Should I block it?

No, this file is 100% safe to run.

VersionsAdditional versions

5.2.3790.4455 (srv03_sp2_gdr.090203-1205) 12.50%
5.2.3790.3959 (srv03_sp2_rtm.070216-1710) 12.50%
5.1.2600.5755 (xpsp_sp3_gdr.090206-1234) 37.50%
5.1.2600.5755 (xpsp_sp3_gdr.090206-1234) 12.50%
5.1.2600.5755 (xpsp_sp3_gdr.090206-1234) 12.50%
5.1.2600.5755 (xpsp_sp3_gdr.090206-1234) 12.50%

Relationships


PE structurePE file structure

Show functions
Import table
advapi32.dll
ControlService, SetTokenInformation, ImpersonateLoggedOnUser, CreateProcessAsUserW, StartServiceW, ConvertSidToStringSidW, QueryServiceStatus, DuplicateTokenEx, RegSetValueExW, LsaRetrievePrivateData, LookupAccountNameW, AccessCheck, GetSecurityDescriptorLength, RegCreateKeyExW, ConvertStringSecurityDescriptorToSecurityDescriptorW, QueryServiceStatusEx, SaferCreateLevel, SaferComputeTokenFromLevel, SaferCloseLevel, CommandLineFromMsiDescriptor, IsValidSecurityDescriptor, LookupAccountSidW, FreeSid, AllocateAndInitializeSid, SetSecurityDescriptorDacl, InitializeSecurityDescriptor, AddAccessAllowedAce, InitializeAcl, GetLengthSid, RegCloseKey, RegQueryValueExW, RegOpenKeyExW, CloseServiceHandle, OpenServiceW, OpenSCManagerW, AllocateLocallyUniqueId, SetServiceStatus, RegQueryValueA, RegisterServiceCtrlHandlerExW, RegisterEventSourceW, ReportEventW, DeregisterEventSource, IsValidSid, GetSidIdentifierAuthority, GetSidSubAuthorityCount, GetSidSubAuthority, GetSecurityDescriptorDacl, GetAce, RegOpenKeyW, RegQueryValueW, CryptAcquireContextW, CryptReleaseContext, SystemFunction036, CryptGenRandom, RegNotifyChangeKeyValue, RegQueryInfoKeyW, RegEnumValueW, ImpersonateAnonymousToken, OpenThreadToken, RevertToSelf, RegOpenUserClassesRoot, SaferiCompareTokenLevels, CheckTokenMembership, CopySid, SetThreadToken, CreateWellKnownSid, LsaOpenPolicy, LsaQueryInformationPolicy, LsaClose, EqualSid, GetTokenInformation, OpenProcessToken, ChangeServiceConfigW, LsaFreeMemory
kernel32.dll
DisableThreadLibraryCalls, SetUnhandledExceptionFilter, UnhandledExceptionFilter, GetCurrentProcess, TerminateProcess, GetCurrentProcessId, GetCurrentThreadId, GetTickCount, LoadLibraryA, InterlockedCompareExchange, FreeLibrary, GetProcAddress, TlsAlloc, LocalAlloc, CreateEventA, LocalFree, Sleep, GetComputerNameA, QueryPerformanceCounter, GlobalMemoryStatus, GetDiskFreeSpaceA, InterlockedExchange, EnterCriticalSection, LeaveCriticalSection, GetComputerNameW, GetLastError, lstrcmpW, GetProcessHeap, HeapAlloc, HeapFree, GetDriveTypeW, lstrcpynW, MultiByteToWideChar, lstrlenA, GetExitCodeProcess, WaitForMultipleObjects, CreateMutexW, UnmapViewOfFile, MapViewOfFile, CreateFileMappingW, ResumeThread, OpenFileMappingW, CreateProcessW, ReadFile, ReleaseActCtx, WriteFile, WaitNamedPipeW, InitializeCriticalSectionAndSpinCount, lstrcmpiA, MapViewOfFileEx, VirtualAlloc, VirtualFree, GetSystemTimeAsFileTime, DelayLoadFailureHook, SetLastError, CloseHandle, DeviceIoControl, CreateFileW, SleepEx, InterlockedIncrement, InterlockedDecrement, CreateThread, GetSystemInfo, lstrcpyW, lstrlenW, RegisterWaitForSingleObject, CreateEventW, SetEvent, WaitForSingleObject, lstrcatW, TerminateJobObject, GetCurrentThread, InterlockedExchangeAdd, DeleteTimerQueueTimer, CreateTimerQueueTimer, DeleteCriticalSection, IsDebuggerPresent, DebugBreak, ResetEvent, TlsSetValue, TlsGetValue, GetModuleHandleW, LoadLibraryExA, ExpandEnvironmentStringsW, GetModuleFileNameW, ReleaseMutex, FindActCtxSectionGuid, FindActCtxSectionStringW, LoadLibraryW, GetSystemDirectoryW, GetSystemWow64DirectoryW, lstrcmpiW, SearchPathW, AddRefActCtx, OpenProcess, DuplicateHandle, InitializeCriticalSection, OpenEventW, LoadLibraryExW, FindClose, FindFirstFileW
msvcrt.dll
DllMain
ntdll.dll
RtlAllocateHeap, RtlFreeHeap, RtlImageNtHeader, RtlNtStatusToDosError, NtOpenFile, RtlInitString, RtlDeleteCriticalSection, RtlEqualSid, NtCompareTokens, NtQueryInformationToken, DbgPrint, NtQuerySystemInformation, NtOpenSection, NtFsControlFile, NtCreateFile, RtlAdjustPrivilege, NtSetInformationProcess, NtDuplicateToken, NtAllocateLocallyUniqueId, RtlInitUnicodeString, RtlEqualUnicodeString, NtSetUuidSeed, RtlSetSaclSecurityDescriptor, RtlSetDaclSecurityDescriptor, RtlSetGroupSecurityDescriptor, RtlSetOwnerSecurityDescriptor, RtlCreateSecurityDescriptor, RtlAddAce, RtlCreateAcl, RtlGetNtProductType, RtlInitializeCriticalSection, RtlLengthRequiredSid, RtlInitializeSid, RtlSubAuthoritySid, RtlAllocateAndInitializeSid, NtClose, NtOpenKey, RtlLengthSid, RtlCopySid
rpcrt4.dll
RpcServerRegisterIf2, RpcMgmtSetServerStackSize, UuidCreate, RpcServerListen, RpcMgmtIsServerListening, I_RpcAllocate, I_RpcFree, RpcServerUseProtseqEpExW, RpcBindingFree, RpcBindingSetAuthInfoW, RpcBindingSetAuthInfoExW, NdrAsyncServerCall, NdrAsyncClientCall, MesEncodeFixedBufferHandleCreate, MesHandleFree, MesDecodeBufferHandleCreate, NdrMesTypeAlignSize2, NdrMesTypeEncode2, NdrMesTypeDecode2, RpcRevertToSelfEx, RpcImpersonateClient, RpcRaiseException, I_RpcBindingInqTransportType, RpcAsyncCompleteCall, RpcBindingSetOption, I_RpcBindingInqWireIdForSnego, RpcServerUnregisterIf, I_RpcServerInqLocalConnAddress, I_RpcServerCheckClientRestriction, TowerExplode, I_RpcSystemFunction001, RpcServerRegisterIfEx, I_RpcServerRegisterForwardFunction, I_RpcServerSetAddressChangeFn, I_RpcExceptionFilter, NdrClientCall2, NdrServerCall2, RpcStringBindingComposeW, RpcMgmtEnableIdleCleanup, I_RpcBindingInqLocalClientPID, RpcRevertToSelf, RpcBindingReset, RpcAsyncCancelCall, RpcBindingFromStringBindingW, RpcBindingSetObject, RpcAsyncInitializeHandle, RpcBindingCopy, RpcServerInqBindings, RpcBindingVectorFree, RpcStringFreeW, RpcBindingToStringBindingW, RpcStringBindingParseW, RpcServerRegisterAuthInfoW
secur32.dll
FreeContextBuffer, LsaLogonUser, LsaLookupAuthenticationPackage, LsaRegisterLogonProcess, LsaFreeReturnBuffer, EnumerateSecurityPackagesW
user32.dll
wsprintfW, LoadStringW, CharUpperW
ws2_32.dll
WSAIoctl, WSASetServiceW
Export table
CoGetComCatalog
GetRPCSSInfo
ServiceMain
WhichService

rpcss.dll

Distributed COM Services by Microsoft

Remove rpcss.dll
Version:   5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)
MD5:   f3763e01e7536f7a6d0c6e392c603ec2
SHA1:   b705ce840954bfe00a336c14e556a85be353f839
SHA256:   1eb70d107eeb320cf02f0f3bbadba966c1beb1da4414870525cc397a329bb427
This is a Windows system installed file with Windows File Protection (WFP) enabled.

Overview

rpcss.dll is loaded as dynamic link library that runs in the context of a process. This version is installed on Windows XP.

DetailsDetails

File name:rpcss.dll
Publisher:Microsoft Corporation
Product name:Distributed COM Services
Description:Microsoft® Windows® Operating System
Typical file path:C:\Windows\System32\rpcss.dll
File version:5.1.2600.5755 (xpsp_sp3_gdr.090206-1234)
Product version:5.1.2600.5755
Size:392 KB (401,408 bytes)
Digital DNA
PE subsystem:Windows Console
File packed:No
Code language:Microsoft Visual C++
.NET CLR:No
More details

BehaviorsBehaviors

Hosted services
Runs as a shared service under the Windows svcHost
  • Shared name is 'RpcSs'
  • Shared name is 'DcomLaunch'
  • Shared name is 'DcomLaunch'
  • Shared name is 'RpcSs'
  • Shared name is 'RpcSs'
  • Shared name is 'RpcSs'
  • Shared name is 'RpcSs'
  • Shared name is 'RpcSs'

Windows OS versionsDistribution by Windows OS

OS versiondistribution
Microsoft Windows XP 100.00%

Distribution by countryDistribution by country

United States installs about 37.50% of Distributed COM Services.

OEM distributionDistribution by PC manufacturer

PC Manufacturerdistribution
Dell 100.00%
Should I remove It? Clean your PC of unwanted adware, toolbars and bloatware.

Download it for FREE