Windows.AccountsControl.dll
Description: Windows Accounts Control
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5794
Architecture: 64-bit
Operating System: Windows NT
SHA256: 60ad25899faf4952daf7c768ef92adcd
File Size: 1.0 MB
Uploaded At: Dec. 1, 2025, 7:43 a.m.
Views: 4
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x54b0)
- DllGetActivationFactory (Ordinal: 2, Address: 0x51a0)
- DllGetClassObject (Ordinal: 3, Address: 0x5380)
- GetProxyDllInfo (Ordinal: 4, Address: 0x2c50)
Imported DLLs & Functions
api-ms-win-appmodel-runtime-l1-1-0.dll
- GetPackageFamilyName (Address: 0x1800bfc90)
- GetPackageFullName (Address: 0x1800bfc88)
- GetPackagesByPackageFamily (Address: 0x1800bfc80)
api-ms-win-appmodel-runtime-l1-1-1.dll
- GetPackageFullNameFromToken (Address: 0x1800bfca0)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x1800bfcb0)
api-ms-win-core-com-l1-1-0.dll
- CoCreateFreeThreadedMarshaler (Address: 0x1800bfd28)
- CoCreateInstance (Address: 0x1800bfd00)
- CoGetApartmentType (Address: 0x1800bfcc0)
- CoGetCallContext (Address: 0x1800bfcd0)
- CoGetCallerTID (Address: 0x1800bfd30)
- CoGetInterfaceAndReleaseStream (Address: 0x1800bfcf8)
- CoGetMalloc (Address: 0x1800bfd08)
- CoMarshalInterface (Address: 0x1800bfcd8)
- CoReleaseMarshalData (Address: 0x1800bfce0)
- CoSwitchCallContext (Address: 0x1800bfcc8)
- CoTaskMemAlloc (Address: 0x1800bfd10)
- CoTaskMemFree (Address: 0x1800bfcf0)
- CoTaskMemRealloc (Address: 0x1800bfd18)
- CoWaitForMultipleHandles (Address: 0x1800bfce8)
- CreateStreamOnHGlobal (Address: 0x1800bfd20)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x1800bfd40)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
- CStdStubBuffer2_Connect (Address: 0x1800bfe20)
- CStdStubBuffer2_CountRefs (Address: 0x1800bfe28)
- CStdStubBuffer2_Disconnect (Address: 0x1800bfdb0)
- CStdStubBuffer2_QueryInterface (Address: 0x1800bfe50)
- NdrProxyForwardingFunction3 (Address: 0x1800bfe18)
- NdrProxyForwardingFunction4 (Address: 0x1800bfdd0)
- NdrProxyForwardingFunction5 (Address: 0x1800bfdf0)
- ObjectStublessClient10 (Address: 0x1800bfd50)
- ObjectStublessClient11 (Address: 0x1800bfdd8)
- ObjectStublessClient12 (Address: 0x1800bfde8)
- ObjectStublessClient13 (Address: 0x1800bfda8)
- ObjectStublessClient14 (Address: 0x1800bfde0)
- ObjectStublessClient15 (Address: 0x1800bfd90)
- ObjectStublessClient16 (Address: 0x1800bfe08)
- ObjectStublessClient17 (Address: 0x1800bfe00)
- ObjectStublessClient18 (Address: 0x1800bfd78)
- ObjectStublessClient19 (Address: 0x1800bfdc8)
- ObjectStublessClient20 (Address: 0x1800bfd88)
- ObjectStublessClient21 (Address: 0x1800bfe10)
- ObjectStublessClient22 (Address: 0x1800bfdc0)
- ObjectStublessClient23 (Address: 0x1800bfd98)
- ObjectStublessClient24 (Address: 0x1800bfe30)
- ObjectStublessClient25 (Address: 0x1800bfe38)
- ObjectStublessClient26 (Address: 0x1800bfdf8)
- ObjectStublessClient27 (Address: 0x1800bfd58)
- ObjectStublessClient28 (Address: 0x1800bfd80)
- ObjectStublessClient3 (Address: 0x1800bfe40)
- ObjectStublessClient4 (Address: 0x1800bfe48)
- ObjectStublessClient5 (Address: 0x1800bfda0)
- ObjectStublessClient6 (Address: 0x1800bfd70)
- ObjectStublessClient7 (Address: 0x1800bfdb8)
- ObjectStublessClient8 (Address: 0x1800bfd68)
- ObjectStublessClient9 (Address: 0x1800bfd60)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800bfe70)
- IsDebuggerPresent (Address: 0x1800bfe68)
- OutputDebugStringW (Address: 0x1800bfe60)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800bfe80)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800bfe90)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800bfea0)
- RaiseException (Address: 0x1800bfeb0)
- SetLastError (Address: 0x1800bfeb8)
- SetUnhandledExceptionFilter (Address: 0x1800bfea8)
- UnhandledExceptionFilter (Address: 0x1800bfec0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800bfed0)
- DuplicateHandle (Address: 0x1800bfed8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800bfef0)
- HeapAlloc (Address: 0x1800bfee8)
- HeapFree (Address: 0x1800bfef8)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1800bff10)
- LocalFree (Address: 0x1800bff08)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1800bff28)
- FindResourceExW (Address: 0x1800bff60)
- FreeLibrary (Address: 0x1800bff40)
- GetModuleFileNameA (Address: 0x1800bff38)
- GetModuleHandleExW (Address: 0x1800bff30)
- GetModuleHandleW (Address: 0x1800bff58)
- GetProcAddress (Address: 0x1800bff70)
- LoadLibraryExW (Address: 0x1800bff48)
- LoadResource (Address: 0x1800bff50)
- LoadStringW (Address: 0x1800bff20)
- LockResource (Address: 0x1800bff68)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800bff80)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1800bffa8)
- GetCurrentProcessId (Address: 0x1800bffc8)
- GetCurrentThread (Address: 0x1800bff98)
- GetCurrentThreadId (Address: 0x1800bffb0)
- GetProcessId (Address: 0x1800bff90)
- OpenProcessToken (Address: 0x1800bffb8)
- OpenThreadToken (Address: 0x1800bffa0)
- TerminateProcess (Address: 0x1800bffc0)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x1800bffd8)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800bffe8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800c0008)
- RegEnumKeyExW (Address: 0x1800c0010)
- RegGetValueW (Address: 0x1800c0000)
- RegOpenKeyExW (Address: 0x1800c0018)
- RegQueryInfoKeyW (Address: 0x1800bfff8)
- RegQueryValueExW (Address: 0x1800c0020)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800c0040)
- RtlLookupFunctionEntry (Address: 0x1800c0030)
- RtlVirtualUnwind (Address: 0x1800c0038)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFileExistsW (Address: 0x1800c0050)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1800c0060)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800c00c8)
- AcquireSRWLockShared (Address: 0x1800c0088)
- CreateEventExW (Address: 0x1800c00b0)
- CreateEventW (Address: 0x1800c0098)
- CreateMutexExW (Address: 0x1800c0070)
- CreateSemaphoreExW (Address: 0x1800c0078)
- DeleteCriticalSection (Address: 0x1800c00e8)
- EnterCriticalSection (Address: 0x1800c00d8)
- InitializeCriticalSectionEx (Address: 0x1800c0080)
- InitializeSRWLock (Address: 0x1800c0090)
- LeaveCriticalSection (Address: 0x1800c00e0)
- OpenSemaphoreW (Address: 0x1800c00b8)
- ReleaseMutex (Address: 0x1800c00d0)
- ReleaseSemaphore (Address: 0x1800c00f0)
- ReleaseSRWLockExclusive (Address: 0x1800c00f8)
- ReleaseSRWLockShared (Address: 0x1800c00a0)
- SetEvent (Address: 0x1800c00a8)
- WaitForSingleObject (Address: 0x1800c0100)
- WaitForSingleObjectEx (Address: 0x1800c00c0)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1800c0120)
- InitOnceComplete (Address: 0x1800c0128)
- InitOnceExecuteOnce (Address: 0x1800c0118)
- Sleep (Address: 0x1800c0110)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1800c0138)
- GetTickCount (Address: 0x1800c0140)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetProductInfo (Address: 0x1800c0150)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x1800c0170)
