002910c)
- GetStdHandle (Address: 0x1002913c)
- GetStringTypeW (Address: 0x100290b0)
- GetSystemDirectoryW (Address: 0x10029044)
- GetSystemInfo (Address: 0x100290a0)
- GetSystemTimeAsFileTime (Address: 0x100290e0)
- GetSystemWow64DirectoryW (Address: 0x10029058)
- GetTempPathW (Address: 0x10029010)
- GetThreadId (Address: 0x10029008)
- GetUserDefaultLCID (Address: 0x10029150)
- HeapAlloc (Address: 0x10029138)
- HeapFree (Address: 0x10029134)
- HeapReAlloc (Address: 0x1002915c)
- HeapSize (Address: 0x1002917c)
- InitializeCriticalSectionAndSpinCount (Address: 0x10029024)
- InitializeCriticalSectionEx (Address: 0x100290bc)
- InitializeSListHead (Address: 0x10029110)
- InterlockedFlushSList (Address: 0x10029118)
- IsDebuggerPresent (Address: 0x10029108)
- IsProcessorFeaturePresent (Address: 0x10029104)
- IsValidCodePage (Address: 0x10029160)
- IsValidLocale (Address: 0x1002914c)
- LCMapStringEx (Address: 0x100290d8)
- LCMapStringW (Address: 0x10029144)
- LeaveCriticalSection (Address: 0x100290b8)
- LoadLibraryExA (Address: 0x100290ac)
- LoadLibraryExW (Address: 0x1002912c)
- LoadLibraryW (Address: 0x10029074)
- MapViewOfFile (Address: 0x10029050)
- MultiByteToWideChar (Address: 0x10029088)
- OpenFileMappingW (Address: 0x1002904c)
- OpenMutexW (Address: 0x10029030)
- OpenProcess (Address: 0x1002903c)
- OutputDebugStringW (Address: 0x10029000)
- Process32FirstW (Address: 0x1002907c)
- Process32NextW (Address: 0x10029080)
- ProcessIdToSessionId (Address: 0x10029094)
- QueryPerformanceCounter (Address: 0x100290dc)
- RaiseException (Address: 0x1002901c)
- ReadProcessMemory (Address: 0x10029048)
- ReleaseMutex (Address: 0x1002902c)
- ResetEvent (Address: 0x100290ec)
- RtlUnwind (Address: 0x10029114)
- SetEvent (Address: 0x100290e8)
- SetFilePointerEx (Address: 0x100290d0)
- SetLastError (Address: 0x10029098)
- SetStdHandle (Address: 0x10029180)
- SetUnhandledExceptionFilter (Address: 0x100290fc)
- TerminateProcess (Address: 0x10029100)
- TlsAlloc (Address: 0x1002911c)
- TlsFree (Address: 0x10029128)
- TlsGetValue (Address: 0x10029120)
- TlsSetValue (Address: 0x10029124)
- UnhandledExceptionFilter (Address: 0x100290f8)
- UnmapViewOfFile (Address: 0x10029054)
- VirtualProtect (Address: 0x100290a4)
- VirtualQuery (Address: 0x100290a8)
- WaitForSingleObjectEx (Address: 0x100290f0)
- WideCharToMultiByte (Address: 0x1002908c)
- WriteConsoleW (Address: 0x1002918c)
- WriteFile (Address: 0x10029188)