oobecoreadapters.dll
Description: oobecoreadapters
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6456
Architecture: 64-bit
Operating System: Windows NT
SHA256: b90109f6e18208e4d4562540f47d98b0
File Size: 651.5 KB
Uploaded At: Dec. 1, 2025, 7:50 a.m.
Views: 5
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x62f0)
- DllGetActivationFactory (Ordinal: 2, Address: 0x5fa0)
- DllGetClassObject (Ordinal: 3, Address: 0x6180)
Imported DLLs & Functions
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x18007ed98)
api-ms-win-core-com-l1-1-0.dll
- CoAddRefServerProcess (Address: 0x18007edb8)
- CoCreateFreeThreadedMarshaler (Address: 0x18007edd8)
- CoCreateInstance (Address: 0x18007edf8)
- CoGetApartmentType (Address: 0x18007ede0)
- CoGetCallContext (Address: 0x18007edd0)
- CoGetMalloc (Address: 0x18007edc8)
- CoIncrementMTAUsage (Address: 0x18007edf0)
- CoMarshalInterface (Address: 0x18007ee08)
- CoReleaseMarshalData (Address: 0x18007ede8)
- CoReleaseServerProcess (Address: 0x18007edb0)
- CoTaskMemAlloc (Address: 0x18007ee18)
- CoTaskMemFree (Address: 0x18007ee00)
- CoWaitForMultipleHandles (Address: 0x18007eda8)
- CreateStreamOnHGlobal (Address: 0x18007edc0)
- StringFromCLSID (Address: 0x18007ee10)
api-ms-win-core-com-l1-1-1.dll
- RoGetAgileReference (Address: 0x18007ee28)
api-ms-win-core-com-midlproxystub-l1-1-0.dll
- CStdStubBuffer2_Connect (Address: 0x18007ee88)
- CStdStubBuffer2_CountRefs (Address: 0x18007eef0)
- CStdStubBuffer2_Disconnect (Address: 0x18007eea0)
- CStdStubBuffer2_QueryInterface (Address: 0x18007eee0)
- NdrProxyForwardingFunction3 (Address: 0x18007eee8)
- NdrProxyForwardingFunction4 (Address: 0x18007ee58)
- NdrProxyForwardingFunction5 (Address: 0x18007ee50)
- ObjectStublessClient10 (Address: 0x18007ef18)
- ObjectStublessClient11 (Address: 0x18007eef8)
- ObjectStublessClient12 (Address: 0x18007ef08)
- ObjectStublessClient13 (Address: 0x18007ee90)
- ObjectStublessClient14 (Address: 0x18007ef00)
- ObjectStublessClient15 (Address: 0x18007eeb0)
- ObjectStublessClient16 (Address: 0x18007ee70)
- ObjectStublessClient17 (Address: 0x18007ee80)
- ObjectStublessClient18 (Address: 0x18007eec0)
- ObjectStublessClient19 (Address: 0x18007ee78)
- ObjectStublessClient20 (Address: 0x18007eeb8)
- ObjectStublessClient21 (Address: 0x18007ef10)
- ObjectStublessClient22 (Address: 0x18007eed8)
- ObjectStublessClient23 (Address: 0x18007eea8)
- ObjectStublessClient24 (Address: 0x18007ef20)
- ObjectStublessClient25 (Address: 0x18007ee60)
- ObjectStublessClient26 (Address: 0x18007ee68)
- ObjectStublessClient27 (Address: 0x18007eec8)
- ObjectStublessClient3 (Address: 0x18007eed0)
- ObjectStublessClient6 (Address: 0x18007ee48)
- ObjectStublessClient7 (Address: 0x18007ee98)
- ObjectStublessClient8 (Address: 0x18007ee40)
- ObjectStublessClient9 (Address: 0x18007ee38)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x18007ef30)
- IsDebuggerPresent (Address: 0x18007ef40)
- OutputDebugStringW (Address: 0x18007ef38)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x18007ef50)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x18007ef60)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x18007ef70)
- RaiseException (Address: 0x18007ef90)
- SetLastError (Address: 0x18007ef80)
- SetUnhandledExceptionFilter (Address: 0x18007ef78)
