CmService.dll
Description: Container Manager Service
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.5848
Architecture: 64-bit
Operating System: Windows NT
SHA256: b5e051b861d89b29ad44251b1d344822
File Size: 1.0 MB
Uploaded At: Dec. 1, 2025, 8:11 a.m.
Views: 29
Security Warning
This file has been flagged as potentially dangerous.
Reason: Detected potentially dangerous functions used for process injection: OpenProcess
Exported Functions
- ServiceMain (Ordinal: 1, Address: 0x14740)
- SvchostPushServiceGlobals (Ordinal: 2, Address: 0x14730)
Imported DLLs & Functions
api-ms-win-appmodel-identity-l1-2-0.dll
- AppContainerDeriveSidFromMoniker (Address: 0x1800d07c0)
- AppContainerRegisterSid (Address: 0x1800d07c8)
api-ms-win-core-com-l1-1-0.dll
- CoTaskMemAlloc (Address: 0x1800d07e0)
- CoTaskMemFree (Address: 0x1800d07d8)
api-ms-win-core-debug-l1-1-0.dll
- DebugBreak (Address: 0x1800d0800)
- IsDebuggerPresent (Address: 0x1800d07f8)
- OutputDebugStringW (Address: 0x1800d07f0)
api-ms-win-core-errorhandling-l1-1-0.dll
- GetLastError (Address: 0x1800d0828)
- RaiseException (Address: 0x1800d0820)
- SetLastError (Address: 0x1800d0830)
- SetUnhandledExceptionFilter (Address: 0x1800d0810)
- UnhandledExceptionFilter (Address: 0x1800d0818)
api-ms-win-core-file-l1-1-0.dll
- CreateDirectoryW (Address: 0x1800d0848)
- CreateFileW (Address: 0x1800d0880)
- DeleteFileW (Address: 0x1800d0878)
- DeleteVolumeMountPointW (Address: 0x1800d0860)
- FindClose (Address: 0x1800d0888)
- FindFirstFileExW (Address: 0x1800d0858)
- FindNextFileW (Address: 0x1800d08b0)
- GetFileAttributesExW (Address: 0x1800d08b8)
- GetFileAttributesW (Address: 0x1800d08a0)
- GetFileSize (Address: 0x1800d0850)
- GetFileSizeEx (Address: 0x1800d0898)
- GetFinalPathNameByHandleW (Address: 0x1800d0890)
- ReadFile (Address: 0x1800d0840)
- RemoveDirectoryW (Address: 0x1800d08c0)
- SetFileAttributesW (Address: 0x1800d0870)
- SetFileInformationByHandle (Address: 0x1800d0868)
- WriteFile (Address: 0x1800d08a8)
api-ms-win-core-file-l1-2-0.dll
- GetTempPathW (Address: 0x1800d08d0)
- GetVolumeNameForVolumeMountPointW (Address: 0x1800d08d8)
api-ms-win-core-file-l2-1-0.dll
- CopyFile2 (Address: 0x1800d08f0)
- MoveFileExW (Address: 0x1800d08e8)
api-ms-win-core-file-l2-1-2.dll
- CopyFileW (Address: 0x1800d0900)
api-ms-win-core-handle-l1-1-0.dll
- CloseHandle (Address: 0x1800d0910)
- DuplicateHandle (Address: 0x1800d0918)
api-ms-win-core-heap-l1-1-0.dll
- GetProcessHeap (Address: 0x1800d0930)
- HeapAlloc (Address: 0x1800d0938)
- HeapFree (Address: 0x1800d0928)
api-ms-win-core-heap-l2-1-0.dll
- LocalAlloc (Address: 0x1800d0948)
- LocalFree (Address: 0x1800d0950)
api-ms-win-core-interlocked-l1-1-0.dll
- InitializeSListHead (Address: 0x1800d0960)
api-ms-win-core-job-l2-1-0.dll
