EmailApis.dll
Description: DLL for EmailRT
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.4355
Architecture: 64-bit
Operating System: Windows NT
SHA256: 9ca439f2389d865788ca7527522e9a46
File Size: 1.1 MB
Uploaded At: Dec. 1, 2025, 7:27 a.m.
Views: 5
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x4ef0)
- DllGetActivationFactory (Ordinal: 2, Address: 0x5060)
- DllGetClassObject (Ordinal: 3, Address: 0x4f50)
Imported DLLs & Functions
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800e6d18)
- IsDebuggerPresent (Address: 0x1800e6d20)
- OutputDebugStringA (Address: 0x1800e6d10)
- OutputDebugStringW (Address: 0x1800e6d28)
api-ms-win-core-delayload-l1-1-0.dll
- DelayLoadFailureHook (Address: 0x1800e6d38)
api-ms-win-core-delayload-l1-1-1.dll
- ResolveDelayLoadedAPI (Address: 0x1800e6d48)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800e6d68)
- RaiseException (Address: 0x1800e6d70)
- SetLastError (Address: 0x1800e6d58)
- SetUnhandledExceptionFilter (Address: 0x1800e6d78)
- UnhandledExceptionFilter (Address: 0x1800e6d60)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x1800e6dc8)
- CreateFileW (Address: 0x1800e6d88)
- DeleteFileW (Address: 0x1800e6d98)
- FindClose (Address: 0x1800e6da8)
- FindFirstFileW (Address: 0x1800e6db8)
- FindNextFileW (Address: 0x1800e6d90)
- GetFullPathNameW (Address: 0x1800e6db0)
- GetTempFileNameW (Address: 0x1800e6da0)
- RemoveDirectoryW (Address: 0x1800e6dc0)
api-ms-win-core-file-l2-1-0.dll
- GetFileInformationByHandleEx (Address: 0x1800e6dd8)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800e6de8)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800e6e00)
- HeapAlloc (Address: 0x1800e6df8)
- HeapFree (Address: 0x1800e6e08)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1800e6e18)
- LocalFree (Address: 0x1800e6e20)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1800e6e50)
- FindResourceExW (Address: 0x1800e6e68)
- FreeLibrary (Address: 0x1800e6e78)
- GetModuleFileNameA (Address: 0x1800e6e60)
- GetModuleFileNameW (Address: 0x1800e6e48)
- GetModuleHandleExW (Address: 0x1800e6e38)
- GetModuleHandleW (Address: 0x1800e6e70)
- GetProcAddress (Address: 0x1800e6e58)
- LoadLibraryExW (Address: 0x1800e6e80)
- LoadResource (Address: 0x1800e6e40)
- SizeofResource (Address: 0x1800e6e30)
api-ms-win-core-libraryloader-l1-2-1.dll
- LoadLibraryW (Address: 0x1800e6e90)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800e6ea0)
api-ms-win-core-path-l1-1-0.dll
- PathAllocCombine (Address: 0x1800e6eb0)
- PathCchCombine (Address: 0x1800e6eb8)
api-ms-win-core-processthreads-l1-1-0.dll
- GetCurrentProcess (Address: 0x1800e6ef0)
- GetCurrentProcessId (Address: 0x1800e6ed0)
- GetCurrentThread (Address: 0x1800e6ef8)
- GetCurrentThreadId (Address: 0x1800e6ec8)
- OpenProcessToken (Address: 0x1800e6ee0)
- OpenThreadToken (Address: 0x1800e6f00)
- SetThreadToken (Address: 0x1800e6ee8)
- TerminateProcess (Address: 0x1800e6ed8)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x1800e6f10)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800e6f20)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800e6f48)
- RegCreateKeyExW (Address: 0x1800e6f30)
- RegDeleteValueW (Address: 0x1800e6f58)
- RegEnumKeyExW (Address: 0x1800e6f60)
- RegOpenKeyExW (Address: 0x1800e6f50)
- RegQueryInfoKeyW (Address: 0x1800e6f40)
- RegSetValueExW (Address: 0x1800e6f38)
api-ms-win-core-rtlsupport-l1-1-0.dll
- RtlCaptureContext (Address: 0x1800e6f80)
- RtlLookupFunctionEntry (Address: 0x1800e6f78)
- RtlVirtualUnwind (Address: 0x1800e6f70)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
- PathFileExistsW (Address: 0x1800e6f90)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x1800e6fa0)
api-ms-win-core-string-l2-1-0.dll
- CharNextW (Address: 0x1800e6fb0)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x1800e6fc0)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800e7068)
- AcquireSRWLockShared (Address: 0x1800e6fd8)