- UnhandledExceptionFilter (Address: 0x18007ef88)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x18007efa8)
- GetFileAttributesW (Address: 0x18007efb0)
- GetFullPathNameW (Address: 0x18007efa0)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x18007efc8)
- DuplicateHandle (Address: 0x18007efc0)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x18007efd8)
- HeapAlloc (Address: 0x18007efe0)
- HeapFree (Address: 0x18007efe8)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x18007eff8)
- LocalFree (Address: 0x18007f000)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x18007f010)
- InterlockedPushEntrySList (Address: 0x18007f018)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- GetSystemPowerStatus (Address: 0x18007f028)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
- PowerClearRequest (Address: 0x18007f038)
- PowerCreateRequest (Address: 0x18007f048)
- PowerSetRequest (Address: 0x18007f040)
api-ms-win-core-kernel32-legacy-l1-1-5.dll
- SetThreadExecutionState (Address: 0x18007f058)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x18007f070)
- FindResourceExW (Address: 0x18007f088)
- FreeLibrary (Address: 0x18007f0b0)
- GetModuleFileNameA (Address: 0x18007f068)
- GetModuleFileNameW (Address: 0x18007f0a0)
- GetModuleHandleExW (Address: 0x18007f078)
- GetModuleHandleW (Address: 0x18007f090)
- GetProcAddress (Address: 0x18007f098)
- LoadLibraryExW (Address: 0x18007f0a8)
- LoadResource (Address: 0x18007f0b8)
- LockResource (Address: 0x18007f080)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x18007f0d8)
- GetGeoInfoW (Address: 0x18007f0d0)
- GetLocaleInfoEx (Address: 0x18007f0f0)
- GetLocaleInfoW (Address: 0x18007f100)
- GetThreadUILanguage (Address: 0x18007f108)
- GetUserDefaultLocaleName (Address: 0x18007f0e0)
- GetUserGeoID (Address: 0x18007f0f8)
- GetUserPreferredUILanguages (Address: 0x18007f0c8)
- ResolveLocaleName (Address: 0x18007f0e8)
api-ms-win-core-localization-l1-2-1.dll
- EnumSystemLocalesEx (Address: 0x18007f118)
api-ms-win-core-localization-l1-2-2.dll
- GetSystemDefaultLocaleName (Address: 0x18007f128)
api-ms-win-core-localization-l1-2-3.dll
- GetUserDefaultGeoName (Address: 0x18007f140)
- SetUserGeoName (Address: 0x18007f138)
api-ms-win-core-localization-private-l1-1-0.dll
- NlsUpdateLocale (Address: 0x18007f150)
api-ms-win-core-path-l1-1-0.dll
- PathAllocCombine (Address: 0x18007f160)
api-ms-win-core-processenvironment-l1-1-0.dll
- ExpandEnvironmentStringsW (Address: 0x18007f170)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x18007f190)
- GetCurrentProcessId (Address: 0x18007f188)
- GetCurrentThread (Address: 0x18007f1a0)
- GetCurrentThreadId (Address: 0x18007f180)
- OpenProcessToken (Address: 0x18007f1a8)
- OpenThreadToken (Address: 0x18007f1b0)
- TerminateProcess (Address: 0x18007f198)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x18007f1c8)
- OpenProcess (Address: 0x18007f1c0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x18007f1d8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18007f210)
- RegCreateKeyExW (Address: 0x18007f220)
- RegDeleteKeyExW (Address: 0x18007f200)
- RegDeleteValueW (Address: 0x18007f228)
- RegEnumKeyExW (Address: 0x18007f1f8)
- RegGetValueW (Address: 0x18007f230)
- RegOpenKeyExW (Address: 0x18007f1e8)
- RegQueryInfoKeyW (Address: 0x18007f238)
- RegQueryValueExW (Address: 0x18007f1f0)