- CreateJobObjectW (Address: 0x1800d0978)
- QueryInformationJobObject (Address: 0x1800d0970)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
- MoveFileW (Address: 0x1800d0990)
- UnregisterWait (Address: 0x1800d0988)
api-ms-win-core-libraryloader-l1-2-0.dll
- DisableThreadLibraryCalls (Address: 0x1800d09c8)
- FreeLibrary (Address: 0x1800d09a8)
- GetModuleFileNameA (Address: 0x1800d09c0)
- GetModuleHandleExW (Address: 0x1800d09b8)
- GetModuleHandleW (Address: 0x1800d09b0)
- GetProcAddress (Address: 0x1800d09d0)
- LoadLibraryExA (Address: 0x1800d09a0)
api-ms-win-core-localization-l1-2-0.dll
- FormatMessageW (Address: 0x1800d09e0)
api-ms-win-core-memory-l1-1-0.dll
- VirtualProtect (Address: 0x1800d09f0)
- VirtualQuery (Address: 0x1800d09f8)
api-ms-win-core-memory-l1-1-1.dll
- GetLargePageMinimum (Address: 0x1800d0a08)
api-ms-win-core-processthreads-l1-1-0.dll
- CreateProcessAsUserW (Address: 0x1800d0a40)
- CreateProcessW (Address: 0x1800d0a90)
- CreateThread (Address: 0x1800d0a38)
- DeleteProcThreadAttributeList (Address: 0x1800d0a30)
- GetCurrentProcess (Address: 0x1800d0a80)
- GetCurrentProcessId (Address: 0x1800d0a60)
- GetCurrentThread (Address: 0x1800d0a68)
- GetCurrentThreadId (Address: 0x1800d0a70)
- GetExitCodeProcess (Address: 0x1800d0a18)
- GetProcessId (Address: 0x1800d0a58)
- InitializeProcThreadAttributeList (Address: 0x1800d0a48)
- OpenProcessToken (Address: 0x1800d0a78)
- OpenThreadToken (Address: 0x1800d0a88)
- SetThreadToken (Address: 0x1800d0a20)
- TerminateProcess (Address: 0x1800d0a50)
- UpdateProcThreadAttribute (Address: 0x1800d0a28)
api-ms-win-core-processthreads-l1-1-1.dll
- IsProcessorFeaturePresent (Address: 0x1800d0aa8)
- OpenProcess (Address: 0x1800d0aa0)
api-ms-win-core-profile-l1-1-0.dll
- QueryPerformanceCounter (Address: 0x1800d0ab8)
api-ms-win-core-realtime-l1-1-0.dll
- QueryUnbiasedInterruptTime (Address: 0x1800d0ac8)
api-ms-win-core-registry-l1-1-0.dll
- RegCloseKey (Address: 0x1800d0b10)
- RegCreateKeyExW (Address: 0x1800d0ae8)
- RegDeleteKeyExW (Address: 0x1800d0b28)
- RegDeleteValueW (Address: 0x1800d0b18)
- RegEnumKeyExW (Address: 0x1800d0b30)
- RegEnumValueW (Address: 0x1800d0b20)
- RegGetValueW (Address: 0x1800d0ae0)
- RegLoadKeyW (Address: 0x1800d0af8)
- RegNotifyChangeKeyValue (Address: 0x1800d0ad8)
- RegOpenKeyExW (Address: 0x1800d0b00)
- RegSetValueExW (Address: 0x1800d0b08)
- RegUnLoadKeyW (Address: 0x1800d0af0)
api-ms-win-core-registry-l2-1-0.dll
- RegCreateKeyTransactedW (Address: 0x1800d0b48)
- RegDeleteKeyTransactedW (Address: 0x1800d0b58)
- RegDeleteKeyW (Address: 0x1800d0b50)
- RegOpenKeyTransactedW (Address: 0x1800d0b40)
api-ms-win-core-shlwapi-obsolete-l1-1-0.dll
- StrStrW (Address: 0x1800d0b68)
api-ms-win-core-string-l1-1-0.dll
- CompareStringOrdinal (Address: 0x1800d0b78)
