¿Para qué sirve la dll tquery.dll?

Consulta de Microsoft Tripoli

Dependencias de la dll tquery.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\tquery.dll

File Type: DLL

  Image has the following dependencies:

    msvcrt.dll
    api-ms-win-core-libraryloader-l1-2-0.dll
    api-ms-win-core-synch-l1-1-0.dll
    api-ms-win-core-heap-l1-1-0.dll
    api-ms-win-core-errorhandling-l1-1-0.dll
    api-ms-win-core-processthreads-l1-1-0.dll
    api-ms-win-core-localization-l1-2-0.dll
    api-ms-win-core-debug-l1-1-0.dll
    api-ms-win-core-handle-l1-1-0.dll
    OLEAUT32.dll
    api-ms-win-core-synch-l1-2-0.dll
    api-ms-win-core-com-l1-1-0.dll
    api-ms-win-core-registry-l1-1-0.dll
    api-ms-win-core-threadpool-l1-2-0.dll
    api-ms-win-core-string-l2-1-0.dll
    api-ms-win-core-string-l1-1-0.dll
    ntdll.dll
    api-ms-win-core-string-obsolete-l1-1-0.dll
    api-ms-win-core-memory-l1-1-0.dll
    api-ms-win-core-libraryloader-l1-2-1.dll
    api-ms-win-core-processenvironment-l1-1-0.dll
    api-ms-win-core-localization-obsolete-l1-2-0.dll
    api-ms-win-core-rtlsupport-l1-1-0.dll
    api-ms-win-core-profile-l1-1-0.dll
    api-ms-win-core-sysinfo-l1-1-0.dll
    api-ms-win-core-file-l1-1-0.dll
    api-ms-win-core-io-l1-1-0.dll
    api-ms-win-eventing-provider-l1-1-0.dll
    api-ms-win-core-kernel32-legacy-l1-1-1.dll
    api-ms-win-core-file-l2-1-0.dll
    api-ms-win-security-base-l1-1-0.dll
    api-ms-win-core-heap-l2-1-0.dll
    api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
    api-ms-win-core-localization-l1-2-2.dll
    api-ms-win-core-io-l1-1-1.dll
    api-ms-win-core-namedpipe-l1-1-0.dll
    api-ms-win-core-synch-l1-2-1.dll
    api-ms-win-core-kernel32-legacy-l1-1-0.dll
    api-ms-win-core-timezone-l1-1-0.dll
    api-ms-win-core-file-l1-2-0.dll
    api-ms-win-core-path-l1-1-0.dll
    api-ms-win-core-shlwapi-legacy-l1-1-0.dll
    api-ms-win-core-datetime-l1-1-0.dll
    api-ms-win-core-delayload-l1-1-1.dll
    api-ms-win-core-delayload-l1-1-0.dll
    api-ms-win-core-util-l1-1-0.dll
    api-ms-win-core-apiquery-l1-1-0.dll
    cryptdll.dll
    api-ms-win-core-realtime-l1-1-0.dll
    api-ms-win-core-processthreads-l1-1-1.dll
    api-ms-win-core-file-l1-2-1.dll
    api-ms-win-core-processtopology-obsolete-l1-1-0.dll
    api-ms-win-core-interlocked-l1-1-0.dll
    api-ms-win-core-heap-obsolete-l1-1-0.dll
    api-ms-win-core-job-l2-1-0.dll
    api-ms-win-core-winrt-string-l1-1-0.dll
    api-ms-win-core-winrt-l1-1-0.dll
    api-ms-win-shell-namespace-l1-1-0.dll

  Image has the following delay load dependencies:

    ext-ms-win-els-elscore-l1-1-0.dll
    PROPSYS.dll
    dbghelp.dll
    efswrt.dll
    ext-ms-win-edputil-policy-l1-1-0.dll
    ext-ms-win-session-usertoken-l1-1-0.dll
    ext-ms-win-shell32-shellfolders-l1-1-0.dll
    ext-ms-win-advapi32-eventlog-l1-1-0.dll
    ext-ms-win-wer-reporting-l1-1-0.dll
    api-ms-win-shell-shdirectory-l1-1-0.dll
    api-ms-win-shcore-registry-l1-1-0.dll
    api-ms-win-service-management-l1-1-0.dll
    api-ms-win-security-sddl-l1-1-0.dll
    SspiCli.dll
    srvcli.dll
    netutils.dll
    api-ms-win-service-core-l1-1-1.dll
    api-ms-win-service-winsvc-l1-1-0.dll
    api-ms-win-winrt-search-folder-l1-1-0.dll
    ESENT.dll
    ext-ms-win-devmgmt-policy-l1-1-0.dll

