File details
File name: shell32.dll
Name: Windows Shell Common Dll
Description: Microsoft® Windows® Operating System
Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
Product version: 6.1.7601.17514
Size: 13.52 MB
Original file name: SHELL32.DLL
Windows file protection:
Yes
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0000743905%
Privileged CPU:
0.0000352219%

User CPU:
0.00003916863860%

Privileged CPU time: 4469.43 ms
Privileged CPU time /min: 2 ms
CPU cycle count:
250,676,569
CPU cycle count /min: 797,282,290
 | Memory utilization averages |
Committed memory:
92.01 MB
Peak committed memory: 115.62 MB
Paged memory:
4.23 MB
Peak paged memory: 5.1 MB
Paged system memory:
174.52 KB
Non-paged system memory: 11.31 KB
Working set memory:
10.16 MB
Peak working set memory: 11.39 MB
Min working set memory: 9.59 MB
Private memory:
4.23 MB
Page faults:
5,859,456
Page faults /min: 2,282
 | Process I/O averages |
Total read operations:
18
Read operations /min: 1
Total read transfer: 225.62 KB
Read transfer /min: 66 Bytes
Total write operations:
1
Write operations /min: 1
Total write transfer: 160 Bytes
Write transfer /min: 0 Bytes
Total other operations:
2,354
Other operations /min: 1
Total other transfer: 32.4 KB
Other Transfer /min: 10 Bytes
 | GUI Object Averages |
GDI objects:
62
Peak GDI objects: 67
USER objects:
40
Peak USER objects: 43
Resources
Handle count average: 115
Thread count average: 4
Thread resource averages
Total CPU: 0.014065721322%
Privileged CPU: 0.003099357869%
User CPU: 0.010966363453%
CPU Cycle count /sec: 15,036,096
Context switches /sec: 10
Module memory size: 60 KB
Total CPU: 0.000024158283%
Privileged CPU: 0.000024158283%
User CPU: 0.000000000000%
CPU Cycle count /sec: 690
Module memory size: 640 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 64-bit
Parent Process
Process Commands
"C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL C:\Windows\System32\timedate.cpl
"C:\Windows\system32\rundll32.exe" shell32.dll,Control_RunDLL PowerCfg.cpl @0,/editplaC:381b4222-f694-41f0-9685-ff5bb260df2e
IE web browser details
CLSID: {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Shell execute hook details
CLSID: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
Shell service object delay load details
Name: CDBurn
Shell open command details
Name: themefile
Command: C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\shell32.dll,Control_RunDLL C:\WINDOWS\system32\desk.cpl desk,@Themes /ActioC:OpenTheme /filC:"%1"
PROTOCOLS filter details
Name: text/webviewhtml
Command: {733AC4CB-F1A4-11d0-B951-00A0C90312E1}
Context menu handler details
Name: Move to
Copy hook handler details
Name: FileSystem
Safe for scripting control details
CLSID: {459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Command: CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}\Implemented Categories\{7DD95801-9882-11CF-9FA9-00AA006C42C4}
Safe for initializing control details
CLSID: {459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}
Command: CLSID\{459DD0F7-0D55-D3DC-67BC-E6BE37E9D762}\Implemented Categories\{7DD95802-9882-11CF-9FA9-00AA006C42C4}
Internet Explorer bar details
CLSID: {C4EE31F3-4768-11D2-BE5C-00A0C9A83DA1}
Search handler details
Name: ShellSearch
Autoplay handler details
Name: MSCDBurningOnArrival
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSCDBurningOnArrival
Approved shell extension details
CLSID: {1531d583-8375-4d3f-b5fb-d23bbd169f22}
Command: Window TXT Preview Handler
Internet Explorer shell browser details
CLSID: {0E5CBF21-D15F-11D0-8301-00AA005B4383}
Image hashes
MD5: 3f178a4a0ab8c6f64043b3a23eaa7d7a
SHA-1: f737c50e75a987ff6bf19b71e399a0340a7d58e4
PE image details
Subsystem: Windows GUI
Langauge*: Microsoft Visual C++
File entropy: 5.93178
File packed: No
Import Table
advapi32.dll

RegCloseKey
AllocateAndInitializeSid
RegQueryValueExW
RegDeleteValueW
RegSetValueExW
MakeSelfRelativeSD
GetSecurityDescriptorLength
EqualSid
GetSecurityDescriptorDacl
GetSecurityDescriptorOwner
GetFileSecurityW
RegCreateKeyExW
RegOpenKeyExW
FreeSid
GetAce
AddAccessAllowedAce
InitializeAcl
RegNotifyChangeKeyValue
RegCreateKeyW
GetSecurityDescriptorControl
EncryptFileW
DecryptFileW
ChangeServiceConfigW
StartServiceW
ControlService
OpenSCManagerW
OpenServiceW
QueryServiceStatus
CloseServiceHandle
GetNamedSecurityInfoW
ConvertSidToStringSidW
RegOpenCurrentUser
LookupAccountNameW
SetNamedSecurityInfoW
CreateProcessWithLogonW
CreateProcessAsUserW
SaferGetPolicyInformation
SaferiIsExecutableFileType
SaferIdentifyLevel
SaferRecordEventLogEntry
SaferGetLevelInformation
InstallApplication
SaferCreateLevel
SaferComputeTokenFromLevel
SaferCloseLevel
RegQueryValueW
OpenThreadToken
CheckTokenMembership
LookupPrivilegeValueW
AdjustTokenPrivileges
CommandLineFromMsiDescriptor
RegSetKeySecurity
RegQueryInfoKeyW
GetUserNameW
RegEnumKeyExW
RegDeleteKeyW
RegEnumValueW
SetFileSecurityW
TreeResetNamedSecurityInfoW
RegEnumKeyW
RegOpenKeyW
RegSetValueW
LookupAccountSidW
GetTokenInformation
OpenProcessToken
RegQueryValueExA
RegOpenKeyExA
GetLengthSid
api-ms-win-appmodel-identity-l1-1-0.dll

AppContainerFreeMemory
AppXGetPackageCapabilities
AppXFreeMemory
AppContainerLookupMoniker
api-ms-win-core-apiquery-l1-1-0.dll