api-ms-win-core-synch-l1-1-0.dll
- AcquireSRWLockExclusive (Address: 0x1800d0ba8)
- AcquireSRWLockShared (Address: 0x1800d0bb0)
- CreateEventExW (Address: 0x1800d0bd8)
- CreateMutexExW (Address: 0x1800d0bc8)
- CreateSemaphoreExW (Address: 0x1800d0ba0)
- DeleteCriticalSection (Address: 0x1800d0be0)
- EnterCriticalSection (Address: 0x1800d0b88)
- InitializeCriticalSectionEx (Address: 0x1800d0b98)
- LeaveCriticalSection (Address: 0x1800d0b90)
- OpenSemaphoreW (Address: 0x1800d0bd0)
- ReleaseMutex (Address: 0x1800d0bf8)
- ReleaseSemaphore (Address: 0x1800d0bf0)
- ReleaseSRWLockExclusive (Address: 0x1800d0c08)
- ReleaseSRWLockShared (Address: 0x1800d0be8)
- ResetEvent (Address: 0x1800d0c10)
- SetEvent (Address: 0x1800d0c00)
- WaitForSingleObject (Address: 0x1800d0bc0)
- WaitForSingleObjectEx (Address: 0x1800d0bb8)
api-ms-win-core-synch-l1-2-0.dll
- InitOnceBeginInitialize (Address: 0x1800d0c20)
- InitOnceComplete (Address: 0x1800d0c50)
- Sleep (Address: 0x1800d0c30)
- SleepConditionVariableSRW (Address: 0x1800d0c40)
- WaitOnAddress (Address: 0x1800d0c48)
- WakeByAddressAll (Address: 0x1800d0c28)
- WakeConditionVariable (Address: 0x1800d0c38)
api-ms-win-core-synch-l1-2-1.dll
- WaitForMultipleObjects (Address: 0x1800d0c60)
api-ms-win-core-sysinfo-l1-1-0.dll
- GetComputerNameExW (Address: 0x1800d0c80)
- GetSystemDirectoryW (Address: 0x1800d0ca0)
- GetSystemInfo (Address: 0x1800d0c88)
- GetSystemTimeAsFileTime (Address: 0x1800d0c70)
- GetSystemWindowsDirectoryW (Address: 0x1800d0c90)
- GetTickCount (Address: 0x1800d0c98)
- GetVersionExW (Address: 0x1800d0c78)
api-ms-win-core-sysinfo-l1-2-1.dll
- DnsHostnameToComputerNameExW (Address: 0x1800d0cb0)
api-ms-win-core-threadpool-l1-2-0.dll
- CallbackMayRunLong (Address: 0x1800d0d08)
- CloseThreadpoolTimer (Address: 0x1800d0d10)
- CloseThreadpoolWait (Address: 0x1800d0cd0)
- CloseThreadpoolWork (Address: 0x1800d0ce0)
- CreateThreadpoolTimer (Address: 0x1800d0cf8)
- CreateThreadpoolWait (Address: 0x1800d0d28)
- CreateThreadpoolWork (Address: 0x1800d0cc8)
- IsThreadpoolTimerSet (Address: 0x1800d0d00)
- SetThreadpoolTimer (Address: 0x1800d0cf0)
- SetThreadpoolWait (Address: 0x1800d0d20)
- SubmitThreadpoolWork (Address: 0x1800d0cc0)
- WaitForThreadpoolTimerCallbacks (Address: 0x1800d0ce8)
- WaitForThreadpoolWaitCallbacks (Address: 0x1800d0d18)
- WaitForThreadpoolWorkCallbacks (Address: 0x1800d0cd8)
api-ms-win-crt-math-l1-1-0.dll
- ceilf (Address: 0x1800d0d38)
api-ms-win-crt-private-l1-1-0.dll
- __C_specific_handler (Address: 0x1800d0e08)
- __CxxFrameHandler3 (Address: 0x1800d0e10)
- __CxxFrameHandler4 (Address: 0x1800d0e90)
- __std_terminate (Address: 0x1800d0e88)
- _CxxThrowException (Address: 0x1800d0e18)
- _o___std_exception_copy (Address: 0x1800d0e78)
- _o___std_exception_destroy (Address: 0x1800d0e70)
- _o___std_type_info_destroy_list (Address: 0x1800d0e68)
- _o___stdio_common_vsnprintf_s (Address: 0x1800d0e60)
- _o___stdio_common_vsnwprintf_s (Address: 0x1800d0e58)
- _o___stdio_common_vswprintf (Address: 0x1800d0e50)
- _o___stdio_common_vswprintf_s (Address: 0x1800d0e48)
- _o__callnewh (Address: 0x1800d0e38)
- _o__cexit (Address: 0x1800d0e30)
- _o__configure_narrow_argv (Address: 0x1800d0e28)
- _o__crt_atexit (Address: 0x1800d0e20)
- _o__errno (Address: 0x1800d0e80)
- _o__execute_onexit_table (Address: 0x1800d0e40)
- _o__initialize_narrow_environment (Address: 0x1800d0d48)
- _o__initialize_onexit_table (Address: 0x1800d0d50)
- _o__invalid_parameter_noinfo (Address: 0x1800d0d58)
- _o__invalid_parameter_noinfo_noreturn (Address: 0x1800d0d60)
- _o__purecall (Address: 0x1800d0d68)
- _o__register_onexit_function (Address: 0x1800d0d70)
- _o__seh_filter_dll (Address: 0x1800d0d78)
- _o__set_errno (Address: 0x1800d0d80)
- _o__wcstoi64 (Address: 0x1800d0d88)
- _o__wtoi (Address: 0x1800d0d98)
- _o_abort (Address: 0x1800d0da0)
- _o_calloc (Address: 0x1800d0da8)
- _o_free (Address: 0x1800d0db0)
- _o_iswxdigit (Address: 0x1800d0db8)
- _o_malloc (Address: 0x1800d0dc0)
- _o_srand (Address: 0x1800d0dc8)
- _o_terminate (Address: 0x1800d0dd0)
- _o_toupper (Address: 0x1800d0dd8)
- _o_wcscpy_s (Address: 0x1800d0de0)
- _o_wcsncat_s (Address: 0x1800d0de8)
- _o_wcsncpy_s (Address: 0x1800d0df0)
- _o_wcstod (Address: 0x1800d0df8)
- _o_wcstoull (Address: 0x1800d0e00)
- memcmp (Address: 0x1800d0e98)
- memcpy (Address: 0x1800d0ea0)
- memmove (Address: 0x1800d0d90)
api-ms-win-crt-runtime-l1-1-0.dll
- _initterm (Address: 0x1800d0eb8)
- _initterm_e (Address: 0x1800d0eb0)
api-ms-win-crt-string-l1-1-0.dll
- memset (Address: 0x1800d0ec8)
- wcscmp (Address: 0x1800d0ed0)
- wcsncmp (Address: 0x1800d0ed8)
api-ms-win-eventing-provider-l1-1-0.dll
- EventActivityIdControl (Address: 0x1800d0ef0)
- EventProviderEnabled (Address: 0x1800d0ee8)
- EventRegister (Address: 0x1800d0f08)
- EventSetInformation (Address: 0x1800d0f10)
- EventUnregister (Address: 0x1800d0f00)
- EventWriteTransfer (Address: 0x1800d0ef8)
api-ms-win-security-base-l1-1-0.dll
- AccessCheck (Address: 0x1800d0f20)
- AdjustTokenPrivileges (Address: 0x1800d0f50)
- AllocateAndInitializeSid (Address: 0x1800d0f70)
- DestroyPrivateObjectSecurity (Address: 0x1800d0f40)
- FreeSid (Address: 0x1800d0f48)
- GetSecurityDescriptorDacl (Address: 0x1800d0f58)
- GetSidLengthRequired (Address: 0x1800d0f78)
- GetSidSubAuthority (Address: 0x1800d0f68)
- GetTokenInformation (Address: 0x1800d0f28)
- InitializeSid (Address: 0x1800d0f60)
- MapGenericMask (Address: 0x1800d0f80)
- PrivilegeCheck (Address: 0x1800d0f38)
- RevertToSelf (Address: 0x1800d0f30)
api-ms-win-security-lsalookup-l2-1-0.dll
- LookupPrivilegeValueW (Address: 0x1800d0f90)
