PeerDistSh.dll

Description: BranchCache Netshell Helper

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.3636

Architecture: 64-bit

Operating System: Windows NT

SHA256: 64bc6b60c068d82956cf7b9e0de1e4d2

File Size: 414.5 KB

Uploaded At: Dec. 1, 2025, 7:36 a.m.

Views: 5

Exported Functions

  • InitHelperDll (Ordinal: 1, Address: 0x1280)

Imported DLLs & Functions

ADVAPI32.dll
  • GetExplicitEntriesFromAclW (Address: 0x180044570)
  • GetNamedSecurityInfoW (Address: 0x180044560)
  • OpenProcessToken (Address: 0x180044550)
  • OpenThreadToken (Address: 0x180044558)
  • RegOpenKeyTransactedW (Address: 0x180044568)
  • SetEntriesInAclW (Address: 0x180044578)
  • SetNamedSecurityInfoW (Address: 0x180044580)
api-ms-win-core-com-l1-1-0.dll
  • CoCreateInstance (Address: 0x180044830)
  • CoInitializeEx (Address: 0x180044820)
  • CoUninitialize (Address: 0x180044828)
api-ms-win-core-delayload-l1-1-0.dll
  • DelayLoadFailureHook (Address: 0x180044840)
api-ms-win-core-delayload-l1-1-1.dll
  • ResolveDelayLoadedAPI (Address: 0x180044850)
api-ms-win-core-errorhandling-l1-1-0.dll
  • GetLastError (Address: 0x180044860)
  • SetUnhandledExceptionFilter (Address: 0x180044870)
  • UnhandledExceptionFilter (Address: 0x180044868)
api-ms-win-core-file-l1-1-0.dll
  • CreateDirectoryW (Address: 0x180044888)
  • DeleteFileW (Address: 0x180044880)
api-ms-win-core-handle-l1-1-0.dll
  • CloseHandle (Address: 0x180044898)
api-ms-win-core-heap-l2-1-0.dll
  • LocalFree (Address: 0x1800448a8)
api-ms-win-core-libraryloader-l1-2-0.dll
  • LoadStringW (Address: 0x1800448b8)
api-ms-win-core-localization-l1-2-0.dll
  • FormatMessageW (Address: 0x1800448c8)
api-ms-win-core-localization-private-l1-1-0.dll
  • LoadStringByReference (Address: 0x1800448d8)
api-ms-win-core-processenvironment-l1-1-0.dll
  • ExpandEnvironmentStringsW (Address: 0x1800448e8)
api-ms-win-core-processthreads-l1-1-0.dll
  • GetCurrentProcess (Address: 0x180044910)
  • GetCurrentProcessId (Address: 0x1800448f8)
  • GetCurrentThreadId (Address: 0x180044918)
  • SetThreadToken (Address: 0x180044900)
  • TerminateProcess (Address: 0x180044908)
api-ms-win-core-profile-l1-1-0.dll
  • QueryPerformanceCounter (Address: 0x180044928)
api-ms-win-core-string-l2-1-1.dll
  • SHLoadIndirectString (Address: 0x180044938)
api-ms-win-core-synch-l1-1-0.dll
  • AcquireSRWLockExclusive (Address: 0x180044970)
  • CreateEventW (Address: 0x180044960)
  • DeleteCriticalSection (Address: 0x180044948)
  • LeaveCriticalSection (Address: 0x180044958)
  • ReleaseSRWLockExclusive (Address: 0x180044968)
  • WaitForSingleObject (Address: 0x180044950)
api-ms-win-core-synch-l1-2-0.dll
  • Sleep (Address: 0x180044980)
api-ms-win-core-sysinfo-l1-1-0.dll
  • GetSystemTimeAsFileTime (Address: 0x180044998)
  • GetTickCount (Address: 0x180044990)
api-ms-win-security-base-l1-1-0.dll
  • CreateWellKnownSid (Address: 0x1800449f0)
  • EqualSid (Address: 0x1800449e8)
  • GetAce (Address: 0x1800449f8)
  • GetAclInformation (Address: 0x180044a00)
  • GetSecurityDescriptorControl (Address: 0x180044a20)
  • GetSecurityDescriptorDacl (Address: 0x1800449e0)
  • GetSecurityDescriptorGroup (Address: 0x1800449b8)
  • GetSecurityDescriptorOwner (Address: 0x1800449a8)
  • GetTokenInformation (Address: 0x1800449b0)
  • InitializeSecurityDescriptor (Address: 0x180044a10)
  • IsValidAcl (Address: 0x180044a18)
  • IsValidSecurityDescriptor (Address: 0x1800449c0)
  • SetSecurityDescriptorControl (Address: 0x1800449c8)
