Search.ProtocolHandler.MAPI2.dll

Description: Microsoft Search Protocol Handler for MAPI2

Authors: © Microsoft Corporation. All rights reserved.

Version: 7.0.19041.6456

Architecture: 32-bit

Operating System: Windows NT

SHA256: 0d89ab5fc3b0c5495cefa791f5949652

File Size: 297.0 KB

Uploaded At: Dec. 1, 2025, 8:04 a.m.

Views: 21

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x10a20)
  • DllGetClassObject (Ordinal: 2, Address: 0x10a40)
  • DllRegisterServer (Ordinal: 3, Address: 0x10a50)
  • DllUnregisterServer (Ordinal: 4, Address: 0x10ab0)

Imported DLLs & Functions

api-ms-win-core-com-l2-1-1.dll
  • StgOpenStorageOnILockBytes (Address: 0x60046028)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x6004603c)
  • IsDebuggerPresent (Address: 0x60046030)
  • OutputDebugStringA (Address: 0x60046038)
  • OutputDebugStringW (Address: 0x60046034)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x60046044)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x6004604c)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x60046060)
  • RaiseException (Address: 0x60046064)
  • SetLastError (Address: 0x6004605c)
  • SetUnhandledExceptionFilter (Address: 0x60046054)
  • UnhandledExceptionFilter (Address: 0x60046058)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x6004608c)
  • DeleteFileW (Address: 0x6004606c)
  • FileTimeToLocalFileTime (Address: 0x60046070)
  • FindClose (Address: 0x60046088)
  • FindFirstFileW (Address: 0x60046084)
  • FindNextFileW (Address: 0x6004607c)
  • FlushFileBuffers (Address: 0x60046080)
  • GetFileSize (Address: 0x60046078)
  • WriteFile (Address: 0x60046074)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x60046098)
  • DuplicateHandle (Address: 0x60046094)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x600460b4)
  • HeapAlloc (Address: 0x600460a8)
  • HeapDestroy (Address: 0x600460a0)
  • HeapFree (Address: 0x600460a4)
  • HeapReAlloc (Address: 0x600460ac)
  • HeapSize (Address: 0x600460b0)
api-ms-win-core-heap-l2-1-0.dll
  • GlobalAlloc (Address: 0x600460c4)
  • GlobalFree (Address: 0x600460c8)
  • LocalAlloc (Address: 0x600460bc)
  • LocalFree (Address: 0x600460c0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • MoveFileW (Address: 0x600460d0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x600460ec)
  • FindResourceExW (Address: 0x600460fc)
  • FreeLibrary (Address: 0x600460f0)
  • GetModuleFileNameA (Address: 0x60046108)
  • GetModuleFileNameW (Address: 0x600460f4)
  • GetModuleHandleExW (Address: 0x600460e8)
  • GetModuleHandleW (Address: 0x600460dc)
  • GetProcAddress (Address: 0x600460e4)
  • LoadLibraryExW (Address: 0x600460f8)
  • LoadResource (Address: 0x60046100)
  • LoadStringW (Address: 0x600460e0)
  • LockResource (Address: 0x600460d8)
  • SizeofResource (Address: 0x60046104)
api-ms-win-core-libraryloader-l1-2-1.dll
  • LoadLibraryW (Address: 0x60046110)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x6004611c)
  • GetLocaleInfoW (Address: 0x60046118)
  • GetSystemDefaultLCID (Address: 0x60046120)
  • IsValidCodePage (Address: 0x60046124)
api-ms-win-core-localization-obsolete-l1-2-0.dll
  • GetSystemDefaultUILanguage (Address: 0x60046130)
  • GetUserDefaultUILanguage (Address: 0x6004612c)
api-ms-win-core-memory-l1-1-0.dll
  • CreateFileMappingW (Address: 0x60046138)
  • MapViewOfFile (Address: 0x6004613c)