ApiSetQueryApiSetPresence
api-ms-win-core-atoms-l1-1-0.dll

GlobalDeleteAtom
GetAtomNameW
GlobalGetAtomNameW
FindAtomW
GlobalAddAtomW
api-ms-win-core-datetime-l1-1-1.dll

api-ms-win-core-debug-l1-1-0.dll

OutputDebugStringW
OutputDebugStringA
api-ms-win-core-debug-l1-1-1.dll

OutputDebugStringW
OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll

DelayLoadFailureHook
ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-0.dll

SetLastError
SetErrorMode
RaiseException
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
api-ms-win-core-errorhandling-l1-1-1.dll

GetLastError
RaiseException
SetErrorMode
SetLastError
UnhandledExceptionFilter
SetUnhandledExceptionFilter
api-ms-win-core-file-l1-1-0.dll

GetFileAttributesExW
GetVolumeInformationW
GetLogicalDrives
GetFileSize
GetShortPathNameW
GetFileAttributesA
GetDriveTypeW
ReadFile
SetFilePointer
CompareFileTime
WriteFile
RemoveDirectoryW
CreateDirectoryW
DeleteFileW
SetFileAttributesW
GetFileAttributesW
QueryDosDeviceW
CreateFileW
GetFileSizeEx
SetFileTime
GetDiskFreeSpaceW
GetLongPathNameW
FindClose
FindNextFileW
GetDiskFreeSpaceExW
FindFirstFileW
FindCloseChangeNotification
GetFullPathNameW
FindNextChangeNotification
FindFirstChangeNotificationW
FlushFileBuffers
GetVolumePathNameW
GetFileInformationByHandle
GetTempFileNameW
FileTimeToSystemTime
FindFirstFileExW
FindVolumeClose
FindNextVolumeW
FindFirstVolumeW
SetEndOfFile
api-ms-win-core-file-l1-2-0.dll

SetFileTime
CompareFileTime
GetVolumeNameForVolumeMountPointW
GetDiskFreeSpaceW
GetFileAttributesExW
SetEndOfFile
GetFileTime
GetVolumeInformationW
GetLogicalDrives
SetFileInformationByHandle
GetFileSize
GetShortPathNameW
FlushFileBuffers
ReadFile
GetDriveTypeW
GetFullPathNameW
SetFilePointer
WriteFile
RemoveDirectoryW
CreateDirectoryW
SetFileAttributesW
SetFilePointerEx
CreateFile2
DeleteFileW
FindFirstFileExW
GetFileInformationByHandle
GetLongPathNameW
FindVolumeClose
GetFileAttributesW
FindNextVolumeW
QueryDosDeviceW
FindFirstVolumeW
GetFileSizeEx
CreateFileW
FindFirstFileW
FindNextFileW
FindClose
GetTempFileNameW
DefineDosDeviceW
GetVolumePathNamesForVolumeNameW
GetVolumePathNameW
GetDiskFreeSpaceExW
FindFirstChangeNotificationW
LocalFileTimeToFileTime
FileTimeToLocalFileTime
FindNextChangeNotification
FindCloseChangeNotification
GetTempPathW
api-ms-win-core-file-l2-1-0.dll

CopyFile2
ReplaceFileW
ReadDirectoryChangesW
CreateHardLinkW
GetFileInformationByHandleEx
MoveFileExW
api-ms-win-core-handle-l1-1-0.dll

CloseHandle
DuplicateHandle
api-ms-win-core-heap-l1-1-0.dll

HeapAlloc
GetProcessHeap
HeapDestroy
HeapReAlloc
HeapFree
api-ms-win-core-heap-l1-2-0.dll

GetProcessHeap
HeapFree
HeapReAlloc
HeapAlloc
HeapDestroy
api-ms-win-core-heap-obsolete-l1-1-0.dll

LocalAlloc
GlobalLock
GlobalUnlock
GlobalSize
GlobalFree
LocalSize
LocalReAlloc
GlobalFlags
LocalFree
GlobalAlloc
GlobalReAlloc
api-ms-win-core-interlocked-l1-1-0.dll

InterlockedExchange
InterlockedDecrement
InterlockedIncrement
InterlockedCompareExchange
InterlockedCompareExchange64
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedCompareExchange64
InterlockedDecrement
InterlockedPopEntrySList
InterlockedExchange
InterlockedPushEntrySList
InterlockedCompareExchange
InterlockedIncrement
api-ms-win-core-io-l1-1-0.dll

CancelIoEx
GetOverlappedResult
DeviceIoControl
api-ms-win-core-io-l1-1-1.dll

DeviceIoControl
GetOverlappedResult
GetQueuedCompletionStatus
CancelSynchronousIo
CreateIoCompletionPort
CancelIoEx
api-ms-win-core-job-l2-1-0.dll

SetInformationJobObject
CreateJobObjectW
AssignProcessToJobObject
api-ms-win-core-kernel32-legacy-l1-1-0.dll

CreateSemaphoreW
GetSystemPowerStatus
UnregisterWait
FindResourceW
LoadLibraryW
DosDateTimeToFileTime
WaitForMultipleObjects
MoveFileW
MulDiv
GetShortPathNameA
CopyFileW
RegisterWaitForSingleObject
WTSGetActiveConsoleSessionId
GetComputerNameW
FileTimeToDosDateTime
GetSystemWow64DirectoryW
SetVolumeLabelW
api-ms-win-core-kernel32-private-l1-1-0.dll

api-ms-win-core-libraryloader-l1-1-0.dll

GetModuleFileNameW
FreeResource
LoadResource
LoadStringW
FreeLibrary
GetModuleHandleW
LoadStringA
GetProcAddress
LoadLibraryExA
FreeLibraryAndExitThread
DisableThreadLibraryCalls
LoadLibraryExW
SizeofResource
GetModuleHandleExW
LockResource
api-ms-win-core-libraryloader-l1-1-1.dll

FreeLibraryAndExitThread
LoadLibraryExA
DisableThreadLibraryCalls
GetProcAddress
SizeofResource
LoadStringW
FindResourceExW
GetModuleFileNameW
LoadStringA
FreeResource
LockResource
LoadResource
FindStringOrdinal
LoadLibraryExW
FreeLibrary
GetModuleHandleExW
GetModuleHandleW
api-ms-win-core-localization-l1-1-0.dll

FindNLSString
GetCPInfoExW
GetLocaleInfoEx
GetSystemDefaultLangID
GetCPInfo
GetLocaleInfoW
GetACP
LCMapStringW
GetThreadLocale
GetUserDefaultLCID
GetThreadUILanguage
GetSystemDefaultLCID
VerLanguageNameW
GetOEMCP
api-ms-win-core-localization-l1-2-0.dll

LCMapStringW
GetUserDefaultLangID
GetThreadUILanguage
LCMapStringEx
GetSystemPreferredUILanguages
LocaleNameToLCID
GetLocaleInfoW
GetSystemDefaultLCID
GetCPInfoExW
VerLanguageNameW
GetLocaleInfoEx
GetOEMCP
IsValidLocaleName
GetThreadLocale
GetSystemDefaultLangID
ResolveLocaleName
FindNLSString
FormatMessageW
GetACP
IsDBCSLeadByte
GetUserDefaultLCID
GetCPInfo
api-ms-win-core-localization-l2-1-0.dll

api-ms-win-core-localization-obsolete-l1-1-0.dll

EnumSystemLocalesEx
GetNumberFormatW
LCIDToLocaleName
GetUserDefaultUILanguage
EnumUILanguagesW
api-ms-win-core-localregistry-l1-1-0.dll

RegCloseKey
RegOpenKeyExW
RegSetValueExW
RegCreateKeyExW
RegEnumValueW
RegDeleteKeyExW
RegDeleteValueW
RegGetValueW
RegQueryInfoKeyW
RegQueryInfoKeyA
RegEnumKeyExW
RegDeleteTreeW
RegOpenKeyExA
RegOpenCurrentUser
RegQueryValueExA
RegQueryValueExW
api-ms-win-core-memory-l1-1-0.dll

UnmapViewOfFile
VirtualProtect
CreateFileMappingW
OpenFileMappingW
ReadProcessMemory
VirtualFree
VirtualAlloc
VirtualQuery
MapViewOfFile
api-ms-win-core-memory-l1-1-1.dll

OpenFileMappingW
VirtualFree
VirtualProtect
ReadProcessMemory
VirtualAlloc
VirtualQuery
PrefetchVirtualMemory
MapViewOfFile
CreateFileMappingW
UnmapViewOfFile
api-ms-win-core-misc-l1-1-0.dll

lstrlenA
Wow64DisableWow64FsRedirection
GlobalAlloc
GlobalFree
Sleep
IsWow64Process
lstrcmpiA
lstrcmpA
LocalReAlloc
FormatMessageW
LocalFree
LocalAlloc
lstrlenW
lstrcmpiW
lstrcmpW
Wow64RevertWow64FsRedirection
api-ms-win-core-path-l1-1-0.dll

PathCchStripPrefix
PathCchAddBackslashEx
PathCchCanonicalizeEx
PathCchRemoveBackslashEx
PathCchAddBackslash
PathCchCombine
PathCchStripToRoot
PathCchCanonicalize
PathCchAddExtension
PathCchRemoveFileSpec
PathCchRemoveBackslash
PathCchFindExtension
PathCchAppend
PathAllocCombine
PathCchRenameExtension
PathIsUNCEx
PathCchAppendEx
api-ms-win-core-privateprofile-l1-1-0.dll

GetPrivateProfileSectionW
WritePrivateProfileStringW
GetPrivateProfileStringW
GetProfileSectionW
GetPrivateProfileIntW
GetProfileIntW
api-ms-win-core-processenvironment-l1-1-0.dll

ExpandEnvironmentStringsW
FreeEnvironmentStringsW
GetCurrentDirectoryW
GetEnvironmentVariableW
SearchPathW
SetEnvironmentVariableW
SetCurrentDirectoryW
GetEnvironmentStringsW
api-ms-win-core-processenvironment-l1-2-0.dll

SearchPathW
SetCurrentDirectoryW
GetEnvironmentVariableW
FreeEnvironmentStringsW
ExpandEnvironmentStringsW
GetEnvironmentStringsW
GetCommandLineW
SetEnvironmentVariableW
GetCurrentDirectoryW
ExpandEnvironmentStringsA
api-ms-win-core-processthreads-l1-1-0.dll

ExitProcess
TerminateProcess
GetExitCodeProcess
GetCurrentThread
OpenThreadToken
GetExitCodeThread
GetThreadId
OpenThread
SetThreadPriority
GetThreadPriority
InitializeProcThreadAttributeList
ResumeThread
GetStartupInfoW
GetProcessTimes
TlsAlloc
TlsFree
ProcessIdToSessionId
GetCurrentProcessId
TlsGetValue
TlsSetValue
CreateThread
GetCurrentProcess
OpenProcessToken
GetCurrentThreadId
DeleteProcThreadAttributeList
CreateProcessAsUserW
SetThreadToken
CreateProcessW
api-ms-win-core-processthreads-l1-1-1.dll

IsProcessorFeaturePresent
ResumeThread
GetThreadId
CreateProcessAsUserW
GetCurrentProcessId
SetThreadToken
ProcessIdToSessionId
GetCurrentThreadId
UpdateProcThreadAttribute
CreateProcessW
GetExitCodeThread
OpenProcess
DeleteProcThreadAttributeList
ExitProcess
OpenThread
SetPriorityClass
TlsAlloc
TerminateThread
TlsFree
CreateThread
OpenThreadToken
GetCurrentThread
GetExitCodeProcess
GetProcessId
GetProcessTimes
FlushInstructionCache
TlsSetValue
TlsGetValue
GetCurrentProcess
TerminateProcess
OpenProcessToken
SetThreadPriority
GetThreadPriority
InitializeProcThreadAttributeList
api-ms-win-core-profile-l1-1-0.dll

QueryPerformanceFrequency
QueryPerformanceCounter
api-ms-win-core-psapi-l1-1-0.dll

