qimei.dll
Description:
Authors:
Version:
Architecture: 32-bit
Operating System:
SHA256: 8d80b6996eedfde883508d788f9f8aa3
File Size: 1.3 MB
Uploaded At: Dec. 2, 2025, 2:49 p.m.
Views: 6
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- a (Ordinal: 1, Address: 0xe7e10)
- a1 (Ordinal: 2, Address: 0xe7d60)
- b (Ordinal: 3, Address: 0xe7e40)
- c (Ordinal: 4, Address: 0xe7f50)
- d (Ordinal: 5, Address: 0xe7fb0)
- e (Ordinal: 6, Address: 0xe80b0)
- f (Ordinal: 7, Address: 0xe80c0)
- g (Ordinal: 8, Address: 0xe80d0)
- h (Ordinal: 9, Address: 0xe8120)
- i (Ordinal: 10, Address: 0xe83c0)
- j (Ordinal: 11, Address: 0xe85c0)
- z (Ordinal: 12, Address: 0xe7d00)
Imported DLLs & Functions
ADVAPI32.dll
- CloseEventLog (Address: 0x6baf8bd4)
- CryptAcquireContextA (Address: 0x6baf8bd8)
- CryptGenRandom (Address: 0x6baf8bdc)
- CryptReleaseContext (Address: 0x6baf8be0)
- GetUserNameA (Address: 0x6baf8be4)
- OpenEventLogA (Address: 0x6baf8be8)
- ReadEventLogA (Address: 0x6baf8bec)
- RegCloseKey (Address: 0x6baf8bf0)
- RegEnumKeyExA (Address: 0x6baf8bf4)
- RegOpenKeyExA (Address: 0x6baf8bf8)
- RegQueryValueExA (Address: 0x6baf8bfc)
api-ms-win-crt-convert-l1-1-0.dll
- atoll (Address: 0x6baf8e44)
api-ms-win-crt-filesystem-l1-1-0.dll
- _mkdir (Address: 0x6baf8e00)
- _splitpath_s (Address: 0x6baf8e04)
- _stat64 (Address: 0x6baf8e08)
api-ms-win-crt-heap-l1-1-0.dll
- _callnewh (Address: 0x6baf8d84)
- calloc (Address: 0x6baf8d88)
- free (Address: 0x6baf8d8c)
- malloc (Address: 0x6baf8d90)
api-ms-win-crt-runtime-l1-1-0.dll
- _cexit (Address: 0x6baf8d98)
- _configure_narrow_argv (Address: 0x6baf8d9c)
- _crt_atexit (Address: 0x6baf8da0)
- _execute_onexit_table (Address: 0x6baf8da4)
- _initialize_narrow_environment (Address: 0x6baf8da8)
- _initialize_onexit_table (Address: 0x6baf8dac)
- _initterm (Address: 0x6baf8db0)
- _initterm_e (Address: 0x6baf8db4)
- _invalid_parameter_noinfo_noreturn (Address: 0x6baf8db8)
- _register_onexit_function (Address: 0x6baf8dbc)
- _seh_filter_dll (Address: 0x6baf8dc0)
- exit (Address: 0x6baf8dc4)
api-ms-win-crt-stdio-l1-1-0.dll
- __stdio_common_vsnprintf_s (Address: 0x6baf8dcc)
- __stdio_common_vsprintf (Address: 0x6baf8dd0)
- __stdio_common_vsscanf (Address: 0x6baf8dd4)
- fclose (Address: 0x6baf8dd8)
- feof (Address: 0x6baf8ddc)
- fopen (Address: 0x6baf8de0)
- fread (Address: 0x6baf8de4)
api-ms-win-crt-string-l1-1-0.dll
- _stricmp (Address: 0x6baf8e10)
- isalnum (Address: 0x6baf8e14)
- isprint (Address: 0x6baf8e18)
- isspace (Address: 0x6baf8e1c)
- isxdigit (Address: 0x6baf8e20)
- strcmp (Address: 0x6baf8e24)
- strlen (Address: 0x6baf8e28)
- strncmp (Address: 0x6baf8e2c)
- strncpy_s (Address: 0x6baf8e30)
- strpbrk (Address: 0x6baf8e34)
- tolower (Address: 0x6baf8e38)
