ersc.dll

Description:

Authors:

Version:

Architecture: 64-bit

Operating System:

SHA256: b67b3daf20cb9552899972cd882d309e

File Size: 2.1 MB

Uploaded At: Feb. 3, 2026, 10:17 p.m.

Views: 12

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • modengine_ext_init (Ordinal: 1, Address: 0x2a50)

Imported DLLs & Functions

ADVAPI32.dll
  • BuildExplicitAccessWithNameW (Address: 0x1801ea210)
  • BuildSecurityDescriptorW (Address: 0x1801ea218)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1801ea220)
  • CryptAcquireContextA (Address: 0x1801ea228)
  • CryptCreateHash (Address: 0x1801ea230)
  • CryptDestroyHash (Address: 0x1801ea238)
  • CryptDestroyKey (Address: 0x1801ea240)
  • CryptEncrypt (Address: 0x1801ea248)
  • CryptGenRandom (Address: 0x1801ea250)
  • CryptGetHashParam (Address: 0x1801ea258)
  • CryptHashData (Address: 0x1801ea260)
  • CryptImportKey (Address: 0x1801ea268)
  • CryptReleaseContext (Address: 0x1801ea270)
  • SystemFunction036 (Address: 0x1801ea278)
CRYPT32.dll
  • CertAddCertificateContextToStore (Address: 0x1801ea288)
  • CertCloseStore (Address: 0x1801ea290)
  • CertCreateCertificateChainEngine (Address: 0x1801ea298)
  • CertEnumCertificatesInStore (Address: 0x1801ea2a0)
  • CertFindCertificateInStore (Address: 0x1801ea2a8)
  • CertFindExtension (Address: 0x1801ea2b0)
  • CertFreeCertificateChain (Address: 0x1801ea2b8)
  • CertFreeCertificateChainEngine (Address: 0x1801ea2c0)
  • CertFreeCertificateContext (Address: 0x1801ea2c8)
  • CertGetCertificateChain (Address: 0x1801ea2d0)
  • CertGetNameStringA (Address: 0x1801ea2d8)
  • CertOpenStore (Address: 0x1801ea2e0)
  • CryptDecodeObjectEx (Address: 0x1801ea2e8)
  • CryptQueryObject (Address: 0x1801ea2f0)
  • CryptStringToBinaryA (Address: 0x1801ea2f8)
  • PFXImportCertStore (Address: 0x1801ea300)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1801e9b38)
  • AreFileApisANSI (Address: 0x1801e9b40)
  • CloseHandle (Address: 0x1801e9b48)
  • CompareStringW (Address: 0x1801e9b50)
  • CreateDirectoryW (Address: 0x1801e9b58)
  • CreateEventW (Address: 0x1801e9b60)
  • CreateFileA (Address: 0x1801e9b68)
  • CreateFileW (Address: 0x1801e9b70)
  • CreateNamedPipeW (Address: 0x1801e9b78)
  • CreateProcessW (Address: 0x1801e9b80)
  • CreateThread (Address: 0x1801e9b88)
  • CreateToolhelp32Snapshot (Address: 0x1801e9b90)
  • DecodePointer (Address: 0x1801e9b98)
  • DeleteCriticalSection (Address: 0x1801e9ba0)
  • DeleteFileW (Address: 0x1801e9ba8)
  • EncodePointer (Address: 0x1801e9bb0)
  • EnterCriticalSection (Address: 0x1801e9bb8)
  • EnumSystemLocalesW (Address: 0x1801e9bc0)
  • ExitProcess (Address: 0x1801e9bc8)
  • ExitThread (Address: 0x1801e9bd0)
  • FileTimeToSystemTime (Address: 0x1801e9bd8)
  • FindClose (Address: 0x1801e9be0)
  • FindFirstFileExW (Address: 0x1801e9be8)
  • FindFirstFileW (Address: 0x1801e9bf0)
  • FindNextFileW (Address: 0x1801e9bf8)
  • FlsAlloc (Address: 0x1801e9c00)
