vmms.exe
by Microsoft
Virtualization
Summary
Hyper-V Virtual Machine Management Service
vmms.exe is the 1962nd most commonly executed Windows program in EchoTrail's dataset, observed 322 times across enterprise environments. It typically runs from C:\Windows\System32 and it is most often launched by services.exe.
1962nd
most commonly executed Windows program
322
observed executions
low
statistical confidence
Behavior
Top Paths
- C:\Windows\System32100%
Top Hashes (SHA256)
- f3a8a7b30e42472b70dec7f7c92f29a7a04dca61db4d24a7ea2fcc7fd4a64c1d35.94%
- a159d8f45fb11f9a98b22683821199b76b35284f9a0710bc451f9df41f7907a113.12%
- 3bef9ddf3d8d544bdcc9582dd6fd526896b457836e062a4f1e0c28a2ff884b098.44%
- 27b897b49af0834644bc018ddd0fc136da8f7e9084c678bdf6ae896b0d4d8edf7.19%
- 9f6082df9ffb612606f159005016748d326923277ec51f33b96d83333c6c8a8c3.44%
- 6b8d0d6f6e4011dde04594ebda353f9b0cf119b75a3836cb488997104515fdac3.12%
- 900a40877317f00d23ed196c4007f3cb6169f8f919f2c8514598dee7eab80ba13.12%
- 0228cff4fdb60ecff8c31328df5c75f267e1f3401789800c8a96aa81f56dde9b2.81%
- c7a93be1ea9a3fa7282cf180b5fbe4dd8dd9595a51da5151ed57039b7b4089f12.19%
- 6363ad2e26462973aae8e6c06db45b3ba0b0ba5d744bd89af1c049432c1af3441.88%
Process Ancestry
Top Grandparents
- wininit.exe100%
Top Parents
- services.exe100%
Top Children
- vmwp.exe100%
Rare or environment-specific process names are omitted from ancestry tables. Percentages are of all observed relationships.
Ask Rocky about vmms.exe
Rocky answers questions about vmms.exe grounded in this same dataset — free, no account needed.
Need this data programmatically? The Rocky API includes 500 free lookups a month. Or just ask Rocky.
Data from EchoTrail's dataset of ~346M Windows process executions. Last extracted 2026-08-04.