- CreateThreadpoolTimer (Address: 0x1800c0178)
- SetThreadpoolTimer (Address: 0x1800c0168)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800c0160)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1800c0190)
- EncodePointer (Address: 0x1800c0188)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x1800c01a8)
- RoOriginateError (Address: 0x1800c01b0)
- RoOriginateErrorW (Address: 0x1800c01c0)
- RoTransformError (Address: 0x1800c01b8)
- SetRestrictedErrorInfo (Address: 0x1800c01a0)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x1800c01d0)
- RoGetMatchingRestrictedErrorInfo (Address: 0x1800c01e0)
- RoReportFailedDelegate (Address: 0x1800c01d8)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x1800c01f0)
- RoGetActivationFactory (Address: 0x1800c01f8)
api-ms-win-core-winrt-robuffer-l1-1-0.dll
- RoGetBufferMarshaler (Address: 0x1800c0208)
api-ms-win-core-winrt-string-l1-1-0.dll
- HSTRING_UserFree (Address: 0x1800c0268)
- HSTRING_UserFree64 (Address: 0x1800c0258)
- HSTRING_UserMarshal (Address: 0x1800c0248)
- HSTRING_UserMarshal64 (Address: 0x1800c0290)
- HSTRING_UserSize (Address: 0x1800c0240)
- HSTRING_UserSize64 (Address: 0x1800c0280)
- HSTRING_UserUnmarshal (Address: 0x1800c0298)
- HSTRING_UserUnmarshal64 (Address: 0x1800c0288)
- WindowsCompareStringOrdinal (Address: 0x1800c0228)
- WindowsCreateString (Address: 0x1800c0238)
- WindowsCreateStringReference (Address: 0x1800c0218)
- WindowsDeleteString (Address: 0x1800c0250)
- WindowsDuplicateString (Address: 0x1800c0230)
- WindowsGetStringLen (Address: 0x1800c02a0)
- WindowsGetStringRawBuffer (Address: 0x1800c0278)
- WindowsIsStringEmpty (Address: 0x1800c0220)
- WindowsStringHasEmbeddedNull (Address: 0x1800c0270)
- WindowsSubstringWithSpecifiedLength (Address: 0x1800c0260)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1800c02d8)
- EventProviderEnabled (Address: 0x1800c02b0)
- EventRegister (Address: 0x1800c02b8)
- EventSetInformation (Address: 0x1800c02c0)
- EventUnregister (Address: 0x1800c02c8)
- EventWriteTransfer (Address: 0x1800c02d0)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
- AllowSetForegroundWindow (Address: 0x1800c02e8)
api-ms-win-security-base-l1-1-0.dll
- CopySid (Address: 0x1800c0328)
- CreateWellKnownSid (Address: 0x1800c0310)
- DuplicateTokenEx (Address: 0x1800c0300)
- EqualSid (Address: 0x1800c0330)
- GetAce (Address: 0x1800c0308)
- GetLengthSid (Address: 0x1800c0318)
- GetTokenInformation (Address: 0x1800c02f8)
- RevertToSelf (Address: 0x1800c0320)
api-ms-win-security-base-l1-2-0.dll
- CheckTokenMembershipEx (Address: 0x1800c0340)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x1800c0350)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1800c0360)
api-ms-win-shcore-scaling-l1-1-1.dll
- (Address: 0x1800c0370)
api-ms-win-shcore-stream-l1-1-0.dll
- SHCreateStreamOnFileEx (Address: 0x1800c0380)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolAllowThreadReuse (Address: 0x1800c0390)
- SHTaskPoolQueueTask (Address: 0x1800c0398)
api-ms-win-storage-exports-external-l1-1-0.dll
- STORAGE_CStorageItem_GetValidatedStorageItem (Address: 0x1800c03a8)
combase.dll
- (Address: 0x1800c03c8)
- (Address: 0x1800c03c0)
- (Address: 0x1800c03b8)
CRYPT32.dll
- CertAddCertificateContextToStore (Address: 0x1800bfb88)
- CertAddSerializedElementToStore (Address: 0x1800bfba8)
- CertCloseStore (Address: 0x1800bfb78)
- CertCompareIntegerBlob (Address: 0x1800bfbb0)
- CertCreateCertificateContext (Address: 0x1800bfb70)
- CertFindCertificateInStore (Address: 0x1800bfba0)
