WindowManagement.dll
Description: Window Management
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 136f3f7049d148ecb02acb982b59d5af
File Size: 1.6 MB
Uploaded At: Dec. 1, 2025, 7:43 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllGetActivationFactory (Ordinal: 1, Address: 0x4e9d0)
- DllGetClassObject (Ordinal: 2, Address: 0x51520)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-l1-1-1.dll
- FindPackagesByPackageFamily (Address: 0x180148da8)
- GetApplicationUserModelIdFromToken (Address: 0x180148d98)
- ParseApplicationUserModelId (Address: 0x180148da0)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x180148db8)
api-ms-win-core-com-l1-1-0.dll
- CoCreateFreeThreadedMarshaler (Address: 0x180148e38)
- CoCreateInstance (Address: 0x180148e28)
- CoDecrementMTAUsage (Address: 0x180148e10)
- CoGetApartmentType (Address: 0x180148df8)
- CoGetCallContext (Address: 0x180148e40)
- CoGetInterfaceAndReleaseStream (Address: 0x180148e48)
- CoGetMalloc (Address: 0x180148e18)
- CoImpersonateClient (Address: 0x180148de8)
- CoIncrementMTAUsage (Address: 0x180148e08)
- CoMarshalInterface (Address: 0x180148de0)
- CoReleaseMarshalData (Address: 0x180148df0)
- CoRevertToSelf (Address: 0x180148dc8)
- CoTaskMemAlloc (Address: 0x180148dd8)
- CoTaskMemFree (Address: 0x180148e30)
- CoTaskMemRealloc (Address: 0x180148e00)
- CoWaitForMultipleHandles (Address: 0x180148dd0)
- CreateStreamOnHGlobal (Address: 0x180148e20)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x180148e58)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x180148e70)
- IsDebuggerPresent (Address: 0x180148e68)
- OutputDebugStringW (Address: 0x180148e78)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180148e88)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180148e98)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180148eb0)
- RaiseException (Address: 0x180148ec8)
- SetLastError (Address: 0x180148ea8)
- SetUnhandledExceptionFilter (Address: 0x180148eb8)
- UnhandledExceptionFilter (Address: 0x180148ec0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180148ee0)
- DuplicateHandle (Address: 0x180148ed8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x180148ef0)
- HeapAlloc (Address: 0x180148ef8)
- HeapFree (Address: 0x180148f00)
api-ms-win-core-heap-l2-1-0.dll
- LocalFree (Address: 0x180148f10)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x180148f20)
api-ms-win-core-libraryloader-l1-2-0.dll
- FreeLibrary (Address: 0x180148f48)
- GetModuleFileNameA (Address: 0x180148f50)
- GetModuleHandleExW (Address: 0x180148f38)
- GetModuleHandleW (Address: 0x180148f40)
- GetProcAddress (Address: 0x180148f30)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x180148f60)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x180148f90)
- GetCurrentProcess (Address: 0x180148fa0)
- GetCurrentProcessId (Address: 0x180148f98)
- GetCurrentThread (Address: 0x180148f80)
- GetCurrentThreadId (Address: 0x180148fa8)
- OpenProcessToken (Address: 0x180148f70)
- OpenThreadToken (Address: 0x180148f88)
- TerminateProcess (Address: 0x180148f78)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x180148fb8)
- OpenProcess (Address: 0x180148fc0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x180148fd0)
api-ms-win-core-psm-key-l1-1-0.dll
- PsmGetKeyFromToken (Address: 0x180148fe0)
api-ms-win-core-quirks-l1-1-0.dll
- QuirkIsEnabledForPackage (Address: 0x180148ff0)
api-ms-win-core-registry-l1-1-0.dll
- RegGetValueW (Address: 0x180149000)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x180149010)
- RtlLookupFunctionEntry (Address: 0x180149018)
- RtlVirtualUnwind (Address: 0x180149020)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x180149030)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1801490a0)
- AcquireSRWLockShared (Address: 0x1801490c0)
- CreateEventExW (Address: 0x180149050)
