nshwfp.dll

Description: Windows Filtering Platform Netsh Helper

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5915

Architecture: 32-bit

Operating System: Windows NT

SHA256: 6827607be5c04ec3249a94d15f30f1c2

File Size: 601.0 KB

Uploaded At: Dec. 1, 2025, 8:02 a.m.

Views: 11

Exported Functions

  • IdpConfigAddPolicy (Ordinal: 1, Address: 0x609b0)
  • IdpConfigAllocateAndGetPolicy (Ordinal: 2, Address: 0x61c50)
  • IdpConfigFreePolicy (Ordinal: 3, Address: 0x61ca0)
  • IdpConfigInitDefaultPolicy (Ordinal: 4, Address: 0x61270)
  • IdpConfigRemovePolicy (Ordinal: 5, Address: 0x60b90)
  • InitHelperDll (Ordinal: 6, Address: 0x5c9b0)
  • WfpCaptureExportedW (Ordinal: 7, Address: 0x5ea40)
  • WfpCaptureStop (Ordinal: 8, Address: 0x5f000)

Imported DLLs & Functions

api-ms-win-core-console-l1-1-0.dll
  • GetConsoleOutputCP (Address: 0x10090084)
api-ms-win-core-console-l1-2-0.dll
  • AttachConsole (Address: 0x1009008c)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1009009c)
  • SetUnhandledExceptionFilter (Address: 0x10090094)
  • UnhandledExceptionFilter (Address: 0x10090098)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileA (Address: 0x100900b4)
  • CreateFileW (Address: 0x100900c0)
  • DeleteFileA (Address: 0x100900b0)
  • DeleteFileW (Address: 0x100900ac)
  • FileTimeToLocalFileTime (Address: 0x100900bc)
  • GetFileAttributesA (Address: 0x100900a4)
  • GetFileInformationByHandle (Address: 0x100900b8)
  • WriteFile (Address: 0x100900a8)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x100900c8)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x100900d0)
  • HeapAlloc (Address: 0x100900dc)
  • HeapCreate (Address: 0x100900e4)
  • HeapDestroy (Address: 0x100900e8)
  • HeapFree (Address: 0x100900d4)
  • HeapReAlloc (Address: 0x100900e0)
  • HeapSize (Address: 0x100900d8)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x100900f4)
  • LocalFree (Address: 0x100900f0)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • FileTimeToDosDateTime (Address: 0x100900fc)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x10090104)
  • GetModuleHandleExW (Address: 0x10090110)
  • GetProcAddress (Address: 0x1009010c)
  • LoadStringW (Address: 0x10090108)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x10090118)
api-ms-win-core-processenvironment-l1-1-0.dll
  • GetStdHandle (Address: 0x10090120)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateProcessW (Address: 0x1009012c)
  • ExitProcess (Address: 0x10090128)
  • GetCurrentProcess (Address: 0x1009013c)
  • GetCurrentProcessId (Address: 0x10090140)
  • GetCurrentThreadId (Address: 0x10090138)
  • GetExitCodeProcess (Address: 0x10090130)
  • TerminateProcess (Address: 0x10090134)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x10090148)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x1009015c)
  • RegEnumValueW (Address: 0x10090158)
  • RegOpenKeyExW (Address: 0x10090154)
  • RegQueryInfoKeyW (Address: 0x10090150)
  • RegQueryValueExW (Address: 0x10090160)
api-ms-win-core-shlwapi-legacy-l1-1-0.dll
  • PathFindExtensionW (Address: 0x10090168)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x10090174)
  • WideCharToMultiByte (Address: 0x10090170)
api-ms-win-core-synch-l1-1-0.dll
  • CreateEventW (Address: 0x10090180)
  • DeleteCriticalSection (Address: 0x10090198)
