Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 90.91%
6.3.9600.16384 (winblue_rtm.130821-1623) 2.60%
6.3.9431.0 (winmain_bluemp.130615-1214) 5.19%
6.3.9431.0 (winmain_bluemp.130615-1214) 1.30%

Relationships


PE structurePE file structure

Show functions
Import table
api-ms-win-core-com-l1-1-1.dll
CoTaskMemAlloc, CoUninitialize, CoInitializeEx, CoCreateInstance, CoTaskMemFree, CoTaskMemRealloc
api-ms-win-core-debug-l1-1-1.dll
OutputDebugStringA
api-ms-win-core-delayload-l1-1-1.dll
DelayLoadFailureHook, ResolveDelayLoadedAPI
api-ms-win-core-errorhandling-l1-1-1.dll
UnhandledExceptionFilter, SetLastError, SetUnhandledExceptionFilter, RaiseException, GetLastError
api-ms-win-core-handle-l1-1-0.dll
CloseHandle
api-ms-win-core-heap-l1-2-0.dll
GetProcessHeap, HeapAlloc, HeapFree
api-ms-win-core-heap-obsolete-l1-1-0.dll
LocalFree
api-ms-win-core-kernel32-legacy-l1-1-1.dll
WTSGetActiveConsoleSessionId
api-ms-win-core-libraryloader-l1-1-1.dll
GetModuleHandleW, LoadResource, GetProcAddress, FreeLibrary, LoadLibraryExW, FindResourceExW, SizeofResource, DisableThreadLibraryCalls, GetModuleFileNameW
api-ms-win-core-libraryloader-l1-2-0.dll
GetModuleFileNameW, SizeofResource, GetModuleHandleW, GetProcAddress, DisableThreadLibraryCalls, LoadLibraryExW, LoadResource, FreeLibrary, FindResourceExW
api-ms-win-core-processthreads-l1-1-2.dll
GetProcessId, SetThreadToken, GetCurrentThreadId, GetCurrentProcessId, TerminateProcess, OpenProcessToken, ProcessIdToSessionId, OpenThreadToken, GetCurrentProcess, GetCurrentThread
api-ms-win-core-profile-l1-1-0.dll
QueryPerformanceCounter
api-ms-win-core-registry-l1-1-0.dll
RegDeleteValueW, RegDeleteTreeW, RegDeleteKeyExW, RegCloseKey, RegOpenKeyExW, RegCreateKeyExW, RegEnumKeyExW, RegSetValueExW, RegQueryInfoKeyW, RegQueryValueExW
api-ms-win-core-string-l1-1-0.dll
MultiByteToWideChar
api-ms-win-core-string-l2-1-0.dll
CharNextW
api-ms-win-core-string-obsolete-l1-1-0.dll
lstrcmpiW
api-ms-win-core-synch-l1-2-0.dll
ResetEvent, CreateEventW, SetEvent, WaitForSingleObject, InitializeCriticalSection, EnterCriticalSection, LeaveCriticalSection, Sleep, DeleteCriticalSection
api-ms-win-core-sysinfo-l1-2-1.dll
GetTickCount, GetSystemTimeAsFileTime, GetTickCount64
api-ms-win-core-threadpool-l1-2-0.dll
TrySubmitThreadpoolCallback
api-ms-win-core-threadpool-legacy-l1-1-0.dll
UnregisterWaitEx
api-ms-win-core-threadpool-private-l1-1-0.dll
RegisterWaitForSingleObjectEx
api-ms-win-eventing-provider-l1-1-0.dll
EventWrite, EventRegister, EventUnregister
api-ms-win-power-setting-l1-1-0.dll
PowerSettingUnregisterNotification, PowerSettingRegisterNotification
api-ms-win-security-base-l1-2-0.dll
GetLengthSid, DuplicateTokenEx, CopySid, IsValidSid, GetTokenInformation, AccessCheck
api-ms-win-security-sddl-l1-1-0.dll
ConvertSidToStringSidW, ConvertStringSecurityDescriptorToSecurityDescriptorW
api-ms-win-service-core-l1-1-1.dll
RegisterServiceCtrlHandlerExW, SetServiceStatus
brokerlib.dll
BrInitializeBrokerInstance, BrSignalBrokerEvent, BrQueryBrokeredEvents, BrUnregisterBrokeredEvent, BrRegisterBrokeredEvent, BrCheckCallerIsAppContainer, BrFindBrokeredEvent, BrCreateBrokeredEvent, BrDeleteBrokeredEvent, BrCheckCallerCapabilities, BrDeleteBrokerInstance, BrBufferFree, BrLockBroker, BrGetBrokeredAppState, BrUnlockBroker, BrCreateBrokerInstance
iphlpapi.dll
InternalGetRtcSlotInformation
msvcrt.dll
DllMain
nsi.dll
NsiSetAllParameters, NsiGetAllParameters
ntdll.dll
RtlNtStatusToDosError, WinSqmAddToStreamEx, RtlLengthSid, RtlCompareMemory, RtlUnsubscribeWnfNotificationWaitForCompletion, RtlSubscribeWnfStateChangeNotification, RtlAllocateWnfSerializationGroup, RtlCopySid, RtlFreeSid, NtQueryWnfStateData, RtlRemoveEntryHashTable, RtlInsertEntryHashTable, RtlDeleteHashTable, RtlGetNextEntryHashTable, NtPowerInformation, RtlInitUnicodeString, RtlInitEnumerationHashTable, RtlEndEnumerationHashTable, RtlEnumerateEntryHashTable, RtlLookupEntryHashTable, RtlCreateHashTable, RtlQueryPackageIdentity, RtlEqualSid, RtlGetVersion
rpcrt4.dll
RpcBindingVectorFree, RpcServerInqBindings, RpcServerUnregisterIfEx, RpcServerUseProtseqW, I_RpcOpenClientProcess, NdrServerCall2, RpcServerRegisterIf3, RpcRevertToSelf, RpcBindingSetAuthInfoW, RpcBindingFree, RpcStringBindingComposeW, RpcBindingFromStringBindingW, NdrClientCall2, NdrAsyncClientCall, RpcAsyncInitializeHandle, RpcEpUnregister, I_RpcExceptionFilter, RpcAsyncCancelCall, NdrAsyncServerCall, RpcServerRegisterIfEx, RpcAsyncCompleteCall, RpcEpRegisterW, RpcSsContextLockExclusive, RpcStringFreeW, RpcImpersonateClient
ws2_32.dll
WSAIoctl
Export table
ServiceMain
SvchostPushServiceGlobals

ncbservice.dll

Network Connection Broker by Microsoft

Remove ncbservice.dll
Version:   6.3.9431.0 (winmain_bluemp.130615-1214)
MD5:   3e0122b5de71e4a8dd0263869e0853fd
SHA1:   0b82fe9a323e6a6d770f26f508ee7d71422659e6
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

ncbservice.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). .

DetailsDetails

File name:ncbservice.dll
Publisher:Microsoft Corporation
Product name:Network Connection Broker
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\ncbservice.dll
Original name:ncbservice.dll.mui
File version:6.3.9431.0 (winmain_bluemp.130615-1214)
Product version:6.3.9431.0
Size:119.5 KB (122,368 bytes)
Build date:6/15/2013 3:02 PM
Digital DNA
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'
  • Shared name is 'NcbService'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 8.1 51.32%
Windows 8.1 Pro 25.00%
Windows 8.1 Single Language 10.53%
Windows 8.1 Pro with Media Center 3.95%
Windows 8.1 Pro Preview 3.95%
Windows 8.1 N 1.32%
Windows 8.1 Enterprise Evaluation 1.32%
Windows 8.1 Single Language Preview 1.32%
Windows 8.1 Pro Preview with Media Center 1.32%

Distribution by countryDistribution by country

United States installs about 38.16% of Network Connection Broker.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
ASUS 22.45%
Lenovo 18.37%
Hewlett-Packard 15.31%
Dell 14.29%
Acer 12.24%
Toshiba 6.12%
Sony 6.12%
Alienware 2.04%
Medion 2.04%
Samsung 1.02%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE