computecore.dll

Description: Hyper-V Host Compute Service Core Client Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 8d96a3d70a43a29ffdf36ecd18133c9b

File Size: 663.4 KB

Uploaded At: Dec. 1, 2025, 7:24 a.m.

Views: 13

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • HcsEnumerateVmWorkerProcesses (Ordinal: 1, Address: 0x151e0)
  • HcsFindVmWorkerProcesses (Ordinal: 2, Address: 0x15360)
  • HcsGetWorkerProcessJob (Ordinal: 3, Address: 0x15430)
  • HcsStartVmWorkerProcess (Ordinal: 4, Address: 0x150e0)
  • HcsCancelOperation (Ordinal: 5, Address: 0x96e0)
  • HcsCloseComputeSystem (Ordinal: 6, Address: 0x102b0)
  • HcsCloseOperation (Ordinal: 7, Address: 0x9220)
  • HcsCloseProcess (Ordinal: 8, Address: 0xa8d0)
  • HcsCrashComputeSystem (Ordinal: 9, Address: 0x10930)
  • HcsCreateComputeSystem (Ordinal: 10, Address: 0xfdd0)
  • HcsCreateComputeSystemInNamespace (Ordinal: 11, Address: 0x10010)
  • HcsCreateEmptyGuestStateFile (Ordinal: 12, Address: 0x14470)
  • HcsCreateEmptyRuntimeStateFile (Ordinal: 13, Address: 0x146f0)
  • HcsCreateOperation (Ordinal: 14, Address: 0x9200)
  • HcsCreateProcess (Ordinal: 15, Address: 0xa420)
  • HcsEnumerateComputeSystems (Ordinal: 16, Address: 0xfbe0)
  • HcsEnumerateComputeSystemsInNamespace (Ordinal: 17, Address: 0xfd20)
  • HcsGetComputeSystemFromOperation (Ordinal: 18, Address: 0x92d0)
  • HcsGetComputeSystemProperties (Ordinal: 19, Address: 0x11270)
  • HcsGetOperationContext (Ordinal: 20, Address: 0x9240)
  • HcsGetOperationId (Ordinal: 21, Address: 0x9330)
  • HcsGetOperationResult (Ordinal: 22, Address: 0x9350)
  • HcsGetOperationResultAndProcessInfo (Ordinal: 23, Address: 0x9410)
  • HcsGetOperationType (Ordinal: 24, Address: 0x9310)
  • HcsGetProcessFromOperation (Ordinal: 25, Address: 0x92f0)
  • HcsGetProcessInfo (Ordinal: 26, Address: 0xad70)
  • HcsGetProcessProperties (Ordinal: 27, Address: 0xb080)
  • HcsGetServiceProperties (Ordinal: 28, Address: 0xb680)
  • HcsGrantVmAccess (Ordinal: 29, Address: 0x147e0)
  • HcsGrantVmGroupAccess (Ordinal: 30, Address: 0x14a60)
  • HcsModifyComputeSystem (Ordinal: 31, Address: 0x113b0)
  • HcsModifyProcess (Ordinal: 32, Address: 0xb270)
  • HcsModifyServiceSettings (Ordinal: 33, Address: 0xb7d0)
  • HcsOpenComputeSystem (Ordinal: 34, Address: 0x100d0)
  • HcsOpenComputeSystemInNamespace (Ordinal: 35, Address: 0x10200)
  • HcsOpenProcess (Ordinal: 36, Address: 0xa790)
  • HcsPauseComputeSystem (Ordinal: 37, Address: 0x10b80)
  • HcsResumeComputeSystem (Ordinal: 38, Address: 0x10dd0)
  • HcsRevokeVmAccess (Ordinal: 39, Address: 0x14920)
  • HcsRevokeVmGroupAccess (Ordinal: 40, Address: 0x14c80)
  • HcsSaveComputeSystem (Ordinal: 41, Address: 0x11020)
  • HcsSetComputeSystemCallback (Ordinal: 42, Address: 0x11620)
  • HcsSetOperationCallback (Ordinal: 43, Address: 0x9660)
  • HcsSetOperationContext (Ordinal: 44, Address: 0x9260)
  • HcsSetProcessCallback (Ordinal: 45, Address: 0xb520)
  • HcsShutDownComputeSystem (Ordinal: 46, Address: 0x105a0)
  • HcsSignalProcess (Ordinal: 47, Address: 0xaba0)
  • HcsStartComputeSystem (Ordinal: 48, Address: 0x10350)
  • HcsSubmitWerReport (Ordinal: 49, Address: 0x14ea0)
  • HcsTerminateComputeSystem (Ordinal: 50, Address: 0x107f0)
  • HcsTerminateProcess (Ordinal: 51, Address: 0xa9d0)
  • HcsWaitForOperationResult (Ordinal: 52, Address: 0x94d0)
  • HcsWaitForOperationResultAndProcessInfo (Ordinal: 53, Address: 0x9590)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180078090)
api-ms-win-core-com-l1-1-0.dll
  • CoCancelCall (Address: 0x1800780c8)
  • CoCreateInstance (Address: 0x1800780a8)
  • CoDisableCallCancellation (Address: 0x1800780b8)
  • CoEnableCallCancellation (Address: 0x1800780b0)
  • CoTaskMemAlloc (Address: 0x1800780c0)
