qimei.dll

Description:

Authors:

Version:

Architecture: 32-bit

Operating System:

SHA256: 8d80b6996eedfde883508d788f9f8aa3

File Size: 1.3 MB

Uploaded At: Dec. 2, 2025, 2:49 p.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • a (Ordinal: 1, Address: 0xe7e10)
  • a1 (Ordinal: 2, Address: 0xe7d60)
  • b (Ordinal: 3, Address: 0xe7e40)
  • c (Ordinal: 4, Address: 0xe7f50)
  • d (Ordinal: 5, Address: 0xe7fb0)
  • e (Ordinal: 6, Address: 0xe80b0)
  • f (Ordinal: 7, Address: 0xe80c0)
  • g (Ordinal: 8, Address: 0xe80d0)
  • h (Ordinal: 9, Address: 0xe8120)
  • i (Ordinal: 10, Address: 0xe83c0)
  • j (Ordinal: 11, Address: 0xe85c0)
  • z (Ordinal: 12, Address: 0xe7d00)

Imported DLLs & Functions

ADVAPI32.dll
  • CloseEventLog (Address: 0x6baf8bd4)
  • CryptAcquireContextA (Address: 0x6baf8bd8)
  • CryptGenRandom (Address: 0x6baf8bdc)
  • CryptReleaseContext (Address: 0x6baf8be0)
  • GetUserNameA (Address: 0x6baf8be4)
  • OpenEventLogA (Address: 0x6baf8be8)
  • ReadEventLogA (Address: 0x6baf8bec)
  • RegCloseKey (Address: 0x6baf8bf0)
  • RegEnumKeyExA (Address: 0x6baf8bf4)
  • RegOpenKeyExA (Address: 0x6baf8bf8)
  • RegQueryValueExA (Address: 0x6baf8bfc)
api-ms-win-crt-convert-l1-1-0.dll
  • atoll (Address: 0x6baf8e44)
api-ms-win-crt-filesystem-l1-1-0.dll
  • _mkdir (Address: 0x6baf8e00)
  • _splitpath_s (Address: 0x6baf8e04)
  • _stat64 (Address: 0x6baf8e08)
api-ms-win-crt-heap-l1-1-0.dll
  • _callnewh (Address: 0x6baf8d84)
  • calloc (Address: 0x6baf8d88)
  • free (Address: 0x6baf8d8c)
  • malloc (Address: 0x6baf8d90)
api-ms-win-crt-runtime-l1-1-0.dll
  • _cexit (Address: 0x6baf8d98)
  • _configure_narrow_argv (Address: 0x6baf8d9c)
  • _crt_atexit (Address: 0x6baf8da0)
  • _execute_onexit_table (Address: 0x6baf8da4)
  • _initialize_narrow_environment (Address: 0x6baf8da8)
  • _initialize_onexit_table (Address: 0x6baf8dac)
  • _initterm (Address: 0x6baf8db0)
  • _initterm_e (Address: 0x6baf8db4)
  • _invalid_parameter_noinfo_noreturn (Address: 0x6baf8db8)
  • _register_onexit_function (Address: 0x6baf8dbc)
  • _seh_filter_dll (Address: 0x6baf8dc0)
  • exit (Address: 0x6baf8dc4)
api-ms-win-crt-stdio-l1-1-0.dll
  • __stdio_common_vsnprintf_s (Address: 0x6baf8dcc)
  • __stdio_common_vsprintf (Address: 0x6baf8dd0)
  • __stdio_common_vsscanf (Address: 0x6baf8dd4)
  • fclose (Address: 0x6baf8dd8)
  • feof (Address: 0x6baf8ddc)
  • fopen (Address: 0x6baf8de0)
  • fread (Address: 0x6baf8de4)
api-ms-win-crt-string-l1-1-0.dll
  • _stricmp (Address: 0x6baf8e10)
  • isalnum (Address: 0x6baf8e14)
  • isprint (Address: 0x6baf8e18)
  • isspace (Address: 0x6baf8e1c)
  • isxdigit (Address: 0x6baf8e20)
  • strcmp (Address: 0x6baf8e24)
  • strlen (Address: 0x6baf8e28)
  • strncmp (Address: 0x6baf8e2c)
  • strncpy_s (Address: 0x6baf8e30)
  • strpbrk (Address: 0x6baf8e34)
