DXToolsMonitor.dll

Description: DirectX Tools Monitor

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.4355

Architecture: 32-bit

Operating System: Windows NT

SHA256: 0f66c3c5cf0d84c5359380648b65ecc6

File Size: 134.0 KB

Uploaded At: Dec. 1, 2025, 7:55 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory, OpenProcess

Exported Functions

  • CLSID_DXDefaultPlatformStorage (Ordinal: 1, Address: 0x1e304)
  • CLSID_DXToolsStockExperiment_FullCapture (Ordinal: 2, Address: 0x1e314)
  • CLSID_DXToolsStockExperiment_FullPlayback (Ordinal: 3, Address: 0x1e2f4)
  • CLSID_DXToolsStockExperiment_Overdraw (Ordinal: 4, Address: 0x1e2d4)
  • CLSID_DXToolsStockExperiment_Recapture (Ordinal: 5, Address: 0x1e2e4)
  • CreateWin8Injector (Ordinal: 6, Address: 0xa220)
  • CreateSerializationController (Ordinal: 7, Address: 0xe8a0)

Imported DLLs & Functions

api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1001f00c)
  • IsDebuggerPresent (Address: 0x1001f014)
  • OutputDebugStringA (Address: 0x1001f008)
  • OutputDebugStringW (Address: 0x1001f010)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1001f01c)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1001f024)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1001f034)
  • RaiseException (Address: 0x1001f030)
  • SetLastError (Address: 0x1001f038)
  • SetUnhandledExceptionFilter (Address: 0x1001f03c)
  • UnhandledExceptionFilter (Address: 0x1001f02c)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x1001f044)
  • FindClose (Address: 0x1001f048)
  • FindFirstFileW (Address: 0x1001f054)
  • GetFileSizeEx (Address: 0x1001f058)
  • ReadFile (Address: 0x1001f050)
  • SetFilePointerEx (Address: 0x1001f05c)
  • WriteFile (Address: 0x1001f04c)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1001f064)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x1001f074)
  • HeapAlloc (Address: 0x1001f070)
  • HeapFree (Address: 0x1001f06c)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • LocalAlloc (Address: 0x1001f07c)
  • LocalFree (Address: 0x1001f080)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x1001f090)
  • InterlockedFlushSList (Address: 0x1001f08c)
  • InterlockedPushEntrySList (Address: 0x1001f088)
api-ms-win-core-io-l1-1-1.dll
  • CancelSynchronousIo (Address: 0x1001f098)
api-ms-win-core-job-l2-1-0.dll
  • AssignProcessToJobObject (Address: 0x1001f0a8)
  • CreateJobObjectW (Address: 0x1001f0a4)
  • QueryInformationJobObject (Address: 0x1001f0a0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • CreateSemaphoreW (Address: 0x1001f0b0)
  • LoadLibraryW (Address: 0x1001f0b4)
api-ms-win-core-libraryloader-l1-2-0.dll
  • FreeLibrary (Address: 0x1001f0bc)
  • GetModuleFileNameA (Address: 0x1001f0c8)
  • GetModuleFileNameW (Address: 0x1001f0d0)
  • GetModuleHandleExW (Address: 0x1001f0c0)
  • GetModuleHandleW (Address: 0x1001f0d4)
  • GetProcAddress (Address: 0x1001f0cc)
  • LoadLibraryExW (Address: 0x1001f0c4)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageA (Address: 0x1001f0dc)
  • FormatMessageW (Address: 0x1001f0e0)
  • LCMapStringEx (Address: 0x1001f0e4)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x1001f100)
  • MapViewOfFile (Address: 0x1001f104)
  • OpenFileMappingW (Address: 0x1001f0f0)
  • ReadProcessMemory (Address: 0x1001f0f4)
  • UnmapViewOfFile (Address: 0x1001f0ec)
