AcSpecfc.dll
Description: Windows Compatibility DLL
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.3636
Architecture: 32-bit
Operating System: Windows NT
SHA256: c3706d4f86ac7157e76382c255c0aa84
File Size: 451.0 KB
Uploaded At: Dec. 1, 2025, 7:52 a.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- GetHookAPIs (Ordinal: 1, Address: 0x1dff0)
- NotifyShims (Ordinal: 2, Address: 0x1e490)
- StiCreateInstanceA (Ordinal: 3, Address: 0x51750)
- CleanupIS (Ordinal: 4, Address: 0x2c4b0)
Imported DLLs & Functions
ADVAPI32.dll
- CloseServiceHandle (Address: 0x79668030)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x79668008)
- DeregisterEventSource (Address: 0x79668020)
- EventWriteTransfer (Address: 0x79668004)
- GetNamedSecurityInfoW (Address: 0x79668000)
- LookupPrivilegeValueW (Address: 0x79668028)
- LsaFreeMemory (Address: 0x79668050)
- LsaOpenPolicy (Address: 0x79668048)
- LsaQueryInformationPolicy (Address: 0x7966804c)
- OpenProcessToken (Address: 0x79668024)
- OpenSCManagerW (Address: 0x79668034)
- OpenServiceW (Address: 0x7966803c)
- QueryServiceStatus (Address: 0x79668054)
- RegDeleteKeyA (Address: 0x79668014)
- RegEnumKeyW (Address: 0x79668010)
- RegisterEventSourceW (Address: 0x79668018)
- RegOpenKeyA (Address: 0x79668058)
- ReportEventW (Address: 0x7966801c)
- SetEntriesInAclW (Address: 0x79668044)
- SetNamedSecurityInfoW (Address: 0x7966800c)
- StartServiceCtrlDispatcherA (Address: 0x7966802c)
- StartServiceCtrlDispatcherW (Address: 0x79668040)
- StartServiceW (Address: 0x79668038)
api-ms-win-core-apiquery-l1-1-0.dll
- ApiSetQueryApiSetPresence (Address: 0x796684d8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x79668500)
- RegCreateKeyExA (Address: 0x79668518)
- RegCreateKeyExW (Address: 0x796684fc)
- RegDeleteValueA (Address: 0x796684e4)
- RegDeleteValueW (Address: 0x79668504)
- RegEnumKeyExW (Address: 0x796684f8)
- RegEnumValueW (Address: 0x79668514)
- RegGetValueW (Address: 0x796684f0)
- RegOpenKeyExA (Address: 0x796684e0)
- RegOpenKeyExW (Address: 0x79668508)
- RegQueryInfoKeyW (Address: 0x796684f4)
- RegQueryValueExA (Address: 0x79668510)
- RegQueryValueExW (Address: 0x796684ec)
- RegSetValueExA (Address: 0x796684e8)
- RegSetValueExW (Address: 0x7966850c)
api-ms-win-mm-time-l1-1-0.dll
- timeGetTime (Address: 0x79668520)
api-ms-win-security-base-l1-1-0.dll
- AccessCheck (Address: 0x79668530)
- AdjustTokenPrivileges (Address: 0x79668540)
- AllocateAndInitializeSid (Address: 0x79668534)
- CheckTokenMembership (Address: 0x79668538)
- CreateWellKnownSid (Address: 0x79668528)
- FreeSid (Address: 0x79668544)
- GetSecurityDescriptorDacl (Address: 0x7966852c)
- GetTokenInformation (Address: 0x7966854c)
- InitializeSecurityDescriptor (Address: 0x79668548)
- SetTokenInformation (Address: 0x7966853c)
apphelp.dll
- SE_CALLBACK_AddHook (Address: 0x79668554)
- SE_CALLBACK_Lookup (Address: 0x79668558)
