FirstLoad.dll
Description: 腾讯QQ
Authors: Copyright (C) 1999-2023 Tencent. All Rights Reserved
Version: 9.7.17.29215
Architecture: 32-bit
Operating System: Windows NT
SHA256: 9d7f3108d07b7d1b2a65a0554be4a714
File Size: 47.9 KB
Uploaded At: Dec. 2, 2025, 2:46 p.m.
Views: 14
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory
Exported Functions
- FirstLoad (Ordinal: 1, Address: 0x1858)
Imported DLLs & Functions
ADVAPI32.dll
- RegOpenKeyW (Address: 0x543d6000)
- RegQueryValueExW (Address: 0x543d6004)
api-ms-win-crt-heap-l1-1-0.dll
- _callnewh (Address: 0x543d612c)
- free (Address: 0x543d6128)
- malloc (Address: 0x543d6130)
api-ms-win-crt-runtime-l1-1-0.dll
- _cexit (Address: 0x543d6154)
- _configure_narrow_argv (Address: 0x543d6150)
- _crt_atexit (Address: 0x543d613c)
- _execute_onexit_table (Address: 0x543d6138)
- _initialize_narrow_environment (Address: 0x543d614c)
- _initialize_onexit_table (Address: 0x543d6144)
- _initterm (Address: 0x543d615c)
- _initterm_e (Address: 0x543d6148)
- _invalid_parameter_noinfo_noreturn (Address: 0x543d6158)
- _register_onexit_function (Address: 0x543d6140)
- _seh_filter_dll (Address: 0x543d6160)
api-ms-win-crt-stdio-l1-1-0.dll
- __stdio_common_vswprintf_s (Address: 0x543d6168)
api-ms-win-crt-string-l1-1-0.dll
- _wcsicmp (Address: 0x543d6180)
- _wcslwr (Address: 0x543d6170)
- tolower (Address: 0x543d617c)
- wcscpy_s (Address: 0x543d6178)
- wcsncpy_s (Address: 0x543d6184)
- wcstok (Address: 0x543d6174)
CRYPT32.dll
- CertGetNameStringW (Address: 0x543d600c)
KERNEL32.dll
- CloseHandle (Address: 0x543d6054)
- DeleteCriticalSection (Address: 0x543d6068)
- EnterCriticalSection (Address: 0x543d6024)
- FlushInstructionCache (Address: 0x543d6018)
- GetCommandLineW (Address: 0x543d6028)
- GetCurrentDirectoryW (Address: 0x543d6060)
- GetCurrentProcess (Address: 0x543d608c)
- GetCurrentProcessId (Address: 0x543d606c)
- GetCurrentThreadId (Address: 0x543d603c)
- GetLastError (Address: 0x543d6050)
- GetModuleFileNameW (Address: 0x543d602c)
- GetModuleHandleW (Address: 0x543d6014)
- GetPrivateProfileStringW (Address: 0x543d604c)
- GetProcAddress (Address: 0x543d6048)
- GetSystemDirectoryW (Address: 0x543d6044)
- GetSystemInfo (Address: 0x543d6058)
- GetSystemTimeAsFileTime (Address: 0x543d609c)
- GetVersionExW (Address: 0x543d6040)
- GetWindowsDirectoryW (Address: 0x543d6064)
- InitializeCriticalSection (Address: 0x543d6038)
- InitializeCriticalSectionAndSpinCount (Address: 0x543d6030)
- InitializeSListHead (Address: 0x543d6098)
- IsDebuggerPresent (Address: 0x543d6084)
- IsProcessorFeaturePresent (Address: 0x543d6080)
- LeaveCriticalSection (Address: 0x543d6034)
- LoadLibraryW (Address: 0x543d605c)
- OutputDebugStringW (Address: 0x543d6094)
- QueryPerformanceCounter (Address: 0x543d6088)
- SetLastError (Address: 0x543d6090)
- SetUnhandledExceptionFilter (Address: 0x543d6078)
- TerminateProcess (Address: 0x543d607c)
- TlsGetValue (Address: 0x543d6070)
- TlsSetValue (Address: 0x543d6020)
- UnhandledExceptionFilter (Address: 0x543d6074)
- VirtualProtect (Address: 0x543d60a0)
- WriteProcessMemory (Address: 0x543d601c)
MSVCP140.dll
- ?_Xlength_error@std@@YAXPBD@Z (Address: 0x543d60a8)
SHELL32.dll
- SHGetFolderPathW (Address: 0x543d60b0)
SHLWAPI.dll
- PathAddBackslashW (Address: 0x543d60c0)
- PathCombineW (Address: 0x543d60b8)
- PathFileExistsW (Address: 0x543d60c4)
- PathFindFileNameW (Address: 0x543d60bc)
VCRUNTIME140.dll
- __CxxFrameHandler3 (Address: 0x543d60e0)
- __std_exception_copy (Address: 0x543d60f4)
- __std_exception_destroy (Address: 0x543d60f8)
- __std_terminate (Address: 0x543d60e4)
- __std_type_info_destroy_list (Address: 0x543d60cc)
- _CxxThrowException (Address: 0x543d60fc)
- _except_handler4_common (Address: 0x543d60f0)
- memcmp (Address: 0x543d60dc)
- memcpy (Address: 0x543d60d4)
- memmove (Address: 0x543d60d8)
- memset (Address: 0x543d60d0)
- wcsrchr (Address: 0x543d60ec)
- wcsstr (Address: 0x543d60e8)
VERSION.dll
- GetFileVersionInfoSizeW (Address: 0x543d610c)
- GetFileVersionInfoW (Address: 0x543d6108)
- VerQueryValueW (Address: 0x543d6104)
WINTRUST.dll
- WinVerifyTrust (Address: 0x543d6118)
- WTHelperGetProvCertFromChain (Address: 0x543d611c)
- WTHelperGetProvSignerFromChain (Address: 0x543d6114)
- WTHelperProvDataFromStateData (Address: 0x543d6120)