Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.1.7600.16385 (win7_rtm.090713-1255) 55.75%
6.1.7600.16385 (win7_rtm.090713-1255) 40.27%
6.1.7600.16385 (win7_rtm.090713-1255) 0.09%
6.0.6000.16386 (vista_rtm.061101-2205) 1.86%
6.0.6000.16386 (vista_rtm.061101-2205) 0.62%
5.1.2600.5512 (xpsp.080413-0852) 1.06%
5.1.2600.5512 (xpsp.080413-0852) 0.18%
5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) 0.18%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
RegCloseKey, RegDeleteKeyW, RegQueryInfoKeyW, RegQueryValueExW, RegCreateKeyExW, RegOpenKeyExW, RegSetValueExW, AdjustTokenPrivileges, OpenProcessToken, RegEnumKeyExW, GetTokenInformation, EqualSid, RegDeleteValueW, OpenThreadToken, SetServiceStatus, RegisterServiceCtrlHandlerExW, CheckTokenMembership, ConvertStringSidToSidW, RegNotifyChangeKeyValue, DuplicateTokenEx, CloseServiceHandle, QueryServiceStatus, OpenServiceW, OpenSCManagerW, RegGetValueW, RegEnumValueW, UnlockServiceDatabase, LockServiceDatabase, DuplicateToken, FreeSid, AllocateAndInitializeSid, InitiateSystemShutdownExW, WmiNotificationRegistrationW
api-ms-win-core-console-l1-1-0.dll
GetConsoleMode, GetConsoleCP, WriteConsoleW, GetConsoleOutputCP, WriteConsoleA
api-ms-win-core-debug-l1-1-0.dll
OutputDebugStringA
api-ms-win-core-errorhandling-l1-1-0.dll
SetUnhandledExceptionFilter, GetLastError, UnhandledExceptionFilter, SetLastError, RaiseException
api-ms-win-core-file-l1-1-0.dll
FlushFileBuffers, SetFilePointer, WriteFile, CreateFileA, CreateFileW, GetFileType
api-ms-win-core-handle-l1-1-0.dll
CloseHandle, DuplicateHandle
api-ms-win-core-heap-l1-1-0.dll
HeapCreate, HeapSize, GetProcessHeap, HeapDestroy, HeapFree, HeapAlloc, HeapReAlloc
api-ms-win-core-interlocked-l1-1-0.dll
InterlockedExchange, InterlockedCompareExchange, InterlockedIncrement, InterlockedDecrement
api-ms-win-core-io-l1-1-0.dll
DeviceIoControl
api-ms-win-core-libraryloader-l1-1-0.dll
LockResource, GetModuleFileNameA, GetModuleHandleA, GetModuleFileNameW, LoadLibraryExW, LoadResource, SizeofResource, LoadLibraryExA, FreeLibrary, GetModuleHandleW, GetProcAddress, DisableThreadLibraryCalls
api-ms-win-core-localization-l1-1-0.dll
GetSystemDefaultLCID, GetOEMCP, GetACP, GetCPInfo, LCMapStringW
api-ms-win-core-memory-l1-1-0.dll
VirtualAlloc, VirtualFree, VirtualProtect, VirtualQuery
api-ms-win-core-misc-l1-1-0.dll
LocalAlloc, SetHandleCount, lstrlenW, lstrcmpiW, lstrcpynW, lstrlenA, Sleep, LocalFree, lstrcmpW, LCMapStringA
api-ms-win-core-processenvironment-l1-1-0.dll
FreeEnvironmentStringsA, ExpandEnvironmentStringsW, SetStdHandle, GetEnvironmentStringsW, GetCommandLineA, GetStdHandle, GetEnvironmentStrings, FreeEnvironmentStringsW
api-ms-win-core-processthreads-l1-1-0.dll
CreateProcessW, TerminateProcess, GetCurrentProcessId, GetCurrentThread, GetCurrentThreadId, OpenProcessToken, GetCurrentProcess, OpenThreadToken, TlsFree, ExitProcess, TlsGetValue, TlsAlloc, TlsSetValue
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-string-l1-1-0.dll
WideCharToMultiByte, MultiByteToWideChar, GetStringTypeW, CompareStringW
api-ms-win-core-synch-l1-1-0.dll
TryEnterCriticalSection, ResetEvent, DeleteCriticalSection, SetEvent, EnterCriticalSection, LeaveCriticalSection, InitializeCriticalSection, OpenEventW, WaitForSingleObject, CreateEventW
api-ms-win-core-sysinfo-l1-1-0.dll
GetVersionExA, GetTickCount, GetSystemTimeAsFileTime, GetSystemInfo, GetVersionExW
kernel32.dll
UnregisterWaitEx, DelayLoadFailureHook, FindResourceW, RegNotifyChangeKeyValue, RegEnumValueW, RegDeleteKeyExW, RegGetValueW, GetStartupInfoA, QueueUserWorkItem, GetPrivateProfileStringW, RegCloseKey, LoadLibraryW, RegQueryInfoKeyW, RegQueryValueExW, RegCreateKeyExW, RegOpenKeyExW, RegSetValueExW, RegEnumKeyExW, RegDeleteValueW, LeaveCriticalSection, DisableThreadLibraryCalls, GetVersionExW, VirtualProtect, VirtualAlloc, GetSystemInfo, VirtualQuery, lstrlenW, RaiseException, InitializeCriticalSection, DeleteCriticalSection, InterlockedIncrement, InterlockedDecrement, HeapFree, HeapAlloc, HeapReAlloc, lstrcmpiW, MultiByteToWideChar, WideCharToMultiByte, GetCurrentThreadId, GetLastError, CloseHandle, GetCurrentProcess, WaitForSingleObject, HeapDestroy, lstrcpynW, FreeLibrary, lstrlenA, SizeofResource, LoadResource, LoadLibraryExW, CreateFileW, GetModuleFileNameW, GetModuleHandleW, GetCurrentThread, CreateEventW, OpenEventW, OutputDebugStringA, CreateThread, SetEvent, GetProcAddress, InterlockedCompareExchange, LoadLibraryA, Sleep, LocalFree, lstrcmpW, InterlockedExchange, DuplicateHandle, TryEnterCriticalSection, ResetEvent, HeapCreate, GetCommandLineA, GetVersionExA, RtlUnwind, GetModuleHandleA, ExitProcess, TlsGetValue, TlsAlloc, TlsSetValue, TlsFree, SetLastError, SetHandleCount, GetStdHandle, GetFileType, GetModuleFileNameA, FreeEnvironmentStringsA, GetEnvironmentStrings, EnterCriticalSection, GetEnvironmentStringsW, VirtualFree, QueryPerformanceCounter, GetTickCount, GetCurrentProcessId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, GetCPInfo, GetACP, GetOEMCP, HeapSize, WriteFile, SetFilePointer, GetConsoleCP, GetConsoleMode, LCMapStringA, LCMapStringW, GetStringTypeA, GetStringTypeW, GetLocaleInfoA, SetStdHandle, WriteConsoleA, GetConsoleOutputCP, WriteConsoleW, CreateFileA, FlushFileBuffers, CompareStringW, LocalAlloc, GetSystemDefaultLCID, DeviceIoControl, LockResource, GetProcessHeap, CreateProcessW, ExpandEnvironmentStringsW, FreeEnvironmentStringsW
kernelbase.dll
GetStringTypeA, GetLocaleInfoA
nsi.dll
NsiGetParameter
ntdll.dll
RtlRegisterWait, NtClose, RtlOpenCurrentUser, RtlUnwind, RtlDeregisterWaitEx, RtlNtStatusToDosError, NtOpenFile, RtlGetNtProductType, RtlInitUnicodeString
ole32.dll
StringFromGUID2, CoTaskMemFree, CoTaskMemAlloc, CoRevokeClassObject, CoRegisterClassObject, CoTaskMemRealloc, CoImpersonateClient, CoRevertToSelf, CLSIDFromString, CoSetProxyBlanket, IIDFromString, CoInitializeEx, CoUninitialize, CoCreateInstance
rasapi32.dll
DwCloneEntry, RasSetAutodialAddressW, RasValidateEntryNameW, RasHangUpW, RasGetEntryPropertiesW, RasRenameEntryW, RasEnumConnectionsW, DwEnumEntryDetails, RasGetConnectStatusW, RasDeleteEntryW
user32.dll
MessageBoxW, LoadImageW, DestroyIcon, UnregisterDeviceNotification, CharNextW, PeekMessageW, DispatchMessageW, MsgWaitForMultipleObjects, RegisterDeviceNotificationW
winnsi.dll
NsiRpcRegisterChangeNotification, NsiRpcDeregisterChangeNotification, NsiDisconnectFromServer, NsiConnectToServer
Export table
DllRegisterServer
DllUnregisterServer
HrGetPnpDeviceStatus
HrLanConnectionNameFromGuidOrPath
HrPnpInstanceIdFromGuid
HrQueryLanMediaState
NetManDiagFromCommandArgs
ProcessQueue
ServiceMain
SvchostPushServiceGlobals