  • OpenFileMappingW (Address: 0x60046144)
  • UnmapViewOfFile (Address: 0x60046140)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x6004614c)
  • SearchPathW (Address: 0x60046150)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x60046164)
  • GetCurrentProcess (Address: 0x6004616c)
  • GetCurrentProcessId (Address: 0x60046170)
  • GetCurrentThreadId (Address: 0x60046160)
  • OpenProcessToken (Address: 0x60046168)
  • SetPriorityClass (Address: 0x6004615c)
  • TerminateProcess (Address: 0x60046158)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x60046178)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x60046180)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x600461a8)
  • RegCreateKeyExW (Address: 0x6004618c)
  • RegDeleteKeyExW (Address: 0x600461ac)
  • RegDeleteValueW (Address: 0x60046188)
  • RegEnumKeyExW (Address: 0x60046194)
  • RegEnumValueW (Address: 0x60046198)
  • RegGetValueW (Address: 0x600461a0)
  • RegOpenKeyExW (Address: 0x600461a4)
  • RegQueryInfoKeyW (Address: 0x6004619c)
  • RegQueryValueExW (Address: 0x600461b0)
  • RegSetValueExW (Address: 0x60046190)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
  • StrCmpNIA (Address: 0x600461b8)
  • StrCmpNIW (Address: 0x600461bc)
api-ms-win-core-string-l1-1-0.dll
  • CompareStringOrdinal (Address: 0x600461c8)
  • CompareStringW (Address: 0x600461c4)
  • MultiByteToWideChar (Address: 0x600461d0)
  • WideCharToMultiByte (Address: 0x600461cc)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x600461d8)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x600461e0)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x60046230)
  • AcquireSRWLockShared (Address: 0x60046210)
  • CreateEventW (Address: 0x600461f4)
  • CreateMutexExW (Address: 0x60046224)
  • CreateSemaphoreExW (Address: 0x600461f0)
  • DeleteCriticalSection (Address: 0x600461fc)
  • EnterCriticalSection (Address: 0x60046204)
  • InitializeCriticalSection (Address: 0x600461ec)
  • InitializeCriticalSectionEx (Address: 0x6004620c)
  • LeaveCriticalSection (Address: 0x6004622c)
  • OpenMutexW (Address: 0x600461f8)
  • OpenSemaphoreW (Address: 0x60046220)
  • ReleaseMutex (Address: 0x60046214)
  • ReleaseSemaphore (Address: 0x60046200)
  • ReleaseSRWLockExclusive (Address: 0x6004621c)
  • ReleaseSRWLockShared (Address: 0x60046228)
  • SetEvent (Address: 0x600461e8)
  • WaitForSingleObject (Address: 0x60046208)
  • WaitForSingleObjectEx (Address: 0x60046218)
api-ms-win-core-synch-l1-2-0.dll
  • InitOnceExecuteOnce (Address: 0x6004623c)
  • Sleep (Address: 0x60046244)
  • SleepConditionVariableSRW (Address: 0x60046240)
  • WakeAllConditionVariable (Address: 0x60046238)
api-ms-win-core-synch-l1-2-1.dll
  • CreateSemaphoreW (Address: 0x6004624c)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x6004625c)
  • GetTickCount (Address: 0x60046254)
  • GetVersionExW (Address: 0x60046258)
api-ms-win-core-threadpool-l1-2-0.dll
  • CloseThreadpoolTimer (Address: 0x60046264)
  • CreateThreadpoolTimer (Address: 0x60046268)
  • SetThreadpoolTimer (Address: 0x6004626c)
  • WaitForThreadpoolTimerCallbacks (Address: 0x60046270)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x60046278)
api-ms-win-core-version-l1-1-0.dll
  • GetFileVersionInfoExW (Address: 0x60046284)
  • GetFileVersionInfoSizeExW (Address: 0x60046288)
