CORPerfMonExt.dll

Description: Microsoft Common Language Runtime - Performance Counter DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.8.9093.0

Architecture: 64-bit

Operating System: Windows

SHA256: 49f72783d1c7d818ad6b1ee93c02d20f

File Size: 138.4 KB

Uploaded At: Dec. 1, 2025, 7:19 a.m.

Views: 25

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • CloseCtrs (Ordinal: 1, Address: 0x18d0)
  • CollectCtrs (Ordinal: 2, Address: 0x14b0)
  • DllRegisterServer (Ordinal: 3, Address: 0x10d0)
  • DllUnRegisterServer (Ordinal: 4, Address: 0x1110)
  • OpenCtrs (Ordinal: 5, Address: 0x1220)

Imported DLLs & Functions

ADVAPI32.dll
  • AllocateAndInitializeSid (Address: 0x180011038)
  • CopySid (Address: 0x180011058)
  • DeleteAce (Address: 0x180011020)
  • DeregisterEventSource (Address: 0x180011090)
  • EqualSid (Address: 0x180011050)
  • EventWrite (Address: 0x180011078)
  • FreeSid (Address: 0x180011040)
  • GetKernelObjectSecurity (Address: 0x180011068)
  • GetLengthSid (Address: 0x1800110a8)
  • GetSecurityDescriptorDacl (Address: 0x180011018)
  • GetSecurityDescriptorOwner (Address: 0x180011060)
  • GetTokenInformation (Address: 0x180011088)
  • InitializeSecurityDescriptor (Address: 0x180011030)
  • OpenProcessToken (Address: 0x180011080)
  • OpenThreadToken (Address: 0x180011070)
  • RegCloseKey (Address: 0x180011000)
  • RegisterEventSourceW (Address: 0x180011098)
  • RegOpenKeyExW (Address: 0x180011008)
  • RegQueryValueExW (Address: 0x180011010)
  • ReportEventW (Address: 0x1800110a0)
  • SetSecurityDescriptorDacl (Address: 0x180011028)
  • SetThreadToken (Address: 0x180011048)
KERNEL32.dll
  • ActivateActCtx (Address: 0x180011110)
  • CloseHandle (Address: 0x180011238)
  • CreateActCtxW (Address: 0x180011118)
  • CreateEventW (Address: 0x180011170)
  • CreateMutexW (Address: 0x180011188)
  • CreateSemaphoreW (Address: 0x180011140)
  • CreateThread (Address: 0x1800111e8)
  • CreateToolhelp32Snapshot (Address: 0x180011230)
  • DeactivateActCtx (Address: 0x180011100)
  • DebugBreak (Address: 0x1800112f8)
  • DeleteCriticalSection (Address: 0x180011268)
  • EnterCriticalSection (Address: 0x180011260)
  • FormatMessageW (Address: 0x1800112e8)
  • FreeLibrary (Address: 0x180011280)
  • FreeLibraryAndExitThread (Address: 0x1800111e0)
  • GetACP (Address: 0x1800112d8)
  • GetCPInfo (Address: 0x1800112d0)
  • GetCurrentProcess (Address: 0x180011320)
  • GetCurrentProcessId (Address: 0x1800112a8)
  • GetCurrentThread (Address: 0x180011358)
  • GetCurrentThreadId (Address: 0x180011300)
  • GetEnvironmentVariableW (Address: 0x180011340)
  • GetLastError (Address: 0x180011218)
  • GetModuleFileNameW (Address: 0x180011288)
  • GetModuleHandleW (Address: 0x1800111c0)
  • GetProcAddress (Address: 0x1800112a0)
  • GetProcessHeap (Address: 0x1800112c8)
  • GetSystemDirectoryW (Address: 0x180011350)
  • GetSystemInfo (Address: 0x180011248)
  • GetSystemTimeAsFileTime (Address: 0x180011308)
  • GetTickCount (Address: 0x180011240)
  • GetWindowsDirectoryW (Address: 0x1800110f0)
  • HeapAlloc (Address: 0x1800112c0)
  • HeapCreate (Address: 0x1800111b8)
  • HeapDestroy (Address: 0x180011148)
  • HeapFree (Address: 0x1800112b8)
  • HeapValidate (Address: 0x180011178)
  • InitializeCriticalSection (Address: 0x180011270)
  • InitializeSListHead (Address: 0x1800111c8)
  • IsDebuggerPresent (Address: 0x1800110e0)
  • IsProcessorFeaturePresent (Address: 0x1800110d8)
  • IsWow64Process (Address: 0x1800111f8)
  • LeaveCriticalSection (Address: 0x180011258)
  • LoadLibraryExW (Address: 0x1800112b0)
  • LocalFree (Address: 0x1800112f0)
  • MapViewOfFile (Address: 0x180011208)
