PresentationHostDLL.dll

Description: Windows Presentation Foundation Host Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 3.0.6920.9158

Architecture: 64-bit

Operating System: Windows

SHA256: c7089d578f14b8596bac58700ec60add

File Size: 171.4 KB

Uploaded At: Dec. 1, 2025, 8:31 a.m.

Views: 17

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllMain (Ordinal: 1, Address: 0x222c)
  • Activate (Ordinal: 2, Address: 0x22ac)
  • Deactivate (Ordinal: 3, Address: 0x2b6c)
  • ForwardTranslateAccelerator (Ordinal: 4, Address: 0x2774)
  • SaveToHistory (Ordinal: 5, Address: 0x2c2c)
  • LoadFromHistory (Ordinal: 6, Address: 0x2c90)
  • ProcessUnhandledException (Ordinal: 7, Address: 0x304c)
  • CreateIDispatchSTAForwarder (Ordinal: 8, Address: 0x14608)
  • DRMInitEnvironment (Ordinal: 601, Address: 0x134c8)
  • DRMCreateBoundLicense (Ordinal: 602, Address: 0x13538)
  • DRMCreateLicenseStorageSession (Ordinal: 603, Address: 0x13594)
  • DRMCreateEnablingBitsDecryptor (Ordinal: 604, Address: 0x135f8)
  • DRMCreateEnablingBitsEncryptor (Ordinal: 605, Address: 0x13654)
  • DRMEncrypt (Ordinal: 606, Address: 0x136b0)
  • DRMDecrypt (Ordinal: 607, Address: 0x13714)
  • DRMGetInfo (Ordinal: 608, Address: 0x13778)
  • DRMGetBoundLicenseObjectCount (Ordinal: 609, Address: 0x137d4)
  • DRMGetBoundLicenseObject (Ordinal: 610, Address: 0x1381c)
  • DRMGetBoundLicenseAttribute (Ordinal: 611, Address: 0x13870)
  • DRMGetSignedIssuanceLicense (Ordinal: 612, Address: 0x138d8)
  • DRMGetServiceLocation (Ordinal: 613, Address: 0x13974)
  • DRMCloseEnvironmentHandle (Ordinal: 614, Address: 0x139d8)
  • DRMCloseHandle (Ordinal: 615, Address: 0x13a0c)

Imported DLLs & Functions

ADVAPI32.dll
  • GetSidSubAuthority (Address: 0x543d9058)
  • GetSidSubAuthorityCount (Address: 0x543d9060)
  • GetTokenInformation (Address: 0x543d9050)
  • GetTraceEnableLevel (Address: 0x543d9070)
  • GetTraceLoggerHandle (Address: 0x543d9080)
  • OpenProcessToken (Address: 0x543d9048)
  • RegCloseKey (Address: 0x543d9010)
  • RegCreateKeyExW (Address: 0x543d9038)
  • RegDeleteKeyW (Address: 0x543d9018)
  • RegDeleteValueW (Address: 0x543d9040)
  • RegEnumKeyExW (Address: 0x543d9028)
  • RegisterTraceGuidsW (Address: 0x543d9068)
  • RegOpenKeyExW (Address: 0x543d9000)
  • RegQueryInfoKeyW (Address: 0x543d9020)
  • RegQueryValueExW (Address: 0x543d9008)
  • RegSetValueExW (Address: 0x543d9030)
  • TraceEvent (Address: 0x543d9078)
GDI32.dll
  • BitBlt (Address: 0x543d9090)
  • CreateCompatibleBitmap (Address: 0x543d90a8)
  • CreateCompatibleDC (Address: 0x543d90a0)
  • CreateSolidBrush (Address: 0x543d9098)
  • DeleteDC (Address: 0x543d90b8)
  • DeleteObject (Address: 0x543d90c0)
  • GetDeviceCaps (Address: 0x543d90c8)
  • GetObjectW (Address: 0x543d90d8)
  • GetStockObject (Address: 0x543d90d0)
  • SelectObject (Address: 0x543d90b0)
KERNEL32.dll
  • CloseHandle (Address: 0x543d9160)
  • CreateEventW (Address: 0x543d90f8)
  • CreateFileMappingW (Address: 0x543d9358)
  • CreateFileW (Address: 0x543d9360)
  • CreateMutexW (Address: 0x543d91a8)
  • CreateToolhelp32Snapshot (Address: 0x543d9140)
  • DeleteCriticalSection (Address: 0x543d9240)
  • DeleteTimerQueueTimer (Address: 0x543d93a8)
  • DisableThreadLibraryCalls (Address: 0x543d90e8)
  • EnterCriticalSection (Address: 0x543d9198)
  • ExitProcess (Address: 0x543d9128)
  • FindClose (Address: 0x543d91e8)
  • FindFirstFileW (Address: 0x543d91e0)
  • FindResourceExW (Address: 0x543d9348)
  • FindResourceW (Address: 0x543d9270)
  • FlushInstructionCache (Address: 0x543d9190)
  • FreeLibrary (Address: 0x543d9248)
  • GetACP (Address: 0x543d92e0)
  • GetCurrentProcess (Address: 0x543d9188)
  • GetCurrentProcessId (Address: 0x543d9148)
  • GetCurrentThread (Address: 0x543d9228)
  • GetCurrentThreadId (Address: 0x543d9230)
  • GetLastError (Address: 0x543d9100)
  • GetLocaleInfoA (Address: 0x543d92e8)
  • GetLocaleInfoW (Address: 0x543d9370)
  • GetModuleFileNameW (Address: 0x543d9290)
  • GetModuleHandleW (Address: 0x543d9288)
  • GetProcAddress (Address: 0x543d91c0)
  • GetProcessHeap (Address: 0x543d9320)
  • GetProcessTimes (Address: 0x543d91c8)
  • GetSystemDefaultUILanguage (Address: 0x543d93c0)
  • GetSystemDirectoryW (Address: 0x543d9130)
  • GetSystemTimeAsFileTime (Address: 0x543d91d0)
  • GetThreadContext (Address: 0x543d93a0)
  • GetThreadLocale (Address: 0x543d92f0)
  • GetTickCount (Address: 0x543d92d8)
  • GetUserDefaultLangID (Address: 0x543d91f0)
  • GetUserDefaultUILanguage (Address: 0x543d93b8)
  • GetVersionExA (Address: 0x543d92f8)
  • GetVersionExW (Address: 0x543d9340)
  • GlobalAlloc (Address: 0x543d9120)
  • GlobalLock (Address: 0x543d9180)
  • GlobalUnlock (Address: 0x543d9178)