QueryFullProcessImageNameW
api-ms-win-core-realtime-l1-1-0.dll

QueryUnbiasedInterruptTime
api-ms-win-core-registry-l1-1-0.dll

RegQueryValueExW
RegCreateKeyExW
RegSetValueExW
RegEnumValueW
RegDeleteTreeW
RegDeleteKeyExW
RegEnumKeyExW
RegQueryInfoKeyW
RegCloseKey
RegGetKeySecurity
RegSetKeySecurity
RegGetValueW
RegDeleteValueW
RegOpenKeyExA
RegNotifyChangeKeyValue
RegOpenKeyExW
RegQueryValueExA
RegOpenCurrentUser
RegQueryInfoKeyA
api-ms-win-core-registryuserspecific-l1-1-0.dll

SHRegEnumUSKeyW
SHRegOpenUSKeyW
SHRegQueryUSValueW
SHRegCloseUSKey
SHRegOpenUSKeyA
SHRegGetBoolUSValueW
SHRegGetUSValueW
api-ms-win-core-shlwapi-legacy-l1-1-0.dll

PathRenameExtensionW
PathRemoveBlanksW
IsCharSpaceW
PathGetArgsA
PathGetCharTypeW
PathAppendW
PathIsUNCW
PathQuoteSpacesA
PathQuoteSpacesW
PathRemoveExtensionW
PathGetArgsW
PathParseIconLocationW
PathUnExpandEnvStringsW
PathRelativePathToW
SHExpandEnvironmentStringsW
SHExpandEnvironmentStringsA
PathIsRelativeW
PathUnquoteSpacesW
PathIsRootW
PathIsUNCServerShareW
PathIsUNCServerW
PathFindExtensionW
PathIsValidCharW
PathAddBackslashW
PathCombineW
PathGetDriveNumberA
PathIsPrefixW
PathGetDriveNumberW
PathIsFileSpecW
PathFindFileNameW
PathAddExtensionW
PathSkipRootW
PathStripToRootW
PathMatchSpecW
PathStripPathW
PathRemoveFileSpecW
PathRemoveBackslashW
PathIsSameRootW
PathFileExistsW
PathMatchSpecExW
PathFindNextComponentW
PathAppendA
PathRemoveFileSpecA
PathIsRootA
PathCommonPrefixW
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll

StrCmpW
StrChrW
StrChrIW
StrChrIA
StrChrA
StrCmpNIA
StrCmpNIW
StrCmpNW
StrRChrA
StrRChrIA
StrRChrIW
StrRChrW
StrRStrIA
StrRStrIW
StrStrA
StrStrIA
StrStrIW
StrStrW
StrToIntW
StrCmpICW
StrCmpCW
StrCmpNA
StrStrNIW
StrTrimA
StrDupW
StrToIntA
StrToInt64ExA
StrSpnW
QISearch
StrCmpIW
StrPBrkW
StrCmpLogicalW
StrCmpNCW
StrDupA
StrCpyNXW
StrCmpICA
StrTrimW
StrCSpnW
StrToIntExW
StrCmpNICW
SHLoadIndirectString
api-ms-win-core-sidebyside-l1-1-0.dll

ReleaseActCtx
QueryActCtxW
CreateActCtxW
DeactivateActCtx
ActivateActCtx
api-ms-win-core-stringansi-l1-1-0.dll

api-ms-win-core-string-l1-1-0.dll

WideCharToMultiByte
CompareStringEx
CompareStringOrdinal
CompareStringW
MultiByteToWideChar
GetStringTypeExW
GetStringTypeW
api-ms-win-core-string-l2-1-0.dll

CharLowerW
CharLowerBuffW
CharUpperBuffW
CharPrevW
CharNextW
CharUpperW
IsCharAlphaW
api-ms-win-core-string-obsolete-l1-1-0.dll

lstrcmpiW
lstrlenW
lstrlenA
lstrcmpW
lstrcmpiA
lstrcmpA
api-ms-win-core-synch-l1-1-0.dll

ReleaseSRWLockExclusive
CreateEventW
ResetEvent
WaitForSingleObject
ReleaseSemaphore
SetEvent
DeleteCriticalSection
InitializeCriticalSection
EnterCriticalSection
LeaveCriticalSection
CreateMutexW
TryEnterCriticalSection
InitializeSRWLock
OpenMutexW
OpenProcess
AcquireSRWLockShared
ReleaseSRWLockShared
ReleaseMutex
OpenEventW
AcquireSRWLockExclusive
SetWaitableTimer
api-ms-win-core-synch-l1-2-0.dll

SetEvent
ResetEvent
AcquireSRWLockShared
CreateEventW
InitializeCriticalSection
OpenEventW
LeaveCriticalSection
EnterCriticalSection
TryEnterCriticalSection
ReleaseSRWLockShared
AcquireSRWLockExclusive
InitializeSRWLock
ReleaseSRWLockExclusive
OpenMutexW
SetWaitableTimer
DeleteCriticalSection
InitOnceExecuteOnce
InitOnceBeginInitialize
ReleaseSemaphore
WaitForMultipleObjectsEx
InitializeCriticalSectionEx
TryAcquireSRWLockExclusive
CreateEventExW
Sleep
ReleaseMutex
OpenSemaphoreW
CreateMutexW
WaitForSingleObjectEx
WaitForSingleObject
api-ms-win-core-sysinfo-l1-1-0.dll

GetVersionExW
SystemTimeToFileTime
GetSystemInfo
GetSystemTime
GetTickCount
GetSystemTimeAsFileTime
GetSystemDirectoryW
GetTickCount64
GetSystemWindowsDirectoryW
GetLocalTime
GlobalMemoryStatusEx
GetComputerNameExW
GetWindowsDirectoryW
api-ms-win-core-sysinfo-l1-2-0.dll

GetTickCount
GetWindowsDirectoryW
GetSystemTimePreciseAsFileTime
GlobalMemoryStatusEx
GetSystemDirectoryW
GetSystemInfo
GetVersionExW
GetSystemTime
GetProductInfo
GetTickCount64
GetSystemWindowsDirectoryW
GetComputerNameExW
GetLocalTime
GetSystemTimeAsFileTime
GetNativeSystemInfo
api-ms-win-core-threadpool-l1-2-0.dll