  • CoTaskMemFree (Address: 0x1800780a0)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x1800780e0)
  • IsDebuggerPresent (Address: 0x1800780d8)
  • OutputDebugStringW (Address: 0x1800780e8)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800780f8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180078108)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180078120)
  • RaiseException (Address: 0x180078130)
  • SetLastError (Address: 0x180078128)
  • SetUnhandledExceptionFilter (Address: 0x180078138)
  • UnhandledExceptionFilter (Address: 0x180078118)
api-ms-win-core-errorhandling-l1-1-2.dll
  • RaiseFailFastException (Address: 0x180078148)
api-ms-win-core-featurestaging-l1-1-0.dll
  • GetFeatureEnabledState (Address: 0x180078158)
  • RecordFeatureUsage (Address: 0x180078170)
  • SubscribeFeatureStateChangeNotification (Address: 0x180078160)
  • UnsubscribeFeatureStateChangeNotification (Address: 0x180078168)
api-ms-win-core-file-l1-1-0.dll
  • CompareFileTime (Address: 0x1800781e0)
  • CreateDirectoryW (Address: 0x180078198)
  • CreateFileW (Address: 0x1800781a8)
  • DeleteFileW (Address: 0x1800781b0)
  • FlushFileBuffers (Address: 0x180078188)
  • GetDiskFreeSpaceW (Address: 0x1800781b8)
  • GetFileAttributesW (Address: 0x180078190)
  • GetFileInformationByHandle (Address: 0x180078200)
  • GetFileSizeEx (Address: 0x1800781d8)
  • GetFileTime (Address: 0x180078180)
  • GetFinalPathNameByHandleW (Address: 0x1800781f8)
  • LockFileEx (Address: 0x1800781f0)
  • ReadFile (Address: 0x1800781e8)
  • SetEndOfFile (Address: 0x1800781c8)
  • SetFilePointerEx (Address: 0x1800781d0)
  • SetFileTime (Address: 0x1800781c0)
  • UnlockFileEx (Address: 0x180078208)
  • WriteFile (Address: 0x1800781a0)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180078218)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180078238)
  • HeapAlloc (Address: 0x180078228)
  • HeapFree (Address: 0x180078230)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x180078248)
api-ms-win-core-heap-obsolete-l1-1-0.dll
  • LocalSize (Address: 0x180078258)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180078270)
  • InterlockedFlushSList (Address: 0x180078268)
  • InterlockedPopEntrySList (Address: 0x180078280)
  • InterlockedPushEntrySList (Address: 0x180078278)
api-ms-win-core-io-l1-1-0.dll
  • CancelIoEx (Address: 0x180078290)
  • DeviceIoControl (Address: 0x1800782a0)
  • GetOverlappedResult (Address: 0x180078298)
api-ms-win-core-io-l1-1-1.dll
  • GetOverlappedResultEx (Address: 0x1800782b0)
api-ms-win-core-libraryloader-l1-2-0.dll
  • GetModuleFileNameA (Address: 0x1800782e0)
  • GetModuleFileNameW (Address: 0x1800782d8)
  • GetModuleHandleExW (Address: 0x1800782d0)
  • GetModuleHandleW (Address: 0x1800782c8)
  • GetProcAddress (Address: 0x1800782c0)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800782f0)
api-ms-win-core-path-l1-1-0.dll
  • PathCchAddBackslash (Address: 0x180078300)
  • PathCchRemoveFileSpec (Address: 0x180078308)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180078320)
  • GetCurrentProcessId (Address: 0x180078328)
  • GetCurrentThreadId (Address: 0x180078318)
  • TerminateProcess (Address: 0x180078330)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180078348)
  • OpenProcess (Address: 0x180078340)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180078360)
  • QueryPerformanceFrequency (Address: 0x180078358)
api-ms-win-core-psapi-l1-1-0.dll
  • K32GetModuleInformation (Address: 0x180078370)
api-ms-win-core-realtime-l1-1-0.dll
  • QueryUnbiasedInterruptTime (Address: 0x180078380)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1800783a0)
  • RegGetValueW (Address: 0x1800783a8)
  • RegOpenKeyExW (Address: 0x180078398)
