winmm.dll

  • File Path: C:\Windows\SysWOW64\winmm.dll
  • Description: MCI API DLL

Hashes

Type Hash
MD5 1228927324ABDC2EAED5E5B9BFE35653
SHA1 955F1AB5872085FD3D5013464D82F6DEA0E97B9F
SHA256 0D0505F797DFE383B2F7A5BA760279AA2A3D5AFEDDE73FDB745C2D343695531C
SHA384 35FD6AC3814BB0D1C807AB6D313E23B7CA553B42D1401C34711C083415D388150FFF31DA703585A74484CA6414AE390C
SHA512 5BA042EE4E919E69B78E4D75A87D0BAC6EB77301705341ABD2B929A61407784F40B89289F0C7BDAE4369BC1771C7F4FFD88F3CB27A421F71986B5BDCB466E49B
SSDEEP 3072:682wUpLCSlGQOQSVnUmdWTly2yqLNa2eTU4z5KKR9tyD4az0qzisLEfyyuHcvatF:OHdCUSVniTly2yvh44z5p9aHuQF
IMP 62315BC823A3B043771A4C23FACA002B
PESHA1 092CEA03460C92CC23CF487D7C70370F5908806B
PE256 9FFE1FE89E7F6883DFBC5D2404D64166E4610DB0A94C01D24D6DBDDE68050709

DLL Exports:

Function Name Ordinal Type
mmTaskSignal 118 Exported Function
mmTaskCreate 117 Exported Function
mmTaskBlock 116 Exported Function
mxd32Message 143 Exported Function
mod32Message 142 Exported Function
mmTaskYield 119 Exported Function
mmioStringToFOURCCA 138 Exported Function
mmioSetInfo 137 Exported Function
mmioSetBuffer 136 Exported Function
mmsystemGetVersion 141 Exported Function
mmioWrite 140 Exported Function
mmioStringToFOURCCW 139 Exported Function
tid32Message 146 Exported Function
sndPlaySoundW 145 Exported Function
sndPlaySoundA 144 Exported Function
timeGetDevCaps 149 Exported Function
timeEndPeriod 148 Exported Function
timeBeginPeriod 147 Exported Function
PlaySound 11 Exported Function
OpenDriver 10 Exported Function
NotifyCallbackData 9 Exported Function
SendDriverMessage 14 Exported Function
PlaySoundW 13 Exported Function
PlaySoundA 12 Exported Function
mmioAdvance 120 Exported Function
mmGetCurrentTask 115 Exported Function
mmDrvInstall 114 Exported Function
mmioCreateChunk 123 Exported Function
mmioClose 122 Exported Function
mmioAscend 121 Exported Function
mixerGetNumDevs 110 Exported Function
mixerGetLineInfoW 109 Exported Function
mixerGetLineInfoA 108 Exported Function
mixerSetControlDetails 113 Exported Function
mixerOpen 112 Exported Function
mixerMessage 111 Exported Function
mmioRenameA 132 Exported Function
mmioRead 131 Exported Function
mmioOpenW 130 Exported Function
mmioSendMessage 135 Exported Function
mmioSeek 134 Exported Function
mmioRenameW 133 Exported Function
mmioGetInfo 126 Exported Function
mmioFlush 125 Exported Function
mmioDescend 124 Exported Function
mmioOpenA 129 Exported Function
mmioInstallIOProcW 128 Exported Function
mmioInstallIOProcA 127 Exported Function
waveOutMessage 182 Exported Function
waveOutGetVolume 181 Exported Function
waveOutGetPosition 180 Exported Function
waveOutPrepareHeader 185 Exported Function
waveOutPause 184 Exported Function
waveOutOpen 183 Exported Function
waveOutGetID 176 Exported Function
waveOutGetErrorTextW 175 Exported Function
waveOutGetErrorTextA 174 Exported Function
waveOutGetPlaybackRate 179 Exported Function
waveOutGetPitch 178 Exported Function
waveOutGetNumDevs 177 Exported Function
wod32Message 194 Exported Function
wid32Message 193 Exported Function
waveOutWrite 192 Exported Function
WOWAppExit 17 Exported Function
WOW32ResolveMultiMediaHandle 16 Exported Function
WOW32DriverCallback 15 Exported Function
waveOutSetPitch 188 Exported Function
waveOutRestart 187 Exported Function
waveOutReset 186 Exported Function
waveOutUnprepareHeader 191 Exported Function
waveOutSetVolume 190 Exported Function
waveOutSetPlaybackRate 189 Exported Function
waveInGetErrorTextA 158 Exported Function
waveInGetDevCapsW 157 Exported Function
waveInGetDevCapsA 156 Exported Function
waveInGetNumDevs 161 Exported Function
waveInGetID 160 Exported Function
waveInGetErrorTextW 159 Exported Function
timeKillEvent 152 Exported Function
timeGetTime 151 Exported Function
timeGetSystemTime 150 Exported Function
waveInClose 155 Exported Function
waveInAddBuffer 154 Exported Function
timeSetEvent 153 Exported Function
waveOutBreakLoop 170 Exported Function
waveInUnprepareHeader 169 Exported Function
waveInStop 168 Exported Function
waveOutGetDevCapsW 173 Exported Function
waveOutGetDevCapsA 172 Exported Function
waveOutClose 171 Exported Function
waveInOpen 164 Exported Function
waveInMessage 163 Exported Function
waveInGetPosition 162 Exported Function
waveInStart 167 Exported Function
waveInReset 166 Exported Function
waveInPrepareHeader 165 Exported Function
mciGetDeviceIDW 44 Exported Function
mciGetDeviceIDFromElementIDW 43 Exported Function
mciGetDeviceIDFromElementIDA 42 Exported Function
mciGetErrorStringW 47 Exported Function
mciGetErrorStringA 46 Exported Function
mciGetDriverData 45 Exported Function
mciExecute 3 Exported Function
mciDriverYield 38 Exported Function
mciDriverNotify 37 Exported Function
mciGetDeviceIDA 41 Exported Function
mciGetCreatorTask 40 Exported Function
mciFreeCommandResource 39 Exported Function
mid32Message 56 Exported Function
mciSetYieldProc 55 Exported Function
mciSetDriverData 54 Exported Function
midiInAddBuffer 59 Exported Function
midiDisconnect 58 Exported Function
midiConnect 57 Exported Function
mciSendCommandA 50 Exported Function
mciLoadCommandResource 49 Exported Function
mciGetYieldProc 48 Exported Function
mciSendStringW 53 Exported Function
mciSendStringA 52 Exported Function
mciSendCommandW 51 Exported Function
DefDriverProc 5 Exported Function
CloseDriver 4 Exported Function
auxSetVolume 24 Exported Function
GetDriverModuleHandle 8 Exported Function
DrvGetModuleHandle 7 Exported Function
DriverCallback 6 Exported Function
auxGetDevCapsW 20 Exported Function
auxGetDevCapsA 19 Exported Function
aux32Message 18 Exported Function
auxOutMessage 23 Exported Function
auxGetVolume 22 Exported Function
auxGetNumDevs 21 Exported Function
joyReleaseCapture 33 Exported Function
joyGetThreshold 32 Exported Function
joyGetPosEx 31 Exported Function
mci32Message 36 Exported Function
joySetThreshold 35 Exported Function
joySetCapture 34 Exported Function
joyGetDevCapsA 27 Exported Function
joyConfigChanged 26 Exported Function
joy32Message 25 Exported Function
joyGetPos 30 Exported Function
joyGetNumDevs 29 Exported Function
joyGetDevCapsW 28 Exported Function
midiStreamClose 92 Exported Function
midiOutUnprepareHeader 91 Exported Function
midiOutShortMsg 90 Exported Function
midiStreamPause 95 Exported Function
midiStreamOut 94 Exported Function
midiStreamOpen 93 Exported Function
midiOutOpen 86 Exported Function
midiOutMessage 85 Exported Function
midiOutLongMsg 84 Exported Function
midiOutSetVolume 89 Exported Function
midiOutReset 88 Exported Function
midiOutPrepareHeader 87 Exported Function
mixerGetDevCapsW 104 Exported Function
mixerGetDevCapsA 103 Exported Function
mixerGetControlDetailsW 102 Exported Function
mixerGetLineControlsW 107 Exported Function
mixerGetLineControlsA 106 Exported Function
mixerGetID 105 Exported Function
midiStreamRestart 98 Exported Function
midiStreamProperty 97 Exported Function
midiStreamPosition 96 Exported Function
mixerGetControlDetailsA 101 Exported Function
mixerClose 100 Exported Function
midiStreamStop 99 Exported Function
midiInOpen 68 Exported Function
midiInMessage 67 Exported Function
midiInGetNumDevs 66 Exported Function
midiInStart 71 Exported Function
midiInReset 70 Exported Function
midiInPrepareHeader 69 Exported Function
midiInGetDevCapsW 62 Exported Function
midiInGetDevCapsA 61 Exported Function
midiInClose 60 Exported Function
midiInGetID 65 Exported Function
midiInGetErrorTextW 64 Exported Function
midiInGetErrorTextA 63 Exported Function
midiOutGetErrorTextW 80 Exported Function
midiOutGetErrorTextA 79 Exported Function
midiOutGetDevCapsW 78 Exported Function
midiOutGetVolume 83 Exported Function
midiOutGetNumDevs 82 Exported Function
midiOutGetID 81 Exported Function
midiOutCacheDrumPatches 74 Exported Function
midiInUnprepareHeader 73 Exported Function
midiInStop 72 Exported Function
midiOutGetDevCapsA 77 Exported Function
midiOutClose 76 Exported Function
midiOutCachePatches 75 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: WINMM.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/0d0505f797dfe383b2f7a5ba760279aa2a3d5afedde73fdb745c2d343695531c/detection/

Possible Misuse

The following table contains possible examples of winmm.dll being misused. While winmm.dll is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma file_event_win_uac_bypass_winsat.yml - '\AppData\Local\Temp\system32\winmm.dll' DRL 1.0
malware-ioc win_apt_invisimole_wrapper_dll.yml - 'Windows\winmm.dll' © ESET 2014-2018
malware-ioc win_apt_invisimole_wrapper_dll.yml - '\winmm.dll' © ESET 2014-2018

MIT License. Copyright (c) 2020-2021 Strontic.