AxInstUI.exe

  • File Path: C:\Windows\system32\AxInstUI.exe
  • Description: ActiveX Installer Service

Hashes

Type Hash
MD5 7C4330CA1C347C2DF864D94221638649
SHA1 67777E34D95BBC864CE084B71F3DCA87EBABCD5F
SHA256 23692FE79CB8E509356399155F22016E067C68B79C94CF149B4B3AADC7934469
SHA384 D15EBC7E885071F8FB4832F774B494666D1303AF870B260A46F8BFCF2FEC6C73B89BE633E7EF5F5927BE4E2DC9EBB904
SHA512 C3249AFA037FEE1267BCD9A7F63599B7053E59ACCAA3E0479AE81AE1266971D6D466325C60E6FD6411744E95C9CE1452125476778E7E3F4C7AEB557C324F5D42
SSDEEP 384:sD00uSxMVdsaSMoZL/w+1xq3UZU9a1xq3UZU9KWLIW:sD0h9saNoZL/w8ZU9QZU9H
IMP 7D8DEE85A40FC5307CB205608512D381
PESHA1 DAF6E2A5E647274222BF77B334BA0D1BE95902FD
PE256 2C334585146C8B08785D3FC0F6927F9C8C98728EE0E5CF38951B727B8C74769A

Runtime Data

Loaded Modules:

Path
C:\Windows\system32\AxInstUI.exe
C:\Windows\System32\combase.dll
C:\Windows\System32\CRYPT32.dll
C:\Windows\System32\GDI32.dll
C:\Windows\System32\gdi32full.dll
C:\Windows\System32\KERNEL32.DLL
C:\Windows\System32\KERNELBASE.dll
C:\Windows\System32\msvcp_win.dll
C:\Windows\System32\msvcrt.dll
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\RPCRT4.dll
C:\Windows\System32\SHELL32.dll
C:\Windows\System32\ucrtbase.dll
C:\Windows\System32\USER32.dll
C:\Windows\System32\win32u.dll
C:\Windows\System32\WINTRUST.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002EC6579AD1E670890130000000002EC
  • Thumbprint: F7C2F2C96A328C13CDA8CDB57B715BDEA2CBD1D9
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: AxInstUI.exe.mui
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.388 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.388
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/74
  • VirusTotal Link: https://www.virustotal.com/gui/file/23692fe79cb8e509356399155f22016e067c68b79c94cf149b4b3aadc7934469/detection

File Similarity (ssdeep match)

File Score
C:\Windows\system32\AxInstUI.exe 55
C:\Windows\system32\AxInstUI.exe 61
C:\Windows\system32\AxInstUI.exe 60
C:\WINDOWS\system32\AxInstUI.exe 57
C:\Windows\system32\AxInstUI.exe 72
C:\Windows\system32\AxInstUI.exe 72
C:\WINDOWS\system32\AxInstUI.exe 66

MIT License. Copyright (c) 2020-2021 Strontic.