- CreateEventW (Address: 0x180149070)
- CreateMutexExW (Address: 0x180149090)
- CreateSemaphoreExW (Address: 0x180149048)
- DeleteCriticalSection (Address: 0x1801490d8)
- EnterCriticalSection (Address: 0x1801490d0)
- InitializeCriticalSection (Address: 0x180149088)
- InitializeCriticalSectionAndSpinCount (Address: 0x1801490a8)
- InitializeCriticalSectionEx (Address: 0x1801490e0)
- InitializeSRWLock (Address: 0x1801490e8)
- LeaveCriticalSection (Address: 0x1801490c8)
- OpenSemaphoreW (Address: 0x180149080)
- ReleaseMutex (Address: 0x180149068)
- ReleaseSemaphore (Address: 0x180149058)
- ReleaseSRWLockExclusive (Address: 0x180149098)
- ReleaseSRWLockShared (Address: 0x1801490b8)
- ResetEvent (Address: 0x180149040)
- SetEvent (Address: 0x1801490b0)
- WaitForSingleObject (Address: 0x180149060)
- WaitForSingleObjectEx (Address: 0x180149078)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x180149110)
- InitOnceComplete (Address: 0x180149108)
- InitOnceExecuteOnce (Address: 0x180149118)
- Sleep (Address: 0x180149120)
- WaitOnAddress (Address: 0x1801490f8)
- WakeByAddressAll (Address: 0x180149100)
api-ms-win-core-synch-l1-2-1.dll
- WaitForMultipleObjects (Address: 0x180149130)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x180149148)
- GetTickCount64 (Address: 0x180149140)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x180149170)
- CloseThreadpoolWork (Address: 0x180149158)
- CreateThreadpoolTimer (Address: 0x180149178)
- CreateThreadpoolWork (Address: 0x180149180)
- FreeLibraryWhenCallbackReturns (Address: 0x180149160)
- SetThreadpoolTimer (Address: 0x180149168)
- SubmitThreadpoolWork (Address: 0x180149188)
- WaitForThreadpoolTimerCallbacks (Address: 0x180149190)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1801491a0)
- EncodePointer (Address: 0x1801491a8)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x1801491c0)
- RoOriginateError (Address: 0x1801491d8)
- RoOriginateErrorW (Address: 0x1801491d0)
- RoTransformError (Address: 0x1801491b8)
- SetRestrictedErrorInfo (Address: 0x1801491c8)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x1801491f0)
- RoGetMatchingRestrictedErrorInfo (Address: 0x1801491f8)
- RoReportFailedDelegate (Address: 0x1801491e8)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x180149228)
- RoGetActivationFactory (Address: 0x180149218)
- RoInitialize (Address: 0x180149220)
- RoRegisterActivationFactories (Address: 0x180149208)
- RoUninitialize (Address: 0x180149210)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsCompareStringOrdinal (Address: 0x180149280)
- WindowsCreateString (Address: 0x180149238)
- WindowsCreateStringReference (Address: 0x180149260)
- WindowsDeleteString (Address: 0x180149268)
- WindowsDuplicateString (Address: 0x180149270)
- WindowsGetStringLen (Address: 0x180149248)
- WindowsGetStringRawBuffer (Address: 0x180149240)
- WindowsIsStringEmpty (Address: 0x180149278)
- WindowsStringHasEmbeddedNull (Address: 0x180149258)
- WindowsTrimStringStart (Address: 0x180149250)
api-ms-win-crt-math-l1-1-0.dll
- ceilf (Address: 0x180149290)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x180149318)
- __CxxFrameHandler3 (Address: 0x180149320)
- __CxxFrameHandler4 (Address: 0x180149398)
- __std_terminate (Address: 0x180149388)
- _CxxThrowException (Address: 0x180149330)
- _o___std_exception_copy (Address: 0x180149378)
- _o___std_exception_destroy (Address: 0x180149370)
- _o___std_type_info_destroy_list (Address: 0x180149368)
- _o___stdio_common_vsnprintf_s (Address: 0x180149360)
- _o___stdio_common_vswprintf (Address: 0x180149348)
- _o__callnewh (Address: 0x180149340)
- _o__cexit (Address: 0x180149338)
- _o__configure_narrow_argv (Address: 0x180149328)
- _o__crt_atexit (Address: 0x180149390)
- _o__errno (Address: 0x180149358)
- _o__execute_onexit_table (Address: 0x180149350)
- _o__initialize_narrow_environment (Address: 0x1801492a0)
- _o__initialize_onexit_table (Address: 0x1801492a8)
- _o__invalid_parameter_noinfo (Address: 0x1801492b0)
- _o__invalid_parameter_noinfo_noreturn (Address: 0x1801492b8)
- _o__purecall (Address: 0x1801492c0)
- _o__register_onexit_function (Address: 0x1801492c8)
- _o__seh_filter_dll (Address: 0x1801492d0)
- _o__wcsicmp (Address: 0x1801492d8)
- _o__wtoi (Address: 0x1801492e8)
- _o_free (Address: 0x1801492f0)
- _o_malloc (Address: 0x1801492f8)
- _o_realloc (Address: 0x180149300)
- _o_terminate (Address: 0x180149308)
- _o_wcstoull (Address: 0x180149310)
- memcmp (Address: 0x1801493a0)
- memcpy (Address: 0x1801493a8)
- memmove (Address: 0x1801492e0)
- wcschr (Address: 0x180149380)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x1801493b8)
- _initterm_e (Address: 0x1801493c0)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x1801493d0)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x1801493f8)
- EventSetInformation (Address: 0x1801493e8)
- EventUnregister (Address: 0x1801493e0)
- EventWriteTransfer (Address: 0x1801493f0)
api-ms-win-ntuser-sysparams-l1-1-0.dll
- EnumDisplayDevicesW (Address: 0x180149410)
- EnumDisplayMonitors (Address: 0x180149418)
- GetMonitorInfoW (Address: 0x180149408)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
- GetClassNameW (Address: 0x180149428)
- GetWindowLongW (Address: 0x180149430)
api-ms-win-security-base-l1-1-0.dll
- AllocateLocallyUniqueId (Address: 0x180149450)
- DuplicateTokenEx (Address: 0x180149440)
- GetTokenInformation (Address: 0x180149448)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x180149460)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180149470)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolAllowThreadReuse (Address: 0x180149490)
- SHTaskPoolGetUniqueContext (Address: 0x180149488)
- SHTaskPoolQueueTask (Address: 0x180149480)
api-ms-win-shcore-thread-l1-1-0.dll
- SHCreateThread (Address: 0x1801494a0)
CoreMessaging.dll
- CoreUICallCreateConversationHost (Address: 0x180148d10)
- CoreUICallReceive (Address: 0x180148d18)
- CoreUICallSend (Address: 0x180148d08)
- CoreUICreate (Address: 0x180148d28)
- MsgBlobCreateShared (Address: 0x180148cf8)
- MsgRelease (Address: 0x180148d00)
- MsgStringCreateShared (Address: 0x180148d20)
CoreUIComponents.dll
- CoreUIFactoryCreate (Address: 0x180148d38)
msvcp_win.dll
- _Mtx_destroy_in_situ (Address: 0x180149618)
- _Mtx_init_in_situ (Address: 0x180149610)
- _Mtx_lock (Address: 0x180149628)
- _Mtx_unlock (Address: 0x180149620)
- ?_Lock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x1801494e0)
- ?_Osfx@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAXXZ (Address: 0x1801495e0)
- ?_Pninc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAPEAGXZ (Address: 0x1801495b8)
- ?_Throw_C_error@std@@YAXH@Z (Address: 0x180149608)
- ?_Unlock@?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAAXXZ (Address: 0x1801494f8)
- ?_Xbad_function_call@std@@YAXXZ (Address: 0x1801495d0)
- ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x180149538)
- ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180149600)
- ??0?$basic_ios@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x1801494b0)
- ??0?$basic_iostream@GU?$char_traits@G@std@@@std@@QEAA@PEAV?$basic_streambuf@GU?$char_traits@G@std@@@1@@Z (Address: 0x180149598)
- ??0?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAA@XZ (Address: 0x180149558)
- ??1?$basic_ios@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x1801495f8)
- ??1?$basic_iostream@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x1801495f0)
- ??1?$basic_streambuf@GU?$char_traits@G@std@@@std@@UEAA@XZ (Address: 0x180149590)
- ??6?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV01@I@Z (Address: 0x180149520)
