shellext.dll
Description: Microsoft Security Client Shell Extension
Authors: © Microsoft Corporation. All rights reserved.
Version: 4.18.1907.16384
Architecture: 64-bit
Operating System: Windows NT
SHA256: 691cf5b193f29b04464ee900829166d9
File Size: 328.5 KB
Uploaded At: Dec. 1, 2025, 8:30 a.m.
Views: 26
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x46d0)
- DllGetClassObject (Ordinal: 2, Address: 0x4710)
- DllRegisterServer (Ordinal: 3, Address: 0x4850)
- DllUnregisterServer (Ordinal: 4, Address: 0x49a0)
Imported DLLs & Functions
ADVAPI32.dll
- AddAce (Address: 0x180034248)
- AdjustTokenPrivileges (Address: 0x1800341f0)
- AllocateAndInitializeSid (Address: 0x1800341a8)
- ChangeServiceConfigW (Address: 0x1800341c8)
- CheckTokenMembership (Address: 0x1800341b0)
- CloseServiceHandle (Address: 0x180034220)
- ControlService (Address: 0x1800341d0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180034170)
- ConvertStringSidToSidW (Address: 0x1800342a8)
- CopySid (Address: 0x180034278)
- CreateProcessAsUserW (Address: 0x180034208)
- DuplicateTokenEx (Address: 0x180034198)
- EqualSid (Address: 0x180034238)
- FreeSid (Address: 0x180034210)
- GetAce (Address: 0x180034258)
- GetAclInformation (Address: 0x180034250)
- GetLengthSid (Address: 0x180034228)
- GetNamedSecurityInfoW (Address: 0x180034298)
- GetSecurityDescriptorControl (Address: 0x180034290)
- GetSecurityDescriptorDacl (Address: 0x180034270)
- GetSecurityDescriptorGroup (Address: 0x180034268)
- GetSecurityDescriptorLength (Address: 0x180034288)
- GetSecurityDescriptorOwner (Address: 0x180034260)
- GetSecurityDescriptorSacl (Address: 0x180034160)
- GetSidSubAuthority (Address: 0x1800341a0)
- GetSidSubAuthorityCount (Address: 0x180034190)
- GetTokenInformation (Address: 0x180034188)
- GetTraceEnableFlags (Address: 0x1800342c0)
- GetTraceEnableLevel (Address: 0x1800342c8)
- GetTraceLoggerHandle (Address: 0x1800342b8)
- InitializeAcl (Address: 0x180034240)
- InitiateSystemShutdownExW (Address: 0x1800341f8)
- IsValidSid (Address: 0x180034230)
- LookupPrivilegeNameW (Address: 0x180034200)
- LookupPrivilegeValueW (Address: 0x1800341e0)
- MakeSelfRelativeSD (Address: 0x180034280)
- OpenProcessToken (Address: 0x180034180)
- OpenSCManagerW (Address: 0x1800341b8)
- OpenServiceW (Address: 0x1800341c0)
- PrivilegeCheck (Address: 0x1800341e8)
- QueryServiceConfigW (Address: 0x1800342b0)
- QueryServiceStatus (Address: 0x1800341d8)
- RegCloseKey (Address: 0x1800342e0)
- RegCreateKeyExW (Address: 0x1800342f0)
- RegDeleteKeyW (Address: 0x180034168)
- RegDeleteValueW (Address: 0x180034310)
- RegEnumKeyExW (Address: 0x1800342f8)
- RegisterTraceGuidsW (Address: 0x1800342d0)
- RegOpenKeyExW (Address: 0x180034308)
- RegQueryInfoKeyW (Address: 0x1800342e8)
- RegQueryValueExW (Address: 0x180034178)
- RegSetValueExW (Address: 0x180034300)
- SetNamedSecurityInfoW (Address: 0x1800342a0)
- TraceMessage (Address: 0x180034218)
- UnregisterTraceGuids (Address: 0x1800342d8)
CRYPT32.dll
- CertVerifyCertificateChainPolicy (Address: 0x180034320)
GDI32.dll
- CreateCompatibleBitmap (Address: 0x180034340)
- CreateCompatibleDC (Address: 0x180034338)
- DeleteDC (Address: 0x180034360)
- DeleteObject (Address: 0x180034368)
- ExtTextOutW (Address: 0x180034358)
- GetObjectW (Address: 0x180034330)
- SelectObject (Address: 0x180034348)
- SetBkColor (Address: 0x180034350)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x1800346d0)
- CloseHandle (Address: 0x180034498)