  • EnterCriticalSection (Address: 0x10090184)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1009017c)
  • LeaveCriticalSection (Address: 0x10090188)
  • OpenEventW (Address: 0x1009018c)
  • SetEvent (Address: 0x10090194)
  • WaitForSingleObject (Address: 0x10090190)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x100901a0)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemInfo (Address: 0x100901ac)
  • GetSystemTimeAsFileTime (Address: 0x100901b0)
  • GetTickCount (Address: 0x100901a8)
api-ms-win-core-timezone-l1-1-0.dll
  • FileTimeToSystemTime (Address: 0x100901b8)
api-ms-win-eventing-controller-l1-1-0.dll
  • ControlTraceW (Address: 0x100901c0)
  • StartTraceW (Address: 0x100901c4)
api-ms-win-eventing-legacy-l1-1-0.dll
  • EnableTrace (Address: 0x100901cc)
api-ms-win-security-base-l1-1-0.dll
  • GetLengthSid (Address: 0x100901d4)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountNameW (Address: 0x100901dc)
api-ms-win-security-lsapolicy-l1-1-0.dll
  • LsaClose (Address: 0x100901f0)
  • LsaFreeMemory (Address: 0x100901e8)
  • LsaOpenPolicy (Address: 0x100901ec)
  • LsaQueryInformationPolicy (Address: 0x100901e4)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x10090200)
  • ConvertSidToStringSidW (Address: 0x100901fc)
  • ConvertStringSidToSidW (Address: 0x100901f8)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x10090208)
  • OpenSCManagerW (Address: 0x1009020c)
  • OpenServiceW (Address: 0x10090210)
api-ms-win-service-management-l2-1-0.dll
  • QueryServiceStatusEx (Address: 0x10090218)
Cabinet.dll
  • (Address: 0x10090014)
  • (Address: 0x10090018)
  • (Address: 0x1009001c)
  • (Address: 0x10090020)
CRYPT32.dll
  • CertCreateCertificateContext (Address: 0x1009000c)
  • CertFreeCertificateContext (Address: 0x10090004)
  • CertGetNameStringW (Address: 0x10090008)
  • CertNameToStrW (Address: 0x10090000)
FirewallAPI.dll
  • FWEnumDynamicKeywordAddressesByType0 (Address: 0x1009002c)
  • FWFreeDynamicKeywordAddressData0 (Address: 0x10090028)
fwpuclnt.dll
  • FwpmCalloutCreateEnumHandle0 (Address: 0x10090248)
  • FwpmCalloutDestroyEnumHandle0 (Address: 0x1009023c)
  • FwpmCalloutEnum0 (Address: 0x10090240)
  • FwpmCalloutGetByKey0 (Address: 0x10090250)
  • FwpmCalloutGetSecurityInfoByKey0 (Address: 0x10090230)
  • FwpmCalloutSetSecurityInfoByKey0 (Address: 0x10090260)
  • FwpmCalloutSubscribeChanges0 (Address: 0x100902b8)
  • FwpmCalloutSubscriptionsGet0 (Address: 0x10090300)
  • FwpmCalloutUnsubscribeChanges0 (Address: 0x100902a4)
  • FwpmEngineClose0 (Address: 0x10090354)
  • FwpmEngineGetOption0 (Address: 0x1009026c)
  • FwpmEngineGetSecurityInfo0 (Address: 0x10090340)
  • FwpmEngineOpen0 (Address: 0x10090224)
  • FwpmEngineSetOption0 (Address: 0x1009025c)
  • FwpmEngineSetSecurityInfo0 (Address: 0x10090228)
  • FwpmFilterAdd0 (Address: 0x10090360)
  • FwpmFilterCreateEnumHandle0 (Address: 0x1009029c)
  • FwpmFilterDeleteByKey0 (Address: 0x10090394)
  • FwpmFilterDestroyEnumHandle0 (Address: 0x1009028c)
  • FwpmFilterEnum0 (Address: 0x10090290)
  • FwpmFilterGetByKey0 (Address: 0x10090244)
  • FwpmFilterGetSecurityInfoByKey0 (Address: 0x10090288)
  • FwpmFilterSetSecurityInfoByKey0 (Address: 0x10090220)
  • FwpmFilterSubscribeChanges0 (Address: 0x100902b4)
  • FwpmFilterSubscriptionsGet0 (Address: 0x100902fc)
  • FwpmFilterUnsubscribeChanges0 (Address: 0x100902a8)
