Gridinsoft Logo

The rpcrt4.dll (Remote Procedure Call Runtime) File Analysis

Technical Analysis

File Name rpcrt4.dll
File Type
PE32+ executable (DLL) (console) x86-64, for MS Windows
Scanner Version 1.0.210.174
Database Version 2025-03-12 22:00:46 UTC

Clean File

No threats detected by our scanner

0%
Detection Rate
1,190,216
File Size (bytes)
2025-03-12
Analysis Date

Scan Another File

File Identification

Hash Type Value Action
MD5
0fcd8e1b8978cf01f32bd168eeaa8a14
SHA1
09fd8b7c0444d8a28e0d29f93da1bc1cd528e8a6
SHA256
6b71520f37e7e30934966fbab9b60de6f194703b6a246a6272feeb1c37e1930e
SHA512
87a9f5e860298117ad3fd353a46893ca809bac770d5eb60b42ff4d6283c5190f4ef353aa5f20273c0857e2e2221324e85130bf8442820d378c4bb506000866e9
ImpHash
ea6b63d47413d34f1c215326df304528

PE Analysis

Basic Information

Image Base 0x180000000
Entry Point 0x1800608d0
Compilation Time 2033-11-19 18:03:39
Checksum 0x0012fdbb (Actual: 0x0012fdbb)
OS Version 10.0
PEiD Signatures PE32+ executable (DLL) (console) x86-64, for MS Windows
PDB Path rpcrt4.pdb
Digital Signature OK
Imports 29 libraries
Exports 557 functions
Resources 3 Resources
Sections 8 Sections

Version Information

CompanyName Microsoft Corporation
FileDescription Remote Procedure Call Runtime
FileVersion 10.0.19041.4957 (WinBuild.160101.0800)
InternalName rpcrt4.dll
LegalCopyright © Microsoft Corporation. All rights reserved.
OriginalFilename rpcrt4.dll
ProductName Microsoft® Windows® Operating System
ProductVersion 10.0.19041.4957
Translation 0x0409 0x04b0

PE Sections

Name Virtual Address Virtual Size Raw Size Entropy Characteristics MD5
.text 0x00001000 887,206 bytes 887,296 bytes 6.37 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ 87ED403DBA9565249BB95777CC6B24D1
.ndr64 0x000da000 26,772 bytes 27,136 bytes 6.18 (Normal) IMAGE_SCN_CNT_CODE|IMAGE_SCN_MEM_EXECUTE|IMAGE_SCN_MEM_READ F1435B8C254F77C8E2C2D6C6382EFEF9
.rdata 0x000e1000 175,314 bytes 175,616 bytes 4.93 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 44153B106538E329936C8AFE3113B79E
.data 0x0010c000 6,504 bytes 2,048 bytes 2.83 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 2E27C8B44555FCB84DE2494E02ECCD67
.pdata 0x0010e000 51,612 bytes 51,712 bytes 6.08 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 09B7CD4BC82C3133EFA7386F559C051C
.didat 0x0011b000 648 bytes 1,024 bytes 2.36 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ|IMAGE_SCN_MEM_WRITE 8A360186B7473626E5C40C955C6391FD
.rsrc 0x0011c000 17,760 bytes 17,920 bytes 3.79 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_READ 03E91CBC2F9EA6D93F701DDBFF3042DE
.reloc 0x00121000 6,092 bytes 6,144 bytes 5.41 (Normal) IMAGE_SCN_CNT_INITIALIZED_DATA|IMAGE_SCN_MEM_DISCARDABLE|IMAGE_SCN_MEM_READ 4BB2206CC29DC972EE9E73AD851CED9D

Resource Analysis

Total Resources: 3 (17,482 bytes)
Resource Type Count Total Size Percentage
MUI 1 232 bytes
1.3%
WEVT_TEMPLATE 1 16,314 bytes
93.3%
RT_VERSION 1 936 bytes
5.4%

Certificate Chain Analysis

Certificate Information
Product Microsoft® Windows® Operating System
Description Remote Procedure Call Runtime
File Version 10.0.19041.4957 (WinBuild.160101.0800)
Original Name rpcrt4.dll
Signing Date 09:04 AM 09/18/2024 (262 days ago)
Verification Status Signed
Signers Microsoft Windows; Microsoft Windows Production PCA 2011; Microsoft Root Certificate Authority 2010
Counter Signers Microsoft Time-Stamp Service; Microsoft Time-Stamp PCA 2010; Microsoft Root Certificate Authority 2010
Internal Name rpcrt4.dll
Copyright © Microsoft Corporation. All rights reserved.
Certificate Chain Summary
Microsoft Windows #1 Primary
Validity Period: 2024-05-16 23:19:08 → 2025-05-14 23:19:08
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 04 8D 7B 46 06 30 18 CC 48 62 00 00 00 00 04 8D
Microsoft Windows Production PCA 2011 #2 Chain
Validity Period: 2011-10-19 18:41:42 → 2026-10-19 18:51:42
Signature Algorithm: sha256RSA
Serial Number: 61 07 76 56 00 00 00 00 00 08
Microsoft Time-Stamp Service #3 Chain
Validity Period: 2024-07-25 18:31:21 → 2025-10-22 18:31:21
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 02 00 0B D7 AA 7F 1B 2A 17 56 00 01 00 00 02 00
Microsoft Time-Stamp PCA 2010 #4 Chain
Validity Period: 2021-09-30 18:22:25 → 2030-09-30 18:32:25
Signature Algorithm: sha256RSA
Serial Number: 33 00 00 00 15 C5 E7 6B 9E 02 9B 49 99 00 00 00 00 00 15

✓ This file has been digitally signed and the certificate chain has been verified

  • The signature ensures file integrity and authenticity from the publisher
  • Timestamping proves when the signature was applied
Certificate Verification Status

OK

Remember: This is Result of Online Virus Scanner

Gridinsoft Anti-Malware has a much more powerful virus scanning engine. We recommend using it for a more precise diagnosis of infected systems. This brief guide will help you install our flagship product for more accurate diagnostics:

Download Anti-Malware

Keep Your System Protected

This file appears clean, but regular security maintenance is important

  1. Regular Scans: Run weekly system scans to detect new threats before they can cause damage.
  2. Keep Software Updated: Ensure your operating system and all applications have the latest security patches.
  3. Safe Browsing: Avoid suspicious websites and never download software from untrusted sources.
  4. Email Security: Be cautious with email attachments and links, even from known contacts.
Proactive Protection
This file passed all security checks, but stay vigilant. New malware variants appear daily that can evade detection. Always verify files come from official sources and check digital signatures when available.

Leave a Comment

Share your thoughts or insights about this file. Do you align with our conclusion?

* Your feedback could influence our rating, and rest assured, your email will remain confidential and will only be used to communicate with you if necessary.
Your Score for

Gridinsoft Anti-Malware

Cure your PC from any kind of malware

GridinSoft Anti-Malware will help you to protect your computer from spyware, trojans, backdoors, rootkits. It cleans your system from annoying advertisement modules and other malicious stuff developed by hackers.

Gridinsoft Anti-Malware