api-ms-win-security-provider-l1-1-0.dll
- GetNamedSecurityInfoW (Address: 0x1800d0fa8)
- GetSecurityInfo (Address: 0x1800d0fb0)
- SetEntriesInAclW (Address: 0x1800d0fa0)
- SetNamedSecurityInfoW (Address: 0x1800d0fc0)
- SetSecurityInfo (Address: 0x1800d0fb8)
api-ms-win-security-sddl-l1-1-0.dll
- ConvertSidToStringSidW (Address: 0x1800d0fe0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1800d0fd0)
- ConvertStringSidToSidW (Address: 0x1800d0fd8)
api-ms-win-security-trustee-l1-1-0.dll
- BuildTrusteeWithSidW (Address: 0x1800d0ff0)
api-ms-win-service-core-l1-1-0.dll
- RegisterServiceCtrlHandlerExW (Address: 0x1800d1008)
- SetServiceStatus (Address: 0x1800d1000)
api-ms-win-service-management-l1-1-0.dll
- CloseServiceHandle (Address: 0x1800d1028)
- OpenSCManagerW (Address: 0x1800d1030)
- OpenServiceW (Address: 0x1800d1020)
- StartServiceW (Address: 0x1800d1018)
api-ms-win-service-winsvc-l1-1-0.dll
- QueryServiceStatus (Address: 0x1800d1040)
api-ms-win-shcore-stream-l1-1-0.dll
- SHCreateMemStream (Address: 0x1800d1058)
- SHCreateStreamOnFileW (Address: 0x1800d1050)
api-ms-win-stateseparation-helpers-l1-1-0.dll
- GetPersistedRegistryLocationW (Address: 0x1800d1068)
bcrypt.dll
- BCryptCloseAlgorithmProvider (Address: 0x1800d1088)
- BCryptCreateHash (Address: 0x1800d10a0)
- BCryptDestroyHash (Address: 0x1800d1098)
- BCryptFinishHash (Address: 0x1800d1078)
- BCryptGetProperty (Address: 0x1800d1090)
- BCryptHashData (Address: 0x1800d10a8)
- BCryptOpenAlgorithmProvider (Address: 0x1800d1080)
computenetwork.dll
- HcnCloseGuestNetworkService (Address: 0x1800d10d8)
- HcnCreateGuestNetworkService (Address: 0x1800d10c8)
- HcnDeleteGuestNetworkService (Address: 0x1800d10b8)
- HcnModifyGuestNetworkService (Address: 0x1800d10c0)
- HcnOpenGuestNetworkService (Address: 0x1800d10d0)
CRYPT32.dll
- CryptBinaryToStringW (Address: 0x1800d0690)
IPHLPAPI.DLL
- CreateIpNetEntry (Address: 0x1800d06a8)
- GetBestInterface (Address: 0x1800d06a0)
- SetIpNetEntry (Address: 0x1800d06b0)
msvcp_win.dll
- ?_Xinvalid_argument@std@@YAXPEBD@Z (Address: 0x1800d10f8)
- ?_Xlength_error@std@@YAXPEBD@Z (Address: 0x1800d10f0)
- ?_Xout_of_range@std@@YAXPEBD@Z (Address: 0x1800d10e8)
ntdll.dll
- NtClose (Address: 0x1800d1138)
- NtCommitRegistryTransaction (Address: 0x1800d11d8)
- NtCreateRegistryTransaction (Address: 0x1800d11c8)
- NtCreateWnfStateName (Address: 0x1800d11e8)
- NtDeleteWnfStateName (Address: 0x1800d1128)
- NtManagePartition (Address: 0x1800d1258)
- NtOpenFile (Address: 0x1800d1110)
- NtQueryInformationProcess (Address: 0x1800d1180)
- NtQuerySystemInformation (Address: 0x1800d1160)
- NtQueryVirtualMemory (Address: 0x1800d1250)
- NtQueryWnfStateData (Address: 0x1800d1130)
- NtRollbackRegistryTransaction (Address: 0x1800d11a8)
