shellext.dll

Description: Microsoft Security Client Shell Extension

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.18.1907.16384

Architecture: 64-bit

Operating System: Windows NT

SHA256: 691cf5b193f29b04464ee900829166d9

File Size: 328.5 KB

Uploaded At: Dec. 1, 2025, 8:30 a.m.

Views: 26

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x46d0)
  • DllGetClassObject (Ordinal: 2, Address: 0x4710)
  • DllRegisterServer (Ordinal: 3, Address: 0x4850)
  • DllUnregisterServer (Ordinal: 4, Address: 0x49a0)

Imported DLLs & Functions

ADVAPI32.dll
  • AddAce (Address: 0x180034248)
  • AdjustTokenPrivileges (Address: 0x1800341f0)
  • AllocateAndInitializeSid (Address: 0x1800341a8)
  • ChangeServiceConfigW (Address: 0x1800341c8)
  • CheckTokenMembership (Address: 0x1800341b0)
  • CloseServiceHandle (Address: 0x180034220)
  • ControlService (Address: 0x1800341d0)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180034170)
  • ConvertStringSidToSidW (Address: 0x1800342a8)
  • CopySid (Address: 0x180034278)
  • CreateProcessAsUserW (Address: 0x180034208)
  • DuplicateTokenEx (Address: 0x180034198)
  • EqualSid (Address: 0x180034238)
  • FreeSid (Address: 0x180034210)
  • GetAce (Address: 0x180034258)
  • GetAclInformation (Address: 0x180034250)
  • GetLengthSid (Address: 0x180034228)
  • GetNamedSecurityInfoW (Address: 0x180034298)
  • GetSecurityDescriptorControl (Address: 0x180034290)
  • GetSecurityDescriptorDacl (Address: 0x180034270)
  • GetSecurityDescriptorGroup (Address: 0x180034268)
  • GetSecurityDescriptorLength (Address: 0x180034288)
  • GetSecurityDescriptorOwner (Address: 0x180034260)
  • GetSecurityDescriptorSacl (Address: 0x180034160)
  • GetSidSubAuthority (Address: 0x1800341a0)
  • GetSidSubAuthorityCount (Address: 0x180034190)
  • GetTokenInformation (Address: 0x180034188)
  • GetTraceEnableFlags (Address: 0x1800342c0)
  • GetTraceEnableLevel (Address: 0x1800342c8)
  • GetTraceLoggerHandle (Address: 0x1800342b8)
  • InitializeAcl (Address: 0x180034240)
  • InitiateSystemShutdownExW (Address: 0x1800341f8)
  • IsValidSid (Address: 0x180034230)
  • LookupPrivilegeNameW (Address: 0x180034200)
  • LookupPrivilegeValueW (Address: 0x1800341e0)
  • MakeSelfRelativeSD (Address: 0x180034280)
  • OpenProcessToken (Address: 0x180034180)
  • OpenSCManagerW (Address: 0x1800341b8)
  • OpenServiceW (Address: 0x1800341c0)
  • PrivilegeCheck (Address: 0x1800341e8)
  • QueryServiceConfigW (Address: 0x1800342b0)
  • QueryServiceStatus (Address: 0x1800341d8)
  • RegCloseKey (Address: 0x1800342e0)
  • RegCreateKeyExW (Address: 0x1800342f0)
  • RegDeleteKeyW (Address: 0x180034168)
  • RegDeleteValueW (Address: 0x180034310)
  • RegEnumKeyExW (Address: 0x1800342f8)
  • RegisterTraceGuidsW (Address: 0x1800342d0)
  • RegOpenKeyExW (Address: 0x180034308)
  • RegQueryInfoKeyW (Address: 0x1800342e8)
  • RegQueryValueExW (Address: 0x180034178)
  • RegSetValueExW (Address: 0x180034300)
  • SetNamedSecurityInfoW (Address: 0x1800342a0)
  • TraceMessage (Address: 0x180034218)
  • UnregisterTraceGuids (Address: 0x1800342d8)
CRYPT32.dll
  • CertVerifyCertificateChainPolicy (Address: 0x180034320)
GDI32.dll
  • CreateCompatibleBitmap (Address: 0x180034340)
  • CreateCompatibleDC (Address: 0x180034338)
  • DeleteDC (Address: 0x180034360)
  • DeleteObject (Address: 0x180034368)
  • ExtTextOutW (Address: 0x180034358)
  • GetObjectW (Address: 0x180034330)
  • SelectObject (Address: 0x180034348)
  • SetBkColor (Address: 0x180034350)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1800346d0)
  • CloseHandle (Address: 0x180034498)
  • CopyFileW (Address: 0x180034650)
  • CreateDirectoryW (Address: 0x180034668)
  • CreateEventW (Address: 0x1800344a8)
  • CreateFileMappingW (Address: 0x180034690)
  • CreateFileW (Address: 0x180034588)
  • CreateMutexW (Address: 0x180034640)
  • CreateProcessW (Address: 0x180034488)
  • CreateThread (Address: 0x180034550)
  • CreateToolhelp32Snapshot (Address: 0x1800345f8)
  • DecodePointer (Address: 0x1800346f0)
  • DeleteCriticalSection (Address: 0x180034418)
  • DeleteFileW (Address: 0x1800345b8)
  • DisableThreadLibraryCalls (Address: 0x1800346a0)
  • EncodePointer (Address: 0x1800346e8)
  • EnterCriticalSection (Address: 0x180034470)
  • FindClose (Address: 0x1800344d8)
  • FindFirstFileW (Address: 0x1800345d0)
  • FindNextFileW (Address: 0x1800345c8)
  • FindResourceExW (Address: 0x180034430)
  • FindResourceW (Address: 0x1800345e0)
  • FreeLibrary (Address: 0x180034408)
  • FreeResource (Address: 0x1800345d8)
  • GetCurrentProcess (Address: 0x1800343c0)
  • GetCurrentProcessId (Address: 0x1800343a8)
  • GetCurrentThreadId (Address: 0x1800343a0)
  • GetDiskFreeSpaceExW (Address: 0x180034608)
  • GetDriveTypeW (Address: 0x1800344c0)
  • GetExitCodeProcess (Address: 0x180034620)
  • GetExitCodeThread (Address: 0x180034538)
  • GetFileAttributesW (Address: 0x180034688)
  • GetFileSize (Address: 0x180034570)
  • GetFileSizeEx (Address: 0x180034568)
  • GetLastError (Address: 0x180034440)
  • GetLocaleInfoW (Address: 0x180034648)
  • GetLocalTime (Address: 0x1800344f0)
  • GetLongPathNameW (Address: 0x180034560)
  • GetModuleFileNameW (Address: 0x180034468)
  • GetModuleHandleW (Address: 0x180034410)
  • GetNativeSystemInfo (Address: 0x180034500)
  • GetPrivateProfileIntW (Address: 0x180034528)
  • GetPrivateProfileStringW (Address: 0x180034530)
  • GetProcAddress (Address: 0x180034420)
  • GetProcessHeap (Address: 0x1800345a8)
  • GetSystemDefaultLCID (Address: 0x180034670)
  • GetSystemDefaultUILanguage (Address: 0x180034518)
  • GetSystemDirectoryW (Address: 0x180034610)
  • GetSystemTimeAsFileTime (Address: 0x180034398)
  • GetTempFileNameW (Address: 0x180034658)
  • GetTempPathW (Address: 0x180034660)
  • GetThreadLocale (Address: 0x180034460)
  • GetTickCount (Address: 0x180034378)
  • GetUserDefaultUILanguage (Address: 0x1800344b0)
  • GetVersionExW (Address: 0x1800344e8)
  • GetVolumeInformationW (Address: 0x1800344d0)
  • GetWindowsDirectoryW (Address: 0x180034618)
  • GlobalFindAtomW (Address: 0x1800344e0)
  • HeapAlloc (Address: 0x1800345b0)
  • HeapDestroy (Address: 0x1800346c0)
  • HeapFree (Address: 0x1800345a0)
  • HeapReAlloc (Address: 0x1800346b8)
  • HeapSize (Address: 0x1800346b0)
  • InitializeCriticalSection (Address: 0x180034450)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180034680)
  • IsWow64Process (Address: 0x180034630)
  • K32GetModuleFileNameExW (Address: 0x180034598)
  • LeaveCriticalSection (Address: 0x180034458)
  • LoadLibraryExW (Address: 0x1800343f8)
  • LoadResource (Address: 0x180034428)
  • LocalFree (Address: 0x180034628)
  • LockResource (Address: 0x1800344a0)
  • lstrcmpiW (Address: 0x180034400)
  • MapViewOfFile (Address: 0x180034698)
  • MoveFileExW (Address: 0x180034678)
  • MoveFileW (Address: 0x180034558)
  • MultiByteToWideChar (Address: 0x180034448)
  • OpenProcess (Address: 0x180034600)
  • OutputDebugStringA (Address: 0x180034380)
  • Process32FirstW (Address: 0x1800345f0)
  • Process32NextW (Address: 0x1800345e8)
  • ProcessIdToSessionId (Address: 0x180034510)
  • QueryPerformanceCounter (Address: 0x1800343b0)
  • RaiseException (Address: 0x180034438)
  • ReadFile (Address: 0x180034580)