- RegSetKeySecurity (Address: 0x18007f208)
- RegSetValueExW (Address: 0x18007f218)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x18007f258)
- RtlLookupFunctionEntry (Address: 0x18007f250)
- RtlVirtualUnwind (Address: 0x18007f248)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x18007f268)
- MultiByteToWideChar (Address: 0x18007f270)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x18007f2c8)
- AcquireSRWLockShared (Address: 0x18007f280)
- CreateEventExW (Address: 0x18007f2b0)
- CreateEventW (Address: 0x18007f310)
- CreateMutexExW (Address: 0x18007f288)
- CreateSemaphoreExW (Address: 0x18007f318)
- DeleteCriticalSection (Address: 0x18007f2e8)
- EnterCriticalSection (Address: 0x18007f300)
- InitializeCriticalSection (Address: 0x18007f328)
- InitializeCriticalSectionEx (Address: 0x18007f320)
- InitializeSRWLock (Address: 0x18007f2a8)
- LeaveCriticalSection (Address: 0x18007f290)
- OpenSemaphoreW (Address: 0x18007f2b8)
- ReleaseMutex (Address: 0x18007f2e0)
- ReleaseSemaphore (Address: 0x18007f308)
- ReleaseSRWLockExclusive (Address: 0x18007f2d8)
- ReleaseSRWLockShared (Address: 0x18007f2a0)
- ResetEvent (Address: 0x18007f298)
- SetEvent (Address: 0x18007f2f8)
- WaitForMultipleObjectsEx (Address: 0x18007f2d0)
- WaitForSingleObject (Address: 0x18007f2f0)
- WaitForSingleObjectEx (Address: 0x18007f2c0)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x18007f348)
- InitOnceComplete (Address: 0x18007f340)
- InitOnceExecuteOnce (Address: 0x18007f338)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x18007f370)
- GetSystemTimeAsFileTime (Address: 0x18007f360)
- GetTickCount (Address: 0x18007f358)
- GetTickCount64 (Address: 0x18007f368)
api-ms-win-core-sysinfo-l1-2-0.dll
- GetSystemTimePreciseAsFileTime (Address: 0x18007f380)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolTimer (Address: 0x18007f3c8)
- CloseThreadpoolWait (Address: 0x18007f3c0)
- CreateThreadpoolTimer (Address: 0x18007f3b8)
- CreateThreadpoolWait (Address: 0x18007f3a8)
- SetThreadpoolTimer (Address: 0x18007f398)
- SetThreadpoolWait (Address: 0x18007f3b0)
- WaitForThreadpoolTimerCallbacks (Address: 0x18007f3a0)
- WaitForThreadpoolWaitCallbacks (Address: 0x18007f390)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x18007f3d8)
- EncodePointer (Address: 0x18007f3e0)
api-ms-win-core-winrt-error-l1-1-0.dll
- GetRestrictedErrorInfo (Address: 0x18007f408)
- RoOriginateError (Address: 0x18007f3f8)
- RoOriginateErrorW (Address: 0x18007f3f0)
- RoTransformError (Address: 0x18007f410)
- SetRestrictedErrorInfo (Address: 0x18007f400)
api-ms-win-core-winrt-error-l1-1-1.dll
- IsErrorPropagationEnabled (Address: 0x18007f438)
- RoGetMatchingRestrictedErrorInfo (Address: 0x18007f430)
- RoOriginateLanguageException (Address: 0x18007f420)
- RoReportFailedDelegate (Address: 0x18007f428)
api-ms-win-core-winrt-l1-1-0.dll
- RoActivateInstance (Address: 0x18007f448)
- RoGetActivationFactory (Address: 0x18007f450)
api-ms-win-core-winrt-string-l1-1-0.dll
- HSTRING_UserFree (Address: 0x18007f4c0)
- HSTRING_UserFree64 (Address: 0x18007f498)
- HSTRING_UserMarshal (Address: 0x18007f4a0)
- HSTRING_UserMarshal64 (Address: 0x18007f480)
- HSTRING_UserSize (Address: 0x18007f4a8)
- HSTRING_UserSize64 (Address: 0x18007f490)
- HSTRING_UserUnmarshal (Address: 0x18007f478)
- HSTRING_UserUnmarshal64 (Address: 0x18007f470)
- WindowsConcatString (Address: 0x18007f488)
- WindowsCreateString (Address: 0x18007f4b0)
- WindowsCreateStringReference (Address: 0x18007f4c8)
- WindowsDeleteString (Address: 0x18007f4b8)
- WindowsDeleteStringBuffer (Address: 0x18007f4f0)
- WindowsDuplicateString (Address: 0x18007f468)
- WindowsGetStringLen (Address: 0x18007f460)
- WindowsGetStringRawBuffer (Address: 0x18007f4d0)
- WindowsIsStringEmpty (Address: 0x18007f4e0)
- WindowsPreallocateStringBuffer (Address: 0x18007f4d8)
- WindowsPromoteStringBuffer (Address: 0x18007f4f8)
- WindowsStringHasEmbeddedNull (Address: 0x18007f4e8)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x18007f568)
- __CxxFrameHandler3 (Address: 0x18007f578)
- __CxxFrameHandler4 (Address: 0x18007f618)
- __std_terminate (Address: 0x18007f610)
- _CxxThrowException (Address: 0x18007f580)
- _o___std_exception_copy (Address: 0x18007f5d8)
- _o___std_exception_destroy (Address: 0x18007f5d0)
- _o___std_type_info_destroy_list (Address: 0x18007f5c8)
- _o___stdio_common_vsnprintf_s (Address: 0x18007f5c0)
- _o___stdio_common_vsprintf (Address: 0x18007f5b8)
- _o___stdio_common_vswprintf (Address: 0x18007f5b0)
- _o__callnewh (Address: 0x18007f5a8)
- _o__cexit (Address: 0x18007f5a0)
- _o__configure_narrow_argv (Address: 0x18007f598)
- _o__crt_atexit (Address: 0x18007f590)
- _o__errno (Address: 0x18007f5f0)
- _o__execute_onexit_table (Address: 0x18007f5e8)
- _o__initialize_narrow_environment (Address: 0x18007f588)
- _o__initialize_onexit_table (Address: 0x18007f570)
- _o__invalid_parameter_noinfo (Address: 0x18007f5f8)
- _o__invalid_parameter_noinfo_noreturn (Address: 0x18007f5e0)
- _o__purecall (Address: 0x18007f508)
- _o__register_onexit_function (Address: 0x18007f510)
- _o__seh_filter_dll (Address: 0x18007f518)
- _o__wcsicmp (Address: 0x18007f520)
- _o__wcsnicmp (Address: 0x18007f528)
- _o_free (Address: 0x18007f538)
- _o_iswspace (Address: 0x18007f540)
- _o_malloc (Address: 0x18007f548)
- _o_realloc (Address: 0x18007f550)
- _o_terminate (Address: 0x18007f558)
- _o_wcscpy_s (Address: 0x18007f560)
- memcmp (Address: 0x18007f620)
- memcpy (Address: 0x18007f628)
- memmove (Address: 0x18007f530)
- wcschr (Address: 0x18007f600)
- wcsrchr (Address: 0x18007f608)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x18007f640)
- _initterm_e (Address: 0x18007f638)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x18007f650)
api-ms-win-eventing-provider-l1-1-0.dll
- EventRegister (Address: 0x18007f670)
- EventSetInformation (Address: 0x18007f668)
- EventUnregister (Address: 0x18007f660)
- EventWriteTransfer (Address: 0x18007f678)
api-ms-win-power-base-l1-1-0.dll
- GetPwrCapabilities (Address: 0x18007f688)
api-ms-win-rtcore-ntuser-synch-l1-1-0.dll
- MsgWaitForMultipleObjectsEx (Address: 0x18007f698)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
- DispatchMessageW (Address: 0x18007f6b0)
- PeekMessageW (Address: 0x18007f6c0)
- PostQuitMessage (Address: 0x18007f6a8)
- TranslateMessage (Address: 0x18007f6b8)
api-ms-win-security-base-l1-1-0.dll
- AllocateAndInitializeSid (Address: 0x18007f6f0)
- CreateWellKnownSid (Address: 0x18007f6e8)
- DuplicateTokenEx (Address: 0x18007f708)
- EqualSid (Address: 0x18007f6d0)
- FreeSid (Address: 0x18007f6d8)
- GetAce (Address: 0x18007f6e0)
- GetTokenInformation (Address: 0x18007f6f8)