- SE_COM_AddHook (Address: 0x7966855c)
- SE_COM_AddServer (Address: 0x79668560)
- SE_COM_HookInterface (Address: 0x7966856c)
- SE_COM_HookObject (Address: 0x79668564)
- SE_COM_Lookup (Address: 0x79668568)
- SE_GetShimId (Address: 0x79668574)
- SE_ShimDPF (Address: 0x79668570)
COMCTL32.dll
- (Address: 0x79668064)
- (Address: 0x79668068)
- (Address: 0x7966806c)
- (Address: 0x79668074)
- (Address: 0x79668078)
- (Address: 0x7966807c)
- (Address: 0x79668090)
- (Address: 0x79668094)
- ImageList_Add (Address: 0x79668084)
- ImageList_Create (Address: 0x79668070)
- ImageList_Destroy (Address: 0x79668060)
- ImageList_Remove (Address: 0x79668080)
- ImageList_Replace (Address: 0x7966808c)
- ImageList_ReplaceIcon (Address: 0x79668088)
COMDLG32.dll
- GetFileTitleA (Address: 0x7966809c)
DDRAW.dll
- DirectDrawCreate (Address: 0x796680a4)
dwmapi.dll
- DwmIsCompositionEnabled (Address: 0x7966857c)
GDI32.dll
- BitBlt (Address: 0x796680cc)
- CreateCompatibleBitmap (Address: 0x796680e4)
- CreateCompatibleDC (Address: 0x796680ec)
- CreateDIBSection (Address: 0x796680ac)
- CreatePalette (Address: 0x796680e0)
- DeleteDC (Address: 0x796680c4)
- DeleteObject (Address: 0x796680c8)
- GdiIsScreenDC (Address: 0x796680dc)
- GetStockObject (Address: 0x796680e8)
- GetSystemPaletteEntries (Address: 0x796680c0)
- RealizePalette (Address: 0x796680b4)
- SelectObject (Address: 0x796680d0)
- SelectPalette (Address: 0x796680b8)
- SetMapMode (Address: 0x796680d8)
- SetSystemPaletteUse (Address: 0x796680b0)
- SetViewportExtEx (Address: 0x796680bc)
- SetWindowExtEx (Address: 0x796680d4)
IMM32.dll
- ImmGetContext (Address: 0x796680f4)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x796681dc)
- CloseHandle (Address: 0x796682f0)
- CompareStringA (Address: 0x79668248)
- CompareStringW (Address: 0x79668188)
- CopyFileW (Address: 0x796682e4)
- CreateDirectoryW (Address: 0x796682e8)
- CreateEventW (Address: 0x79668144)
- CreateFileA (Address: 0x79668278)
- CreateFileMappingA (Address: 0x7966819c)
- CreateFileW (Address: 0x796681a8)
- CreateProcessA (Address: 0x7966829c)
- CreateProcessW (Address: 0x796682f4)
- CreateThread (Address: 0x796681f8)
- DeleteCriticalSection (Address: 0x79668218)
- DeleteFileA (Address: 0x7966817c)
- DeleteFileW (Address: 0x79668238)
- EnterCriticalSection (Address: 0x79668264)
- ExitProcess (Address: 0x79668298)
- ExpandEnvironmentStringsA (Address: 0x7966824c)
- ExpandEnvironmentStringsW (Address: 0x79668118)
- FindClose (Address: 0x796682f8)
- FindFirstFileW (Address: 0x79668304)
- FindNextFileW (Address: 0x796682fc)
- FindResourceW (Address: 0x79668258)
- FlushViewOfFile (Address: 0x79668194)
- FreeLibrary (Address: 0x79668294)
- GetACP (Address: 0x7966813c)
- GetCommandLineA (Address: 0x79668288)
- GetCommandLineW (Address: 0x796682b0)
- GetCurrentDirectoryW (Address: 0x79668174)
- GetCurrentProcess (Address: 0x796682d8)
- GetCurrentProcessId (Address: 0x79668234)
- GetCurrentThread (Address: 0x79668158)
- GetCurrentThreadId (Address: 0x7966822c)
- GetEnvironmentVariableW (Address: 0x7966820c)
- GetExitCodeProcess (Address: 0x796681b8)
- GetFileAttributesA (Address: 0x79668180)
- GetFileAttributesW (Address: 0x796681b4)
- GetFullPathNameW (Address: 0x796681c8)
- GetLastError (Address: 0x79668300)
- GetLocaleInfoW (Address: 0x796681cc)
- GetLocalTime (Address: 0x79668124)
- GetLongPathNameW (Address: 0x796681c4)
- GetModuleFileNameA (Address: 0x796682ac)
- GetModuleFileNameW (Address: 0x7966826c)
- GetModuleHandleA (Address: 0x79668110)
- GetModuleHandleExW (Address: 0x79668228)
- GetModuleHandleW (Address: 0x796682d0)
- GetOverlappedResultEx (Address: 0x79668104)
- GetProcAddress (Address: 0x796682a0)
- GetProcessHeap (Address: 0x79668280)
- GetShortPathNameW (Address: 0x796681c0)
- GetSystemDefaultUILanguage (Address: 0x796682c0)
- GetSystemDirectoryA (Address: 0x79668290)
- GetSystemDirectoryW (Address: 0x796682a8)
- GetSystemTimeAsFileTime (Address: 0x796681ec)
- GetSystemWindowsDirectoryA (Address: 0x79668168)
- GetSystemWindowsDirectoryW (Address: 0x7966814c)
- GetTempFileNameA (Address: 0x796681a0)
- GetTempPathA (Address: 0x796681a4)
- GetTickCount (Address: 0x796681f0)
- GetVersion (Address: 0x79668108)
- GetVersionExW (Address: 0x79668120)
- GetWindowsDirectoryA (Address: 0x796681b0)
- GetWindowsDirectoryW (Address: 0x79668150)
- GlobalFree (Address: 0x79668170)
- HeapAlloc (Address: 0x79668284)
- HeapCreate (Address: 0x79668220)
- HeapFree (Address: 0x7966827c)
- HeapReAlloc (Address: 0x79668224)
- InitializeCriticalSection (Address: 0x7966821c)
- InitializeCriticalSectionAndSpinCount (Address: 0x7966825c)
- IsBadReadPtr (Address: 0x79668270)
- IsBadStringPtrA (Address: 0x796682cc)
- IsBadStringPtrW (Address: 0x796682c8)
- IsWow64Process (Address: 0x796682dc)
- K32EnumProcesses (Address: 0x79668200)
- K32GetModuleBaseNameW (Address: 0x79668134)
- K32GetModuleFileNameExW (Address: 0x7966823c)
- K32GetModuleInformation (Address: 0x79668154)
- K32GetProcessImageFileNameW (Address: 0x79668204)
- LeaveCriticalSection (Address: 0x79668260)
- LoadLibraryA (Address: 0x7966828c)
- LoadLibraryW (Address: 0x796682a4)
- LoadResource (Address: 0x79668254)
- LocalAlloc (Address: 0x79668210)
- LocalFree (Address: 0x796682e0)
- LockResource (Address: 0x79668250)
- lstrcmpA (Address: 0x7966812c)
- lstrcmpiW (Address: 0x7966816c)
- lstrcmpW (Address: 0x7966811c)
- lstrlenA (Address: 0x79668164)
- lstrlenW (Address: 0x79668214)
- MapViewOfFile (Address: 0x79668198)
- MoveFileExW (Address: 0x79668178)
- MoveFileW (Address: 0x79668244)
- MultiByteToWideChar (Address: 0x79668274)
- OpenFileMappingA (Address: 0x79668190)
- OpenMutexW (Address: 0x79668114)
- OpenProcess (Address: 0x79668240)
- ProcessIdToSessionId (Address: 0x79668148)
- QueryDosDeviceW (Address: 0x796680fc)
- QueryPerformanceCounter (Address: 0x796681e8)
- ReleaseMutex (Address: 0x79668130)
- ReleaseSRWLockExclusive (Address: 0x796681d8)
- ResetEvent (Address: 0x796681f4)
- SearchPathW (Address: 0x796681bc)
- SetCurrentDirectoryW (Address: 0x79668268)
- SetEnvironmentVariableW (Address: 0x79668208)
- SetEvent (Address: 0x7966810c)
- SetFileAttributesW (Address: 0x79668140)
- SetLastError (Address: 0x796681ac)
- SetLocaleInfoA (Address: 0x79668128)
- SetThreadContext (Address: 0x79668230)
- SetUnhandledExceptionFilter (Address: 0x79668184)
- Sleep (Address: 0x796681fc)
- SleepConditionVariableSRW (Address: 0x796681e4)
- SwitchToThread (Address: 0x7966815c)
- TerminateProcess (Address: 0x796681d4)
- TlsAlloc (Address: 0x796682b8)
- TlsFree (Address: 0x796682b4)
- TlsGetValue (Address: 0x796682c4)
- TlsSetValue (Address: 0x796682bc)
- TrySubmitThreadpoolCallback (Address: 0x79668160)
- UnhandledExceptionFilter (Address: 0x796681d0)
- UnmapViewOfFile (Address: 0x7966818c)
- VirtualAlloc (Address: 0x79668100)
- VirtualProtect (Address: 0x796682d4)
- WaitForSingleObject (Address: 0x796682ec)
- WakeAllConditionVariable (Address: 0x796681e0)
- WideCharToMultiByte (Address: 0x79668138)
MPR.dll
- WNetConnectionDialog (Address: 0x79668310)
- WNetGetConnectionW (Address: 0x7966830c)
mscms.dll
- GetCountColorProfileElements (Address: 0x79668584)
msi.dll
- (Address: 0x7966858c)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x79668594)
- __dllonexit (Address: 0x7966862c)
- _amsg_exit (Address: 0x7966864c)
- _CxxThrowException (Address: 0x79668600)
- _except_handler4_common (Address: 0x79668624)
- _initterm (Address: 0x79668640)
- _itow_s (Address: 0x79668608)
- _lock (Address: 0x79668634)
- _onexit (Address: 0x79668628)
- _stricmp (Address: 0x796685a0)
- _strlwr (Address: 0x796685b0)
- _strnicmp (Address: 0x796685d0)
- _unlock (Address: 0x79668630)
- _vscprintf (Address: 0x79668620)
- _vscwprintf (Address: 0x7966861c)
- _vsnprintf (Address: 0x796685b4)
- _vsnwprintf (Address: 0x796685e8)
- _wcsicmp (Address: 0x79668598)
- _wcslwr (Address: 0x79668618)
- _wcsnicmp (Address: 0x7966859c)
- _wcsupr (Address: 0x79668614)
- _wsplitpath_s (Address: 0x79668654)
- _wtoi (Address: 0x796685bc)
- _wtol (Address: 0x796685a8)
- _XcptFilter (Address: 0x79668650)
- ??1type_info@@UAE@XZ (Address: 0x79668638)
- ?terminate@@YAXXZ (Address: 0x7966863c)
- free (Address: 0x79668648)
- isalpha (Address: 0x796685d8)
- iswctype (Address: 0x796685f0)
- iswspace (Address: 0x79668658)
- malloc (Address: 0x79668644)
- memcmp (Address: 0x796685c4)
- memcpy (Address: 0x796685c0)
- memmove (Address: 0x79668604)
- memset (Address: 0x7966865c)
- strcat_s (Address: 0x796685cc)
- strcpy_s (Address: 0x796685d4)
- strncmp (Address: 0x796685a4)
- strrchr (Address: 0x796685b8)
- strstr (Address: 0x796685ac)
- towlower (Address: 0x796685f4)
