File details
File name: explorer.exe
Name: Windows Explorer
Description: Microsoft® Windows® Operating System
Version: 6.3.9600.16384 (winblue_rtm.130821-1623)
Product version: 6.3.9600.16384
Size: 2.22 MB
Original file name: EXPLORER.EXE.MUI
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 7/9/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0125711174%
Privileged CPU:
0.0077134231%

User CPU:
0.00485769434232%

Privileged CPU time: 26289.06 ms
Privileged CPU time /min: 0 ms
CPU cycle count:
182,288,695
Context switches /sec:
230
 | Memory utilization averages |
Committed memory:
973.71 MB
Peak committed memory: 1.08 GB
Paged memory:
98.56 MB
Peak paged memory: 121.64 MB
Paged system memory:
1.52 MB
Non-paged system memory: 205.45 KB
Working set memory:
146.88 MB
Peak working set memory: 162.19 MB
Min working set memory: 86.31 MB
Private memory:
98.56 MB
Page faults:
489,731
Page faults /min: 0
 | Process I/O averages |
Total read operations:
5,305
Total read transfer: 19.91 MB
Total write operations:
442
Total write transfer: 2.63 MB
Total other operations:
111,462
Total other transfer: 7.43 MB
 | GUI Object Averages |
GDI objects:
324
Peak GDI objects: 644
USER objects:
319
Peak USER objects: 544
Resources
Handle count average: 2,160
Thread count average: 139
Thread resource averages
windows.immersiveshell.serviceprovider.dll

Total CPU: 0.190302301925%
Privileged CPU: 0.112696806805%
User CPU: 0.077605495120%
CPU Cycle count /sec: 7,688,832
Context switches /sec: 82
Module memory size: 116 KB
Total CPU: 0.163792793447%
Privileged CPU: 0.087689525404%
User CPU: 0.076103268043%
CPU Cycle count /sec: 5,580,786
Context switches /sec: 17
Module memory size: 2.21 MB
Total CPU: 0.102829769938%
Privileged CPU: 0.072904078377%
User CPU: 0.029925691561%
CPU Cycle count /sec: 3,475,598
Context switches /sec: 66
Module memory size: 244 KB
van.dll

Total CPU: 0.087236110672%
Privileged CPU: 0.033622250988%
User CPU: 0.053613859684%
CPU Cycle count /sec: 2,595,327
Context switches /sec: 9
Module memory size: 496 KB
ntdll.dll

Total CPU: 0.025482960650%
Privileged CPU: 0.017702600706%
User CPU: 0.007780359944%
CPU Cycle count /sec: 513,808
Context switches /sec: 1
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.010355593005%
Privileged CPU: 0.004436436580%
User CPU: 0.005919156425%
CPU Cycle count /sec: 303,320
Context switches /sec: 1
Module memory size: 1.66 MB
shcore.dll

Total CPU: 0.010035162921%
Privileged CPU: 0.005817533094%
User CPU: 0.004217629827%
CPU Cycle count /sec: 945,564
Context switches /sec: 7
Module memory size: 644 KB
combase.dll

Total CPU: 0.003593414378%
Privileged CPU: 0.001197804793%
User CPU: 0.002395609585%
CPU Cycle count /sec: 76,326
Module memory size: 1.84 MB
combase.dll

Total CPU: 0.002221323745%
Privileged CPU: 0.000317331964%
User CPU: 0.001903991781%
CPU Cycle count /sec: 63,975
Module memory size: 1.84 MB
twinui.dll

Total CPU: 0.001156440947%
Privileged CPU: 0.000770960631%
User CPU: 0.000385480316%
CPU Cycle count /sec: 23,118
Module memory size: 12.63 MB
mswsock.dll

Total CPU: 0.001051038913%
Privileged CPU: 0.001051038913%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,765
Module memory size: 352 KB
clr.dll

Total CPU: 0.000719666220%
Privileged CPU: 0.000719666220%
User CPU: 0.000000000000%
CPU Cycle count /sec: 2,185
Module memory size: 9.59 MB
windows.ui.xaml.dll

Total CPU: 0.000635247407%
Privileged CPU: 0.000317623704%
User CPU: 0.000317623704%
CPU Cycle count /sec: 21,760
Module memory size: 17.73 MB
wlidprov.dll

Total CPU: 0.000598984587%
Privileged CPU: 0.000000000000%
User CPU: 0.000598984587%
CPU Cycle count /sec: 374
Module memory size: 384 KB
sppc.dll

