tapisrv.dll

Description: Microsoft® Windows(TM) Telephony Server

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6157

Architecture: 32-bit

Operating System: Windows NT

SHA256: 4e0930e289d6191433bba79600c91527

File Size: 246.5 KB

Uploaded At: Dec. 1, 2025, 8:04 a.m.

Views: 12

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • ServiceMain (Ordinal: 1, Address: 0x26430)
  • SvchostPushServiceGlobals (Ordinal: 2, Address: 0x26240)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x1003b1a4)
  • CoInitializeEx (Address: 0x1003b1a0)
  • CoUninitialize (Address: 0x1003b19c)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1003b1d4)
  • RegCreateKeyExW (Address: 0x1003b1bc)
  • RegDeleteKeyExW (Address: 0x1003b1d8)
  • RegDeleteValueW (Address: 0x1003b1cc)
  • RegEnumKeyExW (Address: 0x1003b1b8)
  • RegEnumValueW (Address: 0x1003b1d0)
  • RegNotifyChangeKeyValue (Address: 0x1003b1c8)
  • RegOpenCurrentUser (Address: 0x1003b1dc)
  • RegOpenKeyExA (Address: 0x1003b1c4)
  • RegOpenKeyExW (Address: 0x1003b1ac)
  • RegQueryInfoKeyW (Address: 0x1003b1e0)
  • RegQueryValueExA (Address: 0x1003b1c0)
  • RegQueryValueExW (Address: 0x1003b1b0)
  • RegSetValueExW (Address: 0x1003b1b4)
api-ms-win-service-core-l1-1-0.dll
  • SetServiceStatus (Address: 0x1003b1e8)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x1003b1f0)
  • OpenSCManagerW (Address: 0x1003b1f4)
  • OpenServiceW (Address: 0x1003b1f8)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfigW (Address: 0x1003b200)
api-ms-win-service-winsvc-l1-1-0.dll
  • RegisterServiceCtrlHandlerW (Address: 0x1003b208)
KERNEL32.dll
  • CloseHandle (Address: 0x1003b130)
  • CompareStringW (Address: 0x1003b0f8)
  • CreateEventW (Address: 0x1003b0bc)
  • CreateFileMappingW (Address: 0x1003b054)
  • CreateFileW (Address: 0x1003b0d4)
  • CreateMutexW (Address: 0x1003b108)
  • CreateThread (Address: 0x1003b0ac)
  • DelayLoadFailureHook (Address: 0x1003b004)
  • DeleteCriticalSection (Address: 0x1003b094)
  • DeleteFileW (Address: 0x1003b014)
  • DisableThreadLibraryCalls (Address: 0x1003b0b8)
  • DuplicateHandle (Address: 0x1003b11c)
  • EnterCriticalSection (Address: 0x1003b0fc)
  • ExitThread (Address: 0x1003b0c4)
  • FileTimeToSystemTime (Address: 0x1003b048)
  • FindClose (Address: 0x1003b078)
  • FindFirstFileW (Address: 0x1003b084)
  • FindNextFileW (Address: 0x1003b080)
  • FreeLibrary (Address: 0x1003b000)
  • GetComputerNameExW (Address: 0x1003b0c8)
  • GetComputerNameW (Address: 0x1003b090)
  • GetCurrentDirectoryW (Address: 0x1003b060)
  • GetCurrentProcess (Address: 0x1003b0f0)
  • GetCurrentProcessId (Address: 0x1003b01c)
  • GetCurrentThread (Address: 0x1003b0b4)
  • GetCurrentThreadId (Address: 0x1003b114)
  • GetFileAttributesExW (Address: 0x1003b068)
  • GetFileSize (Address: 0x1003b05c)
  • GetLastError (Address: 0x1003b128)
  • GetLocalTime (Address: 0x1003b030)
  • GetPrivateProfileIntW (Address: 0x1003b0e4)
  • GetPrivateProfileSectionNamesW (Address: 0x1003b0cc)
  • GetPrivateProfileSectionW (Address: 0x1003b07c)
  • GetPrivateProfileStringW (Address: 0x1003b06c)
  • GetProcAddress (Address: 0x1003b098)
  • GetProcessHeap (Address: 0x1003b08c)
  • GetSystemDirectoryW (Address: 0x1003b074)
  • GetSystemInfo (Address: 0x1003b0b0)
  • GetSystemTime (Address: 0x1003b13c)
  • GetSystemTimeAsFileTime (Address: 0x1003b03c)
