MXDWDRV.DLL

Description: Microsoft XPS Document Writer

Authors: © Microsoft Corporation. All rights reserved.

Version: 0.3.19041.6456

Architecture: 64-bit

Operating System: Windows NT

SHA256: 7c9aecdfb3b531201777a1042d095e1e

File Size: 813.5 KB

Uploaded At: Dec. 1, 2025, 7:48 a.m.

Views: 5

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllMain (Ordinal: 1, Address: 0x2670)
  • DrvDisableDriver (Ordinal: 2, Address: 0x2c60)
  • DrvEnableDriver (Ordinal: 3, Address: 0x2da0)
  • DrvQueryDriverInfo (Ordinal: 4, Address: 0x2a50)

Imported DLLs & Functions

ADVAPI32.dll
  • GetTraceEnableFlags (Address: 0x180096908)
  • GetTraceEnableLevel (Address: 0x180096910)
  • GetTraceLoggerHandle (Address: 0x180096918)
  • RegCloseKey (Address: 0x180096950)
  • RegisterTraceGuidsW (Address: 0x180096938)
  • RegOpenKeyExW (Address: 0x180096940)
  • RegQueryValueExW (Address: 0x180096948)
  • TraceEvent (Address: 0x180096930)
  • TraceMessage (Address: 0x180096920)
  • UnregisterTraceGuids (Address: 0x180096928)
DWrite.dll
  • DWriteCreateFactory (Address: 0x180096960)
GDI32.dll
  • BRUSHOBJ_pvAllocRbrush (Address: 0x1800969b0)
  • BRUSHOBJ_pvGetRbrush (Address: 0x180096990)
  • CLIPOBJ_ppoGetPath (Address: 0x1800969d0)
  • EngAlphaBlend (Address: 0x180096a80)
  • EngAssociateSurface (Address: 0x180096a40)
  • EngBitBlt (Address: 0x180096a58)
  • EngCopyBits (Address: 0x180096a50)
  • EngCreateBitmap (Address: 0x180096a78)
  • EngCreateDeviceSurface (Address: 0x180096aa0)
  • EngCreatePalette (Address: 0x180096a88)
  • EngDeletePalette (Address: 0x180096a90)
  • EngDeletePath (Address: 0x1800969d8)
  • EngDeleteSurface (Address: 0x180096a98)
  • EngEraseSurface (Address: 0x180096998)
  • EngFillPath (Address: 0x180096a00)
  • EngGradientFill (Address: 0x1800969f0)
  • EngLockSurface (Address: 0x180096a30)
  • EngMarkBandingSurface (Address: 0x180096a38)
  • EngPlgBlt (Address: 0x180096a68)
  • EngStretchBlt (Address: 0x180096a28)
  • EngStretchBltROP (Address: 0x180096a60)
  • EngStrokeAndFillPath (Address: 0x1800969f8)
  • EngStrokePath (Address: 0x180096a08)
  • EngTextOut (Address: 0x1800969b8)
  • EngTransparentBlt (Address: 0x180096a70)
  • EngUnlockSurface (Address: 0x180096a10)
  • FONTOBJ_cGetGlyphs (Address: 0x180096988)
  • FONTOBJ_pifi (Address: 0x1800969e8)
  • FONTOBJ_pQueryGlyphAttrs (Address: 0x1800969e0)
  • FONTOBJ_pvTrueTypeFontFile (Address: 0x180096970)
  • FONTOBJ_pxoGetXform (Address: 0x180096978)
  • PATHOBJ_bEnum (Address: 0x1800969a8)
  • PATHOBJ_vEnumStart (Address: 0x1800969a0)
  • STROBJ_bEnum (Address: 0x180096a48)
  • STROBJ_vEnumStart (Address: 0x1800969c8)
  • XFORMOBJ_bApplyXform (Address: 0x1800969c0)
  • XFORMOBJ_iGetXform (Address: 0x180096980)
  • XLATEOBJ_cGetPalette (Address: 0x180096a18)
  • XLATEOBJ_piVector (Address: 0x180096a20)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x180096d28)
  • AcquireSRWLockShared (Address: 0x180096d18)
  • CloseHandle (Address: 0x180096b18)
