eve-memory-reader.dll
Description:
Authors:
Version:
Architecture: 64-bit
Operating System:
SHA256: 4b2b58096c29b9a125da767554eb0ae8
File Size: 38.0 KB
Uploaded At: April 12, 2026, 12:36 p.m.
Views: 60
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- cleanup (Ordinal: 1, Address: 0x52e0)
- free_string (Ordinal: 2, Address: 0x52d0)
- free_ui_json (Ordinal: 3, Address: 0x4a90)
- get_ui_json (Ordinal: 4, Address: 0x4ac0)
- initialize (Ordinal: 5, Address: 0x50a0)
- read_ui_trees (Ordinal: 6, Address: 0x4ad0)
- read_ui_trees_from_address (Ordinal: 7, Address: 0x4d00)
Imported DLLs & Functions
api-ms-win-crt-convert-l1-1-0.dll
- wcstombs_s (Address: 0x1800080e0)
api-ms-win-crt-heap-l1-1-0.dll
- calloc (Address: 0x1800080f0)
- free (Address: 0x180008100)
- malloc (Address: 0x1800080f8)
- realloc (Address: 0x180008108)
api-ms-win-crt-runtime-l1-1-0.dll
- _cexit (Address: 0x180008130)
- _configure_narrow_argv (Address: 0x180008148)
- _errno (Address: 0x180008168)
- _execute_onexit_table (Address: 0x180008120)
- _initialize_narrow_environment (Address: 0x180008140)
- _initialize_onexit_table (Address: 0x180008138)
- _initterm (Address: 0x180008160)
- _initterm_e (Address: 0x180008158)
- _invalid_parameter_noinfo (Address: 0x180008118)
- _seh_filter_dll (Address: 0x180008150)
- exit (Address: 0x180008128)
api-ms-win-crt-stdio-l1-1-0.dll
- __acrt_iob_func (Address: 0x180008180)
- __stdio_common_vfprintf (Address: 0x180008190)
- __stdio_common_vsprintf (Address: 0x180008188)
- __stdio_common_vsprintf_s (Address: 0x180008178)
api-ms-win-crt-string-l1-1-0.dll
- _strdup (Address: 0x1800081a0)
- strcmp (Address: 0x1800081b0)
- strcpy_s (Address: 0x1800081a8)
api-ms-win-crt-time-l1-1-0.dll
- _time64 (Address: 0x1800081c0)
KERNEL32.dll
- CloseHandle (Address: 0x180008020)
- DisableThreadLibraryCalls (Address: 0x180008098)
- GetCurrentProcess (Address: 0x180008038)
- GetCurrentProcessId (Address: 0x180008078)
- GetCurrentThreadId (Address: 0x180008080)
- GetSystemTimeAsFileTime (Address: 0x180008088)
- InitializeSListHead (Address: 0x1800080a0)
- IsDebuggerPresent (Address: 0x180008090)
- IsProcessorFeaturePresent (Address: 0x180008068)
- K32EnumProcesses (Address: 0x180008028)
- K32EnumProcessModules (Address: 0x180008030)
- K32GetModuleBaseNameW (Address: 0x180008018)
- OpenProcess (Address: 0x180008000)
- QueryPerformanceCounter (Address: 0x180008070)
- ReadProcessMemory (Address: 0x180008008)
- RtlCaptureContext (Address: 0x180008060)
- RtlLookupFunctionEntry (Address: 0x180008058)
- RtlVirtualUnwind (Address: 0x180008050)
- SetUnhandledExceptionFilter (Address: 0x180008040)
- TerminateProcess (Address: 0x1800080a8)
- UnhandledExceptionFilter (Address: 0x180008048)
- VirtualQueryEx (Address: 0x180008010)
VCRUNTIME140.dll
- __C_specific_handler (Address: 0x1800080c8)
- __std_type_info_destroy_list (Address: 0x1800080b8)
- memcpy (Address: 0x1800080d0)
- memset (Address: 0x1800080c0)