main.dll
Description:
Authors:
Version:
Architecture: 64-bit
Operating System:
SHA256: 3c669abec8032e9e29f55285300b911e
File Size: 44.5 KB
Uploaded At: July 4, 2026, 9:37 a.m.
Views: 15
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess, CreateRemoteThread
Exported Functions
- EzDeleteFileA (Ordinal: 1, Address: 0x1f80)
- EzDeleteFileW (Ordinal: 2, Address: 0x20a0)
- EzUnlockFileA (Ordinal: 3, Address: 0x1c80)
- EzUnlockFileW (Ordinal: 4, Address: 0x1e20)
Imported DLLs & Functions
ADVAPI32.dll
- AdjustTokenPrivileges (Address: 0x180008008)
- LookupPrivilegeValueW (Address: 0x180008000)
- OpenProcessToken (Address: 0x180008010)
api-ms-win-crt-heap-l1-1-0.dll
- _callnewh (Address: 0x180008278)
- free (Address: 0x180008280)
- malloc (Address: 0x180008270)
- realloc (Address: 0x180008288)
api-ms-win-crt-locale-l1-1-0.dll
- ___lc_codepage_func (Address: 0x180008298)
api-ms-win-crt-runtime-l1-1-0.dll
- _cexit (Address: 0x1800082e8)
- _configure_narrow_argv (Address: 0x1800082b8)
- _crt_atexit (Address: 0x1800082d0)
- _execute_onexit_table (Address: 0x1800082c8)
- _initialize_narrow_environment (Address: 0x1800082b0)
- _initialize_onexit_table (Address: 0x1800082a8)
- _initterm (Address: 0x1800082f0)
- _initterm_e (Address: 0x1800082e0)
- _invalid_parameter_noinfo_noreturn (Address: 0x1800082f8)
- _register_onexit_function (Address: 0x1800082c0)
- _seh_filter_dll (Address: 0x1800082d8)
api-ms-win-crt-string-l1-1-0.dll
- _wcsicmp (Address: 0x180008310)
- _wcsnicmp (Address: 0x180008308)
KERNEL32.dll
- AreFileApisANSI (Address: 0x180008118)
- CloseHandle (Address: 0x180008030)
- CreateEventW (Address: 0x180008190)
- CreateFileMappingW (Address: 0x180008080)
- CreateFileW (Address: 0x180008108)
- CreateRemoteThread (Address: 0x180008040)
- CreateToolhelp32Snapshot (Address: 0x180008058)
- DeleteCriticalSection (Address: 0x1800081b0)
- DeleteFileW (Address: 0x180008110)
- DisableThreadLibraryCalls (Address: 0x180008128)
- DuplicateHandle (Address: 0x180008098)
- EnterCriticalSection (Address: 0x1800081c8)
- FormatMessageA (Address: 0x1800081e0)
- GetCurrentProcess (Address: 0x180008090)
- GetCurrentProcessId (Address: 0x180008140)
- GetCurrentThreadId (Address: 0x180008138)
- GetDriveTypeW (Address: 0x1800080a8)
- GetExitCodeThread (Address: 0x180008020)
- GetLastError (Address: 0x1800080f0)
- GetLogicalDrives (Address: 0x1800080b8)
- GetModuleHandleW (Address: 0x180008188)
- GetNativeSystemInfo (Address: 0x1800080d8)
- GetProcAddress (Address: 0x180008038)
- GetSystemTimeAsFileTime (Address: 0x180008130)
- GetWindowsDirectoryW (Address: 0x1800080a0)
- InitializeCriticalSectionAndSpinCount (Address: 0x1800081b8)
- InitializeSListHead (Address: 0x180008120)
- IsDebuggerPresent (Address: 0x180008150)
- IsProcessorFeaturePresent (Address: 0x180008158)
- IsWow64Process (Address: 0x1800080e0)
- K32GetMappedFileNameW (Address: 0x1800080c8)
- K32GetProcessImageFileNameW (Address: 0x1800080e8)
- LeaveCriticalSection (Address: 0x1800081c0)
- LoadLibraryW (Address: 0x1800080c0)
- LocalFree (Address: 0x1800081d8)
- MapViewOfFile (Address: 0x180008078)
- Module32FirstW (Address: 0x180008050)
- Module32NextW (Address: 0x180008088)
- MultiByteToWideChar (Address: 0x1800081d0)
- OpenProcess (Address: 0x180008060)
- Process32FirstW (Address: 0x180008068)
- Process32NextW (Address: 0x1800080f8)
- QueryDosDeviceW (Address: 0x1800080b0)
- QueryPerformanceCounter (Address: 0x180008148)
- ResetEvent (Address: 0x1800081a0)
- RtlCaptureContext (Address: 0x180008180)
- RtlLookupFunctionEntry (Address: 0x180008178)
- RtlVirtualUnwind (Address: 0x180008170)
- SetEvent (Address: 0x1800081a8)
- SetFileAttributesW (Address: 0x180008100)
- SetUnhandledExceptionFilter (Address: 0x180008160)
- TerminateProcess (Address: 0x180008048)
- UnhandledExceptionFilter (Address: 0x180008168)
- UnmapViewOfFile (Address: 0x180008070)
- VirtualQueryEx (Address: 0x1800080d0)
- WaitForSingleObject (Address: 0x180008028)
- WaitForSingleObjectEx (Address: 0x180008198)
MSVCP140.dll
- ?_Syserror_map@std@@YAPEBDH@Z (Address: 0x1800081f0)
- ?_Winerror_map@std@@YAHH@Z (Address: 0x180008200)
- ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800081f8)
- ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x180008208)
VCRUNTIME140_1.dll
- __CxxFrameHandler4 (Address: 0x180008260)
VCRUNTIME140.dll
- __C_specific_handler (Address: 0x180008250)
- __std_exception_copy (Address: 0x180008220)
- __std_exception_destroy (Address: 0x180008228)
- __std_type_info_destroy_list (Address: 0x180008248)
- _CxxThrowException (Address: 0x180008238)
- memcpy (Address: 0x180008218)
- memmove (Address: 0x180008230)
- memset (Address: 0x180008240)