- wcslen (Address: 0x6baf8e3c)
api-ms-win-crt-time-l1-1-0.dll
- _localtime64_s (Address: 0x6baf8dec)
- _mktime64 (Address: 0x6baf8df0)
- _time64 (Address: 0x6baf8df4)
- strftime (Address: 0x6baf8df8)
api-ms-win-crt-utility-l1-1-0.dll
- _byteswap_ulong (Address: 0x6baf8d74)
- rand (Address: 0x6baf8d78)
- srand (Address: 0x6baf8d7c)
CRYPT32.dll
- CertGetNameStringA (Address: 0x6baf8d14)
KERNEL32.dll
- CloseHandle (Address: 0x6baf8aac)
- CreateEventW (Address: 0x6baf8ab0)
- CreateFileA (Address: 0x6baf8ab4)
- CreateFileMappingA (Address: 0x6baf8ab8)
- CreateFileW (Address: 0x6baf8abc)
- CreateMutexA (Address: 0x6baf8ac0)
- CreateThread (Address: 0x6baf8ac4)
- CreateToolhelp32Snapshot (Address: 0x6baf8ac8)
- DeleteCriticalSection (Address: 0x6baf8acc)
- DeviceIoControl (Address: 0x6baf8ad0)
- EnterCriticalSection (Address: 0x6baf8ad4)
- FreeLibrary (Address: 0x6baf8ad8)
- GetComputerNameA (Address: 0x6baf8adc)
- GetCurrentProcess (Address: 0x6baf8ae0)
- GetCurrentProcessId (Address: 0x6baf8ae4)
- GetCurrentThread (Address: 0x6baf8ae8)
- GetCurrentThreadId (Address: 0x6baf8aec)
- GetDiskFreeSpaceA (Address: 0x6baf8af0)
- GetDriveTypeA (Address: 0x6baf8af4)
- GetLastError (Address: 0x6baf8af8)
- GetLocalTime (Address: 0x6baf8afc)
- GetModuleFileNameA (Address: 0x6baf8b00)
- GetModuleHandleA (Address: 0x6baf8b04)
- GetModuleHandleW (Address: 0x6baf8b08)
- GetNativeSystemInfo (Address: 0x6baf8b0c)
- GetPrivateProfileStringA (Address: 0x6baf8b10)
- GetProcAddress (Address: 0x6baf8b14)
- GetProcessHeap (Address: 0x6baf8b18)
- GetSystemDefaultLCID (Address: 0x6baf8b1c)
- GetSystemDirectoryA (Address: 0x6baf8b20)
- GetSystemFirmwareTable (Address: 0x6baf8b24)
- GetSystemInfo (Address: 0x6baf8b28)
- GetSystemTimeAsFileTime (Address: 0x6baf8b2c)
- GetThreadContext (Address: 0x6baf8b30)
- GetTickCount64 (Address: 0x6baf8b34)
- GetTimeZoneInformation (Address: 0x6baf8b38)
- GetVersionExA (Address: 0x6baf8b3c)
- GlobalMemoryStatusEx (Address: 0x6baf8b40)
- HeapAlloc (Address: 0x6baf8b44)
- HeapFree (Address: 0x6baf8b48)
- InitializeCriticalSection (Address: 0x6baf8b4c)
- InitializeCriticalSectionAndSpinCount (Address: 0x6baf8b50)
- InitializeSListHead (Address: 0x6baf8b54)
- IsBadCodePtr (Address: 0x6baf8b58)
- IsDebuggerPresent (Address: 0x6baf8b5c)
- IsProcessorFeaturePresent (Address: 0x6baf8b60)
- K32EnumProcessModules (Address: 0x6baf8b64)
- K32GetModuleFileNameExA (Address: 0x6baf8b68)
- LeaveCriticalSection (Address: 0x6baf8b6c)
- LoadLibraryA (Address: 0x6baf8b70)
- MapViewOfFile (Address: 0x6baf8b74)
- MultiByteToWideChar (Address: 0x6baf8b78)
- OpenFileMappingA (Address: 0x6baf8b7c)
- OpenMutexA (Address: 0x6baf8b80)
- OpenProcess (Address: 0x6baf8b84)
