VmHostAI.dll

Description: CMI vmhost plug-in

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3385

Architecture: 32-bit

Operating System: Windows NT

SHA256: a493497f044fcd0b900fda4491e81ef4

File Size: 83.4 KB

Uploaded At: Dec. 1, 2025, 8:43 a.m.

Views: 12

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x7530)
  • DllCsiGetHandler (Ordinal: 2, Address: 0x7550)

Imported DLLs & Functions

api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x10012084)
  • CoInitializeEx (Address: 0x10012078)
  • CoSetProxyBlanket (Address: 0x10012074)
  • CoTaskMemAlloc (Address: 0x10012080)
  • CoTaskMemFree (Address: 0x1001208c)
  • CoTaskMemRealloc (Address: 0x1001207c)
  • CoUninitialize (Address: 0x10012088)
api-ms-win-core-debug-l1-1-0.dll
  • OutputDebugStringA (Address: 0x10012094)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x100120a4)
  • RaiseException (Address: 0x1001209c)
  • SetLastError (Address: 0x100120a8)
  • SetUnhandledExceptionFilter (Address: 0x100120a0)
  • UnhandledExceptionFilter (Address: 0x100120ac)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x100120b4)
api-ms-win-core-heap-l1-1-0.dll
  • HeapSetInformation (Address: 0x100120bc)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • LocalAlloc (Address: 0x100120c4)
  • LocalFree (Address: 0x100120c8)
api-ms-win-core-libraryloader-l1-1-0.dll
  • DisableThreadLibraryCalls (Address: 0x100120dc)
  • FindResourceExW (Address: 0x100120e8)
  • FreeLibrary (Address: 0x100120e0)
  • GetModuleFileNameW (Address: 0x100120e4)
  • GetModuleHandleW (Address: 0x100120d8)
  • GetProcAddress (Address: 0x100120d0)
  • LoadLibraryExW (Address: 0x100120d4)
  • LoadResource (Address: 0x100120ec)
  • SizeofResource (Address: 0x100120f0)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateThread (Address: 0x1001210c)
  • GetCurrentProcess (Address: 0x10012110)
  • GetCurrentProcessId (Address: 0x10012104)
  • GetCurrentThreadId (Address: 0x10012100)
  • GetExitCodeProcess (Address: 0x100120f8)
  • OpenProcessToken (Address: 0x10012108)
  • TerminateProcess (Address: 0x100120fc)
api-ms-win-core-processthreads-l1-1-1.dll
  • OpenProcess (Address: 0x10012118)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x10012120)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x10012140)
  • RegCreateKeyExW (Address: 0x1001213c)
  • RegDeleteValueW (Address: 0x1001212c)
  • RegEnumKeyExW (Address: 0x10012130)
  • RegOpenKeyExW (Address: 0x10012128)
  • RegQueryInfoKeyW (Address: 0x10012134)
  • RegSetValueExW (Address: 0x10012138)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x10012148)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x10012150)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x10012158)
api-ms-win-core-synch-l1-1-0.dll
  • DeleteCriticalSection (Address: 0x10012170)
  • EnterCriticalSection (Address: 0x1001216c)
  • InitializeCriticalSection (Address: 0x10012164)
  • LeaveCriticalSection (Address: 0x10012160)
  • WaitForSingleObject (Address: 0x10012168)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x10012178)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x10012188)
  • GetTickCount (Address: 0x1001218c)
  • GetTickCount64 (Address: 0x10012180)
  • GetVersionExW (Address: 0x10012184)
api-ms-win-security-base-l1-1-0.dll
  • AddAccessAllowedAce (Address: 0x100121f8)
  • AddAccessAllowedAceEx (Address: 0x10012198)
  • AddAce (Address: 0x100121a4)
  • AllocateAndInitializeSid (Address: 0x100121c8)
  • CreateWellKnownSid (Address: 0x100121b4)
  • DeleteAce (Address: 0x100121fc)
  • EqualSid (Address: 0x10012194)
  • FreeSid (Address: 0x100121c4)
  • GetAce (Address: 0x100121a8)
  • GetAclInformation (Address: 0x100121ac)
  • GetLengthSid (Address: 0x100121a0)
  • GetSecurityDescriptorDacl (Address: 0x100121e0)
  • GetSecurityDescriptorGroup (Address: 0x100121d8)
  • GetSecurityDescriptorLength (Address: 0x100121d0)
  • GetSecurityDescriptorOwner (Address: 0x100121dc)
  • GetSecurityDescriptorSacl (Address: 0x100121e4)
  • GetTokenInformation (Address: 0x100121b8)
  • InitializeAcl (Address: 0x1001219c)
  • InitializeSecurityDescriptor (Address: 0x100121bc)
  • IsValidAcl (Address: 0x100121b0)
  • IsValidSecurityDescriptor (Address: 0x100121e8)
  • MakeAbsoluteSD (Address: 0x100121d4)
  • MakeSelfRelativeSD (Address: 0x100121cc)
  • SetSecurityDescriptorControl (Address: 0x100121c0)
  • SetSecurityDescriptorDacl (Address: 0x100121f4)
  • SetSecurityDescriptorGroup (Address: 0x100121f0)
  • SetSecurityDescriptorOwner (Address: 0x100121ec)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountSidW (Address: 0x10012204)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertStringSidToSidW (Address: 0x1001220c)
api-ms-win-service-core-l1-1-1.dll
  • EnumDependentServicesW (Address: 0x10012214)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x10012220)
  • OpenSCManagerW (Address: 0x10012228)
  • OpenServiceW (Address: 0x1001221c)
  • StartServiceW (Address: 0x10012224)
api-ms-win-service-management-l2-1-0.dll
  • QueryServiceStatusEx (Address: 0x10012230)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x1001223c)
  • QueryServiceStatus (Address: 0x10012238)
msvcrt.dll
  • __CxxFrameHandler3 (Address: 0x100122c0)
  • __dllonexit (Address: 0x10012270)
  • _amsg_exit (Address: 0x1001225c)
  • _callnewh (Address: 0x100122a4)
  • _CxxThrowException (Address: 0x10012280)
  • _errno (Address: 0x10012290)
  • _except_handler4_common (Address: 0x10012284)
  • _initterm (Address: 0x10012260)
  • _lock (Address: 0x1001229c)
  • _onexit (Address: 0x10012278)
  • _purecall (Address: 0x100122b8)
  • _snwprintf_s (Address: 0x10012294)
  • _unlock (Address: 0x1001226c)
  • _vsnwprintf_s (Address: 0x100122a0)
  • _wstrdate (Address: 0x10012268)
  • _wstrtime (Address: 0x1001228c)
  • _XcptFilter (Address: 0x10012258)
  • ??_V@YAXPAX@Z (Address: 0x100122bc)
  • ??0exception@@QAE@ABQBD@Z (Address: 0x10012244)
  • ??0exception@@QAE@ABQBDH@Z (Address: 0x10012248)
  • ??0exception@@QAE@ABV0@@Z (Address: 0x1001224c)
  • ??1exception@@UAE@XZ (Address: 0x10012250)
  • ??1type_info@@UAE@XZ (Address: 0x100122c4)
  • ??3@YAXPAX@Z (Address: 0x10012298)
  • ?terminate@@YAXXZ (Address: 0x10012264)
  • ?what@exception@@UBEPBDXZ (Address: 0x10012254)
  • free (Address: 0x100122ac)
  • malloc (Address: 0x100122b0)
  • memcpy (Address: 0x1001227c)
  • memcpy_s (Address: 0x100122a8)
  • memmove (Address: 0x10012274)
  • memset (Address: 0x100122c8)
  • realloc (Address: 0x10012288)
  • wcsncpy_s (Address: 0x100122b4)
NETAPI32.dll
  • NetLocalGroupAddMembers (Address: 0x10012004)
  • NetLocalGroupDelMembers (Address: 0x10012000)
OLEAUT32.dll
  • SafeArrayAccessData (Address: 0x10012044)
  • SafeArrayCopy (Address: 0x10012018)
  • SafeArrayCreate (Address: 0x10012040)
  • SafeArrayDestroy (Address: 0x1001200c)
  • SafeArrayGetLBound (Address: 0x10012010)
  • SafeArrayGetUBound (Address: 0x10012014)
  • SafeArrayGetVartype (Address: 0x1001201c)
  • SafeArrayLock (Address: 0x10012034)
  • SafeArrayRedim (Address: 0x10012048)
  • SafeArrayUnaccessData (Address: 0x10012020)
  • SafeArrayUnlock (Address: 0x10012024)
  • SysAllocString (Address: 0x10012030)
  • SysFreeString (Address: 0x10012038)
  • VariantClear (Address: 0x1001202c)
  • VariantInit (Address: 0x10012028)
  • VarUI4FromStr (Address: 0x1001203c)
WCP.dll
  • ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x10012054)
  • ?RtlTraceFormat_PCWSTR_AsLiteralString@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10012060)
  • ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x1001206c)
  • RtlConcatenateLUnicodeStrings (Address: 0x10012058)
  • RtlConvertWin32RegistryPathToNtRegistryPath (Address: 0x10012050)
  • RtlFreeLBlob (Address: 0x10012068)
  • RtlFreeLUnicodeString (Address: 0x1001205c)
  • RtlReportErrorOrigination (Address: 0x10012064)