psnt.dll

Description:

Authors:

Version:

Architecture: 32-bit

Operating System:

SHA256: 9d1b1dfd277fd93fce8732c67623f74c

File Size: 54.5 KB

Uploaded At: May 1, 2026, 8:28 a.m.

Views: 43

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • PS_WIND (Ordinal: 1, Address: 0x1000)
  • ps_exepath (Ordinal: 2, Address: 0x11f0)
  • ps_ts_task (Ordinal: 3, Address: 0x12f0)

Imported DLLs & Functions

KERNEL32.dll
  • CloseHandle (Address: 0x1000b010)
  • CreateFileA (Address: 0x1000b018)
  • CreateToolhelp32Snapshot (Address: 0x1000b00c)
  • DeleteCriticalSection (Address: 0x1000b0c0)
  • EnterCriticalSection (Address: 0x1000b104)
  • ExitProcess (Address: 0x1000b0ac)
  • FlushFileBuffers (Address: 0x1000b014)
  • FreeEnvironmentStringsA (Address: 0x1000b0c8)
  • FreeEnvironmentStringsW (Address: 0x1000b0d0)
  • GetACP (Address: 0x1000b06c)
  • GetCommandLineA (Address: 0x1000b040)
  • GetConsoleCP (Address: 0x1000b0fc)
  • GetConsoleMode (Address: 0x1000b100)
  • GetConsoleOutputCP (Address: 0x1000b024)
  • GetCPInfo (Address: 0x1000b060)
  • GetCurrentProcess (Address: 0x1000b048)
  • GetCurrentProcessId (Address: 0x1000b0ec)
  • GetCurrentThreadId (Address: 0x1000b03c)
  • GetEnvironmentStrings (Address: 0x1000b0cc)
  • GetEnvironmentStringsW (Address: 0x1000b0d4)
  • GetFileType (Address: 0x1000b0b8)
  • GetLastError (Address: 0x1000b058)
  • GetLocaleInfoA (Address: 0x1000b11c)
  • GetModuleFileNameA (Address: 0x1000b0c4)
  • GetModuleHandleW (Address: 0x1000b078)
  • GetOEMCP (Address: 0x1000b070)
  • GetProcAddress (Address: 0x1000b07c)
  • GetStartupInfoA (Address: 0x1000b0bc)
  • GetStdHandle (Address: 0x1000b0b4)
  • GetStringTypeA (Address: 0x1000b114)
  • GetStringTypeW (Address: 0x1000b118)
  • GetSystemTimeAsFileTime (Address: 0x1000b0f0)
  • GetTickCount (Address: 0x1000b0e8)
  • HeapAlloc (Address: 0x1000b094)
  • HeapCreate (Address: 0x1000b0d8)
  • HeapDestroy (Address: 0x1000b0dc)
  • HeapFree (Address: 0x1000b05c)
  • HeapReAlloc (Address: 0x1000b110)
  • HeapSize (Address: 0x1000b01c)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1000b034)
  • InterlockedDecrement (Address: 0x1000b068)
  • InterlockedIncrement (Address: 0x1000b064)
  • IsDebuggerPresent (Address: 0x1000b054)
  • IsValidCodePage (Address: 0x1000b074)
  • LCMapStringA (Address: 0x1000b098)
  • LCMapStringW (Address: 0x1000b0a4)
  • LeaveCriticalSection (Address: 0x1000b108)
  • LoadLibraryA (Address: 0x1000b038)
  • MultiByteToWideChar (Address: 0x1000b0a0)
  • OpenProcess (Address: 0x1000b004)
  • Process32First (Address: 0x1000b000)
  • Process32Next (Address: 0x1000b008)
  • QueryPerformanceCounter (Address: 0x1000b0e4)
  • RtlUnwind (Address: 0x1000b030)
  • SetFilePointer (Address: 0x1000b0f4)
  • SetHandleCount (Address: 0x1000b0b0)
  • SetLastError (Address: 0x1000b090)
  • SetStdHandle (Address: 0x1000b02c)
  • SetUnhandledExceptionFilter (Address: 0x1000b050)
  • Sleep (Address: 0x1000b0a8)
  • TerminateProcess (Address: 0x1000b044)
  • TlsAlloc (Address: 0x1000b084)
  • TlsFree (Address: 0x1000b08c)
  • TlsGetValue (Address: 0x1000b080)
  • TlsSetValue (Address: 0x1000b088)
  • UnhandledExceptionFilter (Address: 0x1000b04c)
  • VirtualAlloc (Address: 0x1000b10c)
  • VirtualFree (Address: 0x1000b0e0)
  • WideCharToMultiByte (Address: 0x1000b09c)
  • WriteConsoleA (Address: 0x1000b028)
  • WriteConsoleW (Address: 0x1000b020)
  • WriteFile (Address: 0x1000b0f8)
PSAPI.DLL
  • EnumProcesses (Address: 0x1000b12c)
  • EnumProcessModules (Address: 0x1000b128)
  • GetModuleBaseNameA (Address: 0x1000b124)
USER32.dll
  • MessageBoxA (Address: 0x1000b134)
WTSAPI32.dll
  • WTSCloseServer (Address: 0x1000b140)
  • WTSEnumerateProcessesA (Address: 0x1000b148)
  • WTSFreeMemory (Address: 0x1000b13c)
  • WTSOpenServerA (Address: 0x1000b144)
  • WTSQuerySessionInformationA (Address: 0x1000b14c)
YRTL.dll
  • (Address: 0x1000b154)
  • (Address: 0x1000b158)