CORPerfMonExt.dll

Description: Microsoft Common Language Runtime - Performance Counter DLL

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.8.9093.0

Architecture: 32-bit

Operating System: Windows

SHA256: 1f48042aa68085d10d9800d24e1f96be

File Size: 123.9 KB

Uploaded At: Dec. 1, 2025, 7:19 a.m.

Views: 12

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • CloseCtrs (Ordinal: 1, Address: 0x97f0)
  • CollectCtrs (Ordinal: 2, Address: 0x9620)
  • DllRegisterServer (Ordinal: 3, Address: 0x9300)
  • DllUnRegisterServer (Ordinal: 4, Address: 0x9330)
  • OpenCtrs (Ordinal: 5, Address: 0x9400)

Imported DLLs & Functions

ADVAPI32.dll
  • AllocateAndInitializeSid (Address: 0x1001b01c)
  • CopySid (Address: 0x1001b02c)
  • DeleteAce (Address: 0x1001b010)
  • DeregisterEventSource (Address: 0x1001b048)
  • EqualSid (Address: 0x1001b028)
  • EventWrite (Address: 0x1001b03c)
  • FreeSid (Address: 0x1001b020)
  • GetKernelObjectSecurity (Address: 0x1001b034)
  • GetLengthSid (Address: 0x1001b054)
  • GetSecurityDescriptorDacl (Address: 0x1001b00c)
  • GetSecurityDescriptorOwner (Address: 0x1001b030)
  • GetTokenInformation (Address: 0x1001b044)
  • InitializeSecurityDescriptor (Address: 0x1001b018)
  • OpenProcessToken (Address: 0x1001b040)
  • OpenThreadToken (Address: 0x1001b038)
  • RegCloseKey (Address: 0x1001b000)
  • RegisterEventSourceW (Address: 0x1001b04c)
  • RegOpenKeyExW (Address: 0x1001b004)
  • RegQueryValueExW (Address: 0x1001b008)
  • ReportEventW (Address: 0x1001b050)
  • SetSecurityDescriptorDacl (Address: 0x1001b014)
  • SetThreadToken (Address: 0x1001b024)
KERNEL32.dll
  • ActivateActCtx (Address: 0x1001b07c)
  • CloseHandle (Address: 0x1001b110)
  • CreateActCtxW (Address: 0x1001b080)
  • CreateEventW (Address: 0x1001b0ac)
  • CreateMutexW (Address: 0x1001b0b8)
  • CreateSemaphoreW (Address: 0x1001b094)
  • CreateThread (Address: 0x1001b0ec)
  • CreateToolhelp32Snapshot (Address: 0x1001b10c)
  • DeactivateActCtx (Address: 0x1001b074)
  • DebugBreak (Address: 0x1001b134)
  • DeleteCriticalSection (Address: 0x1001b128)
  • EnterCriticalSection (Address: 0x1001b124)
  • FormatMessageW (Address: 0x1001b16c)
  • FreeLibrary (Address: 0x1001b138)
  • FreeLibraryAndExitThread (Address: 0x1001b0e8)
  • GetACP (Address: 0x1001b164)
  • GetCPInfo (Address: 0x1001b160)
  • GetCurrentProcess (Address: 0x1001b180)
  • GetCurrentProcessId (Address: 0x1001b14c)
  • GetCurrentThread (Address: 0x1001b1a0)
  • GetCurrentThreadId (Address: 0x1001b174)
  • GetEnvironmentVariableW (Address: 0x1001b194)
  • GetLastError (Address: 0x1001b100)
  • GetModuleFileNameW (Address: 0x1001b13c)
  • GetModuleHandleW (Address: 0x1001b0d4)
  • GetProcAddress (Address: 0x1001b148)
  • GetProcessHeap (Address: 0x1001b15c)
  • GetSystemDirectoryW (Address: 0x1001b19c)
  • GetSystemInfo (Address: 0x1001b118)
  • GetSystemTimeAsFileTime (Address: 0x1001b178)
  • GetTickCount (Address: 0x1001b114)
  • GetWindowsDirectoryW (Address: 0x1001b06c)
  • HeapAlloc (Address: 0x1001b158)
  • HeapCreate (Address: 0x1001b0d0)
  • HeapDestroy (Address: 0x1001b098)
  • HeapFree (Address: 0x1001b154)
  • HeapValidate (Address: 0x1001b0b0)
  • InitializeCriticalSection (Address: 0x1001b12c)
  • InitializeSListHead (Address: 0x1001b0dc)
  • IsDebuggerPresent (Address: 0x1001b060)
  • IsProcessorFeaturePresent (Address: 0x1001b068)
  • IsWow64Process (Address: 0x1001b190)
  • LeaveCriticalSection (Address: 0x1001b120)
  • LoadLibraryExW (Address: 0x1001b150)
  • LocalFree (Address: 0x1001b170)
  • MapViewOfFile (Address: 0x1001b0f8)
  • MultiByteToWideChar (Address: 0x1001b168)
  • OpenEventW (Address: 0x1001b0e0)
  • OpenFileMappingW (Address: 0x1001b0f4)
  • OpenProcess (Address: 0x1001b144)
  • OutputDebugStringW (Address: 0x1001b070)
  • Process32FirstW (Address: 0x1001b108)
  • Process32NextW (Address: 0x1001b104)
  • QueryPerformanceCounter (Address: 0x1001b0d8)
  • QueryPerformanceFrequency (Address: 0x1001b11c)
  • RaiseException (Address: 0x1001b17c)
  • ReleaseActCtx (Address: 0x1001b064)
  • ReleaseMutex (Address: 0x1001b0b4)
  • ReleaseSemaphore (Address: 0x1001b0c0)
  • ResetEvent (Address: 0x1001b09c)
  • ResumeThread (Address: 0x1001b0f0)
  • SetErrorMode (Address: 0x1001b078)
  • SetEvent (Address: 0x1001b0a8)
  • SetLastError (Address: 0x1001b140)
  • SetUnhandledExceptionFilter (Address: 0x1001b130)
  • SleepEx (Address: 0x1001b090)
  • TerminateProcess (Address: 0x1001b184)
  • TlsAlloc (Address: 0x1001b0a0)
  • TlsFree (Address: 0x1001b088)
  • TlsGetValue (Address: 0x1001b08c)
  • TlsSetValue (Address: 0x1001b0cc)
  • UnhandledExceptionFilter (Address: 0x1001b05c)
  • UnmapViewOfFile (Address: 0x1001b0fc)
  • VerifyVersionInfoW (Address: 0x1001b18c)
  • VerSetConditionMask (Address: 0x1001b188)
  • VirtualAlloc (Address: 0x1001b0bc)
  • VirtualFree (Address: 0x1001b0c4)
  • VirtualProtect (Address: 0x1001b0c8)
  • VirtualQuery (Address: 0x1001b084)
  • WaitForMultipleObjects (Address: 0x1001b0e4)
  • WaitForSingleObject (Address: 0x1001b198)
  • WaitForSingleObjectEx (Address: 0x1001b0a4)
mscoree.dll
  • GetRequestedRuntimeInfo (Address: 0x1001b1f4)
OLEAUT32.dll
  • SetErrorInfo (Address: 0x1001b1a8)
ucrtbase_clr0400.dll
  • __acrt_iob_func (Address: 0x1001b204)
  • __stdio_common_vfwprintf (Address: 0x1001b1fc)
  • __stdio_common_vsnprintf_s (Address: 0x1001b21c)
  • __stdio_common_vsnwprintf_s (Address: 0x1001b218)
  • __stdio_common_vswprintf_s (Address: 0x1001b234)
  • _cexit (Address: 0x1001b258)
  • _configure_narrow_argv (Address: 0x1001b240)
  • _crt_atexit (Address: 0x1001b254)
  • _errno (Address: 0x1001b220)
  • _execute_onexit_table (Address: 0x1001b250)
  • _initialize_narrow_environment (Address: 0x1001b244)
  • _initialize_onexit_table (Address: 0x1001b248)
  • _initterm (Address: 0x1001b25c)
  • _initterm_e (Address: 0x1001b210)
  • _register_onexit_function (Address: 0x1001b24c)
  • _seh_filter_dll (Address: 0x1001b23c)
  • _wsystem (Address: 0x1001b238)
  • fflush (Address: 0x1001b200)
  • free (Address: 0x1001b20c)
  • malloc (Address: 0x1001b208)
  • strcpy_s (Address: 0x1001b214)
  • wcscat_s (Address: 0x1001b228)
  • wcscpy_s (Address: 0x1001b22c)
  • wcsncpy_s (Address: 0x1001b230)
  • wcstoul (Address: 0x1001b224)
USER32.dll
  • GetProcessWindowStation (Address: 0x1001b1b0)
  • GetUserObjectInformationW (Address: 0x1001b1b8)
  • LoadStringW (Address: 0x1001b1b4)
VCRUNTIME140_CLR0400.dll
  • __CxxFrameHandler3 (Address: 0x1001b1c8)
  • __std_type_info_destroy_list (Address: 0x1001b1d8)
  • _CxxThrowException (Address: 0x1001b1c0)
  • _except_handler4_common (Address: 0x1001b1d4)
  • _purecall (Address: 0x1001b1d0)
  • memcpy (Address: 0x1001b1c4)
  • memmove (Address: 0x1001b1e0)
  • memset (Address: 0x1001b1dc)
  • wcsrchr (Address: 0x1001b1cc)
WTSAPI32.dll
  • WTSEnumerateProcessesW (Address: 0x1001b1e8)
  • WTSFreeMemory (Address: 0x1001b1ec)