• File Path: C:\Program Files (x86)\Windows Kits\10\bin\10.0.15063.0\x64\GenXBF.dll
  • Description: GenXbf


Type Hash
MD5 0D08D939ADF2728051B1E9817EE458AE
SHA1 D13069C5DC3430E5BEA89A2601277D5008CED3A0
SHA256 B7C4A1884E344BFCC86280F58996783062BCB8018734F308851D6B7AEEDE538C
SHA384 F1237365A12857528DCF43189698B47057A50DF01CC662C220D2649A2210DDF0E06162D88157C31FD3965FE3CBF1CC3A
SHA512 DBABD98900C554254CB5377C6DE4B8200848CE16CE015BAD23583740DACDEE1D41005ED6E97B108B87C46F4AB02DB06D815E56C5956551C8D50C0FC64D8A69DA
SSDEEP 24576:1Mn7fA8+FFsHwcNnIVLVHGqsl59R7lpXBPH1tw4vOnF:1MnjAhcwcmVLNc59hXFH1tw4vUF
IMP 4FCC1B0C24223B74B7526B6FF555DBF2
PESHA1 CD9267C7CA4B4102B2EE645829DC6D7F1A99E06C
PE256 EF3D1BA8E3571C164E76A59E0C9755E639218FC41FDAE8DDE0E5B458F96E3F75

DLL Exports:

Function Name Ordinal Type
WriteToStreams 4 Exported Function
WriteWithChecksum 5 Exported Function
Write 3 Exported Function
Dump 1 Exported Function
GenerateBinaryXaml 2 Exported Function


  • Status: The file C:\Program Files (x86)\Windows Kits\10\bin\10.0.15063.0\x64\GenXBF.dll is not digitally signed. You cannot run this script on the current system. For more information about running scripts and setting execution policy, see about_Execution_Policies at https:/
  • Serial: ``
  • Thumbprint: ``
  • Issuer:
  • Subject:

File Metadata

  • Original Filename: GenXbf.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.15063.674 (WinBuild.160101.0800)
  • Product Version: 10.0.15063.674
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/76
  • VirusTotal Link:

MIT License. Copyright (c) 2020 Strontic.