ExecModelClient.dll
Description: ExecModelClient
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 32-bit
Operating System: Windows NT
SHA256: 7d02f6705f4e7f8215eac37b9a6ec900
File Size: 284.6 KB
Uploaded At: Dec. 1, 2025, 7:56 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- CreateForegroundTaskManager (Ordinal: 1, Address: 0x14030)
- TestHook_CancelShutdown (Ordinal: 2, Address: 0x260c0)
- CreateModernVoipPolicy (Ordinal: 3, Address: 0x39700)
- DllCanUnloadNow (Ordinal: 4, Address: 0xce10)
- DllGetActivationFactory (Ordinal: 5, Address: 0x15500)
- DllGetClassObject (Ordinal: 6, Address: 0xc590)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x1003f038)
api-ms-win-core-com-l1-1-0.dll
- CLSIDFromString (Address: 0x1003f080)
- CoCreateFreeThreadedMarshaler (Address: 0x1003f040)
- CoCreateGuid (Address: 0x1003f084)
- CoCreateInstance (Address: 0x1003f058)
- CoGetApartmentType (Address: 0x1003f048)
- CoGetCallContext (Address: 0x1003f064)
- CoGetCallerTID (Address: 0x1003f06c)
- CoGetClassObject (Address: 0x1003f068)
- CoInitializeEx (Address: 0x1003f07c)
- CoMarshalInterface (Address: 0x1003f070)
- CoReleaseMarshalData (Address: 0x1003f078)
- CoTaskMemAlloc (Address: 0x1003f04c)
- CoTaskMemFree (Address: 0x1003f060)
- CoTaskMemRealloc (Address: 0x1003f050)
- CoUninitialize (Address: 0x1003f05c)
- CoWaitForMultipleHandles (Address: 0x1003f044)
- CreateStreamOnHGlobal (Address: 0x1003f074)
- StringFromGUID2 (Address: 0x1003f054)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x1003f08c)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1003f094)
- IsDebuggerPresent (Address: 0x1003f09c)
- OutputDebugStringW (Address: 0x1003f098)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1003f0a4)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1003f0ac)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1003f0b4)
- RaiseException (Address: 0x1003f0b8)
- SetLastError (Address: 0x1003f0c0)
- SetUnhandledExceptionFilter (Address: 0x1003f0c4)
- UnhandledExceptionFilter (Address: 0x1003f0bc)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1003f0cc)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1003f0dc)
- HeapAlloc (Address: 0x1003f0d8)
- HeapFree (Address: 0x1003f0d4)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1003f0ec)
- LocalFree (Address: 0x1003f0e4)
- LocalReAlloc (Address: 0x1003f0e8)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x1003f0f4)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1003f108)
- FindResourceExW (Address: 0x1003f100)
- GetModuleFileNameA (Address: 0x1003f104)
- GetModuleHandleExW (Address: 0x1003f118)
- GetModuleHandleW (Address: 0x1003f110)
- GetProcAddress (Address: 0x1003f10c)
- LoadLibraryExW (Address: 0x1003f114)
- LoadResource (Address: 0x1003f0fc)
- LockResource (Address: 0x1003f11c)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1003f124)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x1003f130)
- GetCurrentProcess (Address: 0x1003f144)
- GetCurrentProcessId (Address: 0x1003f134)
- GetCurrentThreadId (Address: 0x1003f140)
- GetProcessId (Address: 0x1003f13c)
- GetThreadId (Address: 0x1003f12c)
- OpenProcessToken (Address: 0x1003f138)
- TerminateProcess (Address: 0x1003f148)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x1003f150)
- OpenProcess (Address: 0x1003f154)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1003f15c)
api-ms-win-core-psapi-l1-1-0.dll
- K32GetProcessImageFileNameW (Address: 0x1003f164)
api-ms-win-core-psm-key-l1-1-0.dll
- PsmGetKeyFromProcess (Address: 0x1003f16c)
api-ms-win-core-quirks-l1-1-0.dll
- QuirkIsEnabledForPackage (Address: 0x1003f174)
