¿Para qué sirve la dll ureg.dll?

Registry Utility DLL

Dependencias de la dll ureg.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\ureg.dll

File Type: DLL

  Image has the following dependencies:

    msvcrt.dll
    ntdll.dll
    KERNEL32.dll
    ADVAPI32.dll
    ulib.dll

  Summary

        1000 .data
        1000 .pdata
        2000 .rdata
        1000 .reloc
        1000 .rsrc
        6000 .text

Funciones que tiene la dll ureg.dll


1    0 000018F0 ??0REGISTRY@@QEAA@XZ
2    1 000013F0 ??0REGISTRY_KEY_INFO@@QEAA@XZ
3    2 000010E0 ??0REGISTRY_VALUE_ENTRY@@QEAA@XZ
4    3 00001950 ??1REGISTRY@@UEAA@XZ
5    4 00001490 ??1REGISTRY_KEY_INFO@@UEAA@XZ
6    5 00001140 ??1REGISTRY_VALUE_ENTRY@@UEAA@XZ
7    6 00001DF0 ?AddValueEntry@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVREGISTRY_VALUE_ENTRY@@EPEAK@Z
8    7 00002400 ?CreateKey@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@1PEAKE@Z
9    8 000026C0 ?DeleteKey@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
10    9 00002790 ?DeleteValueEntry@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
11    A 00002940 ?DoesKeyExist@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAK@Z
12    B 000029B0 ?DoesValueExist@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@11PEAK@Z
13    C 000046A0 ?EnableRootNotification@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAXKE@Z
14    D 000019F0 ?Initialize@REGISTRY@@QEAAEPEBVWSTRING@@PEAK@Z
15    E 00001580 ?Initialize@REGISTRY_KEY_INFO@@QEAAEPEBVWSTRING@@0K0PEAU_SECURITY_ATTRIBUTES@@@Z
16    F 000011E0 ?Initialize@REGISTRY_VALUE_ENTRY@@QEAAEPEBVWSTRING@@KW4_REG_TYPE@@PEBEK@Z
17   10 00005030 ?IsAccessAllowed@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@KPEAK@Z
18   11 00004AC0 ?LoadHive@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
19   12 00002B00 ?QueryKeyInfo@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAVREGISTRY_KEY_INFO@@PEAK@Z
20   13 00002F60 ?QueryKeySecurity@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVREGISTRY_KEY_INFO@@KPEAPEAXPEAK@Z
21   14 00003110 ?QuerySubKeysInfo@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAVARRAY@@PEAK@Z
22   15 00003670 ?QueryValues@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAVARRAY@@PEAK@Z
23   16 00004ED0 ?RestoreKeyFromFile@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@EPEAK@Z
24   17 00004DA0 ?SaveKeyToFile@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
25   18 00003D20 ?SetKeySecurity@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@KPEAXPEAKE@Z
26   19 00004C70 ?UnLoadHive@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEAK@Z
27   1A 00003E80 ?UpdateKeyInfo@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEAK@Z

Información avanzada sobre funciones que tiene la dll ureg.dll


Microsoft (R) COFF/PE Dumper Version 14.16.27034.0
Copyright (C) Microsoft Corporation.  All rights reserved.


Dump of file C:\Windows\System32\ureg.dll

File Type: DLL

  Section contains the following exports for ureg.dll

    00000000 characteristics
    754604B5 time date stamp
        0.00 version
           1 ordinal base
          27 number of functions
          27 number of names

