oleacc.dll
Description: Active Accessibility Core Component
Authors: © Microsoft Corporation. All rights reserved.
Version: 7.2.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: eae80a9aaeaa3cf42a5fb81c2e188ee2
File Size: 394.5 KB
Uploaded At: Dec. 1, 2025, 7:35 a.m.
Views: 12
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory, OpenProcess, VirtualAllocEx
Exported Functions
- DllRegisterServer (Ordinal: 1, Address: 0xcb10)
- DllUnregisterServer (Ordinal: 2, Address: 0xcb10)
- AccGetRunningUtilityState (Ordinal: 3, Address: 0x3d9e0)
- AccNotifyTouchInteraction (Ordinal: 4, Address: 0x3e570)
- AccSetRunningUtilityState (Ordinal: 5, Address: 0x3e600)
- AccessibleChildren (Ordinal: 6, Address: 0xa370)
- AccessibleObjectFromEvent (Ordinal: 7, Address: 0x3e650)
- AccessibleObjectFromPoint (Ordinal: 8, Address: 0x3e6b0)
- AccessibleObjectFromWindow (Ordinal: 9, Address: 0x5320)
- AccessibleObjectFromWindowTimeout (Ordinal: 10, Address: 0x2c00)
- CreateStdAccessibleObject (Ordinal: 11, Address: 0xe230)
- CreateStdAccessibleProxyA (Ordinal: 12, Address: 0x3e700)
- CreateStdAccessibleProxyW (Ordinal: 13, Address: 0x9a20)
- DllCanUnloadNow (Ordinal: 14, Address: 0xc490)
- DllGetClassObject (Ordinal: 15, Address: 0x34a0)
- GetOleaccVersionInfo (Ordinal: 16, Address: 0x3e750)
- GetProcessHandleFromHwnd (Ordinal: 17, Address: 0xc7c0)
- GetRoleTextA (Ordinal: 18, Address: 0x3e7a0)
- GetRoleTextW (Ordinal: 19, Address: 0x3290)
- GetStateTextA (Ordinal: 20, Address: 0x3e7f0)
- GetStateTextW (Ordinal: 21, Address: 0x3e840)
- IID_IAccessible (Ordinal: 22, Address: 0x4bb40)
- IID_IAccessibleHandler (Ordinal: 23, Address: 0x4caf8)
- LIBID_Accessibility (Ordinal: 24, Address: 0x4eac0)
- LresultFromObject (Ordinal: 25, Address: 0x81d0)
- ObjectFromLresult (Ordinal: 26, Address: 0xe310)
- PropMgrClient_LookupProp (Ordinal: 27, Address: 0x17b0)
- WindowFromAccessibleObject (Ordinal: 28, Address: 0xa210)
Imported DLLs & Functions
api-ms-win-core-atoms-l1-1-0.dll
- GlobalAddAtomW (Address: 0x180049e00)
- GlobalDeleteAtom (Address: 0x180049e08)
- GlobalFindAtomW (Address: 0x180049e10)
- GlobalGetAtomNameW (Address: 0x180049df8)
api-ms-win-core-debug-l1-1-0.dll
- IsDebuggerPresent (Address: 0x180049e20)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x180049e30)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x180049e40)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x180049e60)
- RaiseException (Address: 0x180049e68)
- SetLastError (Address: 0x180049e58)
- SetUnhandledExceptionFilter (Address: 0x180049e50)
- UnhandledExceptionFilter (Address: 0x180049e70)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x180049e88)
- DuplicateHandle (Address: 0x180049e80)
api-ms-win-core-heap-l2-1-0.dll
- GlobalAlloc (Address: 0x180049e98)
- GlobalFree (Address: 0x180049ea0)
- LocalAlloc (Address: 0x180049eb0)
- LocalFree (Address: 0x180049ea8)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- GlobalLock (Address: 0x180049ec8)
- GlobalUnlock (Address: 0x180049ec0)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x180049ed8)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x180049f20)
- FindResourceExW (Address: 0x180049f10)
