profapi.dll

Description: Loader

Authors: Copyright (C) Loader

Version: 1.0.0.0

Architecture: 64-bit

Operating System: Windows

SHA256: 62c87f4b99b4769deb05ca3060acf5cf

File Size: 23.3 KB

Uploaded At: June 20, 2026, 7:13 p.m.

Views: 28

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: VirtualAllocEx, WriteProcessMemory

Exported Functions

  • ServiceMain (Ordinal: 1, Address: 0x1e10)

Imported DLLs & Functions

ADVAPI32.dll
  • RegisterServiceCtrlHandlerExW (Address: 0x180004008)
  • SetServiceStatus (Address: 0x180004000)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x1800041b0)
  • free (Address: 0x1800041a8)
  • malloc (Address: 0x1800041a0)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x1800041d0)
  • _configure_narrow_argv (Address: 0x1800041e8)
  • _execute_onexit_table (Address: 0x1800041c0)
  • _initialize_narrow_environment (Address: 0x1800041f8)
  • _initialize_onexit_table (Address: 0x1800041c8)
  • _initterm (Address: 0x1800041d8)
  • _initterm_e (Address: 0x1800041e0)
  • _seh_filter_dll (Address: 0x1800041f0)
api-ms-win-crt-stdio-l1-1-0.dll
  • __acrt_iob_func (Address: 0x180004210)
  • __stdio_common_vfprintf (Address: 0x180004208)
api-ms-win-crt-string-l1-1-0.dll
  • wcscpy_s (Address: 0x180004220)
  • wcslen (Address: 0x180004228)
KERNEL32.dll
  • CloseHandle (Address: 0x180004048)
  • CreateEventW (Address: 0x180004028)
  • CreateFileA (Address: 0x180004038)
  • CreateProcessW (Address: 0x180004078)
  • CreateThread (Address: 0x180004050)
  • GetCurrentProcessId (Address: 0x180004090)
  • GetCurrentThreadId (Address: 0x180004098)
  • GetLastError (Address: 0x180004030)
  • GetModuleHandleW (Address: 0x180004080)
  • GetProcAddress (Address: 0x180004060)
  • GetSystemTimeAsFileTime (Address: 0x1800040a0)
  • GetThreadContext (Address: 0x1800040b0)
  • InitializeSListHead (Address: 0x1800040c0)
  • QueryPerformanceCounter (Address: 0x1800040c8)
  • ReadProcessMemory (Address: 0x180004070)
  • ResumeThread (Address: 0x180004020)
  • SetEvent (Address: 0x180004040)
  • SetThreadContext (Address: 0x180004088)
  • TerminateProcess (Address: 0x180004058)
  • VirtualAllocEx (Address: 0x180004068)
  • WaitForSingleObject (Address: 0x180004018)
  • WriteFile (Address: 0x1800040a8)
  • WriteProcessMemory (Address: 0x1800040b8)
MSVCP140.dll
  • ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800040d8)
USER32.dll
  • MessageBoxA (Address: 0x1800040e8)
VCRUNTIME140_1.dll
  • __CxxFrameHandler4 (Address: 0x180004138)
VCRUNTIME140.dll
  • __C_specific_handler (Address: 0x180004120)
  • __std_exception_copy (Address: 0x180004118)
  • __std_exception_destroy (Address: 0x180004110)
  • __std_type_info_destroy_list (Address: 0x180004108)
  • _CxxThrowException (Address: 0x180004128)
  • memcpy (Address: 0x180004100)
  • memset (Address: 0x1800040f8)
WINHTTP.dll
  • WinHttpCloseHandle (Address: 0x180004180)
  • WinHttpConnect (Address: 0x180004168)
  • WinHttpCrackUrl (Address: 0x180004160)
  • WinHttpOpen (Address: 0x180004170)
  • WinHttpOpenRequest (Address: 0x180004190)
  • WinHttpQueryDataAvailable (Address: 0x180004158)
  • WinHttpReadData (Address: 0x180004150)
  • WinHttpReceiveResponse (Address: 0x180004148)
  • WinHttpSendRequest (Address: 0x180004188)
  • WinHttpSetOption (Address: 0x180004178)