efsui.exe

  • File Path: C:\Windows\SysWOW64\efsui.exe
  • Description: EFS UI Application

Hashes

Type Hash
MD5 8FE2A7847AB90E6E150B6B4E4C247927
SHA1 8A417B125D22CD6E75EDD8F16C82CB2ADB4EDE3B
SHA256 15D3D82211FE83FEE501D2EFACD0168301CE73DCB7CC08F1CA7BC2EE94A61FC7
SHA384 AB31FD5E2472FAC68316A6A94A2632A06087E46DAA8E3C8E11A1FCABBD414141755053168994E4C29DFE7EB7BF6654E3
SHA512 18FAAA7EED78E6503F90041B65B8C7B9C57A2CA800A9BA4AE59A42B9D5C1F92C13246A34266D18A7FDCD1A646B921163E0E1354815F74455BCC210289E0FCAD1
SSDEEP 192:Qgeajd/FlC6t7V/TGjJKgDIjoBbqZ2kTBWSDRWqfd:tTZFlC6xp8JKjMgZxTBWSDRWqf
IMP FBFCDB62E39168BD77F5A0D82001C66C
PESHA1 E684172D549E0A133D27F5BAEF0D4A3AA8EF93A9
PE256 10CF362FD92E137B1CDDCADA981C0B885398E1B020BCAD64DF1B05AC95BA2F2C

Runtime Data

Child Processes:

setup_wm.exe

Loaded Modules:

Path
C:\Windows\SYSTEM32\ntdll.dll
C:\Windows\System32\wow64.dll
C:\Windows\System32\wow64cpu.dll
C:\Windows\System32\wow64win.dll
C:\Windows\SysWOW64\efsui.exe

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: efsui.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/76
  • VirusTotal Link: https://www.virustotal.com/gui/file/15d3d82211fe83fee501d2efacd0168301ce73dcb7cc08f1ca7bc2ee94a61fc7/detection

MIT License. Copyright (c) 2020-2021 Strontic.