0c08189067fcb42c520b970d1fa7d5bf

Summary

Architecture IMAGE_FILE_MACHINE_AMD64
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date 1963-Nov-29 19:10:33
Detected languages English - United States
Debug artifacts Taskmgr.pdb
CompanyName Microsoft Corporation
FileDescription Task Manager
FileVersion 10.0.18362.1 (WinBuild.160101.0800)
InternalName Task Manager
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename Taskmgr.exe
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.18362.1

Plugin Output

Suspicious Strings found in the binary may indicate undesirable behavior: Contains references to system / monitoring tools:
  • Taskmgr.exe
  • rundll32.exe
  • taskmgr.exe
Contains references to internet browsers:
  • chrome.exe
  • firefox.exe
  • iexplore.exe
Contains references to security software:
  • msmpeng.exe
Tries to detect virtualized environments:
  • HARDWARE\DESCRIPTION\System
May have dropper capabilities:
  • CurrentControlSet\Services
  • CurrentVersion\Run
Miscellaneous malware strings:
  • cmd.exe
Suspicious The PE is possibly packed. Unusual section name found: .imrsiv
Unusual section name found: .didat
Malicious The PE contains functions mostly used by malware. [!] The program may be hiding some of its imports:
  • LoadLibraryExW
  • GetProcAddress
  • LoadLibraryW
Functions which can be used for anti-debugging purposes:
  • NtQueryInformationProcess
  • NtQuerySystemInformation
  • FindWindowW
Code injection capabilities (PowerLoader):
  • GetWindowLongW
  • FindWindowW
Can access the registry:
  • RegQueryValueExW
  • RegDeleteValueW
  • RegOpenKeyExW
  • RegNotifyChangeKeyValue
  • RegCreateKeyExW
  • RegQueryInfoKeyW
  • RegSetValueExW
  • RegCloseKey
  • RegGetValueW
  • RegEnumValueW
Possibly launches other programs:
  • CreateProcessW
  • ShellExecuteW
Uses Windows's Native API:
  • NtPowerInformation
  • NtSetInformationFile
  • NtQuerySystemInformationEx
  • NtQueryInformationProcess
  • ZwQueryWnfStateData
  • NtSetInformationProcess
  • NtQuerySystemInformation
  • NtQueryInformationFile
  • NtQueryObject
  • NtQueryTimerResolution
  • NtQueryInformationThread
  • NtQueryInformationToken
  • NtOpenFile
Can create temporary files:
  • GetTempPathW
  • CreateFileW
Functions related to the privilege level:
  • OpenProcessToken
  • CheckTokenMembership
  • AdjustTokenPrivileges
Enumerates local disk drives:
  • GetDriveTypeW
  • GetLogicalDriveStringsW
Manipulates other processes:
  • OpenProcess
  • ReadProcessMemory
Can take screenshots:
  • GetDC
  • FindWindowW
Info The PE is digitally signed. Signer: Microsoft Windows
Issuer: Microsoft Windows Production PCA 2011
Safe VirusTotal score: 0/70 (Scanned on 2019-09-08 08:13:03) All the AVs think this file is safe.

Hashes

MD5 0c08189067fcb42c520b970d1fa7d5bf
SHA1 5a16bd59c698b992c73bd6064c1b198005d52d71
SHA256 a0331f8199b5f56fa1647023535eb897e495ae0ccffc21e28670edbef9ae9153
SHA3 8436022980b9083fc4e4eb7d8eac9f77f8ddabb6a5d74c2247c52c9fb8bd8712
SSDeep 24576:9y1cjVdLKIxeWPZ17y9o/2n/2GOEIROqzfqyKQKiVydUul:IweWjSBn/2OGzfqyKQVVydt
Imports Hash e4f329a78957ffc58d5575e15b1f4fad

DOS Header

e_magic MZ
e_cblp 0x90
e_cp 0x3
e_crlc 0
e_cparhdr 0x4
e_minalloc 0
e_maxalloc 0xffff
e_ss 0
e_sp 0xb8
e_csum 0
e_ip 0
e_cs 0
e_ovno 0
e_oemid 0
e_oeminfo 0
e_lfanew 0xf8

PE Header

Signature PE
Machine IMAGE_FILE_MACHINE_AMD64
NumberofSections 8
TimeDateStamp 1963-Nov-29 19:10:33
PointerToSymbolTable 0
NumberOfSymbols 0
SizeOfOptionalHeader 0xf0
Characteristics IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LARGE_ADDRESS_AWARE

Image Optional Header

Magic PE32+
LinkerVersion 14.0
SizeOfCode 0xaf200
SizeOfInitializedData 0x5a600
SizeOfUninitializedData 0x200
AddressOfEntryPoint 0x0000000000005CC0 (Section: .text)
BaseOfCode 0x1000
ImageBase 0x140000000
SectionAlignment 0x1000
FileAlignment 0x200
OperatingSystemVersion A.0
ImageVersion A.0
SubsystemVersion A.0
Win32VersionValue 0
SizeOfImage 0x10e000
SizeOfHeaders 0x400
Checksum 0x10ccdc
Subsystem IMAGE_SUBSYSTEM_WINDOWS_GUI
DllCharacteristics IMAGE_DLLCHARACTERISTICS_DYNAMIC_BASE
IMAGE_DLLCHARACTERISTICS_FORCE_INTEGRITY
IMAGE_DLLCHARACTERISTICS_GUARD_CF
IMAGE_DLLCHARACTERISTICS_HIGH_ENTROPY_VA
IMAGE_DLLCHARACTERISTICS_NX_COMPAT
IMAGE_DLLCHARACTERISTICS_TERMINAL_SERVER_AWARE
SizeofStackReserve 0x80000
SizeofStackCommit 0x2000
SizeofHeapReserve 0x100000
SizeofHeapCommit 0x1000
LoaderFlags 0
NumberOfRvaAndSizes 16

.text

MD5 7e8ce835fd85de88b5842aeea6fd7cd0
SHA1 4494d78a8dea78ef3336e657ea877a27323a2635
SHA256 058f1f799c4f5c1da3b739d315968d3aec42f8aadb9c7748a1dc9faf26e45e83
SHA3 16ab4313b88b9499a1ffbd304c27bbed831ecca76f51a3af3172b8779556e291
VirtualSize 0xaf1a6
VirtualAddress 0x1000
SizeOfRawData 0xaf200
PointerToRawData 0x400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_CODE
IMAGE_SCN_MEM_EXECUTE
IMAGE_SCN_MEM_READ
Entropy 6.3922

.imrsiv

MD5 d41d8cd98f00b204e9800998ecf8427e
SHA1 da39a3ee5e6b4b0d3255bfef95601890afd80709
SHA256 e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
SHA3 a7ffc6f8bf1ed76651c14756a061d662f580ff4de43b49fa82d80a4b80f8434a
VirtualSize 0x4
VirtualAddress 0xb1000
SizeOfRawData 0
PointerToRawData 0
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_UNINITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE

.rdata

MD5 1d28ddf9fb8f387f91b061d6ededc1a3
SHA1 2a2b9b44e00bc4c3cb5c2a0413638b4417dc695a
SHA256 3f8f25dc32532af67e0870767710ede9e032d8bd02aeee6f5c6f8d3eff71dfc1
SHA3 4940bb6fabce2b40f1d1012068a33f9747fb09408fc0ef6fb0ec78331e056c36
VirtualSize 0x3ccb8
VirtualAddress 0xb2000
SizeOfRawData 0x3ce00
PointerToRawData 0xaf600
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.76711

.data

MD5 93ef30c8bb10d797344033273b3f06e7
SHA1 f28359763f1375d059b3123cfab1bc9d08646988
SHA256 793c6057a526b1fbd6fcaea461be82cf3fa368132eadbfe1272c1024761989d8
SHA3 cd9f372ea441efec394be03e52ea295012f155fd70762ee3b5d06cf336c78d8e
VirtualSize 0x12e5c
VirtualAddress 0xef000
SizeOfRawData 0xbc00
PointerToRawData 0xec400
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 3.62969

