AcLayers.dll
Description: Windows Compatibility DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 64-bit
Operating System: Windows NT
SHA256: 5620f93cbde964ed16b7f3fadc74751e
File Size: 325.5 KB
Uploaded At: Dec. 1, 2025, 7:21 a.m.
Views: 14
Exported Functions
- GetHookAPIs (Ordinal: 1, Address: 0x1020)
- NotifyShims (Ordinal: 2, Address: 0x2190)
Imported DLLs & Functions
ADVAPI32.dll
- GetFileSecurityA (Address: 0x18002e020)
- GetSecurityInfo (Address: 0x18002e018)
- OpenProcessToken (Address: 0x18002e010)
- OpenThreadToken (Address: 0x18002e028)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18002e328)
- RegDeleteKeyExW (Address: 0x18002e318)
- RegEnumKeyExW (Address: 0x18002e330)
- RegGetKeySecurity (Address: 0x18002e348)
- RegOpenKeyExA (Address: 0x18002e338)
- RegOpenKeyExW (Address: 0x18002e350)
- RegQueryValueExW (Address: 0x18002e320)
- RegSetValueExW (Address: 0x18002e340)
api-ms-win-eventing-provider-l1-1-0.dll
- EventWriteTransfer (Address: 0x18002e360)
api-ms-win-security-base-l1-1-0.dll
- AllocateAndInitializeSid (Address: 0x18002e388)
- CheckTokenMembership (Address: 0x18002e380)
- CopySid (Address: 0x18002e398)
- FreeSid (Address: 0x18002e378)
- GetAce (Address: 0x18002e390)
- GetAclInformation (Address: 0x18002e370)
- GetFileSecurityW (Address: 0x18002e3a8)
- GetSecurityDescriptorDacl (Address: 0x18002e3a0)
- GetTokenInformation (Address: 0x18002e3b0)
apphelp.dll
- SE_GetShimId (Address: 0x18002e3c0)
- SE_ShimDPF (Address: 0x18002e3c8)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18002e240)
- AcquireSRWLockShared (Address: 0x18002e258)
- CancelIo (Address: 0x18002e1f8)
- CloseHandle (Address: 0x18002e1b8)
- CompareStringEx (Address: 0x18002e038)
- CreateActCtxW (Address: 0x18002e0c0)
- CreateEventW (Address: 0x18002e1d8)
- CreateFileMappingW (Address: 0x18002e1a8)
- CreateFileW (Address: 0x18002e118)
- CreateMutexW (Address: 0x18002e0a0)
- DeleteCriticalSection (Address: 0x18002e048)
- EnterCriticalSection (Address: 0x18002e100)
- ExpandEnvironmentStringsA (Address: 0x18002e0f0)
- ExpandEnvironmentStringsW (Address: 0x18002e158)
- FindClose (Address: 0x18002e160)
- FindFirstFileW (Address: 0x18002e168)
- FindNLSStringEx (Address: 0x18002e268)
- GetApplicationRestartSettings (Address: 0x18002e190)
- GetCommandLineW (Address: 0x18002e2b8)
- GetCurrentProcess (Address: 0x18002e220)
- GetCurrentProcessId (Address: 0x18002e1c8)
- GetCurrentThread (Address: 0x18002e218)
- GetCurrentThreadId (Address: 0x18002e250)
- GetDriveTypeW (Address: 0x18002e170)
- GetFileAttributesW (Address: 0x18002e180)
- GetFileSize (Address: 0x18002e108)
- GetLastError (Address: 0x18002e280)
- GetLocaleInfoEx (Address: 0x18002e2b0)
- GetLogicalDriveStringsW (Address: 0x18002e178)
- GetModuleFileNameW (Address: 0x18002e140)
- GetModuleHandleW (Address: 0x18002e058)
- GetProcAddress (Address: 0x18002e050)
- GetProcessHeap (Address: 0x18002e2a0)
- GetShortPathNameW (Address: 0x18002e150)
- GetSystemDirectoryW (Address: 0x18002e138)
- GetSystemTimeAsFileTime (Address: 0x18002e068)
- GetTempFileNameA (Address: 0x18002e0d8)
- GetTempFileNameW (Address: 0x18002e0c8)
- GetTempPathA (Address: 0x18002e0e0)
- GetTempPathW (Address: 0x18002e0d0)
- GetTickCount (Address: 0x18002e060)
- GetVolumeNameForVolumeMountPointW (Address: 0x18002e130)
- GetWindowsDirectoryW (Address: 0x18002e148)
- HeapAlloc (Address: 0x18002e2a8)
- HeapFree (Address: 0x18002e290)
- HeapReAlloc (Address: 0x18002e278)
- InitializeCriticalSection (Address: 0x18002e1e0)
- InitializeCriticalSectionAndSpinCount (Address: 0x18002e0e8)
- InitializeSRWLock (Address: 0x18002e210)
- IsNLSDefinedString (Address: 0x18002e260)
- LCIDToLocaleName (Address: 0x18002e040)
- LCMapStringEx (Address: 0x18002e288)
- LeaveCriticalSection (Address: 0x18002e0f8)
- LoadLibraryW (Address: 0x18002e230)
- LocalAlloc (Address: 0x18002e128)
- LocalFree (Address: 0x18002e120)
- MapViewOfFile (Address: 0x18002e1a0)
- MultiByteToWideChar (Address: 0x18002e298)
- OpenMutexW (Address: 0x18002e0a8)
- OutputDebugStringA (Address: 0x18002e1e8)
- QueryActCtxW (Address: 0x18002e0b8)
- QueryFullProcessImageNameW (Address: 0x18002e228)
- QueryPerformanceCounter (Address: 0x18002e070)
- ReadFile (Address: 0x18002e208)
- RegisterApplicationRestart (Address: 0x18002e188)
- ReleaseActCtx (Address: 0x18002e0b0)
- ReleaseSRWLockExclusive (Address: 0x18002e238)
- ReleaseSRWLockShared (Address: 0x18002e248)
- SearchPathW (Address: 0x18002e098)
- SetFilePointer (Address: 0x18002e110)
- SetLastError (Address: 0x18002e1d0)
- SetNamedPipeHandleState (Address: 0x18002e1c0)
- SetUnhandledExceptionFilter (Address: 0x18002e080)
- Sleep (Address: 0x18002e090)
- TerminateProcess (Address: 0x18002e078)
- UnhandledExceptionFilter (Address: 0x18002e088)
- UnmapViewOfFile (Address: 0x18002e1b0)
- WaitForSingleObject (Address: 0x18002e200)
- WerRegisterMemoryBlock (Address: 0x18002e198)
- WideCharToMultiByte (Address: 0x18002e270)
- WriteFile (Address: 0x18002e1f0)
msvcrt.dll
- __C_specific_handler (Address: 0x18002e428)
- __CxxFrameHandler3 (Address: 0x18002e3f8)
- _amsg_exit (Address: 0x18002e4b0)
- _CxxThrowException (Address: 0x18002e3e8)
- _initterm (Address: 0x18002e4c8)
- _scwprintf (Address: 0x18002e448)
- _stricmp (Address: 0x18002e420)
- _vscprintf (Address: 0x18002e498)
- _vscwprintf (Address: 0x18002e408)
- _vsnprintf (Address: 0x18002e418)
- _vsnwprintf (Address: 0x18002e410)
- _wcsicmp (Address: 0x18002e400)
- _wcsnicmp (Address: 0x18002e450)
- _XcptFilter (Address: 0x18002e4a8)
- ??1type_info@@UEAA@XZ (Address: 0x18002e4d0)
- atol (Address: 0x18002e440)
- free (Address: 0x18002e4b8)
- iswctype (Address: 0x18002e470)
- iswspace (Address: 0x18002e4a0)
- malloc (Address: 0x18002e4c0)
- memcpy (Address: 0x18002e3e0)
- memmove (Address: 0x18002e3d8)
- memset (Address: 0x18002e3f0)
- sprintf_s (Address: 0x18002e430)
- strcmp (Address: 0x18002e4d8)
- towlower (Address: 0x18002e478)
- vsprintf_s (Address: 0x18002e438)
- wcschr (Address: 0x18002e480)
- wcsncmp (Address: 0x18002e460)
- wcspbrk (Address: 0x18002e488)
- wcsrchr (Address: 0x18002e458)
- wcsspn (Address: 0x18002e468)
- wcsstr (Address: 0x18002e490)
ntdll.dll
- NtOpenFile (Address: 0x18002e560)
- NtQueryInformationProcess (Address: 0x18002e520)
- NtQueryInformationToken (Address: 0x18002e580)
- NtQueryKey (Address: 0x18002e4f8)
- NtQueryObject (Address: 0x18002e5c8)
- NtQuerySystemInformation (Address: 0x18002e568)
- NtTerminateProcess (Address: 0x18002e510)
- RtlAllocateHeap (Address: 0x18002e4e8)
- RtlAppendUnicodeToString (Address: 0x18002e5d0)
- RtlCaptureContext (Address: 0x18002e548)
- RtlCaptureStackBackTrace (Address: 0x18002e538)
- RtlCreateUnicodeStringFromAsciiz (Address: 0x18002e590)
- RtlEqualSid (Address: 0x18002e5c0)
- RtlFormatCurrentUserKeyPath (Address: 0x18002e5d8)
- RtlFreeHeap (Address: 0x18002e4f0)
- RtlFreeUnicodeString (Address: 0x18002e598)
- RtlGetLastNtStatus (Address: 0x18002e5e0)
- RtlGetOwnerSecurityDescriptor (Address: 0x18002e5b8)
- RtlImageNtHeader (Address: 0x18002e540)
- RtlInitializeSid (Address: 0x18002e578)
- RtlInitUnicodeString (Address: 0x18002e558)
- RtlLengthRequiredSid (Address: 0x18002e570)
- RtlLookupFunctionEntry (Address: 0x18002e5f8)
- RtlMultiByteToUnicodeN (Address: 0x18002e5a0)
- RtlNtStatusToDosError (Address: 0x18002e500)
- RtlRaiseException (Address: 0x18002e518)
- RtlReportException (Address: 0x18002e508)
- RtlSetLastWin32ErrorAndNtStatusFromNtStatus (Address: 0x18002e5e8)
- RtlSubAuthoritySid (Address: 0x18002e588)
- RtlUnicodeToMultiByteN (Address: 0x18002e5b0)
- RtlUnicodeToMultiByteSize (Address: 0x18002e5a8)
- RtlUniform (Address: 0x18002e528)
- RtlValidateHeap (Address: 0x18002e530)
- RtlVirtualUnwind (Address: 0x18002e5f0)
- WinSqmAddToStream (Address: 0x18002e550)
sfc.dll
- SfcIsKeyProtected (Address: 0x18002e608)
SHELL32.dll
- ShellExecuteExW (Address: 0x18002e2c8)
SHLWAPI.dll
- PathFindFileNameW (Address: 0x18002e2d8)
USER32.dll
- CharUpperW (Address: 0x18002e2f8)
- EnumDisplaySettingsW (Address: 0x18002e2f0)
- GetSystemMetrics (Address: 0x18002e2e8)
WINSPOOL.DRV
- (Address: 0x18002e308)