  Summary

        6000 .data
        1000 .didat
       1E000 .pdata
       B3000 .rdata
        4000 .reloc
        1000 .rsrc
      24F000 .text

Funciones que tiene la dll tquery.dll


254    0 0004A240 ??0CDriveInfo@@QEAA@PEBGK@Z
255    1 00158020 ??0CFullPath@@QEAA@PEBG@Z
256    2 00053E70 ??0CFullPropSpec@@QEAA@AEBV0@@Z
257    3 00042AD0 ??0CMemSerStream@@QEAA@PEAEK@Z
258    4 000EDEC0 ??0CPidLookupTable@@QEAA@XZ
259    5 000D1810 ??0CUnNormalizer@@QEAA@XZ
260    6 000DC360 ??0CiStorage@@QEAA@PEBGKPEAUICiCAdviseStatus@@KH@Z
261    7 001586E0 ??0XAct@@QEAA@XZ
262    8 0001A510 ??1CAllocStorageVariant@@IEAA@XZ
263    9 00042A90 ??1CMemSerStream@@UEAA@XZ
264    A 0015CF30 ??1CPhysStorage@@UEAA@XZ
265    B 000DCDE0 ??1CPidLookupTable@@QEAA@XZ
266    C 000DC440 ??1CiStorage@@UEAA@XZ
253    D 00304030 ?CoTaskAllocator@@3VCCoTaskAllocator@@A
268    E 00049FB0 ?ContainsDrive@CDriveInfo@@SAHPEBG@Z
273    F 000BCA20 ?GetBlob@CMemDeSerStream@@UEAAXPEAEK@Z
274   10 00048C00 ?GetByte@CMemDeSerStream@@UEAAEXZ
275   11 000BCA20 ?GetChar@CMemDeSerStream@@UEAAXPEADK@Z
276   12 00157D60 ?GetDiskSpace@CDriveInfo@@QEAAXAEA_J0@Z
277   13 0016D860 ?GetDouble@CMemDeSerStream@@UEAANXZ
278   14 0004A1F0 ?GetDrive@CDriveInfo@@SAXPEBGPEAG@Z
279   15 00027850 ?GetFloat@CMemDeSerStream@@UEAAMXZ
280   16 000BDD20 ?GetGUID@CMemDeSerStream@@UEAAXAEAU_GUID@@@Z
281   17 00048C30 ?GetLong@CMemDeSerStream@@UEAAJXZ
282   18 00157E00 ?GetSectorSize@CDriveInfo@@QEAAKXZ
283   19 0016D8B0 ?GetString@CMemDeSerStream@@UEAAPEADXZ
284   1A 00048C30 ?GetULong@CMemDeSerStream@@UEAAKXZ
285   1B 000BE690 ?GetUShort@CMemDeSerStream@@UEAAGXZ
286   1C 000BCAB0 ?GetWChar@CMemDeSerStream@@UEAAXPEAGK@Z
287   1D 00023900 ?GetWString@CMemDeSerStream@@UEAAPEAGXZ
288   1E 000ECE00 ?Init@CPidLookupTable@@QEAAHPEAVPRcovStorageObj@@@Z
289   1F 00157EB0 ?IsSameDrive@CDriveInfo@@QEAAHPEBG@Z
290   20 000DC9F0 ?IsWriteProtected@CDriveInfo@@QEAAHXZ
291   21 00158350 ?MakePath@CFullPath@@QEAAXPEBG@Z
292   22 0016D990 ?PeekULong@CMemDeSerStream@@UEAAKXZ
293   23 000BCA70 ?PutBlob@CMemSerStream@@UEAAXPEBEK@Z
294   24 000BDCF0 ?PutByte@CMemSerStream@@UEAAXE@Z
295   25 000BCA70 ?PutChar@CMemSerStream@@UEAAXPEBDK@Z
296   26 0016CEB0 ?PutDouble@CMemSerStream@@UEAAXN@Z
297   27 000275A0 ?PutFloat@CMemSerStream@@UEAAXM@Z
298   28 000BDCB0 ?PutGUID@CMemSerStream@@UEAAXAEBU_GUID@@@Z
299   29 000BCB50 ?PutLong@CMemSerStream@@UEAAXJ@Z
300   2A 0016CF00 ?PutString@CMemSerStream@@UEAAXPEBD@Z
301   2B 000B8BF0 ?PutULong@CMemSerStream@@UEAAXK@Z
302   2C 000BDD60 ?PutUShort@CMemSerStream@@UEAAXG@Z
303   2D 000BCB00 ?PutWChar@CMemSerStream@@UEAAXPEBGK@Z
304   2E 00023890 ?PutWString@CMemSerStream@@UEAAXPEBG@Z
305   2F 000DC6F0 ?QueryPidLookupTable@CiStorage@@QEAAPEAVPRcovStorageObj@@K@Z
306   30 0015E820 ?Read@CCiFile@@QEAAXXZ
307   31 00054950 ?ResetType@CAllocStorageVariant@@IEAAXAEAVPMemoryAllocator@@@Z
308   32 00027E20 ?SetProperty@CFullPropSpec@@QEAAHPEBG@Z
309   33 00166380 ?SetProperty@CFullPropSpec@@QEAAXK@Z
310   34 0016D9E0 ?SkipBlob@CMemDeSerStream@@UEAAXK@Z
311   35 0016DA30 ?SkipByte@CMemDeSerStream@@UEAAXXZ
312   36 0016D9E0 ?SkipChar@CMemDeSerStream@@UEAAXK@Z
313   37 0016DA70 ?SkipDouble@CMemDeSerStream@@UEAAXXZ
314   38 0016DAC0 ?SkipFloat@CMemDeSerStream@@UEAAXXZ
315   39 0016DB10 ?SkipGUID@CMemDeSerStream@@UEAAXXZ
316   3A 0016DAC0 ?SkipLong@CMemDeSerStream@@UEAAXXZ
317   3B 0016DAC0 ?SkipULong@CMemDeSerStream@@UEAAXXZ
318   3C 0016DB60 ?SkipUShort@CMemDeSerStream@@UEAAXXZ
319   3D 0016DBB0 ?SkipWChar@CMemDeSerStream@@UEAAXK@Z
320   3E 00166500 ?UnNormalizeKey@CUnNormalizer@@QEAAXAEBVCKeyBuf@@AEAUtagPROPVARIANT@@PEAGK@Z
325   3F 00175C20 AccessDebugTracer
326   40 00175C40 AccessRetailTracer
267   41 00164170 CIState
270   42 000EC930 CreatePropMapperStorage
269   43 000EC960 CreatePropMapperStorage2
271   44 000E7850 CreateSecurityStoreStorage
327   45 000CE130 DllCanUnloadNow
328   46 000C3920 DllGetClassObject
329   47 00156BB0 DllRegisterServer
330   48 00156C20 DllUnregisterServer
272   49 0001A510 ExceptInitialize
331   4A 000A9F10 ExternPropagateEventToOpenQueries
332   4B 00164C40 ForceMasterMerge
333   4C 00157400 PerfmonClose
334   4D 00157440 PerfmonCollect
335   4E 00157400 PerfmonIDXClose
336   4F 00157690 PerfmonIDXCollect
337   50 001578E0 PerfmonIDXOpen
338   51 00157920 PerfmonOpen
339   52 00175C60 RetailTracerDisable
340   53 00175C80 RetailTracerEnable
341   54 00175D90 RetailTracerReleaseAll
321   55 0016B080 UseLowFragmentationHeap
322   56 00096360 ciDelete
323   57 00092730 ciNew
324   58 000B64E0 ciNewNoThrow