- Process32First (Address: 0x6baf8b88)
- Process32Next (Address: 0x6baf8b8c)
- QueryDosDeviceA (Address: 0x6baf8b90)
- QueryPerformanceCounter (Address: 0x6baf8b94)
- ReadFile (Address: 0x6baf8b98)
- ResetEvent (Address: 0x6baf8b9c)
- SetEvent (Address: 0x6baf8ba0)
- SetUnhandledExceptionFilter (Address: 0x6baf8ba4)
- Sleep (Address: 0x6baf8ba8)
- TerminateProcess (Address: 0x6baf8bac)
- UnhandledExceptionFilter (Address: 0x6baf8bb0)
- WaitForSingleObjectEx (Address: 0x6baf8bb4)
- WideCharToMultiByte (Address: 0x6baf8bb8)
- WriteFile (Address: 0x6baf8bbc)
MSVCP140.dll
- _Mtx_destroy_in_situ (Address: 0x6baf8c80)
- _Mtx_init_in_situ (Address: 0x6baf8c84)
- _Mtx_lock (Address: 0x6baf8c88)
- _Mtx_unlock (Address: 0x6baf8c8c)
- _Xtime_get_ticks (Address: 0x6baf8c90)
- ?_Lock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ (Address: 0x6baf8c2c)
- ?_Osfx@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEXXZ (Address: 0x6baf8c30)
- ?_Throw_C_error@std@@YAXH@Z (Address: 0x6baf8c34)
- ?_Unlock@?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAEXXZ (Address: 0x6baf8c38)
- ?_Xbad_function_call@std@@YAXXZ (Address: 0x6baf8c3c)
- ?_Xlength_error@std@@YAXPBD@Z (Address: 0x6baf8c40)
- ?_Xout_of_range@std@@YAXPBD@Z (Address: 0x6baf8c44)
- ??0?$basic_streambuf@DU?$char_traits@D@std@@@std@@IAE@XZ (Address: 0x6baf8c14)
- ??0ios_base@std@@IAE@XZ (Address: 0x6baf8c18)
- ??1?$basic_streambuf@DU?$char_traits@D@std@@@std@@UAE@XZ (Address: 0x6baf8c1c)
- ??1ios_base@std@@UAE@XZ (Address: 0x6baf8c20)
- ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@H@Z (Address: 0x6baf8c24)
- ??6?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV01@I@Z (Address: 0x6baf8c28)
- ?clear@?$basic_ios@DU?$char_traits@D@std@@@std@@QAEXH_N@Z (Address: 0x6baf8c48)
- ?flush@?$basic_ostream@DU?$char_traits@D@std@@@std@@QAEAAV12@XZ (Address: 0x6baf8c4c)
- ?good@ios_base@std@@QBE_NXZ (Address: 0x6baf8c50)
- ?imbue@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEXABVlocale@2@@Z (Address: 0x6baf8c54)
- ?init@?$basic_ios@DU?$char_traits@D@std@@@std@@IAEXPAV?$basic_streambuf@DU?$char_traits@D@std@@@2@_N@Z (Address: 0x6baf8c58)
- ?setbuf@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEPAV12@PAD_J@Z (Address: 0x6baf8c5c)
- ?setw@std@@YA?AU?$_Smanip@_J@1@_J@Z (Address: 0x6baf8c60)
- ?showmanyc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JXZ (Address: 0x6baf8c64)
- ?sputc@?$basic_streambuf@DU?$char_traits@D@std@@@std@@QAEHD@Z (Address: 0x6baf8c68)
- ?sync@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ (Address: 0x6baf8c6c)
- ?uflow@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAEHXZ (Address: 0x6baf8c70)
- ?uncaught_exceptions@std@@YAHXZ (Address: 0x6baf8c74)
- ?xsgetn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPAD_J@Z (Address: 0x6baf8c78)
- ?xsputn@?$basic_streambuf@DU?$char_traits@D@std@@@std@@MAE_JPBD_J@Z (Address: 0x6baf8c7c)
NETAPI32.dll
- Netbios (Address: 0x6baf8c98)
ole32.dll
- CoCreateGuid (Address: 0x6baf8c04)
- CoInitialize (Address: 0x6baf8c08)
- CoUninitialize (Address: 0x6baf8c0c)
SETUPAPI.dll
- SetupDiDestroyDeviceInfoList (Address: 0x6baf8cc0)
- SetupDiEnumDeviceInfo (Address: 0x6baf8cc4)
- SetupDiGetClassDevsA (Address: 0x6baf8cc8)
- SetupDiGetDevicePropertyW (Address: 0x6baf8ccc)
- SetupDiGetDeviceRegistryPropertyA (Address: 0x6baf8cd0)
SHELL32.dll
- (Address: 0x6baf8bc4)
- SHGetFolderPathA (Address: 0x6baf8bc8)
- SHGetSpecialFolderPathA (Address: 0x6baf8bcc)
SHLWAPI.dll
- PathAppendA (Address: 0x6baf8ca0)
- PathFileExistsA (Address: 0x6baf8ca4)
USER32.dll
- GetCursorPos (Address: 0x6baf8a90)
- GetForegroundWindow (Address: 0x6baf8a94)
- GetKeyboardLayoutList (Address: 0x6baf8a98)
- GetKeyboardType (Address: 0x6baf8a9c)
- GetSystemMetrics (Address: 0x6baf8aa0)
- GetWindowTextA (Address: 0x6baf8aa4)
VCRUNTIME140.dll
- __CxxFrameHandler3 (Address: 0x6baf8d3c)
- __std_exception_copy (Address: 0x6baf8d40)
- __std_exception_destroy (Address: 0x6baf8d44)
- __std_terminate (Address: 0x6baf8d48)
- __std_type_info_destroy_list (Address: 0x6baf8d4c)
- _CxxThrowException (Address: 0x6baf8d38)
- _except_handler4_common (Address: 0x6baf8d50)
- _purecall (Address: 0x6baf8d54)
- memchr (Address: 0x6baf8d58)
- memcmp (Address: 0x6baf8d5c)
- memcpy (Address: 0x6baf8d60)
- memmove (Address: 0x6baf8d64)
- memset (Address: 0x6baf8d68)
- strstr (Address: 0x6baf8d6c)
VERSION.dll
- GetFileVersionInfoA (Address: 0x6baf8cd8)
- GetFileVersionInfoSizeA (Address: 0x6baf8cdc)
- VerQueryValueA (Address: 0x6baf8ce0)
WININET.dll
- HttpOpenRequestA (Address: 0x6baf8d1c)
- HttpSendRequestA (Address: 0x6baf8d20)
- InternetCloseHandle (Address: 0x6baf8d24)
- InternetConnectA (Address: 0x6baf8d28)
- InternetOpenA (Address: 0x6baf8d2c)
- InternetReadFile (Address: 0x6baf8d30)
WINTRUST.dll
- CryptCATAdminAcquireContext (Address: 0x6baf8ce8)
- CryptCATAdminCalcHashFromFileHandle (Address: 0x6baf8cec)
- CryptCATAdminEnumCatalogFromHash (Address: 0x6baf8cf0)
- CryptCATAdminReleaseCatalogContext (Address: 0x6baf8cf4)
- CryptCATAdminReleaseContext (Address: 0x6baf8cf8)
- CryptCATCatalogInfoFromContext (Address: 0x6baf8cfc)
- WinVerifyTrust (Address: 0x6baf8d0c)
- WTHelperGetProvCertFromChain (Address: 0x6baf8d00)
- WTHelperGetProvSignerFromChain (Address: 0x6baf8d04)
- WTHelperProvDataFromStateData (Address: 0x6baf8d08)
WS2_32.dll
- gethostbyname (Address: 0x6baf8cb0)
- gethostname (Address: 0x6baf8cb4)
- inet_ntoa (Address: 0x6baf8cb8)
- WSAStartup (Address: 0x6baf8cac)