preloader.dll

Description:

Authors:

Version: 38395.60189.38889.40405

Architecture: 64-bit

Operating System: Windows NT

SHA256: 319a1b10c37449e150fabf2b6d627143

File Size: 45.4 KB

Uploaded At: June 13, 2026, 1:07 p.m.

Views: 78

Exported Functions

  • (Ordinal: 1, Address: 0xb010)
  • (Ordinal: 2, Address: 0x34a0)

Imported DLLs & Functions

ADVAPI32.dll
  • RegGetValueW (Address: 0x1800041c0)
GDI32.dll
  • Pie (Address: 0x1800041b0)
ntdll.dll
  • __C_specific_handler (Address: 0x180004120)
  • __chkstk (Address: 0x180004128)
  • _snwprintf_s (Address: 0x180004130)
  • LdrAccessResource (Address: 0x180004000)
  • LdrFindEntryForAddress (Address: 0x180004008)
  • LdrFindResource_U (Address: 0x180004010)
  • LdrGetProcedureAddress (Address: 0x180004018)
  • mbstowcs (Address: 0x180004138)
  • MD5Init (Address: 0x180004020)
  • memcmp (Address: 0x180004140)
  • memset (Address: 0x180004148)
  • NtAllocateVirtualMemory (Address: 0x180004028)
  • NtCreateSection (Address: 0x180004030)
  • NtMapViewOfSection (Address: 0x180004038)
  • NtOpenFile (Address: 0x180004040)
  • NtProtectVirtualMemory (Address: 0x180004048)
  • NtReadFile (Address: 0x180004050)
  • NtTerminateProcess (Address: 0x180004058)
  • NtYieldExecution (Address: 0x180004060)
  • RtlAllocateHeap (Address: 0x180004068)
  • RtlAppendUnicodeToString (Address: 0x180004070)
  • RtlCopyUnicodeString (Address: 0x180004078)
  • RtlCreateEnvironment (Address: 0x180004080)
  • RtlCreateProcessParametersEx (Address: 0x180004088)
  • RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x180004090)
  • RtlExpandEnvironmentStrings (Address: 0x180004098)
  • RtlFindCharInUnicodeString (Address: 0x1800040a0)
  • RtlFindMessage (Address: 0x1800040a8)
  • RtlPcToFileHeader (Address: 0x1800040b0)
  • RtlQueryEnvironmentVariable (Address: 0x1800040b8)
  • RtlQueryEnvironmentVariable_U (Address: 0x1800040c0)
  • wcsncat (Address: 0x180004150)
  • wcstoul (Address: 0x180004158)
  • ZwClose (Address: 0x1800040c8)
  • ZwCreateFile (Address: 0x1800040d0)
  • ZwCreateThreadEx (Address: 0x1800040d8)
  • ZwCreateUserProcess (Address: 0x1800040e0)
  • ZwDeleteFile (Address: 0x1800040e8)
  • ZwQueryDirectoryFile (Address: 0x1800040f0)
  • ZwQueryInformationFile (Address: 0x1800040f8)
  • ZwQueryInformationProcess (Address: 0x180004100)
  • ZwQuerySystemInformation (Address: 0x180004108)
  • ZwSetInformationFile (Address: 0x180004110)
  • ZwWaitForSingleObject (Address: 0x180004118)
USER32.dll
  • CallNextHookEx (Address: 0x180004168)
  • DefWindowProcW (Address: 0x180004170)
  • GetProcessWindowStation (Address: 0x180004178)
  • GetUserObjectInformationW (Address: 0x180004180)
  • GetWindowLongPtrW (Address: 0x180004188)
  • IsChild (Address: 0x180004190)
  • MessageBoxW (Address: 0x180004198)
  • SetWindowLongPtrW (Address: 0x1800041a0)