xwreg.dll

  • File Path: C:\Windows\system32\xwreg.dll
  • Description: Extensible Wizard Registration Manager Module

Hashes

Type Hash
MD5 F53B24BEAF5007F8FE7FB9E6FED9827A
SHA1 4FF2C340BF11CE3CB4827534CF28AA1F19202552
SHA256 690837C3ABDA161152CB88B5E411280D7CD8011AC37067D10E416EEF7B901861
SHA384 6EED570ED0116A5DEA4AEC7F2801194615F7FFC6E214D347963D4CE347FB07212F7214696A338332E702116BEF23CCA7
SHA512 1EE6DA4AE62CAF48F7EC7C34C95C652539E368E1DE332C73093B0253ED80D88A5D14EF416E79EDFD4E3E52EB6E682FB594AB6E4EB3F359A325AD33B8ED11C395
SSDEEP 1536:IRAhxqtoZHR/7EnMSmvg6Qjnx6rplaDL9Q4bGnwFSP8+yMlQr2J4aIvY:IQxq+Zx/Xn9inoiRQdF8+yKQr2Jnq
IMP A53794388F30571B6B34D9AB57A01E12
PESHA1 BC89E7B208B0BD7CC695F40747525742BBCB1FEC
PE256 4CB7B4230BF704DB4ED6D41D0C0C9EDAFEC364D6A408E7C62FAC64F15A6BC41E

DLL Exports:

Function Name Ordinal Type
DllGetClassObject 2 Exported Function
DllCanUnloadNow 1 Exported Function

Signature

  • Status: Signature verified.
  • Serial: 3300000266BD1580EFA75CD6D3000000000266
  • Thumbprint: A4341B9FD50FB9964283220A36A1EF6F6FAA7840
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: xwreg.dll
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.19041.1 (WinBuild.160101.0800)
  • Product Version: 10.0.19041.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 64-bit

File Scan

  • VirusTotal Detections: 0/71
  • VirusTotal Link: https://www.virustotal.com/gui/file/690837c3abda161152cb88b5e411280d7cd8011ac37067d10e416eef7b901861/detection/

MIT License. Copyright (c) 2020-2021 Strontic.