  • GetSystemWindowsDirectoryW (Address: 0x1003b04c)
  • GetTickCount (Address: 0x1003b140)
  • GetWindowsDirectoryW (Address: 0x1003b00c)
  • GlobalAlloc (Address: 0x1003b018)
  • GlobalFree (Address: 0x1003b010)
  • HeapAlloc (Address: 0x1003b0a4)
  • HeapCompact (Address: 0x1003b0a0)
  • HeapCreate (Address: 0x1003b144)
  • HeapDestroy (Address: 0x1003b09c)
  • HeapFree (Address: 0x1003b0f4)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1003b0d8)
  • IsDBCSLeadByte (Address: 0x1003b064)
  • K32EnumProcesses (Address: 0x1003b044)
  • LeaveCriticalSection (Address: 0x1003b104)
  • LoadLibraryW (Address: 0x1003b134)
  • LocalAlloc (Address: 0x1003b110)
  • LocalFree (Address: 0x1003b040)
  • lstrcmpiW (Address: 0x1003b088)
  • lstrlenA (Address: 0x1003b034)
  • lstrlenW (Address: 0x1003b100)
  • MapViewOfFile (Address: 0x1003b050)
  • MultiByteToWideChar (Address: 0x1003b120)
  • OpenEventW (Address: 0x1003b0d0)
  • OpenProcess (Address: 0x1003b0c0)
  • OutputDebugStringA (Address: 0x1003b038)
  • QueryPerformanceCounter (Address: 0x1003b020)
  • ReleaseMutex (Address: 0x1003b118)
  • ResetEvent (Address: 0x1003b0a8)
  • ResolveDelayLoadedAPI (Address: 0x1003b008)
  • SetEvent (Address: 0x1003b12c)
  • SetThreadPriority (Address: 0x1003b0dc)
  • SetUnhandledExceptionFilter (Address: 0x1003b028)
  • Sleep (Address: 0x1003b124)
  • TerminateProcess (Address: 0x1003b024)
  • UnhandledExceptionFilter (Address: 0x1003b02c)
  • UnmapViewOfFile (Address: 0x1003b070)
  • UnregisterWait (Address: 0x1003b0e8)
  • WaitForMultipleObjects (Address: 0x1003b0e0)
  • WaitForSingleObject (Address: 0x1003b10c)
  • WriteFile (Address: 0x1003b0ec)
  • WritePrivateProfileSectionW (Address: 0x1003b058)
  • WritePrivateProfileStringW (Address: 0x1003b138)
msvcrt.dll
  • _amsg_exit (Address: 0x1003b228)
  • _except_handler4_common (Address: 0x1003b214)
  • _initterm (Address: 0x1003b224)
  • _itow (Address: 0x1003b22c)
  • _vsnprintf (Address: 0x1003b230)
  • _vsnwprintf (Address: 0x1003b250)
  • _wcsicmp (Address: 0x1003b24c)
  • _wcsnicmp (Address: 0x1003b234)
  • _wcsupr (Address: 0x1003b248)
  • _wtol (Address: 0x1003b23c)
  • _XcptFilter (Address: 0x1003b218)
  • free (Address: 0x1003b220)
  • malloc (Address: 0x1003b210)
  • memcpy (Address: 0x1003b254)
  • memmove (Address: 0x1003b21c)
  • memset (Address: 0x1003b258)
  • wcschr (Address: 0x1003b244)
  • wcsncmp (Address: 0x1003b238)
  • wcsstr (Address: 0x1003b240)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x1003b16c)
  • NdrClientCall4 (Address: 0x1003b178)
  • NdrServerCall2 (Address: 0x1003b174)
  • RpcBindingFree (Address: 0x1003b184)
  • RpcBindingFromStringBindingW (Address: 0x1003b154)
  • RpcBindingSetAuthInfoW (Address: 0x1003b160)
  • RpcCancelThread (Address: 0x1003b17c)
  • RpcImpersonateClient (Address: 0x1003b194)
  • RpcMgmtSetCancelTimeout (Address: 0x1003b158)
  • RpcRevertToSelf (Address: 0x1003b15c)
  • RpcServerInqCallAttributesW (Address: 0x1003b180)
  • RpcServerInqDefaultPrincNameW (Address: 0x1003b150)
  • RpcServerListen (Address: 0x1003b18c)
  • RpcServerRegisterAuthInfoW (Address: 0x1003b188)
  • RpcServerRegisterIfEx (Address: 0x1003b190)
  • RpcServerUnregisterIf (Address: 0x1003b164)
  • RpcServerUseProtseqEpW (Address: 0x1003b14c)
  • RpcStringBindingComposeW (Address: 0x1003b168)
  • RpcStringFreeW (Address: 0x1003b170)