devrtl.dll

  • File Path: C:\Windows\system32\devrtl.dll
  • Description: Device Management Run Time Library

Hashes

Type Hash
MD5 DBE97C4D262B0500C0B25F220E4A1031
SHA1 95804E827D1ACD2E293B0FB3EE5842C2838B828C
SHA256 B8BDB3CA73E22F09F10340A930303558B56CD5B9F07EF94BB36B3D5A3C9A4AF3
SHA384 0F636A25AFEF9B7863121522C94AC1C22139FF04F3E65DDE93E0A09DFE2276EF0AEBD975CCC6925A8F7BC94AF6A917B9
SHA512 DD94EF0561C8C6CD4D6D983712C5534CA78BEC8E58CE6700A65380BC7B55B82A867C68EE9AC4D79544D4F8211720117C631141B1C7BF3634CBACC0B4CD65B774
SSDEEP 1536:O+ieD337b1Ms3XbI5YFSx9TGK6rdTWon:tBD337ZMsbpSjV6rRRn
IMP 7621FD52AC2814AC4C97777F47255615
PESHA1 B64F747647B0A9013075359279CF6522F7C12CDE
PE256 A27942523C1306656E63E7D0F3A7DC0B6064CDB351606CE573405B4AA059586A

DLL Exports:

Function Name Ordinal Type
NdxTableGetPropertyValue 20 Exported Function
NdxTableNextObject 21 Exported Function
NdxTableObjectFromName 22 Exported Function
NdxTableGetPropertyTypeName 19 Exported Function
NdxTableGetObjectTypeName 16 Exported Function
NdxTableGetPropertyTypeClass 17 Exported Function
NdxTableGetPropertyTypeCount 18 Exported Function
NdxTableSetObjectPointer 27 Exported Function
NdxTableSetPropertyValue 28 Exported Function
NdxTableSetTypeDefinition 29 Exported Function
NdxTableRemoveObjectFromList 26 Exported Function
NdxTableObjectFromPointer 23 Exported Function
NdxTableOpen 24 Exported Function
NdxTableRemoveObject 25 Exported Function
NdxTableGetObjectTypeCount 15 Exported Function
DevRtlSetThreadLogToken 5 Exported Function
DevRtlWriteTextLog 6 Exported Function
DevRtlWriteTextLogError 7 Exported Function
DevRtlGetThreadLogToken 4 Exported Function
DevRtlCloseTextLogSection 1 Exported Function
DevRtlCreateTextLogSectionA 2 Exported Function
DevRtlCreateTextLogSectionW 3 Exported Function
NdxTableFirstObjectInList 12 Exported Function
NdxTableGetObjectName 13 Exported Function
NdxTableGetObjectType 14 Exported Function
NdxTableFirstObject 11 Exported Function
NdxTableAddObject 8 Exported Function
NdxTableAddObjectToList 9 Exported Function
NdxTableClose 10 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: DEVRTL.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/66
  • VirusTotal Link: https://www.virustotal.com/gui/file/b8bdb3ca73e22f09f10340a930303558b56cd5b9f07ef94bb36b3d5a3c9a4af3/detection/

MIT License. Copyright (c) 2020-2021 Strontic.