- NtSetInformationFile (Address: 0x1800d1140)
- NtSetInformationJobObject (Address: 0x1800d1198)
- NtSetInformationVirtualMemory (Address: 0x1800d1200)
- NtSetSystemInformation (Address: 0x1800d11c0)
- NtTerminateProcess (Address: 0x1800d11e0)
- RtlAcquirePrivilege (Address: 0x1800d11d0)
- RtlCaptureContext (Address: 0x1800d1220)
- RtlClearAllBits (Address: 0x1800d1238)
- RtlClearBit (Address: 0x1800d11f8)
- RtlDoesFileExists_U (Address: 0x1800d1168)
- RtlDosPathNameToNtPathName_U_WithStatus (Address: 0x1800d1150)
- RtlEqualUnicodeString (Address: 0x1800d1188)
- RtlFindClearBitsAndSet (Address: 0x1800d1230)
- RtlFreeUnicodeString (Address: 0x1800d1148)
- RtlGetNtSystemRoot (Address: 0x1800d11b8)
- RtlInitializeBitMap (Address: 0x1800d1208)
- RtlInitUnicodeString (Address: 0x1800d1190)
- RtlIpv4StringToAddressW (Address: 0x1800d11a0)
- RtlLookupFunctionEntry (Address: 0x1800d1218)
- RtlNtStatusToDosError (Address: 0x1800d1108)
- RtlPublishWnfStateData (Address: 0x1800d1118)
- RtlQueryAllFeatureConfigurations (Address: 0x1800d11b0)
- RtlQueryUnbiasedInterruptTime (Address: 0x1800d1178)
- RtlReleasePrivilege (Address: 0x1800d11f0)
- RtlSetBits (Address: 0x1800d1228)
- RtlSubscribeWnfStateChangeNotification (Address: 0x1800d1170)
- RtlUnsubscribeWnfNotificationWaitForCompletion (Address: 0x1800d1158)
- RtlVirtualUnwind (Address: 0x1800d1210)
- RtlWaitForWnfMetaNotification (Address: 0x1800d1120)
- RtlWaitOnAddress (Address: 0x1800d1248)
- RtlWakeAddressAll (Address: 0x1800d1240)
RPCRT4.dll
- NdrClientCall3 (Address: 0x1800d0718)
- NdrServerCall2 (Address: 0x1800d06f8)
- NdrServerCallAll (Address: 0x1800d0708)
- RpcBindingFree (Address: 0x1800d0748)
- RpcBindingFromStringBindingW (Address: 0x1800d0728)
- RpcBindingSetAuthInfoExW (Address: 0x1800d0740)
- RpcBindingVectorFree (Address: 0x1800d06c0)
- RpcEpRegisterW (Address: 0x1800d0750)
- RpcEpUnregister (Address: 0x1800d0758)
- RpcImpersonateClient (Address: 0x1800d0760)
- RpcRevertToSelfEx (Address: 0x1800d06c8)
- RpcServerInqBindings (Address: 0x1800d0710)
- RpcServerRegisterIf3 (Address: 0x1800d06d8)
- RpcServerUnregisterIfEx (Address: 0x1800d06e8)
- RpcServerUseProtseqW (Address: 0x1800d06f0)
- RpcStringBindingComposeW (Address: 0x1800d0730)
- RpcStringFreeW (Address: 0x1800d0738)
- UuidCompare (Address: 0x1800d06e0)
- UuidCreate (Address: 0x1800d06d0)
- UuidFromStringW (Address: 0x1800d0700)
- UuidToStringW (Address: 0x1800d0720)
USERENV.dll
- CreateAppContainerProfile (Address: 0x1800d0788)
- CreateEnvironmentBlock (Address: 0x1800d0770)
- DeleteAppContainerProfile (Address: 0x1800d0780)
- DestroyEnvironmentBlock (Address: 0x1800d0778)
- GetAllUsersProfileDirectoryW (Address: 0x1800d0790)
VirtDisk.dll
- CreateVirtualDisk (Address: 0x1800d07a0)
XmlLite.dll
- CreateXmlReader (Address: 0x1800d07b0)