VeilGuard.dll

Description:

Authors:

Version:

Architecture: 32-bit

Operating System:

SHA256: 6eae9f97c9e63b53350a160b87f4ae65

File Size: 682.0 KB

Uploaded At: May 19, 2026, 6:19 p.m.

Views: 22

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • IsLicenseValidated (Ordinal: 1, Address: 0x27d90)
  • SetClientLicense (Ordinal: 2, Address: 0x27a00)
  • SetClientLicenseW (Ordinal: 3, Address: 0x27bf0)
  • _VerifySecure@0 (Ordinal: 4, Address: 0x40750)
  • WaitForClientLicense (Ordinal: 5, Address: 0x27de0)

Imported DLLs & Functions

ADVAPI32.dll
  • CryptAcquireContextW (Address: 0x1008900c)
  • CryptCreateHash (Address: 0x10089010)
  • CryptDestroyHash (Address: 0x10089030)
  • CryptGetHashParam (Address: 0x1008902c)
  • CryptHashData (Address: 0x10089034)
  • CryptReleaseContext (Address: 0x10089038)
  • GetUserNameA (Address: 0x10089028)
  • RegCloseKey (Address: 0x10089008)
  • RegCreateKeyExA (Address: 0x10089018)
  • RegEnumValueW (Address: 0x1008901c)
  • RegOpenKeyExA (Address: 0x10089024)
  • RegOpenKeyExW (Address: 0x1008903c)
  • RegQueryInfoKeyW (Address: 0x10089020)
  • RegQueryValueExA (Address: 0x10089000)
  • RegQueryValueExW (Address: 0x10089004)
  • RegSetValueExA (Address: 0x10089014)
CRYPT32.dll
  • CryptBinaryToStringA (Address: 0x10089044)
  • CryptProtectData (Address: 0x1008904c)
  • CryptUnprotectData (Address: 0x10089048)
GDI32.dll
  • BitBlt (Address: 0x1008905c)
  • CreateCompatibleDC (Address: 0x10089070)
  • CreateFontW (Address: 0x1008906c)
  • CreateSolidBrush (Address: 0x10089064)
  • DeleteDC (Address: 0x10089060)
  • DeleteObject (Address: 0x10089078)
  • SelectObject (Address: 0x10089058)
  • SetBkMode (Address: 0x10089074)
  • SetTextColor (Address: 0x10089054)
  • TextOutW (Address: 0x10089068)
IPHLPAPI.DLL
  • GetAdaptersInfo (Address: 0x10089084)
  • GetExtendedTcpTable (Address: 0x10089088)
  • GetIpForwardTable (Address: 0x10089080)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x100892c4)
  • CheckRemoteDebuggerPresent (Address: 0x10089224)
  • CloseHandle (Address: 0x100892b4)
  • CompareStringEx (Address: 0x100892fc)
  • CompareStringW (Address: 0x100891a0)
  • CreateDirectoryA (Address: 0x100890a4)
  • CreateDirectoryW (Address: 0x100890c4)
  • CreateEventA (Address: 0x100890dc)
  • CreateFileA (Address: 0x100890bc)
  • CreateFileW (Address: 0x1008909c)
  • CreateMutexW (Address: 0x1008910c)
  • CreatePipe (Address: 0x100890f8)
  • CreateProcessA (Address: 0x100890f0)
  • CreateProcessW (Address: 0x100890d8)
  • CreateThread (Address: 0x100891e4)
  • CreateToolhelp32Snapshot (Address: 0x100892b0)
  • DecodePointer (Address: 0x100892e8)
  • DeleteCriticalSection (Address: 0x100892f4)
  • DeleteFileA (Address: 0x100891d4)
  • DeleteFileW (Address: 0x10089260)
  • DisableThreadLibraryCalls (Address: 0x100890e0)
  • EncodePointer (Address: 0x100892e4)
  • EnterCriticalSection (Address: 0x100892ec)
  • EnumSystemLocalesW (Address: 0x1008918c)
  • ExitProcess (Address: 0x1008926c)
  • ExitThread (Address: 0x10089258)
  • ExpandEnvironmentStringsA (Address: 0x100890b8)
  • FindClose (Address: 0x10089090)
  • FindFirstFileA (Address: 0x100891d8)
  • FindFirstFileExW (Address: 0x10089184)
  • FindFirstFileW (Address: 0x10089100)
  • FindNextFileA (Address: 0x10089164)
  • FindNextFileW (Address: 0x10089104)
  • FlsAlloc (Address: 0x100891b8)
  • FlsFree (Address: 0x100891ac)
  • FlsGetValue (Address: 0x100891b4)
  • FlsSetValue (Address: 0x100891b0)
  • FlushFileBuffers (Address: 0x10089244)
  • FlushInstructionCache (Address: 0x10089148)
  • FreeEnvironmentStringsW (Address: 0x10089168)
  • FreeLibrary (Address: 0x10089270)
  • FreeLibraryAndExitThread (Address: 0x10089254)
  • GetACP (Address: 0x1008917c)
  • GetCommandLineA (Address: 0x10089174)
  • GetCommandLineW (Address: 0x10089170)
  • GetConsoleMode (Address: 0x100891c8)
  • GetConsoleOutputCP (Address: 0x100891cc)
  • GetCPInfo (Address: 0x10089300)
  • GetCurrentDirectoryW (Address: 0x100890d4)
  • GetCurrentProcess (Address: 0x10089220)
  • GetCurrentProcessId (Address: 0x1008920c)
  • GetCurrentThreadId (Address: 0x10089130)
  • GetDateFormatW (Address: 0x100891a8)
  • GetDriveTypeA (Address: 0x100890b0)
  • GetEnvironmentStringsW (Address: 0x1008916c)
  • GetExitCodeProcess (Address: 0x100890e8)
  • GetExitCodeThread (Address: 0x100892d8)
  • GetFileAttributesA (Address: 0x100890b4)
  • GetFileAttributesExW (Address: 0x100890c8)
  • GetFileAttributesW (Address: 0x100891dc)
  • GetFileSizeEx (Address: 0x100891c0)
  • GetFileType (Address: 0x10089248)
  • GetLastError (Address: 0x10089110)
  • GetLocaleInfoEx (Address: 0x100892dc)
  • GetLocaleInfoW (Address: 0x10089198)
  • GetLocalTime (Address: 0x100890d0)
  • GetLogicalDrives (Address: 0x100890ac)
  • GetModuleFileNameA (Address: 0x10089114)
  • GetModuleFileNameW (Address: 0x10089264)
  • GetModuleHandleA (Address: 0x10089214)
  • GetModuleHandleExA (Address: 0x10089200)
  • GetModuleHandleExW (Address: 0x10089250)
  • GetModuleHandleW (Address: 0x10089118)
  • GetOEMCP (Address: 0x10089178)
  • GetProcAddress (Address: 0x10089210)
  • GetProcessHeap (Address: 0x1008922c)
  • GetStartupInfoW (Address: 0x1008929c)
  • GetStdHandle (Address: 0x1008924c)
  • GetStringTypeW (Address: 0x100892d0)
  • GetSystemTimeAsFileTime (Address: 0x100890cc)
  • GetThreadContext (Address: 0x10089144)
  • GetTimeFormatW (Address: 0x100891a4)
  • GetTimeZoneInformation (Address: 0x10089188)
  • GetUserDefaultLCID (Address: 0x10089190)
  • GetVolumeInformationA (Address: 0x1008911c)
  • HeapAlloc (Address: 0x10089140)
  • HeapCreate (Address: 0x10089124)
  • HeapFree (Address: 0x1008912c)
  • HeapReAlloc (Address: 0x1008913c)
  • HeapSize (Address: 0x1008915c)
  • InitializeCriticalSectionAndSpinCount (Address: 0x10089284)
  • InitializeCriticalSectionEx (Address: 0x100892e0)
  • InitializeSListHead (Address: 0x10089298)
  • InterlockedFlushSList (Address: 0x1008928c)
  • IsDebuggerPresent (Address: 0x10089230)
  • IsProcessorFeaturePresent (Address: 0x100892a0)
  • IsValidCodePage (Address: 0x10089180)
  • IsValidLocale (Address: 0x10089194)
  • LCMapStringEx (Address: 0x100892f8)
  • LCMapStringW (Address: 0x1008919c)
  • LeaveCriticalSection (Address: 0x100892f0)
  • LoadLibraryA (Address: 0x100891e0)
  • LoadLibraryExW (Address: 0x1008925c)
  • LocalFree (Address: 0x10089098)
  • Module32FirstW (Address: 0x100891f4)
  • Module32NextW (Address: 0x100891f0)
  • MoveFileExW (Address: 0x100891f8)
  • MultiByteToWideChar (Address: 0x100891e8)
  • OpenMutexA (Address: 0x100890a8)
  • OpenProcess (Address: 0x10089228)
  • OpenThread (Address: 0x10089204)
  • OutputDebugStringA (Address: 0x100891d0)
  • OutputDebugStringW (Address: 0x10089120)
  • Process32FirstW (Address: 0x1008923c)
  • Process32NextW (Address: 0x10089234)
  • QueryFullProcessImageNameA (Address: 0x100892b8)
  • QueryFullProcessImageNameW (Address: 0x100890fc)
  • QueryPerformanceCounter (Address: 0x10089218)
  • QueryPerformanceFrequency (Address: 0x1008921c)
  • RaiseException (Address: 0x10089290)
  • ReadConsoleW (Address: 0x100891bc)
  • ReadDirectoryChangesW (Address: 0x100890c0)
  • ReadFile (Address: 0x100890a0)
  • ReleaseSRWLockExclusive (Address: 0x100892c0)
  • RemoveDirectoryW (Address: 0x10089108)
  • ResumeThread (Address: 0x10089138)
  • RtlUnwind (Address: 0x10089294)
  • SetEndOfFile (Address: 0x10089304)
  • SetEnvironmentVariableW (Address: 0x100892bc)
  • SetEvent (Address: 0x100890e4)
  • SetFileAttributesA (Address: 0x10089094)
  • SetFilePointerEx (Address: 0x100891c4)
  • SetLastError (Address: 0x10089288)
  • SetStdHandle (Address: 0x10089160)
  • SetThreadContext (Address: 0x1008914c)
  • SetUnhandledExceptionFilter (Address: 0x100892a4)
  • Sleep (Address: 0x100891ec)
  • SleepConditionVariableSRW (Address: 0x100892cc)
  • SuspendThread (Address: 0x10089134)
  • TerminateProcess (Address: 0x100890ec)
  • Thread32First (Address: 0x10089208)
  • Thread32Next (Address: 0x10089268)
  • TlsAlloc (Address: 0x10089280)
  • TlsFree (Address: 0x10089274)
  • TlsGetValue (Address: 0x1008927c)
  • TlsSetValue (Address: 0x10089278)
  • TryAcquireSRWLockExclusive (Address: 0x100892c8)
  • UnhandledExceptionFilter (Address: 0x100892a8)
  • VirtualAlloc (Address: 0x10089154)
  • VirtualFree (Address: 0x10089150)
  • VirtualProtect (Address: 0x10089128)
  • VirtualQuery (Address: 0x100891fc)
  • WaitForSingleObject (Address: 0x100890f4)
  • WaitForSingleObjectEx (Address: 0x100892d4)
  • WakeAllConditionVariable (Address: 0x100892ac)
  • WideCharToMultiByte (Address: 0x10089238)
  • WriteConsoleW (Address: 0x10089158)
  • WriteFile (Address: 0x10089240)
SHELL32.dll
  • ShellExecuteW (Address: 0x10089310)
  • SHGetFolderPathA (Address: 0x1008930c)
  • SHGetFolderPathW (Address: 0x10089314)
SHLWAPI.dll
  • PathFileExistsW (Address: 0x1008931c)
  • PathRemoveFileSpecW (Address: 0x10089320)
urlmon.dll
  • URLDownloadToFileW (Address: 0x100893e8)
USER32.dll
  • AttachThreadInput (Address: 0x1008934c)
  • BeginPaint (Address: 0x10089368)
  • CreateWindowExW (Address: 0x10089380)
  • DefWindowProcW (Address: 0x10089390)
  • DestroyWindow (Address: 0x10089398)
  • DispatchMessageW (Address: 0x10089370)
  • EndPaint (Address: 0x1008939c)
  • EnumWindows (Address: 0x10089334)
  • FillRect (Address: 0x10089378)
  • FindWindowW (Address: 0x10089340)
  • GetForegroundWindow (Address: 0x10089348)
  • GetMessageW (Address: 0x1008938c)
  • GetSystemMetrics (Address: 0x10089384)
  • GetWindowTextA (Address: 0x10089330)
  • GetWindowTextW (Address: 0x1008933c)
  • GetWindowThreadProcessId (Address: 0x1008932c)
  • InvalidateRect (Address: 0x10089360)
  • LoadCursorW (Address: 0x10089328)
  • LoadImageW (Address: 0x1008936c)
  • MessageBoxW (Address: 0x10089338)
  • PostMessageW (Address: 0x1008937c)
  • PostQuitMessage (Address: 0x10089394)
  • RegisterClassW (Address: 0x10089388)
  • SetActiveWindow (Address: 0x10089354)
  • SetFocus (Address: 0x10089358)
  • SetForegroundWindow (Address: 0x10089350)
  • SetWindowPos (Address: 0x1008935c)
  • ShowWindow (Address: 0x10089344)
  • TranslateMessage (Address: 0x10089374)
  • UpdateWindow (Address: 0x10089364)
WINHTTP.dll
  • WinHttpCloseHandle (Address: 0x100893b8)
  • WinHttpConnect (Address: 0x100893a8)
  • WinHttpOpen (Address: 0x100893bc)
  • WinHttpOpenRequest (Address: 0x100893c0)
  • WinHttpQueryDataAvailable (Address: 0x100893b0)
  • WinHttpReadData (Address: 0x100893ac)
  • WinHttpReceiveResponse (Address: 0x100893b4)
  • WinHttpSendRequest (Address: 0x100893a4)
WININET.dll
  • InternetCloseHandle (Address: 0x100893c8)
  • InternetOpenA (Address: 0x100893cc)
  • InternetOpenUrlA (Address: 0x100893d0)
  • InternetReadFile (Address: 0x100893d4)
WS2_32.dll
  • inet_pton (Address: 0x100893e0)
  • ntohs (Address: 0x100893dc)