Total CPU: 0.000598805729%
Privileged CPU: 0.000598805729%
User CPU: 0.000000000000%
CPU Cycle count /sec: 1,061
Module memory size: 136 KB
dui70.dll

Total CPU: 0.000458143701%
Privileged CPU: 0.000000000000%
User CPU: 0.000458143701%
CPU Cycle count /sec: 8,838
Module memory size: 1.67 MB
winmm.dll

Total CPU: 0.000335748646%
Privileged CPU: 0.000000000000%
User CPU: 0.000335748646%
CPU Cycle count /sec: 7,013
Module memory size: 124 KB
uxtheme.dll

Total CPU: 0.000317379638%
Privileged CPU: 0.000317379638%
User CPU: 0.000000000000%
CPU Cycle count /sec: 10,654
Module memory size: 1.13 MB
Total CPU: 0.000317061900%
Privileged CPU: 0.000317061900%
User CPU: 0.000000000000%
CPU Cycle count /sec: 169,648
Context switches /sec: 1
Module memory size: 880 KB
Process details
Runs as (owner): User
Integrety level: Medium
Windows platform: 64-bit
System Tray: Yes
Process Command
C:\Windows\Explorer.EXE
Shell open command details
Name: SHCmdFile
Command: C:\Windows\explorer.exe
Autoplay handler details
Name: MSOpenFolderBackup
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSOpenFolderBackup
Scheduled task details
CLSID: {AD36F1D3-E56E-44BA-A569-280718EB8C51}
Command: \{AD36F1D3-E56E-44BA-A569-280718EB8C51}
Network connectivity
TCP: db3wns2011113.wns.windows.com on port 49195
TCP: localhost on port 49158
Image hashes
MD5: 8479dc46e9a09015c0777a16bc22a15d
SHA-1: 69a663e65333f5f2b5f4f66e2bd33c61d008a2e6
PE image details
Langauge*: Microsoft Visual C++
File entropy: 5.93423
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegCreateKeyW
RegGetValueW
RegOpenKeyExW
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
RegCreateKeyExW
RegQueryValueExW
EventRegister
EventUnregister
EventWrite
EventEnabled
GetLengthSid
GetTokenInformation
OpenProcessToken
RegSetValueExW
RegDeleteKeyExW
TraceMessage
RegOpenKeyW
RegDeleteValueW
RegEnumValueW
RegQueryInfoKeyW
ConvertStringSidToSidW
CloseServiceHandle
OpenServiceW
OpenSCManagerW
RegEnumKeyExW
CreateWellKnownSid
StartServiceW
CryptAcquireContextW
CryptCreateHash
CryptHashData
CryptGetHashParam
CryptDestroyHash
CryptReleaseContext
StartTraceW
EnableTraceEx
StopTraceW
LsaLookupSids
IsValidSid
GetSidSubAuthorityCount
GetSidSubAuthority
LsaOpenPolicy
LsaFreeMemory
LsaClose
OpenThreadToken
ConvertSidToStringSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW
CheckTokenMembership
QueryServiceStatus
GetUserNameW
RegEnumKeyW
RegOpenCurrentUser
LookupAccountNameW
EqualSid
api-ms-win-core-atoms-l1-1-0.dll

api-ms-win-core-com-l1-1-0.dll

CoTaskMemFree
CoInitializeEx
CoUninitialize
CreateStreamOnHGlobal
CoGetApartmentType
CoWaitForMultipleHandles
CoFreeUnusedLibraries
CoEnableCallCancellation
CoDisableCallCancellation
CoCancelCall
StringFromGUID2
PropVariantClear
CoMarshalInterThreadInterfaceInStream
CoReleaseMarshalData
CoCreateInstance
CoRevokeClassObject
CoRegisterClassObject
CoGetInterfaceAndReleaseStream
CoGetMalloc
CoCreateFreeThreadedMarshaler
CoTaskMemAlloc
CLSIDFromString
CoTaskMemRealloc
api-ms-win-core-com-l1-1-1.dll

