File details
File name: explorer.exe
Name: Windows Explorer
Description: Microsoft® Windows® Operating System
Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product version: 6.1.7600.16385
Size: 2.74 MB
Original file name: EXPLORER.EXE.MUI
Windows file protection:
Yes
Digital certificate
Certificate authority:
Microsoft Corporation
Expiration date: 7/9/2013
Resource utilization
 | CPU utilization averages |
Total CPU: 0.0051815244%
Privileged CPU:
0.0023638188%

User CPU:
0.00281770565084%

Privileged CPU time: 169768372.26 ms
Privileged CPU time /min: 52,996 ms
CPU cycle count:
150,052,038
CPU cycle count /min: 298,218,133
Context switches /sec:
63
 | Memory utilization averages |
Committed memory:
398.03 MB
Peak committed memory: 499.99 MB
Paged memory:
62.88 MB
Peak paged memory: 126.3 MB
Paged system memory:
558.62 KB
Non-paged system memory: 78.41 KB
Working set memory:
63.19 MB
Peak working set memory: 87.01 MB
Min working set memory: 37.52 MB
Private memory:
62.88 MB
Page faults:
2,088,067
Page faults /min: 1,452
 | Process I/O averages |
Total read operations:
117,960
Read operations /min: 199
Total read transfer: 50.88 MB
Read transfer /min: 538.59 KB
Total write operations:
8,893
Write operations /min: 5
Total write transfer: 38.39 MB
Write transfer /min: 242.78 KB
Total other operations:
454,053
Other operations /min: 310
Total other transfer: 33.71 MB
Other Transfer /min: 12.65 KB
 | GUI Object Averages |
GDI objects:
503
Peak GDI objects: 688
USER objects:
288
Peak USER objects: 437
Resources
Handle count average: 966
Thread count average: 28
Thread resource averages
Total CPU: 21.044187796936%
Privileged CPU: 3.821175332683%
User CPU: 17.223012464253%
CPU Cycle count /sec: 633,048,138
Module memory size: 240 KB
Total CPU: 18.986886021078%
Privileged CPU: 16.499066855741%
User CPU: 2.487819165337%
CPU Cycle count /sec: 442,819,737
Context switches /sec: 1,036
Module memory size: 168 KB
Total CPU: 0.324328745619%
Privileged CPU: 0.212999852890%
User CPU: 0.111328892729%
CPU Cycle count /sec: 6,838,802
Context switches /sec: 5
Module memory size: 100 KB
Total CPU: 0.053432629906%
Privileged CPU: 0.031959115255%
User CPU: 0.021473514652%
CPU Cycle count /sec: 1,652,815
Context switches /sec: 39
Module memory size: 148 KB
Total CPU: 0.045942343047%
Privileged CPU: 0.020418819351%
User CPU: 0.025523523696%
CPU Cycle count /sec: 4,578,302
Module memory size: 100 KB
Total CPU: 0.043999999609%
Privileged CPU: 0.019704252435%
User CPU: 0.024295747174%
CPU Cycle count /sec: 1,184,681
Context switches /sec: 6
Module memory size: 2.75 MB
Total CPU: 0.042569081995%
Privileged CPU: 0.026326661208%
User CPU: 0.016242420787%
CPU Cycle count /sec: 905,758
Context switches /sec: 48
Module memory size: 204 KB
Total CPU: 0.039380334991%
Privileged CPU: 0.030629149438%
User CPU: 0.008751185554%
CPU Cycle count /sec: 1,713,475
Context switches /sec: 39
Module memory size: 176 KB
qvodextend_x64.dll

Total CPU: 0.039168508674%
Privileged CPU: 0.035215306541%
User CPU: 0.003953202132%
CPU Cycle count /sec: 5,698,344
Context switches /sec: 2
Module memory size: 492 KB
Total CPU: 0.038669089536%
Privileged CPU: 0.027039999040%
User CPU: 0.011629090496%
CPU Cycle count /sec: 905,648
Module memory size: 168 KB
ntdll.dll