  • FlsFree (Address: 0x1801e9c08)
  • FlsGetValue (Address: 0x1801e9c10)
  • FlsSetValue (Address: 0x1801e9c18)
  • FlushFileBuffers (Address: 0x1801e9c20)
  • FlushInstructionCache (Address: 0x1801e9c28)
  • FormatMessageA (Address: 0x1801e9c30)
  • FormatMessageW (Address: 0x1801e9c38)
  • FreeEnvironmentStringsW (Address: 0x1801e9c40)
  • FreeLibrary (Address: 0x1801e9c48)
  • FreeLibraryAndExitThread (Address: 0x1801e9c50)
  • GetACP (Address: 0x1801e9c58)
  • GetCommandLineA (Address: 0x1801e9c68)
  • GetCommandLineW (Address: 0x1801e9c70)
  • GetConsoleMode (Address: 0x1801e9c78)
  • GetConsoleOutputCP (Address: 0x1801e9c80)
  • GetCPInfo (Address: 0x1801e9c60)
  • GetCurrentDirectoryW (Address: 0x1801e9c88)
  • GetCurrentProcess (Address: 0x1801e9c90)
  • GetCurrentProcessId (Address: 0x1801e9c98)
  • GetCurrentThreadId (Address: 0x1801e9ca0)
  • GetDateFormatW (Address: 0x1801e9ca8)
  • GetDriveTypeW (Address: 0x1801e9cb0)
  • GetEnvironmentStringsW (Address: 0x1801e9cb8)
  • GetEnvironmentVariableA (Address: 0x1801e9cc0)
  • GetFileAttributesExW (Address: 0x1801e9cc8)
  • GetFileAttributesW (Address: 0x1801e9cd0)
  • GetFileInformationByHandle (Address: 0x1801e9cd8)
  • GetFileInformationByHandleEx (Address: 0x1801e9ce0)
  • GetFileSize (Address: 0x1801e9ce8)
  • GetFileSizeEx (Address: 0x1801e9cf0)
  • GetFileTime (Address: 0x1801e9cf8)
  • GetFileType (Address: 0x1801e9d00)
  • GetFullPathNameW (Address: 0x1801e9d08)
  • GetLastError (Address: 0x1801e9d10)
  • GetLocaleInfoEx (Address: 0x1801e9d20)
  • GetLocaleInfoW (Address: 0x1801e9d28)
  • GetLocalTime (Address: 0x1801e9d18)
  • GetModuleFileNameA (Address: 0x1801e9d30)
  • GetModuleFileNameW (Address: 0x1801e9d38)
  • GetModuleHandleA (Address: 0x1801e9d40)
  • GetModuleHandleExA (Address: 0x1801e9d48)
  • GetModuleHandleExW (Address: 0x1801e9d50)
  • GetModuleHandleW (Address: 0x1801e9d58)
  • GetOEMCP (Address: 0x1801e9d60)
  • GetProcAddress (Address: 0x1801e9d68)
  • GetProcessHeap (Address: 0x1801e9d70)
  • GetStartupInfoW (Address: 0x1801e9d78)
  • GetStdHandle (Address: 0x1801e9d80)
  • GetStringTypeW (Address: 0x1801e9d88)
  • GetSystemDirectoryA (Address: 0x1801e9d90)
  • GetSystemInfo (Address: 0x1801e9d98)
  • GetSystemTimeAsFileTime (Address: 0x1801e9da0)
  • GetThreadContext (Address: 0x1801e9da8)
  • GetTickCount (Address: 0x1801e9db0)
  • GetTimeFormatW (Address: 0x1801e9db8)
  • GetTimeZoneInformation (Address: 0x1801e9dc0)
  • GetUserDefaultLCID (Address: 0x1801e9dc8)
  • GetVersion (Address: 0x1801e9dd0)
  • HeapAlloc (Address: 0x1801e9dd8)
  • HeapCreate (Address: 0x1801e9de0)
  • HeapFree (Address: 0x1801e9de8)
  • HeapReAlloc (Address: 0x1801e9df0)
  • HeapSize (Address: 0x1801e9df8)
  • InitializeCriticalSection (Address: 0x1801e9e10)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1801e9e18)
  • InitializeCriticalSectionEx (Address: 0x1801e9e20)
