Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

6.3.9600.16384 (winblue_rtm.130821-1623) 0.36%
6.3.9600.16384 (winblue_rtm.130821-1623) 0.12%
6.2.9200.16384 (win8_rtm.120725-1247) 0.95%
6.2.9200.16384 (win8_rtm.120725-1247) 4.04%
6.1.7600.16385 (win7_rtm.090713-1255) 16.88%
6.1.7600.16385 (win7_rtm.090713-1255) 12.13%
6.1.7600.16385 (win7_rtm.090713-1255) 5.11%
6.1.7600.16385 (win7_rtm.090713-1255) 1.43%
6.0.6000.16386 (vista_rtm.061101-2205) 2.02%
6.0.6000.16386 (vista_rtm.061101-2205) 0.83%
6.0.6000.16386 (vista_rtm.061101-2205) 14.03%
6.0.6000.16386 (vista_rtm.061101-2205) 0.36%
6.0.6000.16386 (vista_rtm.061101-2205) 0.71%
6.0.6000.16386 (vista_rtm.061101-2205) 0.12%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 0.24%
5.1.2600.5512 (xpsp.080413-0852) 24.97%
5.1.2600.5512 (xpsp.080413-0852) 1.90%
5.1.2600.5512 (xpsp.080413-0852) 1.43%
5.1.2600.5512 (xpsp.080413-0852) 0.24%
5.1.2600.5512 (xpsp.080413-0852) 1.19%
5.1.2600.5512 (xpsp.080413-0852) 0.12%
5.1.2600.5512 (xpsp.080413-0852) 0.12%
5.1.2600.5512 (xpsp.080413-0852) 0.95%
5.1.2600.5512 (xpsp.080413-0852) 0.24%
5.1.2600.5512 (xpsp.080413-0852) 0.12%
View more