Total CPU: 0.030392444454%
Privileged CPU: 0.012368418974%
User CPU: 0.018024025480%
CPU Cycle count /sec: 851,364
Context switches /sec: 1
Module memory size: 1.66 MB
ntdll.dll

Total CPU: 0.029578014496%
Privileged CPU: 0.014941729398%
User CPU: 0.014636285099%
CPU Cycle count /sec: 683,502
Context switches /sec: 1
Module memory size: 1.66 MB
shlwapi.dll

Total CPU: 0.028970908825%
Privileged CPU: 0.016418798120%
User CPU: 0.012552110705%
CPU Cycle count /sec: 1,387,250
Context switches /sec: 4
Module memory size: 452 KB
Total CPU: 0.024815520445%
Privileged CPU: 0.016287586174%
User CPU: 0.008527934270%
CPU Cycle count /sec: 617,537
Context switches /sec: 8
Module memory size: 148 KB
Total CPU: 0.022622062676%
Privileged CPU: 0.014773591952%
User CPU: 0.007848470724%
CPU Cycle count /sec: 394,944
Context switches /sec: 8
Module memory size: 160 KB
Total CPU: 0.022588058371%
Privileged CPU: 0.013409527100%
User CPU: 0.009178531272%
CPU Cycle count /sec: 466,484
Context switches /sec: 9
Module memory size: 160 KB
ntdll.dll

Total CPU: 0.021205254497%
Privileged CPU: 0.006972104948%
User CPU: 0.014233149549%
CPU Cycle count /sec: 391,381
Context switches /sec: 2
Module memory size: 1.66 MB
wcnapi.dll

Total CPU: 0.020058094418%
Privileged CPU: 0.003997863697%
User CPU: 0.016060230721%
CPU Cycle count /sec: 251,580
Context switches /sec: 2
Module memory size: 136 KB
Total CPU: 0.015769594550%
Privileged CPU: 0.013279658569%
User CPU: 0.002489935982%
CPU Cycle count /sec: 957,245
Context switches /sec: 20
Module memory size: 176 KB
Total CPU: 0.014342164719%
Privileged CPU: 0.014342164719%
User CPU: 0.000000000000%
CPU Cycle count /sec: 13,785,968
Module memory size: 736 KB
Process details
Runs as (owner): User
Integrety level: High
Windows platform: 64-bit
System Tray: Yes
Parent Processes
Process Commands
"C:\Windows\explorer.exe"
C:\Windows\Explorer.EXE
explorer.exe
EXPLORER.EXE
C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -Embedding
Shell open command details
Name: SHCmdFile
Command: C:\Windows\explorer.exe
Autoplay handler details
Name: MSOpenFolderBackup
Command: SOFTWARE\Microsoft\Windows\ CurrentVersion\Explorer\AutoplayHandlers\Handlers\MSOpenFolderBackup
Scheduled task details
CLSID: {AD36F1D3-E56E-44BA-A569-280718EB8C51}
Command: \{AD36F1D3-E56E-44BA-A569-280718EB8C51}
Network connectivity
TCP: localhost on port 58546
UDP: LISTENING on port 56516
UDP: LISTENING on port 65416
UDP: LISTENING on port 52198
UDP: LISTENING on port 49213
UDP: LISTENING on port 58229
TCP: localhost on port 50098
TCP: localhost on port 49729
UDP: LISTENING on port 60410
Image hashes
MD5: 332feab1435662fc6c672e25beb37be3
SHA-1: 5a49d7390ee87519b9d69d3e4aa66ca066cc8255
SHA-256: 6bed1a3a956a859ef4420feb2466c040800eaf01ef53214ef9dab53aeff1cff0
PE image details
Langauge*: Microsoft Visual C++
File entropy: 5.93423
File packed: No
Import Table
advapi32.dll