  • RegQueryValueExW (Address: 0x180078390)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x1800783b8)
  • RtlCaptureStackBackTrace (Address: 0x1800783c8)
  • RtlLookupFunctionEntry (Address: 0x1800783d0)
  • RtlPcToFileHeader (Address: 0x1800783d8)
  • RtlVirtualUnwind (Address: 0x1800783c0)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathIsRelativeW (Address: 0x180078400)
  • PathIsUNCServerShareW (Address: 0x1800783f0)
  • PathIsUNCServerW (Address: 0x1800783f8)
  • PathRemoveFileSpecW (Address: 0x1800783e8)
  • PathSkipRootW (Address: 0x180078408)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x180078420)
  • WideCharToMultiByte (Address: 0x180078418)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180078490)
  • AcquireSRWLockShared (Address: 0x1800784a8)
  • CreateEventExW (Address: 0x180078450)
  • CreateEventW (Address: 0x180078468)
  • CreateMutexExW (Address: 0x1800784d0)
  • CreateSemaphoreExW (Address: 0x180078440)
  • DeleteCriticalSection (Address: 0x1800784c8)
  • EnterCriticalSection (Address: 0x180078488)
  • InitializeCriticalSection (Address: 0x180078430)
  • InitializeCriticalSectionEx (Address: 0x1800784a0)
  • InitializeSRWLock (Address: 0x180078478)
  • LeaveCriticalSection (Address: 0x180078438)
  • OpenSemaphoreW (Address: 0x1800784b8)
  • ReleaseMutex (Address: 0x180078470)
  • ReleaseSemaphore (Address: 0x180078448)
  • ReleaseSRWLockExclusive (Address: 0x180078480)
  • ReleaseSRWLockShared (Address: 0x1800784c0)
  • ResetEvent (Address: 0x180078458)
  • SetEvent (Address: 0x180078498)
  • WaitForSingleObject (Address: 0x180078460)
  • WaitForSingleObjectEx (Address: 0x1800784b0)
api-ms-win-core-synch-l1-2-0.dll
  • InitializeConditionVariable (Address: 0x1800784f0)
  • InitOnceBeginInitialize (Address: 0x180078508)
  • InitOnceComplete (Address: 0x180078500)
  • SleepConditionVariableSRW (Address: 0x1800784e0)
  • WaitOnAddress (Address: 0x1800784f8)
  • WakeAllConditionVariable (Address: 0x1800784e8)
  • WakeByAddressAll (Address: 0x180078510)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180078530)
  • GetTickCount (Address: 0x180078528)
  • GetTickCount64 (Address: 0x180078520)
api-ms-win-core-threadpool-l1-2-0.dll
  • CallbackMayRunLong (Address: 0x180078590)
  • CloseThreadpoolTimer (Address: 0x180078598)
  • CloseThreadpoolWait (Address: 0x180078580)
  • CloseThreadpoolWork (Address: 0x180078578)
  • CreateThreadpoolTimer (Address: 0x180078588)
  • CreateThreadpoolWait (Address: 0x180078560)
  • CreateThreadpoolWork (Address: 0x180078570)
  • SetThreadpoolTimer (Address: 0x180078548)
  • SetThreadpoolWait (Address: 0x180078540)
  • SubmitThreadpoolWork (Address: 0x180078568)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180078550)
  • WaitForThreadpoolWaitCallbacks (Address: 0x180078558)
api-ms-win-core-winrt-string-l1-1-0.dll
  • WindowsCreateStringReference (Address: 0x1800785a8)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x180078748)
  • __CxxFrameHandler3 (Address: 0x1800786b8)
  • __CxxFrameHandler4 (Address: 0x180078750)
  • __std_terminate (Address: 0x180078740)
  • _CxxThrowException (Address: 0x1800786c0)
  • _o___std_exception_copy (Address: 0x180078720)
  • _o___std_exception_destroy (Address: 0x180078718)
  • _o___std_type_info_destroy_list (Address: 0x180078710)
  • _o___stdio_common_vsnprintf_s (Address: 0x1800786f8)
  • _o___stdio_common_vsnwprintf_s (Address: 0x1800786f0)
  • _o___stdio_common_vswprintf (Address: 0x1800786e8)
  • _o___stdio_common_vswprintf_s (Address: 0x1800786e0)
  • _o__callnewh (Address: 0x180078730)
  • _o__cexit (Address: 0x180078728)
  • _o__configure_narrow_argv (Address: 0x180078708)
  • _o__crt_atexit (Address: 0x180078700)
