AcSpecfc.dll

Description: Windows Compatibility DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 32-bit

Operating System: Windows NT

SHA256: c3706d4f86ac7157e76382c255c0aa84

File Size: 451.0 KB

Uploaded At: Dec. 1, 2025, 7:52 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • GetHookAPIs (Ordinal: 1, Address: 0x1dff0)
  • NotifyShims (Ordinal: 2, Address: 0x1e490)
  • StiCreateInstanceA (Ordinal: 3, Address: 0x51750)
  • CleanupIS (Ordinal: 4, Address: 0x2c4b0)

Imported DLLs & Functions

ADVAPI32.dll
  • CloseServiceHandle (Address: 0x79668030)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x79668008)
  • DeregisterEventSource (Address: 0x79668020)
  • EventWriteTransfer (Address: 0x79668004)
  • GetNamedSecurityInfoW (Address: 0x79668000)
  • LookupPrivilegeValueW (Address: 0x79668028)
  • LsaFreeMemory (Address: 0x79668050)
  • LsaOpenPolicy (Address: 0x79668048)
  • LsaQueryInformationPolicy (Address: 0x7966804c)
  • OpenProcessToken (Address: 0x79668024)
  • OpenSCManagerW (Address: 0x79668034)
  • OpenServiceW (Address: 0x7966803c)
  • QueryServiceStatus (Address: 0x79668054)
  • RegDeleteKeyA (Address: 0x79668014)
  • RegEnumKeyW (Address: 0x79668010)
  • RegisterEventSourceW (Address: 0x79668018)
  • RegOpenKeyA (Address: 0x79668058)
  • ReportEventW (Address: 0x7966801c)
  • SetEntriesInAclW (Address: 0x79668044)
  • SetNamedSecurityInfoW (Address: 0x7966800c)
  • StartServiceCtrlDispatcherA (Address: 0x7966802c)
  • StartServiceCtrlDispatcherW (Address: 0x79668040)
  • StartServiceW (Address: 0x79668038)
api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x796684d8)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x79668500)
  • RegCreateKeyExA (Address: 0x79668518)
  • RegCreateKeyExW (Address: 0x796684fc)
  • RegDeleteValueA (Address: 0x796684e4)
  • RegDeleteValueW (Address: 0x79668504)
  • RegEnumKeyExW (Address: 0x796684f8)
  • RegEnumValueW (Address: 0x79668514)
  • RegGetValueW (Address: 0x796684f0)
  • RegOpenKeyExA (Address: 0x796684e0)
  • RegOpenKeyExW (Address: 0x79668508)
  • RegQueryInfoKeyW (Address: 0x796684f4)
  • RegQueryValueExA (Address: 0x79668510)
  • RegQueryValueExW (Address: 0x796684ec)
  • RegSetValueExA (Address: 0x796684e8)
  • RegSetValueExW (Address: 0x7966850c)
api-ms-win-mm-time-l1-1-0.dll
  • timeGetTime (Address: 0x79668520)
api-ms-win-security-base-l1-1-0.dll
  • AccessCheck (Address: 0x79668530)
  • AdjustTokenPrivileges (Address: 0x79668540)
  • AllocateAndInitializeSid (Address: 0x79668534)
  • CheckTokenMembership (Address: 0x79668538)
  • CreateWellKnownSid (Address: 0x79668528)
  • FreeSid (Address: 0x79668544)
  • GetSecurityDescriptorDacl (Address: 0x7966852c)
  • GetTokenInformation (Address: 0x7966854c)
  • InitializeSecurityDescriptor (Address: 0x79668548)
  • SetTokenInformation (Address: 0x7966853c)
apphelp.dll
  • SE_CALLBACK_AddHook (Address: 0x79668554)
  • SE_CALLBACK_Lookup (Address: 0x79668558)
  • SE_COM_AddHook (Address: 0x7966855c)
  • SE_COM_AddServer (Address: 0x79668560)