  • tolower (Address: 0x6baf8e38)
  • wcslen (Address: 0x6baf8e3c)
api-ms-win-crt-time-l1-1-0.dll
  • _localtime64_s (Address: 0x6baf8dec)
  • _mktime64 (Address: 0x6baf8df0)
  • _time64 (Address: 0x6baf8df4)
  • strftime (Address: 0x6baf8df8)
api-ms-win-crt-utility-l1-1-0.dll
  • _byteswap_ulong (Address: 0x6baf8d74)
  • rand (Address: 0x6baf8d78)
  • srand (Address: 0x6baf8d7c)
CRYPT32.dll
  • CertGetNameStringA (Address: 0x6baf8d14)
KERNEL32.dll
  • CloseHandle (Address: 0x6baf8aac)
  • CreateEventW (Address: 0x6baf8ab0)
  • CreateFileA (Address: 0x6baf8ab4)
  • CreateFileMappingA (Address: 0x6baf8ab8)
  • CreateFileW (Address: 0x6baf8abc)
  • CreateMutexA (Address: 0x6baf8ac0)
  • CreateThread (Address: 0x6baf8ac4)
  • CreateToolhelp32Snapshot (Address: 0x6baf8ac8)
  • DeleteCriticalSection (Address: 0x6baf8acc)
  • DeviceIoControl (Address: 0x6baf8ad0)
  • EnterCriticalSection (Address: 0x6baf8ad4)
  • FreeLibrary (Address: 0x6baf8ad8)
  • GetComputerNameA (Address: 0x6baf8adc)
  • GetCurrentProcess (Address: 0x6baf8ae0)
  • GetCurrentProcessId (Address: 0x6baf8ae4)
  • GetCurrentThread (Address: 0x6baf8ae8)
  • GetCurrentThreadId (Address: 0x6baf8aec)
  • GetDiskFreeSpaceA (Address: 0x6baf8af0)
  • GetDriveTypeA (Address: 0x6baf8af4)
  • GetLastError (Address: 0x6baf8af8)
  • GetLocalTime (Address: 0x6baf8afc)
  • GetModuleFileNameA (Address: 0x6baf8b00)
  • GetModuleHandleA (Address: 0x6baf8b04)
  • GetModuleHandleW (Address: 0x6baf8b08)
  • GetNativeSystemInfo (Address: 0x6baf8b0c)
  • GetPrivateProfileStringA (Address: 0x6baf8b10)
  • GetProcAddress (Address: 0x6baf8b14)
  • GetProcessHeap (Address: 0x6baf8b18)
  • GetSystemDefaultLCID (Address: 0x6baf8b1c)
  • GetSystemDirectoryA (Address: 0x6baf8b20)
  • GetSystemFirmwareTable (Address: 0x6baf8b24)
  • GetSystemInfo (Address: 0x6baf8b28)
  • GetSystemTimeAsFileTime (Address: 0x6baf8b2c)
  • GetThreadContext (Address: 0x6baf8b30)
  • GetTickCount64 (Address: 0x6baf8b34)
  • GetTimeZoneInformation (Address: 0x6baf8b38)
  • GetVersionExA (Address: 0x6baf8b3c)
  • GlobalMemoryStatusEx (Address: 0x6baf8b40)
  • HeapAlloc (Address: 0x6baf8b44)
  • HeapFree (Address: 0x6baf8b48)
  • InitializeCriticalSection (Address: 0x6baf8b4c)
  • InitializeCriticalSectionAndSpinCount (Address: 0x6baf8b50)
  • InitializeSListHead (Address: 0x6baf8b54)
  • IsBadCodePtr (Address: 0x6baf8b58)
  • IsDebuggerPresent (Address: 0x6baf8b5c)
  • IsProcessorFeaturePresent (Address: 0x6baf8b60)
  • K32EnumProcessModules (Address: 0x6baf8b64)
  • K32GetModuleFileNameExA (Address: 0x6baf8b68)
  • LeaveCriticalSection (Address: 0x6baf8b6c)
  • LoadLibraryA (Address: 0x6baf8b70)
  • MapViewOfFile (Address: 0x6baf8b74)
  • MultiByteToWideChar (Address: 0x6baf8b78)
  • OpenFileMappingA (Address: 0x6baf8b7c)