RegCloseKey
RegCreateKeyW
RegGetValueW
RegOpenKeyExW
GetTraceEnableFlags
GetTraceEnableLevel
GetTraceLoggerHandle
RegisterTraceGuidsW
UnregisterTraceGuids
RegCreateKeyExW
RegQueryValueExW
EventRegister
EventUnregister
EventWrite
EventEnabled
GetLengthSid
GetTokenInformation
OpenProcessToken
RegSetValueExW
RegDeleteKeyExW
TraceMessage
RegOpenKeyW
RegDeleteValueW
RegEnumValueW
RegQueryInfoKeyW
ConvertStringSidToSidW
CloseServiceHandle
OpenServiceW
OpenSCManagerW
RegEnumKeyExW
CreateWellKnownSid
StartServiceW
CryptAcquireContextW
CryptCreateHash
CryptHashData
CryptGetHashParam
CryptDestroyHash
CryptReleaseContext
StartTraceW
EnableTraceEx
StopTraceW
LsaLookupSids
IsValidSid
GetSidSubAuthorityCount
GetSidSubAuthority
LsaOpenPolicy
LsaFreeMemory
LsaClose
OpenThreadToken
ConvertSidToStringSidW
ConvertStringSecurityDescriptorToSecurityDescriptorW
CheckTokenMembership
QueryServiceStatus
GetUserNameW
RegEnumKeyW
RegOpenCurrentUser
LookupAccountNameW
EqualSid
api-ms-win-core-atoms-l1-1-0.dll

api-ms-win-core-com-l1-1-0.dll

CoTaskMemFree
CoInitializeEx
CoUninitialize
CreateStreamOnHGlobal
CoGetApartmentType
CoWaitForMultipleHandles
CoFreeUnusedLibraries
CoEnableCallCancellation
CoDisableCallCancellation
CoCancelCall
StringFromGUID2
PropVariantClear
CoMarshalInterThreadInterfaceInStream
CoReleaseMarshalData
CoCreateInstance
CoRevokeClassObject
CoRegisterClassObject
CoGetInterfaceAndReleaseStream
CoGetMalloc
CoCreateFreeThreadedMarshaler
CoTaskMemAlloc
CLSIDFromString
CoTaskMemRealloc
api-ms-win-core-com-l1-1-1.dll

CoCreateGuid
CoTaskMemRealloc
CoInitializeEx
CLSIDFromString
CoTaskMemFree
CoCreateInstance
CoTaskMemAlloc
CoGetMalloc
PropVariantClear
CoCancelCall
CoRevokeClassObject
StringFromGUID2
CoGetApartmentType
CreateStreamOnHGlobal
CoSetProxyBlanket
CoWaitForMultipleHandles
CoGetInterfaceAndReleaseStream
CoUninitialize
CoReleaseMarshalData
CoMarshalInterThreadInterfaceInStream
CoFreeUnusedLibraries
CoRegisterClassObject
CoDisableCallCancellation
CoEnableCallCancellation
CoCreateFreeThreadedMarshaler
RoGetAgileReference
api-ms-win-core-com-private-l1-1-0.dll

api-ms-win-core-datetime-l1-1-1.dll

GetDateFormatW
GetDateFormatEx
GetTimeFormatEx
api-ms-win-core-delayload-l1-1-1.dll

DelayLoadFailureHook
ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll

SetErrorMode
SetUnhandledExceptionFilter
SetLastError
GetLastError
RaiseException
UnhandledExceptionFilter
api-ms-win-core-file-l1-2-0.dll

GetLongPathNameW
ReadFile
CreateFileW
WriteFile
GetFileSize
FindClose
CompareFileTime
DeleteFileW
FindNextFileW
FindFirstFileW
GetFileAttributesW
api-ms-win-core-file-l1-2-1.dll

WriteFile
CreateFileW
FindClose
CreateDirectoryW
FindNextFileW
CompareFileTime
FindFirstFileW
GetFileAttributesW
DeleteFileW
FindFirstFileExW
RemoveDirectoryW
GetLongPathNameW
api-ms-win-core-handle-l1-1-0.dll

DuplicateHandle
CloseHandle
api-ms-win-core-heap-l1-2-0.dll

HeapFree
HeapDestroy
HeapSetInformation
HeapAlloc
GetProcessHeap
api-ms-win-core-heap-obsolete-l1-1-0.dll