  • CloseThreadpoolTimer (Address: 0x180096ce8)
  • CompareStringW (Address: 0x180096b00)
  • CreateEventW (Address: 0x180096c20)
  • CreateFileMappingW (Address: 0x180096c90)
  • CreateFileW (Address: 0x180096bf8)
  • CreateHardLinkW (Address: 0x180096c80)
  • CreateMutexExW (Address: 0x180096ca8)
  • CreateSemaphoreExW (Address: 0x180096ca0)
  • CreateThreadpoolTimer (Address: 0x180096cc0)
  • DebugBreak (Address: 0x180096d40)
  • DecodePointer (Address: 0x180096be0)
  • DeleteCriticalSection (Address: 0x180096c08)
  • DeleteFileW (Address: 0x180096cb8)
  • DisableThreadLibraryCalls (Address: 0x180096b60)
  • EncodePointer (Address: 0x180096bd8)
  • EnterCriticalSection (Address: 0x180096b48)
  • FindClose (Address: 0x180096c30)
  • FindFirstFileW (Address: 0x180096c48)
  • FindNextFileW (Address: 0x180096c40)
  • FormatMessageA (Address: 0x180096b68)
  • FormatMessageW (Address: 0x180096d70)
  • FreeLibrary (Address: 0x180096b88)
  • GetCurrentProcess (Address: 0x180096af0)
  • GetCurrentProcessId (Address: 0x180096ac0)
  • GetCurrentThreadId (Address: 0x180096ac8)
  • GetFileSize (Address: 0x180096c68)
  • GetLastError (Address: 0x180096b78)
  • GetModuleFileNameA (Address: 0x180096d48)
  • GetModuleFileNameW (Address: 0x180096b28)
  • GetModuleHandleExW (Address: 0x180096b30)
  • GetModuleHandleW (Address: 0x180096b98)
  • GetProcAddress (Address: 0x180096ba0)
  • GetProcessHeap (Address: 0x180096d58)
  • GetStringTypeW (Address: 0x180096bd0)
  • GetSystemDirectoryW (Address: 0x180096d78)
  • GetSystemInfo (Address: 0x180096c98)
  • GetSystemTimeAsFileTime (Address: 0x180096ad0)
  • GetTempFileNameW (Address: 0x180096c58)
  • GetTempPathW (Address: 0x180096c50)
  • GetTickCount (Address: 0x180096ad8)
  • GetVersionExW (Address: 0x180096ba8)
  • GlobalLock (Address: 0x180096cd0)
  • GlobalUnlock (Address: 0x180096b20)
  • HeapAlloc (Address: 0x180096d68)
  • HeapFree (Address: 0x180096d50)
  • InitializeCriticalSection (Address: 0x180096c10)
  • InitializeCriticalSectionEx (Address: 0x180096cd8)
  • IsDebuggerPresent (Address: 0x180096d38)
  • LeaveCriticalSection (Address: 0x180096c18)
  • LoadLibraryExA (Address: 0x180096bb8)
  • LoadLibraryExW (Address: 0x180096b90)
  • LoadLibraryW (Address: 0x180096b08)
  • LocalAlloc (Address: 0x180096c00)
  • LocalFree (Address: 0x180096b70)
  • MapViewOfFile (Address: 0x180096c88)
  • MulDiv (Address: 0x180096b38)
  • MultiByteToWideChar (Address: 0x180096cb0)
  • OpenProcess (Address: 0x180096d60)
  • OpenSemaphoreW (Address: 0x180096cc8)
  • OutputDebugStringW (Address: 0x180096d30)
  • QueryFullProcessImageNameW (Address: 0x180096d80)
  • QueryPerformanceCounter (Address: 0x180096ab8)
  • RaiseException (Address: 0x180096bc0)
  • ReadFile (Address: 0x180096c70)
  • ReleaseMutex (Address: 0x180096d00)
  • ReleaseSemaphore (Address: 0x180096d08)
  • ReleaseSRWLockExclusive (Address: 0x180096d20)
  • ReleaseSRWLockShared (Address: 0x180096d10)
  • RemoveDirectoryW (Address: 0x180096c38)
  • SetEvent (Address: 0x180096b40)
