WinHvEmulation.dll

  • File Path: C:\Windows\system32\WinHvEmulation.dll
  • Description: Hyper-V Instruction Emulator User-Mode API Library

Hashes

Type Hash
MD5 A23661EB9755E8C1D072CF33B60CE7F6
SHA1 79205BA35B2A2C38BA49FB88994E12859919EAFF
SHA256 942B3FE1CBE287E171ED97550A79BFADE655EB8278D5BBFC37CBE84F7232E44E
SHA384 F8F4D5A73C5A6A9F973548FA3EB1C6021B09C05D9A906E52A8E141B596FBF186B0F1F47654F3E50BD242DD332758A16C
SHA512 92BE3338F29EE76234D7F908723725581FC05C3D0708E1DDC61EAE030914F183EAB8BF66643D6D1477B0353927C1E817E3B3D7BB219EDBF5588E1F3081386EF6
SSDEEP 1536:PBiGdyQ0E+2ei3C8mX0i6FyPRP95uf0+YrOTvSF2JbxjJwE3S6hbc9RqAjCI:PQGB+OC8mXnLPpSwObV13xbcHq0CI
IMP C91A81E4FD3F26D3BC2AF89DDD8BB69D
PESHA1 EAD2CAF0B7FA2CDE04A9E8D1054C78979B88AEB1
PE256 A736DD067CF180CA8BCEF6C8AF6495F46D465B967CBD0209998034EB01972265

DLL Exports:

Function Name Ordinal Type
WHvEmulatorTryIoEmulation 3 Exported Function
WHvEmulatorTryMmioEmulation 4 Exported Function
WHvEmulatorCreateEmulator 1 Exported Function
WHvEmulatorDestroyEmulator 2 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: WinHvEmu.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.264 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.264
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/942b3fe1cbe287e171ed97550a79bfade655eb8278d5bbfc37cbe84f7232e44e/detection/

MIT License. Copyright (c) 2020-2021 Strontic.