WofUtil.dll

  • File Path: C:\Windows\SysWOW64\WofUtil.dll
  • Description: Windows Overlay File System Filter user mode API

Hashes

Type Hash
MD5 14ABE0012FF8B7BA24C775A664E65772
SHA1 48063C0864B33E96488E19BA766DD3B72F6BD840
SHA256 1135E775E3B48D196AB0F5EA90D05F55F8EB59C229AAC5132F40D5EDA5AD48C7
SHA384 91579A941DAB56AEFB9411021EF7FE89D5DB299C28D1F90CC54724743614A4B9D009237DAF5D975F1409F57421CC95F9
SHA512 200B83DC42930434981CBD586FD004164156EC41DDCDA6EF8365520978FAC0F1EE9D2A323335CC5C36B57A85B0AA5794171920BA55BCABC516B82A7CE348FE1E
SSDEEP 768:wZQMj1pHpVqtLDS7B9QpDlDzdTZzZgT3bT:wZQMj1pHpSSt9QpDBzlZzZgTLT
IMP FF0289727CA1EED2B572E3DA1B54C2E7
PESHA1 239FCB211CCD22A9EB63F8F79AF6F77F918D1F49
PE256 B1C083CE49873BDF36CAF3599E44A15DAAC62740FC9C69EE182F0B5849A6A6F4

DLL Exports:

Function Name Ordinal Type
WofWimEnumFiles 8 Exported Function
WofWimAddEntry 7 Exported Function
WofWimRemoveEntry 9 Exported Function
WofWimUpdateEntry 11 Exported Function
WofWimSuspendEntry 10 Exported Function
WofShouldCompressBinaries 6 Exported Function
WofFileEnumFiles 2 Exported Function
WofEnumEntries 1 Exported Function
WofGetDriverVersion 3 Exported Function
WofSetFileDataLocation 5 Exported Function
WofIsExternalFile 4 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: wofutil.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/72
  • VirusTotal Link: https://www.virustotal.com/gui/file/1135e775e3b48d196ab0f5ea90d05f55f8eb59c229aac5132f40d5eda5ad48c7/detection/

File Similarity (ssdeep match)

File Score
C:\WINDOWS\SysWOW64\compact.exe 36
C:\Windows\SysWOW64\compact.exe 40
C:\Windows\SysWOW64\compact.exe 40

MIT License. Copyright (c) 2020 Strontic.