IEShims.dll

Description: Internet Explorer Compatibility Shims

Authors: © Microsoft Corporation. All rights reserved.

Version: 11.0.19041.5794

Architecture: 32-bit

Operating System: Windows NT

SHA256: 2a8016f99238a3da5a296452e9986260

File Size: 333.0 KB

Uploaded At: Dec. 1, 2025, 8:33 a.m.

Views: 18

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • AcRedirNotify (Ordinal: 1, Address: 0x29dc0)
  • AcRedirNotifySetEnabled (Ordinal: 2, Address: 0x29e10)
  • AcRedirSetEnabled (Ordinal: 3, Address: 0x29e30)
  • IEShims_AdminCheckAndLaunch (Ordinal: 4, Address: 0x17240)
  • IEShims_CreateWindowEx (Ordinal: 5, Address: 0x1a700)
  • IEShims_GetOriginatingThreadId (Ordinal: 6, Address: 0x21e90)
  • IEShims_InDllMainContext (Ordinal: 7, Address: 0x1ade0)
  • IEShims_Initialize (Ordinal: 8, Address: 0x1ae00)
  • IEShims_SetRedirectRegistryForThread (Ordinal: 9, Address: 0x1aec0)
  • IEShims_Uninitialize (Ordinal: 10, Address: 0xe060)

Imported DLLs & Functions

api-ms-win-downlevel-advapi32-l1-1-0.dll
  • RegCloseKey (Address: 0x100481b8)
  • RegCreateKeyExW (Address: 0x100481c8)
  • RegEnumKeyExW (Address: 0x100481d4)
  • RegEnumValueW (Address: 0x100481cc)
  • RegGetValueW (Address: 0x100481c0)
  • RegOpenKeyExW (Address: 0x100481b4)
  • RegQueryInfoKeyW (Address: 0x100481d0)
  • RegQueryValueExW (Address: 0x100481bc)
  • RegSetValueExW (Address: 0x100481c4)
api-ms-win-downlevel-shlwapi-l1-1-0.dll
  • PathFindFileNameW (Address: 0x10048200)
  • PathGetArgsW (Address: 0x10048208)
  • PathIsUNCW (Address: 0x100481e8)
  • PathSkipRootW (Address: 0x100481e4)
  • StrCmpCW (Address: 0x100481ec)
  • StrCmpICA (Address: 0x100481f0)
  • StrCmpICW (Address: 0x100481fc)
  • StrCmpIW (Address: 0x10048204)
  • StrCmpNCW (Address: 0x100481e0)
  • StrCmpNIA (Address: 0x100481dc)
  • StrCmpNICW (Address: 0x100481f8)
  • StrDupW (Address: 0x100481f4)
iertutil.dll
  • (Address: 0x10048210)
  • (Address: 0x10048214)
  • (Address: 0x10048218)
  • (Address: 0x1004821c)
  • (Address: 0x10048220)
  • (Address: 0x10048224)
  • (Address: 0x10048228)
  • (Address: 0x1004822c)
  • (Address: 0x10048230)
  • (Address: 0x10048234)
  • (Address: 0x10048238)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x10048144)
  • AcquireSRWLockShared (Address: 0x1004814c)
  • CloseHandle (Address: 0x10048154)
  • CloseThreadpoolTimer (Address: 0x10048168)
  • CopyFileExW (Address: 0x10048078)
  • CreateDirectoryW (Address: 0x10048088)
  • CreateFileMappingW (Address: 0x10048020)
  • CreateFileW (Address: 0x100480b0)
  • CreateMutexExW (Address: 0x10048188)
  • CreateMutexW (Address: 0x10048038)
  • CreateSemaphoreExW (Address: 0x10048000)
  • CreateThreadpoolTimer (Address: 0x10048184)
  • DebugBreak (Address: 0x10048134)
  • DecodePointer (Address: 0x100480b4)
  • DelayLoadFailureHook (Address: 0x10048004)
  • DeleteCriticalSection (Address: 0x10048178)
  • DeleteProcThreadAttributeList (Address: 0x100481ac)
  • DeviceIoControl (Address: 0x10048080)
  • DuplicateHandle (Address: 0x10048074)
  • EncodePointer (Address: 0x10048090)
  • EnterCriticalSection (Address: 0x10048170)
  • ExitThread (Address: 0x100480fc)
  • ExpandEnvironmentStringsW (Address: 0x1004812c)
  • FindClose (Address: 0x10048094)
  • FindFirstFileW (Address: 0x1004809c)
  • FindNextFileW (Address: 0x10048098)
  • FormatMessageW (Address: 0x10048114)
  • GetCurrentDirectoryW (Address: 0x100480d8)
  • GetCurrentProcess (Address: 0x10048070)
  • GetCurrentProcessId (Address: 0x100480ec)
  • GetCurrentThreadId (Address: 0x100480b8)
  • GetEnvironmentVariableW (Address: 0x10048128)
  • GetFileAttributesW (Address: 0x100480c8)
  • GetFileInformationByHandle (Address: 0x10048084)
  • GetFileSizeEx (Address: 0x100480ac)
  • GetFullPathNameW (Address: 0x10048124)
  • GetLastError (Address: 0x100480f4)
  • GetLogicalDriveStringsW (Address: 0x10048014)
  • GetLongPathNameW (Address: 0x10048120)
  • GetModuleFileNameA (Address: 0x10048130)
  • GetModuleFileNameW (Address: 0x100480c0)
  • GetModuleHandleA (Address: 0x10048068)
  • GetModuleHandleExW (Address: 0x100480bc)
  • GetModuleHandleW (Address: 0x10048138)
  • GetProcAddress (Address: 0x100480e8)
  • GetProcessHeap (Address: 0x1004810c)
  • GetProcessId (Address: 0x100480f0)
  • GetProcessIdOfThread (Address: 0x10048100)
  • GetSystemDirectoryW (Address: 0x10048118)
  • GetSystemTimeAsFileTime (Address: 0x10048048)
  • GetThreadId (Address: 0x10048104)
  • GetTickCount (Address: 0x10048044)
  • GetTickCount64 (Address: 0x10048030)
  • GetWindowsDirectoryW (Address: 0x1004811c)
  • HeapAlloc (Address: 0x10048108)
  • HeapFree (Address: 0x10048110)
  • InitializeCriticalSection (Address: 0x1004803c)
  • InitializeCriticalSectionAndSpinCount (Address: 0x10048198)
  • InitializeCriticalSectionEx (Address: 0x10048174)
  • InitializeProcThreadAttributeList (Address: 0x100481a8)