  • FwpmFreeMemory0 (Address: 0x1009038c)
  • FwpmGetAppIdFromFileName0 (Address: 0x10090258)
  • FwpmLayerCreateEnumHandle0 (Address: 0x10090238)
  • FwpmLayerDestroyEnumHandle0 (Address: 0x10090388)
  • FwpmLayerEnum0 (Address: 0x10090234)
  • FwpmLayerGetSecurityInfoByKey0 (Address: 0x10090358)
  • FwpmLayerSetSecurityInfoByKey0 (Address: 0x10090268)
  • FwpmNetEventCreateEnumHandle0 (Address: 0x100902d8)
  • FwpmNetEventDestroyEnumHandle0 (Address: 0x100902d0)
  • FwpmNetEventEnum5 (Address: 0x100902d4)
  • FwpmNetEventsGetSecurityInfo0 (Address: 0x10090254)
  • FwpmNetEventsLost0 (Address: 0x1009034c)
  • FwpmNetEventsSetSecurityInfo0 (Address: 0x10090378)
  • FwpmNetEventSubscribe4 (Address: 0x100902b0)
  • FwpmNetEventSubscriptionsGet0 (Address: 0x100902f0)
  • FwpmNetEventUnsubscribe0 (Address: 0x100902ac)
  • FwpmProviderContextAdd3 (Address: 0x10090344)
  • FwpmProviderContextCreateEnumHandle0 (Address: 0x10090280)
  • FwpmProviderContextDeleteByKey0 (Address: 0x1009024c)
  • FwpmProviderContextDestroyEnumHandle0 (Address: 0x10090278)
  • FwpmProviderContextEnum3 (Address: 0x100903a0)
  • FwpmProviderContextGetByKey3 (Address: 0x10090270)
  • FwpmProviderContextGetSecurityInfoByKey0 (Address: 0x1009027c)
  • FwpmProviderContextSetSecurityInfoByKey0 (Address: 0x10090368)
  • FwpmProviderContextSubscribeChanges0 (Address: 0x100902c8)
  • FwpmProviderContextSubscriptionsGet0 (Address: 0x100902e8)
  • FwpmProviderContextUnsubscribeChanges0 (Address: 0x10090298)
  • FwpmProviderCreateEnumHandle0 (Address: 0x1009037c)
  • FwpmProviderDestroyEnumHandle0 (Address: 0x10090370)
  • FwpmProviderEnum0 (Address: 0x10090374)
  • FwpmProviderGetByKey0 (Address: 0x10090274)
  • FwpmProviderGetSecurityInfoByKey0 (Address: 0x10090348)
  • FwpmProviderSetSecurityInfoByKey0 (Address: 0x1009039c)
  • FwpmProviderSubscribeChanges0 (Address: 0x100902cc)
  • FwpmProviderSubscriptionsGet0 (Address: 0x100902ec)
  • FwpmProviderUnsubscribeChanges0 (Address: 0x10090294)
  • FwpmSessionCreateEnumHandle0 (Address: 0x1009036c)
  • FwpmSessionDestroyEnumHandle0 (Address: 0x1009035c)
  • FwpmSessionEnum0 (Address: 0x10090364)
  • FwpmSubLayerCreateEnumHandle0 (Address: 0x10090334)
  • FwpmSubLayerDestroyEnumHandle0 (Address: 0x1009032c)
  • FwpmSubLayerEnum0 (Address: 0x10090330)
  • FwpmSubLayerGetByKey0 (Address: 0x10090264)
  • FwpmSubLayerGetSecurityInfoByKey0 (Address: 0x10090284)
  • FwpmSubLayerSetSecurityInfoByKey0 (Address: 0x10090380)
  • FwpmSubLayerSubscribeChanges0 (Address: 0x100902c4)
  • FwpmSubLayerSubscriptionsGet0 (Address: 0x100902e4)
  • FwpmSubLayerUnsubscribeChanges0 (Address: 0x100902a0)
  • FwpmSystemPortsGet0 (Address: 0x10090384)
  • FwpmTransactionAbort0 (Address: 0x10090304)
  • FwpmTransactionBegin0 (Address: 0x1009033c)
  • FwpmTransactionCommit0 (Address: 0x10090338)
  • FwpsAleEndpointCreateEnumHandle0 (Address: 0x10090310)
  • FwpsAleEndpointDestroyEnumHandle0 (Address: 0x10090308)
  • FwpsAleEndpointEnum0 (Address: 0x1009030c)
  • IkeextGetStatistics1 (Address: 0x100902e0)
  • IkeextSaCreateEnumHandle0 (Address: 0x10090328)
  • IkeextSaDbGetSecurityInfo0 (Address: 0x10090398)
  • IkeextSaDbSetSecurityInfo0 (Address: 0x1009022c)
  • IkeextSaDestroyEnumHandle0 (Address: 0x10090320)
  • IkeextSaEnum2 (Address: 0x10090324)
  • IPsecDospGetStatistics0 (Address: 0x100902f8)
