FirstLoad.dll

Description: 腾讯QQ

Authors: Copyright (C) 1999-2023 Tencent. All Rights Reserved

Version: 9.7.17.29215

Architecture: 32-bit

Operating System: Windows NT

SHA256: 9d7f3108d07b7d1b2a65a0554be4a714

File Size: 47.9 KB

Uploaded At: Dec. 2, 2025, 2:46 p.m.

Views: 14

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: WriteProcessMemory

Exported Functions

  • FirstLoad (Ordinal: 1, Address: 0x1858)

Imported DLLs & Functions

ADVAPI32.dll
  • RegOpenKeyW (Address: 0x543d6000)
  • RegQueryValueExW (Address: 0x543d6004)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x543d612c)
  • free (Address: 0x543d6128)
  • malloc (Address: 0x543d6130)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x543d6154)
  • _configure_narrow_argv (Address: 0x543d6150)
  • _crt_atexit (Address: 0x543d613c)
  • _execute_onexit_table (Address: 0x543d6138)
  • _initialize_narrow_environment (Address: 0x543d614c)
  • _initialize_onexit_table (Address: 0x543d6144)
  • _initterm (Address: 0x543d615c)
  • _initterm_e (Address: 0x543d6148)
  • _invalid_parameter_noinfo_noreturn (Address: 0x543d6158)
  • _register_onexit_function (Address: 0x543d6140)
  • _seh_filter_dll (Address: 0x543d6160)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vswprintf_s (Address: 0x543d6168)
api-ms-win-crt-string-l1-1-0.dll
  • _wcsicmp (Address: 0x543d6180)
  • _wcslwr (Address: 0x543d6170)
  • tolower (Address: 0x543d617c)
  • wcscpy_s (Address: 0x543d6178)
  • wcsncpy_s (Address: 0x543d6184)
  • wcstok (Address: 0x543d6174)
CRYPT32.dll
  • CertGetNameStringW (Address: 0x543d600c)
KERNEL32.dll
  • CloseHandle (Address: 0x543d6054)
  • DeleteCriticalSection (Address: 0x543d6068)
  • EnterCriticalSection (Address: 0x543d6024)
  • FlushInstructionCache (Address: 0x543d6018)
  • GetCommandLineW (Address: 0x543d6028)
  • GetCurrentDirectoryW (Address: 0x543d6060)
  • GetCurrentProcess (Address: 0x543d608c)
  • GetCurrentProcessId (Address: 0x543d606c)
  • GetCurrentThreadId (Address: 0x543d603c)
  • GetLastError (Address: 0x543d6050)
  • GetModuleFileNameW (Address: 0x543d602c)
  • GetModuleHandleW (Address: 0x543d6014)
  • GetPrivateProfileStringW (Address: 0x543d604c)
  • GetProcAddress (Address: 0x543d6048)
  • GetSystemDirectoryW (Address: 0x543d6044)
  • GetSystemInfo (Address: 0x543d6058)
  • GetSystemTimeAsFileTime (Address: 0x543d609c)
  • GetVersionExW (Address: 0x543d6040)
  • GetWindowsDirectoryW (Address: 0x543d6064)
  • InitializeCriticalSection (Address: 0x543d6038)
  • InitializeCriticalSectionAndSpinCount (Address: 0x543d6030)
  • InitializeSListHead (Address: 0x543d6098)
  • IsDebuggerPresent (Address: 0x543d6084)
  • IsProcessorFeaturePresent (Address: 0x543d6080)
  • LeaveCriticalSection (Address: 0x543d6034)
  • LoadLibraryW (Address: 0x543d605c)
  • OutputDebugStringW (Address: 0x543d6094)
  • QueryPerformanceCounter (Address: 0x543d6088)
  • SetLastError (Address: 0x543d6090)
  • SetUnhandledExceptionFilter (Address: 0x543d6078)
  • TerminateProcess (Address: 0x543d607c)
  • TlsGetValue (Address: 0x543d6070)
  • TlsSetValue (Address: 0x543d6020)
  • UnhandledExceptionFilter (Address: 0x543d6074)
  • VirtualProtect (Address: 0x543d60a0)
  • WriteProcessMemory (Address: 0x543d601c)
MSVCP140.dll
  • ?_Xlength_error@std@@YAXPBD@Z (Address: 0x543d60a8)
SHELL32.dll
  • SHGetFolderPathW (Address: 0x543d60b0)
SHLWAPI.dll
  • PathAddBackslashW (Address: 0x543d60c0)
  • PathCombineW (Address: 0x543d60b8)
  • PathFileExistsW (Address: 0x543d60c4)
  • PathFindFileNameW (Address: 0x543d60bc)
VCRUNTIME140.dll
  • __CxxFrameHandler3 (Address: 0x543d60e0)
  • __std_exception_copy (Address: 0x543d60f4)
  • __std_exception_destroy (Address: 0x543d60f8)
  • __std_terminate (Address: 0x543d60e4)
  • __std_type_info_destroy_list (Address: 0x543d60cc)
  • _CxxThrowException (Address: 0x543d60fc)
  • _except_handler4_common (Address: 0x543d60f0)
  • memcmp (Address: 0x543d60dc)
  • memcpy (Address: 0x543d60d4)
  • memmove (Address: 0x543d60d8)
  • memset (Address: 0x543d60d0)
  • wcsrchr (Address: 0x543d60ec)
  • wcsstr (Address: 0x543d60e8)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x543d610c)
  • GetFileVersionInfoW (Address: 0x543d6108)
  • VerQueryValueW (Address: 0x543d6104)
WINTRUST.dll
  • WinVerifyTrust (Address: 0x543d6118)
  • WTHelperGetProvCertFromChain (Address: 0x543d611c)
  • WTHelperGetProvSignerFromChain (Address: 0x543d6114)
  • WTHelperProvDataFromStateData (Address: 0x543d6120)