  • _o__errno (Address: 0x1800786d8)
  • _o__execute_onexit_table (Address: 0x1800786c8)
  • _o__initialize_narrow_environment (Address: 0x1800785b8)
  • _o__initialize_onexit_table (Address: 0x1800785c0)
  • _o__invalid_parameter_noinfo (Address: 0x1800785c8)
  • _o__invalid_parameter_noinfo_noreturn (Address: 0x1800785d0)
  • _o__isctype (Address: 0x1800785d8)
  • _o__purecall (Address: 0x1800785e0)
  • _o__register_onexit_function (Address: 0x1800785e8)
  • _o__resetstkoflw (Address: 0x1800785f0)
  • _o__seh_filter_dll (Address: 0x1800785f8)
  • _o__stricmp (Address: 0x180078600)
  • _o__wcsicmp (Address: 0x180078610)
  • _o__wcstoi64 (Address: 0x180078738)
  • _o__wcstoui64 (Address: 0x180078618)
  • _o__wtof (Address: 0x180078620)
  • _o__wtoi64 (Address: 0x180078628)
  • _o_abort (Address: 0x180078630)
  • _o_free (Address: 0x180078638)
  • _o_isalnum (Address: 0x180078640)
  • _o_isdigit (Address: 0x180078648)
  • _o_ispunct (Address: 0x180078650)
  • _o_iswalpha (Address: 0x180078658)
  • _o_iswascii (Address: 0x180078660)
  • _o_iswspace (Address: 0x180078668)
  • _o_malloc (Address: 0x180078670)
  • _o_strcpy_s (Address: 0x180078678)
  • _o_terminate (Address: 0x180078680)
  • _o_towupper (Address: 0x180078688)
  • _o_wcscpy_s (Address: 0x180078690)
  • _o_wcsncpy_s (Address: 0x180078698)
  • _o_wcstod (Address: 0x1800786a0)
  • _o_wcstoul (Address: 0x1800786a8)
  • _o_wcstoull (Address: 0x1800786b0)
  • memcmp (Address: 0x180078758)
  • memcpy (Address: 0x180078760)
  • memmove (Address: 0x180078608)
  • wcsstr (Address: 0x1800786d0)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180078778)
  • _initterm_e (Address: 0x180078770)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180078788)
  • wcsncmp (Address: 0x180078790)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventActivityIdControl (Address: 0x1800787a0)
  • EventEnabled (Address: 0x1800787b0)
  • EventRegister (Address: 0x1800787c8)
  • EventSetInformation (Address: 0x1800787c0)
  • EventUnregister (Address: 0x1800787a8)
  • EventWrite (Address: 0x1800787b8)
  • EventWriteEx (Address: 0x1800787d8)
  • EventWriteTransfer (Address: 0x1800787d0)
api-ms-win-security-base-l1-1-0.dll
  • CheckTokenMembership (Address: 0x180078808)
  • CopySid (Address: 0x180078810)
  • CreateWellKnownSid (Address: 0x180078818)
  • GetLengthSid (Address: 0x180078820)
  • GetSecurityDescriptorDacl (Address: 0x1800787e8)
  • GetSidLengthRequired (Address: 0x1800787f8)
  • GetSidSubAuthority (Address: 0x1800787f0)
  • InitializeSid (Address: 0x180078800)
api-ms-win-security-provider-l1-1-0.dll
  • GetSecurityInfo (Address: 0x180078840)
  • SetEntriesInAclW (Address: 0x180078838)
  • SetSecurityInfo (Address: 0x180078830)
combase.dll
  • (Address: 0x180078850)
KERNELBASE.dll
  • LocalAlloc (Address: 0x180078030)
  • LocalReAlloc (Address: 0x180078040)
  • Sleep (Address: 0x180078038)
ntdll.dll
  • NtCreateFile (Address: 0x1800788a8)
  • NtOpenJobObject (Address: 0x180078860)
  • RtlAllocateHeap (Address: 0x180078878)
  • RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x180078888)
  • RtlDosPathNameToRelativeNtPathName_U_WithStatus (Address: 0x1800788a0)
  • RtlFreeHeap (Address: 0x180078880)
  • RtlFreeUnicodeString (Address: 0x180078890)
  • RtlInitUnicodeString (Address: 0x180078870)
  • RtlInitUnicodeStringEx (Address: 0x180078898)
  • RtlNtStatusToDosError (Address: 0x180078868)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x180078070)
  • RpcBindingBind (Address: 0x180078060)
  • RpcBindingCreateW (Address: 0x180078068)
  • RpcBindingFree (Address: 0x180078058)
  • RpcExceptionFilter (Address: 0x180078050)
  • UuidCreate (Address: 0x180078080)
  • UuidFromStringW (Address: 0x180078078)