  • VerQueryValueW (Address: 0x60046280)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventProviderEnabled (Address: 0x6004629c)
  • EventRegister (Address: 0x600462a0)
  • EventSetInformation (Address: 0x60046298)
  • EventUnregister (Address: 0x60046294)
  • EventWriteTransfer (Address: 0x60046290)
api-ms-win-rtcore-ntuser-synch-l1-1-0.dll
  • MsgWaitForMultipleObjects (Address: 0x600462a8)
api-ms-win-rtcore-ntuser-window-l1-1-0.dll
  • DispatchMessageW (Address: 0x600462b8)
  • PeekMessageW (Address: 0x600462b0)
  • TranslateMessage (Address: 0x600462b4)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x60046334)
  • __dllonexit (Address: 0x60046344)
  • _amsg_exit (Address: 0x600462fc)
  • _CxxThrowException (Address: 0x600462f4)
  • _errno (Address: 0x60046358)
  • _except_handler4_common (Address: 0x60046350)
  • _ftol2 (Address: 0x60046380)
  • _initterm (Address: 0x6004630c)
  • _localtime64 (Address: 0x600462f8)
  • _lock (Address: 0x6004633c)
  • _ltow (Address: 0x600462d8)
  • _mktime64 (Address: 0x600462dc)
  • _onexit (Address: 0x60046348)
  • _purecall (Address: 0x60046310)
  • _time64 (Address: 0x600462f0)
  • _unlock (Address: 0x60046340)
  • _vscwprintf (Address: 0x60046308)
  • _vsnprintf (Address: 0x600462e0)
  • _vsnprintf_s (Address: 0x6004632c)
  • _vsnwprintf (Address: 0x60046370)
  • _wcsicmp (Address: 0x60046300)
  • _wcsnicmp (Address: 0x600462cc)
  • _wcsupr (Address: 0x600462d0)
  • _wcsupr_s (Address: 0x60046388)
  • _wtoi (Address: 0x600462c0)
  • _wtol (Address: 0x6004635c)
  • _XcptFilter (Address: 0x60046394)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x60046330)
  • ??0exception@@QAE@XZ (Address: 0x60046338)
  • ??1exception@@UAE@XZ (Address: 0x60046368)
  • ??1type_info@@UAE@XZ (Address: 0x6004634c)
  • ?terminate@@YAXXZ (Address: 0x60046328)
  • bsearch (Address: 0x6004637c)
  • calloc (Address: 0x600462d4)
  • free (Address: 0x60046320)
  • iswdigit (Address: 0x600462c4)
  • iswspace (Address: 0x600462c8)
  • malloc (Address: 0x60046324)
  • memcmp (Address: 0x60046390)
  • memcpy (Address: 0x60046398)
  • memcpy_s (Address: 0x6004636c)
  • memmove (Address: 0x6004638c)
  • memmove_s (Address: 0x60046360)
  • memset (Address: 0x600463a4)
  • realloc (Address: 0x60046374)
  • strrchr (Address: 0x60046304)
  • toupper (Address: 0x6004639c)
  • vswprintf_s (Address: 0x60046354)
  • wcscat_s (Address: 0x60046314)
  • wcschr (Address: 0x60046378)
  • wcscpy_s (Address: 0x6004631c)
  • wcsftime (Address: 0x600462ec)
  • wcsncmp (Address: 0x600463a0)
  • wcsncpy_s (Address: 0x60046318)
  • wcsrchr (Address: 0x60046384)
  • wcsstr (Address: 0x60046364)
  • wcstoul (Address: 0x600462e4)
  • wctomb (Address: 0x600462e8)
ntdll.dll
  • EtwEventRegister (Address: 0x600463bc)
  • EtwEventUnregister (Address: 0x600463b8)
  • EtwEventWriteTransfer (Address: 0x600463b4)
  • RtlGetPersistedStateLocation (Address: 0x600463ac)
  • RtlIsStateSeparationEnabled (Address: 0x600463b0)
  • RtlNtStatusToDosError (Address: 0x600463c0)
OLEAUT32.dll
  • SysAllocString (Address: 0x60046000)
  • SysFreeString (Address: 0x60046014)
  • SysStringLen (Address: 0x60046010)
  • VariantClear (Address: 0x6004600c)
  • VariantInit (Address: 0x60046008)
  • VarUI4FromStr (Address: 0x60046004)
TQUERY.DLL
  • ciDelete (Address: 0x60046020)
  • ciNewNoThrow (Address: 0x6004601c)