  • SetFilePointer (Address: 0x180096c78)
  • SetLastError (Address: 0x180096b58)
  • SetThreadpoolTimer (Address: 0x180096cf8)
  • SetUnhandledExceptionFilter (Address: 0x180096ae8)
  • Sleep (Address: 0x180096ab0)
  • SleepConditionVariableSRW (Address: 0x180096bf0)
  • TerminateProcess (Address: 0x180096af8)
  • UnhandledExceptionFilter (Address: 0x180096ae0)
  • UnmapViewOfFile (Address: 0x180096b10)
  • VerifyVersionInfoW (Address: 0x180096b80)
  • VirtualProtect (Address: 0x180096bb0)
  • VirtualQuery (Address: 0x180096bc8)
  • WaitForSingleObject (Address: 0x180096b50)
  • WaitForSingleObjectEx (Address: 0x180096ce0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180096cf0)
  • WakeAllConditionVariable (Address: 0x180096be8)
  • WideCharToMultiByte (Address: 0x180096c28)
  • WriteFile (Address: 0x180096c60)
msvcrt.dll
  • ___lc_codepage_func (Address: 0x180096ef0)
  • ___lc_handle_func (Address: 0x180096ef8)
  • ___mb_cur_max_func (Address: 0x180096ed0)
  • __C_specific_handler (Address: 0x180097060)
  • __crtLCMapStringA (Address: 0x1800970e8)
  • __crtLCMapStringW (Address: 0x180096fd8)
  • __CxxFrameHandler3 (Address: 0x180097138)
  • __dllonexit (Address: 0x180097038)
  • __pctype_func (Address: 0x180096f08)
  • __RTDynamicCast (Address: 0x180097008)
  • __uncaught_exception (Address: 0x180097130)
  • _amsg_exit (Address: 0x180097070)
  • _beginthreadex (Address: 0x1800970c0)
  • _callnewh (Address: 0x1800970b0)
  • _CxxThrowException (Address: 0x1800970a0)
  • _errno (Address: 0x180096ed8)
  • _finite (Address: 0x180096f78)
  • _fseeki64 (Address: 0x180096f48)
  • _initterm (Address: 0x180097068)
  • _ismbblead (Address: 0x180096ec8)
  • _lock (Address: 0x180097050)
  • _onexit (Address: 0x180097030)
  • _purecall (Address: 0x180097128)
  • _stricmp (Address: 0x1800970b8)
  • _unlock (Address: 0x180097040)
  • _vsnprintf (Address: 0x180097120)
  • _vsnprintf_s (Address: 0x180096fc0)
  • _vsnwprintf (Address: 0x180096fd0)
  • _wcsdup (Address: 0x180096f18)
  • _wcsicmp (Address: 0x1800970d0)
  • _wsetlocale (Address: 0x180097088)
  • _XcptFilter (Address: 0x180097078)
  • ??0bad_cast@@QEAA@AEBV0@@Z (Address: 0x180096fa8)
  • ??0bad_cast@@QEAA@PEBD@Z (Address: 0x180096f98)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180097098)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800970a8)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180097100)
  • ??0exception@@QEAA@XZ (Address: 0x180097108)
  • ??1bad_cast@@UEAA@XZ (Address: 0x180096fa0)
  • ??1exception@@UEAA@XZ (Address: 0x180097110)
  • ??1type_info@@UEAA@XZ (Address: 0x180097028)
  • ?terminate@@YAXXZ (Address: 0x180097058)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180097118)
  • abort (Address: 0x180096ec0)
  • calloc (Address: 0x180096ee8)
  • ceil (Address: 0x180097010)
  • ceilf (Address: 0x180097018)
  • fclose (Address: 0x180096f70)
  • fflush (Address: 0x180096f60)
  • fgetc (Address: 0x180096f30)
  • fgetpos (Address: 0x180096f50)