api-ms-win-core-registry-l1-1-0.dll
- RegGetValueW (Address: 0x1003f17c)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1003f184)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1003f1bc)
- AcquireSRWLockShared (Address: 0x1003f1b4)
- CreateEventExW (Address: 0x1003f1ac)
- CreateEventW (Address: 0x1003f18c)
- CreateMutexExW (Address: 0x1003f1c4)
- CreateSemaphoreExW (Address: 0x1003f1dc)
- DeleteCriticalSection (Address: 0x1003f19c)
- EnterCriticalSection (Address: 0x1003f1a8)
- InitializeCriticalSection (Address: 0x1003f1a0)
- InitializeCriticalSectionAndSpinCount (Address: 0x1003f1e0)
- InitializeCriticalSectionEx (Address: 0x1003f1b0)
- InitializeSRWLock (Address: 0x1003f198)
- LeaveCriticalSection (Address: 0x1003f1a4)
- OpenSemaphoreW (Address: 0x1003f1c8)
- ReleaseMutex (Address: 0x1003f1d0)
- ReleaseSemaphore (Address: 0x1003f1d8)
- ReleaseSRWLockExclusive (Address: 0x1003f1c0)
- ReleaseSRWLockShared (Address: 0x1003f1b8)
- ResetEvent (Address: 0x1003f1e4)
- SetEvent (Address: 0x1003f190)
- WaitForMultipleObjectsEx (Address: 0x1003f194)
- WaitForSingleObject (Address: 0x1003f1d4)
- WaitForSingleObjectEx (Address: 0x1003f1cc)
api-ms-win-core-synch-l1-2-0.dll
- InitializeConditionVariable (Address: 0x1003f1f0)
- InitOnceBeginInitialize (Address: 0x1003f204)
- InitOnceComplete (Address: 0x1003f1f8)
- InitOnceExecuteOnce (Address: 0x1003f1fc)
- InitOnceInitialize (Address: 0x1003f200)
- Sleep (Address: 0x1003f1f4)
- WakeConditionVariable (Address: 0x1003f1ec)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1003f210)
- GetTickCount (Address: 0x1003f20c)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1003f218)
- CreateThreadpoolTimer (Address: 0x1003f224)
- SetThreadpoolTimer (Address: 0x1003f220)
- WaitForThreadpoolTimerCallbacks (Address: 0x1003f21c)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1003f22c)
- EncodePointer (Address: 0x1003f230)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x1003f23c)
- RoOriginateError (Address: 0x1003f248)
- RoOriginateErrorW (Address: 0x1003f238)
- RoTransformError (Address: 0x1003f244)
- SetRestrictedErrorInfo (Address: 0x1003f240)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x1003f254)
- RoGetMatchingRestrictedErrorInfo (Address: 0x1003f258)
- RoReportFailedDelegate (Address: 0x1003f250)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x1003f264)
- RoGetActivationFactory (Address: 0x1003f260)
api-ms-win-core-winrt-string-l1-1-0.dll
- WindowsConcatString (Address: 0x1003f28c)
- WindowsCreateString (Address: 0x1003f270)
- WindowsCreateStringReference (Address: 0x1003f280)
- WindowsDeleteString (Address: 0x1003f284)
- WindowsDuplicateString (Address: 0x1003f27c)
- WindowsGetStringLen (Address: 0x1003f288)
- WindowsGetStringRawBuffer (Address: 0x1003f26c)
- WindowsIsStringEmpty (Address: 0x1003f278)
- WindowsStringHasEmbeddedNull (Address: 0x1003f274)
api-ms-win-crt-private-l1-1-0.dll
- __CxxFrameHandler3 (Address: 0x1003f30c)
- __std_terminate (Address: 0x1003f308)
- _CxxThrowException (Address: 0x1003f2d8)
- _except_handler4_common (Address: 0x1003f2d4)
- _o___std_exception_copy (Address: 0x1003f2fc)
- _o___std_exception_destroy (Address: 0x1003f2f8)
- _o___std_type_info_destroy_list (Address: 0x1003f2f4)
- _o___stdio_common_vsnprintf_s (Address: 0x1003f2e8)
- _o___stdio_common_vswprintf (Address: 0x1003f2e4)
- _o__callnewh (Address: 0x1003f2f0)
- _o__cexit (Address: 0x1003f2e0)
- _o__configure_narrow_argv (Address: 0x1003f2ec)
- _o__crt_atexit (Address: 0x1003f2dc)
- _o__errno (Address: 0x1003f304)
- _o__execute_onexit_table (Address: 0x1003f300)
- _o__initialize_narrow_environment (Address: 0x1003f294)