- FreeLibrary (Address: 0x180049f38)
- GetModuleFileNameW (Address: 0x180049f30)
- GetModuleHandleExW (Address: 0x180049ef8)
- GetModuleHandleW (Address: 0x180049ee8)
- GetProcAddress (Address: 0x180049f18)
- LoadLibraryExW (Address: 0x180049f28)
- LoadResource (Address: 0x180049f00)
- LoadStringW (Address: 0x180049ef0)
- SizeofResource (Address: 0x180049f08)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryW (Address: 0x180049f48)
api-ms-win-core-localization-l1-2-0.dll
- GetLocaleInfoW (Address: 0x180049f60)
- GetThreadLocale (Address: 0x180049f58)
api-ms-win-core-memory-l1-1-0.dll
- CreateFileMappingW (Address: 0x180049f88)
- MapViewOfFile (Address: 0x180049f80)
- ReadProcessMemory (Address: 0x180049f70)
- UnmapViewOfFile (Address: 0x180049fa0)
- VirtualAllocEx (Address: 0x180049f78)
- VirtualFreeEx (Address: 0x180049f90)
- WriteProcessMemory (Address: 0x180049f98)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x180049fd8)
- GetCurrentProcess (Address: 0x180049fe0)
- GetCurrentProcessId (Address: 0x180049fb0)
- GetCurrentThreadId (Address: 0x180049fc8)
- GetExitCodeThread (Address: 0x180049fb8)
- OpenProcessToken (Address: 0x180049fd0)
- TerminateProcess (Address: 0x180049fc0)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x180049ff8)
- OpenProcess (Address: 0x180049ff0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18004a008)
api-ms-win-core-psapi-l1-1-0.dll
- K32GetModuleBaseNameW (Address: 0x18004a018)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18004a048)
- RegCreateKeyExW (Address: 0x18004a050)
- RegDeleteValueW (Address: 0x18004a058)
- RegEnumKeyExW (Address: 0x18004a028)
- RegOpenKeyExW (Address: 0x18004a030)
- RegQueryInfoKeyW (Address: 0x18004a040)
- RegQueryValueExW (Address: 0x18004a060)
- RegSetValueExW (Address: 0x18004a038)
api-ms-win-core-string-l1-1-0.dll
- CompareStringW (Address: 0x18004a078)
- MultiByteToWideChar (Address: 0x18004a080)
- WideCharToMultiByte (Address: 0x18004a070)
api-ms-win-core-string-l2-1-0.dll
- CharLowerBuffW (Address: 0x18004a098)
- CharNextW (Address: 0x18004a090)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x18004a0b0)
- lstrcmpW (Address: 0x18004a0a8)
api-ms-win-core-synch-l1-1-0.dll
- CreateEventW (Address: 0x18004a0c8)
- CreateMutexW (Address: 0x18004a0d8)
- DeleteCriticalSection (Address: 0x18004a0d0)
- EnterCriticalSection (Address: 0x18004a0f8)
- InitializeCriticalSection (Address: 0x18004a0e0)
- LeaveCriticalSection (Address: 0x18004a0f0)
- OpenMutexW (Address: 0x18004a0e8)
- SetEvent (Address: 0x18004a0c0)
- WaitForSingleObject (Address: 0x18004a100)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x18004a110)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x18004a128)
- GetTickCount (Address: 0x18004a120)
- GetVersionExA (Address: 0x18004a130)
- GetVersionExW (Address: 0x18004a138)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
- QueueUserWorkItem (Address: 0x18004a148)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x18004a238)
- __CxxFrameHandler4 (Address: 0x18004a240)
- __std_terminate (Address: 0x18004a230)
- _CxxThrowException (Address: 0x18004a248)
- _o___std_type_info_destroy_list (Address: 0x18004a220)
- _o___stdio_common_vswprintf (Address: 0x18004a218)
- _o___stdio_common_vswprintf_s (Address: 0x18004a210)
- _o__beginthreadex (Address: 0x18004a208)
- _o__cexit (Address: 0x18004a200)
- _o__configure_narrow_argv (Address: 0x18004a1f8)
- _o__crt_atexit (Address: 0x18004a1f0)
- _o__errno (Address: 0x18004a1e8)
- _o__execute_onexit_table (Address: 0x18004a1e0)
- _o__initialize_narrow_environment (Address: 0x18004a158)
- _o__initialize_onexit_table (Address: 0x18004a160)
- _o__invalid_parameter_noinfo (Address: 0x18004a168)
- _o__purecall (Address: 0x18004a170)
- _o__recalloc (Address: 0x18004a178)
- _o__register_onexit_function (Address: 0x18004a180)
- _o__seh_filter_dll (Address: 0x18004a188)
- _o__wcslwr_s (Address: 0x18004a198)
- _o_free (Address: 0x18004a1a0)
- _o_malloc (Address: 0x18004a1a8)
- _o_strncpy_s (Address: 0x18004a1b0)
- _o_terminate (Address: 0x18004a1b8)
- _o_wcscat_s (Address: 0x18004a1c0)
- _o_wcscpy_s (Address: 0x18004a1c8)
- _o_wcsncpy_s (Address: 0x18004a1d0)
- _o_wcstok_s (Address: 0x18004a1d8)
- memcmp (Address: 0x18004a250)
- memcpy (Address: 0x18004a258)
- memmove (Address: 0x18004a190)
- wcsstr (Address: 0x18004a228)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x18004a270)
- _initterm_e (Address: 0x18004a268)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x18004a280)
- wcscmp (Address: 0x18004a288)
api-ms-win-security-base-l1-1-0.dll
- AllocateAndInitializeSid (Address: 0x18004a2a0)
- CheckTokenMembership (Address: 0x18004a298)
- FreeSid (Address: 0x18004a2b8)
- GetSidSubAuthority (Address: 0x18004a2b0)
- GetTokenInformation (Address: 0x18004a2a8)
ntdll.dll
- EtwGetTraceEnableFlags (Address: 0x18004a2e0)
- EtwGetTraceEnableLevel (Address: 0x18004a2d0)
- EtwGetTraceLoggerHandle (Address: 0x18004a2c8)
- EtwLogTraceEvent (Address: 0x18004a318)
- EtwRegisterTraceGuidsW (Address: 0x18004a2d8)
- EtwUnregisterTraceGuids (Address: 0x18004a2f8)
- NtAllocateVirtualMemory (Address: 0x18004a2e8)
- NtFreeVirtualMemory (Address: 0x18004a2f0)
- RtlCaptureContext (Address: 0x18004a300)
- RtlLookupFunctionEntry (Address: 0x18004a308)
- RtlVirtualUnwind (Address: 0x18004a310)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x180049d58)
- CStdStubBuffer_Connect (Address: 0x180049d78)
- CStdStubBuffer_CountRefs (Address: 0x180049da0)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x180049d88)
- CStdStubBuffer_DebugServerRelease (Address: 0x180049d60)
- CStdStubBuffer_Disconnect (Address: 0x180049dc8)
- CStdStubBuffer_Invoke (Address: 0x180049de0)
- CStdStubBuffer_IsIIDSupported (Address: 0x180049d90)
- CStdStubBuffer_QueryInterface (Address: 0x180049d80)
- IUnknown_AddRef_Proxy (Address: 0x180049d98)
- IUnknown_QueryInterface_Proxy (Address: 0x180049dc0)
- IUnknown_Release_Proxy (Address: 0x180049de8)
- NdrCStdStubBuffer_Release (Address: 0x180049dd8)
- NdrCStdStubBuffer2_Release (Address: 0x180049db0)
- NdrDllCanUnloadNow (Address: 0x180049dd0)
- NdrDllGetClassObject (Address: 0x180049d50)
- NdrOleAllocate (Address: 0x180049d70)
- NdrOleFree (Address: 0x180049d68)
- NdrStubCall3 (Address: 0x180049db8)
- NdrStubForwardingFunction (Address: 0x180049da8)