Información avanzada sobre funciones que tiene la dll tquery.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\tquery.dll

File Type: DLL

  Section contains the following exports for TQUERY.DLL

    00000000 characteristics
     275F94D time date stamp
        0.00 version
         253 ordinal base
          89 number of functions
          89 number of names

    ordinal hint RVA      name

        254    0 0004A240 ??0CDriveInfo@@QEAA@PEBGK@Z
        255    1 00158020 ??0CFullPath@@QEAA@PEBG@Z
        256    2 00053E70 ??0CFullPropSpec@@QEAA@AEBV0@@Z
        257    3 00042AD0 ??0CMemSerStream@@QEAA@PEAEK@Z
        258    4 000EDEC0 ??0CPidLookupTable@@QEAA@XZ
        259    5 000D1810 ??0CUnNormalizer@@QEAA@XZ
        260    6 000DC360 ??0CiStorage@@QEAA@PEBGKPEAUICiCAdviseStatus@@KH@Z
        261    7 001586E0 ??0XAct@@QEAA@XZ
        262    8 0001A510 ??1CAllocStorageVariant@@IEAA@XZ
        263    9 00042A90 ??1CMemSerStream@@UEAA@XZ
        264    A 0015CF30 ??1CPhysStorage@@UEAA@XZ
        265    B 000DCDE0 ??1CPidLookupTable@@QEAA@XZ
        266    C 000DC440 ??1CiStorage@@UEAA@XZ
        253    D 00304030 ?CoTaskAllocator@@3VCCoTaskAllocator@@A
        268    E 00049FB0 ?ContainsDrive@CDriveInfo@@SAHPEBG@Z
        273    F 000BCA20 ?GetBlob@CMemDeSerStream@@UEAAXPEAEK@Z
        274   10 00048C00 ?GetByte@CMemDeSerStream@@UEAAEXZ
        275   11 000BCA20 ?GetChar@CMemDeSerStream@@UEAAXPEADK@Z
        276   12 00157D60 ?GetDiskSpace@CDriveInfo@@QEAAXAEA_J0@Z
        277   13 0016D860 ?GetDouble@CMemDeSerStream@@UEAANXZ
        278   14 0004A1F0 ?GetDrive@CDriveInfo@@SAXPEBGPEAG@Z
        279   15 00027850 ?GetFloat@CMemDeSerStream@@UEAAMXZ
        280   16 000BDD20 ?GetGUID@CMemDeSerStream@@UEAAXAEAU_GUID@@@Z
        281   17 00048C30 ?GetLong@CMemDeSerStream@@UEAAJXZ
        282   18 00157E00 ?GetSectorSize@CDriveInfo@@QEAAKXZ
        283   19 0016D8B0 ?GetString@CMemDeSerStream@@UEAAPEADXZ
        284   1A 00048C30 ?GetULong@CMemDeSerStream@@UEAAKXZ
        285   1B 000BE690 ?GetUShort@CMemDeSerStream@@UEAAGXZ
        286   1C 000BCAB0 ?GetWChar@CMemDeSerStream@@UEAAXPEAGK@Z
        287   1D 00023900 ?GetWString@CMemDeSerStream@@UEAAPEAGXZ
        288   1E 000ECE00 ?Init@CPidLookupTable@@QEAAHPEAVPRcovStorageObj@@@Z
        289   1F 00157EB0 ?IsSameDrive@CDriveInfo@@QEAAHPEBG@Z
        290   20 000DC9F0 ?IsWriteProtected@CDriveInfo@@QEAAHXZ
        291   21 00158350 ?MakePath@CFullPath@@QEAAXPEBG@Z
        292   22 0016D990 ?PeekULong@CMemDeSerStream@@UEAAKXZ
        293   23 000BCA70 ?PutBlob@CMemSerStream@@UEAAXPEBEK@Z
        294   24 000BDCF0 ?PutByte@CMemSerStream@@UEAAXE@Z
        295   25 000BCA70 ?PutChar@CMemSerStream@@UEAAXPEBDK@Z
        296   26 0016CEB0 ?PutDouble@CMemSerStream@@UEAAXN@Z
        297   27 000275A0 ?PutFloat@CMemSerStream@@UEAAXM@Z
        298   28 000BDCB0 ?PutGUID@CMemSerStream@@UEAAXAEBU_GUID@@@Z
        299   29 000BCB50 ?PutLong@CMemSerStream@@UEAAXJ@Z
        300   2A 0016CF00 ?PutString@CMemSerStream@@UEAAXPEBD@Z
        301   2B 000B8BF0 ?PutULong@CMemSerStream@@UEAAXK@Z
        302   2C 000BDD60 ?PutUShort@CMemSerStream@@UEAAXG@Z
        303   2D 000BCB00 ?PutWChar@CMemSerStream@@UEAAXPEBGK@Z
        304   2E 00023890 ?PutWString@CMemSerStream@@UEAAXPEBG@Z
        305   2F 000DC6F0 ?QueryPidLookupTable@CiStorage@@QEAAPEAVPRcovStorageObj@@K@Z
        306   30 0015E820 ?Read@CCiFile@@QEAAXXZ
        307   31 00054950 ?ResetType@CAllocStorageVariant@@IEAAXAEAVPMemoryAllocator@@@Z
        308   32 00027E20 ?SetProperty@CFullPropSpec@@QEAAHPEBG@Z
        309   33 00166380 ?SetProperty@CFullPropSpec@@QEAAXK@Z
        310   34 0016D9E0 ?SkipBlob@CMemDeSerStream@@UEAAXK@Z
        311   35 0016DA30 ?SkipByte@CMemDeSerStream@@UEAAXXZ
        312   36 0016D9E0 ?SkipChar@CMemDeSerStream@@UEAAXK@Z
        313   37 0016DA70 ?SkipDouble@CMemDeSerStream@@UEAAXXZ
        314   38 0016DAC0 ?SkipFloat@CMemDeSerStream@@UEAAXXZ
        315   39 0016DB10 ?SkipGUID@CMemDeSerStream@@UEAAXXZ
        316   3A 0016DAC0 ?SkipLong@CMemDeSerStream@@UEAAXXZ
        317   3B 0016DAC0 ?SkipULong@CMemDeSerStream@@UEAAXXZ
        318   3C 0016DB60 ?SkipUShort@CMemDeSerStream@@UEAAXXZ
        319   3D 0016DBB0 ?SkipWChar@CMemDeSerStream@@UEAAXK@Z
        320   3E 00166500 ?UnNormalizeKey@CUnNormalizer@@QEAAXAEBVCKeyBuf@@AEAUtagPROPVARIANT@@PEAGK@Z
        325   3F 00175C20 AccessDebugTracer
        326   40 00175C40 AccessRetailTracer
        267   41 00164170 CIState
        270   42 000EC930 CreatePropMapperStorage
        269   43 000EC960 CreatePropMapperStorage2
        271   44 000E7850 CreateSecurityStoreStorage
        327   45 000CE130 DllCanUnloadNow
        328   46 000C3920 DllGetClassObject
        329   47 00156BB0 DllRegisterServer
        330   48 00156C20 DllUnregisterServer
        272   49 0001A510 ExceptInitialize
        331   4A 000A9F10 ExternPropagateEventToOpenQueries
        332   4B 00164C40 ForceMasterMerge
        333   4C 00157400 PerfmonClose
        334   4D 00157440 PerfmonCollect
        335   4E 00157400 PerfmonIDXClose
        336   4F 00157690 PerfmonIDXCollect
        337   50 001578E0 PerfmonIDXOpen
        338   51 00157920 PerfmonOpen
        339   52 00175C60 RetailTracerDisable
        340   53 00175C80 RetailTracerEnable
        341   54 00175D90 RetailTracerReleaseAll
        321   55 0016B080 UseLowFragmentationHeap
        322   56 00096360 ciDelete
        323   57 00092730 ciNew
        324   58 000B64E0 ciNewNoThrow

  Summary

        6000 .data
        1000 .didat
       1E000 .pdata
       B3000 .rdata
        4000 .reloc
        1000 .rsrc
      24F000 .text

Integridad de la dll tquery.dll



Algorithm       Hash                                                                   Path                                                           
---------       ----                                                                   ----                                                           
SHA256          EDA557C7BBF0C73041A35D57D7557F7E69874C00490DC17380C2D18CAE9443C7       C:\Windows\System32\tquery.dll                                 


Detalles sobre el fichero dll tquery.dll




PSPath            : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32\tquery.dll
PSParentPath      : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32
PSChildName       : tquery.dll
PSDrive           : C
PSProvider        : Microsoft.PowerShell.Core\FileSystem
PSIsContainer     : False
Mode              : -a----
VersionInfo       : File:             C:\Windows\System32\tquery.dll
                    InternalName:     TQUERY.dll
                    OriginalFilename: TQUERY.dll.mui
                    FileVersion:      7.0.19041.561 (WinBuild.160101.0800)
                    FileDescription:  Consulta de Microsoft Tripoli
                    Product:          Windows® Search
                    ProductVersion:   7.0.19041.561
                    Debug:            False
                    Patched:          False
                    PreRelease:       False
                    PrivateBuild:     False
                    SpecialBuild:     False
                    Language:         Español (España, internacional)
                    
BaseName          : tquery
Target            : {C:\Windows\WinSxS\amd64_windowssearchengine_31bf3856ad364e35_7.0.19041.610_none_8bfdd10e0c793303\tquery.dll}
LinkType          : HardLink
Name              : tquery.dll
Length            : 3305984
DirectoryName     : C:\Windows\System32
Directory         : C:\Windows\System32
IsReadOnly        : False
Exists            : True
FullName          : C:\Windows\System32\tquery.dll
Extension         : .dll
CreationTime      : 29/11/2020 11:42:13
CreationTimeUtc   : 29/11/2020 10:42:13
LastAccessTime    : 03/12/2020 15:53:04
LastAccessTimeUtc : 03/12/2020 14:53:04
LastWriteTime     : 29/11/2020 11:42:13
LastWriteTimeUtc  : 29/11/2020 10:42:13
Attributes        : Archive



Procesos que utilizan la dll tquery.dll


RuntimeBroker
RuntimeBroker
SearchApp
sihost