rpcnsh.dll

Description: RPC Netshell Helper

Authors: © Microsoft Corporation. All rights reserved.

Version: 10.0.19041.6157

Architecture: 64-bit

Operating System: Windows NT

SHA256: 78c69443d7bc89368b36792cf0d65997

File Size: 69.0 KB

Uploaded At: Dec. 1, 2025, 7:38 a.m.

Views: 3

Exported Functions

  • InitHelperDll (Ordinal: 1, Address: 0x1220)

Imported DLLs & Functions

ADVAPI32.dll
  • ConvertSecurityDescriptorToStringSecurityDescriptorW (Address: 0x18000d6f0)
  • ConvertStringSecurityDescriptorToSecurityDescriptorW (Address: 0x18000d6d8)
  • RegCloseKey (Address: 0x18000d6c0)
  • RegCreateKeyExA (Address: 0x18000d6d0)
  • RegDeleteKeyExA (Address: 0x18000d6b8)
  • RegGetValueA (Address: 0x18000d6c8)
  • RegOpenKeyExA (Address: 0x18000d6e8)
  • RegSetValueExA (Address: 0x18000d6e0)
fwpuclnt.dll
  • FwpmEngineClose0 (Address: 0x18000d920)
  • FwpmEngineOpen0 (Address: 0x18000d950)
  • FwpmFilterAdd0 (Address: 0x18000d940)
  • FwpmFilterCreateEnumHandle0 (Address: 0x18000d938)
  • FwpmFilterDeleteByKey0 (Address: 0x18000d948)
  • FwpmFilterDestroyEnumHandle0 (Address: 0x18000d928)
  • FwpmFilterEnum0 (Address: 0x18000d958)
  • FwpmFreeMemory0 (Address: 0x18000d930)
IPHLPAPI.DLL
  • GetIfEntry (Address: 0x18000d700)
  • GetIpAddrTable (Address: 0x18000d708)
KERNEL32.dll
  • AcquireSRWLockExclusive (Address: 0x18000d7b8)
  • AcquireSRWLockShared (Address: 0x18000d760)
  • CloseHandle (Address: 0x18000d7a0)
  • CloseThreadpoolTimer (Address: 0x18000d818)
  • CreateMutexExW (Address: 0x18000d770)
  • CreateSemaphoreExW (Address: 0x18000d838)
  • CreateThreadpoolTimer (Address: 0x18000d788)
  • DebugBreak (Address: 0x18000d738)
  • DeleteCriticalSection (Address: 0x18000d810)
  • EnterCriticalSection (Address: 0x18000d850)
  • FormatMessageW (Address: 0x18000d7d0)
  • GetCurrentProcess (Address: 0x18000d758)
  • GetCurrentProcessId (Address: 0x18000d750)
  • GetCurrentThreadId (Address: 0x18000d7e0)
  • GetLastError (Address: 0x18000d828)
  • GetModuleFileNameA (Address: 0x18000d830)
  • GetModuleHandleA (Address: 0x18000d820)
  • GetModuleHandleExW (Address: 0x18000d860)
  • GetModuleHandleW (Address: 0x18000d740)
  • GetProcAddress (Address: 0x18000d778)
  • GetProcessHeap (Address: 0x18000d748)
  • GetSystemTimeAsFileTime (Address: 0x18000d800)
  • GetTickCount (Address: 0x18000d808)
  • HeapAlloc (Address: 0x18000d780)
  • HeapFree (Address: 0x18000d840)
  • InitializeCriticalSectionEx (Address: 0x18000d870)
  • IsDebuggerPresent (Address: 0x18000d730)
  • LeaveCriticalSection (Address: 0x18000d868)
  • LocalFree (Address: 0x18000d768)
  • OpenSemaphoreW (Address: 0x18000d7a8)
  • OutputDebugStringW (Address: 0x18000d7c0)
  • QueryPerformanceCounter (Address: 0x18000d7f8)
  • ReleaseMutex (Address: 0x18000d7d8)
  • ReleaseSemaphore (Address: 0x18000d858)
  • ReleaseSRWLockExclusive (Address: 0x18000d7c8)
  • ReleaseSRWLockShared (Address: 0x18000d790)
  • SetLastError (Address: 0x18000d848)
  • SetThreadpoolTimer (Address: 0x18000d798)
  • SetUnhandledExceptionFilter (Address: 0x18000d718)
  • Sleep (Address: 0x18000d728)
  • TerminateProcess (Address: 0x18000d7f0)
  • UnhandledExceptionFilter (Address: 0x18000d720)
  • WaitForSingleObject (Address: 0x18000d7e8)
  • WaitForSingleObjectEx (Address: 0x18000d7b0)
  • WaitForThreadpoolTimerCallbacks (Address: 0x18000d878)
msvcrt.dll
  • __C_specific_handler (Address: 0x18000d9c0)
  • __dllonexit (Address: 0x18000d970)
  • _amsg_exit (Address: 0x18000d9b0)
  • _callnewh (Address: 0x18000d980)
  • _initterm (Address: 0x18000d9b8)
  • _lock (Address: 0x18000d998)
  • _onexit (Address: 0x18000d9a0)
  • _purecall (Address: 0x18000d9f0)
  • _unlock (Address: 0x18000d988)
  • _vsnprintf (Address: 0x18000da18)
  • _vsnwprintf (Address: 0x18000da10)
  • _wcsicmp (Address: 0x18000da00)
  • _wtoi (Address: 0x18000d9d0)
  • _XcptFilter (Address: 0x18000d990)
  • atol (Address: 0x18000d9a8)
  • free (Address: 0x18000da20)
  • malloc (Address: 0x18000d978)
  • memcmp (Address: 0x18000d9c8)
  • memcpy (Address: 0x18000d968)
  • memcpy_s (Address: 0x18000da08)
  • memmove_s (Address: 0x18000d9d8)
  • memset (Address: 0x18000da28)
  • printf (Address: 0x18000d9e8)
  • swscanf (Address: 0x18000d9f8)
  • wcsrchr (Address: 0x18000d9e0)
NETSH.EXE
  • MatchToken (Address: 0x18000d898)
  • PreprocessCommand (Address: 0x18000d8b0)
  • PrintError (Address: 0x18000d8a8)
  • PrintMessage (Address: 0x18000d8a0)
  • PrintMessageFromModule (Address: 0x18000d8b8)
  • RegisterContext (Address: 0x18000d890)
  • RegisterHelper (Address: 0x18000d888)
ntdll.dll
  • RtlCaptureContext (Address: 0x18000da48)
  • RtlLookupFunctionEntry (Address: 0x18000da40)
  • RtlVirtualUnwind (Address: 0x18000da38)
  • WinSqmIncrementDWORD (Address: 0x18000da50)
  • WinSqmIsOptedIn (Address: 0x18000da58)
RPCRT4.dll
  • UuidCreateNil (Address: 0x18000d8d8)
  • UuidCreateSequential (Address: 0x18000d8e0)
  • UuidEqual (Address: 0x18000d8c8)
  • UuidIsNil (Address: 0x18000d8d0)
WS2_32.dll
  • inet_ntoa (Address: 0x18000d900)
  • inet_pton (Address: 0x18000d8f0)
  • WSAGetLastError (Address: 0x18000d910)
  • WSAStartup (Address: 0x18000d908)
  • WSAStringToAddressW (Address: 0x18000d8f8)