ndfapi.dll

  • File Path: C:\Windows\SysWOW64\ndfapi.dll
  • Description: Network Diagnostic Framework Client API

Hashes

Type Hash
MD5 095C375A462602D5C925859975B8AD95
SHA1 D5863AAFE6295568CC30346278A4FA675C63F85F
SHA256 63F550D139F28BBC07B4658F1B8CB9F13A8234305C3C8A44D19518BA5484DA54
SHA384 1586E160AAF456C6E685FCC2F5BC1EFBBAE3EB38EC82617589F06949004281BB4483380B963AF756BA550942B275538C
SHA512 C9938C5D754EE0B490DBD12C95EBEA28CB8A3F0076483BBE1018C3DDFEE1AF7A51F728EC4D99ED26C95401AEEDB167E0DEA9DABAC0C433082B150C80F9BAE95B
SSDEEP 6144:X9aPkV5ds3IZvKUP9oFo5jRNFzlXoDc0jbJYOjlCLHUZQW:XAPkV5W3GvP6eRNRqVvJ/wLI
IMP 1FEE482237370D69105CD437E2C5123B
PESHA1 2E8DABAD4E10CB5C04561197018BEF925FE0028A
PE256 3A658B6ED6916D02D77F8E2E29915B92FE85B1AC821D94B437B00BB4CAF4C374

DLL Exports:

Function Name Ordinal Type
NdfExecuteDiagnosis 25 Exported Function
NdfGetTraceFile 26 Exported Function
NdfRepairIncident 27 Exported Function
NdfDiagnoseIncident 24 Exported Function
NdfCreateWebIncident 21 Exported Function
NdfCreateWebIncidentEx 22 Exported Function
NdfCreateWinSockIncident 23 Exported Function
NdfRunDllDuplicateIPDefendingSystem 4 Exported Function
NdfRunDllDuplicateIPOffendingSystem 5 Exported Function
NdfRunDllHelpTopic 6 Exported Function
NdfRunDllDiagnoseWithAnswerFile 3 Exported Function
NdfRepairIncidentEx 28 Exported Function
NdfRunDllDiagnoseIncident 1 Exported Function
NdfRunDllDiagnoseNetConnectionIncident 2 Exported Function
NdfCancelIncident 11 Exported Function
NdfCloseIncident 12 Exported Function
NdfCreateConnectivityIncident 13 Exported Function
DllUnregisterServer 10 Exported Function
DllCanUnloadNow 7 Exported Function
DllGetClassObject 8 Exported Function
DllRegisterServer 9 Exported Function
NdfCreateNetConnectionIncident 18 Exported Function
NdfCreatePnrpIncident 19 Exported Function
NdfCreateSharingIncident 20 Exported Function
NdfCreateIncident 17 Exported Function
NdfCreateDNSIncident 14 Exported Function
NdfCreateGroupingIncident 15 Exported Function
NdfCreateInboundIncident 16 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ndfapi.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/67
  • VirusTotal Link: https://www.virustotal.com/gui/file/63f550d139f28bbc07b4658f1b8cb9f13a8234305c3c8a44d19518ba5484da54/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\system32\ndfapi.dll 47

MIT License. Copyright (c) 2020-2021 Strontic.