  • fputc (Address: 0x180096f68)
  • free (Address: 0x1800970f8)
  • fsetpos (Address: 0x180096f40)
  • fwrite (Address: 0x1800970e0)
  • isalnum (Address: 0x180096fe8)
  • isdigit (Address: 0x180096fe0)
  • islower (Address: 0x180096ee0)
  • isspace (Address: 0x180097048)
  • isupper (Address: 0x180096f00)
  • ldexp (Address: 0x180096eb8)
  • localeconv (Address: 0x180096f88)
  • malloc (Address: 0x1800970d8)
  • memchr (Address: 0x180096ff8)
  • memcmp (Address: 0x180096ff0)
  • memcpy (Address: 0x180097090)
  • memcpy_s (Address: 0x180096fc8)
  • memmove (Address: 0x180097080)
  • memmove_s (Address: 0x180096fb8)
  • memset (Address: 0x180096eb0)
  • realloc (Address: 0x180096fb0)
  • setlocale (Address: 0x180096f10)
  • setvbuf (Address: 0x180096f58)
  • sprintf_s (Address: 0x180096f90)
  • sqrtf (Address: 0x180097020)
  • strcmp (Address: 0x180097140)
  • strcpy_s (Address: 0x180096f28)
  • strcspn (Address: 0x180096f80)
  • tolower (Address: 0x180097000)
  • ungetc (Address: 0x180096f38)
  • wcscpy_s (Address: 0x1800970f0)
  • wcsrchr (Address: 0x1800970c8)
  • wcsstr (Address: 0x180096f20)
ntdll.dll
  • RtlCaptureContext (Address: 0x180097168)
  • RtlLookupFunctionEntry (Address: 0x180097158)
  • RtlVirtualUnwind (Address: 0x180097160)
  • VerSetConditionMask (Address: 0x180097150)
ole32.dll
  • CoCreateGuid (Address: 0x180097180)
  • CoCreateInstance (Address: 0x180097178)
  • CoInitializeEx (Address: 0x180097198)
  • CoTaskMemFree (Address: 0x1800971b0)
  • CoUninitialize (Address: 0x180097190)
  • CreateStreamOnHGlobal (Address: 0x1800971a8)
  • GetHGlobalFromStream (Address: 0x180097188)
  • StringFromGUID2 (Address: 0x1800971a0)
OLEAUT32.dll
  • GetErrorInfo (Address: 0x180096da0)
  • SetErrorInfo (Address: 0x180096db8)
  • SysAllocString (Address: 0x180096dc0)
  • SysAllocStringLen (Address: 0x180096db0)
  • SysFreeString (Address: 0x180096d90)
  • SysStringLen (Address: 0x180096da8)
  • VariantClear (Address: 0x180096dc8)
  • VariantInit (Address: 0x180096d98)
USER32.dll
  • CopyRect (Address: 0x180096de0)
  • EqualRect (Address: 0x180096df0)
  • InflateRect (Address: 0x180096e10)
  • IntersectRect (Address: 0x180096dd8)
  • IsRectEmpty (Address: 0x180096e08)
  • OffsetRect (Address: 0x180096e00)
  • SetRectEmpty (Address: 0x180096de8)
  • UnionRect (Address: 0x180096df8)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x180096e30)
  • GetFileVersionInfoW (Address: 0x180096e28)
  • VerQueryValueW (Address: 0x180096e20)
WINSPOOL.DRV
  • AbortPrinter (Address: 0x180096e78)
  • DocumentPropertiesW (Address: 0x180096e50)
  • EndPagePrinter (Address: 0x180096e88)
  • EnumFormsW (Address: 0x180096e60)
  • GetJobW (Address: 0x180096e40)
  • GetPrinterDataW (Address: 0x180096e70)
  • GetPrinterDriverW (Address: 0x180096e48)
  • GetPrinterW (Address: 0x180096e58)
  • SetJobW (Address: 0x180096e90)
  • StartPagePrinter (Address: 0x180096e80)
  • WritePrinter (Address: 0x180096e68)
XmlLite.dll
  • CreateXmlReader (Address: 0x180096ea0)