LocalFree
GlobalFree
GlobalAlloc
LocalReAlloc
LocalAlloc
GlobalLock
GlobalUnlock
api-ms-win-core-interlocked-l1-2-0.dll

InterlockedPushEntrySList
InterlockedPopEntrySList
InterlockedExchange
InterlockedIncrement
InterlockedCompareExchange
InterlockedDecrement
api-ms-win-core-io-l1-1-1.dll

GetQueuedCompletionStatus
CreateIoCompletionPort
api-ms-win-core-job-l2-1-0.dll

AssignProcessToJobObject
QueryInformationJobObject
CreateJobObjectW
SetInformationJobObject
api-ms-win-core-kernel32-legacy-l1-1-0.dll

CopyFileW
RaiseFailFastException
MulDiv
LoadLibraryW
GetComputerNameW
api-ms-win-core-kernel32-legacy-l1-1-1.dll

RaiseFailFastException
CreateSemaphoreW
PowerCreateRequest
MoveFileW
CopyFileW
MulDiv
LoadLibraryW
PowerSetRequest
RegisterWaitForSingleObject
api-ms-win-core-libraryloader-l1-1-1.dll

LoadStringW
FindResourceExW
LoadResource
LockResource
LoadLibraryExW
GetModuleHandleW
FreeLibrary
GetProcAddress
GetModuleHandleExW
FreeLibraryAndExitThread
GetModuleHandleA
GetModuleFileNameW
api-ms-win-core-localization-l1-2-0.dll

GetLocaleInfoW
GetThreadUILanguage
api-ms-win-core-localization-l1-2-1.dll

FormatMessageW
GetUserPreferredUILanguages
IsValidLocaleName
GetThreadUILanguage
GetLocaleInfoW
api-ms-win-core-localization-obsolete-l1-1-0.dll

api-ms-win-core-localization-obsolete-l1-2-0.dll

api-ms-win-core-memory-l1-1-1.dll

MapViewOfFile
VirtualAlloc
UnmapViewOfFile
CreateFileMappingW
VirtualFree
api-ms-win-core-memory-l1-1-2.dll

VirtualFree
CreateFileMappingW
MapViewOfFile
UnmapViewOfFile
VirtualAlloc
api-ms-win-core-path-l1-1-0.dll

PathCchCombine
PathCchAppend
PathCchAddExtension
api-ms-win-core-processenvironment-l1-2-0.dll

GetCommandLineW
ExpandEnvironmentStringsW
SearchPathW
GetCurrentDirectoryW
api-ms-win-core-processthreads-l1-1-1.dll

SetProcessShutdownParameters
GetCurrentThreadId
GetCurrentThread
GetCurrentProcessId
CreateProcessW
GetStartupInfoW
OpenProcessToken
GetThreadPriority
OpenProcess
OpenThreadToken
CreateThread
SetPriorityClass
OpenThread
GetPriorityClass
TerminateProcess
ResumeThread
FlushInstructionCache
IsProcessorFeaturePresent
GetProcessId
GetCurrentProcess
ExitProcess
SetThreadPriority
TerminateThread
api-ms-win-core-processthreads-l1-1-2.dll

TerminateThread
GetExitCodeProcess
SetThreadPriorityBoost
TlsFree
GetPriorityClass
TerminateProcess
OpenProcessToken
QueueUserAPC
ResumeThread
SetPriorityClass
GetCurrentThread
TlsAlloc
FlushInstructionCache
GetCurrentProcess
SetProcessShutdownParameters
CreateThread
GetProcessId
OpenProcess
CreateProcessW
IsProcessorFeaturePresent
TlsSetValue
ExitProcess
GetThreadPriority
OpenThreadToken
GetCurrentThreadId
GetCurrentProcessId
SetThreadPriority
GetStartupInfoW
OpenThread
api-ms-win-core-profile-l1-1-0.dll

