rpcnsh.dll

Description: RPC Netshell Helper

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6157

Architecture: 32-bit

Operating System: Windows NT

SHA256: 1ed146eef87eaf5f9e99a310a4505822

File Size: 52.0 KB

Uploaded At: Dec. 1, 2025, 8:03 a.m.

Views: 15

Exported Functions

  • InitHelperDll (Ordinal: 1, Address: 0x3210)

Imported DLLs & Functions

ADVAPI32.dll
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x1000e004)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x1000e010)
  • RegCloseKey (Address: 0x1000e008)
  • RegCreateKeyExA (Address: 0x1000e000)
  • RegDeleteKeyExA (Address: 0x1000e014)
  • RegGetValueA (Address: 0x1000e00c)
  • RegOpenKeyExA (Address: 0x1000e01c)
  • RegSetValueExA (Address: 0x1000e018)
fwpuclnt.dll
  • FwpmEngineClose0 (Address: 0x1000e150)
  • FwpmEngineOpen0 (Address: 0x1000e144)
  • FwpmFilterAdd0 (Address: 0x1000e13c)
  • FwpmFilterCreateEnumHandle0 (Address: 0x1000e14c)
  • FwpmFilterDeleteByKey0 (Address: 0x1000e140)
  • FwpmFilterDestroyEnumHandle0 (Address: 0x1000e138)
  • FwpmFilterEnum0 (Address: 0x1000e148)
  • FwpmFreeMemory0 (Address: 0x1000e134)
IPHLPAPI.DLL
  • GetIfEntry (Address: 0x1000e024)
  • GetIpAddrTable (Address: 0x1000e028)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x1000e080)
  • AcquireSRWLockShared (Address: 0x1000e058)
  • CloseHandle (Address: 0x1000e078)
  • CloseThreadpoolTimer (Address: 0x1000e084)
  • CreateMutexExW (Address: 0x1000e060)
  • CreateSemaphoreExW (Address: 0x1000e0b0)
  • CreateThreadpoolTimer (Address: 0x1000e06c)
  • DebugBreak (Address: 0x1000e044)
  • DeleteCriticalSection (Address: 0x1000e054)
  • EnterCriticalSection (Address: 0x1000e0bc)
  • FormatMessageW (Address: 0x1000e0e0)
  • GetCurrentProcess (Address: 0x1000e030)
  • GetCurrentProcessId (Address: 0x1000e050)
  • GetCurrentThreadId (Address: 0x1000e0d8)
  • GetLastError (Address: 0x1000e0a8)
  • GetModuleFileNameA (Address: 0x1000e0ac)
  • GetModuleHandleA (Address: 0x1000e0a4)
  • GetModuleHandleExW (Address: 0x1000e0c4)
  • GetModuleHandleW (Address: 0x1000e048)
  • GetProcAddress (Address: 0x1000e064)
  • GetProcessHeap (Address: 0x1000e09c)
  • GetSystemTimeAsFileTime (Address: 0x1000e094)
  • GetTickCount (Address: 0x1000e098)
  • HeapAlloc (Address: 0x1000e068)
  • HeapFree (Address: 0x1000e0b4)
  • InitializeCriticalSectionEx (Address: 0x1000e0cc)
  • IsDebuggerPresent (Address: 0x1000e040)
  • LeaveCriticalSection (Address: 0x1000e0c8)
  • LocalFree (Address: 0x1000e05c)
  • OpenSemaphoreW (Address: 0x1000e07c)
  • OutputDebugStringW (Address: 0x1000e088)
  • QueryPerformanceCounter (Address: 0x1000e090)
  • ReleaseMutex (Address: 0x1000e0dc)
  • ReleaseSemaphore (Address: 0x1000e0c0)
  • ReleaseSRWLockExclusive (Address: 0x1000e08c)
  • ReleaseSRWLockShared (Address: 0x1000e070)
  • SetLastError (Address: 0x1000e0b8)
  • SetThreadpoolTimer (Address: 0x1000e074)
  • SetUnhandledExceptionFilter (Address: 0x1000e034)
  • Sleep (Address: 0x1000e03c)
  • TerminateProcess (Address: 0x1000e04c)
  • UnhandledExceptionFilter (Address: 0x1000e038)
  • WaitForSingleObject (Address: 0x1000e0d4)
  • WaitForSingleObjectEx (Address: 0x1000e0a0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1000e0d0)
msvcrt.dll
  • __dllonexit (Address: 0x1000e180)
  • _amsg_exit (Address: 0x1000e164)
  • _callnewh (Address: 0x1000e158)
  • _except_handler4_common (Address: 0x1000e1b0)
  • _initterm (Address: 0x1000e174)
  • _lock (Address: 0x1000e178)
  • _onexit (Address: 0x1000e184)
  • _purecall (Address: 0x1000e198)
  • _unlock (Address: 0x1000e17c)
  • _vsnprintf (Address: 0x1000e1ac)
  • _vsnwprintf (Address: 0x1000e1a8)
  • _wcsicmp (Address: 0x1000e1a0)
  • _wtoi (Address: 0x1000e16c)
  • _XcptFilter (Address: 0x1000e160)
  • atol (Address: 0x1000e170)
  • free (Address: 0x1000e15c)
  • malloc (Address: 0x1000e188)
  • memcmp (Address: 0x1000e168)
  • memcpy (Address: 0x1000e1b4)
  • memcpy_s (Address: 0x1000e1a4)
  • memmove_s (Address: 0x1000e18c)
  • memset (Address: 0x1000e1b8)
  • printf (Address: 0x1000e194)
  • swscanf (Address: 0x1000e19c)
  • wcsrchr (Address: 0x1000e190)
NETSH.EXE
  • MatchToken (Address: 0x1000e0ec)
  • PreprocessCommand (Address: 0x1000e0f8)
  • PrintError (Address: 0x1000e0f4)
  • PrintMessage (Address: 0x1000e0f0)
  • PrintMessageFromModule (Address: 0x1000e0fc)
  • RegisterContext (Address: 0x1000e100)
  • RegisterHelper (Address: 0x1000e0e8)
ntdll.dll
  • WinSqmIncrementDWORD (Address: 0x1000e1c0)
  • WinSqmIsOptedIn (Address: 0x1000e1c4)
RPCRT4.dll
  • UuidCreateNil (Address: 0x1000e10c)
  • UuidCreateSequential (Address: 0x1000e108)
  • UuidEqual (Address: 0x1000e114)
  • UuidIsNil (Address: 0x1000e110)
WS2_32.dll
  • inet_ntoa (Address: 0x1000e124)
  • inet_pton (Address: 0x1000e12c)
  • WSAGetLastError (Address: 0x1000e120)
  • WSAStartup (Address: 0x1000e11c)
  • WSAStringToAddressW (Address: 0x1000e128)