  • SetSecurityDescriptorDacl (Address: 0x1800449d0)
  • SetSecurityDescriptorGroup (Address: 0x1800449d8)
  • SetSecurityDescriptorOwner (Address: 0x180044a08)
api-ms-win-security-sddl-l1-1-0.dll
  • ConvertSidToStringSidW (Address: 0x180044a40)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x180044a38)
  • ConvertStringSidToSidW (Address: 0x180044a30)
api-ms-win-service-core-l1-1-1.dll
  • EnumDependentServicesW (Address: 0x180044a50)
api-ms-win-service-management-l1-1-0.dll
  • CloseServiceHandle (Address: 0x180044a68)
  • OpenSCManagerW (Address: 0x180044a60)
  • OpenServiceW (Address: 0x180044a78)
  • StartServiceW (Address: 0x180044a70)
api-ms-win-service-management-l2-1-0.dll
  • ChangeServiceConfig2W (Address: 0x180044a98)
  • ChangeServiceConfigW (Address: 0x180044a90)
  • NotifyServiceStatusChangeW (Address: 0x180044a88)
  • QueryServiceConfigW (Address: 0x180044aa0)
  • QueryServiceStatusEx (Address: 0x180044aa8)
api-ms-win-service-winsvc-l1-1-0.dll
  • ControlService (Address: 0x180044ab8)
bcrypt.dll
  • BCryptCloseAlgorithmProvider (Address: 0x180044ac8)
  • BCryptCreateHash (Address: 0x180044ae8)
  • BCryptDecrypt (Address: 0x180044b10)
  • BCryptDestroyHash (Address: 0x180044ae0)
  • BCryptEncrypt (Address: 0x180044b08)
  • BCryptFinishHash (Address: 0x180044b00)
  • BCryptGenerateSymmetricKey (Address: 0x180044af0)
  • BCryptGenRandom (Address: 0x180044ad0)
  • BCryptGetProperty (Address: 0x180044ad8)
  • BCryptHashData (Address: 0x180044af8)
  • BCryptOpenAlgorithmProvider (Address: 0x180044b18)
KERNEL32.dll
  • AcquireSRWLockShared (Address: 0x180044768)
  • CloseThreadpoolCleanupGroup (Address: 0x1800445d0)
  • CloseThreadpoolCleanupGroupMembers (Address: 0x1800445c8)
  • CloseThreadpoolWork (Address: 0x1800445e0)
  • CompareStringW (Address: 0x180044740)
  • CreateFileW (Address: 0x1800445f8)
  • CreateThread (Address: 0x1800446b8)
  • CreateThreadpoolCleanupGroup (Address: 0x1800445c0)
  • CreateThreadpoolWork (Address: 0x1800445d8)
  • DeleteTimerQueueEx (Address: 0x1800445b0)
  • EnterCriticalSection (Address: 0x180044748)
  • FindClose (Address: 0x180044630)
  • FindFirstFileExW (Address: 0x180044650)
  • FindNextFileW (Address: 0x180044640)
  • FreeLibrary (Address: 0x180044708)
  • GetCurrentThread (Address: 0x180044718)
  • GetDiskFreeSpaceExW (Address: 0x180044658)
  • GetExitCodeThread (Address: 0x1800446c8)
  • GetFileSizeEx (Address: 0x1800445f0)
  • GetFullPathNameW (Address: 0x1800445e8)
  • GetModuleFileNameW (Address: 0x180044710)
  • GetModuleHandleExW (Address: 0x1800446d8)
  • GetProcAddress (Address: 0x180044700)
  • GetProcessHeap (Address: 0x1800446e8)
  • GetProcessMitigationPolicy (Address: 0x1800445a8)
  • GetTickCount64 (Address: 0x180044690)
  • GetVolumeInformationW (Address: 0x180044738)
  • GetVolumePathNameW (Address: 0x180044730)
  • GetWindowsDirectoryW (Address: 0x1800446f0)
  • HeapAlloc (Address: 0x1800446e0)
  • HeapFree (Address: 0x180044598)
  • InitializeCriticalSectionAndSpinCount (Address: 0x180044750)
  • InitializeSRWLock (Address: 0x180044760)
  • LoadLibraryW (Address: 0x1800446f8)
  • LocalAlloc (Address: 0x180044628)
  • lstrcmpW (Address: 0x180044648)
  • RaiseFailFastException (Address: 0x180044600)
  • ReadFile (Address: 0x180044728)
  • RegCloseKey (Address: 0x1800446c0)
  • RegCreateKeyExW (Address: 0x180044678)
  • RegDeleteTreeW (Address: 0x180044620)
  • RegDeleteValueW (Address: 0x180044670)