SubmitThreadpoolWork
WaitForThreadpoolWaitCallbacks
CreateThreadpoolWork
TrySubmitThreadpoolCallback
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
CreateThreadpoolWait
CloseThreadpoolTimer
CallbackMayRunLong
FreeLibraryWhenCallbackReturns
CloseThreadpoolWork
SetThreadpoolWait
CloseThreadpoolWait
CreateThreadpoolTimer
api-ms-win-core-threadpool-legacy-l1-1-0.dll

CreateTimerQueueTimer
QueueUserWorkItem
DeleteTimerQueueTimer
UnregisterWaitEx
api-ms-win-core-timezone-l1-1-0.dll

SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
FileTimeToSystemTime
SystemTimeToFileTime
api-ms-win-core-url-l1-1-0.dll

PathCreateFromUrlW
UrlGetPartW
UrlApplySchemeW
PathIsURLW
UrlEscapeW
UrlCreateFromPathW
UrlUnescapeW
HashData
UrlCompareW
UrlUnescapeA
UrlGetLocationW
UrlFixupW
ParseURLW
UrlIsW
UrlCanonicalizeW
api-ms-win-core-util-l1-1-0.dll

api-ms-win-core-version-l1-1-0.dll

VerQueryValueW
GetFileVersionInfoSizeExW
GetFileVersionInfoExW
api-ms-win-core-windowserrorreporting-l1-1-0.dll

WerpNotifyUseStringResource
api-ms-win-core-winrt-error-l1-1-0.dll

RoOriginateErrorW
RoTransformErrorW
GetRestrictedErrorInfo
SetRestrictedErrorInfo
RoTransformError
RoOriginateError
api-ms-win-core-winrt-errorprivate-l1-1-0.dll

RoReportCapabilityCheckFailure
api-ms-win-core-winrt-l1-1-0.dll

RoGetActivationFactory
RoActivateInstance
api-ms-win-core-wow64-l1-1-0.dll

Wow64DisableWow64FsRedirection
IsWow64Process
Wow64RevertWow64FsRedirection
api-ms-win-eventing-classicprovider-l1-1-0.dll

api-ms-win-eventing-provider-l1-1-0.dll

api-ms-win-security-base-l1-1-0.dll

AddAccessAllowedAce
GetSecurityDescriptorControl
GetLengthSid
InitializeAcl
AddAce
GetAclInformation
GetAce
DeleteAce
QuerySecurityAccessMask
GetKernelObjectSecurity
InitializeSecurityDescriptor
SetSecurityDescriptorDacl
GetSidSubAuthorityCount
GetSidLengthRequired
AdjustTokenPrivileges
GetSidSubAuthority
GetSidIdentifierAuthority
GetSecurityDescriptorOwner
GetSecurityDescriptorGroup
IsWellKnownSid
GetSecurityDescriptorDacl
GetSecurityDescriptorSacl
ImpersonateSelf
RevertToSelf
AllocateAndInitializeSid
FreeSid
CreateWellKnownSid
CheckTokenMembership
GetFileSecurityW
AccessCheck
EqualSid
GetTokenInformation
SetFileSecurityW
SetSecurityDescriptorOwner
DuplicateTokenEx
CopySid
IsValidSid
DuplicateToken
AddAccessAllowedAceEx
AddAccessDeniedAceEx
SetTokenInformation
InitializeSid
api-ms-win-security-base-l1-2-0.dll

GetSecurityDescriptorSacl
GetSidIdentifierAuthority
ImpersonateSelf
GetSecurityDescriptorDacl
GetSecurityDescriptorGroup
GetSidSubAuthorityCount
GetSidLengthRequired
InitializeSid
GetSidSubAuthority
QuerySecurityAccessMask
GetKernelObjectSecurity
GetLengthSid
AddAccessAllowedAceEx
IsWellKnownSid
RevertToSelf
ImpersonateLoggedOnUser
DuplicateTokenEx
GetAce
InitializeAcl
FreeSid
InitializeSecurityDescriptor
GetSecurityDescriptorControl
AddAccessAllowedAce
AdjustTokenPrivileges
SetSecurityDescriptorDacl
SetFileSecurityW
IsValidSid
DuplicateToken
DeleteAce
AddAccessDeniedAceEx
SetTokenInformation
SetSecurityDescriptorOwner
AllocateAndInitializeSid
GetAclInformation
CopySid
AddAce
GetTokenInformation
AccessCheck
GetFileSecurityW
CheckTokenMembership
CreateWellKnownSid
CheckTokenCapability
SetSecurityDescriptorControl
EqualSid
GetSecurityDescriptorOwner
api-ms-win-shell-shellcom-l1-1-0.dll

api-ms-win-shell-shellfolders-l1-1-0.dll

SHGetFileInfoW
SHCreateDirectoryExW
SHGetSpecialFolderPathA
SHGetInstanceExplorer
SHGetDesktopFolder
PathCleanupSpec
SHGetKnownFolderPath
SHGetSpecialFolderPathW
SHGetFolderLocation
SHGetFolderPathA
SHGetFolderPathAndSubDirW
SHGetFolderPathW
PathIsExe
SHSetKnownFolderPath
gdi32.dll

SetBkMode
TextOutA
GetTextExtentPoint32A
CreateFontW
GetPixel
CreateDIBitmap
GetDIBits
ExtTextOutW
GetDIBColorTable
SetDIBits
GetObjectType
GetWindowOrgEx
GetRegionData
GetRgnBox
CombineRgn
SaveDC
RestoreDC
CreateRectRgnIndirect
SetDCBrushColor
PlgBlt
ExtSelectClipRgn
GetViewportOrgEx
DeleteMetaFile
PlayMetaFile
SetMetaFileBitsEx
LPtoDP
GetEnhMetaFileBits
GetClipBox
SelectClipRgn
IntersectClipRect
GetClipRgn
CreateRectRgn
SetViewportExtEx
SetViewportOrgEx
SetWindowExtEx
SetMapMode
GetTextAlign
CreatePolygonRgn
LineTo
MoveToEx
SetTextAlign
Rectangle
CreatePen
GetCurrentObject
GetTextColor
StretchBlt
SetStretchBltMode
CreateDIBSection
GdiTransparentBlt
CreateBitmap
GdiAlphaBlend
GetDeviceCaps
GetTextExtentPointW
SetWindowOrgEx
OffsetWindowOrgEx
DeleteObject
CreateFontA
EnumFontFamiliesA
AddFontResourceW
SetLayout
GetLayout
CreateCompatibleBitmap
GetTextFaceW
EnumFontFamiliesExW
CreateDCW
GetTextExtentPoint32W
CreateFontIndirectW
PatBlt
DeleteDC
BitBlt
CreateCompatibleDC
GetTextMetricsW
GetObjectW
SelectObject
SetBkColor
SetTextColor
GetStockObject
CreateSolidBrush
GetNearestColor
TranslateCharsetInfo
TextOutW
GdiFlush
SetFontEnumeration
FillRgn
OffsetRgn
CreateEllipticRgnIndirect
CreateICW
RealizePalette
SelectPalette
RectVisible
GetBitmapBits
CloseMetaFile
CreateMetaFileW
GetBkColor
SetRectRgn
GetPaletteEntries
StretchDIBits
CreateBitmapIndirect
SetPixel
ExtFloodFill
CreatePalette
CreatePatternBrush
CreateHalftonePalette
GetNearestPaletteIndex
Ellipse
Pie
Arc
GetObjectA
DeleteEnhMetaFile
PlayEnhMetaFile
SetBrushOrgEx
GetBrushOrgEx
CreateDIBPatternBrushPt
ExtTextOutA
kernel32.dll

PowerClearRequest
EnumResourceNamesW
PowerCreateRequest
PowerSetRequest
GetPackageFamilyName
OpenState
OpenStateExplicit
GetStateFolder
CloseState
PackageFamilyNameFromFullName
Wow64EnableWow64FsRedirection
CheckElevation
GetBinaryTypeW
GetCompressedFileSizeW
CreateWaitableTimerW
CheckAllowDecryptedRemoteDestinationPolicy
GetPackagesByPackageFamily
WritePrivateProfileSectionW
GetPrivateProfileSectionNamesW
timeGetTime
PackageNameAndPublisherIdFromFamilyName
GetSystemAppDataKey
GetPhysicallyInstalledSystemMemory
PackageIdFromFullName
OpenPackageInfoByFullName
GetPackageInfo
ClosePackageInfo
GetPackageFullName
ResolveLocaleName
LocaleNameToLCID
AssignProcessToJobObject
TerminateThread
GetProcessId
CreateIoCompletionPort
SetInformationJobObject
GetQueuedCompletionStatus
IsProcessInJob
CreateJobObjectW
ExpandEnvironmentStringsA
GetAtomNameW
FindResourceExW
SystemTimeToTzSpecificLocalTime
TzSpecificLocalTimeToSystemTime
LocalFileTimeToFileTime
FileTimeToLocalFileTime
LoadLibraryA
FlushInstructionCache
QueueUserWorkItem
CloseThreadpoolTimer
CreateThreadpoolTimer
SetThreadpoolTimer
CreateHardLinkW
CreateTimerQueueTimer
DeleteTimerQueueTimer
GetSystemWow64DirectoryW
GetProductInfo
FindAtomW
CancelSynchronousIo
UnregisterWait
GlobalFlags
SetVolumeLabelW
WaitForMultipleObjects
CreateSemaphoreW
LocalSize
RegisterWaitForSingleObject
UnregisterWaitEx
WritePrivateProfileStringW
QueryFullProcessImageNameW
ActivateActCtx
DeactivateActCtx
DosDateTimeToFileTime
FileTimeToDosDateTime
GlobalGetAtomNameW
FindResourceW
GetComputerNameW
MoveFileExW
LoadLibraryW
GetPrivateProfileStringW
MulDiv
GetPrivateProfileIntW
GetProfileIntW
GetShortPathNameA
GlobalUnlock
GlobalLock
GlobalReAlloc
DelayLoadFailureHook
GetTempPathW
GetDateFormatW
CheckElevationEnabled
GetProfileSectionW
GetVolumeNameForVolumeMountPointW
GlobalSize
ReplaceFileW
MoveFileW
QueryActCtxW
GlobalDeleteAtom
GlobalAddAtomW
GetNativeSystemInfo
CreateActCtxW
ReleaseActCtx
CopyFileW
WerpNotifyUseStringResource
ReadDirectoryChangesW
GetFileInformationByHandleEx
WTSGetActiveConsoleSessionId
GetPrivateProfileSectionW
GetVolumePathNamesForVolumeNameW
InitOnceExecuteOnce
GetSystemPreferredUILanguages
DllMain
kernelbase.dll

NotifyRedirectedStringChange
EnumSystemLocalesEx
GetNumberFormatW
LCIDToLocaleName
GetUserDefaultUILanguage
EnumUILanguagesW
IsDBCSLeadByte
msvcrt.dll
ntdll.dll