- CopyFileW (Address: 0x180034650)
- CreateDirectoryW (Address: 0x180034668)
- CreateEventW (Address: 0x1800344a8)
- CreateFileMappingW (Address: 0x180034690)
- CreateFileW (Address: 0x180034588)
- CreateMutexW (Address: 0x180034640)
- CreateProcessW (Address: 0x180034488)
- CreateThread (Address: 0x180034550)
- CreateToolhelp32Snapshot (Address: 0x1800345f8)
- DecodePointer (Address: 0x1800346f0)
- DeleteCriticalSection (Address: 0x180034418)
- DeleteFileW (Address: 0x1800345b8)
- DisableThreadLibraryCalls (Address: 0x1800346a0)
- EncodePointer (Address: 0x1800346e8)
- EnterCriticalSection (Address: 0x180034470)
- FindClose (Address: 0x1800344d8)
- FindFirstFileW (Address: 0x1800345d0)
- FindNextFileW (Address: 0x1800345c8)
- FindResourceExW (Address: 0x180034430)
- FindResourceW (Address: 0x1800345e0)
- FreeLibrary (Address: 0x180034408)
- FreeResource (Address: 0x1800345d8)
- GetCurrentProcess (Address: 0x1800343c0)
- GetCurrentProcessId (Address: 0x1800343a8)
- GetCurrentThreadId (Address: 0x1800343a0)
- GetDiskFreeSpaceExW (Address: 0x180034608)
- GetDriveTypeW (Address: 0x1800344c0)
- GetExitCodeProcess (Address: 0x180034620)
- GetExitCodeThread (Address: 0x180034538)
- GetFileAttributesW (Address: 0x180034688)
- GetFileSize (Address: 0x180034570)
- GetFileSizeEx (Address: 0x180034568)
- GetLastError (Address: 0x180034440)
- GetLocaleInfoW (Address: 0x180034648)
- GetLocalTime (Address: 0x1800344f0)
- GetLongPathNameW (Address: 0x180034560)
- GetModuleFileNameW (Address: 0x180034468)
- GetModuleHandleW (Address: 0x180034410)
- GetNativeSystemInfo (Address: 0x180034500)
- GetPrivateProfileIntW (Address: 0x180034528)
- GetPrivateProfileStringW (Address: 0x180034530)
- GetProcAddress (Address: 0x180034420)
- GetProcessHeap (Address: 0x1800345a8)
- GetSystemDefaultLCID (Address: 0x180034670)
- GetSystemDefaultUILanguage (Address: 0x180034518)
- GetSystemDirectoryW (Address: 0x180034610)
- GetSystemTimeAsFileTime (Address: 0x180034398)
- GetTempFileNameW (Address: 0x180034658)
- GetTempPathW (Address: 0x180034660)
- GetThreadLocale (Address: 0x180034460)
- GetTickCount (Address: 0x180034378)
- GetUserDefaultUILanguage (Address: 0x1800344b0)
- GetVersionExW (Address: 0x1800344e8)
- GetVolumeInformationW (Address: 0x1800344d0)
- GetWindowsDirectoryW (Address: 0x180034618)
- GlobalFindAtomW (Address: 0x1800344e0)
- HeapAlloc (Address: 0x1800345b0)
- HeapDestroy (Address: 0x1800346c0)
- HeapFree (Address: 0x1800345a0)
- HeapReAlloc (Address: 0x1800346b8)
- HeapSize (Address: 0x1800346b0)
- InitializeCriticalSection (Address: 0x180034450)
- InitializeCriticalSectionAndSpinCount (Address: 0x180034680)
- IsWow64Process (Address: 0x180034630)
- K32GetModuleFileNameExW (Address: 0x180034598)
- LeaveCriticalSection (Address: 0x180034458)
- LoadLibraryExW (Address: 0x1800343f8)
- LoadResource (Address: 0x180034428)
- LocalFree (Address: 0x180034628)
- LockResource (Address: 0x1800344a0)
- lstrcmpiW (Address: 0x180034400)
- MapViewOfFile (Address: 0x180034698)
- MoveFileExW (Address: 0x180034678)
- MoveFileW (Address: 0x180034558)
- MultiByteToWideChar (Address: 0x180034448)
- OpenProcess (Address: 0x180034600)
- OutputDebugStringA (Address: 0x180034380)
- Process32FirstW (Address: 0x1800345f0)
- Process32NextW (Address: 0x1800345e8)
- ProcessIdToSessionId (Address: 0x180034510)
- QueryPerformanceCounter (Address: 0x1800343b0)
- RaiseException (Address: 0x180034438)
- ReadFile (Address: 0x180034580)
- ReleaseMutex (Address: 0x180034638)
- ReleaseSRWLockExclusive (Address: 0x1800346c8)
- RemoveDirectoryW (Address: 0x1800345c0)
- ResetEvent (Address: 0x180034540)
- RtlCaptureContext (Address: 0x1800343e8)
- RtlLookupFunctionEntry (Address: 0x1800343e0)
- RtlVirtualUnwind (Address: 0x1800343d8)
- SearchPathW (Address: 0x180034390)
- SetErrorMode (Address: 0x1800344c8)
- SetEvent (Address: 0x180034548)
- SetLastError (Address: 0x180034508)
- SetThreadLocale (Address: 0x180034478)
- SetUnhandledExceptionFilter (Address: 0x1800343c8)
- SizeofResource (Address: 0x180034480)
- Sleep (Address: 0x1800343f0)
- SleepConditionVariableSRW (Address: 0x1800346e0)
- SwitchToThread (Address: 0x1800344b8)
- SystemTimeToFileTime (Address: 0x1800344f8)
- TerminateProcess (Address: 0x1800343b8)
- UnhandledExceptionFilter (Address: 0x1800343d0)
- UnmapViewOfFile (Address: 0x180034388)
- VerifyVersionInfoW (Address: 0x180034590)
- VirtualLock (Address: 0x1800346a8)
- WaitForSingleObject (Address: 0x180034490)
- WakeAllConditionVariable (Address: 0x1800346d8)
- WriteFile (Address: 0x180034578)
- WritePrivateProfileStringW (Address: 0x180034520)
msvcrt.dll
- __C_specific_handler (Address: 0x180034b28)
- __CxxFrameHandler3 (Address: 0x180034b30)
- __dllonexit (Address: 0x180034a50)
- _amsg_exit (Address: 0x180034a88)
- _CxxThrowException (Address: 0x180034aa8)
- _errno (Address: 0x180034a78)
- _initterm (Address: 0x180034a80)
- _lock (Address: 0x180034a60)
- _onexit (Address: 0x180034a48)
- _purecall (Address: 0x180034b08)
- _unlock (Address: 0x180034a58)
- _vscwprintf (Address: 0x1800349d0)
- _vsnprintf (Address: 0x180034a30)
- _vsnwprintf (Address: 0x180034a08)
- _wchmod (Address: 0x180034a20)
- _wcsicmp (Address: 0x180034a18)
- _wcsnicmp (Address: 0x1800349f0)
- _XcptFilter (Address: 0x180034a90)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180034ab0)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180034ad8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x180034ad0)
- ??0exception@@QEAA@XZ (Address: 0x180034ab8)
- ??1exception@@UEAA@XZ (Address: 0x180034ae0)
- ??1type_info@@UEAA@XZ (Address: 0x180034a40)
- ?terminate@@YAXXZ (Address: 0x180034a68)
- ?what@exception@@UEBAPEBDXZ (Address: 0x180034ae8)
- bsearch (Address: 0x180034a38)
- calloc (Address: 0x180034ac0)
- free (Address: 0x180034b00)
- iswalpha (Address: 0x1800349e0)
- malloc (Address: 0x180034af8)
- memcpy (Address: 0x180034aa0)
- memcpy_s (Address: 0x180034b20)
- memmove (Address: 0x180034a98)
- memmove_s (Address: 0x180034ac8)
- memset (Address: 0x180034b38)
- realloc (Address: 0x180034a70)
- swprintf_s (Address: 0x180034a28)
- vswprintf_s (Address: 0x1800349d8)
- wcscat_s (Address: 0x180034b10)
- wcschr (Address: 0x180034a00)
- wcscpy_s (Address: 0x180034b18)
- wcsncmp (Address: 0x1800349f8)
- wcsncpy_s (Address: 0x180034af0)
- wcsrchr (Address: 0x1800349e8)
- wcsstr (Address: 0x180034a10)
- wcstoul (Address: 0x1800349c8)
ntdll.dll
- RtlGetVersion (Address: 0x180034b48)
- RtlNtStatusToDosError (Address: 0x180034b50)
ole32.dll
- CoCreateGuid (Address: 0x180034b88)
- CoCreateInstance (Address: 0x180034b70)
- CoTaskMemAlloc (Address: 0x180034b80)
- CoTaskMemFree (Address: 0x180034b68)
- CoTaskMemRealloc (Address: 0x180034b90)
- ReleaseStgMedium (Address: 0x180034b60)
- StringFromGUID2 (Address: 0x180034b78)
OLEAUT32.dll
- LoadTypeLib (Address: 0x180034730)
- RegisterTypeLib (Address: 0x180034720)
- SysAllocString (Address: 0x180034718)
- SysAllocStringByteLen (Address: 0x180034700)
- SysAllocStringLen (Address: 0x180034740)
- SysFreeString (Address: 0x180034728)
- SysStringByteLen (Address: 0x180034760)
- SysStringLen (Address: 0x180034710)
- UnRegisterTypeLib (Address: 0x180034738)
- VarBstrCat (Address: 0x180034748)
- VariantClear (Address: 0x180034758)
- VariantInit (Address: 0x180034750)
- VarUI4FromStr (Address: 0x180034708)
SHELL32.dll
- DragQueryFileW (Address: 0x180034780)
- SHChangeNotify (Address: 0x180034770)
- ShellExecuteW (Address: 0x180034778)
- SHGetFolderPathW (Address: 0x180034788)
- SHGetPathFromIDListW (Address: 0x180034790)
- SHGetSpecialFolderLocation (Address: 0x180034798)
SHLWAPI.dll
- PathAppendW (Address: 0x1800347d0)
- PathCombineW (Address: 0x1800347e0)
- PathFileExistsW (Address: 0x1800347e8)
- PathFindFileNameW (Address: 0x1800347c0)
- PathIsDirectoryW (Address: 0x1800347b0)
- PathIsRelativeW (Address: 0x1800347b8)
- PathIsRootW (Address: 0x1800347c8)
- PathMatchSpecW (Address: 0x1800347a8)
- PathRemoveFileSpecW (Address: 0x1800347d8)
USER32.dll
- AdjustWindowRectEx (Address: 0x180034898)
- AllowSetForegroundWindow (Address: 0x180034838)
- CharNextW (Address: 0x180034808)
- CreateDialogParamW (Address: 0x180034900)
- DestroyIcon (Address: 0x180034830)
- DestroyWindow (Address: 0x1800348f0)
- DrawIconEx (Address: 0x180034810)
- FindWindowExW (Address: 0x180034848)
- FindWindowW (Address: 0x1800348c8)
- GetActiveWindow (Address: 0x180034878)
- GetDC (Address: 0x180034868)
- GetDesktopWindow (Address: 0x180034860)
- GetIconInfo (Address: 0x180034858)
- GetLastActivePopup (Address: 0x180034840)
- GetSysColor (Address: 0x180034870)
- GetSystemMetrics (Address: 0x180034850)
- GetWindowThreadProcessId (Address: 0x180034820)
- InsertMenuW (Address: 0x180034888)
- IsDialogMessageW (Address: 0x1800348a8)
- KillTimer (Address: 0x1800348b0)
- LoadIconW (Address: 0x1800348f8)
- LoadImageW (Address: 0x180034800)
- LoadStringW (Address: 0x1800348e0)
- MessageBoxW (Address: 0x180034828)
- PostMessageW (Address: 0x1800348d8)
- PostThreadMessageW (Address: 0x1800348a0)
- ReleaseDC (Address: 0x180034880)
- SendMessageW (Address: 0x180034818)
- SetForegroundWindow (Address: 0x1800348c0)
- SetMenuItemBitmaps (Address: 0x180034890)
- SetTimer (Address: 0x1800348b8)
- SetWindowTextW (Address: 0x1800348d0)
- ShowWindow (Address: 0x1800348e8)
- UnregisterClassA (Address: 0x1800347f8)
USERENV.dll
- CreateEnvironmentBlock (Address: 0x180034918)
- DestroyEnvironmentBlock (Address: 0x180034910)
- UnloadUserProfile (Address: 0x180034920)
VERSION.dll
- GetFileVersionInfoSizeW (Address: 0x180034930)
- GetFileVersionInfoW (Address: 0x180034938)
- VerQueryValueW (Address: 0x180034940)
WINTRUST.dll
- CryptCATAdminAcquireContext (Address: 0x180034990)
- CryptCATAdminCalcHashFromFileHandle (Address: 0x180034968)
- CryptCATAdminEnumCatalogFromHash (Address: 0x180034980)
- CryptCATAdminReleaseCatalogContext (Address: 0x180034958)
- CryptCATAdminReleaseContext (Address: 0x180034970)
- CryptCATCatalogInfoFromContext (Address: 0x180034978)
- WinVerifyTrust (Address: 0x180034988)
- WTHelperGetProvSignerFromChain (Address: 0x180034960)
- WTHelperProvDataFromStateData (Address: 0x180034950)
WTSAPI32.dll
- WTSEnumerateSessionsW (Address: 0x1800349b0)
- WTSFreeMemory (Address: 0x1800349b8)
- WTSQuerySessionInformationW (Address: 0x1800349a0)
- WTSQueryUserToken (Address: 0x1800349a8)