- RevertToSelf (Address: 0x18007f700)
api-ms-win-security-capability-l1-1-0.dll
- CapabilityCheck (Address: 0x18007f718)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupAccountSidW (Address: 0x18007f728)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x18007f748)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18007f738)
- ConvertStringSidToSidW (Address: 0x18007f740)
api-ms-win-shcore-taskpool-l1-1-0.dll
- SHTaskPoolAllowThreadReuse (Address: 0x18007f760)
- SHTaskPoolQueueTask (Address: 0x18007f758)
api-ms-win-stateseparation-helpers-l1-1-0.dll
- GetPersistedRegistryLocationW (Address: 0x18007f770)
Bcp47Langs.dll
- Bcp47GetUnIsoRegionCode (Address: 0x18007ec50)
combase.dll
- (Address: 0x18007f780)
msvcp_win.dll
- ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x18007f790)
ntdll.dll
- NtQueryLicenseValue (Address: 0x18007f800)
- NtQuerySecurityObject (Address: 0x18007f7a8)
- NtSetSecurityObject (Address: 0x18007f7f8)
- RtlAddAccessAllowedAce (Address: 0x18007f7c8)
- RtlAddAce (Address: 0x18007f7d0)
- RtlAllocateHeap (Address: 0x18007f7d8)
- RtlConvertSidToUnicodeString (Address: 0x18007f7e8)
- RtlCreateAcl (Address: 0x18007f810)
- RtlCreateSecurityDescriptor (Address: 0x18007f7b0)
- RtlFreeHeap (Address: 0x18007f7e0)
- RtlFreeUnicodeString (Address: 0x18007f7b8)
- RtlGetAce (Address: 0x18007f808)
- RtlGetDaclSecurityDescriptor (Address: 0x18007f7c0)
- RtlIsMultiSessionSku (Address: 0x18007f7f0)
- RtlLengthSid (Address: 0x18007f820)
- RtlQueryInformationAcl (Address: 0x18007f7a0)
- RtlSetDaclSecurityDescriptor (Address: 0x18007f818)
OLEAUT32.dll
- SysAllocString (Address: 0x18007ec80)
- SysFreeString (Address: 0x18007ec68)
- SysStringLen (Address: 0x18007ec70)
- VariantClear (Address: 0x18007ec60)
- VariantInit (Address: 0x18007ec78)
POWRPROF.dll
- PowerDeterminePlatformRole (Address: 0x18007ec90)
RPCRT4.dll
- CStdStubBuffer_AddRef (Address: 0x18007ece8)
- CStdStubBuffer_Connect (Address: 0x18007ed68)
- CStdStubBuffer_CountRefs (Address: 0x18007ed70)
- CStdStubBuffer_DebugServerQueryInterface (Address: 0x18007ecd8)
- CStdStubBuffer_DebugServerRelease (Address: 0x18007ed30)
- CStdStubBuffer_Disconnect (Address: 0x18007ed38)
- CStdStubBuffer_Invoke (Address: 0x18007ecc0)
- CStdStubBuffer_IsIIDSupported (Address: 0x18007ed60)
- CStdStubBuffer_QueryInterface (Address: 0x18007ed18)
- IUnknown_AddRef_Proxy (Address: 0x18007ecd0)
- IUnknown_QueryInterface_Proxy (Address: 0x18007ed48)
- IUnknown_Release_Proxy (Address: 0x18007ed10)
- NdrClientCall3 (Address: 0x18007ecc8)
- NdrCStdStubBuffer_Release (Address: 0x18007ecb8)
- NdrCStdStubBuffer2_Release (Address: 0x18007eca0)
- NdrDllCanUnloadNow (Address: 0x18007ecb0)
- NdrDllGetClassObject (Address: 0x18007ed28)
- NdrOleAllocate (Address: 0x18007ed20)
- NdrOleFree (Address: 0x18007ece0)
- NdrStubCall3 (Address: 0x18007ed50)
- NdrStubForwardingFunction (Address: 0x18007ed40)
- RpcBindingFree (Address: 0x18007ecf0)
- RpcBindingFromStringBindingW (Address: 0x18007ed00)
- RpcExceptionFilter (Address: 0x18007eca8)
- RpcStringBindingComposeW (Address: 0x18007ecf8)
- RpcStringFreeW (Address: 0x18007ed08)
- UuidCreate (Address: 0x18007ed58)
samcli.dll
- NetLocalGroupAddMembers (Address: 0x18007f830)
WinLangdb.dll
- GetLocaleFromLanguageAndRegion (Address: 0x18007ed88)
- SetUserLanguagesCore (Address: 0x18007ed80)