  • SE_COM_HookInterface (Address: 0x7966856c)
  • SE_COM_HookObject (Address: 0x79668564)
  • SE_COM_Lookup (Address: 0x79668568)
  • SE_GetShimId (Address: 0x79668574)
  • SE_ShimDPF (Address: 0x79668570)
COMCTL32.dll
  • (Address: 0x79668064)
  • (Address: 0x79668068)
  • (Address: 0x7966806c)
  • (Address: 0x79668074)
  • (Address: 0x79668078)
  • (Address: 0x7966807c)
  • (Address: 0x79668090)
  • (Address: 0x79668094)
  • ImageList_Add (Address: 0x79668084)
  • ImageList_Create (Address: 0x79668070)
  • ImageList_Destroy (Address: 0x79668060)
  • ImageList_Remove (Address: 0x79668080)
  • ImageList_Replace (Address: 0x7966808c)
  • ImageList_ReplaceIcon (Address: 0x79668088)
COMDLG32.dll
  • GetFileTitleA (Address: 0x7966809c)
DDRAW.dll
  • DirectDrawCreate (Address: 0x796680a4)
dwmapi.dll
  • DwmIsCompositionEnabled (Address: 0x7966857c)
GDI32.dll
  • BitBlt (Address: 0x796680cc)
  • CreateCompatibleBitmap (Address: 0x796680e4)
  • CreateCompatibleDC (Address: 0x796680ec)
  • CreateDIBSection (Address: 0x796680ac)
  • CreatePalette (Address: 0x796680e0)
  • DeleteDC (Address: 0x796680c4)
  • DeleteObject (Address: 0x796680c8)
  • GdiIsScreenDC (Address: 0x796680dc)
  • GetStockObject (Address: 0x796680e8)
  • GetSystemPaletteEntries (Address: 0x796680c0)
  • RealizePalette (Address: 0x796680b4)
  • SelectObject (Address: 0x796680d0)
  • SelectPalette (Address: 0x796680b8)
  • SetMapMode (Address: 0x796680d8)
  • SetSystemPaletteUse (Address: 0x796680b0)
  • SetViewportExtEx (Address: 0x796680bc)
  • SetWindowExtEx (Address: 0x796680d4)
IMM32.dll
  • ImmGetContext (Address: 0x796680f4)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x796681dc)
  • CloseHandle (Address: 0x796682f0)
  • CompareStringA (Address: 0x79668248)
  • CompareStringW (Address: 0x79668188)
  • CopyFileW (Address: 0x796682e4)
  • CreateDirectoryW (Address: 0x796682e8)
  • CreateEventW (Address: 0x79668144)
  • CreateFileA (Address: 0x79668278)
  • CreateFileMappingA (Address: 0x7966819c)
  • CreateFileW (Address: 0x796681a8)
  • CreateProcessA (Address: 0x7966829c)
  • CreateProcessW (Address: 0x796682f4)
  • CreateThread (Address: 0x796681f8)
  • DeleteCriticalSection (Address: 0x79668218)
  • DeleteFileA (Address: 0x7966817c)
  • DeleteFileW (Address: 0x79668238)
  • EnterCriticalSection (Address: 0x79668264)
  • ExitProcess (Address: 0x79668298)
  • ExpandEnvironmentStringsA (Address: 0x7966824c)
  • ExpandEnvironmentStringsW (Address: 0x79668118)
  • FindClose (Address: 0x796682f8)
  • FindFirstFileW (Address: 0x79668304)
  • FindNextFileW (Address: 0x796682fc)
  • FindResourceW (Address: 0x79668258)
  • FlushViewOfFile (Address: 0x79668194)
  • FreeLibrary (Address: 0x79668294)
  • GetACP (Address: 0x7966813c)
  • GetCommandLineA (Address: 0x79668288)
  • GetCommandLineW (Address: 0x796682b0)
  • GetCurrentDirectoryW (Address: 0x79668174)
  • GetCurrentProcess (Address: 0x796682d8)
  • GetCurrentProcessId (Address: 0x79668234)
  • GetCurrentThread (Address: 0x79668158)
  • GetCurrentThreadId (Address: 0x7966822c)
  • GetEnvironmentVariableW (Address: 0x7966820c)
  • GetExitCodeProcess (Address: 0x796681b8)
  • GetFileAttributesA (Address: 0x79668180)
  • GetFileAttributesW (Address: 0x796681b4)
  • GetFullPathNameW (Address: 0x796681c8)
  • GetLastError (Address: 0x79668300)
  • GetLocaleInfoW (Address: 0x796681cc)
  • GetLocalTime (Address: 0x79668124)
  • GetLongPathNameW (Address: 0x796681c4)
  • GetModuleFileNameA (Address: 0x796682ac)
  • GetModuleFileNameW (Address: 0x7966826c)
  • GetModuleHandleA (Address: 0x79668110)
  • GetModuleHandleExW (Address: 0x79668228)
  • GetModuleHandleW (Address: 0x796682d0)
  • GetOverlappedResultEx (Address: 0x79668104)
  • GetProcAddress (Address: 0x796682a0)
  • GetProcessHeap (Address: 0x79668280)
  • GetShortPathNameW (Address: 0x796681c0)
  • GetSystemDefaultUILanguage (Address: 0x796682c0)
  • GetSystemDirectoryA (Address: 0x79668290)
  • GetSystemDirectoryW (Address: 0x796682a8)
  • GetSystemTimeAsFileTime (Address: 0x796681ec)
  • GetSystemWindowsDirectoryA (Address: 0x79668168)
  • GetSystemWindowsDirectoryW (Address: 0x7966814c)
  • GetTempFileNameA (Address: 0x796681a0)
  • GetTempPathA (Address: 0x796681a4)
  • GetTickCount (Address: 0x796681f0)
  • GetVersion (Address: 0x79668108)
  • GetVersionExW (Address: 0x79668120)
  • GetWindowsDirectoryA (Address: 0x796681b0)
  • GetWindowsDirectoryW (Address: 0x79668150)
  • GlobalFree (Address: 0x79668170)
  • HeapAlloc (Address: 0x79668284)
  • HeapCreate (Address: 0x79668220)
  • HeapFree (Address: 0x7966827c)
  • HeapReAlloc (Address: 0x79668224)
  • InitializeCriticalSection (Address: 0x7966821c)
  • InitializeCriticalSectionAndSpinCount (Address: 0x7966825c)
  • IsBadReadPtr (Address: 0x79668270)
  • IsBadStringPtrA (Address: 0x796682cc)
  • IsBadStringPtrW (Address: 0x796682c8)
  • IsWow64Process (Address: 0x796682dc)
  • K32EnumProcesses (Address: 0x79668200)
  • K32GetModuleBaseNameW (Address: 0x79668134)
  • K32GetModuleFileNameExW (Address: 0x7966823c)
  • K32GetModuleInformation (Address: 0x79668154)
  • K32GetProcessImageFileNameW (Address: 0x79668204)
  • LeaveCriticalSection (Address: 0x79668260)
  • LoadLibraryA (Address: 0x7966828c)
  • LoadLibraryW (Address: 0x796682a4)
  • LoadResource (Address: 0x79668254)
  • LocalAlloc (Address: 0x79668210)
  • LocalFree (Address: 0x796682e0)
  • LockResource (Address: 0x79668250)
  • lstrcmpA (Address: 0x7966812c)
  • lstrcmpiW (Address: 0x7966816c)
  • lstrcmpW (Address: 0x7966811c)
  • lstrlenA (Address: 0x79668164)
  • lstrlenW (Address: 0x79668214)
  • MapViewOfFile (Address: 0x79668198)
  • MoveFileExW (Address: 0x79668178)
  • MoveFileW (Address: 0x79668244)
  • MultiByteToWideChar (Address: 0x79668274)
  • OpenFileMappingA (Address: 0x79668190)
  • OpenMutexW (Address: 0x79668114)
  • OpenProcess (Address: 0x79668240)
  • ProcessIdToSessionId (Address: 0x79668148)
  • QueryDosDeviceW (Address: 0x796680fc)
  • QueryPerformanceCounter (Address: 0x796681e8)
  • ReleaseMutex (Address: 0x79668130)
  • ReleaseSRWLockExclusive (Address: 0x796681d8)
  • ResetEvent (Address: 0x796681f4)
  • SearchPathW (Address: 0x796681bc)
  • SetCurrentDirectoryW (Address: 0x79668268)
  • SetEnvironmentVariableW (Address: 0x79668208)
  • SetEvent (Address: 0x7966810c)
  • SetFileAttributesW (Address: 0x79668140)
  • SetLastError (Address: 0x796681ac)
  • SetLocaleInfoA (Address: 0x79668128)
  • SetThreadContext (Address: 0x79668230)
  • SetUnhandledExceptionFilter (Address: 0x79668184)
  • Sleep (Address: 0x796681fc)
  • SleepConditionVariableSRW (Address: 0x796681e4)
  • SwitchToThread (Address: 0x7966815c)
  • TerminateProcess (Address: 0x796681d4)
  • TlsAlloc (Address: 0x796682b8)
  • TlsFree (Address: 0x796682b4)
  • TlsGetValue (Address: 0x796682c4)
  • TlsSetValue (Address: 0x796682bc)
  • TrySubmitThreadpoolCallback (Address: 0x79668160)
  • UnhandledExceptionFilter (Address: 0x796681d0)
  • UnmapViewOfFile (Address: 0x7966818c)
  • VirtualAlloc (Address: 0x79668100)
  • VirtualProtect (Address: 0x796682d4)
  • WaitForSingleObject (Address: 0x796682ec)
  • WakeAllConditionVariable (Address: 0x796681e0)
  • WideCharToMultiByte (Address: 0x79668138)
MPR.dll
  • WNetConnectionDialog (Address: 0x79668310)
  • WNetGetConnectionW (Address: 0x7966830c)
mscms.dll
  • GetCountColorProfileElements (Address: 0x79668584)
msi.dll
  • (Address: 0x7966858c)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x79668594)
  • __dllonexit (Address: 0x7966862c)
  • _amsg_exit (Address: 0x7966864c)
  • _CxxThrowException (Address: 0x79668600)
  • _except_handler4_common (Address: 0x79668624)
  • _initterm (Address: 0x79668640)
  • _itow_s (Address: 0x79668608)
  • _lock (Address: 0x79668634)
  • _onexit (Address: 0x79668628)
  • _stricmp (Address: 0x796685a0)
  • _strlwr (Address: 0x796685b0)
  • _strnicmp (Address: 0x796685d0)
  • _unlock (Address: 0x79668630)
  • _vscprintf (Address: 0x79668620)
  • _vscwprintf (Address: 0x7966861c)
  • _vsnprintf (Address: 0x796685b4)
  • _vsnwprintf (Address: 0x796685e8)
  • _wcsicmp (Address: 0x79668598)
  • _wcslwr (Address: 0x79668618)
  • _wcsnicmp (Address: 0x7966859c)
  • _wcsupr (Address: 0x79668614)
  • _wsplitpath_s (Address: 0x79668654)
  • _wtoi (Address: 0x796685bc)
  • _wtol (Address: 0x796685a8)
  • _XcptFilter (Address: 0x79668650)
  • ??1type_info@@UAE@XZ (Address: 0x79668638)
  • ?terminate@@YAXXZ (Address: 0x7966863c)
  • free (Address: 0x79668648)
  • isalpha (Address: 0x796685d8)
  • iswctype (Address: 0x796685f0)
  • iswspace (Address: 0x79668658)
  • malloc (Address: 0x79668644)
  • memcmp (Address: 0x796685c4)
  • memcpy (Address: 0x796685c0)
  • memmove (Address: 0x79668604)
  • memset (Address: 0x7966865c)
  • strcat_s (Address: 0x796685cc)
  • strcpy_s (Address: 0x796685d4)
  • strncmp (Address: 0x796685a4)
  • strrchr (Address: 0x796685b8)
  • strstr (Address: 0x796685ac)
  • towlower (Address: 0x796685f4)
  • towupper (Address: 0x796685f8)
  • wcscat_s (Address: 0x796685e4)
  • wcschr (Address: 0x7966860c)
  • wcsncmp (Address: 0x796685fc)
  • wcspbrk (Address: 0x79668610)
  • wcsrchr (Address: 0x796685c8)
  • wcsspn (Address: 0x796685ec)
  • wcsstr (Address: 0x796685dc)
  • wcstol (Address: 0x796685e0)
ntdll.dll
  • LdrEnumerateLoadedModules (Address: 0x79668698)
  • LdrFindEntryForAddress (Address: 0x79668668)
  • NtClose (Address: 0x79668694)
  • NtCreateKey (Address: 0x796686ac)
  • NtDeleteKey (Address: 0x796686b0)
  • NtEnumerateKey (Address: 0x796686b4)
  • NtOpenKey (Address: 0x796686bc)
  • NtProtectVirtualMemory (Address: 0x79668684)
  • NtQueryInformationFile (Address: 0x7966869c)
  • NtQueryInformationThread (Address: 0x79668690)
  • NtQueryObject (Address: 0x796686a0)
  • NtQueryValueKey (Address: 0x796686b8)
  • NtSetValueKey (Address: 0x796686a4)
  • RtlAllocateHeap (Address: 0x796686a8)
  • RtlCreateUnicodeStringFromAsciiz (Address: 0x79668688)
  • RtlFormatCurrentUserKeyPath (Address: 0x796686c0)
  • RtlFreeHeap (Address: 0x79668664)
  • RtlFreeUnicodeString (Address: 0x7966868c)
  • RtlGetDaclSecurityDescriptor (Address: 0x7966867c)
  • RtlGetNtSystemRoot (Address: 0x79668680)
  • RtlGUIDFromString (Address: 0x79668670)
  • RtlInitUnicodeString (Address: 0x7966866c)
  • RtlSubAuthorityCountSid (Address: 0x79668674)
  • RtlSubAuthoritySid (Address: 0x79668678)
ole32.dll
  • CoCreateInstance (Address: 0x796686c8)
  • CoGetObjectContext (Address: 0x796686d8)
  • CoInitialize (Address: 0x796686dc)
  • CoTaskMemAlloc (Address: 0x796686e0)
  • CoTaskMemFree (Address: 0x796686cc)
  • CoUninitialize (Address: 0x796686d4)
  • StringFromCLSID (Address: 0x796686d0)
OLEAUT32.dll
  • VariantInit (Address: 0x79668318)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x79668344)
  • NdrAsyncClientCall (Address: 0x79668320)
  • RpcAsyncCancelCall (Address: 0x79668328)
  • RpcAsyncCompleteCall (Address: 0x79668334)
  • RpcAsyncInitializeHandle (Address: 0x79668338)
  • RpcBindingFree (Address: 0x79668324)
  • RpcBindingFromStringBindingW (Address: 0x7966833c)
  • RpcBindingSetAuthInfoExW (Address: 0x79668330)
  • RpcStringBindingComposeW (Address: 0x79668340)
  • RpcStringFreeW (Address: 0x7966832c)
SHELL32.dll
  • (Address: 0x79668350)
  • (Address: 0x79668354)
  • CommandLineToArgvW (Address: 0x7966834c)
  • SHChangeNotify (Address: 0x79668358)
  • ShellExecuteExW (Address: 0x79668360)
  • SHGetFolderPathA (Address: 0x7966835c)
  • SHGetFolderPathW (Address: 0x79668364)
  • SHGetSpecialFolderPathW (Address: 0x79668368)
SHLWAPI.dll
  • StrCmpIW (Address: 0x79668374)
  • StrStrW (Address: 0x79668370)
SspiCli.dll
  • GetUserNameExW (Address: 0x7966837c)
USER32.dll
  • AllowSetForegroundWindow (Address: 0x79668444)
  • BeginPaint (Address: 0x79668394)
  • CallNextHookEx (Address: 0x796683bc)
  • CallWindowProcA (Address: 0x7966844c)
  • ChangeDisplaySettingsA (Address: 0x79668490)
  • CopyIcon (Address: 0x79668470)
  • CreateWindowExA (Address: 0x79668408)
  • DefWindowProcA (Address: 0x79668478)