  • ReleaseMutex (Address: 0x180034638)
  • ReleaseSRWLockExclusive (Address: 0x1800346c8)
  • RemoveDirectoryW (Address: 0x1800345c0)
  • ResetEvent (Address: 0x180034540)
  • RtlCaptureContext (Address: 0x1800343e8)
  • RtlLookupFunctionEntry (Address: 0x1800343e0)
  • RtlVirtualUnwind (Address: 0x1800343d8)
  • SearchPathW (Address: 0x180034390)
  • SetErrorMode (Address: 0x1800344c8)
  • SetEvent (Address: 0x180034548)
  • SetLastError (Address: 0x180034508)
  • SetThreadLocale (Address: 0x180034478)
  • SetUnhandledExceptionFilter (Address: 0x1800343c8)
  • SizeofResource (Address: 0x180034480)
  • Sleep (Address: 0x1800343f0)
  • SleepConditionVariableSRW (Address: 0x1800346e0)
  • SwitchToThread (Address: 0x1800344b8)
  • SystemTimeToFileTime (Address: 0x1800344f8)
  • TerminateProcess (Address: 0x1800343b8)
  • UnhandledExceptionFilter (Address: 0x1800343d0)
  • UnmapViewOfFile (Address: 0x180034388)
  • VerifyVersionInfoW (Address: 0x180034590)
  • VirtualLock (Address: 0x1800346a8)
  • WaitForSingleObject (Address: 0x180034490)
  • WakeAllConditionVariable (Address: 0x1800346d8)
  • WriteFile (Address: 0x180034578)
  • WritePrivateProfileStringW (Address: 0x180034520)
msvcrt.dll
  • __C_specific_handler (Address: 0x180034b28)
  • __CxxFrameHandler3 (Address: 0x180034b30)
  • __dllonexit (Address: 0x180034a50)
  • _amsg_exit (Address: 0x180034a88)
  • _CxxThrowException (Address: 0x180034aa8)
  • _errno (Address: 0x180034a78)
  • _initterm (Address: 0x180034a80)
  • _lock (Address: 0x180034a60)
  • _onexit (Address: 0x180034a48)
  • _purecall (Address: 0x180034b08)
  • _unlock (Address: 0x180034a58)
  • _vscwprintf (Address: 0x1800349d0)
  • _vsnprintf (Address: 0x180034a30)
  • _vsnwprintf (Address: 0x180034a08)
  • _wchmod (Address: 0x180034a20)
  • _wcsicmp (Address: 0x180034a18)
  • _wcsnicmp (Address: 0x1800349f0)
  • _XcptFilter (Address: 0x180034a90)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180034ab0)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180034ad8)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180034ad0)
  • ??0exception@@QEAA@XZ (Address: 0x180034ab8)
  • ??1exception@@UEAA@XZ (Address: 0x180034ae0)
  • ??1type_info@@UEAA@XZ (Address: 0x180034a40)
  • ?terminate@@YAXXZ (Address: 0x180034a68)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180034ae8)
  • bsearch (Address: 0x180034a38)
  • calloc (Address: 0x180034ac0)
  • free (Address: 0x180034b00)
  • iswalpha (Address: 0x1800349e0)
  • malloc (Address: 0x180034af8)
  • memcpy (Address: 0x180034aa0)
  • memcpy_s (Address: 0x180034b20)
  • memmove (Address: 0x180034a98)
  • memmove_s (Address: 0x180034ac8)
  • memset (Address: 0x180034b38)
  • realloc (Address: 0x180034a70)
  • swprintf_s (Address: 0x180034a28)
  • vswprintf_s (Address: 0x1800349d8)
  • wcscat_s (Address: 0x180034b10)
  • wcschr (Address: 0x180034a00)
  • wcscpy_s (Address: 0x180034b18)
  • wcsncmp (Address: 0x1800349f8)
  • wcsncpy_s (Address: 0x180034af0)
  • wcsrchr (Address: 0x1800349e8)
  • wcsstr (Address: 0x180034a10)
  • wcstoul (Address: 0x1800349c8)
ntdll.dll
  • RtlGetVersion (Address: 0x180034b48)
  • RtlNtStatusToDosError (Address: 0x180034b50)
ole32.dll
  • CoCreateGuid (Address: 0x180034b88)
  • CoCreateInstance (Address: 0x180034b70)
  • CoTaskMemAlloc (Address: 0x180034b80)
  • CoTaskMemFree (Address: 0x180034b68)
  • CoTaskMemRealloc (Address: 0x180034b90)
  • ReleaseStgMedium (Address: 0x180034b60)
  • StringFromGUID2 (Address: 0x180034b78)
OLEAUT32.dll
  • LoadTypeLib (Address: 0x180034730)
  • RegisterTypeLib (Address: 0x180034720)