    ordinal hint RVA      name

          1    0 000018F0 ??0REGISTRY@@QEAA@XZ
          2    1 000013F0 ??0REGISTRY_KEY_INFO@@QEAA@XZ
          3    2 000010E0 ??0REGISTRY_VALUE_ENTRY@@QEAA@XZ
          4    3 00001950 ??1REGISTRY@@UEAA@XZ
          5    4 00001490 ??1REGISTRY_KEY_INFO@@UEAA@XZ
          6    5 00001140 ??1REGISTRY_VALUE_ENTRY@@UEAA@XZ
          7    6 00001DF0 ?AddValueEntry@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVREGISTRY_VALUE_ENTRY@@EPEAK@Z
          8    7 00002400 ?CreateKey@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@1PEAKE@Z
          9    8 000026C0 ?DeleteKey@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
         10    9 00002790 ?DeleteValueEntry@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
         11    A 00002940 ?DoesKeyExist@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAK@Z
         12    B 000029B0 ?DoesValueExist@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@11PEAK@Z
         13    C 000046A0 ?EnableRootNotification@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAXKE@Z
         14    D 000019F0 ?Initialize@REGISTRY@@QEAAEPEBVWSTRING@@PEAK@Z
         15    E 00001580 ?Initialize@REGISTRY_KEY_INFO@@QEAAEPEBVWSTRING@@0K0PEAU_SECURITY_ATTRIBUTES@@@Z
         16    F 000011E0 ?Initialize@REGISTRY_VALUE_ENTRY@@QEAAEPEBVWSTRING@@KW4_REG_TYPE@@PEBEK@Z
         17   10 00005030 ?IsAccessAllowed@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@KPEAK@Z
         18   11 00004AC0 ?LoadHive@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
         19   12 00002B00 ?QueryKeyInfo@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAVREGISTRY_KEY_INFO@@PEAK@Z
         20   13 00002F60 ?QueryKeySecurity@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVREGISTRY_KEY_INFO@@KPEAPEAXPEAK@Z
         21   14 00003110 ?QuerySubKeysInfo@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAVARRAY@@PEAK@Z
         22   15 00003670 ?QueryValues@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEBVWSTRING@@1PEAVARRAY@@PEAK@Z
         23   16 00004ED0 ?RestoreKeyFromFile@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@EPEAK@Z
         24   17 00004DA0 ?SaveKeyToFile@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEBVWSTRING@@PEAK@Z
         25   18 00003D20 ?SetKeySecurity@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@KPEAXPEAKE@Z
         26   19 00004C70 ?UnLoadHive@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEAK@Z
         27   1A 00003E80 ?UpdateKeyInfo@REGISTRY@@QEAAEW4_PREDEFINED_KEY@@PEAVREGISTRY_KEY_INFO@@PEAK@Z

  Summary

        1000 .data
        1000 .pdata
        2000 .rdata
        1000 .reloc
        1000 .rsrc
        6000 .text

Integridad de la dll ureg.dll



Algorithm       Hash                                                                   Path                                                           
---------       ----                                                                   ----                                                           
SHA256          CC7126B30F64FC34A926935AE303276D0E729E990F428C667FAC32AF2B67F64F       C:\Windows\System32\ureg.dll                                   


Detalles sobre el fichero dll ureg.dll




PSPath            : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32\ureg.dll
PSParentPath      : Microsoft.PowerShell.Core\FileSystem::C:\Windows\System32
PSChildName       : ureg.dll
PSDrive           : C
PSProvider        : Microsoft.PowerShell.Core\FileSystem
PSIsContainer     : False
Mode              : -a----
VersionInfo       : File:             C:\Windows\System32\ureg.dll
                    InternalName:     ureg.dll
                    OriginalFilename: ureg.dll
                    FileVersion:      10.0.19041.1 (WinBuild.160101.0800)
                    FileDescription:  Registry Utility DLL
                    Product:          Microsoft® Windows® Operating System
                    ProductVersion:   10.0.19041.1
                    Debug:            False
                    Patched:          False
                    PreRelease:       False
                    PrivateBuild:     False
                    SpecialBuild:     False
                    Language:         Inglés (Estados Unidos)
                    
BaseName          : ureg
Target            : {C:\Windows\WinSxS\amd64_microsoft-windows-m..ommandlineutilities_31bf3856ad364e35_10.0.19041.1_none_330dfb2b06b21af6\ureg.dll}
LinkType          : HardLink
Name              : ureg.dll
Length            : 32768
DirectoryName     : C:\Windows\System32
Directory         : C:\Windows\System32
IsReadOnly        : False
Exists            : True
FullName          : C:\Windows\System32\ureg.dll
Extension         : .dll
CreationTime      : 07/12/2019 10:09:37
CreationTimeUtc   : 07/12/2019 9:09:37
LastAccessTime    : 03/12/2020 16:07:34
LastAccessTimeUtc : 03/12/2020 15:07:34
LastWriteTime     : 07/12/2019 10:09:37
LastWriteTimeUtc  : 07/12/2019 9:09:37
Attributes        : Archive



Procesos que utilizan la dll ureg.dll