- towupper (Address: 0x796685f8)
- wcscat_s (Address: 0x796685e4)
- wcschr (Address: 0x7966860c)
- wcsncmp (Address: 0x796685fc)
- wcspbrk (Address: 0x79668610)
- wcsrchr (Address: 0x796685c8)
- wcsspn (Address: 0x796685ec)
- wcsstr (Address: 0x796685dc)
- wcstol (Address: 0x796685e0)
ntdll.dll
- LdrEnumerateLoadedModules (Address: 0x79668698)
- LdrFindEntryForAddress (Address: 0x79668668)
- NtClose (Address: 0x79668694)
- NtCreateKey (Address: 0x796686ac)
- NtDeleteKey (Address: 0x796686b0)
- NtEnumerateKey (Address: 0x796686b4)
- NtOpenKey (Address: 0x796686bc)
- NtProtectVirtualMemory (Address: 0x79668684)
- NtQueryInformationFile (Address: 0x7966869c)
- NtQueryInformationThread (Address: 0x79668690)
- NtQueryObject (Address: 0x796686a0)
- NtQueryValueKey (Address: 0x796686b8)
- NtSetValueKey (Address: 0x796686a4)
- RtlAllocateHeap (Address: 0x796686a8)
- RtlCreateUnicodeStringFromAsciiz (Address: 0x79668688)
- RtlFormatCurrentUserKeyPath (Address: 0x796686c0)
- RtlFreeHeap (Address: 0x79668664)
- RtlFreeUnicodeString (Address: 0x7966868c)
- RtlGetDaclSecurityDescriptor (Address: 0x7966867c)
- RtlGetNtSystemRoot (Address: 0x79668680)
- RtlGUIDFromString (Address: 0x79668670)
- RtlInitUnicodeString (Address: 0x7966866c)
- RtlSubAuthorityCountSid (Address: 0x79668674)
- RtlSubAuthoritySid (Address: 0x79668678)
ole32.dll
- CoCreateInstance (Address: 0x796686c8)
- CoGetObjectContext (Address: 0x796686d8)
- CoInitialize (Address: 0x796686dc)
- CoTaskMemAlloc (Address: 0x796686e0)
- CoTaskMemFree (Address: 0x796686cc)
- CoUninitialize (Address: 0x796686d4)
- StringFromCLSID (Address: 0x796686d0)
OLEAUT32.dll
- VariantInit (Address: 0x79668318)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x79668344)
- NdrAsyncClientCall (Address: 0x79668320)
- RpcAsyncCancelCall (Address: 0x79668328)
- RpcAsyncCompleteCall (Address: 0x79668334)
- RpcAsyncInitializeHandle (Address: 0x79668338)
- RpcBindingFree (Address: 0x79668324)
- RpcBindingFromStringBindingW (Address: 0x7966833c)
- RpcBindingSetAuthInfoExW (Address: 0x79668330)
- RpcStringBindingComposeW (Address: 0x79668340)
- RpcStringFreeW (Address: 0x7966832c)
SHELL32.dll
- (Address: 0x79668350)
- (Address: 0x79668354)
- CommandLineToArgvW (Address: 0x7966834c)
- SHChangeNotify (Address: 0x79668358)
- ShellExecuteExW (Address: 0x79668360)
- SHGetFolderPathA (Address: 0x7966835c)
- SHGetFolderPathW (Address: 0x79668364)
- SHGetSpecialFolderPathW (Address: 0x79668368)
SHLWAPI.dll
- StrCmpIW (Address: 0x79668374)
- StrStrW (Address: 0x79668370)
SspiCli.dll
- GetUserNameExW (Address: 0x7966837c)
USER32.dll
- AllowSetForegroundWindow (Address: 0x79668444)
- BeginPaint (Address: 0x79668394)
- CallNextHookEx (Address: 0x796683bc)
- CallWindowProcA (Address: 0x7966844c)
- ChangeDisplaySettingsA (Address: 0x79668490)
- CopyIcon (Address: 0x79668470)
- CreateWindowExA (Address: 0x79668408)
