rpcnsh.dll
Description: RPC Netshell Helper
Authors: © Microsoft Corporation. All rights reserved.
Version: 10.0.19041.6157
Architecture: 64-bit
Operating System: Windows NT
SHA256: 78c69443d7bc89368b36792cf0d65997
File Size: 69.0 KB
Uploaded At: Dec. 1, 2025, 7:38 a.m.
Views: 3
Exported Functions
- InitHelperDll (Ordinal: 1, Address: 0x1220)
Imported DLLs & Functions
ADVAPI32.dll
- ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x18000d6f0)
- ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18000d6d8)
- RegCloseKey (Address: 0x18000d6c0)
- RegCreateKeyExA (Address: 0x18000d6d0)
- RegDeleteKeyExA (Address: 0x18000d6b8)
- RegGetValueA (Address: 0x18000d6c8)
- RegOpenKeyExA (Address: 0x18000d6e8)
- RegSetValueExA (Address: 0x18000d6e0)
fwpuclnt.dll
- FwpmEngineClose0 (Address: 0x18000d920)
- FwpmEngineOpen0 (Address: 0x18000d950)
- FwpmFilterAdd0 (Address: 0x18000d940)
- FwpmFilterCreateEnumHandle0 (Address: 0x18000d938)
- FwpmFilterDeleteByKey0 (Address: 0x18000d948)
- FwpmFilterDestroyEnumHandle0 (Address: 0x18000d928)
- FwpmFilterEnum0 (Address: 0x18000d958)
- FwpmFreeMemory0 (Address: 0x18000d930)
IPHLPAPI.DLL
- GetIfEntry (Address: 0x18000d700)
- GetIpAddrTable (Address: 0x18000d708)
KERNEL32.dll
- AcquireSRWLockExclusive (Address: 0x18000d7b8)
- AcquireSRWLockShared (Address: 0x18000d760)
- CloseHandle (Address: 0x18000d7a0)
- CloseThreadpoolTimer (Address: 0x18000d818)
- CreateMutexExW (Address: 0x18000d770)
- CreateSemaphoreExW (Address: 0x18000d838)
- CreateThreadpoolTimer (Address: 0x18000d788)
- DebugBreak (Address: 0x18000d738)
- DeleteCriticalSection (Address: 0x18000d810)
- EnterCriticalSection (Address: 0x18000d850)
- FormatMessageW (Address: 0x18000d7d0)
- GetCurrentProcess (Address: 0x18000d758)
- GetCurrentProcessId (Address: 0x18000d750)
- GetCurrentThreadId (Address: 0x18000d7e0)
- GetLastError (Address: 0x18000d828)
- GetModuleFileNameA (Address: 0x18000d830)
- GetModuleHandleA (Address: 0x18000d820)
- GetModuleHandleExW (Address: 0x18000d860)
- GetModuleHandleW (Address: 0x18000d740)
- GetProcAddress (Address: 0x18000d778)
- GetProcessHeap (Address: 0x18000d748)
- GetSystemTimeAsFileTime (Address: 0x18000d800)
- GetTickCount (Address: 0x18000d808)
- HeapAlloc (Address: 0x18000d780)
- HeapFree (Address: 0x18000d840)
- InitializeCriticalSectionEx (Address: 0x18000d870)
- IsDebuggerPresent (Address: 0x18000d730)
- LeaveCriticalSection (Address: 0x18000d868)
- LocalFree (Address: 0x18000d768)
- OpenSemaphoreW (Address: 0x18000d7a8)
- OutputDebugStringW (Address: 0x18000d7c0)
- QueryPerformanceCounter (Address: 0x18000d7f8)
- ReleaseMutex (Address: 0x18000d7d8)
- ReleaseSemaphore (Address: 0x18000d858)
- ReleaseSRWLockExclusive (Address: 0x18000d7c8)
- ReleaseSRWLockShared (Address: 0x18000d790)
- SetLastError (Address: 0x18000d848)
- SetThreadpoolTimer (Address: 0x18000d798)
- SetUnhandledExceptionFilter (Address: 0x18000d718)
- Sleep (Address: 0x18000d728)
- TerminateProcess (Address: 0x18000d7f0)
- UnhandledExceptionFilter (Address: 0x18000d720)
- WaitForSingleObject (Address: 0x18000d7e8)
- WaitForSingleObjectEx (Address: 0x18000d7b0)
- WaitForThreadpoolTimerCallbacks (Address: 0x18000d878)
msvcrt.dll
- __C_specific_handler (Address: 0x18000d9c0)
- __dllonexit (Address: 0x18000d970)
- _amsg_exit (Address: 0x18000d9b0)
- _callnewh (Address: 0x18000d980)
- _initterm (Address: 0x18000d9b8)
- _lock (Address: 0x18000d998)
- _onexit (Address: 0x18000d9a0)
- _purecall (Address: 0x18000d9f0)
- _unlock (Address: 0x18000d988)
- _vsnprintf (Address: 0x18000da18)
- _vsnwprintf (Address: 0x18000da10)
- _wcsicmp (Address: 0x18000da00)
- _wtoi (Address: 0x18000d9d0)
- _XcptFilter (Address: 0x18000d990)
- atol (Address: 0x18000d9a8)
- free (Address: 0x18000da20)
- malloc (Address: 0x18000d978)
- memcmp (Address: 0x18000d9c8)
- memcpy (Address: 0x18000d968)
- memcpy_s (Address: 0x18000da08)
- memmove_s (Address: 0x18000d9d8)
- memset (Address: 0x18000da28)
- printf (Address: 0x18000d9e8)
- swscanf (Address: 0x18000d9f8)
- wcsrchr (Address: 0x18000d9e0)
NETSH.EXE
- MatchToken (Address: 0x18000d898)
- PreprocessCommand (Address: 0x18000d8b0)
- PrintError (Address: 0x18000d8a8)
- PrintMessage (Address: 0x18000d8a0)
- PrintMessageFromModule (Address: 0x18000d8b8)
- RegisterContext (Address: 0x18000d890)
- RegisterHelper (Address: 0x18000d888)
ntdll.dll
- RtlCaptureContext (Address: 0x18000da48)
- RtlLookupFunctionEntry (Address: 0x18000da40)
- RtlVirtualUnwind (Address: 0x18000da38)
- WinSqmIncrementDWORD (Address: 0x18000da50)
- WinSqmIsOptedIn (Address: 0x18000da58)
RPCRT4.dll
- UuidCreateNil (Address: 0x18000d8d8)
- UuidCreateSequential (Address: 0x18000d8e0)
- UuidEqual (Address: 0x18000d8c8)
- UuidIsNil (Address: 0x18000d8d0)
WS2_32.dll
- inet_ntoa (Address: 0x18000d900)
- inet_pton (Address: 0x18000d8f0)
- WSAGetLastError (Address: 0x18000d910)
- WSAStartup (Address: 0x18000d908)
- WSAStringToAddressW (Address: 0x18000d8f8)