  • HeapAlloc (Address: 0x543d9318)
  • HeapFree (Address: 0x543d9310)
  • InitializeCriticalSection (Address: 0x543d9238)
  • InterlockedPopEntrySList (Address: 0x543d9338)
  • InterlockedPushEntrySList (Address: 0x543d9300)
  • IsDebuggerPresent (Address: 0x543d92b0)
  • LeaveCriticalSection (Address: 0x543d91a0)
  • LoadLibraryExW (Address: 0x543d9278)
  • LoadLibraryW (Address: 0x543d91d8)
  • LoadResource (Address: 0x543d9268)
  • LocalAlloc (Address: 0x543d9200)
  • LocalFree (Address: 0x543d9208)
  • LockResource (Address: 0x543d9138)
  • lstrcmpiW (Address: 0x543d9250)
  • lstrcmpW (Address: 0x543d9168)
  • lstrlenW (Address: 0x543d9280)
  • MapViewOfFile (Address: 0x543d9350)
  • Module32FirstW (Address: 0x543d9150)
  • Module32NextW (Address: 0x543d9158)
  • MulDiv (Address: 0x543d9170)
  • MultiByteToWideChar (Address: 0x543d9258)
  • OpenProcess (Address: 0x543d91f8)
  • OutputDebugStringW (Address: 0x543d93b0)
  • QueryPerformanceCounter (Address: 0x543d92d0)
  • QueueUserWorkItem (Address: 0x543d9108)
  • RaiseException (Address: 0x543d9110)
  • RegisterWaitForSingleObject (Address: 0x543d9218)
  • ReleaseMutex (Address: 0x543d91b0)
  • ResumeThread (Address: 0x543d9378)
  • RtlCaptureContext (Address: 0x543d92c8)
  • RtlLookupFunctionEntry (Address: 0x543d92c0)
  • RtlVirtualUnwind (Address: 0x543d92b8)
  • SearchPathW (Address: 0x543d93c8)
  • SetEnvironmentVariableW (Address: 0x543d9308)
  • SetEvent (Address: 0x543d90f0)
  • SetLastError (Address: 0x543d9220)
  • SetThreadContext (Address: 0x543d9398)
  • SetUnhandledExceptionFilter (Address: 0x543d92a8)
  • SizeofResource (Address: 0x543d9260)
  • Sleep (Address: 0x543d9298)
  • SuspendThread (Address: 0x543d9380)
  • TerminateProcess (Address: 0x543d9210)
  • UnhandledExceptionFilter (Address: 0x543d92a0)
  • UnmapViewOfFile (Address: 0x543d9368)
  • VirtualAlloc (Address: 0x543d9330)
  • VirtualFree (Address: 0x543d9328)
  • VirtualProtect (Address: 0x543d9388)
  • VirtualQuery (Address: 0x543d9390)
  • WaitForMultipleObjects (Address: 0x543d91b8)
  • WaitForSingleObject (Address: 0x543d9118)
mscoree.dll
  • CorBindToRuntimeEx (Address: 0x543d9888)
MSVCR80.dll
  • __C_specific_handler (Address: 0x543d9478)
  • __clean_type_info_names_internal (Address: 0x543d9410)
  • __CppXcptFilter (Address: 0x543d9420)
  • __crt_debugger_hook (Address: 0x543d9418)
  • __dllonexit (Address: 0x543d9468)
  • _amsg_exit (Address: 0x543d9428)
  • _beginthreadex (Address: 0x543d94b0)
  • _callnewh (Address: 0x543d9510)
  • _CxxThrowException (Address: 0x543d93f0)
  • _decode_pointer (Address: 0x543d9448)
  • _encode_pointer (Address: 0x543d9460)
  • _encoded_null (Address: 0x543d9518)
  • _initterm (Address: 0x543d9438)
  • _initterm_e (Address: 0x543d9430)
  • _lock (Address: 0x543d9458)
  • _malloc_crt (Address: 0x543d9440)
  • _onexit (Address: 0x543d9450)
  • _purecall (Address: 0x543d94b8)
  • _recalloc (Address: 0x543d94c0)
  • _ultow_s (Address: 0x543d9488)
  • _unlock (Address: 0x543d9470)
  • _vsnwprintf (Address: 0x543d9520)
  • _wcsicmp (Address: 0x543d94f0)
  • _wcslwr_s (Address: 0x543d9480)
  • _wcsnicmp (Address: 0x543d94d8)
  • ?_type_info_dtor_internal_method@type_info@@QEAAXXZ (Address: 0x543d9408)
  • ??_V@YAXPEAX@Z (Address: 0x543d94f8)
  • ??3@YAXPEAX@Z (Address: 0x543d9500)
  • ?terminate@@YAXXZ (Address: 0x543d9400)
  • bsearch (Address: 0x543d93e8)
  • free (Address: 0x543d94d0)
  • malloc (Address: 0x543d9508)
  • memcmp (Address: 0x543d94c8)
  • memcpy (Address: 0x543d93e0)
  • memcpy_s (Address: 0x543d94e0)
  • memset (Address: 0x543d93d8)
  • swprintf_s (Address: 0x543d9490)
  • wcschr (Address: 0x543d9498)
  • wcscpy_s (Address: 0x543d93f8)
  • wcsncmp (Address: 0x543d94a8)
  • wcsncpy_s (Address: 0x543d94e8)
  • wcsstr (Address: 0x543d94a0)
ole32.dll
  • CLSIDFromProgID (Address: 0x543d98e8)
  • CLSIDFromString (Address: 0x543d98e0)
  • CoAllowSetForegroundWindow (Address: 0x543d98c8)
  • CoCreateInstance (Address: 0x543d9930)
  • CoGetClassObject (Address: 0x543d9898)
  • CoMarshalInterThreadInterfaceInStream (Address: 0x543d9910)
  • CoReleaseMarshalData (Address: 0x543d98d0)
  • CoTaskMemAlloc (Address: 0x543d98a8)
  • CoTaskMemFree (Address: 0x543d9918)
  • CoTaskMemRealloc (Address: 0x543d98a0)
  • CoUnmarshalInterface (Address: 0x543d9928)
  • CreateBindCtx (Address: 0x543d98b0)
  • CreateStreamOnHGlobal (Address: 0x543d9900)
  • OleCreateMenuDescriptor (Address: 0x543d98c0)
  • OleDestroyMenuDescriptor (Address: 0x543d98b8)
  • OleInitialize (Address: 0x543d9908)
  • OleLockRunning (Address: 0x543d98f0)
  • OleTranslateAccelerator (Address: 0x543d9920)
  • OleUninitialize (Address: 0x543d98d8)
  • StringFromGUID2 (Address: 0x543d98f8)
OLEAUT32.dll
  • DispCallFunc (Address: 0x543d9568)
  • LoadRegTypeLib (Address: 0x543d9558)
  • LoadTypeLib (Address: 0x543d9550)
  • OleCreateFontIndirect (Address: 0x543d9560)
  • SysAllocString (Address: 0x543d9598)
  • SysAllocStringByteLen (Address: 0x543d9578)
  • SysAllocStringLen (Address: 0x543d9540)
  • SysFreeString (Address: 0x543d9590)
  • SysStringByteLen (Address: 0x543d9548)
  • SysStringLen (Address: 0x543d9588)
  • VariantClear (Address: 0x543d9570)
  • VariantCopy (Address: 0x543d9538)
  • VariantInit (Address: 0x543d9530)
  • VarUI4FromStr (Address: 0x543d9580)
PSAPI.DLL
  • GetMappedFileNameW (Address: 0x543d95a8)
SHELL32.dll
  • SHGetFolderPathW (Address: 0x543d95b8)
SHLWAPI.dll
  • PathCombineW (Address: 0x543d95c8)
urlmon.dll
  • CoInternetParseUrl (Address: 0x543d9950)
  • CompareSecurityIds (Address: 0x543d9960)
  • CreateURLMoniker (Address: 0x543d9958)
  • UrlMkGetSessionOption (Address: 0x543d9940)
  • URLOpenBlockingStreamW (Address: 0x543d9948)
USER32.dll
  • BeginPaint (Address: 0x543d97c8)
  • CallWindowProcW (Address: 0x543d96f8)
  • CharNextW (Address: 0x543d95f8)
  • CheckMenuItem (Address: 0x543d9640)
  • ClientToScreen (Address: 0x543d9838)
  • CreateAcceleratorTableW (Address: 0x543d9830)
  • CreateMenu (Address: 0x543d96c8)
  • CreateWindowExW (Address: 0x543d9710)
  • DefWindowProcW (Address: 0x543d9630)
