imecfmui.exe

  • File Path: C:\WINDOWS\system32\IME\SHARED\imecfmui.exe
  • Description: Microsoft IME

Hashes

Type Hash
MD5 FE0E34B0CB56664E9D276A8FBD1B0752
SHA1 063CAC323026311617C404EC9DF4B1FF7CED57A7
SHA256 EE72BEA1268C260F43E8D0B11574AB8E16F796EE2F9CFFE271B0D150AC1ABC83
SHA384 CC96E8B0C483EDD067EF1354CF55DD2BE78B5709DB65F807749871D397A3D4AC71F97611DA88AEEA41F3990C11A5338D
SHA512 80E5C336D39AC8217FCA93FA7F6CFC136C2F9C2397818C8C907099158DFFE3756AF7A3F6B1C0EC3E339FA9D845EFE5CD3969DE85C24915CBF22577DDBE7DCC6C
SSDEEP 6144:ENTJx9dGWG6Z4vNKyitADrE5QZn6Mlm05gRJnstcRZgBk8SK1A:E9j7u0yiq16Mlm0+PYS
IMP 7393127693100331B886EEC76863F4AA
PESHA1 B40713C333E6697F0A0F24B6A171B0568719DD18
PE256 7EF88726D1025F7481B544FE8AAF312EE8E8D6DB29DADA1A19C89584D8F68551

Runtime Data

Loaded Modules:

Path
C:\WINDOWS\System32\ADVAPI32.dll
C:\WINDOWS\system32\IME\SHARED\imecfmui.exe
C:\WINDOWS\System32\KERNEL32.DLL
C:\WINDOWS\System32\KERNELBASE.dll
C:\WINDOWS\SYSTEM32\ntdll.dll

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: imecfmui.exe
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: Language Neutral
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: Unknown

File Similarity (ssdeep match)

File Score
C:\Windows\system32\IME\shared\imecfmui.exe 30
C:\Windows\system32\IME\SHARED\imecfmui.exe 49
C:\WINDOWS\system32\IME\SHARED\imecfmui.exe 36
C:\Windows\system32\IME\SHARED\imecfmui.exe 38
C:\WINDOWS\SysWOW64\IME\SHARED\imecfmui.exe 35
C:\Windows\SysWOW64\IME\SHARED\imecfmui.exe 38
C:\WINDOWS\SysWOW64\IME\SHARED\imecfmui.exe 30
C:\Windows\SysWOW64\IME\shared\imecfmui.exe 30
C:\Windows\SysWOW64\IME\SHARED\imecfmui.exe 36

MIT License. Copyright (c) 2020-2021 Strontic.