netman.dll

Network Connections Manager by Microsoft

Remove netman.dll
Version:   5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
MD5:   25128473f0d3fd431f74cc5bafa123ca
SHA1:   b4b81389a55ac8fb424ba2b43f7f7c02f59eeb2a
SHA256:   fb64e5848f7cdb010ac99637f8798a8f8f3492c7cc8ba778d12024c5b16a1a0f
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

netman.dll is loaded as dynamic link library that runs in the context of a process. This will ad a run once registry key upon installation for all user profiles of the PC that will cause the file to be executed the first time any user logs in. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is installed on Windows XP.

DetailsDetails

File name:netman.dll
Publisher:Microsoft Corporation
Product name:Network Connections Manager
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\netman.dll
Original name:netman.dll.mui
File version:5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Product version:5.1.2600.2180
Size:193.5 KB (198,144 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
  • Shared name is 'Netman'
Startup files (all users) run once
Runs under the registry key 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce'
  • 'NCInstallQueue' → rundll32 netman.dll,ProcessQueue

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 57.50%
Windows 7 Ultimate 26.50%
Windows 7 Professional 10.00%
Windows 7 Home Basic 2.50%
Windows 7 Starter 1.50%
Windows Seven Black Edition 0.50%
Windows 7 Enterprise 0.50%
Windows Se7en Titan 0.50%
Windows Vista Business 0.50%

Distribution by countryDistribution by country

United States installs about 43.65% of Network Connections Manager.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 25.64%
ASUS 16.12%
Hewlett-Packard 15.75%
Acer 13.55%
Toshiba 11.72%
Lenovo 4.40%
Sony 2.93%
Samsung 2.20%
Intel 2.20%
GIGABYTE 1.83%
Alienware 0.73%
Medion 0.73%
Gateway 0.73%
MSI 0.73%
NEC 0.73%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE