tapisrv.dll
Description: Microsoft® Windows(TM) Telephony Server
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6157
Architecture: 64-bit
Operating System: Windows NT
SHA256: a58d84e2666fe33792b98e70edd2d2bf
File Size: 310.5 KB
Uploaded At: Dec. 1, 2025, 7:40 a.m.
Views: 20
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- ServiceMain (Ordinal: 1, Address: 0x254f0)
- SvchostPushServiceGlobals (Ordinal: 2, Address: 0x252a0)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x18003e560)
- CoInitializeEx (Address: 0x18003e558)
- CoUninitialize (Address: 0x18003e550)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x18003e5c0)
- RegCreateKeyExW (Address: 0x18003e590)
- RegDeleteKeyExW (Address: 0x18003e5c8)
- RegDeleteValueW (Address: 0x18003e5b0)
- RegEnumKeyExW (Address: 0x18003e588)
- RegEnumValueW (Address: 0x18003e5b8)
- RegNotifyChangeKeyValue (Address: 0x18003e5a8)
- RegOpenCurrentUser (Address: 0x18003e5d0)
- RegOpenKeyExA (Address: 0x18003e5a0)
- RegOpenKeyExW (Address: 0x18003e570)
- RegQueryInfoKeyW (Address: 0x18003e5d8)
- RegQueryValueExA (Address: 0x18003e598)
- RegQueryValueExW (Address: 0x18003e578)
- RegSetValueExW (Address: 0x18003e580)
api-ms-win-service-core-l1-1-0.dll
- SetServiceStatus (Address: 0x18003e5e8)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x18003e5f8)
- OpenSCManagerW (Address: 0x18003e600)
- OpenServiceW (Address: 0x18003e608)
api-ms-win-service-management-l2-1-0.dll
- ChangeServiceConfigW (Address: 0x18003e618)
api-ms-win-service-winsvc-l1-1-0.dll
- RegisterServiceCtrlHandlerW (Address: 0x18003e628)
KERNEL32.dll
- CloseHandle (Address: 0x18003e460)
- CompareStringW (Address: 0x18003e498)
- CreateEventW (Address: 0x18003e388)
- CreateFileMappingW (Address: 0x18003e2b8)
- CreateFileW (Address: 0x18003e3b8)
- CreateMutexW (Address: 0x18003e410)
- CreateThread (Address: 0x18003e368)
- DelayLoadFailureHook (Address: 0x18003e200)
- DeleteCriticalSection (Address: 0x18003e338)
- DeleteFileW (Address: 0x18003e220)
- DisableThreadLibraryCalls (Address: 0x18003e380)
- DuplicateHandle (Address: 0x18003e438)
- EnterCriticalSection (Address: 0x18003e3f8)
- ExitThread (Address: 0x18003e398)
- FileTimeToSystemTime (Address: 0x18003e2a0)
- FindClose (Address: 0x18003e300)
- FindFirstFileW (Address: 0x18003e318)
- FindNextFileW (Address: 0x18003e310)
- FreeLibrary (Address: 0x18003e470)
- GetComputerNameExW (Address: 0x18003e3a0)
- GetComputerNameW (Address: 0x18003e330)
- GetCurrentDirectoryW (Address: 0x18003e2d0)
- GetCurrentProcess (Address: 0x18003e3f0)
- GetCurrentProcessId (Address: 0x18003e230)
- GetCurrentThread (Address: 0x18003e378)
- GetCurrentThreadId (Address: 0x18003e428)
- GetFileAttributesExW (Address: 0x18003e2e0)
- GetFileSize (Address: 0x18003e2c8)
- GetLastError (Address: 0x18003e450)
- GetLocalTime (Address: 0x18003e270)
- GetPrivateProfileIntW (Address: 0x18003e3d8)
- GetPrivateProfileSectionNamesW (Address: 0x18003e3a8)
- GetPrivateProfileSectionW (Address: 0x18003e308)
- GetPrivateProfileStringW (Address: 0x18003e2e8)
- GetProcAddress (Address: 0x18003e340)
- GetProcessHeap (Address: 0x18003e328)
- GetSystemDirectoryW (Address: 0x18003e2f8)
- GetSystemInfo (Address: 0x18003e370)
- GetSystemTime (Address: 0x18003e1f8)
- GetSystemTimeAsFileTime (Address: 0x18003e288)
- GetSystemWindowsDirectoryW (Address: 0x18003e2a8)
- GetTickCount (Address: 0x18003e480)