CoCreateGuid
CoTaskMemRealloc
CoInitializeEx
CLSIDFromString
CoTaskMemFree
CoCreateInstance
CoTaskMemAlloc
CoGetMalloc
PropVariantClear
CoCancelCall
CoRevokeClassObject
StringFromGUID2
CoGetApartmentType
CreateStreamOnHGlobal
CoSetProxyBlanket
CoWaitForMultipleHandles
CoGetInterfaceAndReleaseStream
CoUninitialize
CoReleaseMarshalData
CoMarshalInterThreadInterfaceInStream
CoFreeUnusedLibraries
CoRegisterClassObject
CoDisableCallCancellation
CoEnableCallCancellation
CoCreateFreeThreadedMarshaler
RoGetAgileReference
api-ms-win-core-com-private-l1-1-0.dll

api-ms-win-core-datetime-l1-1-1.dll

GetDateFormatW
GetDateFormatEx
GetTimeFormatEx
api-ms-win-core-debug-l1-1-1.dll

api-ms-win-core-delayload-l1-1-1.dll

DelayLoadFailureHook
ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll

SetErrorMode
SetUnhandledExceptionFilter
SetLastError
GetLastError
RaiseException
UnhandledExceptionFilter
api-ms-win-core-file-l1-2-0.dll

GetLongPathNameW
ReadFile
CreateFileW
WriteFile
GetFileSize
FindClose
CompareFileTime
DeleteFileW
FindNextFileW
FindFirstFileW
GetFileAttributesW
api-ms-win-core-file-l1-2-1.dll

WriteFile
CreateFileW
FindClose
CreateDirectoryW
FindNextFileW
CompareFileTime
FindFirstFileW
GetFileAttributesW
DeleteFileW
FindFirstFileExW
RemoveDirectoryW
GetLongPathNameW
SetFileTime
api-ms-win-core-handle-l1-1-0.dll

DuplicateHandle
CloseHandle
api-ms-win-core-heap-l1-2-0.dll

HeapFree
HeapDestroy
HeapSetInformation
HeapAlloc
GetProcessHeap
api-ms-win-core-heap-obsolete-l1-1-0.dll

LocalFree
GlobalFree
GlobalAlloc
LocalReAlloc
LocalAlloc
GlobalLock
GlobalUnlock
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedPushEntrySList
InterlockedPopEntrySList
InterlockedExchange
InterlockedIncrement
InterlockedCompareExchange
InterlockedDecrement
api-ms-win-core-io-l1-1-1.dll

GetQueuedCompletionStatus
CreateIoCompletionPort
api-ms-win-core-job-l2-1-0.dll

AssignProcessToJobObject
QueryInformationJobObject
CreateJobObjectW
SetInformationJobObject
api-ms-win-core-kernel32-legacy-l1-1-0.dll

CopyFileW
RaiseFailFastException
MulDiv
LoadLibraryW
GetComputerNameW
api-ms-win-core-kernel32-legacy-l1-1-1.dll

RaiseFailFastException
CreateSemaphoreW
PowerCreateRequest
MoveFileW
CopyFileW
MulDiv
LoadLibraryW
PowerSetRequest
RegisterWaitForSingleObject
api-ms-win-core-libraryloader-l1-1-1.dll

LoadStringW
FindResourceExW
LoadResource
LockResource
LoadLibraryExW
GetModuleHandleW
FreeLibrary
GetProcAddress
GetModuleHandleExW
FreeLibraryAndExitThread
GetModuleHandleA
GetModuleFileNameW
api-ms-win-core-libraryloader-l1-2-0.dll

GetModuleHandleA
GetProcAddress
LoadStringW
FindResourceExW
LoadLibraryExW
GetModuleHandleExW
FreeLibrary
GetModuleFileNameW
LoadResource
FreeLibraryAndExitThread
SizeofResource
LockResource
GetModuleHandleW
api-ms-win-core-localization-l1-2-0.dll

GetLocaleInfoW
GetThreadUILanguage
api-ms-win-core-localization-l1-2-1.dll

FormatMessageW
GetUserPreferredUILanguages
IsValidLocaleName
GetThreadUILanguage
GetLocaleInfoW
api-ms-win-core-localization-obsolete-l1-1-0.dll

api-ms-win-core-localization-obsolete-l1-2-0.dll

api-ms-win-core-memory-l1-1-1.dll

MapViewOfFile
VirtualAlloc
UnmapViewOfFile
CreateFileMappingW
VirtualFree
api-ms-win-core-memory-l1-1-2.dll

VirtualFree
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
VirtualAlloc
api-ms-win-core-path-l1-1-0.dll

PathCchCombine
PathCchAppend
PathCchAddExtension
api-ms-win-core-processenvironment-l1-2-0.dll

GetCommandLineW
ExpandEnvironmentStringsW
SearchPathW
GetCurrentDirectoryW
api-ms-win-core-processthreads-l1-1-1.dll

SetProcessShutdownParameters
GetCurrentThreadId
GetCurrentThread
GetCurrentProcessId
CreateProcessW
GetStartupInfoW
OpenProcessToken
GetThreadPriority
OpenProcess
OpenThreadToken
CreateThread
SetPriorityClass
OpenThread
GetPriorityClass
TerminateProcess
ResumeThread
FlushInstructionCache
IsProcessorFeaturePresent
GetProcessId
GetCurrentProcess
ExitProcess
SetThreadPriority
TerminateThread
api-ms-win-core-processthreads-l1-1-2.dll

TerminateThread
GetExitCodeProcess
SetThreadPriorityBoost
TlsFree
GetPriorityClass
TerminateProcess
OpenProcessToken
QueueUserAPC
ResumeThread
SetPriorityClass
GetCurrentThread
TlsAlloc
FlushInstructionCache
GetCurrentProcess
SetProcessShutdownParameters
CreateThread
GetProcessId
OpenProcess
CreateProcessW
IsProcessorFeaturePresent
TlsSetValue
ExitProcess
GetThreadPriority
OpenThreadToken
GetCurrentThreadId
GetCurrentProcessId
SetThreadPriority
GetStartupInfoW
OpenThread
api-ms-win-core-profile-l1-1-0.dll

QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-core-psapi-l1-1-0.dll

QueryFullProcessImageNameW
api-ms-win-core-registry-l1-1-0.dll

RegDeleteValueW
RegQueryInfoKeyW
RegEnumKeyExW
RegQueryValueExW
RegCreateKeyExW
RegCloseKey
RegOpenKeyExW
RegGetValueW
RegEnumValueW
RegOpenCurrentUser
RegSetValueExW
api-ms-win-core-registry-l2-1-0.dll

RegCreateKeyW
RegDeleteKeyW
api-ms-win-core-registryuserspecific-l1-1-0.dll

SHRegGetUSValueW
SHRegGetBoolUSValueW
api-ms-win-core-shlwapi-legacy-l1-1-0.dll

PathStripPathW
SHExpandEnvironmentStringsW
PathFindExtensionW
PathParseIconLocationW
PathFileExistsW
PathGetDriveNumberW
PathCommonPrefixW
PathRemoveBlanksW
PathFindFileNameW
PathRemoveExtensionW
PathCombineW
PathIsFileSpecW
PathGetArgsW
PathRemoveFileSpecW
PathQuoteSpacesW
PathStripToRootW
PathIsRootW
PathIsPrefixW
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll

StrCmpW
StrCmpICA
SHLoadIndirectString
StrCmpIW
StrCmpNIW
StrRStrIW
StrCmpICW
StrChrW
StrToIntW
QISearch
StrCmpNICW
StrChrIW
StrStrIW
StrTrimW
StrCmpNW
StrCmpCW
StrRChrW
api-ms-win-core-sidebyside-l1-1-0.dll

CreateActCtxW
ReleaseActCtx
ActivateActCtx
DeactivateActCtx
api-ms-win-core-string-l1-1-0.dll

MultiByteToWideChar
CompareStringOrdinal
WideCharToMultiByte
CompareStringW
api-ms-win-core-string-l2-1-0.dll

IsCharAlphaNumericW
CharPrevW
CharUpperW
CharNextW
CharLowerW
api-ms-win-core-string-obsolete-l1-1-0.dll

api-ms-win-core-synch-l1-2-0.dll

InitOnceExecuteOnce
Sleep
OpenMutexW
ReleaseMutex
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
InitializeCriticalSectionEx
CreateEventExW
WaitForSingleObject
InitializeCriticalSection
CreateMutexW
CreateEventW
WaitForMultipleObjectsEx
OpenSemaphoreW
InitializeSRWLock
ResetEvent
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
AcquireSRWLockShared
ReleaseSRWLockShared
ReleaseSemaphore
OpenEventW
SleepEx
SetEvent
WaitForSingleObjectEx
api-ms-win-core-sysinfo-l1-2-0.dll

GetTickCount64
GetTickCount
GetProductInfo
GetVersionExW
GetSystemDirectoryW
GetSystemTimeAsFileTime
GetSystemTime
GetWindowsDirectoryW
GetLocalTime
api-ms-win-core-sysinfo-l1-2-1.dll

GetTickCount64
GetLocalTime
GetSystemTime
GetProductInfo
GetVersionExW
GetTickCount
GetSystemTimeAsFileTime
GetWindowsDirectoryW
GetSystemDirectoryW
GetOsSafeBootMode
api-ms-win-core-threadpool-l1-2-0.dll

CreateThreadpoolTimer
FreeLibraryWhenCallbackReturns
SubmitThreadpoolWork
CallbackMayRunLong
CloseThreadpoolTimer
CreateThreadpoolWork
SetThreadpoolWait
CreateThreadpoolWait
TrySubmitThreadpoolCallback
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
api-ms-win-core-threadpool-legacy-l1-1-0.dll

CreateTimerQueueTimer
UnregisterWaitEx
ChangeTimerQueueTimer
DeleteTimerQueueTimer
QueueUserWorkItem
api-ms-win-core-timezone-l1-1-0.dll

GetDynamicTimeZoneInformation
SystemTimeToFileTime
GetTimeZoneInformation
api-ms-win-core-winrt-l1-1-0.dll

api-ms-win-core-winrt-string-l1-1-0.dll

WindowsCreateStringReference
WindowsCreateString
WindowsGetStringRawBuffer
WindowsDeleteString
api-ms-win-eventing-classicprovider-l1-1-0.dll

GetTraceEnableLevel
GetTraceEnableFlags
RegisterTraceGuidsW
UnregisterTraceGuids
GetTraceLoggerHandle
TraceMessage
api-ms-win-eventing-controller-l1-1-0.dll

EnableTraceEx2
StartTraceW
StopTraceW
api-ms-win-eventing-provider-l1-1-0.dll

EventWrite
EventRegister
EventUnregister
EventEnabled
api-ms-win-power-base-l1-1-0.dll

CallNtPowerInformation
GetPwrCapabilities
PowerDeterminePlatformRoleEx
api-ms-win-security-base-l1-2-0.dll

GetLengthSid
CopySid
CreateWellKnownSid
IsValidSid
CheckTokenMembership
GetTokenInformation
GetSidSubAuthority
GetSidSubAuthorityCount
api-ms-win-security-lsalookup-l1-1-1.dll

EnumerateIdentityProviders
ReleaseIdentityProviderEnumContext
GetIdentityProviderInfoByGUID
GetDefaultIdentityProvider
api-ms-win-service-management-l2-1-0.dll

QueryServiceConfigW
NotifyServiceStatusChangeW
d3d11.dll

dwmapi.dll

DwmEnableBlurBehindWindow
DwmIsCompositionEnabled
DwmSetWindowAttribute
DwmQueryThumbnailSourceSize
DwmUnregisterThumbnail
DwmUpdateThumbnailProperties
DwmGetColorizationColor
DwmRegisterThumbnail
gdi32.dll

GetStockObject
SetWindowOrgEx
StretchBlt
GetTextMetricsW
CombineRgn
Polyline
CreatePen
GetTextColor
ExtCreateRegion
GetRegionData
SetLayout
GetLayout
GetTextExtentPoint32W
OffsetRgn
LPtoDP
GetRgnBox
OffsetViewportOrgEx
GdiFlush
ExtTextOutW
SetDIBits
CreateRectRgn
GetClipRgn
IntersectClipRect
GetViewportOrgEx
SetViewportOrgEx
SelectClipRgn
GetBkColor
SetBkMode
CreateBitmap
PatBlt
CreateCompatibleBitmap
OffsetWindowOrgEx
SetBkColor
SetTextColor
GetTextExtentPointW
GetClipBox
CreateDIBSection
GetObjectW
CreateRectRgnIndirect
DeleteObject
CreateCompatibleDC
SelectObject
BitBlt
GetDeviceCaps
CreateFontIndirectW
DeleteDC
GdiAlphaBlend
CreatePatternBrush
GetPixel
CreateSolidBrush
SetTextAlign
GetDIBits
Rectangle
StretchDIBits
gdiplus.dll

GdipAlloc
GdiplusStartup
GdiplusShutdown
GdipFree
GdipDeleteGraphics
GdipDisposeImage
GdipGetImageWidth
GdipGetImageHeight
GdipCreateBitmapFromHBITMAP
GdipCreateFromHDC
GdipSetCompositingMode
GdipSetInterpolationMode
GdipDrawImageRectI
GdipCloneImage
GdipCreateBitmapFromStream
GdipLoadImageFromFileICM
GdipLoadImageFromFile
GdipCreateBitmapFromStreamICM
kernel32.dll
msvcrt.dll
ntdll.dll

WinSqmSetString
NtQueryInformationProcess
NtSetInformationProcess
WinSqmIsOptedIn
NtOpenThreadToken
NtOpenProcessToken
NtClose
WinSqmAddToStreamEx
NtSetSystemInformation
WinSqmAddToStream
WinSqmEventEnabled
WinSqmSetDWORD
EtwEventWrite
EtwEventEnabled
NtQueryInformationToken
RtlGetProductInfo
RtlNtStatusToDosError
RtlUnsubscribeWnfNotificationWaitForCompletion
RtlSubscribeWnfStateChangeNotification
RtlQueryWnfStateData
WinSqmIncrementDWORD
NtQueryWnfStateData
ole32.dll

OleInitialize
StringFromGUID2
CoRegisterMessageFilter
RegisterDragDrop
RevokeDragDrop
OleUninitialize
CoRevokeClassObject
CoCreateFreeThreadedMarshaler
CreateBindCtx
PropVariantClear
ReleaseStgMedium
CoInitializeEx
CreateStreamOnHGlobal
CoRegisterClassObject
CoCreateInstance
CoTaskMemFree
CoGetInterfaceAndReleaseStream
CoMarshalInterThreadInterfaceInStream
CoUninitialize
CoInitialize
CoGetMalloc
CoTaskMemAlloc
CLSIDFromString
CoFreeUnusedLibraries
CoGetClassObject
CoGetObject
DoDragDrop
CoTaskMemRealloc
CoReleaseMarshalData
CoGetApartmentType
CoWaitForMultipleHandles
powrprof.dll

CallNtPowerInformation
GetPwrCapabilities
PowerDeterminePlatformRole
propsys.dll

PropVariantToUInt32
PropVariantToStringAlloc
PropVariantToUInt64
PropVariantToBoolean
VariantToStringAlloc
VariantToStringWithDefault
PropVariantToString
VariantToBooleanWithDefault
VariantToInt32WithDefault
PSCreateMemoryPropertyStore
PropVariantToInt64
PSGetPropertyKeyFromName
PSPropertyKeyFromString
PSGetNameFromPropertyKey
PSGetPropertyDescription
PSPropertyBag_WriteDWORD
InitVariantFromResource
PropVariantToGUID
rpcrt4.dll

RpcBindingFree
RpcBindingSetAuthInfoExW
RpcStringFreeW
RpcBindingFromStringBindingW
RpcStringBindingComposeW
I_RpcExceptionFilter
NdrClientCall2
secur32.dll

shcore.dll

IsOS
SHStrDupW
IUnknown_Set
IUnknown_QueryService
SHUnicodeToAnsi
SetProcessReference
SHCreateThreadRef
SHSetThreadRef
IUnknown_SetSite
SHRegGetValueW
SHGetValueW
SHSetValueW
SHDeleteValueW
SHCreateThread
SetCurrentProcessExplicitAppUserModelID
SHQueryValueExW
SHOpenRegStream2W
IStream_Reset
IStream_Read
SHCreateMemStream
SHAnsiToUnicode
IStream_Write
SHDeleteKeyW
GetDpiForMonitor
SHEnumKeyExW
SHGetThreadRef
SHQueryInfoKeyW
SHCreateStreamOnFileW
SHStrDupA
shell32.dll
shlwapi.dll
slc.dll

SLGetWindowsInformationDWORD
SLUnregisterWindowsEvent
SLRegisterWindowsEvent
sspicli.dll

user32.dll
userenv.dll

uxtheme.dll

BeginBufferedPaint
IsCompositionActive
IsAppThemed
GetThemeMetric
CloseThemeData
OpenThemeData
SetWindowTheme
DrawThemeBackground
GetThemeTextExtent
DrawThemeText
DrawThemeParentBackground
GetWindowTheme
GetThemePartSize
GetThemeBackgroundContentRect
EndBufferedPaint
GetThemeMargins
DrawThemeTextEx
BufferedPaintInit
BufferedPaintUnInit
IsThemeActive
GetThemeRect
IsThemePartDefined
GetThemeBackgroundRegion
GetThemeColor
GetThemeBool
DrawThemeIcon
GetBufferedPaintBits
BufferedPaintClear
GetThemeBackgroundExtent
GetThemeFont
GetThemeInt
GetCurrentThemeName
wtsapi32.dll

WTSFreeMemory
WTSQuerySessionInformationW