iphlpsvc.dll

Description: Service that offers IPv6 connectivity over an IPv4 network.

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: 6f9745612743797c611282e476243c6b

File Size: 817.0 KB

Uploaded At: Dec. 1, 2025, 7:29 a.m.

Views: 7

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • IphlpsvcSysprepGeneralize (Ordinal: 1, Address: 0x30150)
  • ServiceMain (Ordinal: 2, Address: 0x14620)
  • SvchostPushServiceGlobals (Ordinal: 3, Address: 0x16af0)

Imported DLLs & Functions

api-ms-win-core-apiquery-l1-1-0.dll
  • ApiSetQueryApiSetPresence (Address: 0x180078478)
api-ms-win-core-debug-l1-1-0.dll
  • DebugBreak (Address: 0x180078488)
  • IsDebuggerPresent (Address: 0x180078490)
  • OutputDebugStringW (Address: 0x180078498)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800784a8)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800784b8)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x1800784d8)
  • RaiseException (Address: 0x1800784d0)
  • SetLastError (Address: 0x1800784e8)
  • SetUnhandledExceptionFilter (Address: 0x1800784e0)
  • UnhandledExceptionFilter (Address: 0x1800784c8)
api-ms-win-core-file-l1-1-0.dll
  • CreateFileW (Address: 0x180078500)
  • GetFileInformationByHandle (Address: 0x180078518)
  • ReadFile (Address: 0x1800784f8)
  • SetEndOfFile (Address: 0x180078508)
  • WriteFile (Address: 0x180078510)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180078528)
api-ms-win-core-heap-l1-1-0.dll
  • GetProcessHeap (Address: 0x180078548)
  • HeapAlloc (Address: 0x180078538)
  • HeapCreate (Address: 0x180078558)
  • HeapDestroy (Address: 0x180078550)
  • HeapFree (Address: 0x180078540)
api-ms-win-core-heap-l2-1-0.dll
  • LocalAlloc (Address: 0x180078570)
  • LocalFree (Address: 0x180078568)
api-ms-win-core-interlocked-l1-1-0.dll
  • InitializeSListHead (Address: 0x180078590)
  • InterlockedPopEntrySList (Address: 0x180078588)
  • InterlockedPushEntrySList (Address: 0x180078598)
  • QueryDepthSList (Address: 0x180078580)
api-ms-win-core-io-l1-1-0.dll
  • CancelIoEx (Address: 0x1800785b0)
  • DeviceIoControl (Address: 0x1800785a8)
api-ms-win-core-kernel32-legacy-l1-1-0.dll
  • BindIoCompletionCallback (Address: 0x1800785c8)
  • GetComputerNameW (Address: 0x1800785c0)
api-ms-win-core-kernel32-legacy-l1-1-1.dll
  • GetNumaProcessorNodeEx (Address: 0x1800785d8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180078638)
  • FindResourceExW (Address: 0x180078608)
  • FreeLibrary (Address: 0x1800785f0)
  • GetModuleFileNameA (Address: 0x180078618)
  • GetModuleFileNameW (Address: 0x180078630)
  • GetModuleHandleExW (Address: 0x180078620)
  • GetModuleHandleW (Address: 0x180078628)
  • GetProcAddress (Address: 0x1800785e8)
  • LoadLibraryExW (Address: 0x180078640)
  • LoadResource (Address: 0x180078600)
  • LoadStringW (Address: 0x1800785f8)
  • SizeofResource (Address: 0x180078610)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x180078650)