QueryPerformanceCounter
QueryPerformanceFrequency
api-ms-win-core-psapi-l1-1-0.dll

QueryFullProcessImageNameW
api-ms-win-core-registry-l1-1-0.dll

RegDeleteValueW
RegQueryInfoKeyW
RegEnumKeyExW
RegQueryValueExW
RegCreateKeyExW
RegCloseKey
RegOpenKeyExW
RegGetValueW
RegEnumValueW
RegOpenCurrentUser
RegSetValueExW
api-ms-win-core-registry-l2-1-0.dll

RegCreateKeyW
RegDeleteKeyW
api-ms-win-core-registryuserspecific-l1-1-0.dll

SHRegGetUSValueW
SHRegGetBoolUSValueW
api-ms-win-core-shlwapi-legacy-l1-1-0.dll

PathStripPathW
SHExpandEnvironmentStringsW
PathFindExtensionW
PathParseIconLocationW
PathFileExistsW
PathGetDriveNumberW
PathCommonPrefixW
PathRemoveBlanksW
PathFindFileNameW
PathRemoveExtensionW
PathCombineW
PathIsFileSpecW
PathGetArgsW
PathRemoveFileSpecW
PathQuoteSpacesW
PathStripToRootW
PathIsRootW
PathIsPrefixW
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll

StrCmpW
StrCmpICA
SHLoadIndirectString
StrCmpIW
StrCmpNIW
StrRStrIW
StrCmpICW
StrChrW
StrToIntW
QISearch
StrCmpNICW
StrChrIW
StrStrIW
StrTrimW
StrCmpNW
StrCmpCW
api-ms-win-core-sidebyside-l1-1-0.dll

CreateActCtxW
ReleaseActCtx
ActivateActCtx
DeactivateActCtx
api-ms-win-core-string-l1-1-0.dll

MultiByteToWideChar
CompareStringOrdinal
WideCharToMultiByte
CompareStringW
api-ms-win-core-string-l2-1-0.dll

IsCharAlphaNumericW
CharPrevW
CharUpperW
CharNextW
CharLowerW
api-ms-win-core-string-obsolete-l1-1-0.dll

api-ms-win-core-synch-l1-2-0.dll

InitOnceExecuteOnce
Sleep
OpenMutexW
ReleaseMutex
LeaveCriticalSection
EnterCriticalSection
DeleteCriticalSection
InitializeCriticalSectionEx
CreateEventExW
WaitForSingleObject
InitializeCriticalSection
CreateMutexW
CreateEventW
WaitForMultipleObjectsEx
OpenSemaphoreW
InitializeSRWLock
ResetEvent
AcquireSRWLockExclusive
ReleaseSRWLockExclusive
AcquireSRWLockShared
ReleaseSRWLockShared
ReleaseSemaphore
OpenEventW
SleepEx
SetEvent
api-ms-win-core-sysinfo-l1-2-0.dll

GetTickCount64
GetTickCount
GetProductInfo
GetVersionExW
GetSystemDirectoryW
GetSystemTimeAsFileTime
GetSystemTime
GetWindowsDirectoryW
GetLocalTime
api-ms-win-core-sysinfo-l1-2-1.dll

GetTickCount64
GetLocalTime
GetSystemTime
GetProductInfo
GetVersionExW
GetTickCount
GetSystemTimeAsFileTime
GetWindowsDirectoryW
GetSystemDirectoryW
api-ms-win-core-threadpool-l1-2-0.dll

CreateThreadpoolTimer
FreeLibraryWhenCallbackReturns
SubmitThreadpoolWork
CallbackMayRunLong
CloseThreadpoolTimer
CreateThreadpoolWork
SetThreadpoolWait
CreateThreadpoolWait
TrySubmitThreadpoolCallback
SetThreadpoolTimer
WaitForThreadpoolTimerCallbacks
api-ms-win-core-threadpool-legacy-l1-1-0.dll

CreateTimerQueueTimer
UnregisterWaitEx
ChangeTimerQueueTimer
DeleteTimerQueueTimer
QueueUserWorkItem
api-ms-win-core-timezone-l1-1-0.dll

GetDynamicTimeZoneInformation
SystemTimeToFileTime
GetTimeZoneInformation
api-ms-win-core-winrt-l1-1-0.dll

api-ms-win-core-winrt-string-l1-1-0.dll

WindowsCreateStringReference
WindowsCreateString
WindowsGetStringRawBuffer
WindowsDeleteString
api-ms-win-eventing-classicprovider-l1-1-0.dll

GetTraceEnableLevel
GetTraceEnableFlags
RegisterTraceGuidsW
UnregisterTraceGuids
GetTraceLoggerHandle
TraceMessage
api-ms-win-eventing-controller-l1-1-0.dll

EnableTraceEx2
StartTraceW
StopTraceW
api-ms-win-eventing-provider-l1-1-0.dll

EventWrite
EventRegister
EventUnregister
EventEnabled
api-ms-win-power-base-l1-1-0.dll

CallNtPowerInformation
GetPwrCapabilities
api-ms-win-security-base-l1-2-0.dll

GetLengthSid
CopySid
CreateWellKnownSid
IsValidSid
CheckTokenMembership
GetTokenInformation
GetSidSubAuthority
GetSidSubAuthorityCount
api-ms-win-security-lsalookup-l1-1-1.dll

EnumerateIdentityProviders
ReleaseIdentityProviderEnumContext
GetIdentityProviderInfoByGUID
GetDefaultIdentityProvider
api-ms-win-service-management-l2-1-0.dll

QueryServiceConfigW
NotifyServiceStatusChangeW
d3d11.dll

dwmapi.dll

DwmEnableBlurBehindWindow
DwmIsCompositionEnabled
DwmSetWindowAttribute
DwmQueryThumbnailSourceSize
DwmUnregisterThumbnail
DwmUpdateThumbnailProperties
DwmGetColorizationColor
DwmRegisterThumbnail
gdi32.dll

GetStockObject
SetWindowOrgEx
StretchBlt
GetTextMetricsW
CombineRgn
Polyline
CreatePen
GetTextColor
ExtCreateRegion
GetRegionData
SetLayout
GetLayout
GetTextExtentPoint32W
OffsetRgn
LPtoDP
GetRgnBox
OffsetViewportOrgEx
GdiFlush
ExtTextOutW
SetDIBits
CreateRectRgn
GetClipRgn
IntersectClipRect
GetViewportOrgEx
SetViewportOrgEx
SelectClipRgn
GetBkColor
SetBkMode
CreateBitmap
PatBlt
CreateCompatibleBitmap
OffsetWindowOrgEx
SetBkColor
SetTextColor
GetTextExtentPointW
GetClipBox
CreateDIBSection
GetObjectW
CreateRectRgnIndirect
DeleteObject
CreateCompatibleDC
SelectObject
BitBlt
GetDeviceCaps
CreateFontIndirectW
DeleteDC
GdiAlphaBlend
CreatePatternBrush
GetPixel
CreateSolidBrush
SetTextAlign
GetDIBits
Rectangle
StretchDIBits
gdiplus.dll

GdipAlloc
GdiplusStartup
GdiplusShutdown
GdipFree
GdipDeleteGraphics
GdipDisposeImage
GdipGetImageWidth
GdipGetImageHeight
GdipCreateBitmapFromHBITMAP
GdipCreateFromHDC
GdipSetCompositingMode
GdipSetInterpolationMode
GdipDrawImageRectI
GdipCloneImage
GdipCreateBitmapFromStream
GdipLoadImageFromFileICM
GdipLoadImageFromFile
GdipCreateBitmapFromStreamICM
kernel32.dll
msvcrt.dll
ntdll.dll

WinSqmSetString
NtQueryInformationProcess
NtSetInformationProcess
WinSqmIsOptedIn
NtOpenThreadToken
NtOpenProcessToken
NtClose
WinSqmAddToStreamEx
NtSetSystemInformation
WinSqmAddToStream
WinSqmEventEnabled
WinSqmSetDWORD
EtwEventWrite
EtwEventEnabled
NtQueryInformationToken
RtlGetProductInfo
RtlNtStatusToDosError
RtlUnsubscribeWnfNotificationWaitForCompletion
RtlSubscribeWnfStateChangeNotification
RtlQueryWnfStateData
WinSqmIncrementDWORD
ole32.dll

OleInitialize
StringFromGUID2
CoRegisterMessageFilter
RegisterDragDrop
RevokeDragDrop
OleUninitialize
CoRevokeClassObject
CoCreateFreeThreadedMarshaler
CreateBindCtx
PropVariantClear
ReleaseStgMedium
CoInitializeEx
CreateStreamOnHGlobal
CoRegisterClassObject
CoCreateInstance
CoTaskMemFree
CoGetInterfaceAndReleaseStream
CoMarshalInterThreadInterfaceInStream
CoUninitialize
CoInitialize
CoGetMalloc
CoTaskMemAlloc
CLSIDFromString
CoFreeUnusedLibraries
CoGetClassObject
CoGetObject
DoDragDrop
CoTaskMemRealloc
CoReleaseMarshalData
CoGetApartmentType
CoWaitForMultipleHandles
powrprof.dll

CallNtPowerInformation
GetPwrCapabilities
PowerDeterminePlatformRole
propsys.dll

PropVariantToUInt32
PropVariantToStringAlloc
PropVariantToUInt64
PropVariantToBoolean
VariantToStringAlloc
VariantToStringWithDefault
PropVariantToString
VariantToBooleanWithDefault
VariantToInt32WithDefault
PSCreateMemoryPropertyStore
PropVariantToInt64
PSGetPropertyKeyFromName
PSPropertyKeyFromString
PSGetNameFromPropertyKey
PSGetPropertyDescription
PSPropertyBag_WriteDWORD
InitVariantFromResource
PropVariantToGUID
rpcrt4.dll

RpcBindingFree
RpcBindingSetAuthInfoExW
RpcStringFreeW
RpcBindingFromStringBindingW
RpcStringBindingComposeW
I_RpcExceptionFilter
NdrClientCall2
secur32.dll

shcore.dll

IsOS
SHStrDupW
IUnknown_Set
IUnknown_QueryService
SHUnicodeToAnsi
SetProcessReference
SHCreateThreadRef
SHSetThreadRef
IUnknown_SetSite
SHRegGetValueW
SHGetValueW
SHSetValueW
SHDeleteValueW
SHCreateThread
SetCurrentProcessExplicitAppUserModelID
SHQueryValueExW
SHOpenRegStream2W
IStream_Reset
IStream_Read
SHCreateMemStream
SHAnsiToUnicode
IStream_Write
SHDeleteKeyW
GetDpiForMonitor
SHEnumKeyExW
SHGetThreadRef
SHQueryInfoKeyW
SHCreateStreamOnFileW
SHStrDupA
shell32.dll
shlwapi.dll
slc.dll

SLGetWindowsInformationDWORD
SLUnregisterWindowsEvent
SLRegisterWindowsEvent
sspicli.dll

user32.dll
userenv.dll

uxtheme.dll

BeginBufferedPaint
IsCompositionActive
IsAppThemed
GetThemeMetric
CloseThemeData
OpenThemeData
SetWindowTheme
DrawThemeBackground
GetThemeTextExtent
DrawThemeText
DrawThemeParentBackground
GetWindowTheme
GetThemePartSize
GetThemeBackgroundContentRect
EndBufferedPaint
GetThemeMargins
DrawThemeTextEx
BufferedPaintInit
BufferedPaintUnInit
IsThemeActive
GetThemeRect
IsThemePartDefined
GetThemeBackgroundRegion
GetThemeColor
GetThemeBool
DrawThemeIcon
GetBufferedPaintBits
BufferedPaintClear
GetThemeBackgroundExtent
GetThemeFont
GetThemeInt
GetCurrentThemeName
wtsapi32.dll

WTSFreeMemory
WTSQuerySessionInformationW