  • DestroyAcceleratorTable (Address: 0x543d97b8)
  • DestroyMenu (Address: 0x543d96a0)
  • DestroyWindow (Address: 0x543d9658)
  • DispatchMessageW (Address: 0x543d9618)
  • EnableMenuItem (Address: 0x543d9688)
  • EndPaint (Address: 0x543d97d8)
  • FillRect (Address: 0x543d97d0)
  • GetClassInfoExW (Address: 0x543d9750)
  • GetClassInfoW (Address: 0x543d9670)
  • GetClassNameW (Address: 0x543d9648)
  • GetClientRect (Address: 0x543d9708)
  • GetDC (Address: 0x543d97e0)
  • GetDesktopWindow (Address: 0x543d9740)
  • GetDlgItem (Address: 0x543d9808)
  • GetFocus (Address: 0x543d97f8)
  • GetKeyState (Address: 0x543d9628)
  • GetMenuItemCount (Address: 0x543d95e0)
  • GetMenuItemID (Address: 0x543d95f0)
  • GetMenuItemInfoW (Address: 0x543d9690)
  • GetMenuStringW (Address: 0x543d96c0)
  • GetMessageExtraInfo (Address: 0x543d9600)
  • GetMessageW (Address: 0x543d9778)
  • GetParent (Address: 0x543d9820)
  • GetSubMenu (Address: 0x543d95e8)
  • GetSysColor (Address: 0x543d97c0)
  • GetWindow (Address: 0x543d9660)
  • GetWindowLongPtrW (Address: 0x543d9738)
  • GetWindowLongW (Address: 0x543d97a8)
  • GetWindowTextLengthW (Address: 0x543d9790)
  • GetWindowTextW (Address: 0x543d9798)
  • GetWindowThreadProcessId (Address: 0x543d9668)
  • InsertMenuW (Address: 0x543d96b8)
  • InvalidateRect (Address: 0x543d9758)
  • InvalidateRgn (Address: 0x543d9748)
  • IsChild (Address: 0x543d97f0)
  • IsWindow (Address: 0x543d9800)
  • KillTimer (Address: 0x543d96d0)
  • LoadCursorW (Address: 0x543d95d8)
  • LoadMenuW (Address: 0x543d96b0)
  • LoadStringW (Address: 0x543d9698)
  • MessageBoxW (Address: 0x543d96f0)
  • MoveWindow (Address: 0x543d9730)
  • MsgWaitForMultipleObjects (Address: 0x543d9608)
  • PeekMessageW (Address: 0x543d9610)
  • PostMessageW (Address: 0x543d9638)
  • PostThreadMessageW (Address: 0x543d9728)
  • RedrawWindow (Address: 0x543d9818)
  • RegisterClassExW (Address: 0x543d9678)
  • RegisterClassW (Address: 0x543d9700)
  • RegisterRawInputDevices (Address: 0x543d96d8)
  • RegisterWindowMessageW (Address: 0x543d9788)
  • ReleaseCapture (Address: 0x543d9760)
  • ReleaseDC (Address: 0x543d97e8)
  • RemoveMenu (Address: 0x543d96a8)
  • ScreenToClient (Address: 0x543d9770)
  • SendMessageW (Address: 0x543d9810)
  • SetCapture (Address: 0x543d9768)
  • SetFocus (Address: 0x543d9718)
  • SetMessageExtraInfo (Address: 0x543d9620)
  • SetParent (Address: 0x543d96e8)
  • SetTimer (Address: 0x543d9780)
  • SetWindowLongPtrW (Address: 0x543d96e0)
  • SetWindowLongW (Address: 0x543d97b0)
  • SetWindowPos (Address: 0x543d9828)
  • SetWindowTextW (Address: 0x543d97a0)
  • ShowWindow (Address: 0x543d9720)
  • TranslateMessage (Address: 0x543d9650)
  • UnregisterClassA (Address: 0x543d9680)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x543d9858)
  • GetFileVersionInfoW (Address: 0x543d9850)
  • VerQueryValueW (Address: 0x543d9848)
WININET.dll
  • InternetErrorDlg (Address: 0x543d9868)
  • InternetGetCookieExW (Address: 0x543d9878)
  • InternetSetCookieExW (Address: 0x543d9870)