PeerDist.dll

Description: BranchCache Client Library

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.5794

Architecture: 64-bit

Operating System: Windows NT

SHA256: c4949b70328fec1da5c2887af346c852

File Size: 222.5 KB

Uploaded At: Dec. 1, 2025, 7:36 a.m.

Views: 6

Security Warning

This file has been flagged as potentially dangerous.


Reason: Detected potentially dangerous functions used for process injection: OpenProcess

Exported Functions

  • PeerDistClientAddContentInformation (Ordinal: 1, Address: 0x44b0)
  • PeerDistClientAddData (Ordinal: 2, Address: 0x4870)
  • PeerDistClientBlockRead (Ordinal: 3, Address: 0x4a60)
  • PeerDistClientCancelAsyncOperation (Ordinal: 4, Address: 0x2c50)
  • PeerDistClientCloseContent (Ordinal: 5, Address: 0x42b0)
  • PeerDistClientCompleteContentInformation (Ordinal: 6, Address: 0x46a0)
  • PeerDistClientFlushContent (Ordinal: 7, Address: 0x4e60)
  • PeerDistClientGetInformationByHandle (Ordinal: 8, Address: 0x5040)
  • PeerDistClientOpenContent (Ordinal: 9, Address: 0x40d0)
  • PeerDistClientStreamRead (Ordinal: 10, Address: 0x4c60)
  • PeerDistGetOverlappedResult (Ordinal: 11, Address: 0x5230)
  • PeerDistGetStatus (Ordinal: 12, Address: 0x2770)
  • PeerDistGetStatusEx (Ordinal: 13, Address: 0x2780)
  • PeerDistRegisterForStatusChangeNotification (Ordinal: 14, Address: 0x2a40)
  • PeerDistRegisterForStatusChangeNotificationEx (Ordinal: 15, Address: 0x2a70)
  • PeerDistServerCancelAsyncOperation (Ordinal: 16, Address: 0x2e60)
  • PeerDistServerCloseContentInformation (Ordinal: 17, Address: 0x3f10)
  • PeerDistServerCloseStreamHandle (Ordinal: 18, Address: 0x3610)
  • PeerDistServerOpenContentInformation (Ordinal: 19, Address: 0x3c30)
  • PeerDistServerOpenContentInformationEx (Ordinal: 20, Address: 0x3cc0)
  • PeerDistServerPublishAddToStream (Ordinal: 21, Address: 0x3250)
  • PeerDistServerPublishCompleteStream (Ordinal: 22, Address: 0x3440)
  • PeerDistServerPublishStream (Ordinal: 23, Address: 0x3030)
  • PeerDistServerRetrieveContentInformation (Ordinal: 24, Address: 0x3d20)
  • PeerDistServerUnpublish (Ordinal: 25, Address: 0x37d0)
  • PeerDistShutdown (Ordinal: 26, Address: 0x20e0)
  • PeerDistStartup (Ordinal: 27, Address: 0x1cf0)
  • PeerDistUnregisterForStatusChangeNotification (Ordinal: 28, Address: 0x2aa0)

