VmHostAI.dll
Description: CMI vmhost plug-in
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6088
Architecture: 32-bit
Operating System: Windows NT
SHA256: 62b4edbabc0effc5ad97d593e7d33f7b
File Size: 83.4 KB
Uploaded At: Dec. 1, 2025, 8:43 a.m.
Views: 13
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- DllCanUnloadNow (Ordinal: 1, Address: 0x7530)
- DllCsiGetHandler (Ordinal: 2, Address: 0x7550)
Imported DLLs & Functions
api-ms-win-core-com-l1-1-0.dll
- CoCreateInstance (Address: 0x10012084)
- CoInitializeEx (Address: 0x10012078)
- CoSetProxyBlanket (Address: 0x10012074)
- CoTaskMemAlloc (Address: 0x10012080)
- CoTaskMemFree (Address: 0x1001208c)
- CoTaskMemRealloc (Address: 0x1001207c)
- CoUninitialize (Address: 0x10012088)
api-ms-win-core-debug-l1-1-0.dll
- OutputDebugStringA (Address: 0x10012094)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x100120a4)
- RaiseException (Address: 0x1001209c)
- SetLastError (Address: 0x100120a8)
- SetUnhandledExceptionFilter (Address: 0x100120a0)
- UnhandledExceptionFilter (Address: 0x100120ac)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x100120b4)
api-ms-win-core-heap-l1-1-0.dll
- HeapSetInformation (Address: 0x100120bc)
api-ms-win-core-heap-obsolete-l1-1-0.dll
- LocalAlloc (Address: 0x100120c4)
- LocalFree (Address: 0x100120c8)
api-ms-win-core-libraryloader-l1-1-0.dll
- DisableThreadLibraryCalls (Address: 0x100120dc)
- FindResourceExW (Address: 0x100120e8)
- FreeLibrary (Address: 0x100120e0)
- GetModuleFileNameW (Address: 0x100120e4)
- GetModuleHandleW (Address: 0x100120d8)
- GetProcAddress (Address: 0x100120d0)
- LoadLibraryExW (Address: 0x100120d4)
- LoadResource (Address: 0x100120ec)
- SizeofResource (Address: 0x100120f0)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateThread (Address: 0x1001210c)
- GetCurrentProcess (Address: 0x10012110)
- GetCurrentProcessId (Address: 0x10012104)
- GetCurrentThreadId (Address: 0x10012100)
- GetExitCodeProcess (Address: 0x100120f8)
- OpenProcessToken (Address: 0x10012108)
- TerminateProcess (Address: 0x100120fc)
api-ms-win-core-processthreads-l1-1-1.dll
- OpenProcess (Address: 0x10012118)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x10012120)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x10012140)
- RegCreateKeyExW (Address: 0x1001213c)
- RegDeleteValueW (Address: 0x1001212c)
- RegEnumKeyExW (Address: 0x10012130)
- RegOpenKeyExW (Address: 0x10012128)
- RegQueryInfoKeyW (Address: 0x10012134)
- RegSetValueExW (Address: 0x10012138)
api-ms-win-core-string-l1-1-0.dll
- MultiByteToWideChar (Address: 0x10012148)
api-ms-win-core-string-l2-1-0.dll
- CharNextW (Address: 0x10012150)
api-ms-win-core-string-obsolete-l1-1-0.dll
- lstrcmpiW (Address: 0x10012158)
api-ms-win-core-synch-l1-1-0.dll
- DeleteCriticalSection (Address: 0x10012170)
- EnterCriticalSection (Address: 0x1001216c)
- InitializeCriticalSection (Address: 0x10012164)
- LeaveCriticalSection (Address: 0x10012160)
- WaitForSingleObject (Address: 0x10012168)
api-ms-win-core-synch-l1-2-0.dll
- Sleep (Address: 0x10012178)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetSystemTimeAsFileTime (Address: 0x10012188)
- GetTickCount (Address: 0x1001218c)
- GetTickCount64 (Address: 0x10012180)
- GetVersionExW (Address: 0x10012184)
api-ms-win-security-base-l1-1-0.dll
- AddAccessAllowedAce (Address: 0x100121f8)
- AddAccessAllowedAceEx (Address: 0x10012198)
- AddAce (Address: 0x100121a4)
- AllocateAndInitializeSid (Address: 0x100121c8)
- CreateWellKnownSid (Address: 0x100121b4)
- DeleteAce (Address: 0x100121fc)
- EqualSid (Address: 0x10012194)
- FreeSid (Address: 0x100121c4)
- GetAce (Address: 0x100121a8)
- GetAclInformation (Address: 0x100121ac)
- GetLengthSid (Address: 0x100121a0)
- GetSecurityDescriptorDacl (Address: 0x100121e0)
- GetSecurityDescriptorGroup (Address: 0x100121d8)
- GetSecurityDescriptorLength (Address: 0x100121d0)