api-ms-win-core-memory-l1-1-0.dll
  • VirtualFree (Address: 0x180078660)
api-ms-win-core-memory-l1-1-2.dll
  • VirtualAllocExNuma (Address: 0x180078670)
api-ms-win-core-perfcounters-l1-1-0.dll
  • PerfCreateInstance (Address: 0x180078698)
  • PerfDeleteInstance (Address: 0x1800786a8)
  • PerfSetCounterRefValue (Address: 0x180078680)
  • PerfSetCounterSetInfo (Address: 0x180078688)
  • PerfSetULongCounterValue (Address: 0x1800786a0)
  • PerfSetULongLongCounterValue (Address: 0x1800786b8)
  • PerfStartProviderEx (Address: 0x180078690)
  • PerfStopProvider (Address: 0x1800786b0)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800786c8)
api-ms-win-core-processthreads-l1-1-0.dll
  • CreateRemoteThreadEx (Address: 0x180078708)
  • DeleteProcThreadAttributeList (Address: 0x1800786f8)
  • GetCurrentProcess (Address: 0x1800786e0)
  • GetCurrentProcessId (Address: 0x180078720)
  • GetCurrentThread (Address: 0x1800786d8)
  • GetCurrentThreadId (Address: 0x1800786e8)
  • InitializeProcThreadAttributeList (Address: 0x180078718)
  • OpenThreadToken (Address: 0x1800786f0)
  • TerminateProcess (Address: 0x180078700)
  • UpdateProcThreadAttribute (Address: 0x180078710)
api-ms-win-core-processthreads-l1-1-1.dll
  • IsProcessorFeaturePresent (Address: 0x180078738)
  • OpenProcess (Address: 0x180078730)
api-ms-win-core-processtopology-l1-1-0.dll
  • SetThreadGroupAffinity (Address: 0x180078748)
api-ms-win-core-processtopology-obsolete-l1-1-0.dll
  • GetActiveProcessorCount (Address: 0x180078758)
  • SetThreadAffinityMask (Address: 0x180078760)
api-ms-win-core-processtopology-obsolete-l1-1-1.dll
  • GetActiveProcessorGroupCount (Address: 0x180078770)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180078780)
api-ms-win-core-psapi-l1-1-0.dll
  • QueryFullProcessImageNameW (Address: 0x180078790)
api-ms-win-core-realtime-l1-1-0.dll
  • QueryUnbiasedInterruptTime (Address: 0x1800787a0)
api-ms-win-core-registry-l1-1-0.dll
  • RegCloseKey (Address: 0x180078808)
  • RegCreateKeyExW (Address: 0x1800787f8)
  • RegDeleteKeyExW (Address: 0x1800787f0)
  • RegDeleteTreeW (Address: 0x1800787d0)
  • RegDeleteValueW (Address: 0x180078810)
  • RegEnumKeyExW (Address: 0x180078800)
  • RegEnumValueW (Address: 0x1800787c0)
  • RegGetValueW (Address: 0x1800787b0)
  • RegOpenKeyExA (Address: 0x1800787b8)
  • RegOpenKeyExW (Address: 0x1800787e0)
  • RegQueryInfoKeyW (Address: 0x1800787d8)
  • RegQueryValueExW (Address: 0x1800787c8)
  • RegSetValueExW (Address: 0x1800787e8)
api-ms-win-core-rtlsupport-l1-1-0.dll
  • RtlCaptureContext (Address: 0x180078828)
  • RtlCompareMemory (Address: 0x180078830)
  • RtlLookupFunctionEntry (Address: 0x180078838)
  • RtlVirtualUnwind (Address: 0x180078820)
api-ms-win-core-string-l1-1-0.dll
  • MultiByteToWideChar (Address: 0x180078848)
api-ms-win-core-string-l2-1-0.dll
  • CharNextW (Address: 0x180078858)
api-ms-win-core-string-obsolete-l1-1-0.dll
  • lstrcmpiW (Address: 0x180078868)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x1800788e8)
  • AcquireSRWLockShared (Address: 0x180078878)
  • CreateEventExW (Address: 0x180078910)
  • CreateEventW (Address: 0x1800788d0)
  • CreateMutexExW (Address: 0x180078898)
  • CreateMutexW (Address: 0x180078908)
  • CreateSemaphoreExW (Address: 0x1800788d8)
  • DeleteCriticalSection (Address: 0x180078918)
  • EnterCriticalSection (Address: 0x180078928)
  • InitializeCriticalSection (Address: 0x180078930)
  • InitializeCriticalSectionAndSpinCount (Address: 0x1800788c0)
  • InitializeSRWLock (Address: 0x180078938)
  • LeaveCriticalSection (Address: 0x180078920)
  • OpenEventW (Address: 0x180078880)
  • OpenSemaphoreW (Address: 0x1800788a0)
  • ReleaseMutex (Address: 0x1800788b8)
  • ReleaseSemaphore (Address: 0x1800788a8)
  • ReleaseSRWLockExclusive (Address: 0x180078900)
  • ReleaseSRWLockShared (Address: 0x180078890)
  • ResetEvent (Address: 0x1800788f8)
  • SetEvent (Address: 0x1800788e0)
  • TryAcquireSRWLockExclusive (Address: 0x180078888)
  • WaitForMultipleObjectsEx (Address: 0x1800788c8)
  • WaitForSingleObject (Address: 0x1800788b0)
  • WaitForSingleObjectEx (Address: 0x1800788f0)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180078948)
api-ms-win-core-synch-l1-2-1.dll
  • WaitForMultipleObjects (Address: 0x180078958)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemDirectoryW (Address: 0x180078980)
  • GetSystemInfo (Address: 0x180078978)
  • GetSystemTimeAsFileTime (Address: 0x180078970)
  • GetTickCount (Address: 0x180078968)
  • GetTickCount64 (Address: 0x180078988)
api-ms-win-core-systemtopology-l1-1-0.dll
  • GetNumaNodeProcessorMaskEx (Address: 0x180078998)
api-ms-win-core-threadpool-l1-2-0.dll
  • CancelThreadpoolIo (Address: 0x1800789c0)
  • CloseThreadpool (Address: 0x180078a10)
  • CloseThreadpoolCleanupGroup (Address: 0x180078a20)
  • CloseThreadpoolCleanupGroupMembers (Address: 0x180078a28)
  • CloseThreadpoolIo (Address: 0x1800789b0)
  • CloseThreadpoolTimer (Address: 0x1800789f0)
  • CloseThreadpoolWait (Address: 0x1800789d0)
  • CloseThreadpoolWork (Address: 0x1800789a8)
  • CreateThreadpool (Address: 0x180078a38)
  • CreateThreadpoolCleanupGroup (Address: 0x180078a30)
  • CreateThreadpoolIo (Address: 0x1800789c8)
  • CreateThreadpoolTimer (Address: 0x180078a08)
  • CreateThreadpoolWait (Address: 0x180078a40)
  • CreateThreadpoolWork (Address: 0x180078a18)
  • SetThreadpoolTimer (Address: 0x180078a00)
  • SetThreadpoolWait (Address: 0x1800789e0)
  • StartThreadpoolIo (Address: 0x1800789b8)
  • SubmitThreadpoolWork (Address: 0x1800789e8)
  • TrySubmitThreadpoolCallback (Address: 0x180078a48)
  • WaitForThreadpoolTimerCallbacks (Address: 0x1800789f8)
  • WaitForThreadpoolWaitCallbacks (Address: 0x1800789d8)
api-ms-win-core-threadpool-legacy-l1-1-0.dll
