pwrshmsg.dll

  • File Path: C:\Windows\system32\WindowsPowerShell\v1.0\pwrshmsg.dll
  • Description: Microsoft PowerShell EventLog Message Dll

Hashes

Type Hash
MD5 0D6BD63BBA93BEF25ECA41CFC460AF27
SHA1 7C111AC3FD1FDC65C874A50B49DC57B2DF368A00
SHA256 17B9002BD02D98929DD701FBA5A1D654CD8E259AE6E82ACFDC1DB15C1B5DC062
SHA384 B19EE5D50CB15B9DD772676EB296D3FB92D39EFCE74E292721A4CB66FDF8140DEE65BC438B53C515654646911CB19FB8
SHA512 214CEB84C8F0FCFEE21E4594E2B333063DBD575F0EB699E8747448F7E3B7F3A65132828E7C2D3283F96836C1ABB7C00BE2410EC4B8C0587D6CB779DFE7679C13
SSDEEP 24:elGScfViyKeCmtlSIZW0JH5exNutpg35WWdPPYPNybKSMsC:CcNinFmtEIZWqHSurO5WwHg9Vs
IMP n/a
PESHA1 CC00C34CBF39E82C4526BC0A5427FE819A208C54
PE256 B5BF29275C3DD51BFACD4133E720559101BBE14939E84C8DE7F13F285628235F

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: pwrshmsg.DLL.MUI
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/70
  • VirusTotal Link: https://www.virustotal.com/gui/file/17b9002bd02d98929dd701fba5a1d654cd8e259ae6e82acfdc1db15c1b5dc062/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\system32\advapi32res.dll 54
C:\Windows\system32\asferror.dll 50
C:\Windows\system32\blbres.dll 50
C:\Windows\system32\bridgeres.dll 58
C:\Windows\system32\comres.dll 49
C:\Windows\system32\DMAppsRes.dll 55
C:\Windows\system32\dmdskres.dll 49
C:\Windows\system32\dmdskres2.dll 52
C:\Windows\system32\ETWCoreUIComponentsResources.dll 44
C:\Windows\system32\icmp.dll 46
C:\Windows\system32\imageres.dll 54
C:\Windows\system32\imagesp1.dll 54
C:\Windows\system32\iologmsg.dll 61
C:\Windows\system32\lltdres.dll 52
C:\Windows\system32\MapControlStringsRes.dll 55
C:\Windows\system32\Microsoft-WindowsPhone-SEManagementProvider.dll 52
C:\Windows\system32\moricons.dll 54
C:\Windows\system32\msafd.dll 49
C:\Windows\system32\msprivs.dll 57
C:\Windows\system32\neth.dll 52
C:\Windows\system32\netmsg.dll 58
C:\Windows\system32\normaliz.dll 47
C:\Windows\system32\PhoneServiceRes.dll 60
C:\Windows\system32\PhoneutilRes.dll 68
C:\Windows\system32\qedwipes.dll 50
C:\Windows\system32\rnr20.dll 47
C:\Windows\system32\SensorsCpl.dll 46
C:\Windows\system32\SyncRes.dll 58
C:\Windows\system32\tapiui.dll 52
C:\Windows\system32\TelephonyInteractiveUserRes.dll 50
C:\Windows\system32\TpmCertResources.dll 43
C:\Windows\system32\wbem\WmiApRes.dll 61
C:\Windows\system32\winrsmgr.dll 55
C:\Windows\system32\wmerror.dll 55
C:\Windows\system32\wmploc.DLL 43
C:\Windows\system32\XAudio2_8.dll 49
C:\Windows\SysWOW64\advapi32res.dll 50
C:\Windows\SysWOW64\asferror.dll 47
C:\Windows\SysWOW64\comres.dll 47
C:\Windows\SysWOW64\DMAppsRes.dll 54
C:\Windows\SysWOW64\dmdskres.dll 49
C:\Windows\SysWOW64\dmdskres2.dll 50
C:\Windows\SysWOW64\ETWCoreUIComponentsResources.dll 44
C:\Windows\SysWOW64\icmp.dll 44
C:\Windows\SysWOW64\imageres.dll 52
C:\Windows\SysWOW64\imagesp1.dll 54
C:\Windows\SysWOW64\iologmsg.dll 58
C:\Windows\SysWOW64\MapControlStringsRes.dll 49
C:\Windows\SysWOW64\moricons.dll 46
C:\Windows\SysWOW64\msafd.dll 47
C:\Windows\SysWOW64\mscpx32r.dLL 54
C:\Windows\SysWOW64\msorc32r.dll 46
C:\Windows\SysWOW64\neth.dll 54
C:\Windows\SysWOW64\netmsg.dll 52
C:\Windows\SysWOW64\normaliz.dll 46
C:\Windows\SysWOW64\PhoneutilRes.dll 61
C:\Windows\SysWOW64\qedwipes.dll 47
C:\Windows\SysWOW64\rnr20.dll 47
C:\Windows\SysWOW64\SensorsCpl.dll 46
C:\Windows\SysWOW64\SyncRes.dll 54
C:\Windows\SysWOW64\tapiui.dll 49
C:\Windows\SysWOW64\TpmCertResources.dll 41
C:\WINDOWS\SysWOW64\user.exe 41
C:\Windows\SysWOW64\user.exe 49
C:\Windows\SysWOW64\user.exe 47
C:\Windows\SysWOW64\user.exe 43
C:\Windows\SysWOW64\WindowsPowerShell\v1.0\pwrshmsg.dll 86
C:\Windows\SysWOW64\winrsmgr.dll 55
C:\Windows\SysWOW64\wmerror.dll 55
C:\Windows\SysWOW64\wmploc.DLL 44
C:\Windows\SysWOW64\XAudio2_8.dll 47

MIT License. Copyright (c) 2020 Strontic.