- ?eback@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x1801494c0)
- ?egptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x1801494c8)
- ?epptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x1801494d8)
- ?fill@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAGXZ (Address: 0x1801494b8)
- ?flags@ios_base@std@@QEBAHXZ (Address: 0x180149508)
- ?flush@?$basic_ostream@GU?$char_traits@G@std@@@std@@QEAAAEAV12@XZ (Address: 0x180149570)
- ?gbump@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXH@Z (Address: 0x1801495c0)
- ?good@ios_base@std@@QEBA_NXZ (Address: 0x180149588)
- ?gptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x1801495d8)
- ?imbue@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAXAEBVlocale@2@@Z (Address: 0x180149548)
- ?pbase@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x180149510)
- ?pptr@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEBAPEAGXZ (Address: 0x1801495c8)
- ?rdbuf@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAPEAV?$basic_streambuf@GU?$char_traits@G@std@@@2@XZ (Address: 0x180149560)
- ?setbuf@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAPEAV12@PEAG_J@Z (Address: 0x180149530)
- ?setg@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXPEAG00@Z (Address: 0x1801494d0)
- ?setp@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXPEAG0@Z (Address: 0x180149578)
- ?setp@?$basic_streambuf@GU?$char_traits@G@std@@@std@@IEAAXPEAG00@Z (Address: 0x1801494e8)
- ?setstate@?$basic_ios@GU?$char_traits@G@std@@@std@@QEAAXH_N@Z (Address: 0x180149568)
- ?showmanyc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JXZ (Address: 0x1801495b0)
- ?sputc@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAAGG@Z (Address: 0x180149518)
- ?sputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@QEAA_JPEBG_J@Z (Address: 0x1801495e8)
- ?sync@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAHXZ (Address: 0x180149550)
- ?tie@?$basic_ios@GU?$char_traits@G@std@@@std@@QEBAPEAV?$basic_ostream@GU?$char_traits@G@std@@@2@XZ (Address: 0x180149580)
- ?uflow@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAAGXZ (Address: 0x1801495a8)
- ?uncaught_exception@std@@YA_NXZ (Address: 0x180149500)
- ?width@ios_base@std@@QEAA_J_J@Z (Address: 0x180149540)
- ?width@ios_base@std@@QEBA_JXZ (Address: 0x1801495a0)
- ?xsgetn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEAG_J@Z (Address: 0x180149528)
- ?xsputn@?$basic_streambuf@GU?$char_traits@G@std@@@std@@MEAA_JPEBG_J@Z (Address: 0x1801494f0)
ntdll.dll
- NtClose (Address: 0x180149640)
- NtOpenProcessToken (Address: 0x180149658)
- NtQueryInformationToken (Address: 0x1801496c8)
- RtlAcquireSRWLockExclusive (Address: 0x180149670)
- RtlAcquireSRWLockShared (Address: 0x180149660)
- RtlAllocateHeap (Address: 0x1801496a8)
- RtlCompareUnicodeString (Address: 0x180149698)
- RtlCopySid (Address: 0x180149638)
- RtlFreeHeap (Address: 0x1801496b8)
- RtlGetDeviceFamilyInfoEnum (Address: 0x180149690)
- RtlInitUnicodeString (Address: 0x1801496b0)
- RtlIsMultiSessionSku (Address: 0x180149688)
- RtlLengthSid (Address: 0x180149648)
- RtlNtStatusToDosError (Address: 0x180149680)
- RtlNtStatusToDosErrorNoTeb (Address: 0x1801496a0)
- RtlQueryTokenHostIdAsUlong64 (Address: 0x180149650)
- RtlReleaseSRWLockExclusive (Address: 0x1801496c0)
- RtlSleepConditionVariableSRW (Address: 0x180149668)
- RtlWakeAllConditionVariable (Address: 0x180149678)
RMCLIENT.dll
- HamCloseActivity (Address: 0x180148d68)
- HamConnectToServer (Address: 0x180148d70)
- HamCreateActivity (Address: 0x180148d78)
- HamCreateActivityForProcess (Address: 0x180148d50)
- HamDisconnectFromServer (Address: 0x180148d60)
- HamPopulateActivityPropertiesByClass (Address: 0x180148d58)
- HamStartActivityAsync (Address: 0x180148d48)
RPCRT4.dll
- I_RpcBindingInqLocalClientPID (Address: 0x180148d88)
twinapi.appcore.dll
- (Address: 0x1801496d8)