  • InitializeSListHead (Address: 0x1801e9e28)
  • InitializeSRWLock (Address: 0x1801e9e30)
  • InitOnceBeginInitialize (Address: 0x1801e9e00)
  • InitOnceComplete (Address: 0x1801e9e08)
  • InterlockedFlushSList (Address: 0x1801e9e38)
  • IsDebuggerPresent (Address: 0x1801e9e40)
  • IsProcessorFeaturePresent (Address: 0x1801e9e48)
  • IsValidCodePage (Address: 0x1801e9e50)
  • IsValidLocale (Address: 0x1801e9e58)
  • K32GetModuleInformation (Address: 0x1801e9e60)
  • LCMapStringEx (Address: 0x1801e9e68)
  • LCMapStringW (Address: 0x1801e9e70)
  • LeaveCriticalSection (Address: 0x1801e9e78)
  • LoadLibraryA (Address: 0x1801e9e80)
  • LoadLibraryExW (Address: 0x1801e9e88)
  • LoadLibraryW (Address: 0x1801e9e90)
  • LocalFree (Address: 0x1801e9e98)
  • LockFileEx (Address: 0x1801e9ea0)
  • MoveFileExA (Address: 0x1801e9ea8)
  • MultiByteToWideChar (Address: 0x1801e9eb0)
  • OpenFile (Address: 0x1801e9eb8)
  • OpenProcess (Address: 0x1801e9ec0)
  • OpenThread (Address: 0x1801e9ec8)
  • OutputDebugStringW (Address: 0x1801e9ed0)
  • PeekNamedPipe (Address: 0x1801e9ed8)
  • QueryPerformanceCounter (Address: 0x1801e9ee0)
  • QueryPerformanceFrequency (Address: 0x1801e9ee8)
  • RaiseException (Address: 0x1801e9ef0)
  • ReadConsoleW (Address: 0x1801e9ef8)
  • ReadFile (Address: 0x1801e9f00)
  • ReleaseSRWLockExclusive (Address: 0x1801e9f08)
  • RemoveDirectoryW (Address: 0x1801e9f10)
  • ResetEvent (Address: 0x1801e9f18)
  • ResumeThread (Address: 0x1801e9f20)
  • RtlCaptureContext (Address: 0x1801e9f28)
  • RtlLookupFunctionEntry (Address: 0x1801e9f30)
  • RtlPcToFileHeader (Address: 0x1801e9f38)
  • RtlUnwind (Address: 0x1801e9f40)
  • RtlUnwindEx (Address: 0x1801e9f48)
  • RtlVirtualUnwind (Address: 0x1801e9f50)
  • SetConsoleCtrlHandler (Address: 0x1801e9f58)
  • SetEndOfFile (Address: 0x1801e9f60)
  • SetEnvironmentVariableW (Address: 0x1801e9f68)
  • SetEvent (Address: 0x1801e9f70)
  • SetFilePointerEx (Address: 0x1801e9f78)
  • SetLastError (Address: 0x1801e9f80)
  • SetNamedPipeHandleState (Address: 0x1801e9f88)
  • SetStdHandle (Address: 0x1801e9f90)
  • SetThreadContext (Address: 0x1801e9f98)
  • SetUnhandledExceptionFilter (Address: 0x1801e9fa0)
  • Sleep (Address: 0x1801e9fa8)
  • SleepConditionVariableSRW (Address: 0x1801e9fb0)
  • SleepEx (Address: 0x1801e9fb8)
  • SuspendThread (Address: 0x1801e9fc0)
  • SystemTimeToTzSpecificLocalTime (Address: 0x1801e9fc8)
  • TerminateProcess (Address: 0x1801e9fd0)
  • Thread32First (Address: 0x1801e9fd8)
  • Thread32Next (Address: 0x1801e9fe0)
  • TlsAlloc (Address: 0x1801e9fe8)
  • TlsFree (Address: 0x1801e9ff0)
  • TlsGetValue (Address: 0x1801e9ff8)
  • TlsSetValue (Address: 0x1801ea000)
  • TransactNamedPipe (Address: 0x1801ea008)
  • TryAcquireSRWLockExclusive (Address: 0x1801ea010)
  • UnhandledExceptionFilter (Address: 0x1801ea018)
  • UnlockFileEx (Address: 0x1801ea020)
  • VerifyVersionInfoA (Address: 0x1801ea030)