PE structurePE file structure

Show functions
Import table
advapi32.dll
RegQueryValueExA, RegOpenKeyExA, LsaClose, LsaFreeMemory, LsaRetrievePrivateData, LsaNtStatusToWinError, LsaOpenPolicy, LsaStorePrivateData, LookupAccountSidA, CredWriteA, RegEnumKeyExW, CopySid, GetTokenInformation, CredDeleteA, CheckTokenMembership, AllocateAndInitializeSid, FreeSid, RegisterServiceCtrlHandlerExA, SetServiceStatus, OpenThreadToken, RevertToSelf, EqualSid, ConvertStringSecurityDescriptorToSecurityDescriptorW, OpenSCManagerW, OpenServiceA, QueryServiceStatus, CloseServiceHandle, RegDeleteKeyW, RegCreateKeyExW, RegDeleteValueW, CreateProcessAsUserW, RegOpenKeyExW, RegSetValueExW, RegOpenKeyW, RegQueryInfoKeyW, RegQueryValueExW, SetThreadToken, OpenProcessToken, DuplicateToken, RegDeleteValueA, GetSidLengthRequired, InitializeSid, GetSidSubAuthority, GetLengthSid, InitializeAcl, AddAccessAllowedAce, InitializeSecurityDescriptor, SetSecurityDescriptorDacl, SetSecurityDescriptorOwner, SetSecurityDescriptorGroup, RegCloseKey
crypt32.dll
CertFindChainInStore, CertCloseStore, CertOpenStore, CryptProtectData, CryptUnprotectData, CertEnumCertificatesInStore, CertFreeCertificateContext
cryptdll.dll
MD5Final, MD5Update, MD5Init
devobj.dll
DevObjOpenClassRegKey
eappprxy.dll
EapHostPeerInitialize, EapHostPeerUninitialize
fwpuclnt.dll
WfpFillIpsecProposal, FwpmEngineClose0, WfpFilterListIpsecTransportV6Create, WfpClearIpsecProposal, FwpmFilterAdd0, WfpFillIkeProposal, FwpmEngineOpen0, FwpmTransactionBegin0, IPsecSaDestroyEnumHandle0, IPsecSaEnum0, IPsecSaCreateEnumHandle0, FwpmTransactionAbort0, FwpmTransactionCommit0, WfpFilterListDestroy, FwpmProviderContextAdd0, FwpmProviderContextDeleteByKey0, FwpmFilterDeleteByKey0, FwpmFreeMemory0, WfpGetV4TransportSaSelectors, IPsecSaInitiateAsync0, WfpFilterListIpsecTransportV4Create
gdi32.dll
DeviceCapabilitiesExA
iphlpapi.dll
ConvertInterfaceLuidToIndex, GetSessionCompartmentId, ConvertGuidToStringW, SetSessionCompartmentId, GetAdaptersAddresses, ConvertInterfaceLuidToGuid, ConvertInterfaceIndexToLuid
kernel32.dll
ExpandEnvironmentStringsA, GetOverlappedResult, GetQueuedCompletionStatus, GetTickCount, lstrlenW, QueueUserWorkItem, GetExitCodeProcess, Sleep, QueueUserAPC, InterlockedCompareExchange, QueryPerformanceCounter, GetCurrentThreadId, GetSystemTimeAsFileTime, TerminateProcess, UnhandledExceptionFilter, SetUnhandledExceptionFilter, CreateIoCompletionPort, SetConsoleCtrlHandler, DeleteCriticalSection, InterlockedExchange, GetProcessHeap, HeapAlloc, DeviceIoControl, EnterCriticalSection, LeaveCriticalSection, LoadLibraryA, GetProcAddress, FreeLibrary, PostQueuedCompletionStatus, DisableThreadLibraryCalls, LocalAlloc, LocalFree, SetEvent, GetCurrentProcessId, GetCurrentProcess, OpenProcess, DuplicateHandle, CloseHandle, GetLastError, GetCurrentThread, GetModuleHandleA, HeapFree, WideCharToMultiByte, GetSystemDirectoryW, SetLastError, CreateFileW, LoadLibraryW, GlobalAlloc, GlobalFree, lstrcmpiW, MultiByteToWideChar, InitializeCriticalSection, CreateFileA, CreateEventA, InterlockedIncrement, InterlockedDecrement, PowerCreateRequest, GetModuleHandleExA, CreateThread, WaitForSingleObject, RegDeleteKeyExW, RegEnumKeyExW, RegCreateKeyExW, LoadLibraryExA, DelayLoadFailureHook, PowerSetRequest, PowerClearRequest, WaitForMultipleObjectsEx, FreeLibraryAndExitThread, ProcessIdToSessionId, ResetEvent, ReleaseSemaphore
msvcrt.dll
DllMain
nsi.dll
NsiSetAllParameters, NsiFreeTable, NsiAllocateAndGetTable, NsiGetParameter, NsiGetAllParametersEx, NsiEnumerateObjectsAllParametersEx, NsiSetAllParametersEx, NsiGetParameterEx
ntdll.dll
RtlAnsiStringToUnicodeString, RtlIpv6StringToAddressA, NtQueryInformationProcess, RtlIpv4StringToAddressW, RtlIpv6StringToAddressW, RtlQueueWorkItem, NtSetInformationThread, RtlInitString, RtlInitUnicodeString, DbgPrint, RtlIpv6AddressToStringA, NtClose, NtOpenThreadToken, RtlConvertSidToUnicodeString, RtlNtStatusToDosError, RtlInitAnsiString, EtwGetTraceEnableFlags, EtwGetTraceEnableLevel, EtwGetTraceLoggerHandle, RtlInitializeSid, RtlLengthRequiredSid, EtwTraceMessage, RtlSetDaclSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAbsoluteToSelfRelativeSD, RtlCreateAcl, WinSqmSetDWORD, WinSqmAddToStream, EtwRegisterTraceGuidsW, EtwUnregisterTraceGuids, RtlIpv4AddressToStringA
ole32.dll
CoUninitialize, CoInitializeEx, CoCreateInstance
rpcrt4.dll
RpcImpersonateClient, RpcRevertToSelf, RpcServerInqCallAttributesW, RpcServerUseProtseqEpW, RpcServerRegisterIfEx, I_RpcExceptionFilter, UuidCreate, UuidIsNil, NdrServerCall2, RpcServerRegisterAuthInfoW, I_RpcMapWin32Status, RpcServerUnregisterIf, RpcStringFreeW, RpcServerInqDefaultPrincNameW, I_RpcBindingIsClientLocal, RpcStringFreeA, UuidToStringA
rtutils.dll
TraceRegisterExA, RouterLogDeregisterA, RouterLogRegisterA, RouterLogEventA, RouterLogEventStringW, RouterLogEventStringA, TraceDeregisterA, TraceVprintfExA, RouterLogEventW, TracePrintfExA, RouterLogDeregisterW, RouterLogRegisterW
secur32.dll
LsaCallAuthenticationPackage, LsaRegisterLogonProcess, LsaLookupAuthenticationPackage, LsaDeregisterLogonProcess, LsaFreeReturnBuffer
sens.dll
SensNotifyRasEvent
setupapi.dll
SetupDiOpenClassRegKey
slc.dll
SLGetWindowsInformationDWORD
user32.dll
CharNextW, CharPrevW
userenv.dll
CreateEnvironmentBlock, DestroyEnvironmentBlock
winnsi.dll
NsiRpcDeregisterChangeNotification, NsiDisconnectFromServer, NsiConnectToServer, NsiRpcRegisterChangeNotification
wtsapi32.dll
WTSQueryUserToken, WTSQuerySessionInformationA, WTSFreeMemory
Export table
_RasmanEngine
_RasmanInit
ServiceMain
ServiceRequestInProcess
SetEntryDialParams