- _o__initialize_onexit_table (Address: 0x1003f298)
- _o__invalid_parameter_noinfo (Address: 0x1003f29c)
- _o__invalid_parameter_noinfo_noreturn (Address: 0x1003f2a0)
- _o__purecall (Address: 0x1003f2a4)
- _o__register_onexit_function (Address: 0x1003f2a8)
- _o__seh_filter_dll (Address: 0x1003f2ac)
- _o__ui64tow_s (Address: 0x1003f2b0)
- _o_free (Address: 0x1003f2b8)
- _o_malloc (Address: 0x1003f2bc)
- _o_realloc (Address: 0x1003f2c0)
- _o_terminate (Address: 0x1003f2c4)
- _o_toupper (Address: 0x1003f2c8)
- _o_wcscpy_s (Address: 0x1003f2cc)
- _o_wcstok_s (Address: 0x1003f2d0)
- memcmp (Address: 0x1003f310)
- memcpy (Address: 0x1003f314)
- memmove (Address: 0x1003f2b4)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x1003f320)
- _initterm_e (Address: 0x1003f31c)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x1003f328)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1003f340)
- EventProviderEnabled (Address: 0x1003f344)
- EventRegister (Address: 0x1003f334)
- EventSetInformation (Address: 0x1003f338)
- EventUnregister (Address: 0x1003f330)
- EventWriteTransfer (Address: 0x1003f33c)
api-ms-win-security-accesshlpr-l1-1-0.dll
- BuildSecurityDescriptorForSharingAccess (Address: 0x1003f34c)
- FreeTransientObjectSecurityDescriptor (Address: 0x1003f350)
- QueryTransientObjectSecurityDescriptor (Address: 0x1003f354)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x1003f35c)
- EqualSid (Address: 0x1003f364)
- GetLengthSid (Address: 0x1003f360)
- GetTokenInformation (Address: 0x1003f368)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1003f378)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1003f374)
- ConvertStringSidToSidW (Address: 0x1003f370)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x1003f384)
- OpenSCManagerW (Address: 0x1003f380)
- OpenServiceW (Address: 0x1003f388)
api-ms-win-service-private-l1-1-0.dll
- SubscribeServiceChangeNotifications (Address: 0x1003f390)
- UnsubscribeServiceChangeNotifications (Address: 0x1003f394)
api-ms-win-service-winsvc-l1-1-0.dll
- QueryServiceStatus (Address: 0x1003f39c)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolAllowThreadReuse (Address: 0x1003f3a4)
- SHTaskPoolQueueTask (Address: 0x1003f3a8)
CoreMessaging.dll
- CoreUICreate (Address: 0x1003f000)
msvcp_win.dll
- ?_Xlength_error@std@@YAXPBD@Z (Address: 0x1003f3b0)
- ?_Xout_of_range@std@@YAXPBD@Z (Address: 0x1003f3b4)
ntdll.dll
- NtQueryInformationToken (Address: 0x1003f3e0)
- NtQuerySystemInformation (Address: 0x1003f3c0)
- RtlAcquireSRWLockExclusive (Address: 0x1003f3f8)
- RtlAcquireSRWLockShared (Address: 0x1003f3cc)
- RtlAllocateHeap (Address: 0x1003f3c8)
- RtlCopySid (Address: 0x1003f3e4)
- RtlDeriveCapabilitySidsFromName (Address: 0x1003f3dc)
- RtlFreeHeap (Address: 0x1003f3e8)
- RtlGetDeviceFamilyInfoEnum (Address: 0x1003f3bc)
- RtlInitializeSRWLock (Address: 0x1003f3c4)
- RtlQueryUnbiasedInterruptTime (Address: 0x1003f3ec)
- RtlReleaseSRWLockExclusive (Address: 0x1003f3d8)
- RtlReleaseSRWLockShared (Address: 0x1003f3f0)
- RtlRunOnceBeginInitialize (Address: 0x1003f3d0)
- RtlRunOnceExecuteOnce (Address: 0x1003f3d4)
- RtlSleepConditionVariableSRW (Address: 0x1003f3fc)
- RtlValidSid (Address: 0x1003f3f4)
PROPSYS.dll
- (Address: 0x1003f008)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x1003f030)
- I_RpcMapWin32Status (Address: 0x1003f014)
- NdrClientCall4 (Address: 0x1003f028)
- RpcBindingBind (Address: 0x1003f01c)
- RpcBindingCreateW (Address: 0x1003f020)
- RpcBindingFree (Address: 0x1003f024)
- RpcBindingFromStringBindingW (Address: 0x1003f018)
- RpcStringBindingComposeW (Address: 0x1003f02c)
- RpcStringFreeW (Address: 0x1003f010)