- GetSecurityDescriptorOwner (Address: 0x100121dc)
- GetSecurityDescriptorSacl (Address: 0x100121e4)
- GetTokenInformation (Address: 0x100121b8)
- InitializeAcl (Address: 0x1001219c)
- InitializeSecurityDescriptor (Address: 0x100121bc)
- IsValidAcl (Address: 0x100121b0)
- IsValidSecurityDescriptor (Address: 0x100121e8)
- MakeAbsoluteSD (Address: 0x100121d4)
- MakeSelfRelativeSD (Address: 0x100121cc)
- SetSecurityDescriptorControl (Address: 0x100121c0)
- SetSecurityDescriptorDacl (Address: 0x100121f4)
- SetSecurityDescriptorGroup (Address: 0x100121f0)
- SetSecurityDescriptorOwner (Address: 0x100121ec)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupAccountSidW (Address: 0x10012204)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertStringSidToSidW (Address: 0x1001220c)
api-ms-win-service-core-l1-1-1.dll
- EnumDependentServicesW (Address: 0x10012214)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x10012220)
- OpenSCManagerW (Address: 0x10012228)
- OpenServiceW (Address: 0x1001221c)
- StartServiceW (Address: 0x10012224)
api-ms-win-service-management-l2-1-0.dll
- QueryServiceStatusEx (Address: 0x10012230)
api-ms-win-service-winsvc-l1-1-0.dll
- ControlService (Address: 0x1001223c)
- QueryServiceStatus (Address: 0x10012238)
msvcrt.dll
- __CxxFrameHandler3 (Address: 0x100122c0)
- __dllonexit (Address: 0x10012270)
- _amsg_exit (Address: 0x1001225c)
- _callnewh (Address: 0x100122a4)
- _CxxThrowException (Address: 0x10012280)
- _errno (Address: 0x10012290)
- _except_handler4_common (Address: 0x10012284)
- _initterm (Address: 0x10012260)
- _lock (Address: 0x1001229c)
- _onexit (Address: 0x10012278)
- _purecall (Address: 0x100122b8)
- _snwprintf_s (Address: 0x10012294)
- _unlock (Address: 0x1001226c)
- _vsnwprintf_s (Address: 0x100122a0)
- _wstrdate (Address: 0x10012268)
- _wstrtime (Address: 0x1001228c)
- _XcptFilter (Address: 0x10012258)
- ??_V@YAXPAX@Z (Address: 0x100122bc)
- ??0exception@@QAE@ABQBD@Z (Address: 0x10012244)
- ??0exception@@QAE@ABQBDH@Z (Address: 0x10012248)
- ??0exception@@QAE@ABV0@@Z (Address: 0x1001224c)
- ??1exception@@UAE@XZ (Address: 0x10012250)
- ??1type_info@@UAE@XZ (Address: 0x100122c4)
- ??3@YAXPAX@Z (Address: 0x10012298)
- ?terminate@@YAXXZ (Address: 0x10012264)
- ?what@exception@@UBEPBDXZ (Address: 0x10012254)
- free (Address: 0x100122ac)
- malloc (Address: 0x100122b0)
- memcpy (Address: 0x1001227c)
- memcpy_s (Address: 0x100122a8)
- memmove (Address: 0x10012274)
- memset (Address: 0x100122c8)
- realloc (Address: 0x10012288)
- wcsncpy_s (Address: 0x100122b4)
NETAPI32.dll
- NetLocalGroupAddMembers (Address: 0x10012004)
- NetLocalGroupDelMembers (Address: 0x10012000)
OLEAUT32.dll
- SafeArrayAccessData (Address: 0x10012044)
- SafeArrayCopy (Address: 0x10012018)
- SafeArrayCreate (Address: 0x10012040)
- SafeArrayDestroy (Address: 0x1001200c)
- SafeArrayGetLBound (Address: 0x10012010)
- SafeArrayGetUBound (Address: 0x10012014)
- SafeArrayGetVartype (Address: 0x1001201c)
- SafeArrayLock (Address: 0x10012034)
- SafeArrayRedim (Address: 0x10012048)
- SafeArrayUnaccessData (Address: 0x10012020)
- SafeArrayUnlock (Address: 0x10012024)
- SysAllocString (Address: 0x10012030)
- SysFreeString (Address: 0x10012038)
- VariantClear (Address: 0x1001202c)
- VariantInit (Address: 0x10012028)
- VarUI4FromStr (Address: 0x1001203c)
WCP.dll
- ?RtlGetFacilityTracingFlags@Rtl@WCP@Windows@@YIKPAU_RTL_TRACING_FACILITY@123@@Z (Address: 0x10012054)
- ?RtlTraceFormat_PCWSTR_AsLiteralString@Rtl@WCP@Windows@@YIXPAUIRtlFormattedOutputStream@13@PBX@Z (Address: 0x10012060)
- ?RtlTraceVa@Rtl@WCP@Windows@@YIXKKPAU_RTL_TRACING_FACILITY@123@QBDKPAD@Z (Address: 0x1001206c)
- RtlConcatenateLUnicodeStrings (Address: 0x10012058)
- RtlConvertWin32RegistryPathToNtRegistryPath (Address: 0x10012050)
- RtlFreeLBlob (Address: 0x10012068)
- RtlFreeLUnicodeString (Address: 0x1001205c)
- RtlReportErrorOrigination (Address: 0x10012064)