rasmans.dll

Remote Access Connection Manager by Microsoft

Remove rasmans.dll
Version:   6.1.7600.16385 (win7_rtm.090713-1255)
MD5:   cb9e04dc05eacf5b9a36ca276d475006
SHA1:   920920eaa845d13b6cd33e8c208d158b49a0b68c
SHA256:   4d8c0aef1d4f84f375ad2baf786c9f6c52316a3e655b913449e71ad7c0fca56e
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

rasmans.dll is loaded as dynamic link library that runs in the context of a process. The assembly utilizes the .NET run-time framework (which is required to be installed on the PC). This version is designed to run on Windows 7.

DetailsDetails

File name:rasmans.dll
Publisher:Microsoft Corporation
Product name:Remote Access Connection Manager
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\rasmans.dll
Original name:Rasmans.dll.mui
File version:6.1.7600.16385 (win7_rtm.090713-1255)
Product version:6.1.7600.16385
Size:279.5 KB (286,208 bytes)
Digital DNA
PE subsystem:Windows GUI
File packed:No
Code language:Microsoft Visual C# / Basic .NET
.NET CLR:Yes
.NET NGENed:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'
  • Shared name is 'RasMan'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Windows 7 Home Premium 43.00%
Windows 7 Ultimate 31.50%
Windows 7 Professional 10.50%
Windows Vista Home Premium 6.00%
Windows 7 Home Basic 4.50%
Windows 7 Starter 1.50%
Windows Vista Ultimate 1.50%
Windows Vista Business 0.50%
Windows Vista™ Home Premium 0.50%
Windows 7 Ultimate N 0.50%

Distribution by countryDistribution by country

United States installs about 29.23% of Remote Access Connection Manager.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Hewlett-Packard 23.41%
Dell 20.49%
Acer 17.56%
Toshiba 12.68%
Lenovo 6.83%
ASUS 5.85%
Gateway 3.90%
Sony 2.93%
Intel 1.95%
Samsung 1.46%
GIGABYTE 0.98%
American Megatrends 0.98%
Medion 0.98%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE