MicrosoftAccountExtension.dll

Description: Microsoft Account Extension DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 7821e29be0344bc22e6c592f3078cdcf

File Size: 431.5 KB

Uploaded At: Dec. 1, 2025, 7:33 a.m.

Views: 5

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x5ca0)
  • DllGetActivationFactory (Ordinal: 2, Address: 0x5990)
  • DllGetClassObject (Ordinal: 3, Address: 0x5b70)

Imported DLLs & Functions

AADAUTHHELPER.DLL
  • CreateTokenAuthBufferEx (Address: 0x180050e40)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180050ff0)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateFreeThreadedMarshaler (Address: 0x180051048)
  • CoCreateInstance (Address: 0x180051010)
  • CoGetCallContext (Address: 0x180051020)
  • CoGetCallerTID (Address: 0x180051070)
  • CoGetInterfaceAndReleaseStream (Address: 0x180051080)
  • CoGetMalloc (Address: 0x180051008)
  • CoImpersonateClient (Address: 0x180051028)
  • CoMarshalInterface (Address: 0x180051078)
  • CoReleaseMarshalData (Address: 0x180051060)
  • CoRevertToSelf (Address: 0x180051038)
  • CoTaskMemAlloc (Address: 0x180051030)
  • CoTaskMemFree (Address: 0x180051018)
  • CoWaitForMultipleHandles (Address: 0x180051058)
  • CreateStreamOnHGlobal (Address: 0x180051068)
  • PropVariantClear (Address: 0x180051040)
  • StringFromCLSID (Address: 0x180051000)
  • StringFromGUID2 (Address: 0x180051050)
api-ms-win-core-com-l1-1-1.dll
  • RoGetAgileReference (Address: 0x180051090)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
  • CStdStubBuffer2_Connect (Address: 0x1800510a0)
  • CStdStubBuffer2_CountRefs (Address: 0x1800510c8)
  • CStdStubBuffer2_Disconnect (Address: 0x180051110)
  • CStdStubBuffer2_QueryInterface (Address: 0x180051130)
  • NdrProxyForwardingFunction3 (Address: 0x1800510e0)
  • NdrProxyForwardingFunction4 (Address: 0x180051140)
  • NdrProxyForwardingFunction5 (Address: 0x180051148)
  • ObjectStublessClient10 (Address: 0x180051170)
  • ObjectStublessClient11 (Address: 0x1800510c0)
  • ObjectStublessClient12 (Address: 0x1800510b0)
  • ObjectStublessClient13 (Address: 0x180051128)
  • ObjectStublessClient14 (Address: 0x1800510b8)
  • ObjectStublessClient15 (Address: 0x180051100)
  • ObjectStublessClient16 (Address: 0x180051160)
  • ObjectStublessClient17 (Address: 0x180051168)
  • ObjectStublessClient18 (Address: 0x1800510e8)
  • ObjectStublessClient19 (Address: 0x180051138)
  • ObjectStublessClient20 (Address: 0x1800510f8)
  • ObjectStublessClient21 (Address: 0x1800510f0)
  • ObjectStublessClient22 (Address: 0x1800510d8)
  • ObjectStublessClient23 (Address: 0x180051108)
  • ObjectStublessClient24 (Address: 0x1800510a8)
  • ObjectStublessClient25 (Address: 0x1800510d0)
  • ObjectStublessClient6 (Address: 0x180051150)
  • ObjectStublessClient7 (Address: 0x180051120)
  • ObjectStublessClient8 (Address: 0x180051158)
  • ObjectStublessClient9 (Address: 0x180051118)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180051190)
  • IsDebuggerPresent (Address: 0x180051188)
  • OutputDebugStringW (Address: 0x180051180)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800511a0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800511b0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800511e0)
  • RaiseException (Address: 0x1800511c0)
  • SetLastError (Address: 0x1800511d8)
  • SetUnhandledExceptionFilter (Address: 0x1800511c8)
  • UnhandledExceptionFilter (Address: 0x1800511d0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x1800511f8)
  • DuplicateHandle (Address: 0x1800511f0)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180051210)
  • HeapAlloc (Address: 0x180051230)
  • HeapDestroy (Address: 0x180051218)
  • HeapFree (Address: 0x180051208)
  • HeapReAlloc (Address: 0x180051220)
  • HeapSize (Address: 0x180051228)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180051240)
  • LocalFree (Address: 0x180051248)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180051258)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • GetComputerNameW (Address: 0x180051268)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180051278)