  • VerSetConditionMask (Address: 0x1801ea028)
  • VirtualAlloc (Address: 0x1801ea038)
  • VirtualFree (Address: 0x1801ea040)
  • VirtualProtect (Address: 0x1801ea048)
  • VirtualQuery (Address: 0x1801ea050)
  • WaitForMultipleObjects (Address: 0x1801ea058)
  • WaitForSingleObjectEx (Address: 0x1801ea060)
  • WaitNamedPipeW (Address: 0x1801ea068)
  • WakeAllConditionVariable (Address: 0x1801ea070)
  • WideCharToMultiByte (Address: 0x1801ea078)
  • WriteConsoleW (Address: 0x1801ea080)
  • WriteFile (Address: 0x1801ea088)
Normaliz.dll
  • IdnToAscii (Address: 0x1801ea3a8)
steam_api64.dll
  • SteamAPI_GetHSteamPipe (Address: 0x1801ea0b8)
  • SteamAPI_GetHSteamUser (Address: 0x1801ea0c0)
  • SteamAPI_RegisterCallback (Address: 0x1801ea0c8)
  • SteamAPI_UnregisterCallback (Address: 0x1801ea0d0)
  • SteamInternal_ContextInit (Address: 0x1801ea0d8)
  • SteamInternal_CreateInterface (Address: 0x1801ea0e0)
  • SteamInternal_FindOrCreateGameServerInterface (Address: 0x1801ea0e8)
  • SteamInternal_FindOrCreateUserInterface (Address: 0x1801ea0f0)
USER32.dll
  • GetAsyncKeyState (Address: 0x1801ea098)
  • IsCharAlphaNumericA (Address: 0x1801ea0a0)
  • MessageBoxA (Address: 0x1801ea0a8)
WLDAP32.dll
  • (Address: 0x1801ea360)
  • (Address: 0x1801ea310)
  • (Address: 0x1801ea398)
  • (Address: 0x1801ea390)
  • (Address: 0x1801ea388)
  • (Address: 0x1801ea380)
  • (Address: 0x1801ea378)
  • (Address: 0x1801ea370)
  • (Address: 0x1801ea368)
  • (Address: 0x1801ea318)
  • (Address: 0x1801ea358)
  • (Address: 0x1801ea350)
  • (Address: 0x1801ea348)
  • (Address: 0x1801ea340)
  • (Address: 0x1801ea338)
  • (Address: 0x1801ea330)
  • (Address: 0x1801ea328)
  • (Address: 0x1801ea320)
WS2_32.dll
  • __WSAFDIsSet (Address: 0x1801ea148)
  • accept (Address: 0x1801ea150)
  • bind (Address: 0x1801ea158)
  • closesocket (Address: 0x1801ea160)
  • connect (Address: 0x1801ea168)
  • freeaddrinfo (Address: 0x1801ea170)
  • getaddrinfo (Address: 0x1801ea178)
  • gethostname (Address: 0x1801ea180)
  • getpeername (Address: 0x1801ea188)
  • getsockname (Address: 0x1801ea190)
  • getsockopt (Address: 0x1801ea198)
  • htonl (Address: 0x1801ea1a0)
  • htons (Address: 0x1801ea1a8)
  • ioctlsocket (Address: 0x1801ea1b0)
  • listen (Address: 0x1801ea1b8)
  • ntohl (Address: 0x1801ea1c0)
  • ntohs (Address: 0x1801ea1c8)
  • recv (Address: 0x1801ea1d0)
  • recvfrom (Address: 0x1801ea1d8)
  • select (Address: 0x1801ea1e0)
  • send (Address: 0x1801ea1e8)
  • sendto (Address: 0x1801ea1f0)
  • setsockopt (Address: 0x1801ea1f8)
  • socket (Address: 0x1801ea200)
  • WSACleanup (Address: 0x1801ea100)
  • WSACloseEvent (Address: 0x1801ea108)
  • WSACreateEvent (Address: 0x1801ea110)
  • WSAEnumNetworkEvents (Address: 0x1801ea118)
  • WSAEventSelect (Address: 0x1801ea120)
  • WSAGetLastError (Address: 0x1801ea128)
  • WSAIoctl (Address: 0x1801ea130)
  • WSASetLastError (Address: 0x1801ea138)
  • WSAStartup (Address: 0x1801ea140)