IEShims.dll
Description: Internet Explorer Compatibility Shims
Authors: © Microsoft Corporation. All rights reserved.
Version: 11.0.19041.5794
Architecture: 32-bit
Operating System: Windows NT
SHA256: 2a8016f99238a3da5a296452e9986260
File Size: 333.0 KB
Uploaded At: Dec. 1, 2025, 8:33 a.m.
Views: 18
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- AcRedirNotify (Ordinal: 1, Address: 0x29dc0)
- AcRedirNotifySetEnabled (Ordinal: 2, Address: 0x29e10)
- AcRedirSetEnabled (Ordinal: 3, Address: 0x29e30)
- IEShims_AdminCheckAndLaunch (Ordinal: 4, Address: 0x17240)
- IEShims_CreateWindowEx (Ordinal: 5, Address: 0x1a700)
- IEShims_GetOriginatingThreadId (Ordinal: 6, Address: 0x21e90)
- IEShims_InDllMainContext (Ordinal: 7, Address: 0x1ade0)
- IEShims_Initialize (Ordinal: 8, Address: 0x1ae00)
- IEShims_SetRedirectRegistryForThread (Ordinal: 9, Address: 0x1aec0)
- IEShims_Uninitialize (Ordinal: 10, Address: 0xe060)
Imported DLLs & Functions
api-ms-win-downlevel-advapi32-l1-1-0.dll
- RegCloseKey (Address: 0x100481b8)
- RegCreateKeyExW (Address: 0x100481c8)
- RegEnumKeyExW (Address: 0x100481d4)
- RegEnumValueW (Address: 0x100481cc)
- RegGetValueW (Address: 0x100481c0)
- RegOpenKeyExW (Address: 0x100481b4)
- RegQueryInfoKeyW (Address: 0x100481d0)
- RegQueryValueExW (Address: 0x100481bc)
- RegSetValueExW (Address: 0x100481c4)
api-ms-win-downlevel-shlwapi-l1-1-0.dll
- PathFindFileNameW (Address: 0x10048200)
- PathGetArgsW (Address: 0x10048208)
- PathIsUNCW (Address: 0x100481e8)
- PathSkipRootW (Address: 0x100481e4)
- StrCmpCW (Address: 0x100481ec)
- StrCmpICA (Address: 0x100481f0)
- StrCmpICW (Address: 0x100481fc)
- StrCmpIW (Address: 0x10048204)
- StrCmpNCW (Address: 0x100481e0)
- StrCmpNIA (Address: 0x100481dc)
- StrCmpNICW (Address: 0x100481f8)
- StrDupW (Address: 0x100481f4)
iertutil.dll
- (Address: 0x10048210)
- (Address: 0x10048214)
- (Address: 0x10048218)
- (Address: 0x1004821c)
- (Address: 0x10048220)
- (Address: 0x10048224)
- (Address: 0x10048228)
- (Address: 0x1004822c)
- (Address: 0x10048230)
- (Address: 0x10048234)
- (Address: 0x10048238)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x10048144)
- AcquireSRWLockShared (Address: 0x1004814c)
- CloseHandle (Address: 0x10048154)
- CloseThreadpoolTimer (Address: 0x10048168)
- CopyFileExW (Address: 0x10048078)
- CreateDirectoryW (Address: 0x10048088)
- CreateFileMappingW (Address: 0x10048020)
- CreateFileW (Address: 0x100480b0)
- CreateMutexExW (Address: 0x10048188)
- CreateMutexW (Address: 0x10048038)
- CreateSemaphoreExW (Address: 0x10048000)
- CreateThreadpoolTimer (Address: 0x10048184)
- DebugBreak (Address: 0x10048134)
- DecodePointer (Address: 0x100480b4)
- DelayLoadFailureHook (Address: 0x10048004)
- DeleteCriticalSection (Address: 0x10048178)
- DeleteProcThreadAttributeList (Address: 0x100481ac)
- DeviceIoControl (Address: 0x10048080)
- DuplicateHandle (Address: 0x10048074)
- EncodePointer (Address: 0x10048090)
- EnterCriticalSection (Address: 0x10048170)
- ExitThread (Address: 0x100480fc)
- ExpandEnvironmentStringsW (Address: 0x1004812c)
- FindClose (Address: 0x10048094)
- FindFirstFileW (Address: 0x1004809c)
- FindNextFileW (Address: 0x10048098)
- FormatMessageW (Address: 0x10048114)
- GetCurrentDirectoryW (Address: 0x100480d8)
- GetCurrentProcess (Address: 0x10048070)
- GetCurrentProcessId (Address: 0x100480ec)
- GetCurrentThreadId (Address: 0x100480b8)
- GetEnvironmentVariableW (Address: 0x10048128)
- GetFileAttributesW (Address: 0x100480c8)
- GetFileInformationByHandle (Address: 0x10048084)
- GetFileSizeEx (Address: 0x100480ac)
- GetFullPathNameW (Address: 0x10048124)
- GetLastError (Address: 0x100480f4)
- GetLogicalDriveStringsW (Address: 0x10048014)
- GetLongPathNameW (Address: 0x10048120)
- GetModuleFileNameA (Address: 0x10048130)
- GetModuleFileNameW (Address: 0x100480c0)
- GetModuleHandleA (Address: 0x10048068)
- GetModuleHandleExW (Address: 0x100480bc)
- GetModuleHandleW (Address: 0x10048138)
- GetProcAddress (Address: 0x100480e8)
- GetProcessHeap (Address: 0x1004810c)
- GetProcessId (Address: 0x100480f0)
- GetProcessIdOfThread (Address: 0x10048100)
- GetSystemDirectoryW (Address: 0x10048118)
- GetSystemTimeAsFileTime (Address: 0x10048048)
- GetThreadId (Address: 0x10048104)
- GetTickCount (Address: 0x10048044)
- GetTickCount64 (Address: 0x10048030)
- GetWindowsDirectoryW (Address: 0x1004811c)
- HeapAlloc (Address: 0x10048108)
- HeapFree (Address: 0x10048110)
- InitializeCriticalSection (Address: 0x1004803c)
- InitializeCriticalSectionAndSpinCount (Address: 0x10048198)
- InitializeCriticalSectionEx (Address: 0x10048174)
- InitializeProcThreadAttributeList (Address: 0x100481a8)
- InitializeSRWLock (Address: 0x10048040)
- IsDebuggerPresent (Address: 0x1004813c)
- IsWow64Process (Address: 0x1004802c)
- LeaveCriticalSection (Address: 0x1004818c)
- LoadLibraryA (Address: 0x10048194)
- LocalAlloc (Address: 0x100480d0)
- LocalFree (Address: 0x100480dc)
- lstrcmpiW (Address: 0x1004808c)
- MapViewOfFile (Address: 0x1004801c)
- MultiByteToWideChar (Address: 0x100480e0)
- OpenEventW (Address: 0x100481a4)
- OpenFileMappingW (Address: 0x10048028)
- OpenProcess (Address: 0x10048034)
- OpenSemaphoreW (Address: 0x10048180)
- OutputDebugStringA (Address: 0x10048064)
- OutputDebugStringW (Address: 0x10048140)
- QueryDosDeviceW (Address: 0x10048018)
- QueryFullProcessImageNameW (Address: 0x10048010)
- QueryPerformanceCounter (Address: 0x1004804c)
- RaiseException (Address: 0x1004800c)
- RaiseFailFastException (Address: 0x100480a8)
- ReleaseMutex (Address: 0x1004815c)
- ReleaseSemaphore (Address: 0x10048158)
- ReleaseSRWLockExclusive (Address: 0x10048148)
- ReleaseSRWLockShared (Address: 0x10048150)
- ResolveDelayLoadedAPI (Address: 0x10048008)
- SearchPathW (Address: 0x100480c4)
- SetEnvironmentVariableW (Address: 0x1004806c)
- SetFileAttributesW (Address: 0x1004807c)
- SetLastError (Address: 0x100480cc)
- SetThreadpoolTimer (Address: 0x10048160)
- SetUnhandledExceptionFilter (Address: 0x10048058)
- Sleep (Address: 0x10048060)
- SleepConditionVariableSRW (Address: 0x10048050)
- TerminateProcess (Address: 0x10048190)
- TlsAlloc (Address: 0x100481a0)
- TlsFree (Address: 0x100480a0)
- TlsGetValue (Address: 0x1004819c)
- TlsSetValue (Address: 0x100480f8)
- UnhandledExceptionFilter (Address: 0x1004805c)
- UnmapViewOfFile (Address: 0x10048024)
- VirtualProtect (Address: 0x100480a4)
- VirtualQuery (Address: 0x100480d4)
- WaitForSingleObject (Address: 0x1004817c)
- WaitForSingleObjectEx (Address: 0x1004816c)
- WaitForThreadpoolTimerCallbacks (Address: 0x10048164)
- WakeAllConditionVariable (Address: 0x10048054)
- WideCharToMultiByte (Address: 0x100480e4)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x100482e8)
- __dllonexit (Address: 0x100482d8)
- _amsg_exit (Address: 0x10048250)
- _CxxThrowException (Address: 0x10048268)
- _except_handler4_common (Address: 0x100482e0)
- _initterm (Address: 0x10048294)
- _lock (Address: 0x10048284)
- _onexit (Address: 0x100482dc)
- _stricmp (Address: 0x10048244)
- _unlock (Address: 0x100482d4)
- _vscwprintf (Address: 0x10048298)
- _vsnprintf_s (Address: 0x10048280)
- _vsnwprintf (Address: 0x10048288)
- _wcsicmp (Address: 0x10048270)
- _wcslwr (Address: 0x1004829c)
- _wcsnicmp (Address: 0x100482cc)
- _wfopen (Address: 0x10048254)
- _XcptFilter (Address: 0x1004824c)
- ??0exception@@QAE@ABV0@@Z (Address: 0x10048274)
- ??0exception@@QAE@XZ (Address: 0x1004827c)
- ??1exception@@UAE@XZ (Address: 0x10048278)
- ??1type_info@@UAE@XZ (Address: 0x10048260)
- ?terminate@@YAXXZ (Address: 0x10048258)
- calloc (Address: 0x10048248)
- fclose (Address: 0x10048240)
- fputws (Address: 0x1004825c)
- free (Address: 0x100482c0)
- iswctype (Address: 0x100482b0)
- iswspace (Address: 0x100482c8)
- malloc (Address: 0x100482d0)
- memcmp (Address: 0x10048264)
- memcpy_s (Address: 0x100482b8)
- memmove (Address: 0x100482e4)
- memmove_s (Address: 0x100482a8)
- memset (Address: 0x100482ec)
- realloc (Address: 0x100482bc)
- towlower (Address: 0x100482ac)
- wcschr (Address: 0x100482a4)
- wcsncmp (Address: 0x1004826c)
- wcspbrk (Address: 0x100482a0)
- wcsrchr (Address: 0x10048290)
- wcsspn (Address: 0x100482b4)
- wcsstr (Address: 0x1004828c)
- wcstok_s (Address: 0x100482c4)
ntdll.dll
- NtQueryObject (Address: 0x100482f8)
- RtlNtStatusToDosError (Address: 0x100482f4)