- CreateEventExW (Address: 0x1800e7058)
- CreateEventW (Address: 0x1800e6fe8)
- CreateMutexExW (Address: 0x1800e7008)
- CreateSemaphoreExW (Address: 0x1800e7050)
- DeleteCriticalSection (Address: 0x1800e6fd0)
- EnterCriticalSection (Address: 0x1800e7030)
- InitializeCriticalSection (Address: 0x1800e6ff8)
- InitializeCriticalSectionEx (Address: 0x1800e6fe0)
- InitializeSRWLock (Address: 0x1800e6ff0)
- LeaveCriticalSection (Address: 0x1800e7040)
- OpenSemaphoreW (Address: 0x1800e7010)
- ReleaseMutex (Address: 0x1800e7020)
- ReleaseSemaphore (Address: 0x1800e7038)
- ReleaseSRWLockExclusive (Address: 0x1800e7048)
- ReleaseSRWLockShared (Address: 0x1800e7000)
- SetEvent (Address: 0x1800e7060)
- WaitForSingleObject (Address: 0x1800e7028)
- WaitForSingleObjectEx (Address: 0x1800e7018)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1800e7080)
- InitOnceComplete (Address: 0x1800e7090)
- InitOnceExecuteOnce (Address: 0x1800e7078)
- Sleep (Address: 0x1800e7088)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x1800e70a8)
- GetTickCount (Address: 0x1800e70b0)
- GetTickCount64 (Address: 0x1800e70a0)
api-ms-win-core-threadpool-l1-2-0.dll
- CloseThreadpoolWait (Address: 0x1800e70d0)
- CloseThreadpoolWork (Address: 0x1800e70d8)
- CreateThreadpoolWait (Address: 0x1800e70e8)
- CreateThreadpoolWork (Address: 0x1800e70f8)
- FreeLibraryWhenCallbackReturns (Address: 0x1800e70e0)
- SetThreadpoolWait (Address: 0x1800e70c0)
- SubmitThreadpoolWork (Address: 0x1800e70c8)
- WaitForThreadpoolWaitCallbacks (Address: 0x1800e70f0)
api-ms-win-core-url-l1-1-0.dll
- UrlEscapeW (Address: 0x1800e7108)
- UrlUnescapeW (Address: 0x1800e7110)
api-ms-win-core-util-l1-1-0.dll
- DecodePointer (Address: 0x1800e7128)
- EncodePointer (Address: 0x1800e7120)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1800e7138)
- EventRegister (Address: 0x1800e7150)
- EventSetInformation (Address: 0x1800e7158)
- EventUnregister (Address: 0x1800e7140)
- EventWriteTransfer (Address: 0x1800e7148)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x1800e7168)
- OpenSCManagerW (Address: 0x1800e7178)
- OpenServiceW (Address: 0x1800e7170)
api-ms-win-service-winsvc-l1-1-0.dll
- QueryServiceStatus (Address: 0x1800e7188)
AppointmentApis.dll
- CreatePropertiesFromRecurrencePattern (Address: 0x1800e6cb0)
- CreateRecurrencePatternFromProperties (Address: 0x1800e6ca8)
msvcrt.dll
- __C_specific_handler (Address: 0x1800e71c8)
- __CxxFrameHandler3 (Address: 0x1800e7198)
- __dllonexit (Address: 0x1800e71c0)
- _amsg_exit (Address: 0x1800e71e0)
- _callnewh (Address: 0x1800e71f0)
- _errno (Address: 0x1800e7210)
- _initterm (Address: 0x1800e71d8)
- _lock (Address: 0x1800e71d0)
- _onexit (Address: 0x1800e71a0)
- _purecall (Address: 0x1800e7238)
- _unlock (Address: 0x1800e7260)
- _vsnwprintf (Address: 0x1800e7230)
- _vsnwprintf_s (Address: 0x1800e7218)
- _XcptFilter (Address: 0x1800e71e8)
- free (Address: 0x1800e7250)
- malloc (Address: 0x1800e7248)
- memcmp (Address: 0x1800e71b0)
- memcpy (Address: 0x1800e71b8)
- memcpy_s (Address: 0x1800e7258)
- memmove (Address: 0x1800e71a8)
- memmove_s (Address: 0x1800e7220)
- memset (Address: 0x1800e7268)
- realloc (Address: 0x1800e7228)
- wcschr (Address: 0x1800e7200)
- wcsncmp (Address: 0x1800e7208)
- wcsncpy_s (Address: 0x1800e7240)
- wcstoul (Address: 0x1800e71f8)
ntdll.dll
- RtlQueryWnfStateData (Address: 0x1800e7278)
- RtlSubscribeWnfStateChangeNotification (Address: 0x1800e7280)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1800e7288)
SystemEventsBrokerClient.dll
- SebCreateEmailNotificationEvent (Address: 0x1800e6cc8)
- SebDeleteEvent (Address: 0x1800e6cc0)
UserDataPlatformHelperUtil.dll
- GenerateUserModeServiceName (Address: 0x1800e6cd8)
- GetUserContextFromHandle (Address: 0x1800e6ce8)
- GetUserTokenFromContext (Address: 0x1800e6cf8)
- IsCommsSystemService (Address: 0x1800e6d00)
- RunServicesInProc (Address: 0x1800e6cf0)
- StartAndWaitForServiceForUser (Address: 0x1800e6ce0)