  • SysAllocString (Address: 0x180034718)
  • SysAllocStringByteLen (Address: 0x180034700)
  • SysAllocStringLen (Address: 0x180034740)
  • SysFreeString (Address: 0x180034728)
  • SysStringByteLen (Address: 0x180034760)
  • SysStringLen (Address: 0x180034710)
  • UnRegisterTypeLib (Address: 0x180034738)
  • VarBstrCat (Address: 0x180034748)
  • VariantClear (Address: 0x180034758)
  • VariantInit (Address: 0x180034750)
  • VarUI4FromStr (Address: 0x180034708)
SHELL32.dll
  • DragQueryFileW (Address: 0x180034780)
  • SHChangeNotify (Address: 0x180034770)
  • ShellExecuteW (Address: 0x180034778)
  • SHGetFolderPathW (Address: 0x180034788)
  • SHGetPathFromIDListW (Address: 0x180034790)
  • SHGetSpecialFolderLocation (Address: 0x180034798)
SHLWAPI.dll
  • PathAppendW (Address: 0x1800347d0)
  • PathCombineW (Address: 0x1800347e0)
  • PathFileExistsW (Address: 0x1800347e8)
  • PathFindFileNameW (Address: 0x1800347c0)
  • PathIsDirectoryW (Address: 0x1800347b0)
  • PathIsRelativeW (Address: 0x1800347b8)
  • PathIsRootW (Address: 0x1800347c8)
  • PathMatchSpecW (Address: 0x1800347a8)
  • PathRemoveFileSpecW (Address: 0x1800347d8)
USER32.dll
  • AdjustWindowRectEx (Address: 0x180034898)
  • AllowSetForegroundWindow (Address: 0x180034838)
  • CharNextW (Address: 0x180034808)
  • CreateDialogParamW (Address: 0x180034900)
  • DestroyIcon (Address: 0x180034830)
  • DestroyWindow (Address: 0x1800348f0)
  • DrawIconEx (Address: 0x180034810)
  • FindWindowExW (Address: 0x180034848)
  • FindWindowW (Address: 0x1800348c8)
  • GetActiveWindow (Address: 0x180034878)
  • GetDC (Address: 0x180034868)
  • GetDesktopWindow (Address: 0x180034860)
  • GetIconInfo (Address: 0x180034858)
  • GetLastActivePopup (Address: 0x180034840)
  • GetSysColor (Address: 0x180034870)
  • GetSystemMetrics (Address: 0x180034850)
  • GetWindowThreadProcessId (Address: 0x180034820)
  • InsertMenuW (Address: 0x180034888)
  • IsDialogMessageW (Address: 0x1800348a8)
  • KillTimer (Address: 0x1800348b0)
  • LoadIconW (Address: 0x1800348f8)
  • LoadImageW (Address: 0x180034800)
  • LoadStringW (Address: 0x1800348e0)
  • MessageBoxW (Address: 0x180034828)
  • PostMessageW (Address: 0x1800348d8)
  • PostThreadMessageW (Address: 0x1800348a0)
  • ReleaseDC (Address: 0x180034880)
  • SendMessageW (Address: 0x180034818)
  • SetForegroundWindow (Address: 0x1800348c0)
  • SetMenuItemBitmaps (Address: 0x180034890)
  • SetTimer (Address: 0x1800348b8)
  • SetWindowTextW (Address: 0x1800348d0)
  • ShowWindow (Address: 0x1800348e8)
  • UnregisterClassA (Address: 0x1800347f8)
USERENV.dll
  • CreateEnvironmentBlock (Address: 0x180034918)
  • DestroyEnvironmentBlock (Address: 0x180034910)
  • UnloadUserProfile (Address: 0x180034920)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x180034930)
  • GetFileVersionInfoW (Address: 0x180034938)
  • VerQueryValueW (Address: 0x180034940)
WINTRUST.dll
  • CryptCATAdminAcquireContext (Address: 0x180034990)
  • CryptCATAdminCalcHashFromFileHandle (Address: 0x180034968)
  • CryptCATAdminEnumCatalogFromHash (Address: 0x180034980)
  • CryptCATAdminReleaseCatalogContext (Address: 0x180034958)
  • CryptCATAdminReleaseContext (Address: 0x180034970)
  • CryptCATCatalogInfoFromContext (Address: 0x180034978)
  • WinVerifyTrust (Address: 0x180034988)
  • WTHelperGetProvSignerFromChain (Address: 0x180034960)
  • WTHelperProvDataFromStateData (Address: 0x180034950)
WTSAPI32.dll
  • WTSEnumerateSessionsW (Address: 0x1800349b0)
  • WTSFreeMemory (Address: 0x1800349b8)
  • WTSQuerySessionInformationW (Address: 0x1800349a0)
  • WTSQueryUserToken (Address: 0x1800349a8)