AMMonitoringProvider.dll

Description: Microsoft Security Client Antimalware Monitoring Provider

Authors: © Microsoft Corporation. All rights reserved.

Version: 4.18.1907.16384

Architecture: 64-bit

Operating System: Windows NT

SHA256: d59587f93579682774e3135b49cfa07c

File Size: 200.9 KB

Uploaded At: Dec. 1, 2025, 8:30 a.m.

Views: 21

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • DllCanUnloadNow (Ordinal: 1, Address: 0x7730)
  • DllGetClassObject (Ordinal: 2, Address: 0x7770)
  • DllRegisterServer (Ordinal: 3, Address: 0x78b0)
  • DllUnregisterServer (Ordinal: 4, Address: 0x7990)

Imported DLLs & Functions

ADVAPI32.dll
  • AdjustTokenPrivileges (Address: 0x180021798)
  • AllocateAndInitializeSid (Address: 0x180021850)
  • ChangeServiceConfigW (Address: 0x1800217c0)
  • CheckTokenMembership (Address: 0x180021848)
  • CloseServiceHandle (Address: 0x180021778)
  • ControlService (Address: 0x1800217b8)
  • ControlTraceW (Address: 0x180021730)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180021860)
  • CreateProcessAsUserW (Address: 0x180021780)
  • DeregisterEventSource (Address: 0x180021718)
  • DuplicateTokenEx (Address: 0x1800217c8)
  • EnableTrace (Address: 0x180021728)
  • FreeSid (Address: 0x180021770)
  • GetSidSubAuthority (Address: 0x180021858)
  • GetSidSubAuthorityCount (Address: 0x180021768)
  • GetTokenInformation (Address: 0x180021758)
  • GetTraceEnableFlags (Address: 0x1800217e0)
  • GetTraceEnableLevel (Address: 0x1800217e8)
  • GetTraceLoggerHandle (Address: 0x1800217f0)
  • GetUserNameW (Address: 0x180021750)
  • InitiateSystemShutdownExW (Address: 0x180021790)
  • LookupPrivilegeNameW (Address: 0x180021788)
  • LookupPrivilegeValueW (Address: 0x1800217a8)
  • OpenProcessToken (Address: 0x180021738)
  • OpenSCManagerW (Address: 0x180021840)
  • OpenServiceW (Address: 0x180021838)
  • OpenThreadToken (Address: 0x180021760)
  • PrivilegeCheck (Address: 0x1800217a0)
  • QueryServiceStatus (Address: 0x1800217b0)
  • RegCloseKey (Address: 0x180021830)
  • RegCreateKeyExW (Address: 0x180021808)
  • RegDeleteKeyW (Address: 0x180021740)
  • RegDeleteValueW (Address: 0x180021800)
  • RegEnumKeyExW (Address: 0x180021820)
  • RegisterEventSourceW (Address: 0x180021720)
  • RegisterTraceGuidsW (Address: 0x1800217d8)
  • RegOpenKeyExW (Address: 0x180021818)
  • RegQueryInfoKeyW (Address: 0x180021828)
  • RegQueryValueExW (Address: 0x180021748)
  • RegSetValueExW (Address: 0x180021810)
  • ReportEventW (Address: 0x180021710)
  • TraceMessage (Address: 0x1800217f8)
  • UnregisterTraceGuids (Address: 0x1800217d0)
CRYPT32.dll
  • CertVerifyCertificateChainPolicy (Address: 0x180021870)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1800218b8)
  • CloseHandle (Address: 0x180021968)
  • CopyFileW (Address: 0x180021af0)
  • CreateDirectoryW (Address: 0x180021990)
  • CreateEventW (Address: 0x180021a08)
  • CreateFileW (Address: 0x1800219e8)
  • CreateMutexW (Address: 0x180021b00)
  • CreateProcessW (Address: 0x180021a38)
  • CreateThread (Address: 0x180021b80)
  • CreateToolhelp32Snapshot (Address: 0x180021b28)
  • DecodePointer (Address: 0x180021948)
  • DeleteCriticalSection (Address: 0x180021930)
  • DeleteFileW (Address: 0x180021a18)
  • DisableThreadLibraryCalls (Address: 0x180021a48)
  • EncodePointer (Address: 0x180021950)
  • EnterCriticalSection (Address: 0x180021908)
  • ExpandEnvironmentStringsW (Address: 0x1800219c0)
  • FileTimeToSystemTime (Address: 0x180021a58)
  • FindClose (Address: 0x1800219d8)
  • FindFirstFileW (Address: 0x1800219a0)
  • FindNextFileW (Address: 0x1800219b0)
  • FindResourceExW (Address: 0x180021940)
  • FindResourceW (Address: 0x180021b40)
  • FreeLibrary (Address: 0x180021ae0)
  • FreeResource (Address: 0x180021b48)
  • GetCurrentProcess (Address: 0x1800218d0)
  • GetCurrentProcessId (Address: 0x180021898)
  • GetCurrentThread (Address: 0x180021960)
  • GetCurrentThreadId (Address: 0x180021890)
  • GetDiskFreeSpaceExW (Address: 0x180021b20)
  • GetDriveTypeW (Address: 0x180021bc8)
  • GetExitCodeProcess (Address: 0x180021a40)
  • GetExitCodeThread (Address: 0x180021b88)
  • GetFileAttributesW (Address: 0x1800219f0)
  • GetFileSize (Address: 0x180021b68)
  • GetFileSizeEx (Address: 0x1800219a8)
  • GetLastError (Address: 0x180021ad8)
  • GetLocaleInfoW (Address: 0x180021af8)
  • GetLocalTime (Address: 0x180021a60)
  • GetLongPathNameW (Address: 0x180021b70)
  • GetModuleFileNameW (Address: 0x180021938)
  • GetModuleHandleW (Address: 0x180021ac0)
  • GetNativeSystemInfo (Address: 0x180021a20)
  • GetPrivateProfileIntW (Address: 0x180021b98)
  • GetPrivateProfileStringW (Address: 0x180021b90)
  • GetProcAddress (Address: 0x180021ad0)
  • GetProcessHeap (Address: 0x180021a90)
  • GetSystemDefaultUILanguage (Address: 0x180021ba8)
  • GetSystemDirectoryW (Address: 0x1800219f8)
  • GetSystemTimeAsFileTime (Address: 0x180021888)
  • GetTempFileNameW (Address: 0x180021ae8)
  • GetTempPathW (Address: 0x1800219d0)
  • GetThreadLocale (Address: 0x180021918)
  • GetTickCount (Address: 0x180021b50)
  • GetUserDefaultUILanguage (Address: 0x180021bb0)
  • GetVersionExW (Address: 0x180021bc0)
  • GetWindowsDirectoryW (Address: 0x180021b18)
  • GlobalFindAtomW (Address: 0x180021bd0)
  • HeapAlloc (Address: 0x180021a88)
  • HeapDestroy (Address: 0x180021a98)
  • HeapFree (Address: 0x180021a80)
  • HeapReAlloc (Address: 0x180021a78)
  • HeapSize (Address: 0x180021a70)
  • InitializeCriticalSection (Address: 0x180021928)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180021988)
  • IsWow64Process (Address: 0x180021b10)
  • K32GetModuleFileNameExW (Address: 0x180021b58)
  • LeaveCriticalSection (Address: 0x180021900)
  • LoadLibraryExW (Address: 0x180021ac8)
  • LoadResource (Address: 0x180021958)
  • LocalFree (Address: 0x180021a30)
  • LockResource (Address: 0x180021978)
  • lstrcmpiW (Address: 0x180021ab8)
  • MoveFileW (Address: 0x180021b78)
  • MultiByteToWideChar (Address: 0x180021aa8)
  • OpenProcess (Address: 0x180021a00)
  • OutputDebugStringA (Address: 0x180021880)
  • Process32FirstW (Address: 0x180021b30)
  • Process32NextW (Address: 0x180021b38)
  • ProcessIdToSessionId (Address: 0x180021bb8)