- CertFreeCertificateContext (Address: 0x1800bfb98)
- CertOpenStore (Address: 0x1800bfb90)
- CertSaveStore (Address: 0x1800bfb80)
msvcrt.dll
- __C_specific_handler (Address: 0x1800c0450)
- __CxxFrameHandler3 (Address: 0x1800c04a0)
- __dllonexit (Address: 0x1800c04b8)
- _amsg_exit (Address: 0x1800c03e0)
- _callnewh (Address: 0x1800c0420)
- _CxxThrowException (Address: 0x1800c0418)
- _initterm (Address: 0x1800c03d8)
- _lock (Address: 0x1800c04a8)
- _onexit (Address: 0x1800c04c0)
- _purecall (Address: 0x1800c04c8)
- _unlock (Address: 0x1800c04b0)
- _vsnprintf_s (Address: 0x1800c0460)
- _vsnwprintf (Address: 0x1800c0510)
- _wcsicmp (Address: 0x1800c0500)
- _wtoi (Address: 0x1800c0448)
- _XcptFilter (Address: 0x1800c03e8)
- ??_V@YAXPEAX@Z (Address: 0x1800c0508)
- ??0exception@@QEAA@AEBQEBD@Z (Address: 0x1800c0400)
- ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800c03f8)
- ??0exception@@QEAA@AEBV0@@Z (Address: 0x1800c0468)
- ??0exception@@QEAA@XZ (Address: 0x1800c0470)
- ??1exception@@UEAA@XZ (Address: 0x1800c0478)
- ??1type_info@@UEAA@XZ (Address: 0x1800c04f0)
- ??3@YAXPEAX@Z (Address: 0x1800c04d0)
- ?terminate@@YAXXZ (Address: 0x1800c04f8)
- ?what@exception@@UEBAPEBDXZ (Address: 0x1800c03f0)
- free (Address: 0x1800c0498)
- malloc (Address: 0x1800c0488)
- memcmp (Address: 0x1800c04e0)
- memcpy (Address: 0x1800c0410)
- memcpy_s (Address: 0x1800c04d8)
- memmove (Address: 0x1800c0408)
- memmove_s (Address: 0x1800c0490)
- memset (Address: 0x1800c04e8)
- realloc (Address: 0x1800c0480)
- swprintf_s (Address: 0x1800c0458)
- toupper (Address: 0x1800c0428)
- towupper (Address: 0x1800c0440)
- wcscmp (Address: 0x1800c0518)
- wcscspn (Address: 0x1800c0430)
- wcstok_s (Address: 0x1800c0438)
ntdll.dll
- NtQuerySecurityObject (Address: 0x1800c0540)
- NtSetSecurityObject (Address: 0x1800c0530)
- RtlAddAccessAllowedAce (Address: 0x1800c0550)
- RtlAddAce (Address: 0x1800c0558)
- RtlCreateAcl (Address: 0x1800c0568)
- RtlCreateSecurityDescriptor (Address: 0x1800c0538)
- RtlGetAce (Address: 0x1800c0560)
- RtlGetDaclSecurityDescriptor (Address: 0x1800c0588)
- RtlGetDeviceFamilyInfoEnum (Address: 0x1800c0528)
- RtlIsMultiSessionSku (Address: 0x1800c0578)
- RtlIsMultiUsersInSessionSku (Address: 0x1800c0590)
- RtlLengthSid (Address: 0x1800c0570)
- RtlQueryInformationAcl (Address: 0x1800c0580)
- RtlSetDaclSecurityDescriptor (Address: 0x1800c0548)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x1800bfbe0)
- CStdStubBuffer_Connect (Address: 0x1800bfc48)
- CStdStubBuffer_CountRefs (Address: 0x1800bfc10)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x1800bfbc0)
- CStdStubBuffer_DebugServerRelease (Address: 0x1800bfc38)
- CStdStubBuffer_Disconnect (Address: 0x1800bfc40)
- CStdStubBuffer_Invoke (Address: 0x1800bfbd0)
- CStdStubBuffer_IsIIDSupported (Address: 0x1800bfc50)
- CStdStubBuffer_QueryInterface (Address: 0x1800bfc18)
- I_RpcBindingInqLocalClientPID (Address: 0x1800bfbd8)
- IUnknown_AddRef_Proxy (Address: 0x1800bfbc8)
- IUnknown_QueryInterface_Proxy (Address: 0x1800bfc58)
- IUnknown_Release_Proxy (Address: 0x1800bfc08)
- NdrCStdStubBuffer_Release (Address: 0x1800bfc00)
- NdrCStdStubBuffer2_Release (Address: 0x1800bfbe8)
- NdrDllCanUnloadNow (Address: 0x1800bfbf8)
- NdrDllGetClassObject (Address: 0x1800bfbf0)
- NdrOleAllocate (Address: 0x1800bfc20)
- NdrOleFree (Address: 0x1800bfc30)
- NdrStubCall3 (Address: 0x1800bfc60)
- NdrStubForwardingFunction (Address: 0x1800bfc28)
XmlLite.dll
- CreateXmlReader (Address: 0x1800bfc70)