Imported DLLs & Functions

api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x1800260e0)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x1800260f0)
api-ms-win-core-errorhandling-l1-1-0.dll
  • SetUnhandledExceptionFilter (Address: 0x180026100)
  • UnhandledExceptionFilter (Address: 0x180026108)
api-ms-win-core-libraryloader-l1-2-0.dll
  • DisableThreadLibraryCalls (Address: 0x180026118)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180026140)
  • GetCurrentProcessId (Address: 0x180026130)
  • GetCurrentThreadId (Address: 0x180026138)
  • OpenProcessToken (Address: 0x180026148)
  • TerminateProcess (Address: 0x180026128)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180026158)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180026168)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180026180)
  • GetTickCount (Address: 0x180026178)
api-ms-win-security-base-l1-1-0.dll
  • AdjustTokenPrivileges (Address: 0x180026190)
  • CreateWellKnownSid (Address: 0x180026198)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x1800261a8)
  • OpenSCManagerW (Address: 0x1800261b8)
  • OpenServiceW (Address: 0x1800261c0)
  • StartServiceW (Address: 0x1800261b0)
api-ms-win-service-winsvc-l1-1-0.dll
  • QueryServiceStatus (Address: 0x1800261d0)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x180025f58)
  • AcquireSRWLockShared (Address: 0x180025f68)
  • CheckRemoteDebuggerPresent (Address: 0x180025ed0)
  • CloseHandle (Address: 0x180025fc0)
  • CloseThreadpoolCleanupGroup (Address: 0x180025f10)
  • CloseThreadpoolCleanupGroupMembers (Address: 0x180025f18)
  • CloseThreadpoolTimer (Address: 0x180026028)
  • CloseThreadpoolWait (Address: 0x180025ee0)
  • CloseThreadpoolWork (Address: 0x180025f00)
  • CreateEventW (Address: 0x180025f38)
  • CreateThread (Address: 0x180025fc8)
  • CreateThreadpoolCleanupGroup (Address: 0x180025f20)
  • CreateThreadpoolTimer (Address: 0x180026010)
  • CreateThreadpoolWait (Address: 0x180025ef8)
  • CreateThreadpoolWork (Address: 0x180025f08)
  • DebugBreak (Address: 0x180025ec0)
  • DeleteCriticalSection (Address: 0x180026000)
  • DeleteTimerQueueEx (Address: 0x180025f30)
  • DuplicateHandle (Address: 0x180025f40)
  • EnterCriticalSection (Address: 0x180026038)
  • FileTimeToSystemTime (Address: 0x180026030)
  • FormatMessageW (Address: 0x180025ff0)
  • GetHandleInformation (Address: 0x180025f48)
  • GetLastError (Address: 0x180025f88)
  • GetModuleFileNameW (Address: 0x180026040)
  • GetTickCount64 (Address: 0x180025fb8)
  • GlobalMemoryStatusEx (Address: 0x180026068)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180025f78)
  • InitializeSRWLock (Address: 0x180025eb8)
  • IsDebuggerPresent (Address: 0x180025ec8)
  • IsWow64Process (Address: 0x180026058)
  • K32EnumProcessModules (Address: 0x180026048)
  • LeaveCriticalSection (Address: 0x180026008)
  • LocalFree (Address: 0x180025ff8)
  • lstrcmpiW (Address: 0x180025f90)
  • OpenProcess (Address: 0x180026050)
  • QueryFullProcessImageNameW (Address: 0x180025f80)
  • RegCloseKey (Address: 0x180025fd0)
  • RegNotifyChangeKeyValue (Address: 0x180025fe0)
  • RegOpenKeyExW (Address: 0x180025fd8)
  • RegQueryValueExW (Address: 0x180026060)
  • ReleaseSRWLockExclusive (Address: 0x180025f50)
  • ReleaseSRWLockShared (Address: 0x180025f60)
  • ResetEvent (Address: 0x180025fa0)
  • SetEvent (Address: 0x180025fb0)
  • SetEventWhenCallbackReturns (Address: 0x180025ed8)
  • SetLastError (Address: 0x180025fa8)
  • SetThreadpoolTimer (Address: 0x180026018)
  • SetThreadpoolWait (Address: 0x180025ef0)
  • SubmitThreadpoolWork (Address: 0x180025f28)
  • TryEnterCriticalSection (Address: 0x180025f70)
  • WaitForMultipleObjectsEx (Address: 0x180025fe8)
  • WaitForSingleObject (Address: 0x180025f98)
  • WaitForThreadpoolTimerCallbacks (Address: 0x180026020)
  • WaitForThreadpoolWaitCallbacks (Address: 0x180025ee8)
msvcrt.dll
  • __C_specific_handler (Address: 0x180026260)
  • __CxxFrameHandler3 (Address: 0x180026210)
  • __dllonexit (Address: 0x180026280)
  • _amsg_exit (Address: 0x180026230)
  • _callnewh (Address: 0x180026200)
  • _CxxThrowException (Address: 0x180026220)
  • _initterm (Address: 0x180026258)
  • _lock (Address: 0x180026270)
  • _onexit (Address: 0x180026290)
  • _purecall (Address: 0x180026238)
  • _unlock (Address: 0x180026278)
  • _XcptFilter (Address: 0x180026228)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180026240)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x1800261f0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180026250)
  • ??1exception@@UEAA@XZ (Address: 0x180026208)
  • ??1type_info@@UEAA@XZ (Address: 0x180026268)
  • ?terminate@@YAXXZ (Address: 0x180026248)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180026218)
  • free (Address: 0x1800261e0)
  • malloc (Address: 0x1800261e8)
  • memcmp (Address: 0x1800261f8)
  • memcpy (Address: 0x180026288)
  • memset (Address: 0x180026298)
ntdll.dll
  • DbgPrint (Address: 0x180026338)
  • EtwEventActivityIdControl (Address: 0x1800262d0)
  • EtwEventRegister (Address: 0x180026300)
  • EtwEventUnregister (Address: 0x1800262f0)
  • EtwEventWrite (Address: 0x1800262a8)
  • EtwEventWriteTransfer (Address: 0x1800262c8)
  • EtwGetTraceEnableFlags (Address: 0x180026318)
  • EtwGetTraceEnableLevel (Address: 0x180026320)
  • EtwGetTraceLoggerHandle (Address: 0x180026328)
  • EtwRegisterTraceGuidsW (Address: 0x180026310)
  • EtwTraceMessage (Address: 0x180026330)
  • EtwUnregisterTraceGuids (Address: 0x180026308)
  • NtAllocateReserveObject (Address: 0x1800262b0)
  • NtSetIoCompletionEx (Address: 0x1800262c0)
  • RtlCaptureContext (Address: 0x1800262e8)
  • RtlDllShutdownInProgress (Address: 0x1800262f8)
  • RtlLookupFunctionEntry (Address: 0x1800262e0)
  • RtlNtStatusToDosError (Address: 0x1800262b8)
  • RtlVirtualUnwind (Address: 0x1800262d8)
RPCRT4.dll
  • I_RpcExceptionFilter (Address: 0x1800260a8)
  • Ndr64AsyncClientCall (Address: 0x180026080)
  • NdrClientCall3 (Address: 0x180026078)
  • RpcAsyncCancelCall (Address: 0x180026098)
  • RpcAsyncCompleteCall (Address: 0x180026090)
  • RpcAsyncInitializeHandle (Address: 0x1800260a0)
  • RpcBindingFree (Address: 0x180026088)
  • RpcBindingFromStringBindingW (Address: 0x1800260c8)
  • RpcBindingSetAuthInfoExW (Address: 0x1800260c0)
  • RpcSsDestroyClientContext (Address: 0x1800260b0)
  • RpcStringBindingComposeW (Address: 0x1800260d0)
  • RpcStringFreeW (Address: 0x1800260b8)