  • QueryPerformanceCounter (Address: 0x1800218a0)
  • RaiseException (Address: 0x180021ab0)
  • ReadFile (Address: 0x180021998)
  • ReleaseMutex (Address: 0x180021b08)
  • ReleaseSRWLockExclusive (Address: 0x1800218c0)
  • RemoveDirectoryW (Address: 0x1800219c8)
  • ResetEvent (Address: 0x180021a28)
  • RtlCaptureContext (Address: 0x1800218f8)
  • RtlLookupFunctionEntry (Address: 0x1800218f0)
  • RtlVirtualUnwind (Address: 0x1800218e8)
  • SetEvent (Address: 0x180021a10)
  • SetLastError (Address: 0x180021980)
  • SetThreadLocale (Address: 0x180021910)
  • SetUnhandledExceptionFilter (Address: 0x1800218d8)
  • SizeofResource (Address: 0x180021aa0)
  • Sleep (Address: 0x180021920)
  • SleepConditionVariableSRW (Address: 0x1800218a8)
  • SwitchToThread (Address: 0x180021970)
  • SystemTimeToFileTime (Address: 0x180021a68)
  • TerminateProcess (Address: 0x1800218c8)
  • UnhandledExceptionFilter (Address: 0x1800218e0)
  • VerifyVersionInfoW (Address: 0x180021b60)
  • VirtualLock (Address: 0x180021a50)
  • WaitForSingleObject (Address: 0x1800219e0)
  • WakeAllConditionVariable (Address: 0x1800218b0)
  • WriteFile (Address: 0x1800219b8)
  • WritePrivateProfileStringW (Address: 0x180021ba0)
mpclient.dll
  • MpClientUtilExportFunctions (Address: 0x180021df0)
msvcrt.dll
  • __C_specific_handler (Address: 0x180021ee0)
  • __CxxFrameHandler3 (Address: 0x180021f08)
  • __dllonexit (Address: 0x180021e28)
  • _amsg_exit (Address: 0x180021e50)
  • _CxxThrowException (Address: 0x180021e70)
  • _errno (Address: 0x180021e10)
  • _initterm (Address: 0x180021f38)
  • _lock (Address: 0x180021f10)
  • _onexit (Address: 0x180021e20)
  • _purecall (Address: 0x180021ee8)
  • _unlock (Address: 0x180021e30)
  • _vscwprintf (Address: 0x180021f20)
  • _vsnprintf (Address: 0x180021e00)
  • _vsnwprintf (Address: 0x180021f18)
  • _wchmod (Address: 0x180021ef0)
  • _wcstoui64 (Address: 0x180021e48)
  • _XcptFilter (Address: 0x180021e58)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180021e78)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180021e98)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180021e90)
  • ??0exception@@QEAA@XZ (Address: 0x180021e80)
  • ??1exception@@UEAA@XZ (Address: 0x180021ea0)
  • ??1type_info@@UEAA@XZ (Address: 0x180021e18)
  • ?terminate@@YAXXZ (Address: 0x180021e40)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180021ea8)
  • free (Address: 0x180021ec8)
  • iswalpha (Address: 0x180021f00)
  • malloc (Address: 0x180021ed0)
  • memcpy (Address: 0x180021e68)
  • memcpy_s (Address: 0x180021ec0)
  • memmove (Address: 0x180021e60)
  • memmove_s (Address: 0x180021e88)
  • memset (Address: 0x180021f40)
  • realloc (Address: 0x180021e08)
  • swscanf_s (Address: 0x180021f30)
  • vswprintf_s (Address: 0x180021f28)
  • wcscat_s (Address: 0x180021eb0)
  • wcschr (Address: 0x180021e38)
  • wcscpy_s (Address: 0x180021eb8)
  • wcsncpy_s (Address: 0x180021ed8)
  • wcsrchr (Address: 0x180021ef8)
ntdll.dll
  • RtlGetVersion (Address: 0x180021f50)
  • RtlNtStatusToDosError (Address: 0x180021f58)
ole32.dll