  • UnregisterWaitEx (Address: 0x180078a58)
api-ms-win-core-xstate-l2-1-0.dll
  • GetEnabledXStateFeatures (Address: 0x180078a68)
api-ms-win-crt-private-l1-1-0.dll
  • __C_specific_handler (Address: 0x180078b80)
  • __CxxFrameHandler3 (Address: 0x180078ae8)
  • __std_terminate (Address: 0x180078b68)
  • _CxxThrowException (Address: 0x180078af0)
  • _o___std_exception_copy (Address: 0x180078b40)
  • _o___std_exception_destroy (Address: 0x180078b38)
  • _o___std_type_info_destroy_list (Address: 0x180078b30)
  • _o___stdio_common_vsnwprintf_s (Address: 0x180078b00)
  • _o___stdio_common_vswprintf (Address: 0x180078af8)
  • _o__callnewh (Address: 0x180078b60)
  • _o__cexit (Address: 0x180078b58)
  • _o__configure_narrow_argv (Address: 0x180078b50)
  • _o__crt_atexit (Address: 0x180078b48)
  • _o__errno (Address: 0x180078b10)
  • _o__execute_onexit_table (Address: 0x180078b08)
  • _o__initialize_narrow_environment (Address: 0x180078b28)
  • _o__initialize_onexit_table (Address: 0x180078b20)
  • _o__invalid_parameter_noinfo (Address: 0x180078b18)
  • _o__recalloc (Address: 0x180078a78)
  • _o__register_onexit_function (Address: 0x180078a80)
  • _o__seh_filter_dll (Address: 0x180078a88)
  • _o__stricmp (Address: 0x180078a90)
  • _o__wcsicmp (Address: 0x180078a98)
  • _o__wcsnicmp (Address: 0x180078aa0)
  • _o__wtoi (Address: 0x180078ab0)
  • _o_free (Address: 0x180078ab8)
  • _o_malloc (Address: 0x180078ac0)
  • _o_memcpy_s (Address: 0x180078ac8)
  • _o_wcscpy_s (Address: 0x180078ad0)
  • _o_wcsncpy_s (Address: 0x180078ad8)
  • _o_wcstok_s (Address: 0x180078ae0)
  • memcmp (Address: 0x180078b88)
  • memcpy (Address: 0x180078b90)
  • memmove (Address: 0x180078aa8)
  • wcschr (Address: 0x180078b78)
  • wcsstr (Address: 0x180078b70)
api-ms-win-crt-runtime-l1-1-0.dll
  • _initterm (Address: 0x180078ba8)
  • _initterm_e (Address: 0x180078ba0)
api-ms-win-crt-string-l1-1-0.dll
  • memset (Address: 0x180078bb8)
  • wcscmp (Address: 0x180078bc8)
  • wcsncmp (Address: 0x180078bc0)
  • wcsnlen (Address: 0x180078bd0)
api-ms-win-crt-time-l1-1-0.dll
  • _time64 (Address: 0x180078be0)
api-ms-win-eventing-classicprovider-l1-1-0.dll
  • TraceMessage (Address: 0x180078bf0)
api-ms-win-eventing-provider-l1-1-0.dll
  • EventRegister (Address: 0x180078c00)
  • EventSetInformation (Address: 0x180078c10)
  • EventUnregister (Address: 0x180078c08)
  • EventWriteTransfer (Address: 0x180078c18)
api-ms-win-security-base-l1-1-0.dll
  • AllocateAndInitializeSid (Address: 0x180078c28)
  • CheckTokenMembership (Address: 0x180078c30)
  • CreateWellKnownSid (Address: 0x180078c50)
  • FreeSid (Address: 0x180078c38)
  • InitializeSecurityDescriptor (Address: 0x180078c48)
  • SetSecurityDescriptorDacl (Address: 0x180078c40)
api-ms-win-security-capability-l1-1-0.dll
  • RpcClientCapabilityCheck (Address: 0x180078c60)
api-ms-win-security-lsalookup-l2-1-0.dll