  • RegEnumValueW (Address: 0x180044660)
  • RegGetKeySecurity (Address: 0x180044618)
  • RegGetValueW (Address: 0x180044698)
  • RegNotifyChangeKeyValue (Address: 0x1800446a0)
  • RegOpenKeyExW (Address: 0x1800446a8)
  • RegQueryInfoKeyW (Address: 0x180044668)
  • RegSetKeySecurity (Address: 0x180044610)
  • RegSetValueExW (Address: 0x180044688)
  • ReleaseSRWLockShared (Address: 0x180044770)
  • RemoveDirectoryW (Address: 0x180044638)
  • SetEvent (Address: 0x1800446d0)
  • SetEventWhenCallbackReturns (Address: 0x180044680)
  • SetLastError (Address: 0x1800445a0)
  • SleepEx (Address: 0x180044608)
  • SubmitThreadpoolWork (Address: 0x1800445b8)
  • TryEnterCriticalSection (Address: 0x180044758)
  • WaitForMultipleObjectsEx (Address: 0x1800446b0)
  • WideCharToMultiByte (Address: 0x180044590)
  • WriteFile (Address: 0x180044720)
msvcrt.dll
  • __C_specific_handler (Address: 0x180044b78)
  • __CxxFrameHandler3 (Address: 0x180044bb0)
  • __dllonexit (Address: 0x180044b58)
  • _amsg_exit (Address: 0x180044b90)
  • _callnewh (Address: 0x180044bd8)
  • _CxxThrowException (Address: 0x180044bb8)
  • _initterm (Address: 0x180044b80)
  • _lock (Address: 0x180044b70)
  • _onexit (Address: 0x180044b50)
  • _purecall (Address: 0x180044c10)
  • _unlock (Address: 0x180044b68)
  • _vsnwprintf (Address: 0x180044b88)
  • _wcsnicmp (Address: 0x180044b60)
  • _wcstoui64 (Address: 0x180044c08)
  • _XcptFilter (Address: 0x180044b98)
  • ??0exception@@QEAA@AEBQEBD@Z (Address: 0x180044be8)
  • ??0exception@@QEAA@AEBQEBDH@Z (Address: 0x180044bc0)
  • ??0exception@@QEAA@AEBV0@@Z (Address: 0x180044be0)
  • ??1exception@@UEAA@XZ (Address: 0x180044bf0)
  • ??1type_info@@UEAA@XZ (Address: 0x180044b28)
  • ?terminate@@YAXXZ (Address: 0x180044b30)
  • ?what@exception@@UEBAPEBDXZ (Address: 0x180044bf8)
  • free (Address: 0x180044bd0)
  • iswspace (Address: 0x180044c00)
  • malloc (Address: 0x180044bc8)
  • memcmp (Address: 0x180044ba8)
  • memcpy (Address: 0x180044ba0)
  • memmove (Address: 0x180044c18)
  • memset (Address: 0x180044b38)
  • wcschr (Address: 0x180044b48)
  • wcscmp (Address: 0x180044c20)
  • wcsncmp (Address: 0x180044b40)
NETSH.EXE
  • MatchEnumTag (Address: 0x180044780)
  • MatchToken (Address: 0x180044798)
  • PreprocessCommand (Address: 0x180044788)
  • PrintError (Address: 0x1800447a8)
  • PrintMessage (Address: 0x1800447a0)
  • PrintMessageFromModule (Address: 0x1800447b8)
  • RegisterContext (Address: 0x180044790)
  • RegisterHelper (Address: 0x1800447b0)
ntdll.dll
  • EtwEventActivityIdControl (Address: 0x180044c68)
  • EtwGetTraceEnableFlags (Address: 0x180044c60)
  • EtwGetTraceEnableLevel (Address: 0x180044c70)
  • EtwGetTraceLoggerHandle (Address: 0x180044c30)
  • EtwRegisterTraceGuidsW (Address: 0x180044c58)
  • EtwTraceMessage (Address: 0x180044c78)
  • EtwUnregisterTraceGuids (Address: 0x180044c50)
  • RtlCaptureContext (Address: 0x180044c48)
  • RtlLookupFunctionEntry (Address: 0x180044c40)
  • RtlVirtualUnwind (Address: 0x180044c38)
profapi.dll
  • (Address: 0x180044c88)
RPCRT4.dll
  • NdrClientCall3 (Address: 0x1800447c8)
  • RpcBindingFree (Address: 0x1800447d0)
  • RpcBindingFromStringBindingW (Address: 0x1800447e0)
  • RpcBindingSetAuthInfoExW (Address: 0x1800447d8)
  • RpcStringBindingComposeW (Address: 0x1800447e8)
  • RpcStringFreeW (Address: 0x1800447f0)
SHLWAPI.dll
  • PathCanonicalizeW (Address: 0x180044810)
  • PathIsDirectoryEmptyW (Address: 0x180044800)
  • PathIsDirectoryW (Address: 0x180044808)