  • CoCreateGuid (Address: 0x180021fa0)
  • CoCreateInstance (Address: 0x180021f80)
  • CoImpersonateClient (Address: 0x180021f68)
  • CoRevertToSelf (Address: 0x180021f70)
  • CoTaskMemAlloc (Address: 0x180021f88)
  • CoTaskMemFree (Address: 0x180021f98)
  • CoTaskMemRealloc (Address: 0x180021f90)
  • StringFromGUID2 (Address: 0x180021f78)
OLEAUT32.dll
  • SysAllocString (Address: 0x180021c20)
  • SysAllocStringLen (Address: 0x180021be8)
  • SysFreeString (Address: 0x180021c08)
  • SysStringByteLen (Address: 0x180021be0)
  • SysStringLen (Address: 0x180021bf8)
  • VarBstrCat (Address: 0x180021c00)
  • VariantClear (Address: 0x180021bf0)
  • VariantInit (Address: 0x180021c10)
  • VarUI4FromStr (Address: 0x180021c18)
SHELL32.dll
  • SHGetFolderPathW (Address: 0x180021c30)
  • SHGetPathFromIDListW (Address: 0x180021c38)
  • SHGetSpecialFolderLocation (Address: 0x180021c40)
SHLWAPI.dll
  • PathAppendW (Address: 0x180021c58)
  • PathCombineW (Address: 0x180021c60)
  • PathFileExistsW (Address: 0x180021c78)
  • PathFindFileNameW (Address: 0x180021c88)
  • PathIsDirectoryW (Address: 0x180021c80)
  • PathIsRelativeW (Address: 0x180021c68)
  • PathMatchSpecW (Address: 0x180021c50)
  • PathRemoveFileSpecW (Address: 0x180021c70)
USER32.dll
  • AdjustWindowRectEx (Address: 0x180021cd0)
  • CharNextW (Address: 0x180021ce8)
  • CreateDialogParamW (Address: 0x180021d28)
  • DestroyWindow (Address: 0x180021d18)
  • FindWindowW (Address: 0x180021d20)
  • GetSystemMetrics (Address: 0x180021cd8)
  • GetWindowThreadProcessId (Address: 0x180021c98)
  • IsDialogMessageW (Address: 0x180021cc0)
  • KillTimer (Address: 0x180021cb8)
  • LoadIconW (Address: 0x180021d30)
  • LoadStringW (Address: 0x180021d00)
  • MessageBoxW (Address: 0x180021ca0)
  • PostMessageW (Address: 0x180021cf8)
  • PostThreadMessageW (Address: 0x180021cc8)
  • SendMessageW (Address: 0x180021d10)
  • SetForegroundWindow (Address: 0x180021ca8)
  • SetTimer (Address: 0x180021cb0)
  • SetWindowTextW (Address: 0x180021ce0)
  • ShowWindow (Address: 0x180021d08)
  • UnregisterClassA (Address: 0x180021cf0)
USERENV.dll
  • CreateEnvironmentBlock (Address: 0x180021d48)
  • DestroyEnvironmentBlock (Address: 0x180021d40)
VERSION.dll
  • GetFileVersionInfoSizeW (Address: 0x180021d60)
  • GetFileVersionInfoW (Address: 0x180021d58)
  • VerQueryValueW (Address: 0x180021d68)
WINTRUST.dll
  • CryptCATAdminAcquireContext (Address: 0x180021d88)
  • CryptCATAdminCalcHashFromFileHandle (Address: 0x180021d90)
  • CryptCATAdminEnumCatalogFromHash (Address: 0x180021d80)
  • CryptCATAdminReleaseCatalogContext (Address: 0x180021d78)
  • CryptCATAdminReleaseContext (Address: 0x180021db0)
  • CryptCATCatalogInfoFromContext (Address: 0x180021da8)
  • WinVerifyTrust (Address: 0x180021db8)
  • WTHelperGetProvSignerFromChain (Address: 0x180021d98)
  • WTHelperProvDataFromStateData (Address: 0x180021da0)
WTSAPI32.dll
  • WTSEnumerateSessionsW (Address: 0x180021dd0)
  • WTSFreeMemory (Address: 0x180021dd8)
  • WTSQuerySessionInformationW (Address: 0x180021de0)
  • WTSQueryUserToken (Address: 0x180021dc8)