  • LookupAccountNameW (Address: 0x180078c70)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x180078c80)
FirewallAPI.dll
  • FWIndicatePortInUse (Address: 0x1800781d8)
  • FWIndicateTupleInUse (Address: 0x1800781e0)
  • FWResetIndicatedPortInUse (Address: 0x1800781d0)
  • FWResetIndicatedTupleInUse (Address: 0x1800781e8)
fwpuclnt.dll
  • FwpmEngineClose0 (Address: 0x180078cc0)
  • FwpmEngineOpen0 (Address: 0x180078cd8)
  • FwpmFilterAdd0 (Address: 0x180078cd0)
  • FwpmFilterCreateEnumHandle0 (Address: 0x180078cb8)
  • FwpmFilterDeleteById0 (Address: 0x180078cf8)
  • FwpmFilterDestroyEnumHandle0 (Address: 0x180078ca8)
  • FwpmFilterEnum0 (Address: 0x180078cb0)
  • FwpmFilterGetByKey0 (Address: 0x180078ca0)
  • FwpmFilterSubscribeChanges0 (Address: 0x180078cc8)
  • FwpmFilterUnsubscribeChanges0 (Address: 0x180078d10)
  • FwpmFreeMemory0 (Address: 0x180078c90)
  • FwpmProviderAdd0 (Address: 0x180078d08)
  • FwpmProviderDeleteByKey0 (Address: 0x180078c98)
  • FwpmSubLayerAdd0 (Address: 0x180078ce0)
  • FwpmTransactionAbort0 (Address: 0x180078ce8)
  • FwpmTransactionBegin0 (Address: 0x180078cf0)
  • FwpmTransactionCommit0 (Address: 0x180078d00)
IPHLPAPI.DLL
  • CancelMibChangeNotify2 (Address: 0x1800782c8)
  • ConvertCompartmentIdToGuid (Address: 0x180078270)
  • ConvertGuidToStringA (Address: 0x180078238)
  • ConvertGuidToStringW (Address: 0x1800782c0)
  • ConvertInterfaceGuidToLuid (Address: 0x180078208)
  • ConvertInterfaceIndexToLuid (Address: 0x180078280)
  • ConvertInterfaceLuidToAlias (Address: 0x180078220)
  • ConvertInterfaceLuidToGuid (Address: 0x180078230)
  • ConvertInterfaceLuidToIndex (Address: 0x180078290)
  • ConvertStringToGuidW (Address: 0x180078240)
  • CreateIpForwardEntry2 (Address: 0x1800782a0)
  • DeleteIpForwardEntry2 (Address: 0x180078298)
  • FreeMibTable (Address: 0x180078218)
  • GetAdaptersAddresses (Address: 0x180078278)
  • GetBestInterface (Address: 0x1800782e8)
  • GetBestInterfaceEx (Address: 0x180078300)
  • GetBestRoute2 (Address: 0x180078318)
  • GetIfEntry2 (Address: 0x180078200)
  • GetIfTable2 (Address: 0x180078248)
  • GetIpAddrTable (Address: 0x180078268)
  • GetIpForwardEntry2 (Address: 0x180078210)
  • GetIpForwardTable2 (Address: 0x1800781f8)
  • GetIpInterfaceTable (Address: 0x1800782a8)
  • GetIpNetEntry2 (Address: 0x180078310)
  • GetUnicastIpAddressEntry (Address: 0x1800782e0)
  • GetUnicastIpAddressTable (Address: 0x180078308)
  • Icmp6CreateFile (Address: 0x180078250)
  • Icmp6SendEcho2 (Address: 0x180078258)
  • IcmpCloseHandle (Address: 0x180078260)
  • InitializeIpForwardEntry (Address: 0x1800782b0)
  • InitializeIpInterfaceEntry (Address: 0x1800782f8)
  • InternalSetIpInterfaceEntry (Address: 0x1800782f0)
  • InternalSetTeredoPort (Address: 0x180078228)
  • NotifyIpInterfaceChange (Address: 0x1800782d0)
  • NotifyRouteChange2 (Address: 0x1800782b8)
  • NotifyUnicastIpAddressChange (Address: 0x1800782d8)