strchr
SbSelectProcedure
NtOpenThreadToken
EtwLogTraceEvent
RtlQueryPackageIdentity
RtlCompareUnicodeString
RtlAllocateHeap
RtlNtStatusToDosErrorNoTeb
RtlGetLastWin32Error
NtSetInformationToken
NtOpenProcessToken
NtQueryInformationToken
RtlQueryRegistryValuesEx
RtlCheckRegistryKey
NtQueryLicenseValue
NtQuerySystemInformation
NtQueryObject
RtlDowncaseUnicodeString
RtlOemStringToUnicodeString
RtlInitString
RtlDosPathNameToNtPathName_U
NtSetSecurityObject
NtQuerySecurityObject
ShipAssert
RtlIsTextUnicode
RtlFreeAnsiString
RtlUnicodeStringToAnsiString
NtQueryDirectoryFile
RtlRandomEx
RtlCreateUnicodeString
WinSqmIncrementDWORD
NtSetInformationThread
NtQueryInformationThread
WinSqmAddToStreamEx
RtlCreateServiceSid
RtlLengthRequiredSid
WinSqmIsOptedIn
RtlGetNtProductType
EtwEventRegister
EtwEventUnregister
EtwUnregisterTraceGuids
EtwRegisterTraceGuidsW
EtwGetTraceEnableFlags
EtwGetTraceEnableLevel
EtwGetTraceLoggerHandle
NtPowerInformation
WinSqmSetDWORD
NtQueryInformationProcess
NtQueryAttributesFile
RtlDosPathNameToRelativeNtPathName_U
RtlMapGenericMask
EtwTraceMessage
WinSqmAddToStream
EtwEventEnabled
RtlDestroyEnvironment
RtlSetCurrentEnvironment
RtlCreateEnvironment
RtlExpandEnvironmentStrings_U
RtlSetEnvironmentVariable
RtlQueryEnvironmentVariable_U
RtlInitUnicodeStringEx
RtlGetLastNtStatus
RtlFreeUnicodeString
RtlReleaseRelativeName
RtlDosPathNameToRelativeNtPathName_U_WithStatus
NtQueryVolumeInformationFile
RtlFreeHeap
RtlDosPathNameToNtPathName_U_WithStatus
NtOpenFile
NtSetInformationFile
RtlUnicodeStringToOemString
NtFsControlFile
NtClose
RtlInitializeResource
RtlAcquireResourceExclusive
RtlReleaseResource
RtlDeleteResource
RtlAcquireSRWLockExclusive
RtlReleaseSRWLockExclusive
NtCreateFile
RtlNtStatusToDosError
NtQueryInformationFile
RtlPrefixString
RtlInitUnicodeString
EtwEventWrite
wcscat_s
wcsncpy_s
NtSetEaFile
NtQueryEaFile
RtlConvertSidToUnicodeString
NtEnumerateValueKey
NtOpenKey
RtlImageNtHeader
rpcrt4.dll

RpcStringFreeW
RpcBindingFree
RpcAsyncCompleteCall
RpcAsyncCancelCall
RpcAsyncInitializeHandle
RpcBindingFromStringBindingW
RpcStringBindingComposeW
NdrAsyncClientCall
shlwapi.dll