- DefWindowProcA (Address: 0x79668478)
- DefWindowProcW (Address: 0x79668410)
- DestroyWindow (Address: 0x796683d0)
- DispatchMessageA (Address: 0x79668488)
- DispatchMessageW (Address: 0x79668400)
- EnableWindow (Address: 0x79668438)
- EndPaint (Address: 0x79668390)
- EnumChildWindows (Address: 0x79668474)
- EnumDisplaySettingsW (Address: 0x7966845c)
- EnumWindows (Address: 0x7966849c)
- FillRect (Address: 0x796683a0)
- FindWindowA (Address: 0x79668480)
- FindWindowExA (Address: 0x796683d8)
- FindWindowW (Address: 0x796683fc)
- GetAncestor (Address: 0x79668434)
- GetClassInfoA (Address: 0x796683e4)
- GetClassLongA (Address: 0x79668404)
- GetClassNameA (Address: 0x7966838c)
- GetClassNameW (Address: 0x79668494)
- GetClientRect (Address: 0x796683a4)
- GetCursorPos (Address: 0x79668484)
- GetDC (Address: 0x7966839c)
- GetDesktopWindow (Address: 0x796683ec)
- GetGUIThreadInfo (Address: 0x79668388)
- GetMonitorInfoW (Address: 0x7966841c)
- GetParent (Address: 0x796683f0)
- GetProcessWindowStation (Address: 0x79668430)
- GetPropW (Address: 0x79668468)
- GetSystemMetrics (Address: 0x79668454)
- GetThreadDesktop (Address: 0x79668418)
- GetUpdateRect (Address: 0x79668384)
- GetUserObjectInformationW (Address: 0x79668428)
- GetWindowInfo (Address: 0x796684a0)
- GetWindowLongA (Address: 0x796683e8)
- GetWindowLongW (Address: 0x796683e0)
- GetWindowRect (Address: 0x796683f8)
- GetWindowTextW (Address: 0x796683d4)
- GetWindowThreadProcessId (Address: 0x796683cc)
- InvalidateRect (Address: 0x796683dc)
- IsZoomed (Address: 0x79668458)
- LoadCursorW (Address: 0x7966846c)
- mouse_event (Address: 0x796683ac)
- MsgWaitForMultipleObjects (Address: 0x79668414)
- PeekMessageW (Address: 0x796683c0)
- PostMessageA (Address: 0x7966848c)
- PostQuitMessage (Address: 0x7966842c)
- RegisterClassA (Address: 0x79668498)
- RegisterWindowMessageW (Address: 0x7966847c)
- ReleaseDC (Address: 0x79668398)
- RemovePropW (Address: 0x79668464)
- SendMessageTimeoutW (Address: 0x79668448)
- SendMessageW (Address: 0x796683b0)
- SendNotifyMessageW (Address: 0x796683c4)
- SetActiveWindow (Address: 0x79668440)
- SetCursor (Address: 0x79668424)
- SetCursorPos (Address: 0x796683f4)
- SetForegroundWindow (Address: 0x796683a8)
- SetPropW (Address: 0x79668460)
- SetWindowLongA (Address: 0x79668450)
- SetWindowLongW (Address: 0x796683c8)
- SetWindowsHookExW (Address: 0x796683b8)
- ShowCursor (Address: 0x7966843c)
- TranslateMessage (Address: 0x79668420)
- UnhookWindowsHookEx (Address: 0x796683b4)
- ValidateRect (Address: 0x7966840c)
USERENV.dll
- GetAllUsersProfileDirectoryW (Address: 0x796684ac)
- GetUserProfileDirectoryW (Address: 0x796684a8)
WINMM.dll
- mciSendCommandA (Address: 0x796684b4)
WINSPOOL.DRV
- (Address: 0x796684bc)
- (Address: 0x796684c8)
- EnumFormsW (Address: 0x796684c4)
- OpenPrinterW (Address: 0x796684c0)
WS2_32.dll
- WSASetLastError (Address: 0x796684d0)