werui.dll

  • File Path: C:\Windows\SysWOW64\werui.dll
  • Description: Windows Error Reporting UI DLL

Hashes

Type Hash
MD5 953EB30D45E7FC1E524C4E868235A706
SHA1 A4A3D5E7C88B7F765EE20D387825965861284769
SHA256 404025B810450F0FDFB36EC0955CFED312D5BA778790D5F2FA685D6BB3A580A9
SHA384 AC24520C22B180D980FBC48BB7A3141D1452A483D9FA1BFD3D016F2BA060EA5B528BCDFBC0A241325507374CDA85D9B2
SHA512 A88D4F0B5353FAE08E3F97AB12DFC4BB0AC30933B2E1AC9E703993425A68040CB84EC6CB1F9D7CCADF7CB539CDFB8C5E251EF609FD0B9EFDCF3B31D818DC78C8
SSDEEP 6144:FElSrXe9qcZ8ATmwBxBfdwJVJyB60OHyLC7v:F0pTtj10c2Hyw
IMP 9087FAE47BE45376C69210DF3B2B0DE8
PESHA1 D8A1E063DAFC0015840C96EA66DD44DE891992BF
PE256 47BA3E4D87CEAEF6774174FE12FE5C26FF0C8DA73E80E62EECC2A6B1CCAC39A8

DLL Exports:

Function Name Ordinal Type
WerUIReportSilentProcessExit 1 Exported Function
WerUIShowUpsell 7 Exported Function
WerUIpTaskDialogIndirect 18 Exported Function
WerUIpUIHandleWERWindowMsg 19 Exported Function
WerUIStart 8 Exported Function
WerUIUpdateUIForState 11 Exported Function
WerUIWaitForUserAction 12 Exported Function
WerUITerminate 9 Exported Function
WerUIUpdateStateProgress 10 Exported Function
WerUIpSetWindowSubclass 17 Exported Function
WerUIGetUserSelection 4 Exported Function
WerUIpCheckWindow 13 Exported Function
WerUICreate 2 Exported Function
WerUIDelete 3 Exported Function
WerUIpDefSubclassProc 14 Exported Function
WerUIPromptForSecondLevel 5 Exported Function
WerUIPromptUser 6 Exported Function
WerUIpHeadlessOrImersive 15 Exported Function
WerUIpRemoveWindowSubclass 16 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 330000026551AE1BBD005CBFBD000000000265
  • Thumbprint: E168609353F30FF2373157B4EB8CD519D07A2BFF
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: werui.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.388 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.388
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/68
  • VirusTotal Link: https://www.virustotal.com/gui/file/404025b810450f0fdfb36ec0955cfed312d5ba778790d5f2fa685d6bb3a580a9/detection/

File Similarity (ssdeep match)

File Score
C:\Windows\system32\Faultrep.dll 41
C:\windows\system32\WerFault.exe 35
C:\Windows\system32\WerFault.exe 35
C:\Windows\system32\WerFault.exe 38
C:\Windows\system32\WerFault.exe 41
C:\Windows\system32\WerFaultSecure.exe 54
C:\WINDOWS\system32\WerFaultSecure.exe 50
C:\Windows\system32\WerFaultSecure.exe 52
C:\Windows\system32\WerFaultSecure.exe 49
C:\Windows\system32\WerFaultSecure.exe 54
C:\Windows\system32\WerFaultSecure.exe 58
C:\Windows\system32\WerFaultSecure.exe 47
C:\Windows\system32\WerFaultSecure.exe 47
C:\Windows\system32\wermgr.exe 43
C:\Windows\system32\wermgr.exe 50
C:\Windows\system32\wermgr.exe 50
C:\WINDOWS\system32\wermgr.exe 43
C:\Windows\system32\wermgr.exe 41
C:\Windows\system32\wermgr.exe 52
C:\Windows\system32\wermgr.exe 46
C:\Windows\system32\wermgr.exe 47
C:\Windows\system32\wermgr.exe 47
C:\windows\system32\wermgr.exe 52
C:\Windows\system32\werui.dll 46
C:\Windows\SysWOW64\WerFault.exe 46
C:\windows\SysWOW64\WerFault.exe 33
C:\Windows\SysWOW64\WerFaultSecure.exe 55
C:\Windows\SysWOW64\WerFaultSecure.exe 43
C:\Windows\SysWOW64\WerFaultSecure.exe 49
C:\Windows\SysWOW64\WerFaultSecure.exe 40
C:\WINDOWS\SysWOW64\WerFaultSecure.exe 49
C:\Windows\SysWOW64\WerFaultSecure.exe 52
C:\Windows\SysWOW64\WerFaultSecure.exe 43
C:\Windows\SysWOW64\WerFaultSecure.exe 54
C:\Windows\SysWOW64\wermgr.exe 50
C:\windows\SysWOW64\wermgr.exe 50
C:\Windows\SysWOW64\wermgr.exe 44
C:\WINDOWS\SysWOW64\wermgr.exe 41
C:\Windows\SysWOW64\wermgr.exe 38
C:\Windows\SysWOW64\wermgr.exe 38
C:\Windows\SysWOW64\wermgr.exe 40

MIT License. Copyright (c) 2020 Strontic.