  • VirtualAlloc (Address: 0x1001f0fc)
  • VirtualFree (Address: 0x1001f0f8)
  • WriteProcessMemory (Address: 0x1001f108)
api-ms-win-core-namedpipe-l1-1-0.dll
  • ConnectNamedPipe (Address: 0x1001f114)
  • CreateNamedPipeW (Address: 0x1001f11c)
  • DisconnectNamedPipe (Address: 0x1001f118)
  • WaitNamedPipeW (Address: 0x1001f110)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x1001f134)
  • CreateThread (Address: 0x1001f124)
  • GetCurrentProcess (Address: 0x1001f144)
  • GetCurrentProcessId (Address: 0x1001f12c)
  • GetCurrentThreadId (Address: 0x1001f138)
  • GetExitCodeProcess (Address: 0x1001f130)
  • ProcessIdToSessionId (Address: 0x1001f128)
  • ResumeThread (Address: 0x1001f140)
  • TerminateProcess (Address: 0x1001f13c)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x1001f150)
  • OpenProcess (Address: 0x1001f14c)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x1001f158)
api-ms-win-core-registry-l2-1-0.dll
  • RegCreateKeyW (Address: 0x1001f160)
api-ms-win-core-string-l1-1-0.dll
  • GetStringTypeW (Address: 0x1001f170)
  • MultiByteToWideChar (Address: 0x1001f16c)
  • WideCharToMultiByte (Address: 0x1001f168)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1001f198)
  • AcquireSRWLockShared (Address: 0x1001f190)
  • CreateEventW (Address: 0x1001f1ac)
  • CreateMutexExW (Address: 0x1001f1c4)
  • CreateMutexW (Address: 0x1001f1b4)
  • CreateSemaphoreExW (Address: 0x1001f180)
  • DeleteCriticalSection (Address: 0x1001f17c)
  • EnterCriticalSection (Address: 0x1001f1bc)
  • InitializeCriticalSection (Address: 0x1001f188)
  • InitializeCriticalSectionEx (Address: 0x1001f178)
  • InitializeSRWLock (Address: 0x1001f1a0)
  • LeaveCriticalSection (Address: 0x1001f1b8)
  • OpenSemaphoreW (Address: 0x1001f1c0)
  • ReleaseMutex (Address: 0x1001f1a8)
  • ReleaseSemaphore (Address: 0x1001f184)
  • ReleaseSRWLockExclusive (Address: 0x1001f19c)
  • ReleaseSRWLockShared (Address: 0x1001f194)
  • SetEvent (Address: 0x1001f1a4)
  • WaitForSingleObject (Address: 0x1001f18c)
  • WaitForSingleObjectEx (Address: 0x1001f1b0)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x1001f1d0)
  • Sleep (Address: 0x1001f1cc)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x1001f1d8)
  • GetSystemInfo (Address: 0x1001f1e4)
  • GetSystemTimeAsFileTime (Address: 0x1001f1e0)
  • GlobalMemoryStatusEx (Address: 0x1001f1dc)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x1001f1ec)
  • EncodePointer (Address: 0x1001f1f0)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1001f1fc)
  • RoInitialize (Address: 0x1001f1f8)
  • RoUninitialize (Address: 0x1001f200)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateString (Address: 0x1001f214)
  • WindowsCreateStringReference (Address: 0x1001f210)
  • WindowsDeleteString (Address: 0x1001f20c)
  • WindowsGetStringRawBuffer (Address: 0x1001f208)
api-ms-win-crt-locale-l1-1-0.dll
  • _lock_locales (Address: 0x1001f220)
  • _unlock_locales (Address: 0x1001f21c)
api-ms-win-crt-private-l1-1-0.dll
  • __CxxFrameHandler3 (Address: 0x1001f2c4)
  • __uncaught_exception (Address: 0x1001f298)
  • _CxxThrowException (Address: 0x1001f294)
  • _except_handler4_common (Address: 0x1001f270)
  • _o____lc_codepage_func (Address: 0x1001f2c0)
  • _o____lc_locale_name_func (Address: 0x1001f2b8)
  • _o____mb_cur_max_func (Address: 0x1001f2b0)
  • _o___pctype_func (Address: 0x1001f290)
  • _o___std_exception_copy (Address: 0x1001f280)
  • _o___std_exception_destroy (Address: 0x1001f27c)
  • _o___std_type_info_destroy_list (Address: 0x1001f278)
  • _o___stdio_common_vfprintf (Address: 0x1001f274)
  • _o___stdio_common_vsnprintf_s (Address: 0x1001f2bc)
  • _o___stdio_common_vsnwprintf_s (Address: 0x1001f2b4)
  • _o___stdio_common_vsprintf (Address: 0x1001f2ac)
  • _o___stdio_common_vswprintf (Address: 0x1001f2a8)
  • _o__aligned_free (Address: 0x1001f2a4)
  • _o__aligned_malloc (Address: 0x1001f2a0)
  • _o__callnewh (Address: 0x1001f28c)
  • _o__calloc_base (Address: 0x1001f288)
  • _o__cexit (Address: 0x1001f250)
  • _o__configure_narrow_argv (Address: 0x1001f29c)
  • _o__crt_atexit (Address: 0x1001f284)
  • _o__errno (Address: 0x1001f228)
  • _o__execute_onexit_table (Address: 0x1001f22c)
  • _o__initialize_narrow_environment (Address: 0x1001f230)
  • _o__initialize_onexit_table (Address: 0x1001f234)
  • _o__invalid_parameter_noinfo (Address: 0x1001f238)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x1001f23c)
  • _o__purecall (Address: 0x1001f240)
  • _o__register_onexit_function (Address: 0x1001f244)
  • _o__seh_filter_dll (Address: 0x1001f248)
  • _o__wcsdup (Address: 0x1001f254)
  • _o_abort (Address: 0x1001f258)
  • _o_free (Address: 0x1001f25c)
  • _o_malloc (Address: 0x1001f260)
  • _o_setlocale (Address: 0x1001f264)
  • _o_terminate (Address: 0x1001f268)
  • _o_wcscat_s (Address: 0x1001f26c)
  • memcpy (Address: 0x1001f2c8)
  • memmove (Address: 0x1001f24c)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x1001f2d4)
  • _initterm_e (Address: 0x1001f2d0)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x1001f2dc)
  • wcsnlen (Address: 0x1001f2e0)
api-ms-win-downlevel-advapi32-l1-1-0.dll
  • AddMandatoryAce (Address: 0x1001f2e8)
  • AllocateAndInitializeSid (Address: 0x1001f2fc)
  • CopySid (Address: 0x1001f314)
  • FreeSid (Address: 0x1001f2f4)
  • GetLengthSid (Address: 0x1001f320)
  • GetTokenInformation (Address: 0x1001f324)
  • InitializeAcl (Address: 0x1001f2ec)
  • InitializeSecurityDescriptor (Address: 0x1001f2f0)
  • IsValidSid (Address: 0x1001f318)
  • OpenProcessToken (Address: 0x1001f31c)
  • RegCloseKey (Address: 0x1001f310)
  • RegGetValueW (Address: 0x1001f304)
  • RegOpenKeyExW (Address: 0x1001f308)
  • RegSetValueExW (Address: 0x1001f30c)
  • SetSecurityDescriptorDacl (Address: 0x1001f300)
  • SetSecurityDescriptorSacl (Address: 0x1001f2f8)
api-ms-win-downlevel-ole32-l1-1-0.dll
  • CoCreateInstance (Address: 0x1001f330)
  • CoInitializeEx (Address: 0x1001f32c)
api-ms-win-downlevel-shlwapi-l2-1-0.dll
  • SHCreateStreamOnFileW (Address: 0x1001f338)
api-ms-win-downlevel-version-l1-1-0.dll
  • GetFileVersionInfoExW (Address: 0x1001f348)
  • GetFileVersionInfoSizeExW (Address: 0x1001f340)
  • VerQueryValueW (Address: 0x1001f344)
api-ms-win-security-appcontainer-l1-1-0.dll
  • GetAppContainerNamedObjectPath (Address: 0x1001f350)
api-ms-win-security-provider-l1-1-0.dll
  • SetEntriesInAclW (Address: 0x1001f358)
ntdll.dll
  • NtQueryInformationProcess (Address: 0x1001f36c)
  • RtlConvertSidToUnicodeString (Address: 0x1001f360)
  • RtlFreeUnicodeString (Address: 0x1001f368)
  • RtlNtStatusToDosError (Address: 0x1001f364)
XmlLite.dll
  • CreateXmlReader (Address: 0x1001f000)