  • ParseNetworkString (Address: 0x180078288)
  • ResolveIpNetEntry2 (Address: 0x180078320)
  • SetCurrentThreadCompartmentId (Address: 0x180078328)
MSWSOCK.dll
  • AcceptEx (Address: 0x180078340)
  • GetAcceptExSockaddrs (Address: 0x180078338)
NetSetupApi.dll
  • NetSetupClose (Address: 0x180078388)
  • NetSetupCommit (Address: 0x180078398)
  • NetSetupCreateObject (Address: 0x1800783b0)
  • NetSetupDeleteObject (Address: 0x1800783a0)
  • NetSetupFreeObjects (Address: 0x180078390)
  • NetSetupGetObjects (Address: 0x1800783b8)
  • NetSetupInitialize (Address: 0x1800783a8)
NSI.dll
  • NsiAllocateAndGetTable (Address: 0x180078360)
  • NsiFreeTable (Address: 0x180078368)
  • NsiGetAllParameters (Address: 0x180078370)
  • NsiGetParameter (Address: 0x180078378)
  • NsiSetAllParameters (Address: 0x180078358)
  • NsiSetParameter (Address: 0x180078350)
ntdll.dll
  • EtwEventActivityIdControl (Address: 0x180078d90)
  • EtwTraceMessageVa (Address: 0x180078d88)
  • RtlCreateHashTable (Address: 0x180078dc0)
  • RtlDeleteHashTable (Address: 0x180078d40)
  • RtlEndEnumerationHashTable (Address: 0x180078d80)
  • RtlEnumerateEntryHashTable (Address: 0x180078d38)
  • RtlGetDeviceFamilyInfoEnum (Address: 0x180078d60)
  • RtlGetNextEntryHashTable (Address: 0x180078d28)
  • RtlGetVersion (Address: 0x180078db8)
  • RtlInitEnumerationHashTable (Address: 0x180078db0)
  • RtlInsertEntryHashTable (Address: 0x180078d20)
  • RtlIpv4AddressToStringW (Address: 0x180078d70)
  • RtlIpv4StringToAddressExW (Address: 0x180078da8)
  • RtlIpv4StringToAddressW (Address: 0x180078d68)
  • RtlIpv6AddressToStringW (Address: 0x180078d98)
  • RtlIpv6StringToAddressW (Address: 0x180078d58)
  • RtlLookupEntryHashTable (Address: 0x180078d30)
  • RtlNtStatusToDosError (Address: 0x180078d78)
  • RtlRemoveEntryHashTable (Address: 0x180078d48)
  • WinSqmIncrementDWORD (Address: 0x180078d50)
  • WinSqmSetIfMaxDWORD (Address: 0x180078da0)
RPCRT4.dll
  • I_RpcBindingInqLocalClientPID (Address: 0x1800783e8)
  • NdrServerCall2 (Address: 0x1800783e0)
  • NdrServerCallAll (Address: 0x1800783d8)
  • RpcBindingVectorFree (Address: 0x180078440)
  • RpcEpRegisterW (Address: 0x180078410)
  • RpcEpUnregister (Address: 0x180078418)
  • RpcImpersonateClient (Address: 0x180078408)
  • RpcRevertToSelf (Address: 0x1800783f8)
  • RpcRevertToSelfEx (Address: 0x1800783f0)
  • RpcServerInqBindings (Address: 0x180078438)
  • RpcServerRegisterIf3 (Address: 0x180078400)
  • RpcServerRegisterIfEx (Address: 0x180078430)
  • RpcServerUnregisterIfEx (Address: 0x180078420)
  • RpcServerUseProtseqIfW (Address: 0x1800783d0)
  • RpcServerUseProtseqW (Address: 0x180078428)
  • UuidCreate (Address: 0x1800783c8)
WINNSI.DLL
  • NsiConnectToServer (Address: 0x180078460)
  • NsiDisconnectFromServer (Address: 0x180078450)
  • NsiRpcDeregisterChangeNotification (Address: 0x180078458)
  • NsiRpcRegisterChangeNotification (Address: 0x180078468)