  • OpenMutexA (Address: 0x6baf8b80)
  • OpenProcess (Address: 0x6baf8b84)
  • Process32First (Address: 0x6baf8b88)
  • Process32Next (Address: 0x6baf8b8c)
  • QueryDosDeviceA (Address: 0x6baf8b90)
  • QueryPerformanceCounter (Address: 0x6baf8b94)
  • ReadFile (Address: 0x6baf8b98)
  • ResetEvent (Address: 0x6baf8b9c)
  • SetEvent (Address: 0x6baf8ba0)
  • SetUnhandledExceptionFilter (Address: 0x6baf8ba4)
  • Sleep (Address: 0x6baf8ba8)
  • TerminateProcess (Address: 0x6baf8bac)
  • UnhandledExceptionFilter (Address: 0x6baf8bb0)
  • WaitForSingleObjectEx (Address: 0x6baf8bb4)
  • WideCharToMultiByte (Address: 0x6baf8bb8)
  • WriteFile (Address: 0x6baf8bbc)
MSVCP140.dll
  • _Mtx_destroy_in_situ (Address: 0x6baf8c80)
  • _Mtx_init_in_situ (Address: 0x6baf8c84)
  • _Mtx_lock (Address: 0x6baf8c88)
  • _Mtx_unlock (Address: 0x6baf8c8c)
  • _Xtime_get_ticks (Address: 0x6baf8c90)
  • ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ (Address: 0x6baf8c2c)
  • ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ (Address: 0x6baf8c30)
  • ?_Throw_C_error@std@@YAXH@Z (Address: 0x6baf8c34)
  • ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ (Address: 0x6baf8c38)
  • ?_Xbad_function_call@std@@YAXXZ (Address: 0x6baf8c3c)
  • ?_Xlength_error@std@@YAXPBD@Z (Address: 0x6baf8c40)
  • ?_Xout_of_range@std@@YAXPBD@Z (Address: 0x6baf8c44)
  • ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ (Address: 0x6baf8c14)
  • ??0ios_base@std@@IAE@XZ (Address: 0x6baf8c18)
  • ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ (Address: 0x6baf8c1c)
  • ??1ios_base@std@@UAE@XZ (Address: 0x6baf8c20)
  • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z (Address: 0x6baf8c24)
  • ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z (Address: 0x6baf8c28)
  • ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z (Address: 0x6baf8c48)
  • ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ (Address: 0x6baf8c4c)
  • ?good@ios_base@std@@QBE_NXZ (Address: 0x6baf8c50)
  • ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEXABVlocale@2@@Z (Address: 0x6baf8c54)
  • ?init@?$basic_ios@DU?$char_traits@D@std@@@std@@IAEXPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@_N@Z (Address: 0x6baf8c58)
  • ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEPAV12@PAD_J@Z (Address: 0x6baf8c5c)
  • ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z (Address: 0x6baf8c60)
  • ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ (Address: 0x6baf8c64)
  • ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z (Address: 0x6baf8c68)
  • ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ (Address: 0x6baf8c6c)
  • ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ (Address: 0x6baf8c70)
  • ?uncaught_exceptions@std@@YAHXZ (Address: 0x6baf8c74)
  • ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z (Address: 0x6baf8c78)
  • ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z (Address: 0x6baf8c7c)
NETAPI32.dll
  • Netbios (Address: 0x6baf8c98)
ole32.dll
  • CoCreateGuid (Address: 0x6baf8c04)
  • CoInitialize (Address: 0x6baf8c08)
  • CoUninitialize (Address: 0x6baf8c0c)
SETUPAPI.dll
  • SetupDiDestroyDeviceInfoList (Address: 0x6baf8cc0)
  • SetupDiEnumDeviceInfo (Address: 0x6baf8cc4)
  • SetupDiGetClassDevsA (Address: 0x6baf8cc8)
  • SetupDiGetDevicePropertyW (Address: 0x6baf8ccc)
  • SetupDiGetDeviceRegistryPropertyA (Address: 0x6baf8cd0)
SHELL32.dll
  • (Address: 0x6baf8bc4)
  • SHGetFolderPathA (Address: 0x6baf8bc8)
  • SHGetSpecialFolderPathA (Address: 0x6baf8bcc)
SHLWAPI.dll
  • PathAppendA (Address: 0x6baf8ca0)
  • PathFileExistsA (Address: 0x6baf8ca4)
USER32.dll
  • GetCursorPos (Address: 0x6baf8a90)
  • GetForegroundWindow (Address: 0x6baf8a94)
  • GetKeyboardLayoutList (Address: 0x6baf8a98)
  • GetKeyboardType (Address: 0x6baf8a9c)
  • GetSystemMetrics (Address: 0x6baf8aa0)
  • GetWindowTextA (Address: 0x6baf8aa4)
VCRUNTIME140.dll
  • __CxxFrameHandler3 (Address: 0x6baf8d3c)
  • __std_exception_copy (Address: 0x6baf8d40)
  • __std_exception_destroy (Address: 0x6baf8d44)
  • __std_terminate (Address: 0x6baf8d48)
  • __std_type_info_destroy_list (Address: 0x6baf8d4c)
  • _CxxThrowException (Address: 0x6baf8d38)
  • _except_handler4_common (Address: 0x6baf8d50)
  • _purecall (Address: 0x6baf8d54)
  • memchr (Address: 0x6baf8d58)
  • memcmp (Address: 0x6baf8d5c)
  • memcpy (Address: 0x6baf8d60)
  • memmove (Address: 0x6baf8d64)
  • memset (Address: 0x6baf8d68)
  • strstr (Address: 0x6baf8d6c)
VERSION.dll
  • GetFileVersionInfoA (Address: 0x6baf8cd8)
  • GetFileVersionInfoSizeA (Address: 0x6baf8cdc)
  • VerQueryValueA (Address: 0x6baf8ce0)
WININET.dll
  • HttpOpenRequestA (Address: 0x6baf8d1c)
  • HttpSendRequestA (Address: 0x6baf8d20)
  • InternetCloseHandle (Address: 0x6baf8d24)
  • InternetConnectA (Address: 0x6baf8d28)
  • InternetOpenA (Address: 0x6baf8d2c)
  • InternetReadFile (Address: 0x6baf8d30)
WINTRUST.dll
  • CryptCATAdminAcquireContext (Address: 0x6baf8ce8)
  • CryptCATAdminCalcHashFromFileHandle (Address: 0x6baf8cec)
  • CryptCATAdminEnumCatalogFromHash (Address: 0x6baf8cf0)
  • CryptCATAdminReleaseCatalogContext (Address: 0x6baf8cf4)
  • CryptCATAdminReleaseContext (Address: 0x6baf8cf8)
  • CryptCATCatalogInfoFromContext (Address: 0x6baf8cfc)
  • WinVerifyTrust (Address: 0x6baf8d0c)
  • WTHelperGetProvCertFromChain (Address: 0x6baf8d00)
  • WTHelperGetProvSignerFromChain (Address: 0x6baf8d04)
  • WTHelperProvDataFromStateData (Address: 0x6baf8d08)
WS2_32.dll
  • gethostbyname (Address: 0x6baf8cb0)
  • gethostname (Address: 0x6baf8cb4)
  • inet_ntoa (Address: 0x6baf8cb8)
  • WSAStartup (Address: 0x6baf8cac)