  • DefWindowProcW (Address: 0x79668410)
  • DestroyWindow (Address: 0x796683d0)
  • DispatchMessageA (Address: 0x79668488)
  • DispatchMessageW (Address: 0x79668400)
  • EnableWindow (Address: 0x79668438)
  • EndPaint (Address: 0x79668390)
  • EnumChildWindows (Address: 0x79668474)
  • EnumDisplaySettingsW (Address: 0x7966845c)
  • EnumWindows (Address: 0x7966849c)
  • FillRect (Address: 0x796683a0)
  • FindWindowA (Address: 0x79668480)
  • FindWindowExA (Address: 0x796683d8)
  • FindWindowW (Address: 0x796683fc)
  • GetAncestor (Address: 0x79668434)
  • GetClassInfoA (Address: 0x796683e4)
  • GetClassLongA (Address: 0x79668404)
  • GetClassNameA (Address: 0x7966838c)
  • GetClassNameW (Address: 0x79668494)
  • GetClientRect (Address: 0x796683a4)
  • GetCursorPos (Address: 0x79668484)
  • GetDC (Address: 0x7966839c)
  • GetDesktopWindow (Address: 0x796683ec)
  • GetGUIThreadInfo (Address: 0x79668388)
  • GetMonitorInfoW (Address: 0x7966841c)
  • GetParent (Address: 0x796683f0)
  • GetProcessWindowStation (Address: 0x79668430)
  • GetPropW (Address: 0x79668468)
  • GetSystemMetrics (Address: 0x79668454)
  • GetThreadDesktop (Address: 0x79668418)
  • GetUpdateRect (Address: 0x79668384)
  • GetUserObjectInformationW (Address: 0x79668428)
  • GetWindowInfo (Address: 0x796684a0)
  • GetWindowLongA (Address: 0x796683e8)
  • GetWindowLongW (Address: 0x796683e0)
  • GetWindowRect (Address: 0x796683f8)
  • GetWindowTextW (Address: 0x796683d4)
  • GetWindowThreadProcessId (Address: 0x796683cc)
  • InvalidateRect (Address: 0x796683dc)
  • IsZoomed (Address: 0x79668458)
  • LoadCursorW (Address: 0x7966846c)
  • mouse_event (Address: 0x796683ac)
  • MsgWaitForMultipleObjects (Address: 0x79668414)
  • PeekMessageW (Address: 0x796683c0)
  • PostMessageA (Address: 0x7966848c)
  • PostQuitMessage (Address: 0x7966842c)
  • RegisterClassA (Address: 0x79668498)
  • RegisterWindowMessageW (Address: 0x7966847c)
  • ReleaseDC (Address: 0x79668398)
  • RemovePropW (Address: 0x79668464)
  • SendMessageTimeoutW (Address: 0x79668448)
  • SendMessageW (Address: 0x796683b0)
  • SendNotifyMessageW (Address: 0x796683c4)
  • SetActiveWindow (Address: 0x79668440)
  • SetCursor (Address: 0x79668424)
  • SetCursorPos (Address: 0x796683f4)
  • SetForegroundWindow (Address: 0x796683a8)
  • SetPropW (Address: 0x79668460)
  • SetWindowLongA (Address: 0x79668450)
  • SetWindowLongW (Address: 0x796683c8)
  • SetWindowsHookExW (Address: 0x796683b8)
  • ShowCursor (Address: 0x7966843c)
  • TranslateMessage (Address: 0x79668420)
  • UnhookWindowsHookEx (Address: 0x796683b4)
  • ValidateRect (Address: 0x7966840c)
USERENV.dll
  • GetAllUsersProfileDirectoryW (Address: 0x796684ac)
  • GetUserProfileDirectoryW (Address: 0x796684a8)
WINMM.dll
  • mciSendCommandA (Address: 0x796684b4)
WINSPOOL.DRV
  • (Address: 0x796684bc)
  • (Address: 0x796684c8)
  • EnumFormsW (Address: 0x796684c4)
  • OpenPrinterW (Address: 0x796684c0)
WS2_32.dll
  • WSASetLastError (Address: 0x796684d0)