userinitext.dll
- File Path:
C:\Windows\SysWOW64\userinitext.dll
- Description: UserInit Utility Extension DLL
Hashes
Type |
Hash |
MD5 |
53DAAC6F40F9905E762D851DD5C8D847 |
SHA1 |
BA8D3C29129470D29B87F908D870FF24F9EB5097 |
SHA256 |
05FF12643C85ABEA400A081EA21BA185AE30F37D52869E76BB7F410BA394006C |
SHA384 |
7701A0D53B30369035A13957648B6A70ED3B93D9EBBB04FEF85A32E8CB1F8D98E2188321A8D922350D9C601224D4B111 |
SHA512 |
77708A166B6D43A5940F10A38440F82CBE015032FCAB88FC4F08FF2B760FA3EC12AD587DD6202B4A29F12E47A75F552E27247EE7B101144E3901F8D0B7486F8A |
SSDEEP |
384:/pCe1kRwpbGE2suE4Dri5Fd5fXeByhQ2WSTW0J:0erGErU8F7GUh3JJ |
IMP |
7260F4E9CFA799851B434277C68F6A1D |
PESHA1 |
DC1175BCA93DC9DACD14C90C625EF9DEE6249C32 |
PE256 |
BA9CDB267124FBF456836DB3655BD0579A61F7BDF29B3769D137CD9173FD31EB |
DLL Exports:
Function Name |
Ordinal |
Type |
ProcessTermSrvIniFiles |
9 |
Exported Function |
ProcesRemoteSessionInitialCommand |
8 |
Exported Function |
PerformXForestLogonCheck |
7 |
Exported Function |
UserinitExt |
12 |
Exported Function |
SetupHotKeyForKeyboardLayout |
11 |
Exported Function |
SetShellDesktopSwitchEvent |
10 |
Exported Function |
ImmWorker |
3 |
Exported Function |
DisplayMessageAndExitWindows |
2 |
Exported Function |
CreateExplorerSessionKey |
1 |
Exported Function |
LoadRemoteFontsAndInitMiscWorker |
6 |
Exported Function |
IsTSAppCompatOn |
5 |
Exported Function |
IsSubDesktopSession |
4 |
Exported Function |
Signature
- Status: Signature verified.
- Serial:
3300000266BD1580EFA75CD6D3000000000266
- Thumbprint:
A4341B9FD50FB9964283220A36A1EF6F6FAA7840
- Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
- Original Filename: UserInitExt.DLL
- Product Name: Microsoft Windows Operating System
- Company Name: Microsoft Corporation
- File Version: 10.0.19041.1 (WinBuild.160101.0800)
- Product Version: 10.0.19041.1
- Language: English (United States)
- Legal Copyright: Microsoft Corporation. All rights reserved.
- Machine Type: 32-bit
File Scan
- VirusTotal Detections: 0/71
- VirusTotal Link: https://www.virustotal.com/gui/file/05ff12643c85abea400a081ea21ba185ae30f37d52869e76bb7f410ba394006c/detection/
MIT License. Copyright (c) 2020-2021 Strontic.