  • IPsecDospStateCreateEnumHandle0 (Address: 0x100902f4)
  • IPsecDospStateDestroyEnumHandle0 (Address: 0x100902bc)
  • IPsecDospStateEnum0 (Address: 0x100902c0)
  • IPsecGetStatistics1 (Address: 0x100902dc)
  • IPsecSaContextCreateEnumHandle0 (Address: 0x1009031c)
  • IPsecSaContextDestroyEnumHandle0 (Address: 0x10090314)
  • IPsecSaContextEnum1 (Address: 0x10090318)
  • IPsecSaDbGetSecurityInfo0 (Address: 0x10090350)
  • IPsecSaDbSetSecurityInfo0 (Address: 0x10090390)
IPHLPAPI.DLL
  • GetAdaptersAddresses (Address: 0x10090034)
msvcrt.dll
  • __dllonexit (Address: 0x10090438)
  • _amsg_exit (Address: 0x10090454)
  • _close (Address: 0x100903bc)
  • _errno (Address: 0x100903c8)
  • _except_handler4_common (Address: 0x10090444)
  • _get_errno (Address: 0x100903fc)
  • _i64toa_s (Address: 0x100903e0)
  • _initterm (Address: 0x10090448)
  • _lock (Address: 0x10090440)
  • _lseek (Address: 0x100903b8)
  • _ltoa_s (Address: 0x100903e4)
  • _onexit (Address: 0x10090434)
  • _open (Address: 0x100903cc)
  • _read (Address: 0x100903c4)
  • _set_errno (Address: 0x10090404)
  • _snwprintf_s (Address: 0x10090414)
  • _tempnam (Address: 0x100903b0)
  • _ui64toa_s (Address: 0x100903dc)
  • _ultoa_s (Address: 0x100903f8)
  • _ultow_s (Address: 0x10090410)
  • _unlock (Address: 0x1009043c)
  • _vsnprintf (Address: 0x10090428)
  • _vsnwprintf (Address: 0x10090424)
  • _wcsicmp (Address: 0x10090418)
  • _wcsnicmp (Address: 0x100903d4)
  • _write (Address: 0x100903c0)
  • _XcptFilter (Address: 0x10090458)
  • bsearch (Address: 0x100903ac)
  • free (Address: 0x10090450)
  • isprint (Address: 0x100903e8)
  • malloc (Address: 0x1009044c)
  • memcmp (Address: 0x1009042c)
  • memcpy (Address: 0x10090430)
  • memset (Address: 0x100903a8)
  • qsort (Address: 0x100903d8)
  • remove (Address: 0x100903b4)
  • sprintf_s (Address: 0x100903ec)
  • strcpy_s (Address: 0x100903d0)
  • strpbrk (Address: 0x100903f4)
  • strstr (Address: 0x100903f0)
  • swprintf_s (Address: 0x1009040c)
  • wcsncmp (Address: 0x10090408)
  • wcstol (Address: 0x1009041c)
  • wcstoul (Address: 0x10090400)
  • wprintf (Address: 0x10090420)
NETSH.EXE
  • MatchEnumTag (Address: 0x10090040)
  • PreprocessCommand (Address: 0x10090048)
  • PrintMessage (Address: 0x1009003c)
  • PrintMessageFromModule (Address: 0x10090044)
  • RegisterContext (Address: 0x10090050)
  • RegisterHelper (Address: 0x1009004c)
NSI.dll
  • NsiGetAllParameters (Address: 0x1009005c)
  • NsiSetAllParameters (Address: 0x10090058)
ntdll.dll
  • EtwEventWriteTransfer (Address: 0x10090478)
  • EtwTraceMessage (Address: 0x10090484)
  • RtlApplicationVerifierStop (Address: 0x1009047c)
  • RtlEthernetAddressToStringA (Address: 0x10090464)
  • RtlIpv4AddressToStringA (Address: 0x1009046c)
  • RtlIpv4StringToAddressW (Address: 0x10090470)
  • RtlIpv6AddressToStringA (Address: 0x10090468)
  • RtlIpv6AddressToStringW (Address: 0x10090460)
  • RtlIpv6StringToAddressW (Address: 0x10090474)
  • RtlNtStatusToDosError (Address: 0x10090480)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x10090074)
  • MesDecodeBufferHandleCreate (Address: 0x10090064)
  • MesEncodeDynBufferHandleCreate (Address: 0x10090068)
  • MesHandleFree (Address: 0x10090078)
  • NdrMesTypeDecode2 (Address: 0x10090070)
  • UuidCreate (Address: 0x1009007c)
  • UuidFromStringW (Address: 0x1009006c)