  • InitializeSRWLock (Address: 0x10048040)
  • IsDebuggerPresent (Address: 0x1004813c)
  • IsWow64Process (Address: 0x1004802c)
  • LeaveCriticalSection (Address: 0x1004818c)
  • LoadLibraryA (Address: 0x10048194)
  • LocalAlloc (Address: 0x100480d0)
  • LocalFree (Address: 0x100480dc)
  • lstrcmpiW (Address: 0x1004808c)
  • MapViewOfFile (Address: 0x1004801c)
  • MultiByteToWideChar (Address: 0x100480e0)
  • OpenEventW (Address: 0x100481a4)
  • OpenFileMappingW (Address: 0x10048028)
  • OpenProcess (Address: 0x10048034)
  • OpenSemaphoreW (Address: 0x10048180)
  • OutputDebugStringA (Address: 0x10048064)
  • OutputDebugStringW (Address: 0x10048140)
  • QueryDosDeviceW (Address: 0x10048018)
  • QueryFullProcessImageNameW (Address: 0x10048010)
  • QueryPerformanceCounter (Address: 0x1004804c)
  • RaiseException (Address: 0x1004800c)
  • RaiseFailFastException (Address: 0x100480a8)
  • ReleaseMutex (Address: 0x1004815c)
  • ReleaseSemaphore (Address: 0x10048158)
  • ReleaseSRWLockExclusive (Address: 0x10048148)
  • ReleaseSRWLockShared (Address: 0x10048150)
  • ResolveDelayLoadedAPI (Address: 0x10048008)
  • SearchPathW (Address: 0x100480c4)
  • SetEnvironmentVariableW (Address: 0x1004806c)
  • SetFileAttributesW (Address: 0x1004807c)
  • SetLastError (Address: 0x100480cc)
  • SetThreadpoolTimer (Address: 0x10048160)
  • SetUnhandledExceptionFilter (Address: 0x10048058)
  • Sleep (Address: 0x10048060)
  • SleepConditionVariableSRW (Address: 0x10048050)
  • TerminateProcess (Address: 0x10048190)
  • TlsAlloc (Address: 0x100481a0)
  • TlsFree (Address: 0x100480a0)
  • TlsGetValue (Address: 0x1004819c)
  • TlsSetValue (Address: 0x100480f8)
  • UnhandledExceptionFilter (Address: 0x1004805c)
  • UnmapViewOfFile (Address: 0x10048024)
  • VirtualProtect (Address: 0x100480a4)
  • VirtualQuery (Address: 0x100480d4)
  • WaitForSingleObject (Address: 0x1004817c)
  • WaitForSingleObjectEx (Address: 0x1004816c)
  • WaitForThreadpoolTimerCallbacks (Address: 0x10048164)
  • WakeAllConditionVariable (Address: 0x10048054)
  • WideCharToMultiByte (Address: 0x100480e4)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x100482e8)
  • __dllonexit (Address: 0x100482d8)
  • _amsg_exit (Address: 0x10048250)
  • _CxxThrowException (Address: 0x10048268)
  • _except_handler4_common (Address: 0x100482e0)
  • _initterm (Address: 0x10048294)
  • _lock (Address: 0x10048284)
  • _onexit (Address: 0x100482dc)
  • _stricmp (Address: 0x10048244)
  • _unlock (Address: 0x100482d4)
  • _vscwprintf (Address: 0x10048298)
  • _vsnprintf_s (Address: 0x10048280)
  • _vsnwprintf (Address: 0x10048288)
  • _wcsicmp (Address: 0x10048270)
  • _wcslwr (Address: 0x1004829c)
  • _wcsnicmp (Address: 0x100482cc)
  • _wfopen (Address: 0x10048254)
  • _XcptFilter (Address: 0x1004824c)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x10048274)
  • ??0exception@@QAE@XZ (Address: 0x1004827c)
  • ??1exception@@UAE@XZ (Address: 0x10048278)
  • ??1type_info@@UAE@XZ (Address: 0x10048260)
  • ?terminate@@YAXXZ (Address: 0x10048258)
  • calloc (Address: 0x10048248)
  • fclose (Address: 0x10048240)
  • fputws (Address: 0x1004825c)
  • free (Address: 0x100482c0)
  • iswctype (Address: 0x100482b0)
  • iswspace (Address: 0x100482c8)
  • malloc (Address: 0x100482d0)
  • memcmp (Address: 0x10048264)
  • memcpy_s (Address: 0x100482b8)
  • memmove (Address: 0x100482e4)
  • memmove_s (Address: 0x100482a8)
  • memset (Address: 0x100482ec)
  • realloc (Address: 0x100482bc)
  • towlower (Address: 0x100482ac)
  • wcschr (Address: 0x100482a4)
  • wcsncmp (Address: 0x1004826c)
  • wcspbrk (Address: 0x100482a0)
  • wcsrchr (Address: 0x10048290)
  • wcsspn (Address: 0x100482b4)
  • wcsstr (Address: 0x1004828c)
  • wcstok_s (Address: 0x100482c4)
ntdll.dll
  • NtQueryObject (Address: 0x100482f8)
  • RtlNtStatusToDosError (Address: 0x100482f4)