msimg32.dll

Description: GDIEXT Client DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 6.3.9600.17415

Architecture: 64-bit

Operating System: Windows NT

SHA256: 523198b4b933f95af21970328e505f28

File Size: 12.0 KB

Uploaded At: July 15, 2026, 1:42 p.m.

Views: 14

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory

Exported Functions

  • AlphaBlend (Ordinal: 1, Address: 0x10d3)
  • DllInitialize (Ordinal: 2, Address: 0x130c)
  • GradientFill (Ordinal: 3, Address: 0x1192)
  • TransparentBlt (Ordinal: 4, Address: 0x12f6)
  • vSetDdrawflag (Ordinal: 5, Address: 0x10e9)

Imported DLLs & Functions

KERNEL32.dll
  • CloseHandle (Address: 0x1800062a4)
  • DeleteCriticalSection (Address: 0x1800062cc)
  • DisableThreadLibraryCalls (Address: 0x18000627c)
  • DuplicateHandle (Address: 0x180006304)
  • EnterCriticalSection (Address: 0x1800062ac)
  • FreeLibrary (Address: 0x180006324)
  • GetCurrentProcess (Address: 0x1800062f4)
  • GetCurrentThread (Address: 0x1800062fc)
  • GetModuleFileNameW (Address: 0x18000631c)
  • GetModuleHandleW (Address: 0x180006294)
  • GetProcAddress (Address: 0x18000633c)
  • GetSystemDirectoryW (Address: 0x18000628c)
  • HeapAlloc (Address: 0x1800062ec)
  • HeapCreate (Address: 0x18000626c)
  • HeapDestroy (Address: 0x180006274)
  • HeapFree (Address: 0x1800062bc)
  • HeapReAlloc (Address: 0x180006344)
  • InitializeCriticalSection (Address: 0x1800062dc)
  • LeaveCriticalSection (Address: 0x1800062b4)
  • LoadLibraryW (Address: 0x18000632c)
  • MultiByteToWideChar (Address: 0x18000634c)
  • RegisterWaitForSingleObject (Address: 0x18000630c)
  • TlsAlloc (Address: 0x1800062d4)
  • TlsFree (Address: 0x1800062c4)
  • TlsGetValue (Address: 0x1800062e4)
  • TlsSetValue (Address: 0x180006314)
  • UnregisterWait (Address: 0x18000629c)
  • WideCharToMultiByte (Address: 0x180006334)
  • WriteProcessMemory (Address: 0x180006284)
msvcrt.dll
  • free (Address: 0x18000625c)
  • malloc (Address: 0x180006254)
  • memcpy (Address: 0x180006234)
  • memmove (Address: 0x18000622c)
  • memset (Address: 0x18000621c)
  • strcpy (Address: 0x180006244)
  • strlen (Address: 0x18000623c)
  • wcscmp (Address: 0x180006224)
  • wcslen (Address: 0x18000624c)