.pdata

MD5 9c6582dff9e1fafb4ad6265ce44a072f
SHA1 0262c02a81fe38a7f18bd1fa69ae3c6385847300
SHA256 bd222b42278f3ad9c21d03c5df1c28d953f15509345c96c18569e0d2aea91a53
SHA3 ba3aeb0f2628737a5bd29c8eb252e589ef6932aa6ef9f601b7692d7b7b7b7634
VirtualSize 0x7638
VirtualAddress 0x102000
SizeOfRawData 0x7800
PointerToRawData 0xf8000
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 5.85478

.didat

MD5 630132843856c48c98981e3fcb3b46f3
SHA1 8138d61e7b4cfc1a0c5cbd3414581ebc9ef6161b
SHA256 a365060ab3dfe87d6ea37969e83e7bee8b8c298430fe68467894dfc43f3c9538
SHA3 5cee445a168bd15b7bc009496f7ae4febd6691a9143e4ca154521e418e0a51a8
VirtualSize 0x410
VirtualAddress 0x10a000
SizeOfRawData 0x600
PointerToRawData 0xff800
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
IMAGE_SCN_MEM_WRITE
Entropy 1.96587

.rsrc

MD5 b75b538f608e6fffe87ba89e542c594d
SHA1 b5a139f0196c87c0143412dc4ad258bba1c42b95
SHA256 d18966d69501a1b14626980b279aa02b9191a6f5725e4ab3ef38a62db1bd4bf5
SHA3 78cd16bf81308a730fb1ab358719b6a3121a115bbd20f2f6f6f004341cc3208a
VirtualSize 0xaa0
VirtualAddress 0x10b000
SizeOfRawData 0xc00
PointerToRawData 0xffe00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_READ
Entropy 4.33076

.reloc

MD5 2fddcad3ae944418ea3f4918a4037d3c
SHA1 277211f76be1474254bd3acf4a6c47377c8f3b01
SHA256 446c9b307f22ab6fd1aa753738c964589b3c02ba0305ac9676dae804a6284d1f
SHA3 fa74f56eba29ca652576e36c048014c8018be3a0eaa2149aef8cda1732cbbdaf
VirtualSize 0x1c94
VirtualAddress 0x10c000
SizeOfRawData 0x1e00
PointerToRawData 0x100a00
PointerToRelocations 0
PointerToLineNumbers 0
NumberOfLineNumbers 0
NumberOfRelocations 0
Characteristics IMAGE_SCN_CNT_INITIALIZED_DATA
IMAGE_SCN_MEM_DISCARDABLE
IMAGE_SCN_MEM_READ
Entropy 5.38797

Imports

api-ms-win-crt-runtime-l1-1-0.dll _c_exit
_register_thread_local_exe_atexit_callback
_initterm_e
_initterm
api-ms-win-crt-string-l1-1-0.dll strcmp
wcscmp
memset
api-ms-win-crt-private-l1-1-0.dll _o_iswalpha
_o_iswdigit
_o_iswspace
_o_malloc
_o_realloc
memmove
_o_terminate
_o_toupper
_o_towupper
_o_wcstod
_o_wcstok_s
_o_wcstoul
__C_specific_handler
_o_free
_o_floor
_CxxThrowException
_o_exit
wcsrchr
wcsstr
wcschr
__std_terminate
_o_ceil
_o_bsearch
_o__wcsnicmp
__CxxFrameHandler3
_o__wcsicmp
_o__ui64tow_s
_o__wtol
_o__wtoi
_o__strnicmp
_o__stricmp
_o__set_new_mode
_o__set_fmode
_o__set_errno
_o__set_app_type
_o__seh_filter_exe
_o__register_onexit_function
_o__purecall
_o__invalid_parameter_noinfo_noreturn
_o__invalid_parameter_noinfo
_o__initialize_wide_environment
_o__initialize_onexit_table
_o__i64tow_s
_o__get_wide_winmain_command_line
_o__get_errno
_o__exit
_o__errno
_o__crt_atexit
_o__configure_wide_argv
_o__configthreadlocale
_o__cexit
_o__callnewh
_o___stdio_common_vswscanf
_o___stdio_common_vswprintf
_o___stdio_common_vsnprintf_s
_o___stdio_common_vfwprintf_s
_o___std_exception_destroy
_o___std_exception_copy
_o___p__commode
_o___acrt_iob_func
memcmp
memcpy
api-ms-win-core-profile-l1-1-0.dll QueryPerformanceFrequency
QueryPerformanceCounter
api-ms-win-core-processthreads-l1-1-0.dll ProcessIdToSessionId
SetPriorityClass
SetProcessShutdownParameters
GetCurrentThread
TerminateProcess
CreateThread
GetProcessTimes
GetExitCodeThread
GetPriorityClass
GetStartupInfoW
OpenProcessToken
CreateProcessW
SetThreadPriority
GetThreadPriority
GetCurrentThreadId
GetCurrentProcessId
GetCurrentProcess
api-ms-win-core-sysinfo-l1-1-0.dll GetSystemDirectoryW
GetSystemTimeAsFileTime
GetSystemInfo
GlobalMemoryStatusEx
GetComputerNameExW
GetLocalTime
GetSystemTime
GetTickCount
GetVersionExW
GetLogicalProcessorInformationEx
GetTickCount64
api-ms-win-core-interlocked-l1-1-0.dll InitializeSListHead
api-ms-win-core-rtlsupport-l1-1-0.dll RtlLookupFunctionEntry
RtlVirtualUnwind
RtlCaptureContext
api-ms-win-core-debug-l1-1-0.dll DebugBreak
OutputDebugStringW
OutputDebugStringA
IsDebuggerPresent
api-ms-win-core-errorhandling-l1-1-0.dll GetErrorMode
UnhandledExceptionFilter
SetUnhandledExceptionFilter
GetLastError
SetLastError
RaiseException
SetErrorMode
api-ms-win-core-processthreads-l1-1-1.dll IsProcessorFeaturePresent
OpenProcess
api-ms-win-core-libraryloader-l1-2-0.dll GetModuleFileNameA
GetModuleFileNameW
GetModuleHandleW
LoadLibraryExW
GetProcAddress
LoadStringW
FreeLibrary
GetModuleHandleExW
api-ms-win-core-heap-l1-1-0.dll HeapAlloc
HeapReAlloc
HeapSetInformation
HeapFree
GetProcessHeap
HeapSize
api-ms-win-core-synch-l1-1-0.dll CreateSemaphoreExW
InitializeCriticalSectionAndSpinCount
CreateEventExW
WaitForSingleObject
ReleaseSRWLockShared
ReleaseSemaphore
OpenSemaphoreW
InitializeCriticalSectionEx
WaitForSingleObjectEx
InitializeSRWLock
ResetEvent
CreateMutexExW
DeleteCriticalSection
CreateMutexW
AcquireSRWLockShared
ReleaseSRWLockExclusive
AcquireSRWLockExclusive
OpenEventW
SetEvent
EnterCriticalSection
ReleaseMutex
LeaveCriticalSection
CreateEventW
TryEnterCriticalSection
InitializeCriticalSection
api-ms-win-core-threadpool-l1-2-0.dll WaitForThreadpoolTimerCallbacks
CloseThreadpoolTimer
SetThreadpoolTimer
CreateThreadpoolTimer
api-ms-win-core-localization-l1-2-0.dll FormatMessageW
GetThreadPreferredUILanguages
GetLocaleInfoEx
GetThreadUILanguage
GetLocaleInfoW
api-ms-win-eventing-provider-l1-1-0.dll EventSetInformation
EventRegister
EventWriteTransfer
EventUnregister
EventProviderEnabled
api-ms-win-core-handle-l1-1-0.dll CloseHandle
DuplicateHandle
api-ms-win-core-registry-l1-1-0.dll RegQueryValueExW
RegDeleteValueW
RegOpenKeyExW
RegNotifyChangeKeyValue
RegCreateKeyExW
RegQueryInfoKeyW
RegSetValueExW
RegCloseKey
RegGetValueW
RegEnumValueW
api-ms-win-core-string-l1-1-0.dll CompareStringEx
CompareStringOrdinal
api-ms-win-core-heap-l2-1-0.dll LocalAlloc
LocalFree
api-ms-win-core-libraryloader-l1-2-1.dll LoadLibraryW
api-ms-win-core-synch-l1-2-0.dll Sleep
InitOnceExecuteOnce
InitOnceBeginInitialize
InitOnceComplete
OLEAUT32.dll #7
#4
#8
#9
#2
#411
#16
#6
#26
api-ms-win-security-base-l1-1-0.dll FreeSid
GetLengthSid
CheckTokenMembership
CopySid
AdjustTokenPrivileges
IsWellKnownSid
EqualSid
CreateWellKnownSid
SetTokenInformation
GetTokenInformation
AllocateAndInitializeSid
api-ms-win-core-sysinfo-l1-2-0.dll GetSystemFirmwareTable
GetNativeSystemInfo
api-ms-win-core-datetime-l1-1-0.dll GetDateFormatW
GetTimeFormatW
api-ms-win-core-io-l1-1-1.dll CancelSynchronousIo
api-ms-win-core-synch-l1-2-1.dll WaitForMultipleObjects
api-ms-win-power-setting-l1-1-0.dll PowerSettingUnregisterNotification
PowerSettingRegisterNotification
api-ms-win-core-processenvironment-l1-1-0.dll ExpandEnvironmentStringsA
ExpandEnvironmentStringsW
GetCurrentDirectoryW
api-ms-win-core-timezone-l1-1-0.dll SystemTimeToTzSpecificLocalTime
SystemTimeToFileTime
FileTimeToSystemTime
api-ms-win-core-memory-l1-1-1.dll VirtualUnlock
api-ms-win-core-file-l1-2-0.dll GetVolumePathNamesForVolumeNameW
GetTempPathW
api-ms-win-core-path-l1-1-0.dll PathCchAppend
PathCchCanonicalize
PathCchCombine
api-ms-win-core-file-l1-1-0.dll FindFirstChangeNotificationW
GetFileAttributesExW
GetDriveTypeW
CreateFileW
FindNextChangeNotification
FindClose
GetFileType
GetLogicalDriveStringsW
FindVolumeClose
FindNextVolumeW
FindFirstVolumeW
QueryDosDeviceW
FindCloseChangeNotification
CompareFileTime
FindFirstFileW
FindNextFileW
GetLongPathNameW
api-ms-win-core-wow64-l1-1-0.dll IsWow64Process
api-ms-win-core-version-l1-1-0.dll GetFileVersionInfoSizeExW
GetFileVersionInfoExW
VerQueryValueW
api-ms-win-core-string-l2-1-0.dll CharLowerW
CharUpperBuffW
api-ms-win-core-memory-l1-1-0.dll ReadProcessMemory
api-ms-win-core-version-l1-1-1.dll GetFileVersionInfoSizeW
GetFileVersionInfoW
api-ms-win-core-datetime-l1-1-2.dll GetDurationFormatEx
api-ms-win-core-datetime-l1-1-1.dll GetDateFormatEx
api-ms-win-core-psapi-l1-1-0.dll QueryFullProcessImageNameW
api-ms-win-core-sysinfo-l1-2-2.dll GetProcessorSystemCycleTime
api-ms-win-core-io-l1-1-0.dll DeviceIoControl
api-ms-win-core-sysinfo-l1-2-1.dll GetPhysicallyInstalledSystemMemory
api-ms-win-core-localization-l2-1-0.dll GetNumberFormatEx
api-ms-win-core-string-l2-1-1.dll SHLoadIndirectString
api-ms-win-core-winrt-error-l1-1-0.dll RoTransformError
RoOriginateError
api-ms-win-core-kernel32-legacy-l1-1-0.dll GetComputerNameW
MulDiv
api-ms-win-core-threadpool-legacy-l1-1-0.dll QueueUserWorkItem
CreateTimerQueueTimer
DeleteTimerQueueTimer
api-ms-win-core-shlwapi-legacy-l1-1-0.dll PathIsPrefixW
PathGetArgsW
SHExpandEnvironmentStringsW
PathRemoveBlanksW
PathStripPathW
PathFileExistsW
PathRemoveBackslashW
PathIsRelativeW
PathRemoveExtensionW
api-ms-win-core-sidebyside-l1-1-0.dll CreateActCtxW
FindActCtxSectionStringW
ActivateActCtx
QueryActCtxW
DeactivateActCtx
api-ms-win-core-pcw-l1-1-0.dll PcwAddQueryItem
PcwCreateQuery
PcwCollectData
NSI.dll NsiGetParameter
COMCTL32.dll ImageList_CoCreateInstance
ntdll.dll NtPowerInformation
NtSetInformationFile
NtQuerySystemInformationEx
RtlAllocateHeap
LdrQueryProcessModuleInformation
NtQueryInformationProcess
RtlFreeHeap
RtlImageNtHeader
RtlSecondsSince1970ToTime
ZwQueryWnfStateData
RtlNumberOfSetBitsUlongPtr
RtlTimeToElapsedTimeFields
NtSetInformationProcess
EtwCheckCoverage
RtlIpv6AddressToStringExW
RtlIpv4AddressToStringExW
NtQuerySystemInformation
NtQueryInformationFile
NtQueryObject
NtQueryTimerResolution
RtlNtStatusToDosError
NtQueryInformationThread
RtlInitUnicodeString
RtlCompareUnicodeString
RtlNtStatusToDosErrorNoTeb
NtQueryInformationToken
NtOpenFile
RtlCheckPortableOperatingSystem
UxTheme.dll SetWindowTheme
GetThemeInt
GetThemeColor
OpenThemeData
UpdatePanningFeedback
BeginPanningFeedback
EndPanningFeedback
CloseThemeData
SHLWAPI.dll StrToIntExW
#548
#199
#219
StrRChrIW
SHCreateStreamOnFileEx
#278
StrRetToBufW
SHCreateStreamOnFileW
#629
StrStrW
StrStrIW
#618
StrTrimW
#176
#16
AssocQueryStringW
PathIsNetworkPathW
#437
PathRemoveArgsW
SHELL32.dll Shell_NotifyIconW
SHGetPropertyStoreForWindow
SHGetSpecialFolderPathW
#4
#2
SHGetKnownFolderIDList
#727
Shell_GetCachedImageIndexW
SHGetKnownFolderItem
CommandLineToArgvW
SHEvaluateSystemCommandTemplate
ShellExecuteW
ShellExecuteExW
#75
SHParseDisplayName
SHOpenFolderAndSelectItems
#155
#61
SHBindToParent
DuplicateIcon
credui.dll CredUIPromptForCredentialsW
GDI32.dll GetDeviceCaps
DeleteObject
SelectObject
GetTextExtentPointW
CreatePen
MoveToEx
LineTo
CreateDIBSection
Rectangle
USER32.dll GetDC
LoadImageW
GetWindowLongW
DestroyIcon
GetKeyState
GetSystemMetrics
KillTimer
PostQuitMessage
DestroyWindow
IsWindowEnabled
OpenIcon
SetFocus
IsWindow
GetFocus
PostMessageW
IsIconic
SetTimer
SendMessageW
LoadIconW
DefWindowProcW
GetClientRect
UpdateWindow
ShowWindow
SetMenu
GetMenu
ChangeWindowMessageFilterEx
SetForegroundWindow
CreateWindowInBand
RegisterClassExW
CheckMenuRadioItem
GetSubMenu
GetMenuItemID
GetMenuItemCount
CheckMenuItem
EnableMenuItem
IsZoomed
SetWindowPos
GetMonitorInfoW
MonitorFromPoint
GetWindowRect
DispatchMessageW
TranslateMessage
TranslateAcceleratorW
GetMessageW
LoadAcceleratorsW
MessageBoxW
SendMessageTimeoutW
AllowSetForegroundWindow
GetWindowThreadProcessId
FindWindowW
EqualRect
CopyRect
SystemParametersInfoW
SetGestureConfig
GetGestureInfo
CloseGestureInfoHandle
CreateWindowExW
GetCursorPos
GetWindowLongPtrW
SetWindowLongPtrW
RedrawWindow
RemoveMenu
TrackPopupMenuEx
DestroyMenu
CreatePopupMenu
InsertMenuW
GetForegroundWindow
GetParent
ShowWindowAsync
GetLastActivePopup
MessageBeep
SwitchToThisWindow
DialogBoxParamW
SetDlgItemTextW
EndDialog
GetWindowTextW
GetDlgItem
EnableWindow
GetWindowTextLengthW
CreateDialogParamW
TrackPopupMenu
ReleaseDC
GetCurrentInputMessageSource
GetDoubleClickTime
#2521
MapWindowPoints
PtInRect
GetScrollPos
RegisterWindowMessageW
GetMessagePos
OpenClipboard
EmptyClipboard
SetClipboardData
CloseClipboard
InvalidateRect
LoadMenuW
SetWindowTextW
AppendMenuW
GetMenuItemInfoW
GetMenuState
SetMenuDefaultItem
GetSysColor
#2569
#2573
GetWindowCompositionAttribute
#2574
GetWindowBand
InternalGetWindowText
GetPropW
MsgWaitForMultipleObjectsEx
UnregisterDeviceNotification
RegisterDeviceNotificationW
GetGuiResources
PeekMessageW
CopyIcon
UnregisterClassW
GetClassNameW
GetClassLongPtrW
GetWindow
IsWindowVisible
GhostWindowFromHungWindow
IsHungAppWindow
HungWindowFromGhostWindow
OpenDesktopW
GetThreadDesktop
SetThreadDesktop
EnumDesktopWindows
CloseDesktop
EnumDesktopsW
AreDpiAwarenessContextsEqual
GetProcessWindowStation
GetDpiAwarenessContextForProcess
DeleteMenu
DUser.dll ForwardGadgetMessage
SetGadgetStyle
GetGadgetRect
DUI70.dll ?GetEmbeddedFragmentRoots@ElementProvider@DirectUI@@UEAAJPEAPEAUtagSAFEARRAY@@@Z
?get_BoundingRectangle@ElementProvider@DirectUI@@UEAAJPEAUUiaRect@@@Z
?GetRuntimeId@ElementProvider@DirectUI@@UEAAJPEAPEAUtagSAFEARRAY@@@Z
?Navigate@ElementProvider@DirectUI@@UEAAJW4NavigateDirection@@PEAPEAUIRawElementProviderFragment@@@Z
?ShowContextMenu@ElementProvider@DirectUI@@UEAAJXZ
?get_HostRawElementProvider@ElementProvider@DirectUI@@UEAAJPEAPEAUIRawElementProviderSimple@@@Z
?GetPropertyValue@ElementProvider@DirectUI@@UEAAJHPEAUtagVARIANT@@@Z
?get_ProviderOptions@ElementProvider@DirectUI@@UEAAJPEAW4ProviderOptions@@@Z
?TossElement@ElementProvider@DirectUI@@UEAAXXZ
?QueryInterface@ElementProvider@DirectUI@@UEAAJAEBU_GUID@@PEAPEAX@Z
?Create@ElementProvider@DirectUI@@SAJPEAVElement@2@PEAVInvokeHelper@2@PEAPEAV12@@Z
?Create@HWNDElementProvider@DirectUI@@SAJPEAVHWNDElement@2@PEAVInvokeHelper@2@PEAPEAV12@@Z
?Find@ElementProviderManager@DirectUI@@SAPEAVElementProvider@2@PEAVElement@2@@Z
??1ElementProvider@DirectUI@@UEAA@XZ
??0RefcountBase@DirectUI@@QEAA@XZ
??0ElementProvider@DirectUI@@QEAA@XZ
??0ProviderProxy@DirectUI@@IEAA@XZ
??0ElementProxy@DirectUI@@IEAA@XZ
?GetInvokeHelper@InvokeManager@DirectUI@@SAJPEAPEAVInvokeHelper@2@@Z
?Init@ProviderProxy@DirectUI@@MEAAXPEAVElement@2@@Z
?CreatePatternProvider@Schema@DirectUI@@SAJW4Pattern@12@PEAVElementProvider@2@PEAPEAUIUnknown@@@Z
?IsPatternSupported@ElementProxy@DirectUI@@IEAAJW4Pattern@Schema@2@PEA_N@Z
?AddRef@RefcountBase@DirectUI@@QEAAJXZ
?Release@RefcountBase@DirectUI@@QEAAJXZ
?AddRef@ElementProvider@DirectUI@@UEAAKXZ
?TossPatternProvider@ElementProvider@DirectUI@@QEAAXW4Pattern@Schema@2@@Z
??1RefcountBase@DirectUI@@UEAA@XZ
?DoInvokeArgs@ElementProvider@DirectUI@@QEAAJHP6APEAVProviderProxy@2@PEAVElement@2@@ZPEAD@Z
?GetElement@ElementProvider@DirectUI@@UEAAPEDVElement@2@XZ
?Init@ElementProxy@DirectUI@@MEAAXPEAVElement@2@@Z
?DoMethod@ElementProxy@DirectUI@@UEAAJHPEAD@Z
?GetProperty@ElementProxy@DirectUI@@IEAAJPEAUtagVARIANT@@H@Z
?Release@ElementProvider@DirectUI@@UEAAKXZ
?Init@ElementProvider@DirectUI@@MEAAJPEAVElement@2@PEAVInvokeHelper@2@@Z
??1AutoLock@DirectUI@@QEAA@XZ
??0AutoLock@DirectUI@@QEAA@PEAU_RTL_CRITICAL_SECTION@@@Z
?DoInvoke@ElementProvider@DirectUI@@IEAAJHZZ
?PatternFromPatternId@Schema@DirectUI@@SA?AW4Pattern@12@H@Z
?DataGridControlType@Schema@DirectUI@@2HA
?SelectionPattern@Schema@DirectUI@@2HA
?TablePattern@Schema@DirectUI@@2HA
?InvokePattern@Schema@DirectUI@@2HA
?TableItemPattern@Schema@DirectUI@@2HA
?IsControlElementProperty@Schema@DirectUI@@2HA
?IsContentElementProperty@Schema@DirectUI@@2HA
?TreeItemControlType@Schema@DirectUI@@2HA
?ListItemControlType@Schema@DirectUI@@2HA
?ControlTypeProperty@Schema@DirectUI@@2HA
?GridPattern@Schema@DirectUI@@2HA
?SelectionItemPattern@Schema@DirectUI@@2HA
?ExpandCollapsePattern@Schema@DirectUI@@2HA
?GridItemPattern@Schema@DirectUI@@2HA
?UiaRaiseAutomationPropertyChangedEvent@Schema@DirectUI@@2P6AJPEAUIRawElementProviderSimple@@HUtagVARIANT@@1@ZEA
?GetAccessible@Element@DirectUI@@QEAA_NXZ
?WantPropertyEvent@EventManager@DirectUI@@SA_NH@Z
?FWantAnyEvent@EventManager@DirectUI@@SA_NPEAVElement@2@@Z
?OnReceivedDialogFocus@Button@DirectUI@@UEAA_NPEAUIDialogElement@2@@Z
?OnLostDialogFocus@Button@DirectUI@@UEAA_NPEAUIDialogElement@2@@Z
?DefaultAction@Button@DirectUI@@UEAAJXZ
?OnInput@Button@DirectUI@@UEAAXPEAUInputEvent@2@@Z
??1Button@DirectUI@@UEAA@XZ
??0Button@DirectUI@@QEAA@XZ
?GetClassInfoPtr@Button@DirectUI@@SAPEAUIClassInfo@2@XZ
?Register@Button@DirectUI@@SAJXZ
?KeyFocusedProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?OnPropertyChanged@Button@DirectUI@@UEAAXPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?MouseWithinProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?GetBackgroundColor@Element@DirectUI@@QEAAPEBUFill@2@PEAPEAVValue@2@@Z
?Initialize@Button@DirectUI@@QEAAJIPEAVElement@2@PEAK@Z
?SetFontStyle@Element@DirectUI@@QEAAJH@Z
?SetFontWeight@Element@DirectUI@@QEAAJH@Z
?GetFontStyle@Element@DirectUI@@QEAAHXZ
?GetMouseWithin@Element@DirectUI@@QEAA_NXZ
?SetActive@Element@DirectUI@@QEAAJH@Z
?SetID@Element@DirectUI@@QEAAJPEBG@Z
?SetPressed@Button@DirectUI@@QEAAJ_N@Z
?GetBoolFalse@Value@DirectUI@@SAPEAV12@XZ
?SetBorderThickness@Element@DirectUI@@QEAAJHHHH@Z
?GetContentString@Element@DirectUI@@QEAAPEBGPEAPEAVValue@2@@Z
?SetAnimation@Element@DirectUI@@QEAAJH@Z
?HeightProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?LayoutPosProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?RemoveLocalValue@Element@DirectUI@@QEAAJP6APEBUPropertyInfo@2@XZ@Z
?HasPadding@Element@DirectUI@@QEAA_NXZ
?SetBorderColor@Element@DirectUI@@QEAAJK@Z
?HasBorder@Element@DirectUI@@QEAA_NXZ
?GetType@Value@DirectUI@@QEBAHXZ
?CustomProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?GetValue@Element@DirectUI@@QEAAPEAVValue@2@P6APEBUPropertyInfo@2@XZHPEAUUpdateCache@2@@Z
?SetClass@Element@DirectUI@@QEAAJPEBG@Z
?CreateInt@Value@DirectUI@@SAPEAV12@HW4DynamicScaleValue@@@Z
?IsDestroyed@Element@DirectUI@@QEAA_NXZ
?OnNotify@HWNDHost@DirectUI@@UEAA_NI_K_JPEA_J@Z
?OnPropertyChanged@HWNDHost@DirectUI@@UEAAXPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?GetClassInfoPtr@HWNDHost@DirectUI@@SAPEAUIClassInfo@2@XZ
?Register@HWNDHost@DirectUI@@SAJXZ
?OnInput@HWNDHost@DirectUI@@UEAAXPEAUInputEvent@2@@Z
?Release@Element@DirectUI@@QEAAKXZ
?Initialize@HWNDHost@DirectUI@@QEAAJIIPEAVElement@2@PEAK@Z
??1HWNDHost@DirectUI@@UEAA@XZ
??0HWNDHost@DirectUI@@QEAA@XZ
?GetEnabled@Element@DirectUI@@QEAA_NXZ
?SetAccName@Element@DirectUI@@QEAAJPEBG@Z
?GetDPI@Element@DirectUI@@QEAAHXZ
?SetEnabled@Element@DirectUI@@QEAAJ_N@Z
?UpdateSheets@DUIXmlParser@DirectUI@@QEAAJPEAVElement@2@@Z
?SetMinSize@Element@DirectUI@@QEAAJHH@Z
?IsDescendent@Element@DirectUI@@QEAA_NPEAV12@@Z
?Add@Element@DirectUI@@QEAAJPEAV12@@Z
?SetAccDesc@Element@DirectUI@@QEAAJPEBG@Z
?SetTooltip@Element@DirectUI@@QEAAJ_N@Z
?GetLocation@Element@DirectUI@@QEAAPEBUtagPOINT@@PEAPEAVValue@2@@Z
?SetX@Element@DirectUI@@QEAAJH@Z
?GetPadding@Element@DirectUI@@QEAAPEBUtagRECT@@PEAPEAVValue@2@@Z
?GetBorderThickness@Element@DirectUI@@QEAAPEBUtagRECT@@PEAPEAVValue@2@@Z
?SetContentAlign@Element@DirectUI@@QEAAJH@Z
?ContentProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?SetValue@Element@DirectUI@@QEAAJP6APEBUPropertyInfo@2@XZHPEAVValue@2@@Z
?CreateGraphic@Value@DirectUI@@SAPEAV12@PEAUHICON__@@_N11@Z
??1CCListView@DirectUI@@UEAA@XZ
?PostCreate@CCBase@DirectUI@@MEAAXPEAUHWND__@@@Z
?OnReceivedDialogFocus@CCBase@DirectUI@@UEAA_NPEAUIDialogElement@2@@Z
?OnLostDialogFocus@CCBase@DirectUI@@UEAA_NPEAUIDialogElement@2@@Z
?OnCustomDraw@CCBase@DirectUI@@UEAA_NPEAUtagNMCUSTOMDRAWINFO@@PEA_J@Z
?EraseBkgnd@HWNDHost@DirectUI@@MEAA_NPEAUHDC__@@PEA_J@Z
?SetWindowDirection@HWNDHost@DirectUI@@UEAAXPEAUHWND__@@@Z
?OnWindowStyleChanged@HWNDHost@DirectUI@@UEAAX_KPEBUtagSTYLESTRUCT@@@Z
?OnCtrlThemeChanged@HWNDHost@DirectUI@@UEAA_NI_K_JPEA_J@Z
?OnSinkThemeChanged@HWNDHost@DirectUI@@UEAA_NI_K_JPEA_J@Z
?OnSysChar@HWNDHost@DirectUI@@UEAA_NG@Z
?DefaultAction@CCBase@DirectUI@@UEAAJXZ
?GetAccessibleImpl@HWNDHost@DirectUI@@UEAAJPEAPEAUIAccessible@@@Z
?GetKeyFocused@HWNDHost@DirectUI@@UEAA_NXZ
?OnUnHosted@HWNDHost@DirectUI@@MEAAXPEAVElement@2@@Z
?OnHosted@HWNDHost@DirectUI@@MEAAXPEAVElement@2@@Z
?MessageCallback@HWNDHost@DirectUI@@UEAAIPEAUtagGMSG@@@Z
?GetContentSize@CCListView@DirectUI@@UEAA?AUtagSIZE@@HHPEAVSurface@2@@Z
?Paint@HWNDHost@DirectUI@@UEAAXPEAUHDC__@@PEBUtagRECT@@1PEAU4@2@Z
?OnEvent@HWNDHost@DirectUI@@UEAAXPEAUEvent@2@@Z
?OnDestroy@HWNDHost@DirectUI@@UEAAXXZ
?OnPropertyChanged@CCBase@DirectUI@@UEAAXPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?GetClassInfoPtr@CCListView@DirectUI@@SAPEAUIClassInfo@2@XZ
?Register@CCListView@DirectUI@@SAJXZ
?OnInput@CCBase@DirectUI@@UEAAXPEAUInputEvent@2@@Z
?SetKeyFocus@HWNDHost@DirectUI@@UEAAXXZ
?OnNotify@CCBase@DirectUI@@UEAA_NI_K_JPEA_J@Z
?OnMessage@HWNDHost@DirectUI@@UEAA_NI_K_JPEA_J@Z
?GetRootRelativeBounds@Element@DirectUI@@QEAAJPEAUtagRECT@@@Z
?OnAdjustWindowSize@HWNDHost@DirectUI@@UEAAHHHI@Z
?GetHWND@HWNDHost@DirectUI@@UEAAPEAUHWND__@@XZ
?SetWinStyle@CCBase@DirectUI@@QEAAJH@Z
?Initialize@CCListView@DirectUI@@QEAAJIPEAVElement@2@PEAK@Z
?CreateHWND@CCBase@DirectUI@@UEAAPEAUHWND__@@PEAU3@@Z
??0CCListView@DirectUI@@QEAA@XZ
??0ScrollViewer@DirectUI@@QEAA@XZ
??1ScrollViewer@DirectUI@@UEAA@XZ
?OnPropertyChanging@BaseScrollViewer@DirectUI@@UEAA_NPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?OnPropertyChanged@ScrollViewer@DirectUI@@UEAAXPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?OnInput@BaseScrollViewer@DirectUI@@UEAAXPEAUInputEvent@2@@Z
?OnEvent@BaseScrollViewer@DirectUI@@UEAAXPEAUEvent@2@@Z
?Add@BaseScrollViewer@DirectUI@@UEAAJPEAPEAVElement@2@I@Z
?CreateScrollBars@ScrollViewer@DirectUI@@MEAAJXZ
?AddChildren@ScrollViewer@DirectUI@@MEAAJXZ
?OnListenerAttach@BaseScrollViewer@DirectUI@@UEAAXPEAVElement@2@@Z
?OnListenerDetach@BaseScrollViewer@DirectUI@@UEAAXPEAVElement@2@@Z
?OnListenedPropertyChanging@BaseScrollViewer@DirectUI@@UEAA_NPEAVElement@2@PEBUPropertyInfo@2@HPEAVValue@2@2@Z
?OnListenedPropertyChanged@ScrollViewer@DirectUI@@UEAAXPEAVElement@2@PEBUPropertyInfo@2@HPEAVValue@2@2@Z
?OnListenedInput@BaseScrollViewer@DirectUI@@UEAAXPEAVElement@2@PEAUInputEvent@2@@Z
?OnListenedEvent@BaseScrollViewer@DirectUI@@UEAAXPEAVElement@2@PEAUEvent@2@@Z
?GetClassInfoPtr@Expando@DirectUI@@SAPEAUIClassInfo@2@XZ
?GetClassInfoPtr@ScrollViewer@DirectUI@@SAPEAUIClassInfo@2@XZ
?Initialize@BaseScrollViewer@DirectUI@@QEAAJPEAVElement@2@PEAK@Z
??0Element@DirectUI@@QEAA@XZ
?_PostEvent@Element@DirectUI@@AEAAXPEAUEvent@2@H@Z
?Register@Element@DirectUI@@SAJXZ
?Register@ScrollViewer@DirectUI@@SAJXZ
?GetHScroll@ScrollViewer@DirectUI@@MEAAPEAVBaseScrollBar@2@XZ
?SetFocus@ElementProvider@DirectUI@@UEAAJXZ
?SetXScrollable@BaseScrollViewer@DirectUI@@QEAAJ_N@Z
?SetPadding@Element@DirectUI@@QEAAJHHHH@Z
?SetXOffset@BaseScrollViewer@DirectUI@@QEAAJH@Z
?XOffsetProp@BaseScrollViewer@DirectUI@@SAPEBUPropertyInfo@2@XZ
?ShiftChild@Element@DirectUI@@QEAAJII@Z
?SetForegroundColor@Element@DirectUI@@QEAAJK@Z
?SetBackgroundColor@Element@DirectUI@@QEAAJK@Z
?GetSelected@Element@DirectUI@@QEAA_NXZ
?GetVisible@Element@DirectUI@@QEAA_NXZ
?Initialize@Element@DirectUI@@QEAAJIPEAV12@PEAK@Z
?SetHeight@Element@DirectUI@@QEAAJH@Z
?Insert@Element@DirectUI@@QEAAJPEAV12@I@Z
?GetSize@Value@DirectUI@@QEAAPEBUtagSIZE@@XZ
?ExtentProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?OnInput@Element@DirectUI@@UEAAXPEAUInputEvent@2@@Z
?GetDesiredSize@Element@DirectUI@@QEAAPEBUtagSIZE@@XZ
?GetInt@Value@DirectUI@@QEAAHXZ
?GetWidth@Element@DirectUI@@QEAAHXZ
??1DCSurface@DirectUI@@UEAA@XZ
??0DCSurface@DirectUI@@QEAA@PEAUHDC__@@@Z
?SetValue@Element@DirectUI@@QEAAJPEBUPropertyInfo@2@HPEAVValue@2@@Z
?SetAccValue@Element@DirectUI@@QEAAJPEBG@Z
?SetWidth@Element@DirectUI@@QEAAJH@Z
?RemoveListener@Element@DirectUI@@QEAAXPEAUIElementListener@2@@Z
?SetContentString@Element@DirectUI@@QEAAJPEBG@Z
?GetDisplayNode@Element@DirectUI@@QEAAPEAUHGADGET__@@XZ
?Init@NavReference@DirectUI@@QEAAXPEAVElement@2@PEAUtagRECT@@@Z
?GetKeyWithin@Element@DirectUI@@QEAA_NXZ
?OnEvent@Element@DirectUI@@UEAAXPEAUEvent@2@@Z
?Remove@Element@DirectUI@@QEAAJPEAV12@@Z
?AddListener@Element@DirectUI@@QEAAJPEAUIElementListener@2@@Z
??1Element@DirectUI@@UEAA@XZ
?OnPropertyChanged@Element@DirectUI@@UEAAXPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?OnGroupChanged@Element@DirectUI@@UEAAXH_N@Z
?OnDestroy@Element@DirectUI@@UEAAXXZ
?UpdateTooltip@Element@DirectUI@@MEAAXPEAV12@@Z
?ActivateTooltip@Element@DirectUI@@MEAAXPEAV12@K@Z
?RemoveTooltip@Element@DirectUI@@MEAAXPEAV12@@Z
?GetAccessibleImpl@Element@DirectUI@@UEAAJPEAPEAUIAccessible@@@Z
?ExpandCollapse_ExpandCollapseState_Property@Schema@DirectUI@@2HA
?SetSelected@Element@DirectUI@@QEAAJ_N@Z
?CreateBool@Value@DirectUI@@SAPEAV12@_N@Z
?SetExpanded@Expandable@DirectUI@@QEAAJ_N@Z
?GetExpanded@Expandable@DirectUI@@QEAA_NXZ
?SortChildren@Element@DirectUI@@QEAAJP6AHPEBX0@Z@Z
?GetBool@Value@DirectUI@@QEAA_NXZ
?GetValue@Element@DirectUI@@QEAAPEAVValue@2@PEBUPropertyInfo@2@HPEAUUpdateCache@2@@Z
?GetChildren@Element@DirectUI@@QEAAPEAV?$DynamicArray@PEAVElement@DirectUI@@$0A@@2@PEAPEAVValue@2@@Z
?GetClassInfoPtr@Element@DirectUI@@SAPEAUIClassInfo@2@XZ
?GetParent@Element@DirectUI@@QEAAPEAV12@XZ
?GetClass@Element@DirectUI@@QEAAPEBGPEAPEAVValue@2@@Z
?GetIndex@Element@DirectUI@@QEAAHXZ
?AssertPIZeroRef@ClassInfoBase@DirectUI@@UEBAXXZ
?GetChildren@ClassInfoBase@DirectUI@@UEBAHXZ
?RemoveChild@ClassInfoBase@DirectUI@@UEAAXXZ
?AddChild@ClassInfoBase@DirectUI@@UEAAXXZ
?IsGlobal@ClassInfoBase@DirectUI@@UEBA_NXZ
?GetModule@ClassInfoBase@DirectUI@@UEBAPEAUHINSTANCE__@@XZ
?IsSubclassOf@ClassInfoBase@DirectUI@@UEBA_NPEAUIClassInfo@2@@Z
?IsValidProperty@ClassInfoBase@DirectUI@@UEBA_NPEBUPropertyInfo@2@@Z
?GetName@ClassInfoBase@DirectUI@@UEBAPEBGXZ
?GetGlobalIndex@ClassInfoBase@DirectUI@@UEBAIXZ
?GetPICount@ClassInfoBase@DirectUI@@UEBAIXZ
?GetByClassIndex@ClassInfoBase@DirectUI@@UEAAPEBUPropertyInfo@2@I@Z
?EnumPropertyInfo@ClassInfoBase@DirectUI@@UEAAPEBUPropertyInfo@2@I@Z
?Release@ClassInfoBase@DirectUI@@UEAAHXZ
?AddRef@ClassInfoBase@DirectUI@@UEAAXXZ
?_OnUIStateChanged@HWNDElement@DirectUI@@MEAAXGG@Z
?GetWindowClassNameAndStyle@HWNDElement@DirectUI@@UEAAXPEAPEBGPEAI@Z
?IsMSAAEnabled@HWNDElement@DirectUI@@UEAA_NXZ
?CanSetFocus@HWNDElement@DirectUI@@UEAA_NXZ
?OnCompositionChanged@HWNDElement@DirectUI@@UEAAXXZ
?OnWmSettingChanged@HWNDElement@DirectUI@@UEAAX_K_J@Z
?OnWmThemeChanged@HWNDElement@DirectUI@@UEAAX_K_J@Z
?OnGetDlgCode@HWNDElement@DirectUI@@UEAAXPEAUtagMSG@@PEA_J@Z
?OnNoChildWithShortcutFound@HWNDElement@DirectUI@@UEAAXPEAUKeyboardEvent@2@@Z
?OnImmersiveColorSchemeChanged@HWNDElement@DirectUI@@UEAAXXZ
?GetUiaFocusDelegate@Element@DirectUI@@UEAAPEAV12@XZ
?HandleUiaEventListener@Element@DirectUI@@UEAAXPEAUEvent@2@@Z
?HandleUiaPropertyChangingListener@Element@DirectUI@@UEAAXPEBUPropertyInfo@2@@Z
?HandleUiaPropertyListener@Element@DirectUI@@UEAAXPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?HandleUiaDestroyListener@Element@DirectUI@@UEAAXXZ
?GetElementProviderImpl@Element@DirectUI@@UEAAJPEAVInvokeHelper@2@PEAPEAVElementProvider@2@@Z
?GetUIAElementProvider@Element@DirectUI@@UEAAJAEBU_GUID@@PEAPEAX@Z
?DefaultAction@Element@DirectUI@@UEAAJXZ
?GetAccessibleImpl@HWNDElement@DirectUI@@UEAAJPEAPEAUIAccessible@@@Z
?GetKeyFocused@Element@DirectUI@@UEAA_NXZ
?RemoveTooltip@HWNDElement@DirectUI@@UEAAXPEAVElement@2@@Z
?ActivateTooltip@HWNDElement@DirectUI@@UEAAXPEAVElement@2@K@Z
?UpdateTooltip@HWNDElement@DirectUI@@UEAAXPEAVElement@2@@Z
?OnUnHosted@Element@DirectUI@@MEAAXPEAV12@@Z
?OnHosted@Element@DirectUI@@MEAAXPEAV12@@Z
?_SelfLayoutUpdateDesiredSize@Element@DirectUI@@MEAA?AUtagSIZE@@HHPEAVSurface@2@@Z
?_SelfLayoutDoLayout@Element@DirectUI@@MEAAXHH@Z
?GetImmersiveFocusRectOffsets@Element@DirectUI@@UEAAXPEAUtagRECT@@@Z
?QueryInterface@Element@DirectUI@@UEAAJAEBU_GUID@@PEAPEAX@Z
?MessageCallback@Element@DirectUI@@UEAAIPEAUtagGMSG@@@Z
?RemoveBehavior@Element@DirectUI@@UEAAJPEAUIDuiBehavior@@@Z
?AddBehavior@Element@DirectUI@@UEAAJPEAUIDuiBehavior@@@Z
?SetKeyFocus@Element@DirectUI@@UEAAXXZ
?EnsureVisible@Element@DirectUI@@UEAA_NHHHH@Z
?GetAdjacent@Element@DirectUI@@UEAAPEAV12@PEAV12@HPEBUNavReference@2@K@Z
?Remove@Element@DirectUI@@UEAAJPEAPEAV12@I@Z
?Insert@Element@DirectUI@@UEAAJPEAPEAV12@II@Z
?Add@Element@DirectUI@@UEAAJPEAPEAV12@I@Z
?GetContentSize@Element@DirectUI@@UEAA?AUtagSIZE@@HHPEAVSurface@2@@Z
?Paint@Element@DirectUI@@UEAAXPEAUHDC__@@PEBUtagRECT@@1PEAU4@2@Z
?OnMouseFocusMoved@Element@DirectUI@@UEAAXPEAV12@0@Z
?OnKeyFocusMoved@Element@DirectUI@@UEAAXPEAV12@0@Z
?OnGroupChanged@HWNDElement@DirectUI@@UEAAXH_N@Z
?OnPropertyChanged@Element@DirectUI@@UEAAXPEAUPropertyInfo@2@HPEAVValue@2@1@Z
?OnPropertyChanged@HWNDElement@DirectUI@@UEAAXPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?OnPropertyChanging@Element@DirectUI@@UEAA_NPEAUPropertyInfo@2@HPEAVValue@2@1@Z
?OnPropertyChanging@Element@DirectUI@@UEAA_NPEBUPropertyInfo@2@HPEAVValue@2@1@Z
?GetContentStringAsDisplayed@Element@DirectUI@@UEAAPEBGPEAPEAVValue@2@@Z
?IsContentProtected@Element@DirectUI@@UEAA_NXZ
?IsRTL@Element@DirectUI@@QEAA_NXZ
?IsRTLReading@Element@DirectUI@@UEAA_NXZ
??1ClassInfoBase@DirectUI@@UEAA@XZ
??0ClassInfoBase@DirectUI@@QEAA@XZ
?GetClassInfoPtr@HWNDElement@DirectUI@@SAPEAUIClassInfo@2@XZ
?Initialize@ClassInfoBase@DirectUI@@QEAAJPEAUHINSTANCE__@@PEBG_NPEBQEBUPropertyInfo@2@I@Z
?Register@ClassInfoBase@DirectUI@@QEAAJXZ
?ClassExist@ClassInfoBase@DirectUI@@SA_NPEAPEAUIClassInfo@2@PEBQEBUPropertyInfo@2@IPEAU32@PEAUHINSTANCE__@@PEBG_N@Z
??1CritSecLock@DirectUI@@QEAA@XZ
?GetFactoryLock@Element@DirectUI@@SAPEAU_RTL_CRITICAL_SECTION@@XZ
??0CritSecLock@DirectUI@@QEAA@PEAU_RTL_CRITICAL_SECTION@@@Z
?Register@HWNDElement@DirectUI@@SAJXZ
?OnThemeChanged@HWNDElement@DirectUI@@UEAAXPEAUThemeChangedEvent@2@@Z
?GetLayoutPos@Element@DirectUI@@QEAAHXZ
EnableAnimations
?FireEvent@Element@DirectUI@@QEAAXPEAUEvent@2@_N1@Z
?StartNavigate@Browser@DirectUI@@SA?AVUID@@XZ
DisableAnimations
?Destroy@DUIXmlParser@DirectUI@@QEAAXXZ
?SetXMLFromResource@DUIXmlParser@DirectUI@@QEAAJIPEAUHINSTANCE__@@0@Z
?Create@DUIXmlParser@DirectUI@@SAJPEAPEAV12@P6APEAVValue@2@PEBGPEAX@Z2P6AX11H2@Z2@Z
?CreateElement@DUIXmlParser@DirectUI@@QEAAJPEBGPEAVElement@2@1PEAKPEAPEAV32@@Z
?ShowWindow@NativeHWNDHost@DirectUI@@QEAAXH@Z
?Host@NativeHWNDHost@DirectUI@@QEAAXPEAVElement@2@@Z
?SetVisible@Element@DirectUI@@QEAAJ_N@Z
?SetAccRole@Element@DirectUI@@QEAAJH@Z
?SetAccessible@Element@DirectUI@@QEAAJ_N@Z
?Initialize@HWNDElement@DirectUI@@QEAAJPEAUHWND__@@_NIPEAVElement@2@PEAK@Z
?GetHWND@NativeHWNDHost@DirectUI@@QEAAPEAUHWND__@@XZ
?Create@NativeHWNDHost@DirectUI@@SAJPEBGPEAUHWND__@@PEAUHICON__@@HHHHHHIPEAPEAV12@@Z
?Destroy@Element@DirectUI@@QEAAJ_N@Z
?OnDestroy@HWNDElement@DirectUI@@UEAAXXZ
?OnEvent@HWNDElement@DirectUI@@UEAAXPEAUEvent@2@@Z
?KeyboardNavigate@Element@DirectUI@@SA?AVUID@@XZ
?GetID@Element@DirectUI@@QEAAGXZ
?Click@Button@DirectUI@@SA?AVUID@@XZ
?GetExtent@Element@DirectUI@@QEAAPEBUtagSIZE@@PEAPEAVValue@2@@Z
?Release@Value@DirectUI@@QEAAXXZ
?SetLayoutPos@Element@DirectUI@@QEAAJH@Z
?OnInput@HWNDElement@DirectUI@@UEAAXPEAUInputEvent@2@@Z
?EndDefer@Element@DirectUI@@QEAAXK@Z
?StartDefer@Element@DirectUI@@QEAAXPEAK@Z
?GetHWND@HWNDElement@DirectUI@@UEAAPEAUHWND__@@XZ
StrToID
?GetRoot@Element@DirectUI@@QEAAPEAV12@XZ
?FindDescendent@Element@DirectUI@@QEAAPEAV12@G@Z
?WndProc@HWNDElement@DirectUI@@UEAA_JPEAUHWND__@@I_K_J@Z
?Destroy@NativeHWNDHost@DirectUI@@QEAAXXZ
??1HWNDElement@DirectUI@@UEAA@XZ
??0HWNDElement@DirectUI@@QEAA@XZ
?GetKeyFocusedElement@HWNDElement@DirectUI@@SAPEAVElement@2@XZ
UnInitProcessPriv
UnInitThread
InitThread
InitProcessPriv
?AdviseEventRemoved@ElementProvider@DirectUI@@UEAAJHPEAUtagSAFEARRAY@@@Z
??0IProvider@DirectUI@@QEAA@XZ
?HasChildren@Element@DirectUI@@QEAA_NXZ
?Create@GridLayout@DirectUI@@SAJHHPEAPEAVLayout@2@@Z
?SetLayout@Element@DirectUI@@QEAAJPEAVLayout@2@@Z
?Destroy@Layout@DirectUI@@QEAAXXZ
?KeyWithinProp@Element@DirectUI@@SAPEBUPropertyInfo@2@XZ
?GetVScroll@ScrollViewer@DirectUI@@MEAAPEAVBaseScrollBar@2@XZ
?AdviseEventAdded@ElementProvider@DirectUI@@UEAAJHPEAUtagSAFEARRAY@@@Z
?get_FragmentRoot@ElementProvider@DirectUI@@UEAAJPEAPEAUIRawElementProviderFragmentRoot@@@Z
api-ms-win-core-appcompat-l1-1-1.dll BaseReadAppCompatDataForProcess
BaseFreeAppCompatDataForProcess
pdh.dll PdhCloseQuery
PdhGetRawCounterArrayW
PdhGetFormattedCounterArrayW
PdhAddCounterW
PdhCollectQueryData
PdhOpenQueryW
dxgi.dll CreateDXGIFactory1
DXGIDeclareAdapterRemovalSupport
SETUPAPI.dll SetupDiGetDevicePropertyW
SetupDiEnumDeviceInfo
SetupDiGetClassDevsW
d3d11.dll D3D11CreateDevice
d3d12.dll #101
KERNEL32.dll GetActiveProcessorGroupCount
RegisterApplicationRestart
GetNumberFormatW
GetPackageFamilyName
GetPackageFullName
SetProcessWorkingSetSize
ParseApplicationUserModelId
PackageFamilyNameFromFullName
msvcp_win.dll ?_Xlength_error@std@@YAXPEBD@Z
api-ms-win-eventing-classicprovider-l1-1-0.dll TraceMessage
api-ms-win-core-delayload-l1-1-1.dll ResolveDelayLoadedAPI
api-ms-win-core-delayload-l1-1-0.dll DelayLoadFailureHook
api-ms-win-core-apiquery-l1-1-0.dll ApiSetQueryApiSetPresence
api-ms-win-crt-math-l1-1-0.dll floorf
sqrtf
api-ms-win-core-com-l1-1-0.dll (delay-loaded) CoTaskMemRealloc
CoGetApartmentType
CoWaitForMultipleHandles
CoCreateFreeThreadedMarshaler
CoCancelCall
CoInitializeEx
CoEnableCallCancellation
CoUninitialize
CoCreateInstance
StringFromCLSID
CoDisableCallCancellation
CoTaskMemFree
CreateStreamOnHGlobal
CoTaskMemAlloc
GetHGlobalFromStream
PropVariantClear

Delayed Imports

Attributes 0x1
Name api-ms-win-core-com-l1-1-0.dll
ModuleHandle 0xfab58
DelayImportAddressTable 0x10a178
DelayImportNameTable 0xe3910
BoundDelayImportTable 0xe4478
UnloadDelayImportTable 0
TimeStamp 1970-Jan-01 00:00:00

1

Type MUI
Language English - United States
Codepage UNKNOWN
Size 0x118
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 2.89143
MD5 4b218591f37b44b6f3da0a2f177307a9
SHA1 3457345751ac168b7069494e37f1e0fbee456494
SHA256 85abce98b838a9e70d7f1a8553e2704ceda38b0d8192452af489321a6567a8f5
SHA3 a7d59d77dcf6ffef92695d6181dd2371bfab3acb89d166f07d20a66f403fe197

1 (#2)

Type RT_VERSION
Language English - United States
Codepage UNKNOWN
Size 0x38c
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 3.45661
MD5 63dec3e6f68507bcbaf04b40db81a1c5
SHA1 aaf5992594fddeaea481ecb4d9ad9a95f1484e7f
SHA256 0326bd2185761ae2bd1056e03167c3ffbf5cb22053d25f942fbdb76193b84d3f
SHA3 cbb5ed33c8801ee1bcb6641a241842a612cb01fbbceb4fe1903f9b112e40b439

1 (#3)

Type RT_MANIFEST
Language English - United States
Codepage UNKNOWN
Size 0x504
TimeDateStamp 1980-Jan-01 00:00:00
Entropy 4.95487
MD5 21f515328b7832e516d313554c691e45
SHA1 7a1422e2d9ae5cdae61914bd4f715fc07871403f
SHA256 2b266e3dc2ed6198ab4a83d439e32f94a2d40613b6818aa87df6b180d8a248e5
SHA3 80c27d3344d5320c1eb2d2f089717632ec3a114131e6fde5eee1fe42b626dcc9

Version Info

Signature 0xfeef04bd
StructVersion 0x10000
FileVersion 10.0.18362.1
ProductVersion 10.0.18362.1
FileFlags (EMPTY)
FileOs VOS_DOS_WINDOWS32
VOS_NT
VOS_NT_WINDOWS32
VOS_WINCE
VOS__WINDOWS32
FileType VFT_APP
Language English - United States
CompanyName Microsoft Corporation
FileDescription Task Manager
FileVersion (#2) 10.0.18362.1 (WinBuild.160101.0800)
InternalName Task Manager
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename Taskmgr.exe
ProductName Microsoft® Windows® Operating System
ProductVersion (#2) 10.0.18362.1
Resource LangID English - United States

IMAGE_DEBUG_TYPE_CODEVIEW

Characteristics 0
TimeDateStamp 1963-Nov-29 19:10:33
Version 0.0
SizeofData 36
AddressOfRawData 0xdb590
PointerToRawData 0xd8b90
Referenced File Taskmgr.pdb

IMAGE_DEBUG_TYPE_POGO

Characteristics 0
TimeDateStamp 1963-Nov-29 19:10:33
Version 0.0
SizeofData 1568
AddressOfRawData 0xdb5b4
PointerToRawData 0xd8bb4

UNKNOWN

Characteristics 0
TimeDateStamp 1963-Nov-29 19:10:33
Version 0.0
SizeofData 36
AddressOfRawData 0xdbbd4
PointerToRawData 0xd91d4

TLS Callbacks

StartAddressOfRawData 0x1400dbc18
EndAddressOfRawData 0x1400dbc20
AddressOfIndex 0x1400fb240
AddressOfCallbacks 0x1400ba968
SizeOfZeroFill 0
Characteristics IMAGE_SCN_ALIGN_4BYTES
Callbacks (EMPTY)

Load Configuration

Size 0x108
TimeDateStamp 1970-Jan-01 00:00:00
Version 0.0
GlobalFlagsClear (EMPTY)
GlobalFlagsSet (EMPTY)
CriticalSectionDefaultTimeout 0
DeCommitFreeBlockThreshold 0
DeCommitTotalFreeThreshold 0
LockPrefixTable 0
MaximumAllocationSize 0
VirtualMemoryThreshold 0
ProcessAffinityMask 0
ProcessHeapFlags (EMPTY)
CSDVersion 0
Reserved1 0
EditList 0
SecurityCookie 0x1400f7d50
GuardCFCheckFunctionPointer 5369473104
GuardCFDispatchFunctionPointer 0
GuardCFFunctionTable 0
GuardCFFunctionCount 0
GuardFlags (EMPTY)
CodeIntegrity.Flags 0
CodeIntegrity.Catalog 0
CodeIntegrity.CatalogOffset 0
CodeIntegrity.Reserved 0
GuardAddressTakenIatEntryTable 0
GuardAddressTakenIatEntryCount 0
GuardLongJumpTargetTable 0
GuardLongJumpTargetCount 0

RICH Header

XOR Key 0xaf0da742
Unmarked objects 0
Imports (VS2008 SP1 build 30729) 125
C objects (26715) 20
ASM objects (26715) 3
C++ objects (26715) 38
Total imports 2017
Imports (26715) 34
269 (26715) 87
253 (26715) 1
Resource objects (26715) 1
Linker (26715) 1

Errors

[*] Warning: Section .imrsiv has a size of 0!