ndfapi.dll

  • File Path: C:\Windows\system32\ndfapi.dll
  • Description: Network Diagnostic Framework Client API

Hashes

Type Hash
MD5 0EAD8D59C75A28E7E9AAD9264C6E19DB
SHA1 28B45106C5AF7C93161EC43EB09CC3B27899EA16
SHA256 007A87AD8AFB2556373E076F0B8C377CBDAC0364D1E54EEF2DFAD0AA0D40D46B
SHA384 34980F9F3EECE5666022D1CEE5457F87AFB72294496AD9B0B2963C2B5A0D24A88D1B8D6A2EA5100797B867FE81A46FB0
SHA512 9E774CF2DFD0CF13F2032BC57B103D5C4A136166503D4EDA15415A32D8C1054B8F355B3178388062D45DD6640FDFBDBD4292E7C2B90CA98038C120ACF3670EBF
SSDEEP 6144:Ouitied5H1nkURyT96154XFzJ361emUsoc0jbJYOjlCLHUZQV:ZitienuUY616tvJ/wLI
IMP 1F41C7A3A49962E2659DEA0A8CF4D236
PESHA1 F67C5A21FF839CB4C34DBD5C15106A4A77E5031F
PE256 E6F7EB645770E30D75FC8F63E8F4A15FF1BB3DCB34690C07F18221C007F6ACBD

DLL Exports:

Function Name Ordinal Type
NdfExecuteDiagnosis 25 Exported Function
NdfGetTraceFile 26 Exported Function
NdfRepairIncident 27 Exported Function
NdfDiagnoseIncident 24 Exported Function
NdfCreateWebIncident 21 Exported Function
NdfCreateWebIncidentEx 22 Exported Function
NdfCreateWinSockIncident 23 Exported Function
NdfRunDllDuplicateIPDefendingSystem 4 Exported Function
NdfRunDllDuplicateIPOffendingSystem 5 Exported Function
NdfRunDllHelpTopic 6 Exported Function
NdfRunDllDiagnoseWithAnswerFile 3 Exported Function
NdfRepairIncidentEx 28 Exported Function
NdfRunDllDiagnoseIncident 1 Exported Function
NdfRunDllDiagnoseNetConnectionIncident 2 Exported Function
NdfCancelIncident 11 Exported Function
NdfCloseIncident 12 Exported Function
NdfCreateConnectivityIncident 13 Exported Function
DllUnregisterServer 10 Exported Function
DllCanUnloadNow 7 Exported Function
DllGetClassObject 8 Exported Function
DllRegisterServer 9 Exported Function
NdfCreateNetConnectionIncident 18 Exported Function
NdfCreatePnrpIncident 19 Exported Function
NdfCreateSharingIncident 20 Exported Function
NdfCreateIncident 17 Exported Function
NdfCreateDNSIncident 14 Exported Function
NdfCreateGroupingIncident 15 Exported Function
NdfCreateInboundIncident 16 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: ndfapi.dll.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/007a87ad8afb2556373e076f0b8c377cbdac0364d1e54eef2dfad0aa0d40d46b/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\SysWOW64\ndfapi.dll 47

MIT License. Copyright (c) 2020-2021 Strontic.