  • MultiByteToWideChar (Address: 0x1800112e0)
  • OpenEventW (Address: 0x1800111d0)
  • OpenFileMappingW (Address: 0x180011200)
  • OpenProcess (Address: 0x180011298)
  • OutputDebugStringW (Address: 0x1800110f8)
  • Process32FirstW (Address: 0x180011228)
  • Process32NextW (Address: 0x180011220)
  • QueryPerformanceCounter (Address: 0x180011310)
  • QueryPerformanceFrequency (Address: 0x180011250)
  • RaiseException (Address: 0x180011318)
  • ReleaseActCtx (Address: 0x1800110e8)
  • ReleaseMutex (Address: 0x180011180)
  • ReleaseSemaphore (Address: 0x180011198)
  • ResetEvent (Address: 0x180011150)
  • ResumeThread (Address: 0x1800111f0)
  • RtlCaptureContext (Address: 0x1800110d0)
  • RtlLookupFunctionEntry (Address: 0x1800110c8)
  • RtlVirtualUnwind (Address: 0x1800110c0)
  • SetErrorMode (Address: 0x180011108)
  • SetEvent (Address: 0x180011168)
  • SetLastError (Address: 0x180011290)
  • SetUnhandledExceptionFilter (Address: 0x180011278)
  • SleepEx (Address: 0x180011138)
  • TerminateProcess (Address: 0x180011328)
  • TlsAlloc (Address: 0x180011158)
  • TlsFree (Address: 0x180011128)
  • TlsGetValue (Address: 0x180011130)
  • TlsSetValue (Address: 0x1800111b0)
  • UnhandledExceptionFilter (Address: 0x1800110b8)
  • UnmapViewOfFile (Address: 0x180011210)
  • VerifyVersionInfoW (Address: 0x180011338)
  • VerSetConditionMask (Address: 0x180011330)
  • VirtualAlloc (Address: 0x180011190)
  • VirtualFree (Address: 0x1800111a0)
  • VirtualProtect (Address: 0x1800111a8)
  • VirtualQuery (Address: 0x180011120)
  • WaitForMultipleObjects (Address: 0x1800111d8)
  • WaitForSingleObject (Address: 0x180011348)
  • WaitForSingleObjectEx (Address: 0x180011160)
mscoree.dll
  • GetRequestedRuntimeInfo (Address: 0x180011408)
OLEAUT32.dll
  • SetErrorInfo (Address: 0x180011368)
ucrtbase_clr0400.dll
  • __acrt_iob_func (Address: 0x180011420)
  • __stdio_common_vfwprintf (Address: 0x180011458)
  • __stdio_common_vsnprintf_s (Address: 0x180011450)
  • __stdio_common_vsnwprintf_s (Address: 0x180011448)
  • __stdio_common_vswprintf_s (Address: 0x180011488)
  • _cexit (Address: 0x1800114d8)
  • _configure_narrow_argv (Address: 0x1800114a8)
  • _crt_atexit (Address: 0x1800114d0)
  • _errno (Address: 0x180011460)
  • _execute_onexit_table (Address: 0x1800114c8)
  • _initialize_narrow_environment (Address: 0x1800114b0)
  • _initialize_onexit_table (Address: 0x1800114b8)
  • _initterm (Address: 0x180011438)
  • _initterm_e (Address: 0x180011498)
  • _register_onexit_function (Address: 0x1800114c0)
  • _seh_filter_dll (Address: 0x1800114a0)
  • _wsystem (Address: 0x180011490)
  • fflush (Address: 0x180011418)
  • free (Address: 0x180011430)
  • malloc (Address: 0x180011428)
  • strcpy_s (Address: 0x180011440)
  • wcscat_s (Address: 0x180011470)
  • wcscmp (Address: 0x1800114e0)
  • wcscpy_s (Address: 0x180011478)
  • wcsncpy_s (Address: 0x180011480)
  • wcstoul (Address: 0x180011468)
USER32.dll
  • GetProcessWindowStation (Address: 0x180011380)
  • GetUserObjectInformationW (Address: 0x180011378)
  • LoadStringW (Address: 0x180011388)
VCRUNTIME140_1_CLR0400.dll
  • __CxxFrameHandler4 (Address: 0x180011398)
VCRUNTIME140_CLR0400.dll
  • __C_specific_handler (Address: 0x1800113d8)
  • __std_type_info_destroy_list (Address: 0x1800113c8)
  • _CxxThrowException (Address: 0x1800113b0)
  • _purecall (Address: 0x1800113c0)
  • memcpy (Address: 0x1800113e0)
  • memmove (Address: 0x1800113a8)
  • memset (Address: 0x1800113d0)
  • wcsrchr (Address: 0x1800113b8)
WTSAPI32.dll
  • WTSEnumerateProcessesW (Address: 0x1800113f0)
  • WTSFreeMemory (Address: 0x1800113f8)