- GetWindowsDirectoryW (Address: 0x18003e210)
- GlobalAlloc (Address: 0x18003e228)
- GlobalFree (Address: 0x18003e218)
- HeapAlloc (Address: 0x18003e358)
- HeapCompact (Address: 0x18003e350)
- HeapCreate (Address: 0x18003e488)
- HeapDestroy (Address: 0x18003e348)
- HeapFree (Address: 0x18003e478)
- InitializeCriticalSectionAndSpinCount (Address: 0x18003e3c0)
- IsDBCSLeadByte (Address: 0x18003e2d8)
- K32EnumProcesses (Address: 0x18003e298)
- LeaveCriticalSection (Address: 0x18003e408)
- LoadLibraryW (Address: 0x18003e468)
- LocalAlloc (Address: 0x18003e420)
- LocalFree (Address: 0x18003e290)
- lstrcmpiW (Address: 0x18003e320)
- lstrlenA (Address: 0x18003e278)
- lstrlenW (Address: 0x18003e400)
- MapViewOfFile (Address: 0x18003e2b0)
- MultiByteToWideChar (Address: 0x18003e440)
- OpenEventW (Address: 0x18003e3b0)
- OpenProcess (Address: 0x18003e390)
- OutputDebugStringA (Address: 0x18003e280)
- QueryPerformanceCounter (Address: 0x18003e238)
- ReleaseMutex (Address: 0x18003e430)
- ResetEvent (Address: 0x18003e360)
- ResolveDelayLoadedAPI (Address: 0x18003e208)
- RtlCaptureContext (Address: 0x18003e268)
- RtlLookupFunctionEntry (Address: 0x18003e260)
- RtlVirtualUnwind (Address: 0x18003e258)
- SetEvent (Address: 0x18003e458)
- SetThreadPriority (Address: 0x18003e3c8)
- SetUnhandledExceptionFilter (Address: 0x18003e248)
- Sleep (Address: 0x18003e448)
- TerminateProcess (Address: 0x18003e240)
- UnhandledExceptionFilter (Address: 0x18003e250)
- UnmapViewOfFile (Address: 0x18003e2f0)
- UnregisterWait (Address: 0x18003e3e0)
- WaitForMultipleObjects (Address: 0x18003e3d0)
- WaitForSingleObject (Address: 0x18003e418)
- WriteFile (Address: 0x18003e3e8)
- WritePrivateProfileSectionW (Address: 0x18003e2c0)
- WritePrivateProfileStringW (Address: 0x18003e490)
msvcrt.dll
- __C_specific_handler (Address: 0x18003e6b8)
- _amsg_exit (Address: 0x18003e658)
- _initterm (Address: 0x18003e640)
- _itow (Address: 0x18003e670)
- _vsnprintf (Address: 0x18003e648)
- _vsnwprintf (Address: 0x18003e6b0)
- _wcsicmp (Address: 0x18003e6a8)
- _wcsnicmp (Address: 0x18003e678)
- _wcsupr (Address: 0x18003e6a0)
- _wtol (Address: 0x18003e688)
- _XcptFilter (Address: 0x18003e668)
- free (Address: 0x18003e638)
- malloc (Address: 0x18003e660)
- memcpy (Address: 0x18003e6c0)
- memmove (Address: 0x18003e650)
- memset (Address: 0x18003e6c8)
- wcschr (Address: 0x18003e698)
- wcsncmp (Address: 0x18003e680)
- wcsstr (Address: 0x18003e690)
RPCRT4.dll
- I_RpcExceptionFilter (Address: 0x18003e4e8)
- NdrClientCall3 (Address: 0x18003e508)
- NdrServerCall2 (Address: 0x18003e4f8)
- NdrServerCallAll (Address: 0x18003e500)
- RpcBindingFree (Address: 0x18003e520)
- RpcBindingFromStringBindingW (Address: 0x18003e4b8)
- RpcBindingSetAuthInfoW (Address: 0x18003e4d0)
- RpcCancelThread (Address: 0x18003e510)
- RpcImpersonateClient (Address: 0x18003e540)
- RpcMgmtSetCancelTimeout (Address: 0x18003e4c0)
- RpcRevertToSelf (Address: 0x18003e4c8)
- RpcServerInqCallAttributesW (Address: 0x18003e518)
- RpcServerInqDefaultPrincNameW (Address: 0x18003e4b0)
- RpcServerListen (Address: 0x18003e530)
- RpcServerRegisterAuthInfoW (Address: 0x18003e528)
- RpcServerRegisterIfEx (Address: 0x18003e538)
- RpcServerUnregisterIf (Address: 0x18003e4d8)
- RpcServerUseProtseqEpW (Address: 0x18003e4a8)
- RpcStringBindingComposeW (Address: 0x18003e4e0)
- RpcStringFreeW (Address: 0x18003e4f0)