IntlStrEqWorkerW
AssocIsDangerous
PathIsDirectoryA
StrFormatByteSizeEx
PathCompactPathW
SHSkipJunction
PathSetDlgItemPathW
PathIsContentTypeW
PathIsDirectoryEmptyW
PathFindSuffixArrayW
PathCompactPathExW
AssocQueryStringByKeyW
AssocQueryStringW
PathMakePrettyW
PathFindOnPathW
GetMenuPosFromID
AssocGetPerceivedType
PathRemoveArgsW
PathIsDirectoryW
AssocQueryKeyW
AssocCreate
StrFormatByteSizeW
SHAutoComplete
PathMakeSystemFolderW
ColorHLSToRGB
ColorRGBToHLS
DllMain
user32.dll
Export Table
activate_rundll
appcompat_rundllw
assoccreateforclasses
assocgetdetailsofpropkey
callcplentry16
cdeffoldermenu_create
cdeffoldermenu_create2
checkescapesa
checkescapesw
cidldata_createfromidarray
commandlinetoargvw
control_fillcache_rundll
control_fillcache_rundlla
control_fillcache_rundllw
control_rundll
control_rundlla
control_rundllasuserw
control_rundllw
dad_autoscroll
dad_dragenterex
dad_dragenterex2
dad_dragleave
dad_dragmove
dad_setdragimage
dad_showdragimage
dllcanunloadnow
dllgetactivationfactory
dllgetclassobject
dllgetversion
dllinstall
dllregisterserver
dllunregisterserver
doenvironmentsubsta
doenvironmentsubstw
dragacceptfiles
dragfinish
dragqueryfile
dragqueryfilea
dragqueryfileaorw
dragqueryfilew
dragquerypoint
drivetype
duplicateicon
extractassociatedicona
extractassociatediconexa
extractassociatediconexw
extractassociatediconw
extracticona
extracticonex
extracticonexa
extracticonexw
extracticonresinfoa
extracticonresinfow
extracticonw
extractversionresource16w
findexecutablea
findexecutablew
findexedlgproc
freeiconlist
getcurrentprocessexplicitappusermodelid
getfilenamefrombrowse
ilappendid
ilclone
ilclonefirst
ilcombine
ilcreatefrompath
ilcreatefrompatha
ilcreatefrompathw
ilfindchild
ilfindlastid
ilfree
ilgetnext
ilgetsize
ilisequal
ilisparent
illoadfromstream
illoadfromstreamex
ilremovelastid
ilsavetostream
initnetworkaddresscontrol
internalextracticonlista
internalextracticonlistw
islfndrive
islfndrivea
islfndrivew
isnetdrive
isuseranadmin
launchmshelp_rundllw
openas_rundll
openas_rundlla
openas_rundllw
openregstream
options_rundll
options_rundlla
options_rundllw
pathcleanupspec
pathcleanupspecworker
pathgetshortpath
pathisexe
pathisexeworker
pathisslowa
pathissloww
pathmakeuniquename
pathprocesscommand
pathqualify
pathresolve
pathyetanothermakeuniquename
pickicondlg
pifmgr_closeproperties
pifmgr_getproperties
pifmgr_openproperties
pifmgr_setproperties
preparediscforburnrundllw
printersgetcommand_rundll
printersgetcommand_rundlla
printersgetcommand_rundllw
readcabinetstate
realdrivetype
realshellexecutea
realshellexecuteexa
realshellexecuteexw
realshellexecutew
regenerateuserenvironment
restartdialog
restartdialogex
runasnewuser_rundllw
setcurrentprocessexplicitappusermodelid
shadddefaultpropertiesbyext
shaddfrompropsheetextarray
shaddtorecentdocs
shalloc
shallocshared
shappbarmessage
shassocenumhandlers
shassocenumhandlersforprotocolbyapplication
shbindtofolderidlistparent
shbindtofolderidlistparentex
shbindtoobject
shbindtoparent
shbrowseforfolder
shbrowseforfoldera
shbrowseforfolderw
shchangenotification_lock
shchangenotification_unlock
shchangenotify
shchangenotifyderegister
shchangenotifyregister
shchangenotifyregisterthread
shchangenotifysuspendresume
shclonespecialidlist
shclsidfromstring
shcocreateinstance
shcocreateinstanceworker
shcreateassociationregistration
shcreatedataobject
shcreatedefaultcontextmenu
shcreatedefaultextracticon
shcreatedefaultpropertiesop
shcreatedirectory
shcreatedirectoryexa
shcreatedirectoryexw
shcreatedirectoryexwworker
shcreatefileextracticonw
shcreateitemfromidlist
shcreateitemfromparsingname
shcreateitemfromrelativename
shcreateiteminknownfolder
shcreateitemwithparent
shcreatelocalserverrundll
shcreateprocessasuserw
shcreatepropsheetextarray
shcreatequerycancelautoplaymoniker
shcreateshellfolderview
shcreateshellfolderviewex
shcreateshellitem
shcreateshellitemarray
shcreateshellitemarrayfromdataobject
shcreateshellitemarrayfromidlists
shcreateshellitemarrayfromshellitem
shcreatestdenumfmtetc
shdefextracticona
shdefextracticonw
shdestroypropsheetextarray
shdodragdrop
shechangedira
shechangedirexa
shechangedirexw
shechangedirw
sheconvertpathw
shefullpatha
shefullpathw
shegetcurdrive
shegetdira
shegetdirexw
shegetdirw
shegetpathoffsetw
shell_getcachedimageindex
shell_getcachedimageindexa
shell_getcachedimageindexw
shell_getimagelists
shell_mergemenus
shell_notifyicon
shell_notifyicona
shell_notifyicongetrect
shell_notifyiconw
shellabouta
shellaboutw
shellexec_rundll
shellexec_rundlla
shellexec_rundllw
shellexecutea
shellexecuteex
shellexecuteexa
shellexecuteexw
shellexecutew
shellhookproc
shellmessageboxa
shellmessageboxw
shemptyrecyclebina
shemptyrecyclebinw
shenableserviceobject
shenumerateunreadmailaccountsw
sheremovequotesa
sheremovequotesw
shesetcurdrive
sheshortenpatha
sheshortenpathw
shevaluatesystemcommandtemplate
shextracticonsw
shfileoperation
shfileoperationa
shfileoperationw
shfind_initmenupopup
shfindfiles
shflushclipboard
shflushsfcache
shformatdrive
shfree
shfreenamemappings
shfreeshared
shgetattributesfromdataobject
shgetdatafromidlista
shgetdatafromidlistw
shgetdesktopfolder
shgetdesktopfolderworker
shgetdiskfreespacea
shgetdiskfreespaceexa
shgetdiskfreespaceexw
shgetdrivemedia
shgetfileinfo
shgetfileinfoa
shgetfileinfow
shgetfileinfowworker
shgetfolderlocation
shgetfolderlocationworker
shgetfolderpatha
shgetfolderpathandsubdira
shgetfolderpathandsubdirw
shgetfolderpathandsubdirwworker
shgetfolderpathaworker
shgetfolderpathex
shgetfolderpathw
shgetfolderpathwworker
shgeticonoverlayindexa
shgeticonoverlayindexw
shgetidlistfromobject
shgetimagelist
shgetinstanceexplorer
shgetinstanceexplorerworker
shgetitemfromdataobject
shgetitemfromobject
shgetknownfolderidlist
shgetknownfolderitem
shgetknownfolderpath
shgetknownfolderpathworker
shgetlocalizedname
shgetmalloc
shgetnamefromidlist
shgetnewlinkinfo
shgetnewlinkinfoa
shgetnewlinkinfow
shgetpathfromidlist
shgetpathfromidlista
shgetpathfromidlistex
shgetpathfromidlistw
shgetpropertystoreforwindow
shgetpropertystorefromidlist
shgetpropertystorefromparsingname
shgetrealidl
shgetsetfoldercustomsettings
shgetsetfoldercustomsettingsw
shgetsetsettings
shgetsettings
shgetshellstylehinstance
shgetspecialfolderlocation
shgetspecialfolderpatha
shgetspecialfolderpathaworker
shgetspecialfolderpathw
shgetspecialfolderpathwworker
shgetstockiconinfo
shgettemporarypropertyforitem
shgetunreadmailcountw
shhandleupdateimage
shhelpshortcuts_rundll
shhelpshortcuts_rundlla
shhelpshortcuts_rundllw
shilcreatefrompath
shinvokeprintercommanda
shinvokeprintercommandw
shisfileavailableoffline
shlimitinputedit
shloadinproc
shloadnonloadediconoverlayidentifiers
shloadole
shlockshared
shmapidlisttoimagelistindexasync
shmappidltosystemimagelistindex
shmultifileproperties
shobjectproperties
shopenfolderandselectitems
shopenpropsheetw
shopenwithdialog
shparsedisplayname
shpathprepareforwritea
shpathprepareforwritew
shpropstgcreate
shpropstgreadmultiple
shpropstgwritemultiple
shqueryrecyclebina
shqueryrecyclebinw
shqueryusernotificationstate
shremovelocalizedname
shreplacefrompropsheetextarray
shresolvelibrary
shrestricted
shruncontrolpanel
shsetdefaultproperties
shsetfolderpatha
shsetfolderpathw
shsetinstanceexplorer
shsetknownfolderpath
shsetknownfolderpathworker
shsetlocalizedname
shsettemporarypropertyforitem
shsetunreadmailcountw
shshellfolderview_message
shshowmanagelibraryui
shsimpleidlistfrompath
shstartnetconnectiondialogw
shtesttokenmembership
shunlockshared
shupdateimagea
shupdateimagew
shupdaterecyclebinicon
shvalidateunc
signalfileopen
stgmakeuniquename
strchra
strchria
strchriw
strchrw
strcmpna
strcmpnia
strcmpniw
strcmpnw
strcpyna
strcpynw
strncmpa
strncmpia
strncmpiw
strncmpw
strncpya
strncpyw
strrchra
strrchria
strrchriw
strrchrw
strrstra
strrstria
strrstriw
strrstrw
strstra
strstria
strstriw
strstrw
waitforexplorerrestartw
win32deletefile
wowshellexecute
writecabinetstate