efsadu.dll

  • File Path: C:\Windows\SysWOW64\efsadu.dll
  • Description: File Encryption Utility

Hashes

Type Hash
MD5 C46B4BBA1B46BA2E6953286DC8BECD85
SHA1 8CDB8CB139BB3EEE1F64A2197F321F2A2DD493DC
SHA256 5EC6AAED85AFAD68619825E9C19ABE39FA852227B2E06B853D86EBADFC513C96
SHA384 62F517969784F93758EDDA9831DE42C19BC9A52019AC32F6466735E92B69A166B2D2E9D6B89F34DE18E54F81D1EF2334
SHA512 5EE85285AABFDE709995A30718CE492CC6780D2EA3796D5D8EDE0DF4D8A600032C272190B92ED701BE69D036797E538A045875A32B9208C09F6B564DEEF5C269
SSDEEP 1536:De9uFuQqBbkDQpr+37TVDvsegSM+8FjNeLT+B45cIUVax1Ix3DkvvvvvvvvvvvvV:DfFuQqBbkDQCvsoT+B45AUqxzBNv5w
IMP B498B66CCC6DEB0CA1D278ABCB6F076D
PESHA1 DAF5A090958FBF656F8A99B0C2A41AA3E8BF7DCE
PE256 DA34ECDAE85B39352AD5B81434BDF1D32D2D6EAAEA108406B1B298C0B0596DD3

DLL Exports:

Function Name Ordinal Type
EfsUIUtilKeyBackup 10 Exported Function
EfsUIUtilInstallDra 9 Exported Function
EfsUIUtilEnrollEfsCertificateEx 8 Exported Function
EfsUIUtilPromptForPin 11 Exported Function
EfsUIUtilShowBalloonAndWait 14 Exported Function
EfsUIUtilSelectCard 13 Exported Function
EfsUIUtilPromptForPinDialog 12 Exported Function
EfsDetail 3 Exported Function
BackCurrentEfsCert 2 Exported Function
AddUserToObjectW 1 Exported Function
EfsUIUtilCheckScardStatus 4 Exported Function
EfsUIUtilEnrollEfsCertificate 7 Exported Function
EfsUIUtilEncryptMyDocuments 6 Exported Function
EfsUIUtilCreateSelfSignedCertificate 5 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: EFSADU.DLL
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/69
  • VirusTotal Link: https://www.virustotal.com/gui/file/5ec6aaed85afad68619825e9c19abe39fa852227b2e06b853d86ebadfc513c96/detection/

MIT License. Copyright (c) 2020-2021 Strontic.