  • GetModuleFileNameA (Address: 0x180051298)
  • GetModuleFileNameW (Address: 0x180051290)
  • GetModuleHandleExW (Address: 0x180051280)
  • GetModuleHandleW (Address: 0x1800512a0)
  • GetProcAddress (Address: 0x180051288)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800512b8)
  • GetThreadPreferredUILanguages (Address: 0x1800512b0)
  • GetUserDefaultLocaleName (Address: 0x1800512c0)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x1800512d8)
  • GetCurrentProcessId (Address: 0x180051318)
  • GetCurrentThread (Address: 0x180051300)
  • GetCurrentThreadId (Address: 0x1800512d0)
  • GetProcessId (Address: 0x1800512e8)
  • GetProcessIdOfThread (Address: 0x1800512e0)
  • OpenProcessToken (Address: 0x180051310)
  • OpenThread (Address: 0x180051308)
  • OpenThreadToken (Address: 0x1800512f0)
  • TerminateProcess (Address: 0x1800512f8)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180051328)
  • OpenProcess (Address: 0x180051330)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180051340)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180051378)
  • RegCreateKeyExW (Address: 0x180051350)
  • RegDeleteKeyExW (Address: 0x1800513a0)
  • RegDeleteTreeW (Address: 0x180051398)
  • RegDeleteValueW (Address: 0x180051368)
  • RegEnumKeyExW (Address: 0x180051388)
  • RegEnumValueW (Address: 0x180051380)
  • RegGetValueW (Address: 0x1800513a8)
  • RegOpenCurrentUser (Address: 0x180051358)
  • RegOpenKeyExW (Address: 0x180051390)
  • RegQueryInfoKeyW (Address: 0x180051360)
  • RegQueryValueExW (Address: 0x180051370)
  • RegSetValueExW (Address: 0x1800513b0)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800513c8)
  • RtlLookupFunctionEntry (Address: 0x1800513c0)
  • RtlVirtualUnwind (Address: 0x1800513d0)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x1800513e8)
  • MultiByteToWideChar (Address: 0x1800513e0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180051420)
  • AcquireSRWLockShared (Address: 0x180051418)
  • CreateEventExW (Address: 0x1800514a8)
  • CreateEventW (Address: 0x1800514a0)
  • CreateMutexExW (Address: 0x180051488)
  • CreateSemaphoreExW (Address: 0x180051440)
  • DeleteCriticalSection (Address: 0x180051458)
  • EnterCriticalSection (Address: 0x180051450)
  • InitializeCriticalSection (Address: 0x180051468)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180051478)
  • InitializeCriticalSectionEx (Address: 0x180051460)
  • LeaveCriticalSection (Address: 0x180051448)
  • OpenEventW (Address: 0x180051408)
  • OpenSemaphoreW (Address: 0x180051410)
  • ReleaseMutex (Address: 0x180051480)
  • ReleaseSemaphore (Address: 0x180051490)
  • ReleaseSRWLockExclusive (Address: 0x1800513f8)
  • ReleaseSRWLockShared (Address: 0x180051438)
  • ResetEvent (Address: 0x180051498)
  • SetEvent (Address: 0x180051470)
  • WaitForMultipleObjectsEx (Address: 0x180051400)
  • WaitForSingleObject (Address: 0x180051430)
  • WaitForSingleObjectEx (Address: 0x180051428)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceBeginInitialize (Address: 0x1800514c8)
  • InitOnceComplete (Address: 0x1800514c0)
  • InitOnceExecuteOnce (Address: 0x1800514b8)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x1800514e0)
  • GetVersionExW (Address: 0x1800514d8)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x180051508)
  • CreateThreadpoolTimer (Address: 0x1800514f0)
  • SetThreadpoolTimer (Address: 0x1800514f8)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180051500)
api-ms-win-core-util-l1-1-0.dll
  • DecodePointer (Address: 0x180051518)
  • EncodePointer (Address: 0x180051520)
api-ms-win-core-version-l1-1-0.dll
  • GetFileVersionInfoExW (Address: 0x180051530)
  • GetFileVersionInfoSizeExW (Address: 0x180051540)
  • VerQueryValueW (Address: 0x180051538)
api-ms-win-core-winrt-error-l1-1-0.dll
  • GetRestrictedErrorInfo (Address: 0x180051570)
  • RoOriginateError (Address: 0x180051558)
  • RoOriginateErrorW (Address: 0x180051550)
  • RoTransformError (Address: 0x180051560)
  • SetRestrictedErrorInfo (Address: 0x180051568)
api-ms-win-core-winrt-error-l1-1-1.dll
  • IsErrorPropagationEnabled (Address: 0x180051590)
  • RoGetMatchingRestrictedErrorInfo (Address: 0x180051580)
  • RoReportFailedDelegate (Address: 0x180051588)
api-ms-win-core-winrt-l1-1-0.dll
  • RoActivateInstance (Address: 0x1800515a8)
  • RoGetActivationFactory (Address: 0x1800515a0)
api-ms-win-core-winrt-string-l1-1-0.dll
  • HSTRING_UserFree (Address: 0x180051600)
  • HSTRING_UserFree64 (Address: 0x180051610)
  • HSTRING_UserMarshal (Address: 0x180051618)
  • HSTRING_UserMarshal64 (Address: 0x1800515f8)
  • HSTRING_UserSize (Address: 0x180051620)
  • HSTRING_UserSize64 (Address: 0x180051608)
  • HSTRING_UserUnmarshal (Address: 0x1800515f0)
  • HSTRING_UserUnmarshal64 (Address: 0x1800515e8)
  • WindowsCompareStringOrdinal (Address: 0x1800515d0)
  • WindowsCreateString (Address: 0x1800515b8)
  • WindowsCreateStringReference (Address: 0x1800515c0)
  • WindowsDeleteString (Address: 0x1800515e0)
  • WindowsDuplicateString (Address: 0x1800515d8)
  • WindowsGetStringLen (Address: 0x1800515c8)
  • WindowsGetStringRawBuffer (Address: 0x180051638)
  • WindowsIsStringEmpty (Address: 0x180051630)
  • WindowsStringHasEmbeddedNull (Address: 0x180051628)
api-ms-win-crt-math-l1-1-0.dll
  • ceilf (Address: 0x180051648)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x1800516b8)
  • __CxxFrameHandler3 (Address: 0x1800516c0)
  • __CxxFrameHandler4 (Address: 0x180051758)
  • __std_terminate (Address: 0x180051750)
  • _CxxThrowException (Address: 0x1800516c8)
  • _o___std_exception_copy (Address: 0x180051730)
  • _o___std_exception_destroy (Address: 0x180051728)
  • _o___std_type_info_destroy_list (Address: 0x180051720)
  • _o___stdio_common_vsnprintf_s (Address: 0x180051718)
  • _o___stdio_common_vswprintf (Address: 0x180051710)
  • _o__callnewh (Address: 0x180051708)
  • _o__cexit (Address: 0x180051700)
  • _o__configure_narrow_argv (Address: 0x1800516e8)
  • _o__crt_atexit (Address: 0x1800516e0)
  • _o__errno (Address: 0x1800516d8)
  • _o__execute_onexit_table (Address: 0x1800516d0)
  • _o__initialize_narrow_environment (Address: 0x180051760)
  • _o__initialize_onexit_table (Address: 0x180051748)
  • _o__invalid_parameter_noinfo (Address: 0x1800516f8)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x1800516f0)
  • _o__purecall (Address: 0x180051658)
  • _o__register_onexit_function (Address: 0x180051660)
  • _o__seh_filter_dll (Address: 0x180051668)
  • _o__set_errno (Address: 0x180051670)
  • _o__wcsicmp (Address: 0x180051678)
  • _o__wcsnicmp (Address: 0x180051680)
  • _o__wtol (Address: 0x180051690)
  • _o_free (Address: 0x180051698)
  • _o_malloc (Address: 0x1800516a0)
  • _o_terminate (Address: 0x1800516a8)
  • _o_wcstol (Address: 0x1800516b0)
  • memcmp (Address: 0x180051768)
  • memcpy (Address: 0x180051770)
  • memmove (Address: 0x180051688)
  • strrchr (Address: 0x180051738)
  • wcsstr (Address: 0x180051740)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180051788)
  • _initterm_e (Address: 0x180051780)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180051798)
  • wcscmp (Address: 0x1800517a0)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x1800517b0)
  • EventRegister (Address: 0x1800517c0)
  • EventSetInformation (Address: 0x1800517c8)
  • EventUnregister (Address: 0x1800517b8)
  • EventWriteTransfer (Address: 0x1800517d0)
api-ms-win-ntuser-sysparams-l1-1-0.dll
  • GetSystemMetrics (Address: 0x1800517e0)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • GetDesktopWindow (Address: 0x1800517f0)
api-ms-win-security-base-l1-1-0.dll
  • CreateWellKnownSid (Address: 0x180051800)
  • EqualSid (Address: 0x180051818)
  • GetAce (Address: 0x180051808)
  • GetSecurityDescriptorDacl (Address: 0x180051830)
  • GetSecurityDescriptorSacl (Address: 0x180051828)
  • GetTokenInformation (Address: 0x180051810)
  • ImpersonateLoggedOnUser (Address: 0x180051840)
  • IsValidSid (Address: 0x180051838)
  • RevertToSelf (Address: 0x180051820)
api-ms-win-security-capability-l1-1-0.dll
  • CapabilityCheck (Address: 0x180051850)
api-ms-win-security-credentials-l1-1-0.dll
  • CredProtectW (Address: 0x180051860)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountNameW (Address: 0x180051870)
api-ms-win-security-provider-l1-1-0.dll
  • SetNamedSecurityInfoW (Address: 0x180051880)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180051898)
  • ConvertStringSidToSidW (Address: 0x180051890)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x1800518b0)
  • OpenSCManagerW (Address: 0x1800518a8)
  • OpenServiceW (Address: 0x1800518b8)
api-ms-win-service-winsvc-l1-1-0.dll
  • QueryServiceStatus (Address: 0x1800518c8)
api-ms-win-shcore-taskpool-l1-1-0.dll
  • SHTaskPoolAllowThreadReuse (Address: 0x1800518e0)
  • SHTaskPoolQueueTask (Address: 0x1800518d8)
combase.dll
  • (Address: 0x1800518f0)
CRYPT32.dll
  • CryptProtectData (Address: 0x180050e68)
  • CryptProtectMemory (Address: 0x180050e58)
  • CryptStringToBinaryW (Address: 0x180050e70)
  • CryptUnprotectData (Address: 0x180050e60)
  • CryptUnprotectMemory (Address: 0x180050e50)
msvcp_win.dll
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x180051908)
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x180051900)
ntdll.dll
  • NtQuerySecurityObject (Address: 0x180051930)
  • NtSetSecurityObject (Address: 0x180051940)
  • RtlAddAccessAllowedAce (Address: 0x180051920)
  • RtlAddAce (Address: 0x180051978)
  • RtlCreateAcl (Address: 0x180051958)
  • RtlCreateSecurityDescriptor (Address: 0x180051938)
  • RtlGetAce (Address: 0x180051918)
  • RtlGetDaclSecurityDescriptor (Address: 0x180051970)
  • RtlGetDeviceFamilyInfoEnum (Address: 0x180051948)
  • RtlLengthSid (Address: 0x180051950)
  • RtlNtStatusToDosError (Address: 0x180051968)
  • RtlQueryInformationAcl (Address: 0x180051960)
  • RtlSetDaclSecurityDescriptor (Address: 0x180051928)
OLEAUT32.dll
  • SysFreeString (Address: 0x180050e80)
  • SysStringByteLen (Address: 0x180050e88)
PROPSYS.dll
  • PropVariantToStringAlloc (Address: 0x180050e98)
RPCRT4.dll
  • CStdStubBuffer_AddRef (Address: 0x180050eb0)
  • CStdStubBuffer_DebugServerQueryInterface (Address: 0x180050f38)
  • CStdStubBuffer_DebugServerRelease (Address: 0x180050ec8)
  • CStdStubBuffer_Invoke (Address: 0x180050f58)
  • CStdStubBuffer_IsIIDSupported (Address: 0x180050f30)
  • I_RpcBindingInqLocalClientPID (Address: 0x180050f88)
  • IUnknown_AddRef_Proxy (Address: 0x180050f40)
  • IUnknown_QueryInterface_Proxy (Address: 0x180050ed0)
  • IUnknown_Release_Proxy (Address: 0x180050eb8)
  • MesBufferHandleReset (Address: 0x180050f60)
  • MesDecodeBufferHandleCreate (Address: 0x180050f70)
  • MesEncodeFixedBufferHandleCreate (Address: 0x180050f10)
  • MesHandleFree (Address: 0x180050f68)
  • Ndr64AsyncClientCall (Address: 0x180050f20)
  • NdrCStdStubBuffer2_Release (Address: 0x180050f08)
  • NdrDllCanUnloadNow (Address: 0x180050f98)
  • NdrDllGetClassObject (Address: 0x180050f90)
  • NdrOleAllocate (Address: 0x180050ec0)
  • NdrOleFree (Address: 0x180050ea8)
  • NdrStubCall3 (Address: 0x180050f00)
  • NdrStubForwardingFunction (Address: 0x180050f50)
  • RpcAsyncCancelCall (Address: 0x180050f18)
  • RpcAsyncCompleteCall (Address: 0x180050f28)
  • RpcAsyncInitializeHandle (Address: 0x180050f80)
  • RpcBindingFree (Address: 0x180050ed8)
  • RpcBindingFromStringBindingW (Address: 0x180050ef8)
  • RpcBindingSetAuthInfoExW (Address: 0x180050ee8)
  • RpcSsDestroyClientContext (Address: 0x180050f48)
  • RpcStringBindingComposeW (Address: 0x180050ef0)
  • RpcStringFreeW (Address: 0x180050ee0)
  • UuidCreate (Address: 0x180050f78)
SspiCli.dll
  • LogonUserExExW (Address: 0x180050fd0)
  • LsaCallAuthenticationPackage (Address: 0x180050fa8)
  • LsaConnectUntrusted (Address: 0x180050fb8)
  • LsaDeregisterLogonProcess (Address: 0x180050fc8)
  • LsaLookupAuthenticationPackage (Address: 0x180050fb0)
  • LsaRegisterLogonProcess (Address: 0x180050fc0)
USERENV.dll
  • GetProfileType (Address: 0x180050fe0)